Skip to main content
Knowledge HubScenario LabAboutTry the tool
Knowledge HubFraudInvestment Scam Investigation Handbook
Guide

Investment Scam Investigation Handbook:
Reconstructing the offer, identity and money route

Investment scams borrow credibility. The investigation fails when one real element is allowed to prove that everything around it was real too.

Written by Pratik Zanke

UKEvidence reviewed 3 October 202640 min read2 worked scenarios, 3 decisions
Jurisdiction
United Kingdom
Audience
Fraud, payments, AML, complaints and financial-crime practitioners
Evidence reviewed
3 October 2026
Change sensitivity
High. Payment and crypto rules are route-specific and change-sensitive

The question, and what this handbook will not decide

A customer reports a loss on an investment. The file contains a real firm name, a working bank transfer, a registered exchange and a dashboard full of profit. Which of those facts tell you the investment was genuine?

This handbook answers one question. When an investment journey contains both genuine and false elements, what does the available evidence establish about the proposition, the promoter and the money route, and what should the investigator do next? It teaches the method on UK facts and is written for practitioners who work scam, payment, complaint and financial-crime files. It is a practitioner method, not legal advice.

It deliberately stops short of three decisions that belong elsewhere: whether a customer is reimbursed, whether a recipient account holder knew what was happening, and whether a suspicion report is made. It builds the evidence record those decisions rely on, and it keeps them apart.

Do not let one genuine fact answer a larger question than it can support.

Intelligence questionWhen an investment journey contains both genuine and false elements, what does the evidence establish about the proposition, promoter and money route, and what should the investigator do next?
Evidence stateRegulator and ombudsman statements are relied on only as far as the source list records them. The four-stream method and the Legitimate Node Trap are FinCrimeRadar assessments. The scenario facts are synthetic.
Decision objectClassify the evidential state, identify the next evidence that matters, start proportionate containment or recovery, and route reimbursement, complaint, recipient-account and financial-crime decisions to the right process.
UncertaintyA Warning List absence, a working platform, a genuine firm identity, an authorised payment or a registered exchange does not establish whether the whole journey is genuine. The destination and control of value may remain unknown.
What would change the assessmentIndependent confirmation of the promoter and its permissions, proof the product exists and is held for the customer, control of the destination wallet, a verified withdrawal, or new linked-victim or receiving-account evidence.
Practitioner outcomeAfter this handbook you should be able to separate what is genuine from what that genuine fact does not prove, build an evidence map a reviewer can follow, and make a defensible next-step decision without collapsing classification into reimbursement.

How evidence is labelled

  • Established What a named regulator or ombudsman page says, as read on the evidence date.
  • FinCrimeRadar assessment Our analysis of how the sources apply to the facts, and our recommended action.
  • Unknown A fact the evidence does not settle.

Out of scope: any live lookup of a firm, domain, wallet or victim, recipient-account intent, and the reimbursement rules themselves. The APP Scam Decision Framework covers reimbursement and complaint defensibility. This handbook links to it and does not repeat it.

The Legitimate Node Trap

A register entry can be genuine. The person using it may not be.

A crypto exchange can be registered. The external wallet may still be controlled by a fraudster. A bank transfer can reach a real company account, and that company may be a mule, a payment intermediary, a shell or an unrelated business whose details were misused. A dashboard can show prices and profits that are nothing more than controlled screen content.

The mistake is not believing a genuine fact. It is allowing that fact to answer a larger question than it can support. We call this the Legitimate Node Trap. It is a FinCrimeRadar assessment of how investment scam files go wrong, not a term any regulator uses.

For every reassuring fact, write two sentences: what this establishes, and what this does not establish.

Take an FCA record. It may establish that a named firm was authorised, and for which permissions, at a given time. It does not establish that the caller, the domain, the messaging account, the beneficiary or the wallet belonged to that firm. The FCA describes a clone firm as a copy of a genuine, authorised firm, and tells consumers to make sure the contact details they were given match those on the Firm Checker [1]. The investigator should apply the same discipline: compare what the promoter supplied with details retrieved independently.

The discipline works in reverse as well. A firm that does not appear on the Warning List has not been cleared. The FCA says that if a firm is not on the list it may still be unauthorised or be a scam, and that unauthorised firms often change their names before the FCA is aware of it [2].

Build four evidence streams

Reconstruct the proposition, the identity, the journey and the money route separately. Each answers a different question, and none can stand in for another.

