Most AI-in-AML discussions begin with placement: in the detection layer, above the alert queue, inside the investigation workflow, or at onboarding. Less visible is the question that sits before all of those choices: what does the model learn from?
Before a machine-learning AML model can improve detection, someone has to define financial crime in structured terms.
That definition has to be consistent, machine-readable, and reusable across systems and teams. Most institutions lack that. They have prose. The gap between unstructured knowledge and structured knowledge is where many AI deployments in compliance quietly fail before the model is trained.
The knowledge problem in AML
AML generates large volumes of knowledge. FATF publishes typology reports. Financial intelligence units publish trend analyses. National supervisors issue guidance. Internal investigators write case notes and SAR narratives. Compliance teams draft procedures and policy. All of it is useful. Most of it is unstructured prose, and each document brings its own vocabulary.
Trade-based money laundering in one FATF report maps to trade finance abuse in a supervisor guidance note. Shell company in a SAR narrative maps to nominee shareholder structure in an internal typology memo. Red-flag indicator means different things depending on who wrote the document and for which audience. When institutions apply AI to material like this, the model absorbs the inconsistency. Features extracted from inconsistent terminology are themselves inconsistent, and a model trained on them generalises poorly – across institutions, and often within a single institution as analysts turn over. The model problem, in many cases, starts as a knowledge-structure problem.
A PRISMA-style review by Akartuna et al., Journal of Experimental Criminology, 2024 examined 105 typology and trend reports across FATF, national FIUs, supervisors, and academic literature. The review documented 16 typologies, more than 200 value instruments, more than 200 actor categories, and 2,565 red-flag indicators – collected and labelled, but reported in non-standardised ways across the corpus. The finding describes the gap that structured knowledge frameworks are designed to close. Its argument is structural: independent of any one registry, the field’s typological knowledge is fragmented enough that the inconsistency itself becomes a problem.
From unstructured AML knowledge to structured outputs – the knowledge-structuring layer that underpins detection, alert triage, and investigation models.
Knowledge structuring as an AI use case
Four AI value propositions are commonly discussed for AML: detection improvement, alert management, investigation reasoning, and knowledge structuring. Knowledge structuring is the least visible of the four, and it is foundational to the other three. It means taking unstructured AML material and turning it into structured, consistent, reusable outputs:
- KYC documents and onboarding responses become structured customer attributes that risk models can consume.
- Payment-message narratives become categorised transaction-intent fields that can be scored.
- Adverse-media articles become risk-categorised entity profiles that feed customer screening.
- SAR narratives become labelled features that can train future detection models or search historic cases.
- Typology reports become tactic, technique, indicator, and mitigation structures that guide rule engineering and model training.
Without this layer, detection models are trained on inconsistent labels, alert-triage models have no structured typology reference to score against, and investigation-drafting models have no standard vocabulary to draw from. This is also where natural-language processing and large language models can be useful in compliance without being placed near a final compliance decision. An NLP pipeline that produces structured labels from typology reports is a productive, relatively low-risk AI deployment compared with a model that scores transaction alerts directly. The labels feed human reviewers, rule engineers, and training datasets. The model is not making the compliance decision; it is helping structure the knowledge that humans and downstream systems will use.
The EU AI Act (Regulation (EU) 2024/1689), applicable from 2 August 2026, brings high-risk AI obligations into application – Articles 9 (risk management), 10 (data and data governance), 11 (technical documentation), 13 (transparency), 14 (human oversight), 14(5) (no autonomous decision on specified decisions), 15 (accuracy, robustness, cybersecurity), 26 (deployer obligations), and 86 (right to an explanation of individual decisions). Whether a given AML AI system is high-risk under Annex III turns on Commission classification guidelines under Article 6(4), signalled to publish during 2026. A knowledge-structuring pipeline that labels typology documents has a different risk shape from a system that scores individual transactions; that distinction matters for governance design and vendor selection. It is not a blanket low-risk claim, and classification depends on the deployment.
What AMLTRIX does in this layer
AMLTRIX is an openly licensed AML/CFT knowledge base structured as a four-level taxonomy: Tactic → Technique → Indicator → Mitigation. Tactics describe the high-level money-laundering or terrorism-financing objective – placement, layering, integration, or TF-specific goals. Techniques describe the specific method used to execute a tactic: smurfing, trade-based money laundering, shell-company layering, and others. Indicators describe the observable red-flag signals associated with each technique: the patterns analysts and systems look for. Mitigations describe the corresponding controls or detection measures: rule scenarios, enhanced due diligence procedures, and monitoring flags.
