
Aml Cft
- 24 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Assess counter-terrorist and proliferation financing risk: TF typologies, sanctions and asset-freeze workflows, NPO due diligence, and FATF R6-R8 alignment.
About
Guides counter-terrorist and proliferation financing risk covering TF typologies, targeted financial sanctions, CFT STR narratives, NPO due diligence, and FATF R6-R8 alignment. A developer or analyst uses it when scoping CFT/PF controls distinct from a general AML program.
- TF typologies: self-funding, charitable fronts, MVTS, trade-based TF
- Aligns controls to FATF Recommendations 6-8
Aml Cft by the numbers
- 24 all-time installs (skills.sh)
- Ranked #699 of 1,106 Finance & Trading skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill aml-cftAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 24 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Assess counter-terrorist and proliferation financing risk: TF typologies, sanctions and asset-freeze workflows, NPO due diligence, and FATF R6-R8 alignment.
Files
AML / CFT (Counter-Terrorist & Proliferation Financing)
When to Use
- Assess terrorist financing (TF) typologies and red flags distinct from general money laundering
- Design or improve CFT/PF controls, policies, and risk appetite—not a full AML program from scratch
- Scope proliferation financing (PF) and dual-use goods exposure in trade finance or correspondent flows
- Map targeted financial sanctions (TFS), designation lists, and asset freeze operational workflows (conceptual)
- Draft CFT-specific STR/SAR narrative structure and internal escalation fact packs (not filing legal advice)
- Conduct charitable NPO and nonprofit sector due diligence and de-risking decisions
- Evaluate MVTS (money/value transfer services), remittance corridors, and informal value transfer risks
- Address correspondent banking and cross-border TF vulnerabilities and nested-account risks
- Align controls to FATF Recommendations 6–8 and related interpretive guidance at a high level
- Integrate sanctions screening with CFT disposition, true-match escalation, and freeze holds
- Plan CFT training, independent review, and exam readiness for TF/PF-focused questions
When NOT to Use
- Build or mature a full risk-based AML program (KYC tiers, CDD/EDD, TM scenarios, MLRO governance) →
aml-compliance - Implement SOC 2, ISO 27001, or technical control evidence automation only →
compliance-engineer - Internal/IT audit workpapers without CFT/PF or sanctions lens →
auditor - Legal advice, regulatory interpretation as counsel, contract redlines, or filing strategy →
commercial-counsel - Deploy SIEM, screening software engineering, or IAM (primary) →
information-security-engineer - Sanctions API/oracle integration only →
chainalysis-sanctions-screening(pointer), then route CFT context here - Law enforcement investigation tactics, attribution, or victim tracing → blockint /
on-chain-investigator-agentskills - General money laundering typologies without TF/PF angle →
aml-compliance
Related skills
| Need | Skill |
|---|---|
| Full AML program, KYC/CDD, TM tuning, MLRO reporting | aml-compliance |
| Technical SOC/ISO evidence, CCM, control automation | compliance-engineer |
| IT audit testing, workpapers, sampling | auditor |
| Contracts, regulatory interpretation as counsel | commercial-counsel |
| SIEM/EDR, screening system deployment | information-security-engineer |
| FATF glossary definitions (authoritative terms) | fatf-glossary-reference |
| Public sanctions API/oracle (engineering pointer) | chainalysis-sanctions-screening |
| Address/transaction screening UI concepts | address-screening-workflow-concepts, transaction-screening-workflow-concepts |
| Blockchain investigation reports | on-chain-investigator-agent, solana-tracing-specialist |
Core Workflows
1. CFT/PF risk scoping
1. Inventory products, channels, and geographies with TF/PF exposure (NPO, MVTS, trade finance, crypto, correspondent) 2. Document inherent CFT/PF risk separately from general AML inherent risk where useful 3. Map controls to FATF R6–R8 themes (TFS, PF, NPO) at a high level 4. Prioritize gaps with owners, evidence, and trigger-based refresh (new corridor, designation, exam finding)
See `references/aml_cft_scope.md`.
