10 Facts About Financial Crime from FinCrime Agent's Founder — An Oninvest Exclusive

Preventing financial crime is no longer just a matter of tracking suspicious transactions, says Marco Beranzoni. / Photo: Unsplash / Sandra Gabriel
Financial crime prevention should not rely solely on list screening or statistical risk valuations, it requires ongoing monitoring, a good understanding of the customer, behavioural analysis and investigators who can identify when a “normal” customer stops behaving normally. This is the view of Marco Beranzoni, a financial crime prevention professional and founder of FinCrime Agent educational platform. Beranzoni has nearly 20 years of experience in the field, having held positions at some of the world’s largest financial institutions, including HSBC, Standard Chartered and Bank of America Merrill Lynch. In an interview with Oninvest, the expert outlined 10 key facts about modern financial crime.
1. What Financial Crime Means Today
Financial crime today is much broader than traditional money laundering or terrorist financing. It includes sanctions evasion, fraud, bribery and corruption, tax evasion, market abuse, proliferation financing, cyber-enabled crime, human trafficking, trade-based money laundering, crypto-related illicit finance, and increasingly the misuse of digital identities and AI-enabled deception.
What has changed over the last decade is that these areas no longer sit neatly in separate boxes. The individual risks are not new, but they now overlap much more often across fraud, money laundering, sanctions, cybercrime, crypto, trade and professional intermediaries. A fraud case may also involve money laundering, a sanctions evasion case may involve trade finance, crypto, shell companies and professional enablers. A cybercrime case may lead to mule accounts, payment fraud and cross-border laundering.
"Money mule" is an established term used to describe a person who transfers money or other assets obtained through criminal activity at the behest of another person. The term is used, in particular, by the FATF and the U.S. FBI.
So, in practice, today financial crime prevention is no longer just about spotting suspicious transactions. It is about understanding how money, identity, technology, goods, companies and people are used together to move, hide or legitimise value.
2. Differences Between Financial Crime “On Paper” and in Real Life
The biggest is that financial crime looks very structured on paper, but very messy in real life. On paper, you have policies, procedures, risk assessments, escalation routes, transaction monitoring scenarios, sanctions screening rules, governance forums and audit trails.
In real life, analysts are dealing with incomplete data, poor customer information, fragmented systems, unclear ownership, competing priorities and cases where the answer is not obvious and pressure to clear alerts generated by financial crime monitoring and control systems. These may comprise transaction monitoring, sanctions screening, fraud monitoring, adverse media screening or customer due diligence review triggers.
They are not usually part of one single programme. Each institution uses different systems, rules and thresholds depending on its business model and risk appetite.
For instance, a bank’s policy may say "escalate where suspicion exists," which in practice usually means sending the case to a higher level of review because the risk cannot be safely closed by the first reviewer. This may involve a senior analyst, sanctions team, legal team or another internal decision-maker. Depending on the case, it may lead to further investigation, enhanced due diligence, account restrictions, sanctions-related action or exit of the relationship.
But the hard part is deciding whether suspicion exists when the evidence is incomplete. A system may generate an alert, but the investigator still has to understand the customer, the behaviour, the context and whether the explanation makes sense.
That is the gap I focus on a lot in my training: financial crime prevention is not just about knowing the rules, it’s about applying judgement under uncertainty and documenting that judgement clearly.
3. Why a Legitimate Customer Is Harder to Detect Than a (Potential) Criminal
Usually, the harder case is the customer who looks legitimate. If someone is already known to authorities or appears on sanctions, law enforcement or adverse media lists, the institution has something concrete to work with. The challenge may still be complex, but there is a known risk indicator.
The harder cases are the ones where the customer has a normal-looking profile, clean documentation, reasonable income, plausible business activity and no obvious negative media. Criminals know this. They use front companies, professional intermediaries, nominee directors, legitimate businesses, relatives, associates and clean counterparties to reduce suspicion. This is why financial crime prevention cannot rely only on list screening or static risk ratings.
It also needs behavioural analysis, ongoing monitoring, good customer understanding and investigators who can identify when a "normal" customer stops behaving normally.
4. What is the Most Underestimated Money Laundering Scheme Today
Trade-based money laundering remains one of the most underestimated areas. Most people understand money moving through bank accounts. Fewer people understand money moving through invoices, goods, shipping routes, customs declarations, pricing manipulation and complex corporate structures.
Trade-based money laundering is difficult because the transaction may look commercially legitimate on the surface. There is an invoice. There is a shipment. There is a company. There is a payment. But the value may be manipulated through over-invoicing, under-invoicing, phantom shipments, multiple invoicing, misdescription of goods, or the use of intermediaries in higher-risk jurisdictions.
It is underestimated because many financial institutions still monitor payments better than they understand the underlying trade activity. The bank may see the payment, but not always the commercial reality behind it. This is also why criminal networks like trade structures. They allow illicit value to move inside activity that looks like normal business.
Money laundering through trade transactions—trade-based money laundering (TBML)—as defined by the FATF, refers not merely to crimes in the sphere of foreign trade, but to the use of trade transactions to conceal criminal proceeds and transfer value. The FATF specifically notes that the purpose of TBML is precisely to transfer illicit proceeds through trade, and not necessarily to transfer the goods themselves.