The four streams are our own investigative structure. They organise the evidence. They are not a legal test.

1 The proposition

Start with what the customer believed they were buying, not the label later given to the case. Record the product, issuer, expected return, term, custody arrangement, withdrawal conditions, fees and any protection that was claimed. Preserve the original advertisement, landing page, proposal, contract and dashboard.

A promise of returns is not the product. A visible balance is not proof that the asset exists or is held for the customer. Ask what evidence would exist if the proposition were genuine: a verifiable issuer, independently confirmed product documentation, a custody record, a contract with coherent counterparties, or an asset visible through a channel the promoter does not control.

The Screen Balance

A number on a screen is treated as money held for the customer.

Risk
A functioning dashboard is treated as custody evidence.
Signal
The only proof of value is a promoter-controlled screen.
Response
Seek independent asset, custody, transaction or withdrawal evidence.

2 The identity

Four questions are often collapsed into one. Keep them apart.

  • Does the named legal entity exist?
  • Is it authorised, registered or exempt for the relevant activity?
  • Does it hold the permission for this product or service?
  • Is the person, domain, phone number, account or wallet in this case actually attributable to it?

Authorisation, registration and permission are not synonyms. The FCA says that being authorised means a firm must meet certain standards and has permission to provide certain products and services, while being registered means it cannot provide regulated products that need authorisation, and that an authorised firm can offer both regulated and unregulated products [1]. A genuine firm identity therefore does not validate every product carrying its name, and clone firms depend on that shortcut.

Compare the email domain, telephone number, website and payment instructions with details retrieved independently from the Firm Checker or Financial Services Register. The FCA notes that a firm's contact details are provided and confirmed by the firm, so a match narrows the question without settling who actually controls the channel [1]. Where an appointed representative is claimed, the FCA says to check with the principal, so confirm the relationship and the permitted activity through contact details you sourced yourself [1].

The Borrowed Badge

A genuine register entry is made to vouch for the whole journey.

Risk
A genuine register entry clears the whole journey.
Signal
The file records the firm reference number but not independently verified contact details or permissions.
Response
Attribute every channel, product and payment instruction separately.

3 The journey

Reconstruct the persuasion sequence before judging any single message. How did contact begin, and what created trust? Was there a small early withdrawal, an apparent adviser, a celebrity image, a private messaging group, a remote-access session or a time-limited opportunity? When did the customer first try to withdraw, and what new reason was then given for another payment?

Sequence matters because the FCA describes professional-looking sites where fraudsters may manipulate software to fake prices and investment returns, and says a customer may not realise it is a scam until they try to sell the investment [4]. A small early return may be part of the inducement. It is not, on its own, evidence of genuine performance.

Keep customer conduct separate from promoter conduct. A customer's confidence, prior investment experience or decision to continue after a warning does not show that the proposition was genuine. Those facts may matter to a prevention, reimbursement or complaint assessment, and that assessment belongs in the APP Scam Decision Framework, not in this file.

4 The money route

Map each transfer as a change of control, not just a line on a statement. For fiat, capture the sending account, beneficiary, account name, institution, reference, date, value and any recall or freeze response. For crypto, capture the exchange account, asset, network, transaction hash, sending and destination addresses, timestamps, and whether the customer or another party controlled the private keys.

Do not stop at a legitimate intermediary. A customer may pay their own account at a genuine exchange before value leaves for an external wallet. The exchange is real. The investment destination can still be fraudulent. Equally, payment to a third party is not proof that the recipient knowingly took part. Recipient intent is a separate assessment and this handbook does not make it.

The route also affects which reimbursement rules may apply, and the Ombudsman says it may still examine what a firm did outside those rules. The sources section below sets out what each source does and does not say. Classification and reimbursement stay separate decisions.

The evidence table: what each fact does and does not prove

Each row is a piece of evidence that commonly gets read as more than it is. Use the table to write the two sentences for each fact: what it establishes, and what it cannot establish alone.