2. Typology-led detection and monitoring
1. Select TF typologies relevant to the business model (self-funding, front NPO, MVTS, trade-based TF) 2. Translate typologies into red flags, scenarios, and analyst investigation playbooks 3. Separate CFT alerts from general AML and fraud where systems differ 4. Tune with documented approvals; track false positives and missed-pattern feedback
See `references/terrorist_financing_typologies.md` and `references/npo_mvts_and_cross_border_cft.md`.
3. PF, dual-use, and trade exposure
1. Identify customers, corridors, and commodities with proliferation or dual-use sensitivity 2. Apply PF red flags (opaque ownership, shell intermediaries, inconsistent shipping docs) 3. Coordinate with trade finance and sanctions teams on holds and escalations
See `references/proliferation_financing_and_dual_use.md`.
4. TFS, screening, and asset freeze
1. Run sanctions and TFS screening with match disposition and audit trail 2. On true match or designation: initiate freeze workflow, block movements, restrict account access (per policy) 3. Document reporting to competent authority where required—escalate legal/compliance for timing and content 4. Manage delisting, unfreeze, and license/Exception pathways only with counsel guidance
See `references/targeted_sanctions_and_asset_freeze.md`.
5. Reporting, governance, and exam readiness
1. Assemble CFT-focused STR/SAR fact packs: TF purpose indicators, networks, channels, NPO links 2. Maintain need-to-know, confidentiality, and record retention per policy 3. Prepare CFT/PF exam samples: TFS policies, NPO procedures, MVTS oversight, training logs, independent review
See `references/reporting_governance_and_exam_readiness.md`.
When to load references
| Topic | Reference |
|---|---|
| Mission, boundaries, handoffs vs aml-compliance | references/aml_cft_scope.md |
| TF typologies and red flags | references/terrorist_financing_typologies.md |
| PF, dual-use, trade-based proliferation | references/proliferation_financing_and_dual_use.md |
| TFS, asset freeze, screening integration | references/targeted_sanctions_and_asset_freeze.md |
| NPO, MVTS, correspondent, cross-border CFT | references/npo_mvts_and_cross_border_cft.md |
| STR narratives, training, independent review, exams | references/reporting_governance_and_exam_readiness.md |
Operating principles
- Typology-first — anchor controls and investigations to known TF/PF patterns, not only ML rules
- Separate TF from ML — document why activity suggests terrorist or proliferation purpose
- No legal conclusions — provide fact packs and draft structures; MLRO/counsel decide filings and freezes
- Sanctions are immediate — treat TFS hits as priority; do not process pending legal comfort informally
- NPO nuance — apply risk-based approach; avoid blanket de-risking without governance
- Label uncertainty — screening and open-source intel are heuristic; document confidence and gaps
AML/CFT scope
Table of contents
1. Mission 2. In scope 3. Out of scope 4. Relationship to aml-compliance 5. Handoffs 6. Operating principles
Mission
Support counter-terrorist financing (CFT) and proliferation financing (PF) compliance and risk management: identify TF/PF exposure, apply typology-led controls, integrate targeted financial sanctions (TFS) and asset freezes, and prepare governance and reporting artifacts. Optimize for purpose-based suspicion (terrorist or proliferation aims) and sanctions immediacy—not for rebuilding enterprise-wide AML customer due diligence or transaction monitoring programs.
