Skip to content
DELCOS Financial Infrastructure

Case Management

AML Case Management

Investigations, Evidence and Decision Control

AML case management converts alerts, referrals and exceptions into controlled investigations. It establishes what entered the case, which evidence was available, who owned each decision, how the matter was escalated, and why it was closed, reported or reopened.

A mature case-management capability preserves the chain from originating signal to final disposition. It separates facts from analytical inference, protects sensitive reporting decisions, and returns structured outcomes to monitoring, customer risk and control design.

Originating signals

Case intake

AML case management

Ownership, evidence and decisions

Investigation

Decision authority

Disposition and evidence

Quality and feedback

Customer and transaction data

What AML Case Management Controls

AML case management governs the point at which an institution accepts responsibility for investigating a signal and reaching a documented decision. The signal may originate from transaction monitoring, sanctions screening, customer due diligence, payment controls, fraud operations, an employee referral or an external request.

The case becomes the authoritative decision record. It connects the original trigger with the subjects under review, investigation scope, evidence, analytical reasoning, actions, approvals and final disposition. It also records any reporting decision, continuing obligations and conditions that could require the matter to be reopened.

Element Meaning
Alert A system-generated or manually identified signal requiring review. An alert can be resolved during pre-case assessment or accepted into a formal case.
Case The governed record through which an institution assigns ownership, investigates a defined matter and records accountable decisions.
Investigation The controlled work performed to establish relevant facts, test explanations and determine the significance of the observed activity.
Disposition The documented conclusion reached at a review stage or at case level, supported by evidence and an authorised rationale.
Regulatory reporting decision A separately governed determination of whether the established facts require or justify an external report under the applicable framework.
Customer or control action A decision to restrict activity, change a customer relationship, update risk treatment or modify an internal control.

Alert resolution, investigation disposition, regulatory reporting and customer or payment action remain separately governed decisions. Resolving an alert may end pre-case review, while an existing case continues to its own disposition. That disposition informs a separate reporting decision, and customer or payment action follows its own authority and criteria.

Within the wider compliance infrastructure, transaction monitoring identifies and structures activity for review. Case management determines what the complete evidence establishes and records the resulting decision. Regulatory operations then execute required external reporting, regulatory communication and remediation processes.

01

Reconstructing the Decision Record

A controlled case should allow another authorised reviewer to reconstruct:

  • what triggered the review;
  • why a case was formed;
  • which persons, entities, accounts and transactions entered its scope;
  • what information was available at each material decision point;
  • which statements were facts and which were analytical conclusions;
  • who performed, reviewed, escalated and authorised each action;
  • why the case reached its disposition;
  • which reporting, customer or control actions followed;
  • what circumstances would require continued review or reopening.

This standard turns case management into an evidence and decision-control mechanism. It creates a reliable record for quality assurance, internal audit, regulatory examination and future control improvement.

The Case Lifecycle and State Model

A controlled case lifecycle makes every material change in ownership, scope, evidence, urgency and decision authority visible. Each case status represents a defined state with entry criteria, permitted actions, required evidence and an authorised route to the next state.

At every transition, the workflow records:

  • the event or decision that caused the transition;
  • the person or system that initiated it;
  • the accountable owner at that point;
  • the effective date and timestamp;
  • the evidence available when the transition occurred;
  • the reason for the change;
  • the next action, deadline or dependency.
Case state Purpose Information recorded
Received Register the incoming alert, referral or exception without altering its original content. Source, trigger, subjects, originating timestamp and unique identifier.
Triage Assess urgency, initial scope, routing requirements and possible relationships with existing matters. Priority factors, conflicts, duplicate checks and routing rationale.
Assigned Establish accountable ownership and the required level of review. Investigator, reviewer, due date, skills or jurisdiction required.
Investigation Gather evidence, test explanations and document findings against the defined scope. Investigation plan, actions, evidence, findings and scope changes.
Awaiting evidence Record a material dependency while preserving responsibility and visibility of ageing. Requested evidence, responsible party, request date, expected response and escalation date.
Escalated Transfer a question or decision to the appropriate authority. Escalation reason, recipient, evidence package, urgency and required decision.
Decision Record the authorised disposition and any separate reporting, customer or control decisions. Decision, rationale, approver, applicable criteria and resulting obligations.
Action or reporting Track the execution of approved actions and obtain confirmation of completion. Handoff, recipient, completion status, reference numbers and exceptions.
Closed Confirm that closure criteria have been met and preserve continuing obligations. Final rationale, approvals, retained evidence, follow-up actions and reopening conditions.
Reopened or continued Resume controlled review when new information or continuing activity affects the previous assessment. Reopening trigger, affected decision, revised scope, owner and new deadline.

Several tasks can run in parallel under one authoritative case state. Evidence collection, legal review, customer outreach and reporting preparation may progress at different speeds. As those workstreams move, the case record retains each task, dependency and owner so that the overall status remains visible.

01

State Transitions

For each status change, the operating model defines:

  • which roles may create, accept, reassign, escalate, close or reopen a case;
  • which fields and evidence are mandatory before each transition;
  • when an approval or four-eyes review is required;
  • how deadlines continue during evidence requests and internal holds;
  • how priority changes affect queue position and escalation;
  • how rejected or overridden decisions remain visible;
  • how system-generated transitions identify the rule, workflow or model that initiated them.

Previous states, owners and rationales remain part of the permanent event history. When a correction is needed, the workflow creates a new event while retaining the information originally available to the decision-maker.

02

Linking, Merging and Splitting Cases

When several alerts describe one underlying matter, they may belong within a connected investigation. A case may also reveal separate subjects, jurisdictions or reporting obligations that require distinct decision records. The case-management model therefore supports controlled linking, merging and splitting.

Whether records are linked, merged or split, the operation retains:

  • the original identifiers and source records;
  • the relationship between the affected cases;
  • the evidence transferred or shared;
  • the reason and authority for the operation;
  • any deadlines or obligations that remain attached to the original matter;
  • the ability to reconstruct each decision before and after the change.

As a result, investigators can adapt the case structure without losing institutional memory, accountability or evidence continuity.

Case Intake and Formation

Case intake establishes the record on which every later investigation and decision depends. The intake process should preserve the originating signal, establish accountable ownership and capture enough context for reliable triage.

Cases may originate from:

  • transaction-monitoring alerts;
  • sanctions-screening escalations;
  • changes identified through KYC and KYB;
  • fraud, cybersecurity or operational investigations;
  • payment-control exceptions;
  • employee, customer or counterparty referrals;
  • law-enforcement, court or regulatory requests;
  • information received through authorised sharing arrangements.

The intake record should retain the signal in the form originally received. Subsequent enrichment may add context, but it should preserve the initial data, timestamp, source and analytical conditions.

For a system-generated alert, this includes the applicable rule, scenario, threshold, model or list version. For a manual referral, it includes the submitter, stated concern, supporting material and any restrictions on access or onward disclosure.