When institutions apply AI to SAR narratives, typology documents, or regulatory guidance, the model needs a target schema to map outputs into. Without a shared schema, each institution produces different labels from the same source material. The models built around those labels become institution-specific in ways that limit their value and make external audit of model logic harder. A shared structured vocabulary changes that. An institution doing NLP over its historic SARs can map outputs to AMLTRIX Technique identifiers. An institution building detection rules can align scenarios against AMLTRIX Indicators. An institution preparing for a regulatory examination can document its typology coverage against a public reference the regulator can also read. An institution training an alert-scoring model can build training labels using AMLTRIX Technique and Indicator identifiers, producing training data that is consistent and auditable against a public reference.
The framework also has a privacy property that matters in practice. Sharing typology structure – what to look for, and how to categorise it – does not require sharing transaction data, customer data, or case data. Institutions can converge on a common structured vocabulary without exposing confidential information. Share what to look for, not who you saw. It is a way to address the knowledge-consistency problem that broader cross-institution data pooling cannot solve, because it works inside the EU privacy ceiling rather than trying to push past it.
AMLTRIX offers machine-readable exports in STIX 2.1 format and ATT&CK Navigator format, making the framework directly consumable by technical teams building NLP pipelines, detection rule libraries, and training datasets. AMLTRIX is openly licensed under a custom open licence based on Creative Commons principles (attribution required, commercial use permitted, derivative works allowed). Not Apache 2.0; not standard CC-BY-SA.
AMLTRIX taxonomy: four levels – Tactic, Technique, Indicator, Mitigation – with examples.
What AMLTRIX is – and is not
AMLTRIX is a published structured-knowledge reference: a target schema for NLP outputs, a labelling reference for training data, and a public reference an institution can use to document its typology coverage to a supervisor in a vocabulary the supervisor can also read.
AMLTRIX is not a transaction-monitoring product, a detection engine, an alert-scoring model, a vendor product gate, or a commercial offering. It is infrastructure: a labelling reference. The taxonomy is the load-bearing part.
AMLTRIX was published as an early beta in early 2025. There has been no significant update since. AMLYZE has been capacity-constrained on this stream. The framework is a published artefact, not a live product roadmap. What remains in place is what matters for the use cases described above: the published taxonomy structure, the STIX 2.1 and ATT&CK Navigator exports, the open licence, and the sandbox-participation record. Those artefacts are public; their value does not depend on active registry extension. The open licence is, in this sense, the test of the framework. If you can use it, fork it, or extend it under those terms, it is doing the work an open infrastructure layer is supposed to do. If a partner – an FIU, supervisor, consortium, or research institution – wants to extend AMLTRIX or take stewardship, that conversation is open. The licence is permissive on purpose.
The structural argument does not depend on AMLTRIX being actively maintained. The Akartuna review, MITRE F3 in fraud, and FS-ISAC CFPF in cyber-fraud (below) describe the same gap and the same kind of answer. AMLTRIX is one EU-originated, AML/CFT-specific instance a reader can open and read.
The wider category
Cybersecurity has had MITRE ATT&CK ™ for over a decade. ATT&CK provides a shared vocabulary for adversary tactics, techniques, and procedures, used by defenders to map detection coverage, by vendors to align products, and by incident responders to describe what they observed in language that stays consistent across institutions, countries, and toolsets. ATT&CK does not tell defenders which threats to prioritise or how to respond. It provides a common structured vocabulary that makes downstream activity more consistent and comparable across organisations.
Financial crime is converging on the same category. In fraud, MITRE’s Financial Fraud Framework (F3)™ was launched in April 2026 under Apache 2.0 – seven tactics covering the fraud-incident lifecycle from Reconnaissance through to Monetisation, with F1XXX-series fraud-specific technique identifiers. Adjacent to it, the FS-ISAC Cyber Fraud Prevention Framework (CFPF), published April 2025, addresses cyber-fraud specifically. AMLTRIX sits in this category for AML/CFT: one EU-originated, openly licensed instance alongside the US-originated, fraud-specific F3 and the cyber-fraud-specific CFPF.
A common structured reference also changes conversations that today happen in inconsistent and opaque language. A vendor can describe which AMLTRIX Indicators its product addresses, letting buyers compare coverage systematically. Two institutions comparing notes on a typology pattern they have both observed can use shared terminology instead of translating between internal vocabularies. And the benefit is not limited to cross-institution communication; it applies just as much inside a single institution building consistent training labels, reviewable detection rules, and portable investigation knowledge that can withstand analyst turnover.