In scope
- CFT/PF risk assessment slices (products, channels, geographies, customer types with TF/PF elevation)
- Terrorist financing typologies and investigation playbooks (distinct from ML patterns)
- Proliferation financing and dual-use goods red flags in trade and correspondent contexts
- TFS alignment, designation handling, asset freeze operational steps (conceptual)
- CFT-specific STR/SAR narrative structure and internal escalation packages
- NPO/nonprofit sector due diligence and proportionate de-risking
- MVTS, remittance, and informal value transfer TF risks
- Correspondent and cross-border TF vulnerabilities
- High-level mapping to FATF Recommendations 6–8 and related guidance
- Sanctions screening integration with CFT disposition and freeze holds
- CFT training, independent review, and exam readiness for TF/PF topics
Out of scope
| Topic | Route to |
|---|---|
| Full AML program design (KYC tiers, CDD/EDD, PEP, broad TM) | aml-compliance |
| SOC 2, ISO 27001, HIPAA technical control evidence | compliance-engineer |
| IT audit workpapers, COSO, ITGC without CFT lens | auditor |
| Legal advice, filing sufficiency, regulatory strategy | commercial-counsel / MLRO |
| SIEM rule build, screening engine implementation | information-security-engineer |
| Sanctions API/oracle engineering only | chainalysis-sanctions-screening |
| Law enforcement investigation, attribution, chain tracing | blockint skills |
| Sanctions list curation or government list maintenance | Competent authorities / list publishers |
Relationship to aml-compliance
| Dimension | aml-compliance | aml-cft (this skill) |
|---|---|---|
| Primary focus | Risk-based AML program, KYC/CDD, TM, SAR/STR program | TF typologies, PF, TFS, NPO/MVTS, CFT narratives |
| FATF emphasis | Broader Recommendations (10–23 program elements) | R6–R8 (TFS, PF, NPO) and TF purpose |
| Customer work | CDD/EDD tiers, beneficial ownership, refresh | NPO due diligence, MVTS oversight, correspondent TF |
| Monitoring | ML scenarios, structuring, mule patterns | TF typology scenarios, sanctions freeze triggers |
| Reporting | General SAR/STR program | CFT-flavored fact packs and TF purpose indicators |
| When to use both | New product launch affecting NPO/MVTS/correspondent | Start aml-compliance for program shell; aml-cft for TF/PF slice |
Use aml-compliance first when the user needs an enterprise AML framework. Use aml-cft when the question is specifically terrorist financing, proliferation, TFS, asset freezes, or FATF R6–R8—not when they only mention "AML program" without CFT/PF context.
Handoffs
From `aml-compliance`:
- Receive: customer tiers, screening stack, TM governance, MLRO escalation paths
- Add: TF/PF typology coverage, NPO/MVTS procedures, TFS freeze runbooks, CFT exam topics
To `aml-compliance`:
- Return: gaps in CDD/TM that affect CFT (e.g., missing BO for trade finance) for program-level remediation
To `commercial-counsel`:
- Escalate: freeze legality, license applications, regulatory interpretation, filing decisions
To `information-security-engineer`:
- Request: screening API integration, case management workflows, audit logs—not CFT policy content
Operating principles
- Purpose over placement — TF can involve small, seemingly legitimate flows; document terrorist purpose indicators
- Do not duplicate aml-compliance — link to existing KYC/TM where sufficient; extend only for CFT/PF gaps
- Sanctions first — TFS matches override normal payment processing pending disposition
- Risk-based NPO approach — comply with FATF NPO guidance spirit; avoid discriminatory blanket exits without governance
- No legal determinations — operational guidance only; counsel/MLRO owns filings and regulatory communications
NPO, MVTS, and cross-border CFT
Table of contents
1. NPO sector risk 2. NPO due diligence 3. MVTS and remittance 4. Cross-border and correspondent TF 5. De-risking governance 6. Monitoring scenarios 7. Limitations
NPO sector risk
Nonprofit and charitable organizations are legitimate and often essential. A subset is abused for terrorist financing through diverted donations, affiliate entities, and weak governance.