01

Information Recorded at Case Intake

A case should begin with a structured set of information:

Field Why it matters
Case identifier Maintains a persistent reference across systems, evidence and downstream actions.
Originating source Identifies the system, team, institution or authority that produced the signal.
Trigger Records the event, behaviour, match, request or information that initiated review.
Subjects and relationships Identifies relevant persons, entities, accounts, instruments, devices and counterparties.
Initial scope Defines the activity, period, products and jurisdictions entering review.
Source snapshot Preserves the data and analytical output available at formation.
Ownership Names the team and individual responsible for the next controlled action.
Priority and deadlines Records operational urgency and any applicable legal or internal time limits.
Access classification Applies confidentiality, privilege, need-to-know and information-sharing restrictions.
Related records Connects alerts, previous cases, customer reviews, payment events and external requests.

Automated intake can populate these fields and assemble an initial evidence package. The receiving team remains responsible for confirming that the case is complete, correctly routed and accessible to the authorised investigators.

02

Correlation and Duplicate Control

Multiple signals may relate to the same underlying activity. Intake should search for connected customers, beneficial owners, counterparties, accounts, devices, addresses, transactions and prior cases.

Correlation supports three different decisions:

  • attach the signal to an existing active case;
  • create a linked case with separate ownership or obligations;
  • create an independent case and retain the detected relationship.

Duplicate control should preserve the provenance of every source signal. Combining records should never remove a distinct reporting deadline, jurisdictional obligation, subject or decision path.

Triage, Prioritisation and Assignment

Triage determines how the institution handles the case before the full investigation begins. It establishes urgency, confirms the initial scope, identifies restrictions and assigns the matter to a team with the required authority and expertise.

During initial review, triage considers:

  1. whether the source record is complete and technically valid;
  2. whether immediate protective or payment action may be required;
  3. whether a legal, regulatory or contractual deadline applies;
  4. whether the activity appears active, continuing or time-sensitive;
  5. whether related cases or unresolved alerts already exist;
  6. whether confidentiality, privilege or conflict restrictions affect routing;
  7. which products, jurisdictions, entities and specialist skills are involved;
  8. whether the case requires enhanced review or immediate escalation.

01

Priority, Severity, Confidence and Complexity

Priority, severity, confidence and complexity answer different operational questions.

Dimension What it establishes
Priority How quickly the institution needs to act.
Severity The potential impact if the concern is substantiated.
Confidence The reliability and specificity of the originating signal.
Complexity The expertise, evidence and investigation effort the case will require.

When potential harm is immediate, a case may receive high priority despite limited initial evidence. A high-confidence signal may still present limited exposure, while complexity can require specialist routing even at moderate urgency.

As an allocation decision, triage directs attention and resources while leaving suspicion and final disposition to the investigation and authorised decision process.

02

Dynamic Prioritisation

New information can change the case’s priority. Reassessment may follow:

  • new transactions or attempted activity;
  • additional linked subjects or accounts;
  • a material change in customer information;
  • a credible external request or intelligence update;
  • approaching reporting or response deadlines;
  • evidence that may become unavailable;
  • an escalation from another control function;
  • a change in the potential impact of delaying action.

With each change, the record retains the previous rating, the new information, the decision-maker and the effect on deadlines or queue position.

03

Case Ownership and Assignment

Authority, capacity and competence together determine assignment. Routing factors may include product knowledge, jurisdiction, language, typology, legal restrictions, customer segment, investigation complexity and access to protected information.

Even when several specialists contribute, one identifiable owner remains accountable for the case. On reassignment, the record retains the prior owner, transfer time, reason, outstanding tasks and accepted handoff, keeping responsibility visible as work moves between teams or institutions.

Investigation Workflow

An AML investigation establishes what happened, who participated, how the activity moved through the institution and whether the available facts support further action. It should begin with a defined question and develop through recorded evidence, analysis and review.

The initial investigation scope should identify:

  • the subjects, accounts, instruments and relationships under review;
  • the activity or behaviour that caused concern;
  • the relevant time period;
  • the products, channels and jurisdictions involved;
  • the questions that the investigation needs to resolve;
  • the evidence sources expected to answer those questions;
  • any immediate gaps, restrictions or dependencies.

This creates a starting point for the investigation while allowing the scope to develop as new facts emerge.

01

Building the Investigation

Investigators may draw on customer records, beneficial-ownership information, transaction data, payment messages, screening results, account activity, device and access data, internal communications, previous cases and authorised external sources.

The investigation should connect these materials through a coherent chronology. Event time, transaction time, booking time, alert time and review time may describe different moments. Preserving these distinctions helps establish what the institution knew and when it became available.

Each investigative action should record:

  • the question being examined;
  • the source consulted;
  • the search terms or parameters used;
  • the information retrieved;
  • the investigator’s finding;
  • any resulting change in scope or priority;
  • the next required action.

02

Facts, Representations, Inferences and Gaps

A reliable case record distinguishes four forms of information:

Information Meaning
Observed fact Information directly supported by a retained system record, transaction, document or verified event.
Sourced representation A statement supplied by a customer, employee, counterparty, institution or external source.
Analytical inference A reasoned interpretation derived from one or more facts or representations.
Unresolved gap Information that remains unavailable, contradictory or insufficient at the decision point.

This distinction allows reviewers to assess the strength of the reasoning. A customer explanation remains a sourced representation until supporting evidence verifies it. A relationship inferred from shared attributes remains an analytical conclusion until additional evidence establishes its meaning.

Investigators should also record evidence that supports an ordinary or legitimate explanation. The case record should show how competing explanations were considered and why the final interpretation carried greater weight.

03

Relationships and Network Context

Activity that appears isolated at account level may form part of a wider relationship or transaction network. Investigation can connect:

  • customers and beneficial owners;
  • counterparties and intermediaries;
  • accounts and payment instruments;
  • shared addresses, devices or contact details;
  • recurring transaction paths;
  • previous alerts, cases and regulatory enquiries.

A detected connection establishes an investigative lead. Its significance depends on context, timing, source reliability and the behaviour observed across the network.

Entity-resolution and graph-analysis tools can surface hidden relationships and reduce repeated manual searches. The case should retain the attributes that produced each connection, the matching method and the investigator’s assessment of its relevance.

04

Changes in Scope

New evidence may expand, narrow or divide an investigation. A scope change should identify:

  • the information that caused the change;
  • the subjects, activity or period added or removed;
  • the person authorising the change;
  • the effect on priority, deadlines and required expertise;
  • whether related cases or teams need to be notified.

This preserves the relationship between the original concern and the matter ultimately decided.

05

Customer and Third-Party Enquiries

Customer contact can clarify the purpose of activity, source of funds, source of wealth, commercial relationships or transaction instructions. The enquiry should follow an approved communication strategy that protects confidential information and avoids disclosing the existence of protected reporting or investigative activity.

The case record should preserve the questions asked, responses received, documents supplied, communication channel, dates and investigator’s assessment. Any inconsistency between the response and independently available evidence should enter the investigation as a separate finding.

06

Reaching an Investigative Conclusion

An investigation reaches decision readiness when:

  • the material questions have been addressed;
  • relevant evidence has been collected or identified as unavailable;
  • contradictions and alternative explanations have been considered;
  • changes in scope are documented;
  • facts and analytical conclusions remain distinguishable;
  • remaining uncertainty is visible to the decision-maker;
  • the record supports a reasoned disposition and any subsequent action.

Decision readiness requires an accountable evidential basis. The case may retain uncertainty, provided that the uncertainty, its significance and its effect on the decision are clearly recorded.

