Skip to main content
Can You Justify This Wire? A Direct AML Investigation ChecklistAML and KYC
5 min readFor AML/KYC Compliance Officers

Can You Justify This Wire? A Direct AML Investigation Checklist

You've flagged a transaction. The customer's wire pattern shifted three weeks ago, or a PEP connection surfaced during enhanced due diligence. Now what? The gap between detecting a red flag and filing a Suspicious Activity Report (SAR) is where most AML programs either prove their value or expose their weaknesses.

This checklist guides you through the investigation phase, helping you determine whether an anomaly is explainable business activity or grounds for regulatory reporting. It's designed for compliance officers who need a clear, actionable framework.

Prerequisites

Before starting an investigation, ensure you have:

  • Access to the complete transaction history for the flagged customer, including timestamps, counterparties, amounts, and transaction types. You should be able to pull six months of activity in under five minutes without IT support.

  • The customer's current risk profile and KYC documentation on hand, including their stated business purpose, expected transaction volume, and geographic footprint. Ideally, this is in a single file or system view that shows baseline expectations alongside current behavior.

  • A documented escalation path to management and legal counsel. Know exactly who reviews your findings, within what timeframe, and have their direct contact information.

  • A secure case management system where you can log investigation steps, client communications, and decisions without mixing them into email threads. Every action should be timestamped and auditable.

Investigation Checklist

1. Document the Red Flag Trigger

Record what caused the alert: a transaction monitoring rule, a manual review, a third-party screening hit, or a referral from another department. Include the specific threshold or pattern that triggered it.

Example: "Customer exceeded $50,000 aggregate monthly wire volume for the first time; baseline expectation was $10,000, $15,000 per KYC onboarding interview conducted 2023-08-14."

2. Contact the Customer Directly

Reach out to the customer and ask them to explain the change in transaction pattern or the flagged activity. Frame your questions around their stated business purpose. If they're a commercial client, ask for supporting documentation like invoices, contracts, or shipping records.

Example: You have a written or recorded response from the customer within 72 hours, and you've documented their explanation verbatim before analyzing it.

3. Collect Transactional Evidence

Pull wire instructions, beneficiary details, originating account information, and any reference fields or memos attached to the transactions. Cross-check counterparty names against your sanctions and watchlist screening tools.

Example: You've verified that every counterparty in the flagged transactions has been screened against current OFAC, UN, and EU sanctions lists, and you've documented the screening results in your case file.

4. Compare Against the Customer's Risk Profile

Does the customer's explanation align with their stated occupation, business model, and geographic footprint? If they're a retail business owner wiring funds to a free trade zone, does that match their supply chain? If they're receiving funds from a Politically Exposed Person (PEP), was that relationship disclosed during onboarding?

Example: You've written a two-paragraph narrative that either confirms consistency ("Customer provided invoices showing new supplier relationship in declared business line") or flags inconsistency ("Customer could not explain why a personal account is receiving wires from a corporate entity in a high-risk jurisdiction").

5. Evaluate the Customer's Justification

If the customer provided an explanation, assess whether it's credible and supported by documentation. A vague answer ("business expenses") or a refusal to provide records is itself a red flag.

Example: You've rated the explanation as either "substantiated with documentation," "plausible but unsupported," or "inconsistent with known facts," and you've noted which category applies in your case notes.

6. Escalate to Management if Justification Fails

If the customer cannot justify the transactions, or if their explanation conflicts with known information, escalate your findings to the designated AML manager or compliance officer. Include your analysis and recommendation.

Example: Management receives a written summary within 24 hours of your determination, and you've logged the escalation timestamp in your case file.

7. Determine Whether to File a SAR

Work with management and legal counsel to decide if the activity meets the threshold for filing a Suspicious Activity Report with FINTRAC (in Canada) or FinCEN (in the United States). Consider whether the activity involves structuring, sanctions evasion, trade-based money laundering, or other typologies.

Example: You've documented the decision rationale in writing, whether you file or not, and you've noted the specific regulatory threshold or typology that applies.

8. Document the Full Investigation

Compile all customer communications, transactional evidence, screening results, and your analysis into a single case file. Include timestamps for every step. This documentation is your defense in an examination.

Example: An examiner can reconstruct your entire investigation from your case notes without asking follow-up questions, and every decision point has a clear justification.

9. Close the Case or Initiate Ongoing Monitoring

If you file a SAR, continue monitoring the customer for related activity. If you close the case without filing, document why the activity was deemed non-suspicious and set a review interval to confirm the pattern doesn't recur.

Example: You've set a calendar reminder to review the customer again in 30 or 60 days, and you've updated their risk profile to reflect the investigation outcome.

Common Mistakes

Waiting too long to contact the customer. The longer you delay, the harder it is to reconstruct the business context. Reach out within 48 hours of flagging the transaction.

Accepting vague explanations without documentation. "Business purposes" or "personal reasons" isn't enough. Push for invoices, contracts, or other records.

Failing to screen counterparties. You can't evaluate ML/TF risk without knowing who's on the other side of the wire. Run every name through your sanctions and PEP screening tools.

Mixing investigation notes with unrelated emails. Keep your case file separate and structured. Email threads aren't auditable.

Skipping the escalation even when you're uncertain. If you're on the fence, escalate. Management and legal counsel exist to help you make the call.

Next Steps

After completing this checklist, review your investigation queue. Are certain transaction types or customer segments generating repeat red flags? That's a signal to adjust your risk-based approach by refining your monitoring rules or enhancing due diligence at onboarding.

Schedule a quarterly review with your AML manager to assess case closure rates, SAR filing trends, and investigation turnaround times. If you're consistently closing cases without filing, or if your average investigation takes more than two weeks, your program needs recalibration.

Your investigation process is the bridge between detection and action. Make it repeatable, auditable, and fast enough to matter.

You Might Also Like