FATF Recommendation 8 calls for focused, risk-based oversight of NPOs—not blanket exclusion of the sector.
| Risk factor | Examples |
|---|---|
| Governance | No board oversight; related-party transactions |
| Geography | Operations or transfers to conflict/high-TF regions |
| Transparency | No public annual reports; unaudited accounts |
| Flows | Round amounts; rapid pass-through; cash intensity |
| Affiliation | Links to designated persons or sanctioned entities (screening) |
NPO due diligence
Apply proportionate measures by risk tier:
| Tier | Examples | Measures |
|---|---|---|
| Low | Registered local charity, transparent accounts | Standard CDD + sanctions |
| Medium | Cross-border programs, cash collection | EDD elements, purpose verification |
| High | High-risk geography, opaque governance, law enforcement interest | Senior approval, enhanced monitoring, possible exit |
Due diligence elements (select by tier):
1. Verify legal registration and governance structure 2. Understand mission, programs, and geographic footprint 3. Obtain financial statements or alternative assurance where available 4. Identify beneficial owners, directors, and signatories; screen all 5. Document intended use of accounts and expected transaction profile 6. Set transaction limits and alert scenarios aligned to stated purpose 7. Refresh on triggers (media, designation, suspicious activity)
Route legal questions on NPO regulation to commercial-counsel; route CDD policy gaps to aml-compliance.
MVTS and remittance
Money or value transfer services (including remittance providers, currency exchanges, and agent networks) are high-risk for TF when agents lack oversight.
| Control theme | Implementation concepts |
|---|---|
| Licensing | Verify regulatory authorization in each jurisdiction |
| Agent management | Agent agreements, audits, termination for breaches |
| KYC | Sender and beneficiary identification per corridor rules |
| Limits | Caps, velocity controls, structuring detection |
| Corridors | Country risk scoring; deny high-risk where policy requires |
| Settlement | Reconcile nostro/vostro; detect pass-through without economic purpose |
Red flags: unlicensed agents; smurfing across branches; beneficiary lists inconsistent with sender profile; commingling with unrelated commercial flows.
Cross-border and correspondent TF
| Risk | Mitigation concepts |
|---|---|
| Nested accounts | Identify underlying customers; refuse opaque nesting |
| Payable-through | Restrict where policy prohibits |
| Respondent banks | Due diligence, certifications, periodic review |
| Wire stripping | Detect missing originator/beneficiary information |
| Trade overlap | Coordinate with trade finance PF/TF typologies |
| Crypto corridors | VASP due diligence; travel rule where applicable (aml-compliance) |
Document correspondent risk assessment updates when corridors or products change.
De-risking governance
De-risking (terminating relationships or corridors) may be necessary but should be governed:
1. Risk-based decision with documented rationale—not reputation alone 2. Approval by committee or second line for high-impact exits 3. Consider humanitarian impact where relevant (counsel input) 4. Avoid tipping off where law restricts customer explanation 5. Monitor for displacement to less regulated channels (inform management)
Do not use this skill to advise evading regulatory expectations through offshore shells.
Monitoring scenarios
Examples to map to TM or manual review (calibrate locally):
- NPO account outflows to unrelated commercial entities
- Donation spikes after geopolitical events then rapid outbound wires
- MVTS same beneficiary from many senders (mule-like)
- Cross-border wires with incomplete originator data
- Correspondent concentration to high-TF jurisdiction without business rationale
Separate CFT queue or tags where possible for analyst training.
Limitations
- NPO regulatory requirements vary widely by country
- Do not label organizations terrorist without designation or lawful process
- MVTS licensing research is not legal advice
- Correspondent exit decisions need compliance and business alignment
Proliferation financing and dual-use
Table of contents
1. Definitions 2. PF vs TF and ML 3. Dual-use goods and services 4. PF red flags 5. Trade finance and correspondent touchpoints 6. Controls and escalation 7. Limitations
Definitions
Proliferation financing (PF) — providing funds or financial services for the manufacture, acquisition, possession, development, export, trans-shipment, brokering, transport, transfer, stockpiling, or use of nuclear, chemical, or biological weapons and related delivery systems, in violation of national and international obligations.
Dual-use — goods, software, technology, and services that can serve legitimate civilian and proscribed military or WMD-related purposes. Lists and controls vary by jurisdiction (e.g., export control regimes).