Evidence Architecture and Audit Trail

To reproduce a case after source systems, customer records, models or external data have changed, an authorised reviewer needs to see what entered the investigation, where it came from, how it changed and how it influenced the decision. The evidential record provides that chain.

01

Preserving the Evidence Available at the Time

As operational systems update the same record, customer profiles change, transactions receive new statuses, screening lists are revised and external sources may disappear. At the moment of reliance, the case captures the material information available to the investigator or decision-maker.

Relevant timestamps may include:

  • when the underlying event occurred;
  • when the institution received or recorded it;
  • when a system processed or enriched it;
  • when it became available to the investigator;
  • when the investigator reviewed it;
  • when it influenced a decision.

Together, these timestamps establish the sequence of knowledge and action, distinguishing a decision made on incomplete information from a later review informed by additional evidence.

02

Evidence Provenance

For every finding, evidence provenance connects that finding to its origin and subsequent treatment.

Evidence layer Information retained
Source record Originating system, provider, document, communication or authorised external source.
Preserved snapshot The content, status and metadata available at the relevant point in time.
Transformation Normalisation, translation, extraction, calculation or other processing applied to the source.
Enrichment Additional attributes, entity matches, network connections or external information added to the record.
Analytical output Investigator finding, rule result, model output, summary or inferred relationship.
Decision reference The conclusion or action for which the evidence was considered material.

A stable and retrievable source may remain linked by reference. A mutable or temporary source requires a preserved snapshot or an equivalent record that can reproduce the information used.

When a system transforms evidence, the case retains the relevant input, method, version and output. This applies to currency conversions, name matching, entity resolution, transaction aggregation, document extraction, translation, risk scoring and machine-generated analysis.

03

Evidence Integrity

To protect evidence from silent alteration, the case record applies integrity measures. These may include immutable storage, cryptographic hashes, signed records, version histories and controlled replacement procedures.

When evidence is corrected, a new version identifies:

  • the original record;
  • the corrected information;
  • the reason for the correction;
  • the person or system making it;
  • the effective timestamp;
  • any decisions potentially affected.

The original evidence remains available as part of the historical record. If corrected information changes the basis of an existing decision, the case should enter a reassessment or reopening process.

04

The Event History

Across the case lifecycle, the audit trail captures material events, including:

  • creation, linking, merging and splitting;
  • assignment and reassignment;
  • searches and evidence retrieval;
  • evidence addition, replacement and restriction;
  • changes to scope, priority or deadline;
  • investigator findings and reviewer comments;
  • status transitions;
  • escalations and approvals;
  • dispositions and overrides;
  • information exports and external handoffs;
  • access to specially protected material;
  • closure, reopening and retention actions.

For each event, the audit trail identifies the actor, time, action, affected record and stated reason. System-generated events also identify the workflow, rule, model or integration that initiated them.

As comments and narratives develop during an investigation, any edit that changes a material fact, conclusion or rationale creates a retained version. Reviewers can then see how the analysis developed and whether later wording altered the meaning of the original decision.

05

Reproducing the Decision

A reproducible case supports three connected forms of review:

  1. Source reconstruction
    The reviewer can locate or reproduce the information relied upon.

  2. Analytical reconstruction
    The reviewer can understand how facts, transformations, assumptions and inferences produced the findings.

  3. Decision reconstruction
    The reviewer can identify the applicable criteria, responsible authority, reasoning and resulting actions.

Reproducibility does not require every reviewer to reach an identical conclusion. It requires a complete record that makes the reasoning, evidence and exercise of judgement visible.

06

Evidence Continuity Across Systems

As case information moves between monitoring platforms, customer systems, document repositories, reporting tools and external service providers, every transfer carries its identifiers, timestamps, classification, provenance and access restrictions.

On receipt, the destination system confirms:

  • which records were transferred;
  • whether the transfer completed successfully;
  • whether any fields were changed or omitted;
  • which version became authoritative;
  • who owns correction and reconciliation;
  • how updates return to the originating system.

With those confirmations, the institution can maintain one coherent decision record across a distributed compliance architecture.

Roles, Escalation and Decision Authority

Investigators, reviewers, business teams, legal specialists, reporting officers and external service providers may all contribute to one case. The record shows who supplied information, who performed the analysis and who held authority for each decision.

Decision authority follows the type of decision being made. Operational seniority alone does not establish the relevant legal, regulatory or control authority.

Role Responsibility within the case
Intake or triage analyst Confirms the originating signal, establishes initial scope, assigns priority and routes the case.
Investigator Collects evidence, tests explanations, records findings and prepares a supported recommendation.
Reviewer or approver Challenges the investigation, verifies completeness and approves or returns the proposed disposition.
Money Laundering Reporting Officer (MLRO) or designated reporting authority Makes or authorises reporting decisions where the applicable framework assigns that responsibility.
Business or customer owner Provides operational context and executes authorised relationship actions without controlling the independent investigation outcome.
Legal, privacy or information-sharing specialist Advises on privilege, confidentiality, disclosure, data transfer and jurisdictional restrictions.
Data or system owner Resolves source-data, lineage, access and system-integrity issues affecting the evidence.
Regulatory operations Executes approved filings, authority communications, response tracking and related remediation.
Quality assurance or audit Assesses investigation quality, decision consistency and the effectiveness of the operating framework.

Where one participant performs several roles, the case still distinguishes the capacity in which each action was taken and applies the required separation between investigation, approval and independent assurance.

01

Decision Rights

For each decision type, the institution assigns authority separately for:

  • accepting a signal into case management;
  • changing priority or scope;
  • assigning or transferring ownership;
  • requesting restricted information;
  • escalating the matter;
  • approving an investigation disposition;
  • making a regulatory reporting decision;
  • initiating customer, account or payment action;
  • closing or reopening the case;
  • accepting a material exception or override.

Permissions and workflow rules enforce these rights within the case-management system. Edit access alone provides no authority to approve, override or close.

02

Independent Review

When potential consequence, uncertainty or regulatory significance requires challenge, a second person reviews the case. That reviewer assesses its substance rather than confirming completion of required fields.

During review, the reviewer establishes whether:

  • the investigation addressed the material questions;
  • the scope reflects the activity and relationships identified;
  • the retained evidence supports the stated facts;
  • analytical inferences follow from that evidence;
  • contradictory information received appropriate consideration;
  • unresolved gaps remain visible;
  • the recommendation follows the applicable decision criteria;
  • resulting actions and continuing obligations are complete.

Points of challenge, investigator responses and the basis for approval form part of the retained review record. If the reviewer returns the case, the record identifies the additional work required while retaining the recommendation originally submitted.

03

Escalation

When the current owner cannot resolve a question, risk or decision, escalation transfers it to the person or function with the required authority or expertise. The request states what requires a decision, why escalation is necessary and when the response is needed.

Escalation may arise from:

  • immediate or continuing financial harm;
  • a material reporting or response deadline;
  • evidence extending the matter into another jurisdiction or legal entity;
  • uncertainty about confidentiality, privilege or permitted disclosure;
  • suspected internal involvement or a conflict of interest;
  • significant evidence gaps or source-data failures;
  • activity involving several institutions or service providers;
  • repeated patterns indicating a wider control weakness;
  • disagreement between the investigator and reviewer;
  • a proposed exception from an established policy or decision criterion.

