Skip to main content
FinCrimes

Financial crime analytics for central banks, regulators and FIUs

Reserve banks, financial regulators and financial intelligence units see what no single institution can: the same people and accounts appearing across many reporting institutions. FinCrimes applies its entity resolution, graph analytics and typology library to that wider view, deployed in-country on infrastructure the authority controls. Intake layouts, institution views and reporting codes are configured to the authority’s mandate during deployment.

See how it works
Network analysisacross institutionsOperational andstrategic analysisConsistent regulatoryfilingsReport intake andtriageExamination evidencefrom supervised institutionsSovereign deploymentand access controlCentral banks andregulatorsPART OF DARK POOLS FINCRIMES
Capabilities

What central banks and regulators gives your team

Network analysis across institutions

When submissions from several institutions load into the authority’s workspace, every account keeps the institution that holds it, taken from the BIC, routing number or bank field of the source record. Entity resolution then links the same person across banks, and the graph shows the flows between them.

  • Sub-threshold cash deposits at several banks surface as one resolved party with accounts at each
  • Mule networks whose accounts sit at different institutions
  • Community detection, fund tracing and cycle detection across the whole reporting population
  • Each institution’s submissions kept as separately lineaged batches

Report intake and triage

STRs, CTRs and transaction data arrive as structured exports, over SFTP or through the ingest API. Mapping templates match each institution’s layout to the platform’s fields, and records that fail validation are quarantined with the reason recorded.

  • A data-quality report and drift check for every submission
  • Report subjects screened against sanctions, PEP and domestic watchlists
  • Transactions scored against the typology library, with alerts routed to queues by severity
  • SLA clocks in business hours against the authority’s own calendar

Operational and strategic analysis

Operational analysis starts from a subject and works outward through the link chart, fund traces, related reports and precedent cases. Strategic analysis looks across the population at which typologies are rising, in which product lines and channels, and where.

  • The 28-typology library as a shared analytical vocabulary
  • Cohort, distribution and trend views over alerts and cases
  • Alert-lifecycle flows from typology to severity to disposition
  • Geographic distribution by city where addresses are supplied

Examination evidence from supervised institutions

Where supervised institutions run FinCrimes, examiners receive evidence they can verify themselves. A case examination pack carries the criteria each alert met, the lineage from ingest to disposition, the ruleset version and verification of a hash-chained custody ledger.

  • Point-in-time reconstruction of the sanctions list in force when a customer was screened
  • Versioned rulesets, backtests and approvals behind every threshold change
  • Recall and adversarial test results for each typology
  • A decision ledger recording every hold and release

Consistent regulatory filings

Reporting institutions on FinCrimes draft STR, SAR and CTR reports as goAML-format XML, using the reporting-entity ID, transaction-mode, funds and indicator codes the FIU issues. Each report is checked for required fields, code-list values and narrative quality, so incomplete reports are caught before they reach the FIU.

  • FIU code lists held as configuration for each jurisdiction
  • Filing deadlines tracked from case to submission
  • A second approver required before any report is filed

Sovereign deployment and access control

The platform deploys on premises, in a government cloud or as a hybrid, with data held in-country. Tenants are isolated on every query and API key.

  • Single sign-on over SAML 2.0 or OIDC, with SCIM user provisioning
  • Maker-checker permissions and a full security event log
  • PII token vault with field classification, retention policies and logged access
  • Separate, isolated tenants can be configured for each institution in a sector the authority hosts
How it works

From data to decision

  1. 01Register sourcesEach reporting institution is set up as a source with its own mapping template and delivery channel.
  2. 02IngestSubmissions arrive by SFTP, API or upload, with a data-quality report and quarantine for failed records.
  3. 03ResolveSubjects resolve across institutions into one party master, and every account keeps its institution.
  4. 04TriageTransactions are scored and subjects screened, and alerts route into queues by severity with SLA clocks.
  5. 05AnalyzeAnalysts trace funds, map networks across institutions and track typology trends over time.
  6. 06DisseminateFindings leave as case reports with the evidence trail, for law enforcement referral or supervisory action.
In the field

Where it is used

FAQ

Questions buyers ask

Get started

Take the next step

See central banks and regulators working on your own data, deployed on infrastructure you control.

Explore FinCrimes