This reference supports risk identification and escalation—not export licensing determinations (route to legal/trade compliance).
PF vs TF and ML
| Dimension | PF | TF | ML |
|---|---|---|---|
| Primary aim | WMD / proliferation networks | Terrorist operations | Disguise crime proceeds |
| Customer types | Traders, brokers, shippers, labs | NPO, MVTS, individuals | Varied |
| Geography | Sanctions, proliferation concern states | Conflict zones | Any |
| Documentation | Shipping, end-user, licenses | Donation purpose | Often weak for ML |
| Sanctions link | Strong (designated proliferators) | Strong (terrorist designations) | Secondary |
Many cases touch multiple typologies; document each angle separately.
Dual-use goods and services
Examples (non-exhaustive; jurisdiction-specific):
- Advanced machine tools, CNC, precision manufacturing
- Certain chemicals, biological cultures, toxins (controlled lists)
- Nuclear-related materials, radiation detection, enrichment-related tech
- Missile technology, drones with military specs, navigation/avionics
- Encryption, surveillance, cyber intrusion tools (dual-use in some regimes)
- Research services, university partnerships, intangible technology transfers
Red flag: customer business description inconsistent with ordered goods; sudden product line change; refusal to provide end-user certificate.
PF red flags
| Category | Indicators |
|---|---|
| Ownership | Opaque shells; nominee directors; rapid entity churn |
| Shipping | Misdeclared HS codes; transshipment through hubs; false consignee |
| Payments | Third-party payers; unrelated jurisdictions; prepayment from high-risk banks |
| Documents | Missing or generic end-user statements; reused certificates |
| Behavior | Avoidance of export control questions; split orders under thresholds |
| Sanctions | Partial name matches; affiliated addresses; designated vessel/aircraft lists |
Combine sanctions screening with trade and KYC data—screening alone may miss PF without goods intelligence.
Trade finance and correspondent touchpoints
| Touchpoint | PF consideration |
|---|---|
| Letters of credit | Beneficiary, goods description, ports, parties on docs |
| Documentary collections | Same as LC; watch third-party documents |
| Open account trade | Stronger reliance on ongoing monitoring |
| Correspondent banks | Nested respondent PF exposure; CDD on respondents |
| Crypto / VASP | Token transfers tied to sanctioned proliferator wallets (heuristic) |
Escalate to trade compliance / legal when export control classification is in question.
Controls and escalation
1. Risk assess customers in trade finance, commodities, tech, and research sectors 2. Screen parties, vessels, aircraft, and locations against sanctions and proliferation lists 3. Require end-user and end-use documentation proportionate to risk 4. Train front office and trade ops on PF typologies (not only ML) 5. Freeze on TFS match per policy—do not await ML investigation 6. Report internal STR/SAR consideration when PF purpose suspected—MLRO/counsel decides
Align program narrative to FATF Recommendation 7 (PF) at high level; verify local law for mandatory PF obligations.
Limitations
- Export licensing and classification are legal/regulatory specialties—not decided here
- List-based screening misses non-designated PF networks; use typologies
- Do not provide legal advice on proliferation crimes or filing obligations
- Blockchain analytics cannot prove end-use of goods
Reporting, governance, and exam readiness
Table of contents
1. CFT governance 2. STR/SAR narratives for TF 3. Internal escalation 4. Training 5. Independent review 6. Exam readiness 7. Board and MLRO reporting 8. Limitations
CFT governance
| Element | Purpose |
|---|---|
| CFT/PF policy | TF/PF scope, roles, TFS, NPO, MVTS, escalation |
| Risk assessment | Document TF/PF inherent and residual risk |
| Procedures | Playbooks by typology; freeze; NPO tiers |
| Three lines | Business owns customers; compliance oversees; audit assures |
| Sanctions committee | Complex matches, licenses, de-risking (optional) |
Align policy cross-references to FATF R6–R8 without duplicating full AML program text in aml-compliance.
STR/SAR narratives for TF
Provide fact packs and narrative structure—not legal filing decisions.
