FRAML is an operating model that joins fraud and AML functions, data, and controls so financial crime is handled as one problem instead of in silos. It reflects that the same events, such as scams, mule accounts, and account takeover, feed both teams, and splitting them creates blind spots between the two.
What is FRAML, in plain English?
FRAML is a mashup of fraud and AML, and it names an operating model that joins the two functions, their data, and their controls so financial crime is treated as one problem rather than two separate ones. Instead of a fraud team and an AML team that barely talk, FRAML puts their signals and alerting on shared rails.
The reason it makes sense is that the same events feed both teams. A scam, a mule account, an account takeover: each is simultaneously a fraud event and a money-laundering event. When the two functions sit in silos, the fraud team sees half the picture and the AML team sees the other half, and the gap between them is exactly where organized crime operates.
The upside of FRAML is shared signals, unified alerting, and fewer gaps. The snag is that fraud and AML answer to different regulatory drivers, data rules, and metrics, so merging them is not free. The guiding principle is to integrate the work without blurring the distinct obligations each side still carries.
Siloed vs FRAML
What changes | Siloed teams | FRAML model |
Signals | Fraud and AML each see half the picture. | Shared signals give one complete view. |
Alerting | Duplicate or conflicting alerts across teams. | Unified alerting on the same event. |
Blind spots | Crime hides in the gap between the two. | The gap closes as data is joined. |
Obligations | Cleanly separate but disconnected. | Kept distinct even as work integrates. |
What it looks like in practice
In practice
A customer falls for an investment scam and authorizes a payment to a new account at the same institution. The fraud team logs it as a scam loss and moves on. Separately, the AML team sees that receiving account collect similar payments from several unrelated victims and flags a possible mule, but never connects it to the fraud team's scam reports.
Under a FRAML model the two signals meet: the scam payments and the mule pattern are the same story. The team both supports the fraud victims and files the suspicious activity report on the mule, and it identifies the wider network faster because nobody was working with half the data.
Why you integrate the work, not the obligations
The clear win from FRAML is that shared signals and unified alerting close the blind spots that open up when fraud and AML operate apart. Because scams, mules, and account takeover are simultaneously fraud and laundering events, joining the data lets a firm see the whole pattern and act on it faster.
But merging the teams is not free. Fraud and AML answer to different regulatory drivers, different data-handling rules, and different metrics; a fraud loss number and a SAR-filing duty are not the same kind of obligation. The discipline that makes FRAML work is keeping those obligations distinct even as the operational work merges. Integrate the signals, the tooling, and the investigations, but do not blur the firm's separate SAR duties and fraud-loss duties into one undifferentiated process.
What to watch for
- Blurred obligations. A combined team that stops distinguishing SAR duties from fraud-loss handling risks failing both.
- Metric mismatch. Fraud is measured in losses prevented, AML in detection and reporting; a single scorecard can distort both.
- Data-rule conflicts. Fraud and AML sit under different data-handling and privacy constraints that a merged pipeline has to respect.
- Lost specialism. Deep fraud or AML expertise can thin out if the merged team is staffed as generalists only.
- Shared event, single owner. When one event is both fraud and laundering, make sure each obligation still has a clear owner.
Quick questions
What does FRAML stand for?
It is a blend of fraud and AML. It describes an operating model that joins the two functions, their data, and their controls so financial crime is handled as one problem rather than in silos.
Why combine fraud and AML at all?
Because the same events, like scams, mule accounts, and account takeover, feed both teams. Working them separately creates blind spots in the gap between the two functions that criminals exploit.
What is the main benefit?
Shared signals, unified alerting, and fewer gaps. A joined view lets a firm see the whole pattern behind an event and act faster than two disconnected teams could.
What is the biggest risk of a FRAML model?
Blurring distinct obligations. Fraud and AML answer to different regulatory drivers and metrics, so a merged team must keep its SAR duties and fraud-loss duties separate rather than collapsing them into one process.
Does FRAML mean one team does everything?
Not necessarily. It means integrating data, signals, and workflows. The obligations and often the specialist expertise stay distinct; the point is to connect the work, not erase the differences.
Is FRAML a regulation?
No. It is an operating model and a design choice, not a legal requirement. The underlying fraud and AML obligations remain whatever the applicable regimes require, however the firm organizes its teams.
Go deeper
- FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
- FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