Evidence, what it may establish, what it cannot establish alone, and the next check
EvidenceWhat it may establishWhat it cannot establish aloneNext check
FCA firm matchThe named firm exists and has a recorded status or permissions.That the contact is genuine, that the product exists, or that the promoter controls the firm.Compare independently retrieved contact details, permissions and historical status.
Warning List hitThe FCA has published a concern about the firm or identity.A criminal conviction, or the complete fraud mechanism.Preserve the warning record and test the case identifiers against it.
No Warning List hitNo matching published warning was found at the time of the check.Legitimacy or authorisation.Firm Checker, permissions, identity attribution and overseas regulator warnings.
Companies House recordA company was incorporated, and named officers or filings exist.FCA authorisation, trading legitimacy, or control of the contact channel.FCA status, permissions, independent contact details and payment-account ownership.
Small withdrawalValue was returned once.Genuine profits, or a sustainable investment.The source of the returned funds, later withdrawal conditions and asset custody.
Genuine exchangeA real service converted or held value.That the external wallet is legitimate, or that the exchange was used for a genuine investment.Wallet control, destination, transaction hash and the customer journey.
Platform balanceA website displayed a number.That the asset exists, is held in custody, or can be withdrawn.Independent custody or on-chain evidence, and a controlled withdrawal test where it is safe to run one.
Beneficiary name matchPayment details matched a name.The recipient's intent, or the promoter's identity.Account history, linked victims, onboarding records and onward movement, through authorised channels.

The Companies House row is a FinCrimeRadar investigative recommendation. Incorporation records are not worthless. They answer a narrower question than authorisation or legitimacy. The FCA statements behind the firm match and Warning List rows are set out in the sources section [1] [2].

Make three decisions, not one

The question is not simply scam or not scam. Classification, containment and recovery, and routing are three decisions with different clocks and different owners.

1. Classification

Which explanation best fits the evidence? These are FinCrimeRadar analytical labels. They are not legal categories.

  • Probable investment scam. Material deception is supported across more than one evidence stream.
  • Unresolved but high risk. Material gaps remain, but the evidence justifies containment or escalation while targeted checks continue.
  • Genuine investment loss or dispute. The promoter, product, custody and journey are evidenced, but value fell or performance disappointed.
  • Insufficient evidence. Neither fraud nor legitimacy is established. Record the gaps and the next check instead of turning uncertainty into clearance.

2. Containment and recovery

What can still be stopped, recalled, frozen or preserved? Run this work alongside classification wherever delay can reduce options. Notify the relevant payment institution or provider promptly, preserve communications and transaction identifiers, and identify the recipient or wallet path. The FCA tells a person who has made a payment or given personal information to tell their bank immediately [3].

Do not promise recovery. Do not point a customer to a recovery service because it claims specialist access: the FCA warns that people who have been targeted are at greater risk of being targeted again, potentially by recovery room scammers who pose as legitimate firms offering to recover lost funds [3].

The Waiting Room

Recovery waits in a queue behind a perfect classification.

Risk
Recovery waits for perfect classification.
Signal
No recall, provider contact or evidence preservation begins while the file seeks certainty.
Response
Run time-sensitive containment and preservation in parallel with targeted investigation.

3. Escalation and routing

Which process owns the next decision?

  • The scam classification file records the evidence and the competing explanation.
  • Reimbursement and complaint analysis applies the rule set for the exact payment route and date.
  • Receiving-account or wallet evidence goes through authorised internal or external channels, without declaring a recipient intent that the evidence does not establish.
  • Money-laundering suspicion follows the firm's existing internal reporting and MLRO process.
  • The FCA invites reports of suspected scams, and UK victims are directed to Report Fraud first [3].

What the sources say, and what they do not

Six teaching points carry regulatory weight. For each, the Source block says what the named authority states, the Application block is our reading of what that means for a file, and the Action block is our recommendation. Only the first is the authority's own position.

Authorisation, registration, permission and contact details

Source Established

The FCA says that being authorised means a firm must meet certain standards and has permission to provide certain products and services, while being registered means it cannot provide regulated products and services that need authorisation. It says the Firm Checker shows whether a firm is authorised and has permission for the product or service, and that firms it authorises can offer both regulated and unregulated products. It describes a clone firm as a copy of a genuine, authorised firm, advises that contact details given for the firm should match those on the Firm Checker, and notes that firm contact details are provided and confirmed by the firm. It adds that using an authorised firm with the correct permissions will greatly reduce the risk of harm but will not remove all risk. [1]

Application FinCrimeRadar assessment

A register match answers whether a named firm exists and what it is recorded as permitted to do. It does not answer whether this domain, number, account or product belongs to it. Authorisation does not extend to every product that carries the firm's name, and a registered status is not authorisation.

Action FinCrimeRadar assessment

Record the firm's status and permissions as at the case dates, and test each channel and payment instruction against details you retrieved yourself. Treat a mismatch as a finding in its own right. Where an appointed representative is claimed, confirm the relationship and the permitted activity with the principal.