Suggested narrative sections
1. Subject — customer name, type (NPO, MVTS, individual), account IDs, relationship length 2. Summary — why TF is suspected in one paragraph (purpose-focused) 3. Activity — dates, amounts, channels, counterparties, instruments 4. TF indicators — typology match (charitable front, MVTS, self-funding, etc.) 5. Sanctions — any TFS matches, freezes, or related designations 6. Open-source / intel — vetted only; cite sources; note confidence 7. Prior filings — reference earlier SAR/STR if continuing activity 8. Action taken — freeze, account closure, law enforcement contact (if any)
TF-specific facts to include
- Links to high-risk geographies or conflict zones
- NPO program inconsistency (collections vs distributions)
- Beneficiary patterns suggesting network support
- Donor anonymity or straw senders
- Trade or MVTS path if used for value transfer
Do not include privileged legal analysis or speculate on criminal charges.
Internal escalation
Analyst → Team lead → AML/CFT compliance → MLRO → Counsel (as needed)
│
└── Freeze / hold (parallel on TFS)| Trigger | Escalation |
|---|---|
| Confirmed sanctions match | Immediate freeze + sanctions team |
| TF typology strong match | Senior compliance within SLA |
| Law enforcement inquiry | MLRO + counsel |
| Media / designation event | Relationship review + rescreen |
Maintain confidentiality and tipping-off awareness per jurisdiction.
Training
| Audience | Topics |
|---|---|
| Front office | TF red flags, NPO basics, sanctions escalation |
| Payments / wire | MVTS, cross-border, incomplete wire data |
| Trade finance | PF dual-use introduction, document red flags |
| Crypto desk | Sanctions, heuristic analytics limits |
| Board / exec | CFT risk appetite, de-risking, major incidents |
Annual refresh plus triggered training after exam findings or typology advisories.
Independent review
Scope examples for second-line or third-line review:
- Sample of sanctions true-match dispositions and timeliness
- NPO high-risk files for due diligence completeness
- MVTS agent oversight files
- CFT alert closure quality vs typologies
- TFS freeze and unfreeze approvals
- Training completion rates
Distinguish AML independent test (broad) from CFT-focused sample—can be a workstream under aml-compliance testing.
Exam readiness
Prepare TF/PF-specific request lists:
| Artifact | Examiner interest |
|---|---|
| CFT/PF risk assessment | Methodology, approvals, refresh |
| TFS policy and procedures | Freeze, rejection, reporting |
| NPO procedure | Tiering, EDD, de-risking |
| MVTS oversight | Agent audits, licensing |
| Sanctions tuning | False positive management |
| Sample cases | TF investigations, freezes |
| Training logs | Role-based completion |
| Independent review | Findings and remediation |
Walkthrough tips: show typology-to-scenario mapping; demonstrate freeze hold on test case; explain NPO risk-based approach vs blanket exit.
Coordinate with auditor for ITGC and access evidence; with aml-compliance for enterprise AML program artifacts.
Board and MLRO reporting
Periodic pack elements (examples):
- CFT/PF KRI trends (sanctions hits, NPO exits, MVTS incidents)
- Geographic and product exposure changes
- Regulatory and FATF mutual evaluation themes (high level)
- Remediation status on CFT findings
- Resource asks (staffing, tooling)
No legal conclusions in board materials—state facts and management actions.
Limitations
- Filing thresholds and formats are jurisdiction-specific—MLRO/counsel decides
- Do not draft law enforcement subpoena responses without counsel
- Exam answers are factual; defer legal interpretations to compliance/legal
- This skill does not replace
aml-complianceenterprise exam prep
Targeted financial sanctions and asset freeze
Table of contents
1. Concepts 2. TFS lifecycle 3. Screening integration 4. Match disposition 5. Asset freeze workflow 6. Delisting and licenses 7. Governance and records 8. Limitations
Concepts
Targeted financial sanctions (TFS) — financial measures directed at named persons, entities, vessels, aircraft, or groups (terrorist, proliferation, territorial integrity, etc.) without necessarily imposing comprehensive country embargoes.
