There's a conversation happening across financial services right now, and it's long overdue. It's not just another acronym to memorize — the idea behind FRAML is fundamentally sound: fraud and AML are not two separate disciplines operating in parallel. They are two chapters in the same book. And for as long as organizations keep reading them separately, they're going to keep missing the story.

This article is about why that matters, what gets lost when the two functions operate in silos, and what it actually looks like to build a financial crime program that treats them as one.


The perception problem

Fraud is a hero story. You catch a bad actor, you recover money, you have a number to put on a slide deck. Fraud teams are easy to justify because the return on investment is obvious — prevention metrics, recovery totals, incident counts. When I built Benevity's fraud program, one of the first things I was able to show leadership was $315,000 recovered within the first month of implementing standardized processes. That's a compelling number. It's the kind of thing that gets fraud programs funded.

AML doesn't get that luxury. It's the Cinderella of financial crime — doing some of the most consequential work in the building, receiving considerably less credit for it. The value of AML is structural: it's about dismantling the organizations that move money through the financial system at scale. That takes months, sometimes years. The outcome isn't a recovered dollar figure; it's a Suspicious Transaction Report filed with a financial intelligence unit that may contribute — alongside dozens of other reports from other institutions — to a prosecution that happens years from now. The ROI is real. It just doesn't show up in a quarterly business review.

This asymmetry in visibility is one of the main reasons the two functions end up siloed. Fraud gets investment because it's easy to measure. AML is treated as a cost centre because its wins are diffuse and delayed. The result is that most organizations under-resource AML and over-silo fraud — and financial criminals benefit from both mistakes.


The sprint and the marathon

The distinction I find most useful is this: fraud is a sprint, AML is a marathon.

Fraud is reactive and immediate. A transaction looks wrong, you pull it, you investigate, you act. The timeline is compressed. The data is transactional — individual events, individual actors, individual losses. Fraud investigators are sprinters: they need to move fast, make defensible decisions under uncertainty, and close cases.

AML operates on a completely different timescale. The targets aren't individual transactions — they're people, relationships, and the patterns those relationships create over months and years. Money laundering isn't a single event; it's a process. Placement, layering, integration. By the time you're looking at the integration stage, the original fraud that generated the funds may have happened a year ago, at a different institution, under a different name. AML investigators are marathoners: patience and pattern recognition are the job.

Neither of these is more important than the other. What they are is interdependent — and that interdependence is exactly what gets lost when the functions don't talk.


What siloed organizations miss

The practical consequences of keeping fraud and AML separate are more serious than most organizations realize.

You can't see the full lifecycle of a crime. Fraud generates the dirty money. AML is supposed to catch what happens to it afterward. If your fraud team closes a case when they've identified the loss and your AML team isn't aware that a customer was flagged for fraud, no one is watching what that customer does next. The crime continues; you just stopped looking.

I built something that illustrated this gap before I had language to describe it as a FRAML problem.

The Platform Integrity Agent I developed at Benevity was scoped as a fraud tool — NPO legitimacy checks, match harvesting detection, donation pattern analysis. But as I built out the investigation pipeline, I kept running into the same problem: the fraud signals were pointing somewhere the fraud framework couldn't follow. Stage 7 of the agent — network analysis, cross-referencing EINs, board members, and platform history — wasn't just catching isolated fraudulent NPOs. It was surfacing the networks behind them. Shared board members across multiple flagged entities. Addresses that linked to prior suspensions. Organizational structures that had migrated under new names when they suspected they'd been identified.

Those are AML questions. Placement, layering, network obfuscation — the fraud was the visible surface. What the network analysis kept gesturing at was the infrastructure underneath. A fraud tool, designed well, will eventually start asking AML questions. The better question is whether your organization is set up to answer them.

You investigate the same customers twice. This is more common than it should be. A customer triggers a fraud alert. The fraud team investigates, closes the case as confirmed or inconclusive, and files it. Months later, the same customer triggers an AML alert. The AML team starts from scratch — often pulling the same data points, running the same OSINT queries, reaching the same or similar conclusions. The duplication isn't just inefficient; it means neither team ever builds a complete picture of who they're looking at.

Your reporting to financial intelligence units is fragmented. This is the one I feel most strongly about. When fraud and AML operate independently, their reports to FIUs — Suspicious Activity Reports in the US, STRs under FINTRAC in Canada — reflect only their portion of the picture. The fraud team files a SAR about a transaction. The AML team files a SAR about a pattern of behavior. The FIU receives two separate documents that don't connect, and the investigative burden of assembling the full story falls on them.

