The question, and what this handbook will not decide
A customer reports a loss on an investment. The file contains a real firm name, a working bank transfer, a registered exchange and a dashboard full of profit. Which of those facts tell you the investment was genuine?
This handbook answers one question. When an investment journey contains both genuine and false elements, what does the available evidence establish about the proposition, the promoter and the money route, and what should the investigator do next? It teaches the method on UK facts and is written for practitioners who work scam, payment, complaint and financial-crime files. It is a practitioner method, not legal advice.
It deliberately stops short of three decisions that belong elsewhere: whether a customer is reimbursed, whether a recipient account holder knew what was happening, and whether a suspicion report is made. It builds the evidence record those decisions rely on, and it keeps them apart.
Do not let one genuine fact answer a larger question than it can support.
How evidence is labelled
- Established What a named regulator or ombudsman page says, as read on the evidence date.
- FinCrimeRadar assessment Our analysis of how the sources apply to the facts, and our recommended action.
- Unknown A fact the evidence does not settle.
Out of scope: any live lookup of a firm, domain, wallet or victim, recipient-account intent, and the reimbursement rules themselves. The APP Scam Decision Framework covers reimbursement and complaint defensibility. This handbook links to it and does not repeat it.
The Legitimate Node Trap
A register entry can be genuine. The person using it may not be.
A crypto exchange can be registered. The external wallet may still be controlled by a fraudster. A bank transfer can reach a real company account, and that company may be a mule, a payment intermediary, a shell or an unrelated business whose details were misused. A dashboard can show prices and profits that are nothing more than controlled screen content.
The mistake is not believing a genuine fact. It is allowing that fact to answer a larger question than it can support. We call this the Legitimate Node Trap. It is a FinCrimeRadar assessment of how investment scam files go wrong, not a term any regulator uses.
For every reassuring fact, write two sentences: what this establishes, and what this does not establish.
Take an FCA record. It may establish that a named firm was authorised, and for which permissions, at a given time. It does not establish that the caller, the domain, the messaging account, the beneficiary or the wallet belonged to that firm. The FCA describes a clone firm as a copy of a genuine, authorised firm, and tells consumers to make sure the contact details they were given match those on the Firm Checker [1]. The investigator should apply the same discipline: compare what the promoter supplied with details retrieved independently.
The discipline works in reverse as well. A firm that does not appear on the Warning List has not been cleared. The FCA says that if a firm is not on the list it may still be unauthorised or be a scam, and that unauthorised firms often change their names before the FCA is aware of it [2].
Build four evidence streams
Reconstruct the proposition, the identity, the journey and the money route separately. Each answers a different question, and none can stand in for another.
The four streams are our own investigative structure. They organise the evidence. They are not a legal test.
1 The proposition
Start with what the customer believed they were buying, not the label later given to the case. Record the product, issuer, expected return, term, custody arrangement, withdrawal conditions, fees and any protection that was claimed. Preserve the original advertisement, landing page, proposal, contract and dashboard.
A promise of returns is not the product. A visible balance is not proof that the asset exists or is held for the customer. Ask what evidence would exist if the proposition were genuine: a verifiable issuer, independently confirmed product documentation, a custody record, a contract with coherent counterparties, or an asset visible through a channel the promoter does not control.
The Screen Balance
- Risk
- A functioning dashboard is treated as custody evidence.
- Signal
- The only proof of value is a promoter-controlled screen.
- Response
- Seek independent asset, custody, transaction or withdrawal evidence.
2 The identity
Four questions are often collapsed into one. Keep them apart.
- Does the named legal entity exist?
- Is it authorised, registered or exempt for the relevant activity?
- Does it hold the permission for this product or service?
- Is the person, domain, phone number, account or wallet in this case actually attributable to it?
Authorisation, registration and permission are not synonyms. The FCA says that being authorised means a firm must meet certain standards and has permission to provide certain products and services, while being registered means it cannot provide regulated products that need authorisation, and that an authorised firm can offer both regulated and unregulated products [1]. A genuine firm identity therefore does not validate every product carrying its name, and clone firms depend on that shortcut.
