Knowledge Hub Scenario Lab About Try the tool →
This guide uses an experimental "Evidence Essay" layout, a second one-off format test. Read why.
Evidence Essay · Fraud & AML

Classification asymmetry: the fraud vs AML divide

A fraudster steals from one bank. The money lands at another as an unremarkable deposit. Each institution sees a different crime, and fraud-style behavioural scoring can miss the laundering side entirely while producing false positives on genuine fraud victims.

Executive briefing

Where the two crimes stop looking like each other

Some platforms are marketed as detection systems that catch fraud and money laundering together, on the theory that both are "transactional risk" and both can be flagged by a change in behaviour. A granted US patent on alert-system design, cited here for its analysis of the detection problem, not as a legal or regulatory authority, states the problem with that theory plainly: fraud can be detected because a fraudster who has stolen a victim's identity or financial instrument behaves differently from the victim, but this same behavioural-deviation logic "cannot detect many basic money laundering activities," which are built to look like ordinary, cooperative account activity, not a deviation from it [1].

The clearest version of the failure: a fraudster steals funds from Institution A. Those funds move to Institution B, where they arrive looking like an ordinary deposit, no fraud occurred at B, nothing about the transaction looks unusual from B's side. Institution A sees a fraud case. Institution B, if it sees anything at all, sees a potential money laundering case, an incoming deposit with no clear source. Neither institution sees the whole picture, because neither has any default, built-in way to connect its side of the transaction to the other's.

This guide works through why that gap exists structurally, not just as a data-sharing problem, what UK law actually requires of the institution receiving the deposit, and what an analyst on either side of it can actually do about it.

Chapter 1

Two different mechanisms, not two flavours of the same risk

Fraud and money laundering get bundled together in a lot of vendor pitches as "transactional financial crime," a single risk that a single sufficiently clever model can be trained to catch. The mechanism each one is actually detected by does not support that framing. A granted US patent on alert-system design, filed individually by inventors Yuh-Shen Song, Catherine Lew, Alexander Song and Victoria Song rather than a major institutional vendor, states the distinction in its own background section: fraud is detectable through behavioural deviation, because "a fraudster that has stolen a victim's identity (or financial instrument) behaves differently from the victim" [1]. The account starts spending in a new city, at a new time of day, on categories it never touched before. That deviation from the account's own baseline is the signal a fraud model is built to catch.

Money laundering does not reliably produce that same signal, and the patent is explicit about why: it states that fraud-oriented "real-time risk scoring, real-time detection, daily risk scoring, and daily detection methods... cannot detect many basic money laundering activities" [1]. The patent's own detailed description explains why: money launderers "usually pretend to be good customers because they need the financial institutions' assistance to accomplish their schemes," and are willing to pay extra fees or forgo interest to keep that relationship, which is exactly why an account can be laundering funds while looking like a bank's most cooperative customer [1]. The patent's own answer is that laundering has to be caught a different way, through known transactional patterns, structuring, layering, a recurring shape across multiple transactions or multiple periods, rather than a single transaction looking wrong in isolation: "even if there is no change of behavior, a money laundering activity can be detected based on the transactional pattern" [1].

One granted patent argues that fraud-style behavioural scoring can produce money laundering false positives while missing laundering that does not deviate from normal behaviour. Put the two mechanisms next to each other and the problem with a single shared-signal system becomes concrete. A system tuned to flag behavioural deviation will miss laundering that never deviates from a normal-looking pattern. The same system will also generate false laundering positives on genuine fraud victims, whose accounts are, correctly, behaving abnormally, because they have just been defrauded, not because they are laundering anything. Sharing a data pipeline between fraud and AML detection is not the problem the patent describes. Collapsing two different detection logics into one shared signal is.

Chapter 2

The asymmetry, worked through

Chapter 1 explains why fraud and money laundering need different detection logic. This chapter works through what happens when the same transaction crosses an institutional boundary, the structural pattern the patent's own background section uses to illustrate why a combined system misses cases neither institution alone was ever positioned to catch.

