The Typology Files

AI is rewriting the rules. Learn how to stay ahead.

I document how generative and agentic AI are reshaping financial-crime compliance — where they're breaking KYC/AML controls, where they're rebuilding them, and what that means for how this work gets done next.

Try the AI Prompt Builder →

AI & Compliance

Agentic AI in Compliance: Who's Accountable When the Analyst Is a System

Agentic AI can already run adverse media research, draft EDD narratives, and triage alerts with no human touching the middle steps. The technology changes fast. The accountability question doesn't move at all — and most teams haven't worked out where it actually sits.

Jul 28, 202610 min read

AI & Compliance

The EU AI Act Quietly Split Fraud Detection and AML Into Two Different Risk Categories

Two AI systems can look almost identical — score a transaction, flag it, route it for review — and sit in completely different regulatory categories under the EU AI Act, for a reason that has nothing to do with how they work and everything to do with what they're labelled for.

Jul 26, 20269 min read

AI & Compliance

The FCA Isn't Writing AI Rules. Here's What It's Doing Instead

No AI-specific rulebook, no bespoke licensing regime — the FCA has said twice now that it isn't planning one. That's not regulatory neglect. It's a deliberate bet, and it puts more weight on judgment a compliance team already has to have, not less.

Jul 24, 20268 min read

Regulatory Update

How Disasters Like Sri Lanka's 2025 Floods Expose Weaknesses in AML Risk Management Systems

Cyclone Ditwah displaced over two million people and triggered a multi-billion-dollar relief effort. Large-scale disasters don't just test emergency response — they test every assumption a KYC/AML program makes about identity, cash, and oversight.

Jul 22, 202611 min read

Fraud Detection

A Step-by-Step Playbook for Investigating Suspected AI-Generated Fraud in Onboarding

Deepfake selfies, GAN-forged IDs, and synthetic identities are already inside the funnel. Here's a repeatable method for catching them before they clear KYC — and building a defensible case file when they don't.

Jul 18, 202613 min read

Fraud Detection

Synthetic Identity Fraud: The Typology Most Training Programs Still Get Wrong

It's not stolen identity and it's not fully fake identity — it's both, blended, and aged like a real customer. Here's why that combination breaks conventional fraud detection.

Jun 30, 20269 min read

Fundamentals

KYC, CDD, and EDD Are Not the Same Thing — Here's the Actual Difference

The three terms get used interchangeably in job postings and casually in conversation. In practice they're a hierarchy, and knowing where one ends and the next begins is what separates a checklist analyst from a risk-based one.

Jun 12, 20268 min read

Regulatory Update

What Makes a SAR Narrative Defensible (Not Just Filed)

A suspicious activity report that reads as a summary of a gut feeling doesn't hold up to regulatory review. One that reads as a chain of specific, dated observations does. The difference is almost entirely structural.

May 22, 20268 min read

Regulatory Update

Shell Companies and Beneficial Ownership: Mapping the Layers That Are Built to Confuse You

Placement, layering, and integration is the model everyone memorizes for the exam. Shell company structures are where 'layering' stops being an abstraction and becomes a genuinely hard research problem.

Apr 15, 202610 min read