Compare the email domain, telephone number, website and payment instructions with details retrieved independently from the Firm Checker or Financial Services Register. The FCA notes that a firm's contact details are provided and confirmed by the firm, so a match narrows the question without settling who actually controls the channel [1]. Where an appointed representative is claimed, the FCA says to check with the principal, so confirm the relationship and the permitted activity through contact details you sourced yourself [1].
The Borrowed Badge
- Risk
- A genuine register entry clears the whole journey.
- Signal
- The file records the firm reference number but not independently verified contact details or permissions.
- Response
- Attribute every channel, product and payment instruction separately.
3 The journey
Reconstruct the persuasion sequence before judging any single message. How did contact begin, and what created trust? Was there a small early withdrawal, an apparent adviser, a celebrity image, a private messaging group, a remote-access session or a time-limited opportunity? When did the customer first try to withdraw, and what new reason was then given for another payment?
Sequence matters because the FCA describes professional-looking sites where fraudsters may manipulate software to fake prices and investment returns, and says a customer may not realise it is a scam until they try to sell the investment [4]. A small early return may be part of the inducement. It is not, on its own, evidence of genuine performance.
Keep customer conduct separate from promoter conduct. A customer's confidence, prior investment experience or decision to continue after a warning does not show that the proposition was genuine. Those facts may matter to a prevention, reimbursement or complaint assessment, and that assessment belongs in the APP Scam Decision Framework, not in this file.
4 The money route
Map each transfer as a change of control, not just a line on a statement. For fiat, capture the sending account, beneficiary, account name, institution, reference, date, value and any recall or freeze response. For crypto, capture the exchange account, asset, network, transaction hash, sending and destination addresses, timestamps, and whether the customer or another party controlled the private keys.
Do not stop at a legitimate intermediary. A customer may pay their own account at a genuine exchange before value leaves for an external wallet. The exchange is real. The investment destination can still be fraudulent. Equally, payment to a third party is not proof that the recipient knowingly took part. Recipient intent is a separate assessment and this handbook does not make it.
The route also affects which reimbursement rules may apply, and the Ombudsman says it may still examine what a firm did outside those rules. The sources section below sets out what each source does and does not say. Classification and reimbursement stay separate decisions.
The evidence table: what each fact does and does not prove
Each row is a piece of evidence that commonly gets read as more than it is. Use the table to write the two sentences for each fact: what it establishes, and what it cannot establish alone.
| Evidence | What it may establish | What it cannot establish alone | Next check |
|---|---|---|---|
| FCA firm match | The named firm exists and has a recorded status or permissions. | That the contact is genuine, that the product exists, or that the promoter controls the firm. | Compare independently retrieved contact details, permissions and historical status. |
| Warning List hit | The FCA has published a concern about the firm or identity. | A criminal conviction, or the complete fraud mechanism. | Preserve the warning record and test the case identifiers against it. |
| No Warning List hit | No matching published warning was found at the time of the check. | Legitimacy or authorisation. | Firm Checker, permissions, identity attribution and overseas regulator warnings. |
| Companies House record | A company was incorporated, and named officers or filings exist. | FCA authorisation, trading legitimacy, or control of the contact channel. | FCA status, permissions, independent contact details and payment-account ownership. |
| Small withdrawal | Value was returned once. | Genuine profits, or a sustainable investment. | The source of the returned funds, later withdrawal conditions and asset custody. |
| Genuine exchange | A real service converted or held value. | That the external wallet is legitimate, or that the exchange was used for a genuine investment. | Wallet control, destination, transaction hash and the customer journey. |
| Platform balance | A website displayed a number. | That the asset exists, is held in custody, or can be withdrawn. | Independent custody or on-chain evidence, and a controlled withdrawal test where it is safe to run one. |
| Beneficiary name match | Payment details matched a name. | The recipient's intent, or the promoter's identity. | Account history, linked victims, onboarding records and onward movement, through authorised channels. |
The Companies House row is a FinCrimeRadar investigative recommendation. Incorporation records are not worthless. They answer a narrower question than authorisation or legitimacy. The FCA statements behind the firm match and Warning List rows are set out in the sources section [1] [2].