The Warning List is not a clearance list

Source Established

The FCA says its Warning List shows firms it is concerned are working without its permission, that it adds firms as soon as possible, that a firm not on the list may still be unauthorised or be a scam, and that unauthorised firms often change their names before the FCA is aware of it. It advises checking warnings from overseas regulators for an overseas firm. [2]

Application FinCrimeRadar assessment

A hit is strong official evidence of concern. It is not a conviction and it does not describe the whole fraud mechanism. A non-hit records only that no matching warning was found at the time of the check.

Action FinCrimeRadar assessment

Preserve any warning record with the date checked. Never record a non-hit as legitimacy or authorisation. Do not hold a file open waiting for a warning to appear.

Crypto promotions and registered exchanges

Source Established

The FCA says its financial promotions regime applies to all firms marketing cryptoassets to UK consumers regardless of whether the firm is based overseas or what technology is used, and that the definition of a financial promotion is broad and covers a firm's website, mobile apps, social media posts and online advertising. [5]

Application FinCrimeRadar assessment

A website, an app or a registered exchange relationship does not by itself tell you whether a particular promotion was lawfully communicated. The FCA page we read describes the regime as it stood when it began in October 2023, including a route that then depended on legislation still before Parliament. We therefore do not list communication routes or consequences here. Check them against the current rules before relying on any.

Action FinCrimeRadar assessment

Record where and how the customer first met the promotion: platform, account name, date and a capture of the advertisement. Treat the lawfulness of the route as a question for current rules and, where it matters to the file, legal advice. Do not describe registration as equivalent to authorisation.

Reimbursement scope and what sits outside it

Source Established

The Financial Ombudsman Service says the Faster Payments and CHAPS reimbursement rules came into force on 7 October 2024 and that they do not cover payments in cryptocurrency or payments to an account under the consumer's control, among other exclusions. It says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more to prevent the scam, including for payments to the customer's own account, payments to cryptocurrency providers, card payments to a genuine merchant, payments to an overseas payee and cash withdrawals. It will consider whether the payments should have alerted the firm, what warning was given and what was done to recover the money, and for a receiving firm, what it did once told of the scam and whether anything should have caused concern about its customer. [6] The Payment Systems Regulator describes PS25/5 as general guidance that consolidates earlier publications, and says its definitive requirements are in its legal instruments. [7]

Application FinCrimeRadar assessment

Whether a mandatory scheme applies depends on the payment route, the destination, the claimant and the date. Falling outside it is a statement about scheme scope. It is not a finding that no scam occurred, and it does not end the Ombudsman's wider look at a firm's conduct.

Action FinCrimeRadar assessment

Classify the scam evidence first, then apply the rules for the exact route and date as a separate step. Send the reimbursement reasoning to the APP Scam Decision Framework and to the legal instruments themselves. This handbook does not decide it.

The Scope Verdict

A statement about scheme scope is read as a finding about fraud.

Risk
Reimbursement scope becomes the fraud verdict.
Signal
An own-account or crypto route is rejected as not a scam because it falls outside mandatory scheme scope.
Response
Classify the scam evidence first, then apply the payment-route rules separately.

Reporting is not recovery

Source Established

The FCA says a person who has given personal information or made a payment should tell their bank immediately, that UK victims should report scams to Report Fraud, and that it can only look into scams involving financial services it regulates. It says it cannot help a victim get their money back, though it looks into every report it receives, and that people who are targeted are at greater risk of being targeted again, potentially by recovery room scammers posing as legitimate firms offering to recover lost funds. [3] For crypto investment scams it adds that a follow-up scam may include an offer to get the money back, or an offer to buy back the investment after a fee is paid. [4]

Application FinCrimeRadar assessment

A report supports intelligence and disruption. It is not a recovery route, and no body that receives a report guarantees an investigation or the return of funds. Whether any money can still be recalled is a separate, time-sensitive question for the sending and receiving firms.

Action FinCrimeRadar assessment

Start recall and preservation work at once, report through the current routes, and never promise recovery. Treat any approach offering to recover funds as a new proposition that needs independent verification, and warn the customer against paying for it.

The Second Hook

The victim of one scam becomes the target of the next.

Risk
The victim is exposed to a second scam.
Signal
A new party requests an upfront fee to recover funds.
Response
Treat the recovery offer as a new proposition that needs independent verification, and warn against further payment.