To transfer the decision cleanly, the escalation record contains a concise statement of the issue, relevant evidence, available options, prior actions and the authority requested. Formal acceptance by the receiving party marks the handoff; a returned matter carries a recorded explanation.

04

Overrides and Exceptions

When an authorised actor changes a recommendation, priority, workflow outcome or system-generated result, the case records an override and preserves:

  • the original result or recommendation;
  • the person proposing the override;
  • the authorised approver;
  • the evidence and reasoning supporting the change;
  • any policy exception involved;
  • the effect on reporting, customer action or control remediation;
  • whether enhanced review or subsequent testing is required.

Viewed in aggregate, override patterns can reveal unclear decision criteria, training needs, weak models or inconsistent risk treatment, making them a programme-level signal for quality assurance.

05

Conflicts and Segregation

Where a person involved in the underlying activity, customer relationship or originating control issue also presents a conflict, the case records that relationship, restricts decision authority where appropriate and routes the matter to an independent reviewer.

By separating investigation, approval and assurance while preserving access to necessary expertise, segregation of duties protects the investigation’s integrity and keeps accountability visible through every handoff.

Disposition, Reporting Decisions and Resulting Actions

A completed investigation may produce several decisions with different criteria, authorities and consequences. The case record should distinguish the investigative conclusion from the regulatory reporting decision and from any action affecting the customer, transaction or control environment.

01

Three Decisions Arising from One Investigation

Decision Question answered
Investigation disposition What does the available evidence establish about the activity under review?
Regulatory reporting decision Does the applicable legal and regulatory framework require or support an external report?
Customer or control action What should the institution do about the relationship, transaction, exposure or underlying control weakness?

These decisions may follow different timelines. An institution may take an immediate protective action while the investigation continues. A reporting decision may require designated authority. A customer relationship decision may depend on contractual, legal, operational and risk considerations beyond the case disposition.

02

Investigation Disposition

The disposition should use a controlled outcome category supported by a concise case-specific rationale. Depending on the institution and applicable framework, outcomes may include:

  • activity supported by the available evidence and context;
  • concern unresolved because material evidence remains unavailable;
  • concern substantiated and referred for an authorised reporting decision;
  • matter linked to an existing investigation;
  • matter transferred to another control function or institution;
  • data, model or process issue requiring remediation;
  • investigation closed with continuing monitoring or another defined follow-up action.

A reason code supports aggregation and analysis. The written rationale explains why the evidence supports that outcome. It should identify the material facts, address contradictory information and state how unresolved gaps affected the conclusion.

03

Regulatory Reporting Decision

The reporting decision should identify:

  • the applicable jurisdiction and decision criteria;
  • the facts considered material;
  • the person holding reporting authority;
  • the decision date;
  • the reporting deadline, where applicable;
  • the relationship between the case conclusion and the reporting decision;
  • any dissent, escalation or override;
  • the team responsible for execution.

The case-management function preserves the decision and its evidential basis. Regulatory operations prepares and submits the required report, manages acknowledgements and requests, and confirms completion through a controlled handoff.

The case identifier and reporting reference should remain connected while access restrictions protect sensitive filing information.

05

Customer, Transaction and Control Actions

The investigation may support actions such as:

  • requesting updated customer information;
  • changing customer risk treatment;
  • restricting a product, channel, account or payment;
  • subjecting activity to enhanced review;
  • referring the relationship for continuation or exit decisions;
  • correcting customer, transaction or beneficial-ownership data;
  • changing a monitoring rule, threshold or model;
  • addressing a process, training or system weakness.

Each action should have an authorised owner, due date, completion evidence and escalation route. The case should record the legal or policy basis where an action materially affects the customer or transaction.

Closure, Reopening and Continuing Activity

Case closure confirms that the current decision cycle has reached an authorised conclusion. It preserves the rationale, completed actions and future obligations associated with the matter.

Closure occurs when:

  • the investigation disposition has been approved;
  • reporting and customer-action decisions have been made or formally handed off;
  • material evidence and unresolved gaps are recorded;
  • required reviews and approvals are complete;
  • follow-up actions have named owners and deadlines;
  • connected systems have received required updates;
  • retention and access classifications have been applied;
  • reopening conditions have been defined.

Where another process has formally accepted ownership, outstanding work can continue after closure. The case identifies that process, responsible party and completion reference, leaving no unassigned obligation behind.

01

Reopening a Case

A closed case may require renewed investigation when new information affects the previous conclusion. Reopening triggers may include:

  • material new activity;
  • corrected or newly available source data;
  • evidence received after closure;
  • a connected case revealing a relevant relationship;
  • information from another institution or authority;
  • quality assurance identifying a material deficiency;
  • an overturned reporting or customer decision;
  • a model, rule or data issue affecting the original findings;
  • failure to complete an action on which closure depended.

On reopening, the record retains the original disposition, identifies which facts, assumptions or decisions require reassessment, and establishes a revised scope, owner, priority and deadline.

02

Continuing Activity

Continuing activity can be managed through an open case, a linked follow-up case or a defined monitoring process. The choice reflects applicable obligations, the nature of the activity and the institution’s operating model.

The continuing-activity record states:

  • what activity remains under observation;
  • who owns the review;
  • which events or dates trigger reassessment;
  • how new alerts connect to the existing matter;
  • when a new reporting decision becomes necessary;
  • when the continuing review ends.

With clear continuation and reopening criteria, the institution avoids premature closure and indefinitely open cases with unclear ownership.

Information Sharing and Confidentiality

Case management brings together customer data, transaction records, investigative analysis, reporting decisions and information received from other parties. These materials carry different disclosure restrictions and should remain separately identifiable throughout the case.

01

Different Information Requires Different Protection

Information category Typical treatment
Underlying facts and transactions May support internal or authorised external investigation, subject to applicable privacy, secrecy, contractual and data-transfer requirements.
Customer or counterparty representations Retain the source, context, permitted purpose and any restriction attached to the information.
Investigative analysis Limit access according to role, purpose, legal entity and sensitivity.
Regulatory reporting information Apply the specific confidentiality rules governing the existence, content and preparation of a report.
Authority-derived information Preserve any limits on use, onward disclosure, retention and notification.
Legally privileged material Segregate and provide access only through the authorised legal framework.

This separation allows an institution to share permissible facts without exposing a protected reporting decision or another restricted part of the case.

In its September 2025 cross-border information-sharing guidance, FinCEN distinguished protected SAR information from underlying facts, transactions and supporting documents. Within the U.S. framework, a financial institution may share permissible underlying information while protecting the SAR itself and information that would reveal its existence.

The precise boundary depends on jurisdiction, recipient, purpose and information source. The case should therefore classify each item rather than applying one access rule to the entire record.

02

Access Within the Institution

Access should follow the user’s role, assigned case, legal entity, jurisdiction and purpose. Sensitive material may require compartmentalised permissions even when a user can access the wider customer record.

Relevant safeguards include:

  • role- and attribute-based permissions;
  • legal-entity and jurisdictional restrictions;
  • separate access to reporting information;
  • time-limited access for specialists and external reviewers;
  • enhanced approval for exports or bulk retrieval;
  • redaction and masking;
  • recorded emergency access;
  • monitoring of viewing, downloading, printing and sharing;
  • periodic removal of obsolete permissions.

