
Financial Intelligence Unit
- 24 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Guides Financial Intelligence Unit operations in an AML/CFT program: alert and case triage, financial-flow analysis, typology investigations, and MLRO escalation packs.
About
Guides FIU operations including alert/case intake and triage, financial-flow and counterparty analysis, typology-driven investigations, and MLRO escalation packs. An analyst uses it when running AML case investigations, documenting case files, or preparing internal FIU reporting.
- Typology-driven analysis for structuring, layering, mule, and crypto patterns
- MLRO escalation packs with fact summaries and recommendation options
Financial Intelligence Unit by the numbers
- 24 all-time installs (skills.sh)
- Ranked #699 of 1,106 Finance & Trading skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill financial-intelligence-unitAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 24 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Guides Financial Intelligence Unit operations in an AML/CFT program: alert and case triage, financial-flow analysis, typology investigations, and MLRO escalation packs.
Files
FIU (Financial Intelligence Unit)
When to Use
- Run FIU operations: alert queues, case assignment, triage, and investigation lifecycle
- Perform financial analysis on suspicious activity—flows, networks, counterparties, products, corridors
- Document case files with facts, chronology, hypotheses tested, and disposition rationale
- Prepare MLRO escalation packs—fact summaries, open questions, recommendation options (not filing decisions)
- Apply typology-driven analysis (structuring, layering, mule, trade-based ML, VASP/crypto patterns)
- Coordinate with transaction monitoring, second-line compliance, and investigations (fraud, security)
- Support internal FIU reporting—backlog, SLA, quality metrics, management information (not regulator filing advice)
- Run quality assurance, peer review, and case reconstruction for audits or lessons learned
- Design handover, training, and playbook updates from closed cases and tuning feedback
- Integrate adverse media context at a high level (route deep NLP/sentiment pipelines elsewhere)
When NOT to Use
- Design or mature the full AML/CFT program, policies, KYC tiers, or enterprise risk assessment →
aml-compliance - CFT/PF-only typologies, TFS/asset-freeze programs, or NPO sector controls without general FIU case work →
aml-cft - Draft or finalize STR/SAR narratives for filing templates as the primary deliverable →
str-report - Execute internal/IT audit workpapers, SOC 2 testing, or control effectiveness sampling →
auditor - Implement technical controls, evidence automation, or screening/TM engineering →
compliance-engineer - Legal advice, filing duty, regulatory interpretation, or entity structuring →
commercial-counsel - Per-text sentiment labeling or aggregate sentiment forecasting →
sentiment-analysis-engineer,sentiment-forecasting-engineer - Law enforcement blockchain forensics as primary output → blockint /
on-chain-investigator-agentskills
Related skills
| Need | Skill |
|---|---|
| Full AML program, KYC/CDD, TM scenarios, program governance | aml-compliance |
| STR/SAR narrative structure and filing-oriented drafting | str-report |
| Terrorist financing / proliferation financing typologies | aml-cft |
| IT audit workpapers, control testing, sampling | auditor |
| SOC/ISO evidence pipelines, technical control automation | compliance-engineer |
| Legal interpretation, contracts, filing duty as counsel | commercial-counsel |
| Per-text sentiment / NLP labeling for media streams | sentiment-analysis-engineer |
| FATF standardized terms (STR, CDD, etc.) | fatf-glossary-reference |
| Transaction screening UI and rescreen concepts | transaction-screening-workflow-concepts |
| Behavioral monitoring heuristics (educational) | behavioral-risk-screening-concepts |
| Blockchain tracing for investigation support | on-chain-investigator-agent, solana-tracing-specialist |
Core Workflows
1. Intake and triage
1. Classify source (TM alert, referral, law-enforcement request, ad hoc) 2. Assign priority using risk, amount, SLA, and repeat-subject rules 3. Confirm minimum data before investigation (KYC, alert details, lookback window) 4. Route duplicates, false-positive candidates, and out-of-scope items with coded dispositions
See `references/case_intake_and_triage.md`.
2. Financial analysis and typologies
1. Reconstruct flows (accounts, instruments, corridors, counterparties) 2. Map networks and related parties; separate verified facts from inference 3. Test typology hypotheses against observable indicators; document innocent explanations considered 4. Request blockchain or external intelligence with confidence labels when needed
See `references/financial_analysis_and_typologies.md`.
