How to Launder Money: Why Auditors Need to Understand How Financial Crime Actually Works
Lessons for Internal Auditors, External Auditors, Fraud Examiners and AML Professionals from George Cottrell and Lawrence Burke Files
Auditors spend enormous amounts of time testing whether organizations comply with policies, regulations, and internal controls.
Money launderers have a different objective.
They look for ways around them.
That difference makes How to Launder Money: A Guide for Law Enforcement, Prosecutors and Policymakers, by George Cottrell and Lawrence Burke Files, particularly interesting for auditors.
Published by Biteback Publishing in February 2026, the book examines how illicit value moves through the financial system and challenges whether conventional anti-money-laundering controls are actually accomplishing their intended objectives. Its chapters address cash, gold, cryptocurrency, anonymity, legal entities, real estate, bribery, and other mechanisms through which financial crime can be concealed.
For auditors, the value of the book is not learning how to launder money.
It is learning to think more like the people who are trying to defeat the controls we audit.
That is a very different skill.
The Auditor's Problem: Compliance Does Not Necessarily Equal Effectiveness
One of the central arguments of the book is deliberately provocative: the authors contend that today's AML regulatory structure imposes substantial costs while failing to stop much of the underlying criminal activity. The book ultimately argues for more effective approaches to identifying actual financial crime rather than relying excessively on compliance processes.
Whether an auditor agrees with all of that criticism or not, the argument raises an excellent audit question:
Is the control actually reducing the risk, or are we merely proving that the control was performed?
This issue reaches far beyond AML.
Consider an auditor who determines:
100% of required AML training was completed.
Required customer documentation was obtained.
Transaction-monitoring reports were generated.
Alerts were reviewed.
Policies were updated.
Required certifications were signed.
The compliance results may look excellent.
But the auditor still needs to ask:
Is the AML program actually capable of identifying suspicious activity?
That is the difference between compliance auditing and control-effectiveness auditing.
Stop Auditing the Checklist and Start Auditing the Risk
This may be the most important lesson auditors can take from the book.
Suppose an AML program contains 50 required controls.
An auditor can spend weeks determining whether all 50 controls were performed.
That produces one kind of assurance.
A stronger auditor asks another question:
How would someone actually move illicit value through this organization?
Then:
Which controls would detect it?
Then:
Could those controls be circumvented?
That changes the audit methodology.
Instead of:
Policy → Requirement → Test → Compliance
the auditor begins thinking:
Objective → Threat → Method → Vulnerability → Control → Detection → Response
That is much closer to adversarial risk assessment.
Money Laundering Isn't Just About Cash
One reason the book should interest auditors is its broad treatment of the concept of money and value.
Its chapters specifically address gold, cash, cryptocurrency, anonymity, entities, and real estate, among other topics.
That matters because an inexperienced auditor may associate money laundering primarily with cash moving through banks.
The real audit question is broader:
How can value be stored, transferred, disguised, converted, or controlled?
Once auditors start thinking about value rather than merely currency, their risk assessment changes.
Assets and transactions that may deserve attention can include:
Cash
Securities
Digital assets
Real estate
Precious metals
Business entities
Loans
Receivables
Trade transactions
Ownership interests
The auditor needs to understand the economic substance of transactions, not merely their accounting classification.
Follow the Value
Auditors are taught to follow transactions through accounting systems.
Financial-crime auditing requires something more.
Follow the value.
Ask:
Where did it originate?
↓
Who controlled it?
↓
Where did it move?
↓
Did its form change?
↓
Who ultimately benefited?
↓
Does the transaction make economic sense?
This can reveal relationships that ordinary transaction testing misses.
A payment may be properly authorized.
The accounting may be correct.
The documentation may exist.
But the auditor still needs to understand:
Who is really receiving the economic benefit?
Legal Entities Deserve More Attention
One of the book's chapters addresses entities, management and escape.
That topic should immediately interest auditors.
A legal entity can have:
A legitimate registered name
A valid address
A bank account
Tax identification
Corporate documentation
and still leave unanswered the most important question:
Who actually controls or benefits from it?
That is why beneficial ownership and related-party analysis can become important.
When auditors encounter unusual vendors, customers, investments, intermediaries, consultants, or counterparties, they should consider questions such as:
Who owns the entity?
Who controls it?
Who are its officers?
When was it established?
Why was it selected?
Does it have a legitimate business purpose?
Are there undisclosed relationships?