5. How Money Laundering Works in the Luxury Goods Industry
A luxury item can act as a portable store of value. Instead of moving money through a bank transfer, someone can buy a high-value watch, handbag, jewellery item, artwork or collectible, then move that item across borders, gift it, resell it, use it as informal settlement, or convert it back into cash later. The item becomes a form of value transfer. It may be easier to explain than a suspicious wire, especially if the person has access to cash, intermediaries or luxury dealers with weak controls.
For example, criminal proceeds can be used to buy a watch. That watch can then be transported, sold in another country, or transferred to another person as payment. On paper, there may be no traditional bank transfer between the criminal and the beneficiary. But value has still moved.
The risk is not that every luxury purchase is suspicious. The risk is when high-value goods are used to disguise ownership, move value discreetly, or create a false appearance of legitimate wealth.
6. Why Banks and Other Financial Institutions Still Miss Obvious Money Laundering Schemes Despite Having Access to Vast Volumes of Data
Having data is not the same as understanding risk. Many institutions have enormous amounts of data, but it is often fragmented across systems: onboarding records, transaction monitoring alerts, sanctions screening, fraud systems, adverse media tools, case management platforms and customer relationship systems.
The problem is not always lack of information. Sometimes the information exists, but no one has connected it properly. There are also operational pressures. Alert volumes can be very high. Analysts may have limited time. Data quality may be poor. Customer profiles may be outdated. Different teams may own different parts of the risk.
Fraud, AML and sanctions teams may all see parts of the same customer story, but not the full picture. That is why some failures look obvious in hindsight.
Once a regulator, journalist or investigator reconstructs the full timeline, the red flags appear clear. But inside the institution, those red flags may have been spread across different teams, systems and moments in time.
The weakness is often not the absence of controls. It is the failure to turn a known red flag into timely action.
7. How Do Sanctions Really Work
Sanctions can be powerful, but they are not magic. They can freeze assets, restrict access to financial markets, increase reputational risk, disrupt networks and make it harder for sanctioned actors to operate openly. But sophisticated actors adapt. They use intermediaries, family members, front companies, professional enablers, alternative jurisdictions, trade structures, crypto, shipping networks and layered ownership.
So in many cases sanctions make access more expensive, slower and riskier rather than impossible. But that still matters. Increasing friction can disrupt operations, expose networks, raise costs and force sanctioned actors to rely on less efficient or more visible methods.
The objective is not always to create a perfect wall. Sometimes the objective is to increase pressure, reduce options and make evasion more detectable.
The real challenge for banks and compliance teams is that sanctions risk does not stop at the name on the list. The harder question is: who controls the company, who benefits from the transaction, and who is really behind the structure?
8. How AI Is Being Used for Committing Financial Crimes Today
Criminals are already using AI mainly to scale deception. That includes more convincing phishing messages, fake documents, synthetic identities, deepfake audio or video, automated scam scripts, multilingual social engineering and more realistic impersonation.
The next stage is not just criminals using AI to write better scam emails, but it is criminals using automation to test controls, generate identities, adapt narratives, move funds faster and identify weaknesses in onboarding or monitoring processes.
Will we reach a point where one AI system helps launder money while another AI system tries to detect it? In some ways, yes.
Financial crime prevention is moving toward machine-versus-machine behaviour: automated fraud, automated onboarding abuse, automated transaction patterns and automated detection.
But I would be careful with the idea that AI will fully "launder money" by itself. Criminal intent still comes from people. AI may accelerate the process, reduce the skill barrier and make attacks more scalable, but humans are still designing the objective and benefiting from the outcome.
9. Who Is Responsible for AI Errors in Detecting Financial Crime
Responsibility should not disappear just because AI is involved. The financial institution deploying the AI must remain accountable for how it is used. A bank cannot say, "the system made the decision" and treat that as a defence. If the AI is part of the control framework, then governance, validation, oversight, documentation and escalation must be part of that framework too.
The human investigator also has responsibility, but only within a realistic boundary. If the system is poorly designed, badly governed or impossible to challenge, it is unfair to place all responsibility on the analyst using it.
The technology developer may also have responsibility, especially if the tool was misrepresented, poorly tested, unsafe, or not fit for its stated purpose. This is why AI governance matters so much.
The key questions are: who owns the model, who validated it, what data was it trained or tested on, what does good performance mean, what happens when it gets something wrong, and can a human meaningfully challenge the output?
In financial crime prevention, that principle is essential. AI should support investigators, not replace accountability.
10. What Makes a Strong Financial Crime Investigator
A strong investigator can build a story from imperfect information. Knowing the rules is important, but it is not enough. A good investigator knows how to ask: does this activity make sense for this customer? Is the behaviour consistent with the profile? What changed? What is missing? What would I expect to see if the activity was legitimate? What would I expect to see if it was suspicious?
The best investigators are curious, structured and sceptical without becoming cynical. They do not just clear alerts. They test explanations. They connect information across customer records, transactions, counterparties, geography, adverse media and previous behaviour.
They also write well. That is often underestimated. A strong investigation that is badly documented can become weak evidence. A good investigator can explain the risk, the rationale and the decision in a way that another person, such as a manager, auditor or regulator, can understand later.