Asset freeze (blocking) — obligation to prevent access to funds and economic resources, hold assets without transfer, and reject transactions benefiting designated parties, subject to jurisdictional rules and exceptions.
Consolidated lists — national and international lists (e.g., UN, OFAC, EU, UK) updated frequently. Multiple list regimes may apply to a single institution.
This reference describes operational concepts—not legal interpretation of sanctions programs.
TFS lifecycle
List update → Screening refresh → Match → Investigation → Disposition
│ │
└──────────── Freeze / Block / Reject ◄────────┘1. Ingest list updates on schedule (intraday where required) 2. Rescreen customer and transaction populations per policy 3. Detect matches (name, alias, ID, vessel IMO, etc.) 4. Investigate true vs false positive with audit trail 5. Act freeze, block, or reject; notify compliance/legal 6. Report to competent authority when mandated 7. Review periodic unfreeze/delisting and license grants
Screening integration
| Layer | CFT role |
|---|---|
| Customer onboarding | Sanctions + PEP at admission; block account opening on true TFS |
| Periodic rescreen | Event-driven and scheduled; include NPO and MVTS agents |
| Payments | Real-time or near-real-time wire screening |
| Trade | Party, bank, vessel, port screening where supported |
| Crypto | Address screening (heuristic); treat as decision support only |
Coordinate with information-security-engineer for feed latency, parsing, and case tooling—not list legal interpretation.
Pointer: chainalysis-sanctions-screening for public API/oracle engineering patterns.
Match disposition
| Outcome | Action |
|---|---|
| False positive | Document rationale; allow processing; retain evidence |
| Possible true match | Hold transaction/account; escalate to sanctions team |
| True match / confirmed designation | Freeze; stop outflows; restrict services per policy |
| Inconclusive | Escalate; do not release pending senior/compliance decision |
Record: analyst, timestamp, list version, matching fields, rationale, approver.
Do not inform the customer of a filing or investigation in ways that violate tipping-off rules—follow local law and policy.
Asset freeze workflow
Conceptual steps (adapt to jurisdictional and institutional policy):
1. Hold accounts and pending transactions immediately on confirmed match 2. Block cards, wires, trading, and crypto withdrawals as applicable 3. Inventory balances, positions, and economic resources (including joint accounts per policy) 4. Notify internal legal/compliance and MLRO 5. File required reports to competent authority within prescribed timelines (counsel confirms) 6. Communicate with relationship managers only on need-to-know basis 7. Document all actions for exam and audit
Reject incoming funds that would benefit a designated party when policy requires rejection vs freeze.
Delisting and licenses
| Situation | Guidance |
|---|---|
| Delisting / name removal | Rescreen; documented unfreeze approval; release holds |
| General or specific license | Only legal/counsel initiates; operations execute approved payments |
| Humanitarian exceptions | Jurisdiction-specific; never assume without written approval |
| Partial hits (e.g., common names) | Enhanced due diligence; do not auto-freeze without policy |
Governance and records
- Policy — TFS scope, roles (first/second line), escalation, freeze authority
- Procedures — match investigation, freeze, rejection, reporting, unfreeze
- Training — tellers, payments ops, trade finance, crypto desk
- Testing — independent review of sample matches and timeliness
- Retention — list versions, match records, freeze logs, authority communications
Map themes to FATF Recommendation 6 (TFS) in program documentation.
