Executive summary: More data sources don’t produce a better investigation. A risk-based approach does: calibrating how deep an investigation goes to what the specific case actually presents, the same standard already required of the reader’s own program. In practice that means entity resolution built for real-world aliases and transliteration, beneficial ownership tracing that follows a structure through every jurisdiction it touches instead of stopping at the first opaque layer, and a documented record of which sources were corroborated before they shaped a conclusion. The result is a case file an examiner can retrace, built on evidence that was checked before it counted.
A routine customer review doesn’t get the same depth as a flagged one, and it shouldn’t. But “routine” has come to mean a quick search, a screenshot of the first page, and a note in the file. Meanwhile the case that actually needed depth got the same quick pass as everything else, because there wasn’t time to tell the difference until it was too late.
That’s the real shape of the volume problem. It isn’t too many sources per case. It’s too many cases getting the same shallow pass, with no reliable way to route the ones that need real scrutiny into it.
Cross-border ownership enhances the problem. A structure that spans three jurisdictions means three registries, three disclosure standards, and three sets of naming conventions that don’t line up. Adverse media in a language your team doesn’t read natively either gets skipped or gets machine-translated and taken on faith.
When a case slips through, the instinct is predictable: lower the threshold, widen the matching, add another source. It produces more alert noise, not more insight, and the AML investigation backlog it was supposed to fix gets worse.
None of this is solved by casting a wider net. Reading more of everything doesn’t fix a system that can’t tell you where to look harder in the first place. That’s a different problem than access to data. It’s a problem of knowing where the risk actually sits, case by case, before you spend the time.
A Risk-Based Approach to AML Investigation Software

You already don’t screen every customer against every possible source at maximum depth. A risk-based approach means the depth of scrutiny matches the risk, not that every case gets identical treatment. That’s the regulatory standard, not a shortcut around it.
The same logic decides which sources get queried on a given case and how deep the investigation runs. A shell company flagged for adverse media doesn’t get the same pass as a routine KYC refresh. A correspondent banking relationship tied to a higher-risk jurisdiction gets more scrutiny than a domestic vendor payment, the same way your own program already tiers risk by exposure.
This is judgment, applied consistently and at a pace no analyst pool can match unassisted. It’s calibrated the same way your own risk-based framework is calibrated: to what the specific case actually presents, not to a fixed checklist run the same way on every alert regardless of what it’s showing.
Built by People Who’ve Run These Investigations
The reasoning behind where to look and how hard doesn’t come from a generic rule engine. It comes from people who’ve done this work: investigators and sanctions officers with real casework behind them, not a compliance vendor’s idea of what casework looks like.
Tangos’ investigation reasoning is built on more than 75 years of combined financial crime, sanctions, and intelligence experience, and more than 5,000 regulator-grade investigations led by the people who shaped it. That’s the difference between a system that treats a PEP hit in a wealth-management account the same way it treats a shell-company red flag in a trade transaction, and one that knows those two alerts call for different questions entirely.
That experience is specific to the type of risk being investigated. A correspondent banking review draws on what actually gets missed in nested foreign-bank relationships. A trade-finance case draws on the invoice-mismatch patterns experienced examiners look for first, not a generic checklist applied the same way to every alert.
The result is reasoning tied to real casework experience, encoded once and applied consistently, so it’s available on every case instead of only the ones a senior investigator has time to touch personally. It’s how expertise scales without adding headcount: the judgment is captured once, not re-taught to every new hire, and it compounds as institutional knowledge instead of walking out the door with the analyst who had it.
Nothing Counts Until It’s Corroborated
A source only carries weight in a conclusion once it’s been checked. That doesn’t mean every input has to originate from a premium data feed. Much of EDD work runs on public search results and adverse media of uncertain provenance, and pretending otherwise would make the reasoning less credible, not more.
What changes is what happens to that input before it shapes a finding. A single adverse-media hit doesn’t settle anything on its own. It gets corroborated against independent sources, checked for consistency, and weighted accordingly, the same discipline a careful analyst already applies without necessarily writing it down every time.
That weighting is documented, not assumed. When two sources agree, that’s noted. When they conflict, that’s noted too, along with which one carried more weight and why, the same way a SAR narrative has to show its work rather than just assert a conclusion. A finding built on one unverified post looks different in the case file than one built on three independent, consistent sources, and it should.
This is what answers the question this reader carries into every case: will this hold up if an examiner asks me to justify it. It holds up because no source shaped a conclusion without being weighed first, and the record of that weighing sits in the case file, not buried somewhere it can’t be reviewed.
Following Beneficial Ownership Across Borders

Beneficial ownership tracing is where EDD data sources get stress-tested hardest, and it’s usually where manual review runs out of time first. A structure with ten layers across three or four jurisdictions doesn’t resolve to one owner from a single registry search. It takes pulling company filings, property records, and litigation history from each jurisdiction the structure touches, and reconciling naming conventions and disclosure standards that don’t match from one registry to the next.