US Patent 12,086,874, background section
“A fraudster may use financial institution A to launder the money, which the fraudster has stolen from financial institution B. To financial institution B, this is a fraud case. To financial institution A, this is a money laundering case. Neither of financial institution A nor financial institution B, however, sees both the fraud case and the money laundering case occurring to this same customer.”
Yuh-Shen Song, Catherine Lew, Alexander Song, Victoria Song, "Intelligent Alert System" [1]

This is the guide's spine insight, and it is worth being precise about where it comes from. It is a granted patent's own background section, describing a mechanism the inventors observed well enough to design a detection system around, not a marketing claim, and not evidence of any specific real case. The patent is cited here for that mechanism and that insight alone, it is not a regulatory or legal authority, and nothing in this guide treats it as one.

Where the picture actually splits
Institution A
The fraud victim's own bank. Opens a fraud case: a customer's funds stolen and moved out.
No shared visibility
Neither institution can see across this gap. The funds move on with no institutional record trailing them.
Institution B
The receiving bank. Sees, at most, an unremarkable deposit or a potential money-laundering case, no fraud occurred on B's own side.
Both institutions carry their own independent obligation. Neither's is contingent on knowing what happened at the other.

Institution A's fraud team, if the victim reported quickly, may open a case within hours. Institution B's own systems see none of that: a deposit that matches the receiving account's stated activity, nothing in the transaction itself deviates from that account's own recent pattern. Both institutions are behaving exactly as their own detection logic tells them to. Neither is behaving incorrectly on its own terms. The asymmetry is not a failure of either institution's system, it is a structural consequence of each system only ever seeing one side of a transaction that, in reality, has two.

This structural gap describes the default position, not an absolute one. Sections 339ZB to 339ZD of POCA 2002, inserted by the Criminal Finances Act 2017, create a voluntary gateway letting a person in the regulated sector share information with another regulated-sector person about a suspicion of money laundering, and, where that sharing happens within the statutory timeframe, submit a joint disclosure report to the NCA, sometimes called a "Super SAR," which can itself satisfy the section 330 reporting requirement in place of an individual SAR. The gateway is genuinely voluntary on both sides: it requires an affirmative request and disclosure, either institution can decline, and nothing about it happens automatically once a suspicious transaction occurs. It does not change this guide's core point or Verdict D's reasoning below: absent that voluntary step actually being taken, neither institution has any default, unprompted visibility into the other's side of the transaction, and Institution B's own section 330 duty stands on its own terms whether or not the gateway is ever used [5].

Chapter 3

The obligation does not wait for the other side of the story

Chapter 2 explains why the asymmetry exists. This chapter explains why it is not a legal excuse.

Under section 330 of the Proceeds of Crime Act 2002, a person commits an offence if they know, suspect, or have reasonable grounds for knowing or suspecting that another person is engaged in money laundering, and fail to disclose that knowledge or suspicion as soon as practicable, either to their firm's nominated officer or directly to the National Crime Agency, provided that knowledge or suspicion came to them in the course of a business in the regulated sector. The offence attaches to the individual person who held that knowledge or suspicion, not to a firm as an abstract entity. For readability, the rest of this chapter uses "Institution B" as shorthand for the person or people at Institution B who would actually hold that knowledge or suspicion in the course of their regulated-sector work, not as a claim that the obligation itself runs to the institution in the abstract. Legislation.gov.uk's own explanatory notes describe subsection (2)(b) as introducing a negligence-style test: the offence is committed where a person "has reasonable grounds for knowing or suspecting that another person is engaged in money laundering, even if they did not actually know or suspect" [2]. The trigger is deliberately self-contained, what that individual person themselves knows or has reasonable grounds to suspect, based on information that came to them in the course of their own regulated-sector business, not what a different institution has separately reported, flagged, or discovered.

Institution B's obligation to consider filing a Suspicious Activity Report exists in full the moment B has reasonable grounds for suspicion about a deposit, whether or not Institution A's fraud case is visible to B, has been reported anywhere, or even exists as far as B's own systems can tell. Independent legal commentary on section 330 reaches the same reading of the trigger: the obligation turns on information that actually came to the regulated person in the course of their own business, an internally self-contained standard, not one that depends on coordination or knowledge-sharing between institutions [3].

This closes off the most tempting excuse the asymmetry creates: "we had no way of knowing this was connected to a fraud elsewhere." Section 330 does not ask whether an institution could see the whole picture. It asks whether that institution, on its own information, had reasonable grounds to suspect. A deposit that looks unremarkable in isolation, and would look very different with visibility into Institution A's fraud report, is exactly the scenario section 330's own wording was built to cover, reasonable grounds does not require certainty, and it does not require the full picture.

