Skip to main content
Should You Merge Your AML and Fraud Teams?Customer Due Diligence
5 min readFor MLROs

Should You Merge Your AML and Fraud Teams?

The question isn't whether financial crime crosses organizational boundaries. It does. The question is whether your institution's structure acknowledges that reality or fights it.

Money laundering and fraud prevention typically operate as separate functions with distinct budgets, reporting lines, and technology stacks. Meanwhile, criminal operations run as integrated enterprises. A stolen child's identity becomes a synthetic profile that passes your onboarding checks, receives scam proceeds, and serves as a mule account in a layering scheme. Your fraud team sees the scam. Your AML team sees the structuring. Neither connects them because they're not designed to.

This structural gap isn't just inefficient. It's creating blind spots that regulators are starting to penalize.

The Case for Integration

Merging AML and fraud functions is supported by three observations about how financial crime actually works.

First, criminal typologies don't respect your org chart. Human trafficking generates small, repeated payments through peer-to-peer applications. The amounts sit below AML thresholds, but the pattern matters. Fraud teams might flag the velocity. AML teams might notice the beneficiary network. Neither perspective alone reveals the full picture.

Second, your control environment can't scale if it's duplicated. Starling Bank's £28.96 million fine in 2024 illustrates this. The bank grew from roughly 43,000 customers in 2017 to 3.6 million in 2023, but its control framework stayed essentially static. More problematic: its automated sanctions screening had been running against only a fraction of the full sanctions list since 2017. If sanctions screening and fraud prevention are separate systems drawing from separate customer data repositories, you're maintaining two incomplete views instead of one accurate one.

Third, data quality failures compound when systems don't talk to each other. A customer loses their job, direct deposits stop, and funds start arriving from accounts linked to a mule network. That person has moved from fraud victim to money laundering participant, knowingly or not. If your fraud team updates the customer's status but your AML risk rating doesn't refresh automatically, you're making decisions on stale information.

The integrated model promises efficiency: one customer data repository, one screening engine, one case management workflow, one set of investigators trained to recognize both fraud and laundering patterns.

The Case for Separation

The counterargument starts with regulatory reporting requirements.

Suspicious Activity Reports under the Bank Secrecy Act have specific filing obligations, timelines, and confidentiality rules that don't apply to fraud cases. Counter-Terrorist Financing investigations trigger Targeted Financial Sanctions obligations under FATF Recommendation 6, including freezing without delay. Fraud losses go to your operational risk function and your insurer. Merging the teams means training every investigator on every framework, which dilutes expertise.

Second, the skill sets diverge more than they overlap. Fraud analysts excel at behavioral pattern recognition and real-time decisioning. They're stopping a transaction before it completes. AML analysts work retrospectively, building evidence trails that meet the reasonable grounds threshold for a SAR. They're documenting a suspicion after the fact. The investigation tempo is different. The evidence standards are different. The technology requirements are different.

Third, separation creates accountability. If AML and fraud share a budget and a director, which function gets priority when resources are tight? Fraud losses are immediate and measurable. AML failures show up years later in enforcement actions. The incentive structure favors the urgent over the important, and money laundering controls suffer.

Finally, there's a practical concern about information barriers. Tipping off prohibitions mean that once an AML investigation is underway, you cannot disclose that fact to the customer or to internal teams that might inadvertently reveal it. If your fraud team shares case management systems with AML, you're creating disclosure risks every time someone accesses a file.

Where Practitioners Actually Land

Most institutions haven't merged the functions entirely, but they've stopped pretending the wall between them makes sense.

The common middle ground is operational coordination with structural separation. AML and fraud remain distinct teams with separate reporting lines, but they share customer data platforms, meet weekly to review cross-functional cases, and maintain joint escalation protocols for high-risk scenarios.

The shared data layer is non-negotiable. You can't run effective Customer Due Diligence if your fraud team has updated address and device information that your AML risk rating doesn't reflect. Duplicate records, incomplete identifiers, and stale party data limit both functions equally.

Information sharing is the other practical necessity. The FCA's enforcement actions against Starling and Monzo (fined £21.1 million) both highlighted failures that crossed functional boundaries. Monzo opened accounts against implausible addresses and didn't consistently verify beneficial owners on business accounts. Those are onboarding failures that affect both fraud exposure and AML obligations, and they require a coordinated response.

Some institutions have created financial crime fusion centers where AML analysts, fraud investigators, and sanctions specialists sit together physically and work from shared case queues. The reporting lines stay separate, but the information flow is real-time.

Our Take

Full integration is the wrong answer for most institutions, but so is the status quo.

The regulatory frameworks are distinct enough that you need specialized expertise in both domains. A fraud analyst shouldn't be filing SARs without AML training, and an AML analyst shouldn't be making real-time transaction decisions without understanding fraud typologies. Merging the teams means either training everyone on everything, which is expensive and slow, or creating generalists who handle neither function well.

But separation without coordination is creating the blind spots that criminals exploit systematically. One in fifty children in the United States are affected by identity theft annually. Those stolen identities become synthetic profiles that pass your sanctions screening, generate no adverse media, and fail only when someone asks whether a 25-year-old could plausibly have no credit history. That question sits between your fraud team's device intelligence and your AML team's identity verification, and if those teams don't compare notes, nobody asks it.

The better model is shared infrastructure with distinct accountability. One customer data platform. One screening engine. One set of risk ratings that both teams update and consume. But separate case management workflows, separate reporting lines, and separate training programs that reflect the different regulatory obligations each team carries.

Test whether your current structure allows a fraud analyst to see that a customer's income source just changed and an AML analyst to see that the same customer's device was flagged in a scam network. If that information doesn't flow in both directions automatically, your organizational chart is working against you.

You Might Also Like