Make three decisions, not one
The question is not simply scam or not scam. Classification, containment and recovery, and routing are three decisions with different clocks and different owners.
1. Classification
Which explanation best fits the evidence? These are FinCrimeRadar analytical labels. They are not legal categories.
- Probable investment scam. Material deception is supported across more than one evidence stream.
- Unresolved but high risk. Material gaps remain, but the evidence justifies containment or escalation while targeted checks continue.
- Genuine investment loss or dispute. The promoter, product, custody and journey are evidenced, but value fell or performance disappointed.
- Insufficient evidence. Neither fraud nor legitimacy is established. Record the gaps and the next check instead of turning uncertainty into clearance.
2. Containment and recovery
What can still be stopped, recalled, frozen or preserved? Run this work alongside classification wherever delay can reduce options. Notify the relevant payment institution or provider promptly, preserve communications and transaction identifiers, and identify the recipient or wallet path. The FCA tells a person who has made a payment or given personal information to tell their bank immediately [3].
Do not promise recovery. Do not point a customer to a recovery service because it claims specialist access: the FCA warns that people who have been targeted are at greater risk of being targeted again, potentially by recovery room scammers who pose as legitimate firms offering to recover lost funds [3].
The Waiting Room
- Risk
- Recovery waits for perfect classification.
- Signal
- No recall, provider contact or evidence preservation begins while the file seeks certainty.
- Response
- Run time-sensitive containment and preservation in parallel with targeted investigation.
3. Escalation and routing
Which process owns the next decision?
- The scam classification file records the evidence and the competing explanation.
- Reimbursement and complaint analysis applies the rule set for the exact payment route and date.
- Receiving-account or wallet evidence goes through authorised internal or external channels, without declaring a recipient intent that the evidence does not establish.
- Money-laundering suspicion follows the firm's existing internal reporting and MLRO process.
- The FCA invites reports of suspected scams, and UK victims are directed to Report Fraud first [3].
What the sources say, and what they do not
Six teaching points carry regulatory weight. For each, the Source block says what the named authority states, the Application block is our reading of what that means for a file, and the Action block is our recommendation. Only the first is the authority's own position.
Authorisation, registration, permission and contact details
Source Established
The FCA says that being authorised means a firm must meet certain standards and has permission to provide certain products and services, while being registered means it cannot provide regulated products and services that need authorisation. It says the Firm Checker shows whether a firm is authorised and has permission for the product or service, and that firms it authorises can offer both regulated and unregulated products. It describes a clone firm as a copy of a genuine, authorised firm, advises that contact details given for the firm should match those on the Firm Checker, and notes that firm contact details are provided and confirmed by the firm. It adds that using an authorised firm with the correct permissions will greatly reduce the risk of harm but will not remove all risk. [1]
Application FinCrimeRadar assessment
A register match answers whether a named firm exists and what it is recorded as permitted to do. It does not answer whether this domain, number, account or product belongs to it. Authorisation does not extend to every product that carries the firm's name, and a registered status is not authorisation.
Action FinCrimeRadar assessment
Record the firm's status and permissions as at the case dates, and test each channel and payment instruction against details you retrieved yourself. Treat a mismatch as a finding in its own right. Where an appointed representative is claimed, confirm the relationship and the permitted activity with the principal.
The Warning List is not a clearance list
Source Established
The FCA says its Warning List shows firms it is concerned are working without its permission, that it adds firms as soon as possible, that a firm not on the list may still be unauthorised or be a scam, and that unauthorised firms often change their names before the FCA is aware of it. It advises checking warnings from overseas regulators for an overseas firm. [2]
Application FinCrimeRadar assessment
A hit is strong official evidence of concern. It is not a conviction and it does not describe the whole fraud mechanism. A non-hit records only that no matching warning was found at the time of the check.
Action FinCrimeRadar assessment
Preserve any warning record with the date checked. Never record a non-hit as legitimacy or authorisation. Do not hold a file open waiting for a warning to appear.