Keep the correspondence, and keep disputes apart from scams

Source Established

The Financial Ombudsman Service tells a person who thinks they have been scammed to keep records of all contact and correspondence with the scammer, which it says is useful when asking the bank to reimburse and if a complaint is brought later. It also says that not all disputes are scams, and that it may need to consider whether a person has fallen victim to a scam or is involved in a civil dispute, for example where a legitimate business delivered poor work. [8]

Application FinCrimeRadar assessment

The same record serves three purposes: it is the evidence for the four streams, it supports any reimbursement or complaint review, and it is what separates a scam from a disappointing investment. Disappointing performance and genuine service failure are different hypotheses from fraud.

Action FinCrimeRadar assessment

Preserve original advertisements, URLs, messages, contracts, dashboard captures, payment details, exchange records, wallet addresses, transaction hashes and later payment demands. Collect only what the file needs and handle personal data under the firm's policies.

Worked scenario 1 · Identity stream

The authorised firm that never made the offer

Every document in the file is real. The offer is not.

Composite scenario for teaching. It does not describe a real firm, customer or case.

  • A customer reports three transfers totalling 72,000 GBP for a fixed-return green bond.
  • The proposal carries the name and firm reference number of an FCA-authorised wealth manager.
  • The customer found the offer after searching online, then spoke with an adviser who used a similar domain.
  • The first 500 GBP interest payment arrived on time.
  • The register confirms the named firm exists. The email domain, telephone number and beneficiary account do not match the details retrieved independently.
  • The genuine firm confirms that it did not issue the bond.
What is the strongest next conclusion?

How each option grades

Not supported by the evidence A. Close as genuine because the firm reference number and interest payment verify the investment.

Source

The FCA describes a clone firm as a copy of a genuine, authorised firm, and advises that the contact details given for a firm should match those on the Firm Checker. [1]

Application

The firm reference number belongs to a genuine firm, which establishes only that the firm exists. It does not attach this domain, number, beneficiary or bond to that firm, and here none of them match its record and the firm denies issuing the bond. The 500 GBP payment shows value was returned once. It does not show that the bond exists.

Action

Do not close the file. Write down what each reassuring fact establishes and what it does not, and open the clone-firm assessment.

Best supported by the evidence B. Treat the evidence as supporting a probable clone-firm investment scam, begin recovery and reporting actions, and keep recipient intent separate pending further evidence.

Source

The FCA says a clone firm copies a genuine, authorised firm and advises that contact details given for the firm should match those on the Firm Checker. It also says a firm that is not on the Warning List may still be unauthorised or be a scam. [1] [2]

Application

The authorised firm is genuine, but the case-specific channels, beneficiary and purported product are not attributable to it. The small return proves only that value was returned once. The genuine firm's denial materially weakens the legitimate-offer explanation. These facts support a probable clone-firm assessment. They do not establish the receiving account holder's knowledge.

Action

Begin available recall or freeze work. Preserve the proposal, communications, domain and payment records. Report through the appropriate fraud and FCA routes. Route recipient-account analysis separately.

Not supported by the evidence C. Treat the case only as a poor investment because a payment was returned.

Source

The Financial Ombudsman Service says not all disputes are scams, and gives the example of a legitimate business whose work or product was poor. [8] The FCA says a clone firm is a copy of a genuine, authorised firm. [1]

Application

A poor-investment reading needs a real issuer and a real product. Here the named firm denies issuing the bond and the channel details do not match its record, so the usual starting point for a genuine loss is missing. Our classification labels reserve a genuine loss or dispute for cases where the promoter, product, custody and journey are evidenced.

Action

Do not record the file as a dispute. Hold it as a probable scam, or as unresolved but high risk if you need targeted checks first, and start containment.

Contains a true point, stops short D. Wait for the firm to appear on the FCA Warning List before acting.

Source

The FCA says the Warning List shows firms it is concerned are working without its permission, that a firm not on the list may still be unauthorised or be a scam, and that unauthorised firms often change names before the FCA is aware of it. [2]

Application

Checking the list is sensible, and a hit would add official evidence of concern. Waiting for one is the error. The clone's domain may not be listed yet, and the contact mismatch and the genuine firm's denial already carry weight. Delay can also reduce what recall or freezing can still achieve.

Action

Check the list and record the result and the date, then act without waiting: recall, preservation and reporting do not depend on a warning being published.

