How financial crime investigators actually work: a practitioner's guide
I have spent about twenty years in this work, across banks, fintechs, payment institutions and crypto firms. The gap I keep meeting is not a knowledge gap. People arrive able to recite the regulation and unable to say what a finished case file looks like. This is that missing half.
What actually arrives on your desk
The mental picture most people bring to a first analyst role is an investigation: a suspicion, then a search for evidence. The reality runs the other way round. You are handed a queue of machine-generated signals, most of which mean nothing, and your job is to work out which ones deserve a human being's attention.
A working morning tends to look like this. Somewhere between six and thirty items are waiting, depending on the institution and how badly its thresholds are tuned. Each one is a rule that fired: a payment above a value band, a pattern of deposits sitting just under a reporting threshold, a counterparty in a jurisdiction on an internal watch list, a customer whose activity in the last month bears no resemblance to the twelve before it. None of these are accusations. They are arithmetic.
Most of them close. In the teams I have run, somewhere between eighty and ninety-five per cent of monitoring alerts were resolved without escalation, and that is a healthy number rather than a failure. The purpose of a monitoring system is not to be right. It is to be sensitive enough that the genuinely unusual cannot pass unexamined, which mathematically guarantees a large volume of ordinary activity gets examined too.
Understanding that changes how you read the queue. A new analyst treats each alert as a question about whether the customer is doing something wrong. An experienced one treats it as a question about whether the file can explain what happened. Those are different jobs, and only the second one is achievable.
The order of operations
Most rework I have seen traces back to sequence rather than skill. Analysts open the customer record first, form a view, then go looking for transactions that support it. By the time they reach the data they are no longer reading it, they are confirming themselves.
Read the alert on its own terms before you know whose it is. What rule fired, over what window, on what amounts, in what direction. Write down, in one sentence, what would have to be true of this customer for the pattern to be entirely ordinary. Only then open the profile.
What you are doing with that sentence is committing to a test before you know the answer. If the customer turns out to be a wholesale food importer and the pattern is high-volume round-figure payments to overseas suppliers, your sentence has been answered and the alert closes in four minutes. If the customer is a salaried employee with no declared business, the same pattern has not been answered, and now you have a real piece of work.
Case note
A retail customer, on file for eleven years as a salaried administrator, receives fourteen inbound faster payments across nine days, each between £2,100 and £2,900, from twelve different individuals with no apparent relationship to her. Ninety per cent moves out within forty-eight hours to a single third party. Total across the period is a little under £34,000.
The junior analyst who first held this file closed it. The rationale recorded was that the individual amounts were small, the customer had no adverse media, and the tenure was long. Every one of those statements was accurate. None of them addressed the pattern.
What the file needed was one line: nothing in the customer's known profile explains inbound payments from twelve unconnected individuals, and the rapid onward movement of nearly all of it to one recipient is inconsistent with personal use of funds. That was the finding. The onward recipient was already the subject of two reports from another institution.
The alert had not been misjudged so much as never actually engaged. Long tenure and clean adverse media are reasons the customer is unlikely to be a professional criminal. They are not reasons the account is not being used by someone else.
Where files fall apart
When a regulator, an internal audit function or a successor analyst pulls a file two years later, they cannot see what you thought. They can only see what you wrote. Nearly every weak file I have inherited was weak in the same place: the conclusion was defensible and the record of how it was reached was not.
Three failures account for most of it.
Conclusions recorded without the reasoning
"Activity consistent with customer profile" is not a rationale. It is the last line of one. Which part of the profile, established when, and consistent in what respect. A reviewer who cannot reconstruct your logic has to redo your work, and redone work usually reaches a different answer.
Evidence referenced but not retained
An analyst reviews an invoice, satisfies themselves, and notes that documentation was reviewed. The document is in an email thread that leaves with them when they change jobs. If it is not attached to the case, it was not obtained.
The negative finding left unwritten
This is the subtle one, and it is the difference between a competent file and a good one. If you looked for adverse media and found none, that is a finding and it belongs in the record. If you asked a relationship manager about the source of a payment and never received an answer, that absence is material. Silence in a file reads as an omission, and an omission looks like something that was never checked.
The habits that separate people
Five things distinguish analysts who clear their queue from those whose queue slowly buries them. None of them are technical.
- Timeboxing the ordinary. A clear false positive should take minutes, and the discipline is to close it rather than admire it. The interesting work only gets attention if the routine work is genuinely routine.
- Writing while working. Not after. The rationale composed the following afternoon is a reconstruction, and it shows.
- Naming the alternative explanation. The strongest files I have signed off state clearly what innocent reading of the activity was considered, and why the available evidence did not support it.
- Asking earlier than feels comfortable. The cost of a five-minute question to a colleague who has seen the pattern before is always lower than the cost of a file that has to be reopened.
- Reading your own closed alerts once a month. Nothing improves judgement faster than meeting your own reasoning from six weeks ago as a stranger would.
Disposition is the whole job
Every alert ends in a decision, and there are only a few of them: close with rationale, escalate for enhanced review, file a suspicious activity report, exit the relationship. New analysts fixate on picking the right one. That is the wrong anxiety.
The standard you are held to is not correctness, because correctness is frequently unknowable from inside a single institution — you can see one bank's slice of a network and nothing else. The standard is whether a reasonable practitioner, given the information available at the time, could arrive at your conclusion by following your recorded reasoning. That is defensibility, and it is achievable on every file.
It also explains why documentation is not administrative overhead sitting after the real work. It is the real work. The judgement exists only in the form in which it was recorded.
The point here: the skill this job actually rewards is not spotting criminals. It is building a record that survives someone else reading it two years from now, without you in the room to explain it.