What it means
The category is broad because the crimes share a motive rather than a method. Fraud involves deception to obtain money or property, money laundering disguises the origin of criminal proceeds, bribery buys improper influence, and market abuse exploits information or price manipulation.
Grouping them makes sense to regulators because the same controls, monitoring and reporting infrastructure tends to address them all. For ordinary businesses the most immediate exposure is fraud, and the most common single loss is business email compromise.
Someone impersonates a supplier or a senior executive, sends convincing payment instructions and diverts a legitimate payment to a criminal account. The defence is almost always procedural rather than technical: verify bank detail changes by calling a known number, and require two people to authorise payments above a threshold.
The second exposure is being used rather than targeted. A company that accepts large cash payments, deals in high-value goods, or trades in jurisdictions under sanctions can find itself moving criminal money without knowing it, and the legal consequences of failing to have adequate controls can attach even where nobody in the business acted dishonestly.
This is why customer due diligence and source-of-funds checks exist. Enforcement has shifted decisively towards holding organisations responsible for prevention rather than only punishing individual wrongdoers.
Regulators expect documented risk assessments, staff training, screening of customers and suppliers, transaction monitoring and clear escalation routes for suspicions. Being able to evidence that the systems existed and were followed is frequently the difference between a warning and a substantial penalty.
The costs of getting it wrong extend well past any fine. Bank accounts can be frozen during investigation, insurers may decline claims where controls were absent, customers and lenders walk away, and senior managers can face personal liability.
For most businesses the prevention spend is modest compared with the disruption a single serious incident causes.
In practice
Real-world examples.
Example
A construction firm receives an email that appears to come from a long-standing subcontractor advising new bank details, and pays $84,000 to a criminal account. A written policy requiring a callback to a previously verified number would have stopped it, and the firm introduces one the same week.
Example
An accountancy practice onboarding a new client notices that the source of a $500,000 deposit cannot be explained by the client's stated business. The firm declines the engagement and files a suspicious activity report rather than proceeding.
Example
A distributor discovers that its sales agent in an overseas market has been making unofficial payments to customs officials to speed up clearance. Because bribery liability can attach to the company for acts by people associated with it, the board suspends the agent and commissions an independent review.
Think of it
“Financial crime is illegal activity for money-crimes committed for financial gain.
Case study
Seen in the real world.
This is an illustrative and entirely fictional example. Ravenstone Trading, an invented importer of industrial fasteners, ran a lean finance function where a single accounts payable clerk both set up new suppliers and released payments. There was no callback procedure and no dual authorisation on any payment under $100,000.
Over four months a criminal group created three fictitious supplier accounts using convincing documents and letterheads, then submitted invoices sized just below the authorisation threshold. By the time a routine supplier statement reconciliation exposed the gap, $412,000 had left the business, and Ravenstone's insurer reduced the claim substantially on the grounds that basic segregation of duties had been absent.
The fictional remediation was neither expensive nor complicated: supplier setup was separated from payment release, every bank detail change required a call to a number held on file before the change was made, and payments above $10,000 needed two approvers. The controls cost Ravenstone almost nothing beyond a fortnight of process redesign.
Watch out
Common mistakes.
- Assuming financial crime is only a concern for banks, when suppliers, professional firms and ordinary trading companies are all exposed and often less well defended.
- Treating anti-fraud controls as an IT problem, when the majority of successful attacks exploit weak human processes such as unverified payment detail changes.
- Writing a policy document and never testing it, so nobody discovers the gaps until a real incident forces the issue.
Questions
People also ask.
What is the single most effective control for a small business?
Independent verification of any change to supplier bank details, using a phone number already held on file rather than one supplied in the request.
Does financial crime always involve dishonesty by someone inside the company?
No, businesses are frequently the victim or the unwitting conduit, though failing to maintain adequate prevention systems can still create legal exposure.
How much should a business spend on prevention?
Enough to match its risk profile, which for most trading companies means clear payment procedures, staff training and periodic testing rather than expensive monitoring software.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