SARs in the UK go to the NCA's UKFIU under POCA Part 7 (and the Terrorism Act 2000 for terrorist financing). Section 339A POCA sets a threshold amount that exempts two specific circumstances from needing a Defence Against Money Laundering before proceeding, not a general low-value-transaction allowance: a deposit-taking body, electronic money institution, or payment institution operating an account below the threshold, and a regulated-sector firm paying away property when terminating a business relationship with a customer. Both thresholds currently stand at £3,000, raised from £1,000 on 31 July 2025, which itself had been raised from £250 on 5 January 2023, two separate increases, not one [4]. Neither exemption changes or lowers the underlying section 330 obligation to consider disclosure, and neither applies outside these two specific circumstances, most of the transactions an analyst reviews are not covered by either one at all.

Composite case

The deposit that looked like nothing

This is a composite case, not a real, publicly documented incident. No real case demonstrating this exact asymmetry, with a citable regulatory or enforcement source naming both sides of the same transaction, was identified after a genuine search for one. It is built around the real mechanism in Chapters 1 and 2 and the real obligation in Chapter 3, using a plausible, unnamed scenario rather than inventing a specific real-sounding company or incident.

Composite, built to illustrate the mechanism above

A phishing email convinces a customer at Institution A to authorise a payment to what they believe is their own new savings account. The funds move through two intermediate accounts before landing at Institution B as a deposit into a business account, styled as an invoice payment for consulting services. Institution A's fraud team opens a case within hours, the customer reported the loss almost immediately. Institution B's systems see none of this: a business account receiving a client payment that matches its stated line of work, nothing about the transaction deviates from the account's own recent pattern. The deposit clears normally. Three weeks later, Institution A's investigation traces the funds to the intermediate accounts and, eventually, to Institution B, by which point the money has moved on again.

Composite scenario. No specific real customer, company, or institution is depicted. The illustrative figures used in the worked scenario below are original teaching detail, not tied to any real case, and are correctly left uncited, consistent with this project's own standard for illustrative versus material claims.
Worked scenario

The Business Account

The mechanism and the obligation above show up as a concrete decision, not abstract policy. This is the judgement call Institution B's own analyst actually faces.

Situation

You are a transaction monitoring analyst at Institution B. A business account you monitor receives a £14,000 payment described as "consulting invoice #2291." The account's stated business is marketing consulting, and the amount is broadly consistent with invoices it has received before, though slightly larger than its recent average. Nothing in Institution B's own systems flags fraud, sanctions, or PEP exposure. You have no visibility into any other institution's records.

Material facts. Section 330 POCA does not require certainty or visibility into the sender's own institution, only reasonable grounds for knowing or suspecting money laundering, based on what is actually available to you. The account has received four similarly sized "consulting" payments in the past two months from four different, unconnected-looking payers.

Knowledge check

Test your understanding

1. According to the patent's own framing, what actually happens when a detection system uses fraud-style behavioural scoring to try to catch money laundering too?
2. Why did neither Institution A nor Institution B in the patent's own example see the whole picture?
3. In the composite case's worked scenario, what is the strongest basis for Institution B's suspicion, rather than any single transaction?
4. Under section 330 of POCA 2002, what actually triggers the failure-to-disclose offence?
5. In the worked scenario, why is option D, deciding reasonable grounds cannot exist because Institution B has no visibility into any fraud elsewhere, unsafe?
0/5
FAQ

