Why financial crime detection needs a new approach
By Swagatam Sen, Founder & CEO, ControlOne
A few years ago, I sat in a meeting with a financial crime team at a major bank. They had just finished a year-long project using machine-learning to spot suspicious activity from past data. The number of alerts was down. By the usual measures, the system was doing well. Everyone in the room agreed it was an improvement.
Then someone asked a quiet question. “Are we catching more crime?”
Nobody could answer with confidence.
That moment has stayed with me. It gets to the heart of what the industry has been doing for the last decade: improving the machinery of compliance without solving the underlying detection problem. From the outside the two things look similar. They are not the same.
The problem is not the technology. It is what we choose to look at.
Money laundering is a crime of networks. Criminal organisations do not work through single accounts acting on their own. They work through coordinated groups: accounts used to move money on behalf of criminals (often called “mules”), long chains of transfers designed to hide where the money came from, and companies that exist only on paper. Any single transaction looks harmless, but put together the pattern clearly reveals criminal activity. Every major laundering method that the Financial Action Task Force (FATF) have documented over the last twenty years shares this feature. The risk sits between accounts, not within any one of them.
Yet every generation of detection system has been built to assess one account at a time.
Rules: easy to explain, but frozen in place
The first generation of these systems relied on fixed rules. Flag any cash deposit above a set amount. Raise a flag on transfers sent to high-risk countries. Rules can be checked and traced, regulators understand them, and the teams using them can explain why every alert was raised. But by their nature they never change. Criminal networks work out where the limits are set and simply route around them. The result is a system that reliably catches the tricks of the past while raising thousands of false alarms — keeping investigators busy without catching much organised crime.
Rules were never going to solve the problem. But they set an important expectation inside these institutions: that a detection system should be explainable. That expectation matters. Any architecture that replaces them has to meet it.
The first wave of machine learning: smarter scoring, same limit
The industry’s first serious move into machine learning — software that learns patterns from data rather than following fixed rules — brought genuine improvements to how alerts were sorted and how risky each customer was judged to be. These systems are quicker to update than rules, better at handling complicated combinations of information, and far more accurate by the usual measures.
But they depend entirely on clues that people have to define in advance. You have to know what you are looking for before you can teach the system to find it. It catches someone breaking a large deposit into lots of small ones only because a person told it to look for exactly that. A new laundering method that doesn’t match a known template stays invisible. The system can only ever be as good as the clues it has been given, and no one can describe a pattern the bank has never seen before.
Mapping the network: the connections become visible, but frozen in time
The realisation that financial crime is a network problem led to serious investment in approaches that map how accounts connect to one another. Instead of looking only at what a single account does, these systems learn from the links between accounts. This is genuine progress. Connecting accounts that share the same trading partners, the same hidden owners, or the same flows of money reveals patterns that account-by-account systems simply cannot see.
But most of these systems in use today treat the network as a single frozen photograph. They learn who is connected to whom at one moment in time. They do not learn the sequence of events flowing through those connections over time.
Financial crime is not a structure. It is a process. A network of mule accounts is defined not just by how it is wired together but by the rhythm of the money moving through it: the gaps in timing, the order in which accounts are used, the coordinated pattern that appears when several accounts act together over weeks or months. A frozen snapshot captures the wiring and misses the movement.
Following events over time: the timeline arrives, but not the group
The latest approaches are powerful at reasoning about sequences of events. They can learn patterns of timing across long transaction histories, apply what they have learned across different kinds of institution, and spot unusual activity that no rule-writer ever thought to describe. In some tasks like reviewing documents, writing up case summaries, building a picture of customer behaviour, they are game-changing.
But they are almost always pointed at one account at a time. One model. One customer. One timeline.
Financial crime does not operate one customer at a time. It operates across many customers at once. A system racing through individual account histories side by side is still solving the wrong problem. Doing it efficiently, and on a huge scale, but the wrong problem all the same.
What a detection system actually needs to do
Each generation has solved a real part of the problem. Rules gave us the ability to explain decisions. The first wave of machine learning gave us the ability to adapt. Mapping the network let us see the connections. The latest models let us follow events over time. But no system in use today has combined all four of these strengths while looking at the right thing.
What is needed is a system that treats whole groups of accounts; not single accounts; as the main thing it examines. One that learns the tell-tale sequences of criminal behaviour directly from the data, without needing analysts to spell out the patterns in advance. One that works out the role each account is playing within a group, not from fixed rules but from the patterns that emerge in the data itself. And one that produces an explanation you can genuinely follow: not a risk score with a rough justification bolted on afterwards, but a clear, step-by-step record showing exactly which coordinated chain of behaviour led to the decision.
This is not a matter of fine-tuning the systems we already have. It calls for something built around the criminal network, not the individual account, from the ground up.
Where this leads
The institutions spending tens of billions every year on fighting financial crime are not failing for lack of effort or money. They are running systems designed for a different problem. The question is not whether to upgrade. Regulators and investors are already forcing that conversation. The question is whether the next generation of tools will change what we look at or simply run faster while looking at the same old thing.
Closing the detection gap means starting from the right place. That means looking at the whole ring, not just one of its members.
That is what ControlOne is building.