A case should preserve an access history for specially protected material. Unusual access patterns may require security or compliance review.

04

Sharing with Other Institutions

Authorised information-sharing arrangements can reveal relationships and activity that remain incomplete within one institution. Effective collaboration requires a defined legal framework, permitted purpose, participant group and secure exchange mechanism.

Singapore’s COSMIC platform provides one model of bounded information sharing among participating financial institutions under a specific statutory framework. Its relevance to case management lies in the need to receive, classify, assess and retain externally supplied information without treating the shared concern as an established fact.

A disclosure package should record:

  • the recipient and participating legal entities;
  • the authorised purpose;
  • the information selected for disclosure;
  • the basis permitting the exchange;
  • applied redactions and exclusions;
  • the approving authority;
  • the transfer channel and timestamp;
  • restrictions on onward use;
  • acknowledgement or response received.

05

Cross-Border Financial Intelligence Unit Exchange

In July 2026, AMLA opened a consultation on cross-border FIU information exchanges. The proposals include structured criteria that FIU.net could apply automatically when determining cross-border relevance.

The consultation concerns exchange between Financial Intelligence Units. It also signals a wider architectural direction: case information increasingly needs structured identifiers, consistent transaction fields, explicit jurisdictions and machine-readable handling conditions.

Institutions should preserve these attributes before the reporting stage. Regulatory operations can then assemble an accurate exchange or reporting package without reconstructing essential data from unstructured narratives.

06

Confidentiality During Customer Contact

Customer and counterparty enquiries should obtain necessary information while protecting confidential investigative and reporting activity. The communication plan should define:

  • which questions may be asked;
  • who may contact the customer;
  • which explanation may be provided for the request;
  • what information remains restricted;
  • how responses and supplied documents enter the case;
  • when legal or reporting authority should review the communication.

The case record should connect the enquiry to the investigation question while keeping protected reporting information in a separately controlled part of the record.

Effective information sharing depends on selective disclosure, preserved provenance and visible authority. These qualities allow relevant facts to move while maintaining the confidentiality of the decisions and materials that remain protected.

Queues, Service Levels and Backlog Control

Unresolved cases form a queue of outstanding risk and decision responsibility. Its operating view needs to show which matters require action, how long they have waited, why they are delayed and whether qualified capacity is sufficient.

01

Measuring Time Across the Case

A single end-to-end completion target can conceal the point of delay. Separate measures distinguish:

  • time from signal creation to intake;
  • time awaiting triage;
  • time without an assigned owner;
  • active investigation time;
  • time awaiting internal or external evidence;
  • time awaiting review or decision;
  • time between decision and required action;
  • total age and time beyond the applicable deadline.

When a clock pauses, the status identifies the dependency, responsible party, pause authority, review date and escalation point. Both elapsed calendar time and active handling time remain visible.

02

Structuring the Queue

Across the queue, cases remain visible by:

  • priority, severity, confidence and complexity;
  • applicable legal or regulatory deadline;
  • age and overdue status;
  • customer, product and jurisdiction;
  • investigation skill required;
  • assigned team and accountable owner;
  • evidence or decision dependency;
  • confidentiality or access restriction;
  • related case or continuing activity.

Segmentation allocates work by operating path while preserving a consolidated view of institutional exposure. High-volume, lower-complexity cases may move differently from network investigations or matters requiring specialist authority.

03

Backlog as Risk Inventory

Once the institution lacks qualified capacity to investigate cases within the time and quality standards their risk requires, the backlog becomes material. Open-case volume alone cannot show that exposure.

Assessment therefore considers:

  • age distribution rather than average age;
  • priority and potential consequence;
  • statutory and internal deadlines;
  • active versus inactive customer relationships;
  • continuing or accelerating activity;
  • evidence likely to expire or become unavailable;
  • concentration by product, jurisdiction or originating control;
  • cases awaiting specialist review;
  • repeated extensions or pauses;
  • the quality of accelerated closures.

To forecast capacity, management connects expected inflow with investigation complexity, handling time, skill availability, review requirements, reopening rates and planned system changes. Contingency capacity covers control failures, lookbacks, new typologies and unexpected alert growth.

04

Preventing Queue Distortion

When incentives reward apparent timeliness, decision quality can weaken. Indicators include:

  • priority inflation that moves most cases into urgent queues;
  • selection of simple cases while complex matters continue ageing;
  • repeated pauses without active dependency management;
  • reassignment shortly before deadlines;
  • bulk closure using generic rationales;
  • reduced scope introduced to meet throughput targets;
  • completed workflow tasks with unresolved downstream actions;
  • rising reopen or reviewer-return rates after accelerated closure.

Connecting throughput with evidence completeness, decision quality and downstream outcomes exposes that distortion in management reporting.

05

Lessons from Enforcement

FinCEN’s 2024 TD Bank consent order describes sustained investigation backlogs, delayed reporting and weaknesses in the documentation supporting case closures. The order records more than 6,000 late SAR filings associated with the bank’s processing failures.

FinCEN’s August 2026 action against UBS Financial Services also connects monitoring and case-disposition deficiencies with required lookback and remediation work.

Together, these actions show how unresolved queue pressure can develop into reporting failures, incomplete investigations and unreliable closure decisions. Reducing the backlog effectively therefore combines prioritised risk treatment, controlled capacity and independent review of the resulting dispositions.

Quality Assurance and Decision Consistency

Quality assurance tests whether investigations produce supported, authorised and reproducible decisions. In doing so, it examines the substance of the case and the operating conditions that shaped it.

01

Three Levels of Review

Review level Purpose
Quality control Detects and corrects case-level deficiencies during investigation, review or closure.
Quality assurance Independently samples completed and active cases to evaluate consistency and recurring weaknesses.
Internal audit Assesses whether governance, design and operation provide effective programme-level assurance.

To preserve its value, quality assurance remains sufficiently independent from the production targets and management decisions it evaluates.

02

What Quality Review Should Examine

Across a case, review assesses:

  • whether the case entered with complete and traceable source information;
  • whether triage and priority reflected the known risk;
  • whether the investigation addressed the relevant activity and relationships;
  • whether evidence supported the recorded facts;
  • whether conclusions remained distinguishable from assumptions;
  • whether contradictory information received appropriate consideration;
  • whether the correct authority made each decision;
  • whether reporting and customer actions remained separately governed;
  • whether deadlines and delays were accurately recorded;
  • whether confidentiality and access restrictions were maintained;
  • whether closure and reopening conditions were complete;
  • whether outcomes returned to the relevant controls.

03

Selecting Cases for Review

By combining random, risk-based and thematic sampling, a reliable programme tests both routine and concentrated exposure.

The sample includes:

  • high-priority and high-impact cases;
  • closed cases with no external report;
  • cases completed close to or after deadlines;
  • overrides and policy exceptions;
  • cases returned by reviewers;
  • reopened or linked cases;
  • investigations using automated or AI-generated analysis;
  • cases involving external providers or cross-border sharing;
  • matters generated by newly introduced rules, models or data sources.