Common questions

Is there a real, named case showing this exact fraud-to-laundering asymmetry?
No, and this guide does not claim otherwise. A genuine search for a real, publicly documented case, with a citable regulatory or enforcement source demonstrating this exact pattern, funds stolen at one institution landing at another with neither connecting the two, did not turn one up. The Composite case section is clearly labelled as composite for that reason, built around the real mechanism the patent describes and the real obligation in Chapter 3, not around a specific real incident.
Does this mean combined fraud and AML detection tooling is always the wrong choice?
No, and this guide does not argue that. The patent's own point, and Chapter 1's, is about detection logic, not infrastructure. A shared data pipeline is not the problem. Collapsing fraud's behavioural-deviation signal and money laundering's pattern-based signal into one shared signal, so a single model output is expected to catch both, is what produces the blind spot. Two distinct detection logics can run on shared infrastructure without that collapse.
Does the higher DAML threshold mean smaller deposits like the one in this scenario don't need a SAR?
No, and the two are easy to conflate, and easy to overstate too. Section 339A's £3,000 threshold is not a general low-value-transaction allowance, it exempts only two specific circumstances from needing a Defence Against Money Laundering first: a firm operating an account below the threshold, and a firm paying away property when terminating a business relationship. A business account receiving a routine payment is not automatically covered by either exemption, and even where it is, the exemption only concerns whether consent is needed before proceeding, not whether the underlying section 330 obligation to consider disclosure applies at all. That trigger is not value-gated, a £14,000 payment sits well above the threshold regardless of which exemption might apply.
If Institution A never reports its fraud case anywhere, does that reduce Institution B's own obligation under section 330?
No. This is the exact excuse Chapter 3 closes off. Section 330's obligation is self-contained to what Institution B itself knows or has reasonable grounds to suspect, based on information that came to it in its own business. Whether Institution A ever files a report, and whether that report is ever visible to B, does not change what B's own information already supports.
The three patterns

Risk, signal, response

Three recurring failure patterns behind the mechanism and the obligation above, each with the risk it creates, the signal that should catch it, and the response that closes it.

🔁
The Split Picture
Institution A sees fraud. Institution B sees an ordinary deposit. Neither sees both.
Risk
A detection system tuned for behavioural deviation misses laundering that never deviates.
Signal
A deposit that looks unremarkable in isolation but sits inside a pattern across several senders or several periods.
Response
Build suspicion from pattern, not from a single transaction looking wrong alone.
🚫
The Borrowed Excuse
"We had no way of knowing" is not a legal defence under section 330.
Risk
Treating lack of cross-institution visibility as equivalent to lack of reasonable grounds.
Signal
A suspicion decision deferred indefinitely pending information that will never arrive from another institution.
Response
Assess reasonable grounds on your own institution's own information, that is what the statute actually asks for.
⚙️
The Combined System's Blind Spot
Fraud-style behavioural scoring can miss laundering entirely while producing false positives on genuine fraud victims.
Risk
Fraud's behavioural-deviation signal and money laundering's pattern-based signal are different mechanisms, not the same risk wearing two labels.
Signal
High false-positive rates on genuine fraud victims, alongside missed laundering that never deviates from a normal-looking pattern.
Response
Keep the two detection logics distinct even where the underlying data pipeline is shared.
Quick reference

At a glance

Three patterns, the risk that makes each one look routine, the signal that actually gives it away, and the response that fits.

Quick reference

Summary snapshot

The full guide in one image, for quick reference or sharing.

Classification Asymmetry summary infographic showing the Institution A / Institution B split from US Patent 12,086,874, why fraud detection relies on behavioural deviation while money laundering detection relies on transactional pattern, the section 330 POCA reasonable-grounds obligation, and the three Risk, Signal, Response patterns: The Split Picture, The Borrowed Excuse, and The Combined System's Blind Spot.
⬇️ Download summary
Verification

Sources

Each numbered claim above is checked against the specific source below it. The patent's full text was retrieved and read directly, not taken from a secondary description of it.

  1. Inventors Yuh-Shen Song, Catherine Lew, Alexander Song, Victoria Song, US Patent 12,086,874 B2, "Intelligent Alert System," filed individually rather than by an institutional vendor, priority date 13 February 2019, granted by the USPTO 10 September 2024, current assignee Apex Techlink, Inc. Cited for its mechanism and insight only, not as a legal or regulatory authority. patents.google.com
  2. Proceeds of Crime Act 2002, Section 330 (Failure to disclose: regulated sector) and its Explanatory Notes, on the reasonable-grounds negligence-style trigger. legislation.gov.uk
  3. Kingsley Napley, "Will the CPS' decision to update its guidance mean an increase in prosecutions for failure to disclose under section 330 of POCA 2002?", corroborating legal commentary on the self-contained knowledge trigger. kingsleynapley.co.uk
  4. The Proceeds of Crime (Money Laundering) (Threshold Amount) (Amendment) Order 2025 (SI 2025/877), raising the DAML threshold under section 339A from £1,000 to £3,000, effective 31 July 2025. legislation.gov.uk
  5. Criminal Finances Act 2017, Explanatory Notes, division 6 (paras. 101 to 104), on sections 339ZB to 339ZD of POCA 2002, the voluntary regulated-sector information-sharing gateway and joint disclosure report mechanism. legislation.gov.uk
Methodology and limitations