The investigation works through this the way a thorough analyst would, just without running out of hours. It queries the registries that actually matter for the structure at hand, whether that’s Companies House, SEC EDGAR, federal court records, property registries, or global corporate-ownership data, and traces ownership percentages through each layer instead of stopping at the first shell that comes back opaque. Nominee directors and trust arrangements get flagged as what they are, not treated as a dead end. Ownership percentages are calculated against the threshold that actually applies to the case: the 25 percent test under EU and UK rules, the 50 percent rule under OFAC guidance, whichever regime governs.
Correspondent banking risk gets the same network-tracing treatment. A respondent bank’s nested foreign-bank relationships and downstream customer exposure get traced the same way an ownership structure does, because they’re the same kind of problem: relationships hidden a few layers deep, across borders, in records that don’t share a common format.
The output is a documented ownership finding: which registries were checked, what each layer showed, and which threshold applied to the result. Every layer traced is a layer an examiner can retrace.
The Name Problem
This is the friction every sanctions and EDD team already knows by name. The same individual shows up as five different spellings across five different systems. A name transliterated from Arabic, Persian, or Cyrillic script rarely comes through the same way twice, and a sanctions list built around one romanization won’t catch a variant nobody typed exactly that way.
A missed alias isn’t a data quality issue to the team that missed it. It’s a compliance failure with a name attached to it, discovered during an exam or, worse, after the fact.
The investigation treats this as the primary problem, not an edge case. Entity resolution for sanctions screening runs across names, aliases, addresses, registration numbers, and relationships together, not name-matching in isolation. It works across more than 30 languages, so adverse media and registry records in a script your team doesn’t read natively still get evaluated instead of skipped. A hit doesn’t get dismissed just because the spelling doesn’t match your system’s index exactly. It gets resolved, with the reasoning for the match, or the non-match, documented in the case.
The gap between a sanctions list entry and the dozen ways a name might actually appear in the world is exactly where sanctions screening false negatives live. Closing that gap isn’t a data problem. It’s an investigation problem.
That gap is where real exposure hides, and it’s the area where getting it wrong carries the highest cost: a true match dismissed as noise, or a name buried three transliterations deep in a registry nobody thought to check in the original script.
Staying Current as Guidance Changes
Sanctions programs change. FATF issues new guidance. OFAC adds designations and delists others. A typology that was rare two years ago becomes the pattern of the quarter. Every compliance program already runs a periodic policy review to keep pace, because static procedures go stale the moment the regulatory landscape moves and nobody updates the manual.
The reasoning behind Tangos investigations gets the same discipline. New designations and guidance changes are tested against how the reasoning currently handles them, not assumed to already be covered. Edge cases and near-misses get reviewed the way a compliance team reviews its own close calls, and what’s learned feeds back into how the next case gets investigated.
The reasoning is reviewed and adjusted on a cycle, the same disciplined way your own program is reviewed, so it doesn’t drift out of step with what FATF, OFAC, or your own regulator currently expects. Institutional knowledge that compounds only compounds if someone keeps it current. That review is where it happens.
The Standard You’re Already Held To
When an examiner asks why an investigation looked where it looked, the weak answer is that the procedures said so. Procedures explain what happened. They don’t explain why it was the right call for this case.
The answer that holds up is specific: this case presented this risk, so the investigation went this deep, queried these sources, and reached this conclusion, and every step of that reasoning traces back to evidence that was checked before it counted.
That’s the standard this reader is already held to in every other part of the job. The investigation should be able to meet it too, and produce an examiner-ready case file for the moment someone asks.
Ready to transform your investigation workflow?
See how Tangos eliminates alert backlogs and accelerates financial crime investigations.
Summary
- Depth of scrutiny should match risk, not treat every case the same. That’s already the regulatory standard this reader works under.
- No source shapes a conclusion until it’s corroborated against independent sources, with the weighting documented in the case.
- Beneficial ownership tracing follows a structure through every jurisdiction and threshold it touches, not just the first registry that resolves cleanly.
- Entity resolution runs across names, aliases, and transliterations in 30+ languages, because a missed variant is a compliance failure, not a data gap.
- Every finding traces back to evidence an examiner can retrace, built on reasoning shaped by 75+ years of combined investigation experience.
Frequently Asked Questions
Does an analyst still sign off on the finding, or does this run without human review? A person is accountable for every finding that leaves an investigation. Your analyst reviews a documented, explainable case file, the same way they’d review a colleague’s work. Judgment stays with your team. What changes is how much of the underlying research they have to do themselves before they can apply it.
What happens when two sources genuinely conflict, not just when one is missing information? Borderline and conflicting cases get flagged for analyst review rather than force-resolved to a single answer. Both sources and the disagreement are documented in the case file. The threshold for what counts as conflicting enough to escalate is calibrated per case type, not fixed across the board.
Do we need to replace our existing screening and case management tools to use this? No. Investigations run alongside what you’ve already deployed. Alerts come in from your existing screening and case management tools, and the completed case goes back out in the format your workflow expects. There’s no rip-and-replace of your detection stack.
Is this specific to sanctions and EDD, or does it also cover AML typologies and counter-terror financing? Coverage extends across financial crime typologies: sanctions, AML, EDD, counter-terror financing, trade-based money laundering, and market abuse, each configured to the authorities and typologies your program is built around. This piece focuses on sanctions and EDD because that’s where the volume-versus-depth problem is sharpest, not because it’s the limit of what gets investigated.