Does the address make sense?
Are payments consistent with its apparent business?
This is where due diligence and auditing intersect.
Lawrence Burke Files Brings a Due-Diligence Perspective
Lawrence Burke Files' background makes the book especially relevant for auditors.
Files is described as an international financial investigator and due-diligence specialist who has handled matters in more than 130 countries. His professional work encompasses due diligence, AML, finance, risk management, and anti-corruption. He is also the author of Due Diligence for the Financial Professional.
That background brings an important perspective to auditing:
Do not limit your investigation to the information management gives you.
Management-provided information is evidence to evaluate.
It isn't necessarily the entire evidence universe.
Auditors performing higher-risk work may need to corroborate information through appropriate independent sources.
George Cottrell Brings a Very Different Perspective
The book is unusual because the two authors approach the subject from very different backgrounds.
The publisher describes George Cottrell as a British financier and political strategist who was arrested in 2016 on allegations connected with a money-laundering conspiracy; the book's official site says his U.S. prison term for wire fraud informs his perspective on financial crime.
That creates an unusual combination:
Financial investigator
Someone with direct experience of the criminal-justice side of financial crime
For auditors, the combination reinforces the value of examining a control system from both sides:
How was the control designed to work?
versus:
How would someone try to defeat it?
The second question is frequently missing from conventional auditing.
Think Like an Adversary
Cybersecurity professionals use concepts such as penetration testing and red teaming.
The basic principle can be applied to financial controls.
Instead of asking only:
“Does this control operate?”
ask:
“If I wanted to circumvent this control, where would I attack it?”
That doesn't require attempting criminal conduct.
It requires analyzing vulnerabilities.
For example: Control: New vendors require approval.
The conventional auditor tests whether approvals exist.
The adversarial auditor additionally asks:
Could a fictitious vendor obtain approval?
Could an employee control both sides of the process?
Could an existing vendor record be changed?
Could ownership relationships be concealed?
Does anyone independently validate the vendor?
Now the auditor is testing the control objective, not merely the evidence of approval.
Bribery and Corruption Belong in the Auditor's Risk Universe
The book devotes a chapter to bribery.
Auditors should recognize that corrupt payments rarely arrive in the general ledger labeled:
BRIBE EXPENSE — $250,000
They may appear as apparently legitimate business expenses.
That means auditors need to understand areas such as:
Consulting arrangements
Commissions
Agents
Intermediaries
Professional services
Unusual bonuses
Charitable contributions
Vendor payments
Related parties
Unexplained reimbursements
The key question becomes:
What is the economic substance of this payment?
That is a much better audit question than simply determining whether an invoice exists.
Real Estate Can Be a Financial-Crime Risk
The book also devotes a chapter to real estate.
Again, auditors should think in terms of value.
Real estate transactions can involve:
Large dollar amounts
Multiple legal entities
Complex ownership
Intermediaries
Financing
Cross-border participants
Auditors involved with financial institutions, investment organizations, insurance organizations, real estate companies, or high-net-worth clients should understand how those characteristics affect AML and fraud risk.
Cryptocurrency Expands the Audit Risk Universe
Cryptocurrency receives its own chapter as well.
Auditors increasingly need at least a working understanding of digital assets.
That does not mean every Internal Auditor needs to become a blockchain specialist.
It does mean the auditor should recognize when specialist knowledge is required.
Questions may include:
Does the organization accept digital assets?
Does it hold them?
Who controls the wallets?
How are transactions authorized?
What third parties are involved?
How are transactions monitored?
How are digital assets valued and accounted for?
What AML risks exist?
Ignoring cryptocurrency because it falls outside the auditor's traditional accounting background is no longer a sound risk-management strategy.
Anonymity Is an Audit Red Flag
The book's treatment of anonymity also has direct relevance to audit work.
An auditor should become increasingly skeptical as the answer to:
“Who is actually behind this transaction?”
becomes more difficult to determine.
Complexity isn't proof of wrongdoing.
Neither is privacy.
But unnecessary complexity can increase risk.
The auditor should understand why the structure exists.
AML Auditors Need to Look for Control Circumvention
An AML audit should not stop with determining whether policies exist.
The auditor should test whether the program can detect attempts to circumvent them.
Consider:
Customer Due Diligence
The auditor should not merely determine whether documentation was collected.
Ask whether the information is meaningful and appropriately validated.
Transaction Monitoring
Do not merely confirm that alerts were generated.