3. Documentation, QA, and escalation
1. Maintain case chronology, exhibit index, and decision log 2. Run peer review or QA sampling before MLRO handoff 3. Package MLRO escalation: summary facts, suspicion elements, gaps, and options—not legal conclusions 4. Hand off to str-report when narrative drafting for filing is the next step
See `references/escalation_and_mlro_handoff.md` and `references/quality_assurance_and_documentation.md`.
4. Reporting, coordination, and metrics
1. Produce internal MI (volumes, aging, typologies, outcomes)—not filing advice 2. Coordinate with TM on tuning feedback and scenario performance 3. Track backlog, SLA, rework, and quality defect rates 4. Capture training topics and playbook updates from closed cases
See `references/reporting_coordination_and_metrics.md`.
When to load references
| Topic | Reference |
|---|---|
| Mission, boundaries, handoffs | references/fiu_scope.md |
| Queues, prioritization, routing | references/case_intake_and_triage.md |
| Flows, networks, typologies | references/financial_analysis_and_typologies.md |
| MLRO packs and escalation | references/escalation_and_mlro_handoff.md |
| Case files, peer review, QA | references/quality_assurance_and_documentation.md |
| MI, TM coordination, metrics | references/reporting_coordination_and_metrics.md |
Operating principles
- Facts first — chronology and amounts before suspicion narrative
- Typology-led, evidence-bound — hypotheses tied to observable indicators
- Segregation of duties — investigators vs QA vs MLRO; log overrides
- Need-to-know — restrict sensitive case materials; access audited
- No legal filing advice — internal packs and MI only; MLRO/counsel decide filings
- Close the loop — feed TM tuning and training from dispositions and QA findings
Case intake and triage
Table of contents
1. Sources and queues 2. Minimum data checklist 3. Prioritization 4. Routing and assignment 5. Disposition at triage 6. SLA and backlog
Sources and queues
| Source | Typical handling |
|---|---|
| Transaction monitoring | Primary volume; tie to scenario ID and threshold breach |
| Manual referral | Branch, RM, fraud, security; require referrer ID and reason code |
| Periodic / event-driven review | EDD refresh, profile change, geolocation shift |
| External request | Law enforcement, regulator, partner bank—escalate per policy immediately |
| Ad hoc | Executive or audit sample—document sponsor and scope |
Maintain separate queues where regulations or licensing differ (entity, product, corridor). Do not commingle jurisdictions without explicit analyst training.
Minimum data checklist
Before opening a full investigation, confirm:
- Customer ID, legal entity, and CDD tier snapshot
- Alert or referral reference, date range, and scenario/rule name
- Account(s) and instrument(s) in scope
- Amounts and currencies (normalized to reporting currency where used)
- Prior alerts and dispositions on same subject (lookback per policy)
- Sanctions / PEP status at triage (true match vs false positive disposition)
If gaps exist, set status Pending data with owner and due date—do not investigate on incomplete KYC without documented exception approval.
Prioritization
Use a scoring model aligned to policy, for example:
| Factor | Weighting guidance |
|---|---|
| Amount or velocity | Higher notional or rapid movement increases score |
| High-risk geography / corridor | Elevate per risk assessment |
| PEP / sanctions touchpoint | Elevate; may mandate immediate senior review |
| Repeat subject | Prior STR consideration or open case increases score |
| Scenario severity | Critical scenarios (e.g., known typology) override FIFO |
| SLA proximity | Time-to-breach boosts queue position |
Document priority override with approver when analysts reprioritize outside the model.
Routing and assignment
- Skill-based routing: complex trade finance, crypto, correspondent, or corporate structures
- Capacity balancing: cap WIP per analyst; supervisor rebalances daily
- Conflict check: analyst must not investigate own onboarding or overrides they performed
- Escalation path: team lead → FIU manager → MLRO for threshold breaches
Disposition at triage
| Code | When to use |
|---|---|
| Close – no investigation | Obvious false positive with documented reason (e.g., payroll pattern explained) |
| Close – duplicate | Same underlying activity as open or recently closed case |
| Investigate | Minimum data met; typology or risk warrants analysis |
| Refer – fraud | Primary loss or account takeover indicators |
| Refer – security | Cyber or internal theft indicators |
| Refer – CFT | TF/PF-specific indicators without broader ML case |
| Pending data | Hold with tracker until KYC/TM data retrieved |
All dispositions require actor, timestamp, and free-text rationale retrievable for audit.
