
Reporting by the Financial Times, Wall Street Journal and Reuters has exposed the scale of A7, the Russia-linked sanctions-evasion network that allegedly moved $6.9 billion through global banks using front companies and forged documents. FinCEN’s subsequent findings describe a wider operation whose overseas sub-agents processed more than $17 billion between January 2025 and June 2026, with accounts at approximately 435 financial institutions across at least 83 countries.
FinCEN also proposed restrictions on funds transfers involving A7’s overseas sub-agents, while the Office of Foreign Assets Control (OFAC) sanctioned the network as a significant transnational criminal organisation. The alert gives institutions a public account of the ownership links, intermediaries and transaction patterns they should examine when assessing exposure.
For capital-markets firms, the case offers a starting point for examining the division between financial-crime controls and investment-product due diligence. Becki LaPorte, Principal for AML Strategy and Innovation at FinScan, sees gaps where product specialists and sanctions experts assess different aspects of the same business.A former chief AML officer at a large US broker-dealer, LaPorte recalls working with product due-diligence teams that consulted her when they spotted something unusual. “They would bring me in if something was funky,” she says in discussion with RegTech Insight. “But they wouldn’t bring me in on a regular basis.”
Product Review
That arrangement places considerable responsibility on people whose expertise lies outside financial crime. LaPorte questions how many specialists reviewing investment products have the knowledge to recognise sanctions-evasion techniques involving associates, family members or obscured ownership.
“One doesn’t often give the other a seat at the table,” she says of the relationship between the two functions.
Her examples include business development companies, which invest in businesses, and real estate investment trusts. She also questions the depth of scrutiny applied to the companies within a fund. Investment due diligence may examine a product’s strategy and underlying assets without drawing on the sanctions team’s understanding of the people behind those businesses.
These are examples of potential exposure, rather than findings that particular products have breached sanctions. They illustrate where LaPorte believes product review needs access to financial-crime expertise before an unusual relationship prompts escalation. Who decides when a product’s ownership or investment strategy warrants a specialist financial-crime review?
Intermediary Exposure
Advisers and portfolio managers add another source of exposure. LaPorte points to advisers placing trades on clients’ behalf, leaving executing firms with limited visibility of the underlying clients and their ownership links.
She also describes omnibus arrangements, where an intermediary combines business for underlying clients. The resulting distance from those clients can complicate an institution’s understanding of ultimate beneficial ownership.
LaPorte sees a related problem in the division between clearing and introducing brokers: each may expect the other to identify an issue. Firms need to understand the checks their intermediaries perform and the information available to support their own review.
Domestic Assumptions
At her former broker-dealer, LaPorte encountered resistance to the idea that a domestic firm could carry exposure to overseas sanctions risk.
“We don’t work with Russia. We don’t work with China,” she recalls hearing from colleagues.
Her response pointed to securities traded in other markets. A firm’s domestic customer base does not describe the reach of the investments it offers. Funds and externally managed strategies can introduce relationships that sit beyond the immediate account holder.
That misunderstanding also affects how firms learn from their peers. LaPorte’s independent broker-dealer compared itself with similar businesses, rather than global investment banks or clearing brokers. Different activities create different exposures, but they can also discourage firms from examining lessons outside their own peer group.
Control Capacity
Regulators’ guidance gives firms practical steps to address these gaps. FinCEN’s Section 314(b) framework allows eligible, registered institutions to share information about suspected money laundering or terrorist activity, subject to safeguards. The FCA recommends product-level sanctions risk assessments, role-specific training, oversight of intermediaries’ controls and testing against emerging evasion techniques.
For capital-markets firms, applying that guidance means bringing financial-crime expertise into product reviews, defining escalation responsibilities and using shared intelligence to investigate ownership links that individual teams cannot resolve.
LaPorte argues that commercial growth should prompt investment in trained staff, technology and preventive controls. From FinScan’s perspective, LaPorte emphasises data quality as the foundation of screening. She says the company built its screening solution on its data-management capabilities and allows institutions to configure controls for their business models. Her account of product review also identifies decisions that technology alone cannot settle, including when specialists participate and who owns escalation.
Public enforcement findings could help firms make those decisions, LaPorte argues, if they explained control failures in greater detail. A description of a technology deficiency may omit which records were missed and why. Without that detail, peers struggle to identify the corresponding weakness in their own systems.
“There’s so little information that’s given publicly,” she says. “It’s really hard to make that correction.”
Subscribe to our newsletter