Counterfactual: change one fact FinCrimeRadar assessment

The fact changed. The domain and telephone number match the details retrieved independently from the FCA record, the firm confirms the product, the firm's permission covers the activity, and the payment went to the firm's verified client-money route.

What follows. The clone hypothesis would materially weaken, because the facts that pointed away from the firm would now point towards it. The investigator would still need to distinguish fraud from an investment loss or a service dispute, and the evidence for that sits in the proposition and journey streams, not in the register.

Worked scenario 2 · Money route stream

The real exchange and the false investment

The fiat payments went somewhere genuine. The investment never did.

Composite scenario for teaching. It does not describe a real firm, customer or case.

  • A customer sends 38,000 GBP over four payments to an account in their own name at a genuine crypto exchange.
  • They buy stablecoins and, following instructions from an investment coach met through a social-media advertisement, send them to external wallet addresses.
  • A professional dashboard shows a balance of 61,000 GBP.
  • When the customer asks to withdraw, the coach demands a further 9,000 GBP for tax and liquidity release.
  • The customer does not control the destination wallets and cannot verify the displayed trades independently.
What should the investigator do?

How each option grades

Not supported by the evidence A. Clear the concern because the fiat payments reached the customer's own account at a genuine exchange.

Source

The FCA says fraudsters may manipulate software on professional-looking websites to fake prices and investment returns. [4] The Financial Ombudsman Service says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more, including for payments to the customer's own account and to cryptocurrency providers. [6]

Application

The exchange leg is genuine, which is the Legitimate Node Trap in its plainest form. The exchange does not control or validate the external wallets, and it does not validate the dashboard. A genuine first hop says nothing about where the value went next.

Action

Do not clear the file. Trace the route from the exchange account to the external addresses and record who controlled each.

Best supported by the evidence B. Record a suspected investment scam, preserve the full fiat and on-chain route, stop further payment if possible, and assess prevention, recovery and reimbursement under their separate applicable standards.

Source

The FCA describes fake platforms that display manipulated prices and returns, where a customer may not realise it is a scam until they try to sell. [4] The Financial Ombudsman Service says the Faster Payments and CHAPS reimbursement rules do not cover payments in cryptocurrency or payments to an account under the consumer's control, and that it will still investigate whether the firm could have done more to prevent the scam and what it did to recover the money. [6]

Application

The exchange is a genuine node, but it does not control or validate the external wallets or the dashboard. The customer lacks control of the destination, the trades are not independently evidenced and the withdrawal request has produced a further payment demand. Those facts support a suspected scam assessment. Scheme scope does not decide whether a scam occurred.

Action

Preserve exchange and wallet records, transaction hashes, communications and the advertisement. Attempt available intervention or recovery. Prevent further payment where the firm's authority and controls permit. Route reimbursement and complaint analysis separately.

Contains a true point, stops short C. Reject the report because crypto payments are outside the mandatory reimbursement rules.

Source

The Financial Ombudsman Service says the Faster Payments and CHAPS reimbursement rules do not cover payments in cryptocurrency or payments to an account under the consumer's control. It also says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more to prevent the scam, including for payments to cryptocurrency providers, and will consider warnings and recovery. [6]

Application

The scope point is accurate and it answers a narrow question: whether a mandatory scheme applies. It does not answer whether a scam occurred, and it does not end the examination of the firm's prevention, warning and recovery conduct.

Action

Record scheme scope as its own finding. Classify the scam evidence on its merits, and let the complaint and prevention analysis follow the rules that apply to the route and date.

Not supported by the evidence D. Advise the customer to pay the release fee so the withdrawal can prove whether the platform is genuine.

Source

The FCA says a customer may not realise they have invested in a scam until they try to sell, that people who have been scammed may be targeted again, and that a follow-up scam can include an offer to get the money back or an offer to buy back the investment after a fee is paid. [3] [4]

Application

The withdrawal request has already produced a payment demand in place of a withdrawal. Paying to test the platform asks the customer to fund the test with more money, and a demand like this fits deception more readily than it fits a genuine platform. That is our reading of the facts. The FCA does not describe this exact demand.

Action

Do not advise payment. Warn the customer, preserve the demand, and stop further payment where the firm's authority and controls permit.

Counterfactual: change one fact FinCrimeRadar assessment

The fact changed. The customer controls the destination wallet, has independently verified the assets on-chain, keeps the ability to transfer them without the promoter's permission, and can evidence the platform's genuine role.