Ask whether the scenarios are capable of identifying relevant suspicious activity.
Alert Disposition
Do not merely confirm that alerts were closed.
Examine why they were closed.
Escalation
Determine whether genuinely suspicious activity reaches people with appropriate authority.
Training
Don't merely count completion certificates.
Ask whether personnel understand the red flags they are expected to identify.
That's a much more demanding audit.
Internal Auditors Should Look for Management Override
Financial criminals don't necessarily attack the strongest control.
They look for the weakest point.
Sometimes that weakness is human authority.
The auditor should therefore consider:
Who can override controls?
Who can suppress alerts?
Who can approve exceptions?
Who can change customer information?
Who can change vendor information?
Who can modify monitoring parameters?
Who reviews those actions?
The most sophisticated control environment can be undermined if a powerful individual can circumvent it without independent review.
External Auditors Can Learn From This Too
The book isn't only relevant to AML specialists.
Financial statement auditors should also think about how laundering and financial crime could affect:
Revenue
Cash
Related parties
Investments
Receivables
Real estate
Legal contingencies
Going concern
Fraud risk
Regulatory exposure
An external auditor doesn't conduct a criminal investigation simply because something unusual appears.
But unusual transactions can require heightened professional skepticism and additional procedures.
Use Data Analytics to Look for the Unexpected
Modern audit technology creates an important opportunity.
Rather than only sampling individual transactions, auditors can analyze populations for unusual characteristics.
For example:
Unusual Counterparty
Unusual Amount
Unusual Geography
Unusual Timing
Unusual Approval
Unusual Transaction Pattern
does not automatically equal money laundering.
But it may equal:
Ask another question.
That is often where good auditing begins.
AI Can Help Auditors Think More Broadly About AML Risk
AI can also assist with financial-crime auditing when used within appropriate confidentiality and governance requirements.
An auditor could use an approved AI environment to help:
Develop AML risk scenarios
Generate interview questions
Analyze policies
Compare procedures with regulatory requirements
Analyze large collections of narrative information
Identify inconsistencies
Develop potential red flags
Challenge preliminary conclusions
Summarize investigation materials
A particularly useful prompt might be:
“Act as a skeptical AML audit manager. Identify ways this control could fail to detect suspicious activity and develop audit procedures to determine whether those vulnerabilities exist.”
That is a much stronger use of AI than:
“Write me an AML audit program.”
Compliance Is Not the Same as Risk Reduction
This brings us back to the book's central challenge.
Cottrell and Files argue that existing AML regulation often imposes significant compliance burdens without stopping enough underlying criminal activity.
Auditors do not have to accept every policy conclusion in the book to benefit from that argument.
We should welcome the challenge.
Because every Internal Auditor should occasionally ask:
Are we auditing whether management complies with the control—or whether the control actually manages the risk?
Those are not always the same thing.
A Different Kind of Book for Auditors
How to Launder Money isn't a traditional auditing textbook.
That is precisely why it may be useful.
Its published table of contents moves through money itself, laundering, bribery, gold, cash, cryptocurrency, anonymity, entities, real estate, the development and consequences of AML laws, and ultimately recommendations for improvement.
That forces auditors to look at financial crime from outside the audit program.
And that perspective matters.
Auditors need to understand not only:
How controls are supposed to work.
They also need to understand:
How people try to get around them.
The Bottom Line for Auditors
The greatest value of How to Launder Money for an auditor is not its provocative title.
It is the mindset behind the subject.
Financial criminals are adaptive.
They look for gaps.
They exploit complexity.
They move value into different forms.
They use intermediaries.
They exploit weak due diligence.
And when controls change, they adapt.
Auditors therefore cannot rely solely upon yesterday's audit program.
A stronger financial-crime auditor thinks:
Understand the Business
↓
Understand How Value Moves
↓
Identify the Financial-Crime Risk
↓
Understand the Criminal's Potential Objective
↓
Identify Control Vulnerabilities
↓
Test the Controls
↓
Look for Circumvention
↓
Follow the Exceptions
↓
Evaluate Whether the Program Actually Reduces Risk
That is the larger lesson.
Don't simply audit the AML program. Audit whether the AML program can actually detect the behavior it was designed to stop.
For Internal Auditors, External Auditors, CFEs, AML professionals, compliance officers, and financial investigators, How to Launder Money provides a provocative way to challenge conventional thinking about financial-crime controls.

Comments