Crypto promotions and registered exchanges
Source Established
The FCA says its financial promotions regime applies to all firms marketing cryptoassets to UK consumers regardless of whether the firm is based overseas or what technology is used, and that the definition of a financial promotion is broad and covers a firm's website, mobile apps, social media posts and online advertising. [5]
Application FinCrimeRadar assessment
A website, an app or a registered exchange relationship does not by itself tell you whether a particular promotion was lawfully communicated. The FCA page we read describes the regime as it stood when it began in October 2023, including a route that then depended on legislation still before Parliament. We therefore do not list communication routes or consequences here. Check them against the current rules before relying on any.
Action FinCrimeRadar assessment
Record where and how the customer first met the promotion: platform, account name, date and a capture of the advertisement. Treat the lawfulness of the route as a question for current rules and, where it matters to the file, legal advice. Do not describe registration as equivalent to authorisation.
Reimbursement scope and what sits outside it
Source Established
The Financial Ombudsman Service says the Faster Payments and CHAPS reimbursement rules came into force on 7 October 2024 and that they do not cover payments in cryptocurrency or payments to an account under the consumer's control, among other exclusions. It says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more to prevent the scam, including for payments to the customer's own account, payments to cryptocurrency providers, card payments to a genuine merchant, payments to an overseas payee and cash withdrawals. It will consider whether the payments should have alerted the firm, what warning was given and what was done to recover the money, and for a receiving firm, what it did once told of the scam and whether anything should have caused concern about its customer. [6] The Payment Systems Regulator describes PS25/5 as general guidance that consolidates earlier publications, and says its definitive requirements are in its legal instruments. [7]
Application FinCrimeRadar assessment
Whether a mandatory scheme applies depends on the payment route, the destination, the claimant and the date. Falling outside it is a statement about scheme scope. It is not a finding that no scam occurred, and it does not end the Ombudsman's wider look at a firm's conduct.
Action FinCrimeRadar assessment
Classify the scam evidence first, then apply the rules for the exact route and date as a separate step. Send the reimbursement reasoning to the APP Scam Decision Framework and to the legal instruments themselves. This handbook does not decide it.
The Scope Verdict
- Risk
- Reimbursement scope becomes the fraud verdict.
- Signal
- An own-account or crypto route is rejected as not a scam because it falls outside mandatory scheme scope.
- Response
- Classify the scam evidence first, then apply the payment-route rules separately.
Reporting is not recovery
Source Established
The FCA says a person who has given personal information or made a payment should tell their bank immediately, that UK victims should report scams to Report Fraud, and that it can only look into scams involving financial services it regulates. It says it cannot help a victim get their money back, though it looks into every report it receives, and that people who are targeted are at greater risk of being targeted again, potentially by recovery room scammers posing as legitimate firms offering to recover lost funds. [3] For crypto investment scams it adds that a follow-up scam may include an offer to get the money back, or an offer to buy back the investment after a fee is paid. [4]
Application FinCrimeRadar assessment
A report supports intelligence and disruption. It is not a recovery route, and no body that receives a report guarantees an investigation or the return of funds. Whether any money can still be recalled is a separate, time-sensitive question for the sending and receiving firms.
Action FinCrimeRadar assessment
Start recall and preservation work at once, report through the current routes, and never promise recovery. Treat any approach offering to recover funds as a new proposition that needs independent verification, and warn the customer against paying for it.
The Second Hook
- Risk
- The victim is exposed to a second scam.
- Signal
- A new party requests an upfront fee to recover funds.
- Response
- Treat the recovery offer as a new proposition that needs independent verification, and warn against further payment.
Keep the correspondence, and keep disputes apart from scams
Source Established
The Financial Ombudsman Service tells a person who thinks they have been scammed to keep records of all contact and correspondence with the scammer, which it says is useful when asking the bank to reimburse and if a complaint is brought later. It also says that not all disputes are scams, and that it may need to consider whether a person has fallen victim to a scam or is involved in a civil dispute, for example where a legitimate business delivered poor work. [8]
Application FinCrimeRadar assessment
The same record serves three purposes: it is the evidence for the four streams, it supports any reimbursement or complaint review, and it is what separates a scam from a disappointing investment. Disappointing performance and genuine service failure are different hypotheses from fraud.