What follows. The fake-custody hypothesis would materially weaken, because control of the destination is the fact the original file lacked. Loss of market value alone would not establish fraud, and the file would need to be classified on the rest of the evidence.

What would change the assessment?

A conclusion at the evidence date is a position, not a verdict. These facts would move it.

  • Independent confirmation that the promoter, domain and product belong to the authorised firm.
  • Evidence that the firm's permission covered the represented activity at the relevant time.
  • Independent custody or on-chain evidence showing the customer controls the asset.
  • A verified withdrawal that was not funded by later victims or by the customer's own further payment.
  • Linked complaints, FCA warnings or receiving-account intelligence connecting the route to other victims.
  • Evidence that the recipient account or wallet had an ordinary, documented economic purpose consistent with the transaction.
  • Evidence that the dispute concerns performance or service rather than false identity, non-existent assets or dishonest inducement.

One-screen summary

The method on one page. Every line restates wording from the sections above and adds no new claim.

Four evidence streams

  1. The proposition. Start with what the customer believed they were buying, not the label later given to the case.
  2. The identity. Is the person, domain, phone number, account or wallet in this case actually attributable to it?
  3. The journey. Reconstruct the persuasion sequence before judging any single message.
  4. The money route. Map each transfer as a change of control, not just a line on a statement.

Three decisions

  1. Classification. Which explanation best fits the evidence?
  2. Containment and recovery. What can still be stopped, recalled, frozen or preserved?
  3. Escalation and routing. Which process owns the next decision?

Write what each fact establishes and what it does not, then connect the four streams.

Risk, Signal, Response

Five ways a file goes wrong. Each card names the risk, the signal that shows it in the record, and the response.

1. The Borrowed Badge

A genuine register entry is made to vouch for the whole journey.

Risk
A genuine register entry clears the whole journey.
Signal
The file records the firm reference number but not independently verified contact details or permissions.
Response
Attribute every channel, product and payment instruction separately.

2. The Screen Balance

A number on a screen is treated as money held for the customer.

Risk
A functioning dashboard is treated as custody evidence.
Signal
The only proof of value is a promoter-controlled screen.
Response
Seek independent asset, custody, transaction or withdrawal evidence.

3. The Scope Verdict

A statement about scheme scope is read as a finding about fraud.

Risk
Reimbursement scope becomes the fraud verdict.
Signal
An own-account or crypto route is rejected as not a scam because it falls outside mandatory scheme scope.
Response
Classify the scam evidence first, then apply the payment-route rules separately.

4. The Waiting Room

Recovery waits in a queue behind a perfect classification.

Risk
Recovery waits for perfect classification.
Signal
No recall, provider contact or evidence preservation begins while the file seeks certainty.
Response
Run time-sensitive containment and preservation in parallel with targeted investigation.

5. The Second Hook

The victim of one scam becomes the target of the next.

Risk
The victim is exposed to a second scam.
Signal
A new party requests an upfront fee to recover funds.
Response
Treat the recovery offer as a new proposition that needs independent verification, and warn against further payment.

Knowledge check

Choose one answer for each question. The score is an aid to review, not a credential or a case decision.

1. What does an FCA firm match prove?
2. Does absence from the FCA Warning List clear a firm?
3. Why can a real exchange sit inside a fraudulent journey?
4. Does exclusion from mandatory reimbursement scope mean no scam occurred?
5. What is the Legitimate Node Trap?

Answer notes

Question 1. Source: The FCA says the Firm Checker shows whether a firm is authorised and has permission for the product or service, and that a clone firm is a copy of a genuine, authorised firm. [1] Application: A match establishes the firm and its recorded permissions. It says nothing about who controls this domain, number or account. Action: Test each channel against details you retrieved yourself.

Question 2. Source: The FCA says a firm that is not on the Warning List may still be unauthorised or be a scam. [2] Application: A non-hit records that no matching warning was found at the time of the check. Action: Record the date of the check and keep investigating.

Question 3. Source: The Financial Ombudsman Service says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more, including for payments to the customer's own account and to cryptocurrency providers. [6] Application: FinCrimeRadar assessment: the exchange can be genuine while the destination is not, which is why a genuine node cannot vouch for the journey. Action: Trace from the exchange account to the external addresses.

Question 4. Source: The Ombudsman says the Faster Payments and CHAPS reimbursement rules do not cover payments in cryptocurrency or payments to an account under the consumer's control, and that it will still investigate whether the firm could have done more. [6] Application: Scheme scope, classification and complaint responsibility are separate questions. Action: Classify first, then apply the route rules separately.

