Switzerland's consideration of joining the International Anti-Corruption Coordination Centre (IACCC) isn't just diplomatic positioning. It's a signal that bilateral information-sharing agreements and national-level investigations no longer scale against modern money laundering operations. The IACCC has identified £1.8 billion in suspected stolen funds and frozen £641 million in assets since its founding. That success comes from structured intelligence fusion, not heroic individual investigations.
Your compliance team faces the same problem at an institutional scale. Money launderers don't operate within your transaction monitoring system's view. They split activity across institutions, jurisdictions, and payment rails. You're fighting a network problem with a single-node defense.
This guide walks you through building a cross-institutional intelligence-sharing capability that mirrors the IACCC model. You won't be sharing intelligence with foreign governments, but you can share typologies, Indicators of Compromise (IoCs), and risk signals with peer institutions through structured frameworks.
What You Need Before Starting
Legal clearance on information sharing frameworks
You can't share customer PII or transaction details without explicit legal authority. You can share:
- Anonymized typologies (behavioral patterns without identifiers)
- Indicators of Compromise (wallet addresses, shell company patterns, routing behaviors)
- Threat actor TTPs (tactics, techniques, procedures)
Work with legal counsel to document what falls under permissible sharing under the Bank Secrecy Act, FATF Recommendations, and any applicable state privacy laws. The Wolfsberg Principles provide guidance on correspondent banking information exchange; adapt those frameworks for peer-to-peer sharing.
Access to a trusted peer network
You need 3-5 institutions willing to participate. Start with:
- Correspondent banking partners you already have due diligence relationships with
- Industry working groups (regional banking associations, fintech consortiums)
- Sector-specific ISACs (Information Sharing and Analysis Centers)
Financial Services ISAC (FS-ISAC) membership gives you a structured channel. If you're a fintech, consider forming a bilateral arrangement with your sponsor bank first.
Technical infrastructure for anonymized data exchange
You need a mechanism to share indicators without exposing customer data. Options include:
- Structured Threat Information Expression (STIX) format for IoC exchange
- A shared secure portal (many ISACs provide this)
- Encrypted email with PGP if you're starting small
Defined use cases and success metrics
Don't build this to "share intelligence generally." Pick two specific money laundering typologies you're seeing repeatedly and want help detecting earlier. Examples:
- Trade-based money laundering through over/under-invoicing
- Structuring across multiple institutions (classic smurfing)
- Nested correspondent account abuse
Step-by-Step Implementation
Step 1: Establish the governance framework (Week 1-2)
Draft a bilateral or multilateral information sharing agreement. Include:
- Scope of permissible information (anonymized typologies, IoCs, not customer PII)
- Handling and retention requirements (how long can shared intelligence be stored?)
- Incident response protocols (what happens if shared intelligence leads to a SAR filing?)
- Liability limitations (you're sharing intelligence, not making accusations)
Template language from FS-ISAC's Traffic Light Protocol works well here. Mark intelligence as:
- Red: Internal use only, do not share
- Amber: Share with named partners only
- Green: Share freely within the community
Step 2: Build your IoC taxonomy (Week 2-3)
Create a structured format for the intelligence you'll share. Don't just send narrative emails saying "we're seeing suspicious wire activity." Use fields:
- Typology: Trade-based money laundering, structuring, nested accounts
- IoC Type: Wallet address, shell company name pattern, routing behavior
- Confidence Level: Confirmed (linked to filed SAR), suspected, observed anomaly
- Temporal Pattern: Time of day, day of week, transaction velocity
- Geographic Pattern: Originating jurisdictions, beneficiary locations
Example IoC entry:
Typology: [Structuring (Smurfing)](/glossary/structuring-smurfing)
IoC: Deposits just under $10,000 filed within 2-hour windows
Confidence: Confirmed (3 SARs filed)
Pattern: Monday mornings, 8-10am, across branch network
Geography: Deposits in urban branches, wire destinations in [jurisdiction]
Step 3: Integrate shared intelligence into transaction monitoring (Week 3-6)
You can't manually review every shared IoC. Automate ingestion:
If you use a commercial TMS (transaction monitoring system) like Actimize, SAS, or FICO:
- Create custom scenarios based on shared typologies
- Load IoC lists (wallet addresses, entity names) into negative file screening
- Adjust risk scoring rules when shared intelligence matches
If you built your own monitoring:
- Ingest IoCs via API or batch file upload
- Tag transactions that match shared intelligence with elevated risk scores
- Create a separate alert queue for "peer-intelligence matches"
Step 4: Establish feedback loops (Week 4 ongoing)
Intelligence sharing dies without feedback. When you act on shared intelligence:
- Notify the sharing institution (within your legal constraints)
- Share whether it led to a SAR filing, account closure, or false positive
- Update the IoC confidence level based on your findings
Build a monthly cadence:
- Week 1: Each institution shares new IoCs from the previous month
- Week 2: Review and integrate into monitoring systems
- Week 3: Provide feedback on previously shared intelligence
- Week 4: Joint working session to discuss emerging typologies
Step 5: Expand the typology library (Month 2 onwards)
Start with 2-3 typologies. After 60 days, assess:
- Which shared IoCs generated the most true positive alerts?
- What new patterns emerged from joint analysis?
- Where are the gaps in coverage?
Block was fined $40 million by the New York Department of Financial Services for insufficient AML controls. That penalty reflects failure to detect patterns that likely existed across multiple platforms. If Block and its peer fintechs had shared intelligence on structuring patterns or suspicious Cash App behaviors, detection might have happened earlier.
Add one new typology per quarter based on:
- SAR trends across participating institutions
- Regulatory guidance (FinCEN advisories, FATF typology reports)
- Joint case reviews where multiple institutions touched the same laundering operation
Validation: How to Verify It Works
Measure detection improvements
Track these metrics before and after intelligence sharing:
- Time from first suspicious activity to SAR filing (target: reduce by 30%)
- Percentage of SARs that reference activity at peer institutions (should increase)
- False positive rate on alerts generated from shared intelligence (target: under 15%)
Conduct joint case reviews
Quarterly, select 2-3 filed SARs and trace them backward:
- Was the activity visible at multiple institutions?
- Did shared intelligence flag it earlier than internal monitoring alone?
- What would have happened without the intelligence sharing?
Test with synthetic scenarios
Create a hypothetical money laundering operation:
- Design a structuring pattern across three institutions
- Share the IoCs through your framework
- Measure how quickly each institution would detect it in their monitoring
Maintenance and Ongoing Tasks
Monthly IoC refresh
Intelligence decays. Money launderers change wallets, shell companies, and routing patterns. Every 30 days:
- Archive IoCs older than 90 days unless they're still generating hits
- Update confidence levels based on feedback
- Add new IoCs from recent investigations
Quarterly typology review
Meet with peer institutions to:
- Review effectiveness of shared intelligence
- Identify new money laundering methods
- Adjust scenario parameters in transaction monitoring systems
Annual framework audit
Review your information sharing agreement:
- Are you still within legal boundaries?
- Have regulatory expectations changed?
- Do you need to expand or contract the peer network?
Staff training
Your investigators need to understand how to use shared intelligence. Quarterly training should cover:
- How to interpret IoC confidence levels
- When to escalate peer-intelligence matches
- How to provide useful feedback to sharing partners
Switzerland's potential move to join the IACCC recognizes that no single jurisdiction can fight money laundering alone. Your institution faces the same reality. Build the infrastructure to share intelligence with peers now, before the next major laundering operation touches your platform and three others without anyone connecting the dots.



