# Fraud Investigation and Evidence Controls

Demo consolidation of official supervisory principles. Case names and transaction data shown in Regence are fictional.

## 1. Risk-based transaction monitoring
Financial institutions should apply risk-based AML/CFT controls capable of identifying unusual transaction patterns for review. An alert is an investigative lead, not a conclusion that fraud or money laundering occurred. Source: Central Bank of Nigeria AML/CFT supervision materials, https://www.cbn.gov.ng/supervision/AML-CFT/

## 2. Investigation chronology
An investigation record should preserve the date, value, parties, accounts, stated purpose and sequence of relevant transactions. The chronology should distinguish observed facts from analyst inference and record who performed each review step.

## 3. Related-party analysis
Reviewers should compare customer, director, beneficial-owner, address, telephone, email, introducer and account data to identify shared attributes. A shared attribute is a risk indicator requiring corroboration; it is not by itself proof of common control or wrongdoing.

## 4. Pass-through and structuring indicators
Rapid receipt and onward transfer, repeated round-value movements, splitting of an economically connected amount and transfers to parties with shared identifiers may justify enhanced review. The institution should test the activity against the customer's known business, expected account use and supporting documents.

## 5. Evidence gaps and customer enquiry
Material gaps should be stated precisely. Appropriate enquiries may include contracts, invoices, delivery records, beneficial-ownership evidence, explanations of economic purpose and independent confirmation of counterparties. Records supplied by the customer should be tested against independent sources where risk warrants it.

## 6. Investigation narrative
The narrative should identify the trigger, state the verified chronology, describe relevant links, explain why the activity is unusual, record evidence obtained and missing, and set out proportionate next steps. It should avoid unsupported allegations and preserve alternative explanations.

## 7. Escalation, reporting and confidentiality
Potential suspicious-transaction reporting is a controlled human decision under applicable law and internal authority. Staff should escalate material indicators to the designated compliance or MLRO function, preserve confidentiality, maintain the audit trail and avoid tipping off affected parties.

## 8. Governance and quality assurance
Case decisions should be reviewable, time-stamped and attributable. Independent quality assurance should test whether evidence supports the conclusion, whether contrary facts were considered and whether escalation and closure were authorised.