Question 5. Source: This is not a regulator's term and no source is cited for it. Application: FinCrimeRadar assessment: the trap is letting a genuine element answer a larger question than it can support. Action: Write what each reassuring fact establishes and what it does not.

FAQ

Does a Companies House record prove the investment business is genuine?

No. It may establish incorporation and filing information. It does not answer FCA authorisation, product permission, promoter attribution or whether the investment asset exists. That is our reading, and the FCA's own description of what its Firm Checker shows is in the sources. [1]

Does a small successful withdrawal prove the investment is real?

No. It proves that value was returned once. The source of the payment, the custody of the supposed asset and the conditions on later withdrawals still need testing. The FCA says that on a fake platform a customer may not realise it is a scam until they try to sell. [4]

Should the investigator wait for a Warning List entry?

No. The FCA says a firm that is not on the list may still be unauthorised or be a scam, and that unauthorised firms often change their names before the FCA is aware of it. [2] Act on the evidence you have and use the current reporting routes. [3]

Is every crypto loss an investment scam?

No. Market loss, platform failure, mis-selling and fraud are different hypotheses. This handbook asks for evidence of deception, identity, custody and control, and does not treat crypto as the conclusion.

Does this handbook decide reimbursement?

No. It builds the investigation and classification record. The applicable scheme, complaint and prevention analysis depends on the payment route, destination, date and the customer's circumstances. Use the APP Scam Decision Framework for that decision, and the legal instruments for the rules themselves. [6] [7]

What should be preserved first?

Original advertisements, URLs, messages, email headers where available, contracts, dashboard captures, bank payment details, exchange records, wallet addresses, transaction hashes, attempted withdrawal messages and any later payment demands. The Ombudsman asks a person who thinks they have been scammed to keep records of all contact and correspondence with the scammer. [8] Collect only what is necessary and handle personal data under the firm's policies.

Sources and methodology

Scope: UK investment scam investigation, drawn from regulator and ombudsman publications about firm status, scam reporting, crypto promotions and reimbursement routes. It does not cover other jurisdictions, recipient-account intent or the reimbursement rules themselves. This is decision support for practitioners, not legal advice.

Method: Each source page was read from its publisher's website on 3 October 2026, recording the title and the last-updated date where the page shows one. The two scenarios are synthetic and describe no real firm, customer or case. The FCA crypto promotions page describes the regime as it began in October 2023, so it is used only for the scope of the regime and not for routes or penalties. The PSR page was read for its own description of PS25/5. An independent review on 3 October 2026 checked PS25/5 [7], the Pay.UK FPS Reimbursement Rules Schedule 4 version 4.0 dated 1 May 2026 [9] and the Bank of England's current CHAPS reimbursement rules [10] against the reimbursement wording in this handbook. The PSR's legal instruments themselves were not analysed.

Evidence separation: Source blocks state what an authority says. Application and Action blocks are FinCrimeRadar analysis and recommendation, and they are labelled as ours.

Limits: The two Financial Ombudsman Service pages carry no date. A source page can change after the date read, so recheck before relying on any wording.

  1. Financial Conduct Authority, How to check a firm or individual is authorised, page last updated 22 September 2026.
  2. Financial Conduct Authority, FCA Warning List of unauthorised firms, page last updated 30 June 2026.
  3. Financial Conduct Authority, Report a scam, page last updated 19 January 2026.
  4. Financial Conduct Authority, Crypto investment scams, page last updated 16 February 2026.
  5. Financial Conduct Authority, Cryptoasset firms marketing to UK consumers, page last updated 6 February 2026.
  6. Financial Ombudsman Service, APP fraud and other scams involving authorised payments or withdrawals, guidance for businesses, no date shown.
  7. Payment Systems Regulator, PS25/5 APP scams reimbursement requirement, published 21 May 2025.
  8. Financial Ombudsman Service, Scams where you've been tricked into making a payment, guidance for consumers, no date shown.
  9. Pay.UK, FPS Reimbursement Rules, Schedule 4, Version 4.0, dated 1 May 2026.
  10. Bank of England, Annex A to the CHAPS Reference Manual: CHAPS Reimbursement Rules, linked from the Bank's CHAPS page, last updated 17 August 2026.

Last reviewed: 3 October 2026. Recheck when the FCA updates its crypto promotions or firm-checking pages, when the reimbursement rules or the Ombudsman's approach change, and before release.