SLA and backlog
- Define SLA by priority tier (e.g., P1 24h, P2 72h, P3 10 business days)—adjust to license and risk appetite
- Report aging buckets (0–3d, 4–7d, 8–14d, 15+d) in daily stand-up
- Escalate breaches with root cause: volume, staffing, data latency, rework
- Cap reopen rate tracking—frequent reopens signal triage or QA issues
Feed false positive closures back to TM with structured fields (scenario, reason code, sample tx IDs) for tuning governance.
Escalation and MLRO handoff
Table of contents
1. Escalation triggers 2. MLRO pack structure 3. Suspicion mapping 4. Options and recommendations 5. Handoff to STR drafting 6. Post-MLRO actions
Escalation triggers
Escalate to MLRO (or designated delegate) when any apply:
- Policy mandatory escalation (amount, typology, PEP, sanctions nexus)
- Unresolved suspicion after investigation steps completed
- Repeat subject with prior STR consideration or open regulatory matter
- Cross-border or multi-entity complexity beyond analyst authority
- Media, law enforcement, or partner bank involvement
- Control failure or systemic issue affecting multiple customers
- Analyst recommends STR/SAR consideration regardless of threshold
Document who escalated, when, and prior reviews (QA sign-off where required).
MLRO pack structure
| Section | Content |
|---|---|
| Cover | Case ID, entity, subjects, analyst, dates, classification |
| Executive summary | 5–10 sentences: what happened, why it matters, recommended next step |
| Subject profile | Customer type, CDD tier, PEP/sanctions, relationship length |
| Chronology | Key dates and events (table) |
| Financial summary | Aggregated amounts, accounts, corridors, instruments |
| Suspicion mapping | Facts linked to typologies / red flags |
| Innocent explanations | Tested and outcome |
| Gaps | Missing data; follow-up owner |
| Exhibits | Numbered index with description |
| Prior history | Alerts, cases, filings (internal reference only) |
| Options | See below—not a legal filing decision |
Restrict distribution per need-to-know; watermark or classify per policy.
Suspicion mapping
Use a matrix:
| Red flag / indicator | Supporting fact (tx ID, date, amount) | Typology | Analyst assessment |
|---|---|---|---|
| Example: rapid movement | Tx list attached | Layering | Supported |
Avoid legal conclusions (“money laundering proved”). Use suspicious indicators language aligned to internal policy and FATF concepts via fatf-glossary-reference when helpful.
Options and recommendations
Present options, not decisions, for MLRO:
| Option | When appropriate |
|---|---|
| Close with rationale | Hypotheses tested; innocent explanation evidenced; low residual risk |
| Continue investigation | Gaps remediable; additional lookback needed |
| STR/SAR consideration | Indicators meet internal threshold; hand to narrative drafting |
| Refer CFT | TF/PF-specific angle → coordinate with aml-cft |
| Refer fraud / security | Non-AML primary |
| Exit / offboard | Policy-driven relationship decision (with compliance approval) |
| Law enforcement liaison | Per policy and counsel guidance |
MLRO selects option; do not state “must file” unless user explicitly requests counsel skill.
Handoff to STR drafting
When MLRO directs STR/SAR preparation:
1. Transfer MLRO pack and exhibit index to str-report workflow 2. Avoid duplicating investigation—narrative skill assembles who/what/when/where/why 3. List open questions for narrative author explicitly 4. Maintain case master record in FIU system of record
Post-MLRO actions
- Record MLRO decision, date, and rationale in case system
- If closed: apply closure code and TM feedback
- If STR path: track draft, review, approval statuses (FIU may QA facts, not replace MLRO sign-off)
- Schedule retrospective for systemic issues (tuning, training, policy)
- Retention per jurisdictional schedule; restrict access post-filing
Financial analysis and typologies
Table of contents
1. Analysis framework 2. Flow reconstruction 3. Networks and counterparties 4. Typology catalog 5. Crypto and VASP considerations 6. Innocent explanations 7. External intelligence
Analysis framework
1. Scope — subjects, accounts, date range, products, jurisdictions 2. Baseline — expected activity from KYC, RM notes, and historical profile 3. Deviation — quantify vs baseline (amount, count, velocity, geography) 4. Hypothesis — typology-led; multiple hypotheses allowed 5. Test — gather evidence; reject or support each hypothesis 6. Conclusion — suspicion level for internal use; gaps and next steps
Separate verified data (core banking, TM, KYC) from inference (heuristic blockchain labels, media).
