SardineCon SF/2026

Learn More

O que é Investigation?

SUBSCRIBE

An investigation is the structured review of suspicious activity that pulls together KYC, transaction history, and outside information to reach and document a conclusion you can defend. It sits between the alert and the final disposition or SAR, and it is where the who, what, when, where, why, and how of a case actually get established.

What is an investigation, in plain English?

When an alert fires, someone has to figure out what is actually going on. The investigation is that work: a structured review that gathers the customer's KYC file, transaction history, prior alerts, and any outside or counterparty information, then weighs it all to decide whether the activity is benign or genuinely suspicious.

A good investigation follows a repeatable method and records every source pulled and every reasoning step taken along the way. It is not a hunch written up after the fact; it is a documented process that a stranger could follow and understand. The goal is a conclusion you can defend, backed by a file that shows how you got there.

It occupies the middle of the workflow, between detection and disposition. Detection says something might be wrong; the investigation establishes the who, what, when, where, why, and how; and the disposition or SAR records the outcome. Without the investigation, the other two steps have nothing solid connecting them.

How an investigation is run

  1. Frame — Understand the trigger. The analyst reviews what alerted and why, and defines what the investigation needs to resolve.
  2. Gather — Pull the evidence. KYC, transaction history, prior alerts, and counterparty or 314(b) information are collected in one place.
  3. Analyze — Establish the story. The facts are reconstructed into the who, what, when, where, why, and how of the activity.
  4. Conclude — Decide and document. A defensible conclusion is reached, with every source and reasoning step recorded in the file.

What it looks like in practice

In practice

An alert flags a customer whose account received a burst of transfers from ten different senders, then wired most of it overseas. The analyst opens the KYC file, sees the customer was onboarded as a freelance graphic designer, and finds no invoices or business history that would explain ten inbound payers in a week.

She pulls three months of transaction history, notes the inbound senders share no obvious connection to the customer, and uses 314(b) to learn two of them were themselves fraud victims. Each source and finding goes into the case file with dates and amounts. The documented conclusion, that the account is acting as a mule, supports a SAR that a reader could act on years later.

Why it matters to operators

The investigation file is the primary evidence examiners and law enforcement rely on, sometimes years after the case closed. Whatever an analyst concluded, the file is what proves the conclusion was reasoned rather than guessed. That is why documentation is not paperwork tacked on at the end; it is the substance of the work.

The hard truth operators internalize is that a sound conclusion with no documented work behind it is nearly as weak as no conclusion at all. If the reasoning and sources are not captured, there is no way to show the decision was defensible, no way for a reviewer to follow it, and no usable lead for anyone downstream. A repeatable method and contemporaneous notes are what turn individual judgment into a program that holds up under scrutiny.

Operator notes

  • Document as you go. Contemporaneous notes beat reconstruction; record each source and reasoning step while the work is fresh.
  • Follow a repeatable method. Consistency across analysts is what makes conclusions comparable and the program defensible.
  • Establish all six questions. Who, what, when, where, why, and how; a gap in any of them weakens the file.
  • Reach past your own records. Counterparty data and 314(b) often supply the piece that turns suspicion into a conclusion.
  • Undocumented is unproven. A correct call with no captured work cannot be defended when someone reviews it later.

Quick questions

How is an investigation different from an alert?

An alert is an automated flag saying something might warrant a look. An investigation is the human review that determines what is actually happening and reaches a documented conclusion. Many alerts are investigated and closed with no action.

What goes into an investigation file?

The KYC record, relevant transaction history, prior alerts, any counterparty or 314(b) information, the analyst's reasoning, and the final conclusion, with dates, amounts, and sources captured. It should let a reviewer follow the logic without the analyst present.

Why does documentation matter so much?

Because the file is the evidence examiners and law enforcement rely on later. A conclusion with no recorded work behind it cannot be shown to be defensible, so it is treated as almost as weak as no conclusion at all.

Does every investigation lead to a SAR?

No. Many end in a documented no-action disposition once the activity is explained. The investigation determines the outcome; a SAR is only one of several possible results.

What makes an investigation defensible?

A repeatable method, complete evidence, reasoning tied to the facts, and a clear record of what was and was not determined. Consistency across similar cases strengthens it further.

Go deeper

O que saber junto com Investigation