Limitations
- Do not advise whether a party is legally designated—that is counsel/list publisher domain
- Do not configure vendor rules as sole compliance control without governance
- No circumvention guidance—ever
- Public screening APIs (e.g., Chainalysis public sanctions) are supplemental, not exhaustive
Terrorist financing typologies
Table of contents
1. TF vs money laundering 2. Core typologies 3. Red flags by typology 4. Investigation prompts 5. Scenario mapping 6. Limitations
TF vs money laundering
| Dimension | Money laundering (ML) | Terrorist financing (TF) |
|---|---|---|
| Primary aim | Disguise illicit proceeds of crime | Fund terrorist acts or support networks |
| Source of funds | Often criminal proceeds | May be legitimate, self-funded, or mixed |
| Transaction size | Often larger, layering focus | May be small, high frequency, purpose-driven |
| Lifecycle stage | Placement, layering, integration | Any stage; reverse flow (funds out for ops) |
| Detection bias | Amount, velocity, jurisdiction risk | Purpose, associates, channels, NPO/trade abuse |
Do not dismiss low-value activity when TF purpose indicators exist.
Core typologies
Self-funding
Individuals or cells use salaries, savings, benefits, or small businesses to fund operations. Funds may appear clean; suspicion rests on behavior, travel, associates, and open-source context.
Charitable and nonprofit fronts
Legitimate or sham NPOs collect donations and divert a portion to designated groups. Typology combines social trust, cross-border transfers, and weak governance.
MVTS and remittance abuse
Licensed or unlicensed money/value transfer services move funds across corridors with limited transparency. Structuring may mirror ML but beneficiary patterns and corridor risk dominate.
Trade-based terrorist financing
Mis-invoicing, over/under-shipment, and commodity trades move value alongside or instead of wire transfers. Overlaps with TBML; add end-user and dual-use concerns for PF overlap.
Cash couriers and stored value
Physical movement of cash, prepaid cards, vouchers, and crypto ATMs—often below thresholds. Document route, handlers, and counterparties.
Crowdfunding and social media solicitation
Online platforms, crypto wallets, and P2P appeals for "humanitarian" causes with opaque ultimate use. Monitor wallet clustering only as decision support with limitations.
State or organized sponsor flows
Large-scale flows from sponsor entities (sanctions-sensitive). Route to TFS and PF references; escalate immediately on designation matches.
Red flags by typology
| Typology | Example red flags |
|---|---|
| Self-funding | Dormant account activation before travel; purchases inconsistent with profile; donations to high-risk causes |
| Charitable front | NPO with no program spend; transfers to unrelated commercial entities; high-risk geography concentration |
| MVTS | Agent without license; split transactions; sender/beneficiary incoherence; weak KYC at agents |
| Trade-based TF | Invoice mismatch; round-dollar shipping; goods inconsistent with stated business |
| Cash / stored value | Repeated sub-threshold deposits; multiple branches same day; voucher churn |
| Crowdfunding | New platform + immediate cross-border outflows; mixer exposure (heuristic only) |
Investigation prompts
When reviewing alerts or cases, document answers where known:
1. Who benefits—individuals, NPO, MVTS agent, shell company? 2. What is the stated purpose—donation, remittance, trade, payroll? 3. Where are corridors and countries—sanctions, conflict, FATF high-risk? 4. When did pattern change—event-linked spikes (conflict, designation)? 5. Why is TF suspected vs ML—purpose indicators, OSINT, law enforcement inquiries? 6. How did funds move—wire, MVTS, cash, trade, crypto (with analytics limits)?
Maintain need-to-know; do not tip off subjects during investigation.
Scenario mapping
Map internal scenarios to typologies for coverage reviews:
| Internal scenario (examples) | Primary typology |
|---|---|
| NPO account → high-risk wire | Charitable front / cross-border |
| Remittance aggregator burst | MVTS |
| Invoice value >> market | Trade-based TF |
| Customer small donations, unknown NGO out | Charitable / crowdfunding |
| Sanctions hit + prior benign history | TFS (see targeted sanctions reference) |
Review false negative feedback from law enforcement typology advisories annually.
Limitations
- Red flags are not proof of TF; combine transaction, KYC, and vetted intelligence
- Open-source and blockchain labels are heuristic; document confidence
- Do not advise law enforcement tactics or covert operations
- Legal filing decisions belong to MLRO/counsel—not this skill