Flow reconstruction
| Element | Document |
|---|---|
| Timeline | Ordered events with UTC/local assumption stated |
| Legs | Debit/credit, rail (wire, ACH, card, crypto), fees |
| Aggregation | Related txs grouped (same counterparty, round amounts, rapid in/out) |
| Round-tripping | Funds leaving and returning via related accounts |
| Layering indicators | Multiple hops, pass-through, short dwell time |
Use tables: date, amount, currency, account, counterparty, type, reference, analyst note.
Networks and counterparties
- Map direct counterparties (name, country, bank, VASP if applicable)
- Identify related parties (UBO, common address, device, IP where policy allows)
- Flag high-risk jurisdictions and sectors per risk assessment
- Document unknown counterparties explicitly—do not invent entity names
- For nested relationships, attach simple diagram or adjacency list in case file
Typology catalog
| Typology | Observable indicators (examples) |
|---|---|
| Structuring | Just-below threshold deposits; smurfing patterns |
| Layering | Rapid movement across accounts/institutions; pass-through |
| Integration | Sudden use of funds for assets inconsistent with profile |
| Trade-based ML | Over/under invoicing; mismatched goods and flows |
| Mule / funnel | Many small inflows, single outflow; dormancy then burst |
| Correspondent abuse | Nested accounts; payable-through without due diligence |
| VASP / crypto | Exchange hops, mixer exposure (heuristic), travel rule gaps |
| Identity abuse | Profile mismatch; synthetic identity signals from KYC |
Tie each indicator to specific transactions or events—avoid generic typology labels without facts.
Crypto and VASP considerations
- Use blockchain analytics as decision support; document label confidence
- Record wallet addresses, chains, and tx hashes in exhibit index
- Note travel rule data completeness where relevant
- Route deep forensic narratives to blockint skills; FIU integrates summary into case file
- Do not treat heuristic clustering as proof of ownership
Innocent explanations
For each material deviation, record:
- Hypothesis (e.g., payroll, tuition, property sale, intra-group transfer)
- Evidence checked (payslip, invoice, public record, RM confirmation)
- Outcome — supported, rejected, or unresolved
Unresolved explanations increase escalation likelihood; do not close solely because a plausible story exists without evidence.
External intelligence
| Source | Use in FIU |
|---|---|
| Adverse media | High-level relevance check; route NLP depth to sentiment-analysis-engineer |
| Commercial screening | True-match disposition already in KYC; do not re-litigate without new hits |
| Law enforcement / partner bank | Restricted handling; document receipt and response |
| Blockchain intelligence | Summary with confidence; attach provider report as exhibit |
Record date, source, and analyst interpretation for each external pull.
FIU scope
Table of contents
1. Mission 2. In scope 3. Out of scope 4. Handoffs 5. Operating principles 6. Deliverable patterns
Mission
Operate the Financial Intelligence Unit (FIU) as the investigative and analytical arm of an AML/CFT program. Convert alerts and referrals into defensible case files: triage, financial analysis, typology testing, documentation, quality review, and MLRO-ready escalation packs. Optimize for throughput with quality, clear audit trails, and feedback into transaction monitoring—not for substituting enterprise policy design, legal filing decisions, or IT audit fieldwork.