Action FinCrimeRadar assessment
Preserve original advertisements, URLs, messages, contracts, dashboard captures, payment details, exchange records, wallet addresses, transaction hashes and later payment demands. Collect only what the file needs and handle personal data under the firm's policies.
The authorised firm that never made the offer
Every document in the file is real. The offer is not.
Composite scenario for teaching. It does not describe a real firm, customer or case.
- A customer reports three transfers totalling 72,000 GBP for a fixed-return green bond.
- The proposal carries the name and firm reference number of an FCA-authorised wealth manager.
- The customer found the offer after searching online, then spoke with an adviser who used a similar domain.
- The first 500 GBP interest payment arrived on time.
- The register confirms the named firm exists. The email domain, telephone number and beneficiary account do not match the details retrieved independently.
- The genuine firm confirms that it did not issue the bond.
How each option grades
Not supported by the evidence A. Close as genuine because the firm reference number and interest payment verify the investment.
Source
The FCA describes a clone firm as a copy of a genuine, authorised firm, and advises that the contact details given for a firm should match those on the Firm Checker. [1]
Application
The firm reference number belongs to a genuine firm, which establishes only that the firm exists. It does not attach this domain, number, beneficiary or bond to that firm, and here none of them match its record and the firm denies issuing the bond. The 500 GBP payment shows value was returned once. It does not show that the bond exists.
Action
Do not close the file. Write down what each reassuring fact establishes and what it does not, and open the clone-firm assessment.
Best supported by the evidence B. Treat the evidence as supporting a probable clone-firm investment scam, begin recovery and reporting actions, and keep recipient intent separate pending further evidence.
Source
The FCA says a clone firm copies a genuine, authorised firm and advises that contact details given for the firm should match those on the Firm Checker. It also says a firm that is not on the Warning List may still be unauthorised or be a scam. [1] [2]
Application
The authorised firm is genuine, but the case-specific channels, beneficiary and purported product are not attributable to it. The small return proves only that value was returned once. The genuine firm's denial materially weakens the legitimate-offer explanation. These facts support a probable clone-firm assessment. They do not establish the receiving account holder's knowledge.
Action
Begin available recall or freeze work. Preserve the proposal, communications, domain and payment records. Report through the appropriate fraud and FCA routes. Route recipient-account analysis separately.
Not supported by the evidence C. Treat the case only as a poor investment because a payment was returned.
Source
The Financial Ombudsman Service says not all disputes are scams, and gives the example of a legitimate business whose work or product was poor. [8] The FCA says a clone firm is a copy of a genuine, authorised firm. [1]
Application
A poor-investment reading needs a real issuer and a real product. Here the named firm denies issuing the bond and the channel details do not match its record, so the usual starting point for a genuine loss is missing. Our classification labels reserve a genuine loss or dispute for cases where the promoter, product, custody and journey are evidenced.
Action
Do not record the file as a dispute. Hold it as a probable scam, or as unresolved but high risk if you need targeted checks first, and start containment.
Contains a true point, stops short D. Wait for the firm to appear on the FCA Warning List before acting.
Source
The FCA says the Warning List shows firms it is concerned are working without its permission, that a firm not on the list may still be unauthorised or be a scam, and that unauthorised firms often change names before the FCA is aware of it. [2]
Application
Checking the list is sensible, and a hit would add official evidence of concern. Waiting for one is the error. The clone's domain may not be listed yet, and the contact mismatch and the genuine firm's denial already carry weight. Delay can also reduce what recall or freezing can still achieve.
Action
Check the list and record the result and the date, then act without waiting: recall, preservation and reporting do not depend on a warning being published.
Counterfactual: change one fact FinCrimeRadar assessment
The fact changed. The domain and telephone number match the details retrieved independently from the FCA record, the firm confirms the product, the firm's permission covers the activity, and the payment went to the firm's verified client-money route.
What follows. The clone hypothesis would materially weaken, because the facts that pointed away from the firm would now point towards it. The investigator would still need to distinguish fraud from an investment loss or a service dispute, and the evidence for that sits in the proposition and journey streams, not in the register.
The real exchange and the false investment
The fiat payments went somewhere genuine. The investment never did.