The CBI Innovation Sandbox cohort 1 (December 2024 – June 2025) was the regulator-supervised setting in which AMLTRIX was tested as a labelling reference, alongside privacy-preserving information-sharing tools, identity-verification work, and fraud-prevention tooling. AMLTRIX was subsequently selected as a finalist for the BIS Innovation Hub Analytics Challenge 2025 on combating financial crime (Pometry won). Both are credentials on the framework as published, not statements about update cadence.
Structured vs unstructured AML knowledge – practical comparison across vocabulary, machine-readability, training labels, audit, sharing, and AI model quality.
A practical question for teams deploying AI in AML
If your institution is introducing AI into any part of the AML workflow — detection, alert triage, investigation, or onboarding – one foundational question is worth asking before model selection: what is the model learning from?
If the answer is historic analyst decisions and SAR narratives without a structured reference, the quality of those labels determines the quality of the model. Inconsistent labels produce inconsistent models. Models trained on inconsistent labels may perform well inside the institution’s own analyst conventions and poorly against any external typology reference. If the answer includes a structured typology reference as part of the labelling process — whether AMLTRIX or another framework that serves a similar function – the model has a better chance of learning something consistent and portable. It also has a better chance of withstanding analyst turnover, because the knowledge the model has learned is encoded in a public structured reference rather than only in the implicit mental models of the analysts who labelled the training data.
The EBA Opinion and Report on ML/TF risks (July 2025) points to documented, auditable data governance – including the governance of training data and labelling processes – as core to internal model governance for AI in financial services. FATF Recommendation 15 (New Technologies) sets the standard that obliged entities identify and assess money-laundering and terrorist-financing risks arising from new technologies, including AI, before launch, and manage those risks. The FATF Methodology weighs effectiveness in practice, not just technical compliance on paper. Institutions building AI-assisted AML capabilities now should be building their labelling infrastructure with those obligations in mind.
AMLTRIX is one open attempt to make that reference available for AML/CFT – a structured knowledge layer, not a detection product, that institutions can use to make their AI better grounded and more auditable, on the terms of the published artefact.
What matters most is the category, not any one framework within it. Before AI can work reliably in financial crime detection, the knowledge that defines financial crime has to be structured. That work is invisible in a vendor demonstration and does not fit neatly in a procurement checklist, but it determines whether the detection, alert-triage, and investigation models built on top of it hold up over time. For institutions building AI-powered compliance programmes, structuring the knowledge base is not preliminary work; it is part of the foundation.
Sources & notes
- Akartuna et al., Journal of Experimental Criminology, 2024 – DOI 10.1007/s11292-024-09623-y. PRISMA-style review of 105 typology and trend reports; 16 typologies, 200+ value instruments, 200+ actor categories, 2,565 red-flag indicators. Figures are paper-internal counts of the reviewed corpus, not industry benchmarks.
- AMLTRIX – amltrix.com. Published as an early beta in early 2025; no significant update since. Custom open licence based on Creative Commons principles (attribution required; commercial use permitted; derivative works allowed). Not Apache 2.0; not standard CC-BY-SA. Machine-readable exports: STIX 2.1 + ATT&CK Navigator format.
- MITRE ATT&CK – mitre.org.
- MITRE Financial Fraud Framework (F3) – mitre.org/fraud –launched April 2026, Apache 2.0.
- FS-ISAC Cyber Fraud Prevention Framework (CFPF) – fsiac.com – April 2025.
- AMLTRIX BIS Innovation Hub Analytics Challenge 2025 – com (finalist; Pometry won). CBI Innovation Sandbox cohort 1 (December 2024 – June 2025) – centralbank.ie.
- EU AI Act — Regulation (EU) 2024/1689 – EUR-Lex. High-risk obligations apply from 2 August 2026; Annex III classification is conditional on Commission guidelines under Article 6(4), signalled to publish during 2026.
- EBA Opinion and Report on ML/TF risks across the EU financial sector, July 2025 – eba.europa.eu.
- FATF Recommendation 15 (New Technologies) – fatf-gafi.org. FATF Methodology for Assessing Technical Compliance and Effectiveness – fatf-gafi.org.
AMLYZE builds transaction monitoring, customer screening, and AML case management software for regulated financial institutions in Europe: configurable rule catalogue, no-code rule design, real-time alert processing. AMLTRIX is published openly at framework.amltrix.com under a custom open licence.