This combination reveals population-wide inconsistency alongside concentrated weaknesses.

04

Measuring Decision Quality

When pass rates are viewed alone, they can conceal defect severity and recurrence. Quality reporting distinguishes:

  • critical, material and procedural deficiencies;
  • evidence and reasoning defects;
  • authority and segregation failures;
  • late or incomplete downstream actions;
  • repeated defects by team, investigator or case type;
  • disagreement and overturn rates;
  • cases reopened because the original investigation was incomplete;
  • remediation completion and recurrence after correction.

Where comparable facts produce different outcomes, calibration measures the variation and helps locate unclear criteria, weak training, uneven access to evidence or conflicting production incentives.

Findings then drive defined changes in guidance, training, workflow, data, models and staffing, correcting both the individual record and the system that produced it.

Effectiveness and the Closed Feedback Loop

Case management produces information about how financial crime controls perform in practice. Each investigation can reveal useful signals, weak data, ineffective thresholds, misunderstood customer behaviour, hidden relationships and failures in the operating process.

An effective framework returns these findings to the systems and teams that can act on them.

01

From Activity Counts to Useful Outcomes

Alert, case and reporting volumes describe workload. They provide limited evidence about whether the institution identified meaningful risk, reached reliable decisions or improved its controls.

The Wolfsberg Group’s 2024 statement on effective monitoring advances an outcomes-focused approach to suspicious-activity monitoring. It places greater emphasis on the usefulness of results and the contribution of monitoring to the wider financial crime risk-management system.

For case management, this means assessing whether investigations:

  • identify relevant activity and relationships;
  • produce evidence-supported decisions;
  • support useful regulatory reporting where appropriate;
  • enable timely customer or transaction action;
  • reveal data and control weaknesses;
  • improve future detection and investigation;
  • provide information that authorised public authorities can use.

Conversion rates such as alert-to-case or case-to-report remain useful diagnostic measures. Their meaning depends on the risk covered, customer population, decision thresholds, data quality and operating model.

02

Measuring Case Outcomes

Area Relevant indicators
Decision quality Reviewer returns, material overrides, reasoning deficiencies, inconsistent outcomes and reopened cases.
Evidence quality Missing sources, unsupported conclusions, provenance gaps and evidence obtained only after initial review.
Timeliness Time to triage, investigation, decision and resulting action, measured by priority and deadline.
Investigative value Relevant networks, counterparties, typologies and previously unidentified exposure discovered through cases.
Reporting value Complete and timely reports, authority feedback and subsequent requests for information where available.
Control improvement Monitoring, KYC, screening, payment or data changes initiated by investigation findings.
Remediation durability Recurrence of the same weakness after corrective action.
Operational resilience Backlog recovery, dependency management, continuity during system change and availability of specialist capacity.

Metrics should retain their connection to the cases and decisions that produced them. Aggregate reporting can then show both the scale of an issue and the evidence behind it.

03

Returning Outcomes to Monitoring and Customer Risk

A case should generate structured feedback when an investigation identifies:

  • a useful or misleading alert feature;
  • a recurring legitimate explanation;
  • an important relationship absent from the original alert;
  • an entity-resolution error;
  • a missing customer or beneficial-ownership attribute;
  • an inappropriate threshold or segmentation assumption;
  • a pattern that spans several products or channels;
  • a transaction field that investigators consistently require;
  • activity that an existing control failed to detect;
  • a control defect that created repeated cases.

The feedback record should identify the originating cases, affected control, supporting evidence, responsible owner and required response. It should then track evaluation, testing, approval, implementation and post-change performance.

This connects case management with AML programme governance and converts individual investigations into institutional learning.

04

Preserving the Meaning of Investigator Feedback

Investigator decisions can support rule tuning, model development and machine-learning labels. Their value depends on the consistency and quality of the underlying cases.

A closure reason may reflect limited evidence, jurisdictional criteria, customer context or an operational constraint. Treating every closed case as a false positive can introduce misleading training data. Treating every filed case as confirmation of criminal activity creates a different distortion.

Feedback used for analytics or model development should therefore retain:

  • the precise disposition and decision type;
  • the supporting evidence strength;
  • unresolved gaps;
  • reviewer agreement or override;
  • applicable jurisdiction and policy;
  • the rule, model or data version involved;
  • any later reopening or authority feedback.

This context allows model developers and control owners to understand what the label represents.

05

Change Without Freezing the Control Environment

The Wolfsberg Group’s 2025 statement on transition and validation addresses the movement from established monitoring approaches to more effective methods. It highlights the need to balance model risk with the financial crime risk created by retaining weaker controls.

Case management supports this transition by providing:

  • reliable historical outcomes for testing;
  • case cohorts for comparison before and after change;
  • evidence of previously missed activity;
  • investigator and reviewer feedback;
  • records of model-generated findings and overrides;
  • post-deployment quality and outcome measures.

Validation should assess whether a change improves relevant outcomes under controlled conditions. Case volume reduction can form part of that assessment when evidence quality, risk coverage and decision performance remain visible.

06

Closing the Feedback Loop

A feedback loop reaches completion when the institution:

  1. identifies a finding through one or more cases;
  2. assigns the finding to the responsible control owner;
  3. evaluates its scale and potential consequence;
  4. approves and implements a proportionate change;
  5. tests the change against historical and current activity;
  6. measures its effect on detection and decision quality;
  7. records any residual issue or further action.

Case management becomes a learning mechanism when its outcomes change how the institution detects, understands and responds to future activity.

Automation, AI and Agentic Case Work

From predefined workflow rules, case-management automation is moving toward systems that retrieve evidence, organise investigations, generate analysis and execute bounded tasks across connected platforms.

During 2025, public announcements from NICE Actimize and Nasdaq Verafin illustrated the emergence of AI agents for fraud and financial-crime operations. Contextual analytics and graph platforms such as Quantexa also show the growing role of entity resolution and network intelligence in investigative work.

Taken together, these developments indicate market direction. The institution remains responsible for validating each capability within its own data, decision framework and regulatory environment.

01

Emerging Capabilities

AI-assisted case management can support:

  • retrieving customer, transaction and previous-case information;
  • assembling chronological evidence packages;
  • identifying connected entities, accounts and activity;
  • summarising documents and communications;
  • translating and extracting structured information;
  • identifying missing evidence or conflicting facts;
  • recommending priority, routing and investigation steps;
  • categorising backlog populations;
  • drafting findings and regulatory narratives;
  • checking case completeness before review;
  • initiating approved queries or workflow tasks;
  • returning structured outcomes to monitoring and customer-risk systems.

Reliable value depends on the quality of the available data, the precision of system permissions and the ability to trace every output to its source.

02

Assist, Recommend and Act

At task level, AI authority remains explicit.

Authority level Permitted activity Required oversight
Assist Retrieve, organise, extract, translate or summarise information without changing the case decision. Investigator verifies the sources and resulting content.
Recommend Suggest priority, scope, relationships, next actions or a possible disposition. An authorised person evaluates and accepts, changes or rejects the recommendation.
Act Execute predefined searches, requests, routing changes or other bounded workflow actions. Permissions, action limits, approval thresholds, monitoring and reversal procedures govern execution.

Within one system, tasks may operate at different authority levels. Evidence retrieval may run automatically while a reporting decision remains reserved for a designated human authority.