Financial intelligence units expect a holistic review of customer activity, particularly on SARs. A unified report that traces a customer's full activity — the fraudulent transactions, the behavioral patterns, the network connections — is exponentially more useful to an investigation than two partial reports that arrived separately. When we work in silos, we give FIUs puzzle pieces. When we work together, we give them the assembled picture.


The same goal, different tools

None of this should be surprising, because fraud and AML have always had the same fundamental objective: defend against financial crime and protect the system from being exploited.

The difference is methodological. Fraud defends at the transaction level. AML defends at the network level. Fraud catches the individual actor; AML catches the organization behind them. And in a world where financial crime has become professionalized — where the same networks that run fraud schemes also launder the proceeds — you need both.

Consider what a unified view looks like in practice. A customer is flagged for a suspicious donation pattern — a fraud signal. The fraud team investigates and confirms it: coordinated match harvesting, possible insider involvement. Under a siloed model, that's a closed case. Under a FRAML model, the same investigation also asks: where did the recovered funds go? Are there secondary accounts receiving payouts? Do the people involved have relationships with other flagged customers? Is there a layering pattern in the transaction history that suggests the fraud wasn't just opportunistic, but part of something larger?

Those are AML questions. They don't replace the fraud investigation — they extend it. And the answers often lead somewhere the fraud investigation, on its own, was never going to go.


What FRAML actually looks like

I want to be specific here, because FRAML can sound like a buzzword if it isn't grounded in operational reality.

At its core, a FRAML approach means shared intelligence and unified reporting. It doesn't necessarily mean a single team or a reorganized org chart — though that's one way to do it. What it requires is that fraud and AML analysts have visibility into each other's findings, that customer-level risk is assessed holistically rather than per-alert, and that reports to financial intelligence units reflect the full picture of a customer's activity on the platform.

It also means shared tooling where it makes sense. Fraud and AML draw on overlapping data — transaction history, customer identity, behavioral patterns, network relationships. A unified case management system, or at minimum a shared customer risk profile, prevents duplication and ensures that a fraud finding informs the AML review of the same customer.

The shift in mindset is the harder part. Fraud teams are trained to think in cases. AML teams are trained to think in patterns. A FRAML approach requires both — and it requires analysts who are comfortable moving between those two modes of thinking. That's not trivial. It's also, in my experience, exactly the kind of work that fraud and AML professionals find most interesting when they're given the space to do it.


Financial crime is evolving. Our response should too.

The financial crime landscape has changed significantly in the time I've been working in this space. The criminals are more sophisticated, more organized, and more deliberate about exploiting the gaps between functions. The gap between fraud and AML is one of the most reliable gaps there is — and it exists in almost every institution of every size.

The answer isn't to do what we've always done, but faster. It's to change the frame. Financial crime is not a fraud problem with an AML component, or an AML problem with a fraud component. It is a financial crime problem, and it requires a financial crime response — one that treats fraud and AML as two parts of a single program rather than two programs that happen to share a building.

FRAML is not a new idea. But it's an urgent one. The organizations that get there first will be better at detecting crime, better at supporting law enforcement, and better at protecting the people who use their platforms. That seems like a good enough reason to start.

Key takeaways

  • Fraud and AML have the same goal — defend against financial crime — but most organizations treat them as separate functions with separate mandates. That separation is a gap that financial criminals exploit.
  • Fraud is high-visibility and easy to measure. AML is slower, harder to quantify, and arguably more consequential at scale. The asymmetry in visibility leads to chronic under-investment in AML.
  • Siloed organizations miss the full lifecycle of financial crime, investigate the same customers twice, and deliver fragmented reporting to FIUs — reducing the investigative value of every SAR or STR filed.
  • FIUs expect holistic customer reviews. A unified fraud-and-AML report is exponentially more useful than two partial reports filed separately.
  • A fraud tool, designed well, will eventually start asking AML questions. The better question is whether your organization is set up to answer them.
  • FRAML in practice means shared intelligence, unified customer risk profiles, and reports to financial intelligence units that reflect the complete picture.
  • The mindset shift is harder than the structural change. Fraud thinks in cases; AML thinks in patterns. Effective FRAML programs need both — and analysts who can move between them.
  • Financial crime is evolving. A siloed response is a structurally weaker one. The frame needs to change.