In scope
| Domain | Examples |
|---|---|
| Intake & triage | Queue management, prioritization, duplicate handling, disposition codes |
| Investigation | Flow reconstruction, counterparty mapping, product/channel context |
| Typologies | ML patterns (structuring, layering, mules, trade-based ML, crypto/VASP) |
| Case documentation | Chronology, exhibit index, hypotheses tested, analyst notes |
| QA / peer review | Sampling, rework, standards, lessons learned |
| MLRO escalation | Fact packs, suspicion elements, gaps, options (not filing advice) |
| Internal reporting | Backlog, SLA, typology mix, outcome metrics, management MI |
| Coordination | TM tuning input, compliance second line, fraud/security investigations |
| Training & handover | Playbooks, shadowing, shift handover checklists |
Out of scope
| Topic | Route to |
|---|---|
| Enterprise AML/CFT policy, risk assessment, KYC program design | aml-compliance |
| STR/SAR narrative drafting as primary filing deliverable | str-report |
| CFT/PF-only programs, TFS/asset freeze, NPO sector controls | aml-cft |
| Internal/IT audit workpapers and control testing | auditor |
| Technical evidence automation, SOC/ISO control implementation | compliance-engineer |
| Legal filing duty, regulator strategy, entity structuring | commercial-counsel |
| Deep sentiment/NLP pipelines for media | sentiment-analysis-engineer |
| Primary blockchain LE investigation reports | blockint skills |
Handoffs
From transaction monitoring / first line:
- Provide: alert ID, scenario, thresholds, lookback, customer profile snapshot, prior alerts
- Receive: disposition, tuning feedback, and documented rationale for closure or escalation
To MLRO / `str-report`:
- Deliver: verified fact pack, chronology, suspicion mapping, exhibit index, open questions
- Request: STR/SAR narrative drafting when filing preparation is the next step—not duplicate investigation
To `aml-compliance`:
- Escalate: systemic control gaps, policy exceptions, program-level risk changes
- Do not: rewrite enterprise AML policy inside a single case file
To `auditor`:
- Provide: sample cases, QA results, disposition codes, access logs for independent review
- Distinguish: FIU QA (second-line operations) vs third-line audit plan
To blockint / investigation skills:
- Request: on-chain traces and entity labels with confidence; FIU owns case disposition and internal narrative
Operating principles
- Investigate to standard — same minimum steps for like cases; avoid ad hoc shortcuts
- Document as you go — contemporaneous notes; reconstructable by another analyst
- Separate facts and inference — label assumptions and data gaps explicitly
- Escalate early — complex typologies, high amounts, PEP/sanctions touchpoints, media attention
- Protect confidentiality — need-to-know access; no casual sharing of suspicion details
- No legal conclusions — describe suspicious indicators; MLRO/counsel decide filings
Deliverable patterns
| Deliverable | Contents |
|---|---|
| Triage note | Source, priority, minimum data check, route/assign |
| Investigation memo | Chronology, flows, typology assessment, innocent explanations |
| MLRO pack | Executive summary, facts, suspicion elements, gaps, recommendation options |
| QA record | Reviewer, findings, rework required, sign-off |
| MI slide / table | Volumes, aging, outcomes, top typologies, SLA breach drivers |
Quality assurance and documentation
Table of contents
1. Case file standards 2. Documentation elements 3. Peer review 4. QA sampling program 5. Defect taxonomy 6. Rework and sign-off 7. Audit and exam support
Case file standards
Every investigated case should be reconstructable by a second analyst without oral history.
| Standard | Requirement |
|---|---|
| Completeness | Triage, analysis, disposition, approvals present |
| Accuracy | Amounts match source systems; currency assumptions stated |
| Clarity | Facts vs opinion labeled |
| Traceability | Source system, pull date, and query parameters noted |
| Timeliness | Contemporaneous notes; late additions flagged |
| Access control | Need-to-know; no copies in unsecured channels |
Documentation elements
Minimum artifacts by stage:
| Stage | Artifacts |
|---|---|
| Triage | Priority score, minimum data check, route/disposition |
| Investigation | Chronology table, flow summary, typology worksheet |
| Analysis | Hypothesis log, innocent-explanation tests |
| Escalation | MLRO pack (if applicable) |
| Closure | Final rationale, closure code, TM feedback fields |
| QA | Reviewer checklist, findings, rework record |
Exhibit index: number, title, source, date obtained, sensitivity.
Decision log: date, actor, decision, rationale (overrides, priority changes, reopen).
Peer review
Use peer review before MLRO escalation when policy requires or case exceeds thresholds.
Reviewer confirms:
- Scope appropriate; no material txs omitted
- Typologies tested against facts
- Innocent explanations documented
- Escalation pack complete and internally consistent
- No prohibited language (legal conclusions, guaranteed filing)
Peer reviewer must not be the primary analyst or the KYC officer who approved exceptions on same customer.
QA sampling program
| Parameter | Guidance |
|---|---|
| Population | All closed and escalated cases in period |
| Sample size | Risk-based: higher for new analysts, new scenarios, STR-path cases |
| Frequency | Monthly operational QA; quarterly thematic deep dives |
| Themes | Structuring, crypto, PEP, high-value, repeat subjects |
Score cases with a rubric (see defect taxonomy). Trend scores by team, scenario, and source system.
Defect taxonomy
| Severity | Examples |
|---|---|
| Critical | Wrong disposition; missed mandatory escalation; factual error on amount/subject |
| Major | Incomplete chronology; untested typology; missing innocent-explanation review |
| Minor | Formatting; typo in non-material field; late but complete documentation |
| Advisory | Style; optional enhancement |
Critical defects require rework and supervisor sign-off before closure stands.