How this guide was built and checked

The patent's individual-filer status, and its current assignee. US Patent 12,086,874 is a real, granted US patent, and its background section states this guide's spine insight almost exactly. It is worth being precise about what it is not: the inventors filed individually, Yuh-Shen Song, Catherine Lew, Alexander Song and Victoria Song, not on behalf of a major institutional vendor such as FICO or NICE. Google Patents' own record lists the patent's current assignee as Apex Techlink, Inc., a small entity the same inventor family has assigned several related patents to, not a major institutional vendor either. That does not weaken the underlying mechanism the patent describes, which was independently checked against the patent's own full text, but the guide does not imply the patent carries the institutional weight a major vendor's own published research would, and the Sources entry below separates inventors, issuing authority, and current assignee rather than conflating them.

A quote wrongly reported as unverifiable, now restored, and why. An earlier pass through this guide's own build process concluded the phrase "usually pretend to be good customers" could not be confirmed in the patent's text, and dropped it rather than present an unverified quotation. That conclusion was itself wrong, caught by external review. The phrase is genuinely in the patent's Detailed Description section, quoted directly in Chapter 1. The retrieval tool used for the original check had been silently truncating this patent's long full text rather than returning it in full, and a second attempt against that same retrieval path repeated the identical false negative before a full-text mirror was tried instead and located it immediately. That is two strikes against the same source, not one, and nothing about the tool changed between attempts, only the source did: treat this as a known failure mode for sourcing any further claim from this specific patent's full text, not something a second try against Google Patents alone will reliably catch. This note stays in place rather than being deleted now that the quote is restored, on the same basis the rest of this section runs on: a mistake is only genuinely corrected if the record says so, not if the earlier wrong claim just quietly disappears.

The corrected inventor list. An earlier description of this content named only two inventors, Yuh-Shen Song and Catherine Lew. The patent's own record lists four: Song, Lew, Alexander Song, and Victoria Song. Corrected here after direct verification against the patent itself.

The corrected DAML threshold. An earlier description of this content stated the current DAML threshold as £1,000, raised from £250 on 5 January 2023. That was the position as of that increase, but a second increase has since taken effect: the threshold rose again, from £1,000 to £3,000, on 31 July 2025, under a separate statutory instrument. This guide states the current, £3,000 figure and discloses both increases, rather than repeating a since-superseded figure.

Corroborating commentary substitution. Two independent legal commentary sources were originally identified to corroborate the section 330 reading: Kingsley Napley and Croner Navigate. Croner Navigate's relevant page sits behind a subscription wall that could not be independently verified during this build, so it is not cited. Kingsley Napley's own published commentary, publicly accessible, is cited in its place and independently supports the same reading of the self-contained trigger.

Illustrative detail. The specific figures in the worked scenario, the £14,000 payment and the pattern of four similarly sized payments, are original composite teaching detail built around the real mechanism and obligation described above. They are not tied to a specific real customer or case and are correctly uncited, consistent with this project's standard that illustrative worked examples do not carry a citation the way a regulatory or enforcement claim does.

Format. This guide uses the same experimental "Evidence Essay" layout, with a source-record panel, first built for the Gambling's White-Label Blind Spot guide, distinct from both the standard Knowledge Hub card format and the PEP and SAR series' narrative format. This is the format's second use, still under evaluation, not yet a standing decision. See the note on format for why the site's guides do not all look the same.

Practice the underlying judgement

The reasonable-grounds question in the worked scenario above is one version of a pattern that comes up across financial crime investigation generally, not just this specific asymmetry. FinCrimeRadar's Scenario Lab puts related judgement calls in front of you under time pressure, free, no signup required.

Try Scenario Lab →

The exported summary image contains: guide title, FinCrimeRadar.org, verification date 14 August 2026, source markers 1 to 4, a statement that the image is a summary and not complete regulatory guidance, and the three Risk, Signal, Response cards already present as readable text earlier on this page.