Composite scenario for teaching. It does not describe a real firm, customer or case.
- A customer sends 38,000 GBP over four payments to an account in their own name at a genuine crypto exchange.
- They buy stablecoins and, following instructions from an investment coach met through a social-media advertisement, send them to external wallet addresses.
- A professional dashboard shows a balance of 61,000 GBP.
- When the customer asks to withdraw, the coach demands a further 9,000 GBP for tax and liquidity release.
- The customer does not control the destination wallets and cannot verify the displayed trades independently.
How each option grades
Not supported by the evidence A. Clear the concern because the fiat payments reached the customer's own account at a genuine exchange.
Source
The FCA says fraudsters may manipulate software on professional-looking websites to fake prices and investment returns. [4] The Financial Ombudsman Service says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more, including for payments to the customer's own account and to cryptocurrency providers. [6]
Application
The exchange leg is genuine, which is the Legitimate Node Trap in its plainest form. The exchange does not control or validate the external wallets, and it does not validate the dashboard. A genuine first hop says nothing about where the value went next.
Action
Do not clear the file. Trace the route from the exchange account to the external addresses and record who controlled each.
Best supported by the evidence B. Record a suspected investment scam, preserve the full fiat and on-chain route, stop further payment if possible, and assess prevention, recovery and reimbursement under their separate applicable standards.
Source
The FCA describes fake platforms that display manipulated prices and returns, where a customer may not realise it is a scam until they try to sell. [4] The Financial Ombudsman Service says the Faster Payments and CHAPS reimbursement rules do not cover payments in cryptocurrency or payments to an account under the consumer's control, and that it will still investigate whether the firm could have done more to prevent the scam and what it did to recover the money. [6]
Application
The exchange is a genuine node, but it does not control or validate the external wallets or the dashboard. The customer lacks control of the destination, the trades are not independently evidenced and the withdrawal request has produced a further payment demand. Those facts support a suspected scam assessment. Scheme scope does not decide whether a scam occurred.
Action
Preserve exchange and wallet records, transaction hashes, communications and the advertisement. Attempt available intervention or recovery. Prevent further payment where the firm's authority and controls permit. Route reimbursement and complaint analysis separately.
Contains a true point, stops short C. Reject the report because crypto payments are outside the mandatory reimbursement rules.
Source
The Financial Ombudsman Service says the Faster Payments and CHAPS reimbursement rules do not cover payments in cryptocurrency or payments to an account under the consumer's control. It also says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more to prevent the scam, including for payments to cryptocurrency providers, and will consider warnings and recovery. [6]
Application
The scope point is accurate and it answers a narrow question: whether a mandatory scheme applies. It does not answer whether a scam occurred, and it does not end the examination of the firm's prevention, warning and recovery conduct.
Action
Record scheme scope as its own finding. Classify the scam evidence on its merits, and let the complaint and prevention analysis follow the rules that apply to the route and date.
Not supported by the evidence D. Advise the customer to pay the release fee so the withdrawal can prove whether the platform is genuine.
Source
The FCA says a customer may not realise they have invested in a scam until they try to sell, that people who have been scammed may be targeted again, and that a follow-up scam can include an offer to get the money back or an offer to buy back the investment after a fee is paid. [3] [4]
Application
The withdrawal request has already produced a payment demand in place of a withdrawal. Paying to test the platform asks the customer to fund the test with more money, and a demand like this fits deception more readily than it fits a genuine platform. That is our reading of the facts. The FCA does not describe this exact demand.
Action
Do not advise payment. Warn the customer, preserve the demand, and stop further payment where the firm's authority and controls permit.
Counterfactual: change one fact FinCrimeRadar assessment
The fact changed. The customer controls the destination wallet, has independently verified the assets on-chain, keeps the ability to transfer them without the promoter's permission, and can evidence the platform's genuine role.
What follows. The fake-custody hypothesis would materially weaken, because control of the destination is the fact the original file lacked. Loss of market value alone would not establish fraud, and the file would need to be classified on the rest of the evidence.
What would change the assessment?
A conclusion at the evidence date is a position, not a verdict. These facts would move it.