03

The AI Action Record

Rather than the model alone, the relevant unit of control is the complete action performed within the case.

For each material AI contribution, the action record identifies:

  • the case and task;
  • the input data and retrieved sources;
  • the instructions or workflow applied;
  • the model, version and configuration;
  • the tools and systems the AI could access;
  • the output produced;
  • any confidence or uncertainty indicator;
  • the human reviewer and resulting decision;
  • corrections, rejected content and overrides;
  • any action executed in another system.

That record allows the institution to reproduce the output and determine whether a later model, data or system change affects the original case.

04

Source-Grounded Analysis

For every material factual statement, generated text retains a direct connection to the relevant source record, date and case location.

Within the case, four categories remain distinct:

  • information extracted directly from a source;
  • a generated summary of that information;
  • an inferred relationship or interpretation;
  • a recommended decision or action.

Once generated, a narrative forms part of the analytical work product. It does not become independent evidence merely because it appears in a case record.

From any generated statement, investigators can open the supporting source, inspect the original context and correct the output without losing the previous version.

05

Risks Specific to Agentic Workflows

Because an agent combines reasoning with system access and task execution, its risk extends beyond inaccurate text.

Material risks include:

  • unsupported factual statements;
  • omission of contradictory evidence;
  • compression that removes important context;
  • incorrect entity resolution;
  • reliance on stale or superseded information;
  • sensitive-data leakage;
  • instructions embedded in retrieved documents influencing the agent;
  • access beyond the assigned case or legal entity;
  • unintended status changes, exports or customer contact;
  • repeated execution of the same action;
  • silent changes to the underlying model;
  • excessive reliance on a plausible recommendation.

To bound those risks, safeguards include source allowlists, constrained retrieval, separate read and write permissions, transaction limits, approval gates, action logs, duplicate prevention, rollback procedures and continuous monitoring.

06

Evaluation Before and After Deployment

Before deployment, AI performance is tested against representative cases, including complex, incomplete and contradictory matters. Evaluation examines:

  • accuracy of source attribution;
  • unsupported-statement rate;
  • material evidence omitted from summaries;
  • quality of entity and relationship matches;
  • consistency across comparable cases;
  • detection of missing evidence;
  • escalation performance;
  • investigator correction and rejection rates;
  • effect on decision quality;
  • effect on timeliness and backlog;
  • performance across customer, product and language segments;
  • changes following model or data updates.

Beyond time savings, deployment success depends on preserved evidence quality, reliable escalation and accountable decisions.

07

Human Authority and Institutional Accountability

By approving generated analysis, an investigator assumes responsibility for its use. The interface therefore makes verification practical: sources remain accessible, uncertainty remains visible and material changes require conscious approval.

For each use case, the institution defines which decisions require human authority, which tasks an agent may execute and which information the agent may access. These boundaries remain enforceable through the case-management architecture and visible in the audit trail.

When combined with source provenance, bounded authority and reproducible human judgement, agentic case management can reduce repetitive work and expand investigative context sustainably.

Structured Reporting and Interoperability

As regulatory data becomes more structured and evidence assembly more automated, case management increasingly supports reliable exchange among monitoring, customer, payment and reporting systems. Narrative remains important, drawing on identifiable data that can move without losing meaning or provenance.

01

The Shift Toward Structured Regulatory Data

On 2 July 2026, AMLA opened its consultation on draft technical standards for reporting suspicions and providing transaction records, which runs until 20 September 2026.

Under the draft, proposed templates cover suspicion reports and transaction-record submissions to Financial Intelligence Units. AMLA also states that the formats can support automated methods for internal reporting within obliged entities.

Because the proposals remain in draft form, they indicate architectural direction rather than binding rules: institutions need case data that can populate structured reporting fields while preserving the evidence and reasoning behind them.

02

A Portable Case Record

Across migrations, vendor platforms, legal entities and downstream reporting processes, stable identifiers remain attached to:

  • the case and any related cases;
  • originating alerts and referrals;
  • persons, entities and beneficial owners;
  • accounts, instruments, wallets and devices;
  • transactions, payment messages and linked events;
  • evidence sources and documents;
  • investigation findings and decisions;
  • reporting packages and authority acknowledgements;
  • customer, transaction and remediation actions.

These identifiers keep records and relationships traceable. When a source system is merged or replaced, the relationship between the historical identifier and its successor remains intact.

03

Connecting Case Data Across Systems

Between case creation and final action, case management may exchange information with:

  • transaction-monitoring and screening platforms;
  • customer and beneficial-ownership records;
  • payment, ledger and messaging systems;
  • document and communication repositories;
  • fraud, cybersecurity and operational-risk systems;
  • regulatory reporting platforms;
  • data-quality and model-governance tools;
  • authorised external providers and public authorities.

For each connection, the operating design defines the authoritative source, permitted use, update frequency and response to correction.

Depending on its function, an integration may provide:

  • real-time queries for current information;
  • event notifications when relevant data changes;
  • structured case creation and routing;
  • evidence retrieval by reference;
  • controlled updates to customer or monitoring systems;
  • reporting packages and transaction-record exports;
  • acknowledgements and status reconciliation;
  • bulk extraction for authorised lookbacks or remediation.

Where the payment lifecycle contains several operational timestamps and statuses for one transaction, the case preserves the relevant states rather than reducing the transaction to its final settlement result.

04

Structured Data and Narrative

Structured fields support validation, aggregation, routing and automated reporting. Narrative explains context, relationships, uncertainty and reasoning.

Structured information Narrative contribution
Subjects and identifiers Explains the roles and relationships between them.
Transactions, currencies and dates Explains the pattern, sequence and economic context.
Products, channels and jurisdictions Explains why their combination matters to the investigation.
Reason and disposition codes Explains the evidence supporting the conclusion.
Reporting and action decisions Explains the applicable criteria and decision rationale.
Evidence references Explains how the sources answer the investigation questions.

Before submission or closure, the narrative and structured fields remain consistent; material differences trigger review.

05

Time, Currency and Identity

Across systems and jurisdictions, interoperable records retain:

  • local time, time zone and coordinated reference time;
  • original transaction amount and currency;
  • any converted amount, rate, source and conversion time;
  • original and normalised names;
  • scripts, transliterations and aliases;
  • account and instrument identifiers in their original format;
  • transaction direction from the perspective of each relevant party;
  • event, processing, settlement and reporting dates.

Even after transformation, the information needed to reconstruct the activity remains available.

06

Data Quality at the Reporting Boundary

Before submission, the reporting workflow identifies missing, invalid and conflicting information. If a required value remains unavailable, the record states the reason rather than inserting an assumed value.

Validation may examine:

  • identifier format and uniqueness;
  • mandatory relationships between fields;
  • date and transaction sequence;
  • currency and amount reconciliation;
  • consistency between subjects and accounts;
  • consistency between structured data and narrative;
  • completeness of supporting transaction records;
  • permitted character sets and transliteration;
  • jurisdiction-specific reporting requirements.

At completion, the final package retains the validation result, preparer, approver, submitted version and authority response.