Rework and sign-off
1. QA issues finding sheet with severity and due date 2. Analyst remediates with tracked changes 3. Reviewer re-checks remediated items only or full file per severity 4. Supervisor signs off on critical/major closure 5. Feed root cause into training and playbooks
Audit and exam support
For auditor or regulator requests:
- Provide sample lists with case ID, disposition, date, analyst (not full narrative in email)
- Redact third-party and LE-sensitive material per policy
- Explain QA methodology and metrics trend
- Distinguish FIU QA from independent AML testing (
aml-compliancescope)
Do not alter historical records; attach addenda for corrections with approver.
Reporting, coordination, and metrics
Table of contents
1. Internal management information 2. Metrics catalog 3. Coordination with transaction monitoring 4. Coordination with compliance and investigations 5. Regulatory reporting support 6. Training and handover 7. Dashboard cadence
Internal management information
FIU MI supports MLRO, COO, and risk committees—not external filing.
| Report | Audience | Typical contents |
|---|---|---|
| Operations dashboard | FIU manager | Volumes, backlog, SLA, staffing |
| Outcome summary | MLRO | Escalations, closures, STR-path counts |
| Typology trends | Risk / TM | Top scenarios, emerging patterns |
| Quality scorecard | FIU + QA lead | Defect rates, rework, thematic findings |
State limitations: data lag, definition changes, and one-off events affecting trends.
Metrics catalog
| Metric | Definition notes |
|---|---|
| Alert / case volume | By source, entity, product, scenario |
| Aging | Days open from triage or assignment; bucketed |
| SLA adherence | % closed within tier target |
| Analyst productivity | Cases closed per FTE (normalize for complexity) |
| Escalation rate | % to MLRO; % STR-path |
| Rework rate | QA failures / cases reviewed |
| False positive feedback | Closed at triage or post-investigation with TM reason codes |
| Repeat subjects | Customers with N cases in rolling window |
| Typology distribution | Primary typology tag at closure |
Avoid single-metric incentives that encourage premature closure; pair productivity with quality scores.
Coordination with transaction monitoring
Structured feedback loop:
1. Tuning requests — scenario ID, sample case IDs, proposed change, expected impact 2. False positive reviews — monthly joint session with documented outcomes 3. New product / corridor — FIU input on typologies before go-live (aml-compliance owns risk sign-off) 4. Model validation support — labeled outcomes for back-testing where governance requires
Log TM changes with version, approver, and effective date—FIU references version in cases affected.
Coordination with compliance and investigations
| Partner | FIU role |
|---|---|
| Second-line AML compliance | Policy interpretation requests; thematic reviews; issue tracking |
| Fraud operations | Referrals with handoff template; avoid duplicate interviews |
| Security / cyber | Account takeover vs ML distinction |
| Legal / counsel | Fact packs only; no filing strategy from FIU |
| CFT specialists | TF/PF cases → aml-cft collaboration on same case ID |
Use shared case IDs or links across systems; never parallel undocumented investigations on same subject.
Regulatory reporting support
FIU may assemble factual extracts for MLRO or regulatory requests:
- Aggregate STR counts (internal)
- Trend narratives on typologies (non-legal)
- Population descriptions for statistical reporting
Do not:
- Advise whether a filing is legally required
- Draft final regulator submissions without MLRO/counsel
- Replace
str-reportfor narrative assembly
Coordinate exam requests with aml-compliance and auditor—FIU provides case samples and QA evidence.
Training and handover
| Activity | Purpose |
|---|---|
| Playbook updates | Capture QA themes and new typologies |
| Case studies | Anonymized closed cases for induction |
| Shadowing | New analysts on live queues with reviewer |
| Shift handover | Open P1/P2 cases, breaches, LE-sensitive items |
| Lessons learned | Post-incident or post-exam findings |
Track training completion in HR/LMS where required; link to competency matrix (retail vs corporate vs crypto).
Dashboard cadence
| Cadence | Forum |
|---|---|
| Daily | Stand-up: backlog, breaches, LE items |
| Weekly | TM feedback; staffing |
| Monthly | MI to MLRO; QA scorecard |
| Quarterly | Thematic review; playbook refresh |
Archive dashboards with definitions so period-over-period comparisons remain valid.