- Independent confirmation that the promoter, domain and product belong to the authorised firm.
- Evidence that the firm's permission covered the represented activity at the relevant time.
- Independent custody or on-chain evidence showing the customer controls the asset.
- A verified withdrawal that was not funded by later victims or by the customer's own further payment.
- Linked complaints, FCA warnings or receiving-account intelligence connecting the route to other victims.
- Evidence that the recipient account or wallet had an ordinary, documented economic purpose consistent with the transaction.
- Evidence that the dispute concerns performance or service rather than false identity, non-existent assets or dishonest inducement.
One-screen summary
The method on one page. Every line restates wording from the sections above and adds no new claim.
Four evidence streams
- The proposition. Start with what the customer believed they were buying, not the label later given to the case.
- The identity. Is the person, domain, phone number, account or wallet in this case actually attributable to it?
- The journey. Reconstruct the persuasion sequence before judging any single message.
- The money route. Map each transfer as a change of control, not just a line on a statement.
Three decisions
- Classification. Which explanation best fits the evidence?
- Containment and recovery. What can still be stopped, recalled, frozen or preserved?
- Escalation and routing. Which process owns the next decision?
Write what each fact establishes and what it does not, then connect the four streams.
Risk, Signal, Response
Five ways a file goes wrong. Each card names the risk, the signal that shows it in the record, and the response.
1. The Borrowed Badge
- Risk
- A genuine register entry clears the whole journey.
- Signal
- The file records the firm reference number but not independently verified contact details or permissions.
- Response
- Attribute every channel, product and payment instruction separately.
2. The Screen Balance
- Risk
- A functioning dashboard is treated as custody evidence.
- Signal
- The only proof of value is a promoter-controlled screen.
- Response
- Seek independent asset, custody, transaction or withdrawal evidence.
3. The Scope Verdict
- Risk
- Reimbursement scope becomes the fraud verdict.
- Signal
- An own-account or crypto route is rejected as not a scam because it falls outside mandatory scheme scope.
- Response
- Classify the scam evidence first, then apply the payment-route rules separately.
4. The Waiting Room
- Risk
- Recovery waits for perfect classification.
- Signal
- No recall, provider contact or evidence preservation begins while the file seeks certainty.
- Response
- Run time-sensitive containment and preservation in parallel with targeted investigation.
5. The Second Hook
- Risk
- The victim is exposed to a second scam.
- Signal
- A new party requests an upfront fee to recover funds.
- Response
- Treat the recovery offer as a new proposition that needs independent verification, and warn against further payment.
Knowledge check
Choose one answer for each question. The score is an aid to review, not a credential or a case decision.
Answer notes
Question 1. Source: The FCA says the Firm Checker shows whether a firm is authorised and has permission for the product or service, and that a clone firm is a copy of a genuine, authorised firm. [1] Application: A match establishes the firm and its recorded permissions. It says nothing about who controls this domain, number or account. Action: Test each channel against details you retrieved yourself.
Question 2. Source: The FCA says a firm that is not on the Warning List may still be unauthorised or be a scam. [2] Application: A non-hit records that no matching warning was found at the time of the check. Action: Record the date of the check and keep investigating.
Question 3. Source: The Financial Ombudsman Service says that where the Faster Payments, CHAPS and CRM Code rules do not apply it will still investigate whether the firm could have done more, including for payments to the customer's own account and to cryptocurrency providers. [6] Application: FinCrimeRadar assessment: the exchange can be genuine while the destination is not, which is why a genuine node cannot vouch for the journey. Action: Trace from the exchange account to the external addresses.
Question 4. Source: The Ombudsman says the Faster Payments and CHAPS reimbursement rules do not cover payments in cryptocurrency or payments to an account under the consumer's control, and that it will still investigate whether the firm could have done more. [6] Application: Scheme scope, classification and complaint responsibility are separate questions. Action: Classify first, then apply the route rules separately.
Question 5. Source: This is not a regulator's term and no source is cited for it. Application: FinCrimeRadar assessment: the trap is letting a genuine element answer a larger question than it can support. Action: Write what each reassuring fact establishes and what it does not.