07

Reconciliation and Change

When information changes after a case or report has moved to another system, the correction process determines:

  • which systems received the affected record;
  • whether the change alters an investigation or reporting decision;
  • whether an amendment or supplemental submission is required;
  • which version remains authoritative;
  • who confirms reconciliation.

Once acknowledgements, filing references, authority requests and completed actions return to the case, bidirectional integration completes the record and supplies structured feedback to the controls that originated the investigation.

08

Portability and Long-Term Access

During regulatory requests, lookbacks, institutional restructuring and platform replacement, the institution can export an authorised case package containing its evidence references, event history, decisions, relationships, access classifications and downstream actions.

That portability also reduces dependence on a vendor-specific interface for reconstructing historical decisions.

Structured interoperability turns case management into a durable layer between detection, investigation and regulatory operations. It allows information to move while preserving the context, authority and evidence that give it meaning.

Responsibility Across Institutions and Providers

Case work may be distributed across banks, fintechs, group entities, technology vendors and managed investigation teams. The operating model should identify which party supplies data, performs each task, controls the decision and remains accountable under the applicable framework.

A service provider can perform investigation work. Access to a workflow does not create authority to make every decision recorded within it.

01

Dividing the Responsibilities

Responsibility Questions the operating model should answer
Signal creation Which party operates the monitoring, screening or referral mechanism and validates its output?
Case formation Who accepts the signal, establishes the case and confirms its initial scope?
Evidence provision Which party holds the customer, transaction, payment and communication records?
Investigation Who gathers evidence, performs analysis and prepares the recommendation?
Review and approval Which legal entity and authorised person approve the disposition?
Regulatory reporting Who makes the reporting decision, submits the report and handles subsequent requests?
Customer or transaction action Which party can restrict activity, update risk treatment or change the relationship?
Quality assurance Who tests case quality independently from production delivery?
Remediation Who corrects the data, system, model or process weakness identified through the case?
Record retention Which party preserves the authoritative evidence and provides access throughout the required period?

Responsibility should follow the actual control, legal obligation and decision authority of each participant. The bank–fintech responsibility framework should remain visible inside the case rather than being inferred from commercial branding or the location of the technology platform.

02

Managed Investigation Services

A managed service may perform intake, evidence collection, investigation, drafting and first-line quality review. The appointing institution should retain sufficient capability to direct, challenge and verify the work.

The arrangement should define:

  • investigator qualifications and permitted locations;
  • customer, product and jurisdictional coverage;
  • access to systems and protected information;
  • investigation and escalation criteria;
  • review and decision authority;
  • capacity and backlog obligations;
  • quality sampling and defect remediation;
  • use of automation, models and AI;
  • subcontractors and further outsourcing;
  • incident and confidentiality responsibilities;
  • audit, regulator-access and information-production rights;
  • transition and exit procedures.

Production targets should remain consistent with the evidence and decision standards applied to internal investigators.

03

Evidence Access and Institutional Oversight

The accountable institution should be able to retrieve the complete case record, understand the analysis and reproduce the decision without depending on an individual provider employee or proprietary interface.

Oversight requires access to:

  • source evidence and provenance;
  • investigator actions and searches;
  • versions of narratives and findings;
  • reviewer comments and overrides;
  • queue, ageing and quality information;
  • automation and model records;
  • completed reporting and remediation actions.

A provider dashboard may summarise performance. The underlying case evidence remains necessary for institutional challenge, audit and regulatory examination.

04

Handoffs Between Participants

A handoff should identify the sending party, receiving party, transferred information, outstanding actions, deadline and moment at which responsibility changes.

The sender retains responsibility until the recipient acknowledges acceptance. Rejected, incomplete or technically failed handoffs should remain visible in the originating queue.

Where several institutions maintain local cases, common identifiers should connect the records while preserving each entity’s authority, confidentiality restrictions and reporting obligations.

05

Platform Change and Provider Exit

Case continuity should survive a change of vendor, service provider or institutional structure. The exit framework should provide an authorised export of:

  • open and closed cases;
  • evidence and source references;
  • complete event histories;
  • relationships and linked identifiers;
  • decisions, approvals and overrides;
  • access classifications;
  • reporting references;
  • continuing actions and reopening conditions.

The institution should test whether exported records remain searchable, readable and reproducible before retiring the previous platform.

Where Case Management Fails

Failure pattern Consequence Required safeguard
The alert becomes the case without formal intake Ownership, scope and decision criteria remain unclear. Record acceptance, accountable owner, initial scope and preserved trigger.
Evidence changes with the source system A reviewer cannot establish what information supported the original decision. Preserve material snapshots, versions and timestamps.
Narratives contain the only usable information Reporting, analytics and control feedback require manual reconstruction. Connect structured fields with source-grounded narrative.
Scope expands without a recorded decision The final disposition loses its relationship to the original concern. Record each material scope change, authority and resulting deadline.
Priority and suspicion become interchangeable Urgent cases receive predetermined conclusions and resources become distorted. Maintain separate priority, severity, confidence and complexity assessments.
Paused statuses conceal ageing Backlog and deadline exposure disappear from management reporting. Preserve calendar age, pause reason, dependency owner and escalation date.
Reporting and customer actions share one decision Filing, relationship and transaction outcomes occur without the correct authority. Record each decision separately with its own criteria and approver.
Closure relies on generic language The evidence cannot explain why the matter ended. Require a concise case-specific rationale linked to material facts.
Protected and shareable information remain mixed Permitted collaboration may expose confidential reporting information. Classify facts, analysis, reporting information and authority-derived material separately.
Several institutions investigate without common identifiers Evidence fragments and connected activity appears unrelated. Link local cases while preserving entity-level ownership and restrictions.
A provider performs the work without full evidence access for the institution Oversight depends on summaries and contractual assurances. Preserve retrieval, audit, export and reconstruction rights.
AI-generated content becomes evidence Unsupported or compressed statements can influence decisions as if independently verified. Retain source citations and distinguish extraction, summary, inference and recommendation.
Throughput targets dominate quality Teams reduce scope, defer complex work or close cases with weak reasoning. Combine timeliness with evidence, review, reopen and outcome measures.
Case outcomes remain inside the case platform Monitoring, customer risk and data weaknesses recur. Return structured findings to accountable control owners and track the resulting change.

Strong case management keeps evidence, authority, time and responsibility connected from intake through final action. Weakness appears when one of those connections becomes invisible.

Connected Compliance Systems

Case management connects detection, investigation, decision and regulatory action. Its effectiveness depends on reliable handoffs to the systems that create signals, hold evidence and execute resulting decisions.

System Relationship to case management
Compliance Infrastructure Provides the wider governance, data, technology and operating environment.
Transaction Monitoring Detects and structures transaction activity for review, then receives investigation feedback.
Sanctions Screening Produces screening escalations and retains responsibility for matching and screening logic.
KYC & KYB Supplies customer, ownership and relationship evidence and receives relevant risk updates.
Payment Controls Creates payment exceptions and executes authorised transaction-level actions.
Regulatory Operations Converts approved decisions into filings, authority communications and remediation activity.
AML Programs Governs policy, risk coverage, testing, training and programme-level improvement.
Compliance Architecture Defines system boundaries, decision rights, control relationships and evidence continuity.
Bank–Fintech Responsibility Allocates investigation, reporting and customer-action responsibilities across participants.

Sources