Eight short lessons. Mostly things to click, work out and get wrong, rather than things to read. Every lesson ends on a real case that shows what happens when it goes wrong. About an hour.
No account needed and nothing is collected. Your progress is remembered in this browser only, so use the search above to jump straight to what you need.
Thirty seconds on what's in here, if you want the gist before starting.
Criminal money has one problem. It exists, but it can't be explained. Everything below is the work of making it explainable.
A single small branch in Tallinn handled a vast volume of largely non-resident money, with suspected laundering put as high as $235bn. Nobody carried cash into that branch in bin bags. The money arrived already inside the system and the branch was used to move it.
The point: almost nothing you see will be placement. You are looking at layering, and layering looks like ordinary banking until you ask why.
Don't memorise regulations. Learn the stack. It's the same everywhere and only the names change.
One customer, a jewellery business, deposited around £365m between 2012 and 2016, roughly £264m of it in cash. The bank's monitoring had been configured so that cash deposits were treated as cheques. The FCA brought its first ever criminal prosecution under the Money Laundering Regulations and NatWest was fined £264.8m. The sentencing judge said the bank was "functionally vital" to the laundering.
The point: these regulations are criminal law, not guidance. A configuration error in a monitoring system was enough to convict a bank.
Knowing where you sit tells you what you're allowed to decide. Most new-analyst trouble comes from quietly making somebody else's call.
Wilkinson filed four internal reports in 2013 and 2014, to internal audit and to management in Copenhagen, about what was happening in the Estonian branch. He did exactly what the framework asks a first line employee to do. The bank did not properly respond until 2018, by which point the scandal was public and his name had been leaked to a newspaper.
The point: escalation only works if the lines above act on it. Your duty is to raise it and to leave a record that you raised it.
If a file doesn't fit the rules, that is not a problem to solve on your own. Escalating is doing your job, not failing at it.
Every KYC file answers four questions. Click through the journey to see where each one gets answered.
Between January 2018 and April 2024 around 92% of TD's transaction volume went unmonitored, roughly $18.3 trillion of activity. Whole categories were never covered, and new products were launched without monitoring being extended to them. Three criminal networks moved more than $670m through the accounts. Total penalties came to more than $3bn, the largest Bank Secrecy Act resolution in US history.
The point: a file that never records what normal looks like leaves monitoring with nothing to compare against. At TD there was often no monitoring at all.
Here is a customer pack. Five things in it should stop you. Click anything you think is wrong.
The same case as lesson 2, seen from the counter. Branch staff reported large volumes of Scottish notes being deposited across England, cash that carried a strong musty smell, and individuals behaving oddly. Those observations reached the bank. The FCA found that no appropriate action was ever taken.
The point: the red flags were spotted. People did notice. The failure was everything that happened after somebody raised a hand, which is why "flagged and unresolved" is worse than never flagged.
A red flag is not a finding. It is a question you now have to answer, and your file should record the answer and how you tested it. Flagged and unresolved is worse than never flagged.
Under the UK regulations a beneficial owner of a company is broadly someone holding more than 25% of shares or voting rights, or who otherwise controls it. Thresholds vary, so check yours.
Money leaving the Malaysian state fund was routed through a British Virgin Islands company called Aabar Investments PJS Limited. There was a real Aabar Investments PJS, an Abu Dhabi entity. The shell was named to be mistaken for it. Around $238m went from that company to the production firm behind a Hollywood film.
The point: a name is not an identity. Verify the registration number, the jurisdiction and the registry entry, because a near-identical name is a deliberate technique, not a coincidence.
Trusts have no shares, so there is no percentage. You identify the settlor, the trustees, the beneficiaries (or a description of the class where they are not named), and anyone with control. Some training material adds an income right to a capital right and produces "125% beneficial ownership". Nobody holds more than 100%, and that is not how trusts are assessed.
Source of wealth is the whole story of how someone came to have money. Source of funds is where this particular payment came from. You can satisfy one and completely fail the other.
The country's vice president agreed to give up more than $30m of US assets bought with corruption proceeds, among them a Malibu mansion and a collection of Michael Jackson memorabilia. He held public office. His official salary was a small fraction of what he was spending.
The point: source of wealth is a reconciliation, not a story. When the assets and the known income don't meet, that gap is the finding, and somebody banked all of it along the way.
Does a document link the money to the activity that produced it? Plausible is free. A gift letter moves the question to the giver, it does not answer it.
Effort goes in proportion to risk, and you have to be able to explain the proportion. Switch factors on and watch what it does.
A PEP or a customer connected to a high risk third country takes you to enhanced due diligence regardless of what else is on the file. No amount of good factors scores that away. A PEP is not a criminal and not a refusal, it is a higher corruption risk with a process attached.
The exchange pleaded guilty to failing to maintain an effective anti-money laundering programme and to report suspicious transactions, and paid more than $4bn. Its founder pleaded guilty and stepped down. The business was enormous, profitable and popular. None of that substituted for the reporting obligation.
The point: internal reporting is not admin that supports the real work. In most regimes it is the obligation, and the absence of it is the offence.
Modules 2 to 5 are live in KYC in Practice, with the document matrix builder, a worked file, a screening threshold sandbox and the career module.
Written in a personal capacity for education. General information about how financial crime controls work, not legal or regulatory advice, and not the view of any employer. Rules differ by country and change often, so work from your own firm's policy and your own regulator. Worked examples in the exercises use invented people and companies. The case studies are real and drawn from public regulator statements, court and enforcement records, summarised here for teaching.