FAQ
Does a Companies House record prove the investment business is genuine?
No. It may establish incorporation and filing information. It does not answer FCA authorisation, product permission, promoter attribution or whether the investment asset exists. That is our reading, and the FCA's own description of what its Firm Checker shows is in the sources. [1]
Does a small successful withdrawal prove the investment is real?
No. It proves that value was returned once. The source of the payment, the custody of the supposed asset and the conditions on later withdrawals still need testing. The FCA says that on a fake platform a customer may not realise it is a scam until they try to sell. [4]
Should the investigator wait for a Warning List entry?
No. The FCA says a firm that is not on the list may still be unauthorised or be a scam, and that unauthorised firms often change their names before the FCA is aware of it. [2] Act on the evidence you have and use the current reporting routes. [3]
Is every crypto loss an investment scam?
No. Market loss, platform failure, mis-selling and fraud are different hypotheses. This handbook asks for evidence of deception, identity, custody and control, and does not treat crypto as the conclusion.
Does this handbook decide reimbursement?
No. It builds the investigation and classification record. The applicable scheme, complaint and prevention analysis depends on the payment route, destination, date and the customer's circumstances. Use the APP Scam Decision Framework for that decision, and the legal instruments for the rules themselves. [6] [7]
What should be preserved first?
Original advertisements, URLs, messages, email headers where available, contracts, dashboard captures, bank payment details, exchange records, wallet addresses, transaction hashes, attempted withdrawal messages and any later payment demands. The Ombudsman asks a person who thinks they have been scammed to keep records of all contact and correspondence with the scammer. [8] Collect only what is necessary and handle personal data under the firm's policies.
Sources and methodology
Scope: UK investment scam investigation, drawn from regulator and ombudsman publications about firm status, scam reporting, crypto promotions and reimbursement routes. It does not cover other jurisdictions, recipient-account intent or the reimbursement rules themselves. This is decision support for practitioners, not legal advice.
Method: Each source page was read from its publisher's website on 3 October 2026, recording the title and the last-updated date where the page shows one. The two scenarios are synthetic and describe no real firm, customer or case. The FCA crypto promotions page describes the regime as it began in October 2023, so it is used only for the scope of the regime and not for routes or penalties. The PSR page was read for its own description of PS25/5. An independent review on 3 October 2026 checked PS25/5 [7], the Pay.UK FPS Reimbursement Rules Schedule 4 version 4.0 dated 1 May 2026 [9] and the Bank of England's current CHAPS reimbursement rules [10] against the reimbursement wording in this handbook. The PSR's legal instruments themselves were not analysed.
Evidence separation: Source blocks state what an authority says. Application and Action blocks are FinCrimeRadar analysis and recommendation, and they are labelled as ours.
Limits: The two Financial Ombudsman Service pages carry no date. A source page can change after the date read, so recheck before relying on any wording.
- Financial Conduct Authority, How to check a firm or individual is authorised, page last updated 22 September 2026.
- Financial Conduct Authority, FCA Warning List of unauthorised firms, page last updated 30 June 2026.
- Financial Conduct Authority, Report a scam, page last updated 19 January 2026.
- Financial Conduct Authority, Crypto investment scams, page last updated 16 February 2026.
- Financial Conduct Authority, Cryptoasset firms marketing to UK consumers, page last updated 6 February 2026.
- Financial Ombudsman Service, APP fraud and other scams involving authorised payments or withdrawals, guidance for businesses, no date shown.
- Payment Systems Regulator, PS25/5 APP scams reimbursement requirement, published 21 May 2025.
- Financial Ombudsman Service, Scams where you've been tricked into making a payment, guidance for consumers, no date shown.
- Pay.UK, FPS Reimbursement Rules, Schedule 4, Version 4.0, dated 1 May 2026.
- Bank of England, Annex A to the CHAPS Reference Manual: CHAPS Reimbursement Rules, linked from the Bank's CHAPS page, last updated 17 August 2026.
Last reviewed: 3 October 2026. Recheck when the FCA updates its crypto promotions or firm-checking pages, when the reimbursement rules or the Ombudsman's approach change, and before release.