top of page
Search

How to Launder Money: Why Auditors Need to Understand How Financial Crime Actually Works

Lessons for Internal Auditors, External Auditors, Fraud Examiners and AML Professionals from George Cottrell and Lawrence Burke Files


Auditors spend enormous amounts of time testing whether organizations comply with policies, regulations, and internal controls.


Money launderers have a different objective.


They look for ways around them.


That difference makes How to Launder Money: A Guide for Law Enforcement, Prosecutors and Policymakers, by George Cottrell and Lawrence Burke Files, particularly interesting for auditors.


Published by Biteback Publishing in February 2026, the book examines how illicit value moves through the financial system and challenges whether conventional anti-money-laundering controls are actually accomplishing their intended objectives. Its chapters address cash, gold, cryptocurrency, anonymity, legal entities, real estate, bribery, and other mechanisms through which financial crime can be concealed.


For auditors, the value of the book is not learning how to launder money.


It is learning to think more like the people who are trying to defeat the controls we audit.


That is a very different skill.


The Auditor's Problem: Compliance Does Not Necessarily Equal Effectiveness

One of the central arguments of the book is deliberately provocative: the authors contend that today's AML regulatory structure imposes substantial costs while failing to stop much of the underlying criminal activity. The book ultimately argues for more effective approaches to identifying actual financial crime rather than relying excessively on compliance processes.


Whether an auditor agrees with all of that criticism or not, the argument raises an excellent audit question:

Is the control actually reducing the risk, or are we merely proving that the control was performed?

This issue reaches far beyond AML.


Consider an auditor who determines:

  • 100% of required AML training was completed.

  • Required customer documentation was obtained.

  • Transaction-monitoring reports were generated.

  • Alerts were reviewed.

  • Policies were updated.

  • Required certifications were signed.


The compliance results may look excellent.


But the auditor still needs to ask:

Is the AML program actually capable of identifying suspicious activity?

That is the difference between compliance auditing and control-effectiveness auditing.


Stop Auditing the Checklist and Start Auditing the Risk

This may be the most important lesson auditors can take from the book.


Suppose an AML program contains 50 required controls.


An auditor can spend weeks determining whether all 50 controls were performed.


That produces one kind of assurance.


A stronger auditor asks another question:

How would someone actually move illicit value through this organization?

Then:

Which controls would detect it?

Then:

Could those controls be circumvented?

That changes the audit methodology.


Instead of:


Policy → Requirement → Test → Compliance


the auditor begins thinking:


Objective → Threat → Method → Vulnerability → Control → Detection → Response


That is much closer to adversarial risk assessment.


Money Laundering Isn't Just About Cash

One reason the book should interest auditors is its broad treatment of the concept of money and value.


Its chapters specifically address gold, cash, cryptocurrency, anonymity, entities, and real estate, among other topics.


That matters because an inexperienced auditor may associate money laundering primarily with cash moving through banks.


The real audit question is broader:

How can value be stored, transferred, disguised, converted, or controlled?

Once auditors start thinking about value rather than merely currency, their risk assessment changes.


Assets and transactions that may deserve attention can include:

  • Cash

  • Securities

  • Digital assets

  • Real estate

  • Precious metals

  • Business entities

  • Loans

  • Receivables

  • Trade transactions

  • Ownership interests


The auditor needs to understand the economic substance of transactions, not merely their accounting classification.


Follow the Value

Auditors are taught to follow transactions through accounting systems.


Financial-crime auditing requires something more.

Follow the value.

Ask:


Where did it originate?

Who controlled it?

Where did it move?

Did its form change?

Who ultimately benefited?

Does the transaction make economic sense?


This can reveal relationships that ordinary transaction testing misses.


A payment may be properly authorized.


The accounting may be correct.


The documentation may exist.


But the auditor still needs to understand:

Who is really receiving the economic benefit?

Legal Entities Deserve More Attention

One of the book's chapters addresses entities, management and escape.


That topic should immediately interest auditors.


A legal entity can have:

  • A legitimate registered name

  • A valid address

  • A bank account

  • Tax identification

  • Corporate documentation

and still leave unanswered the most important question:

Who actually controls or benefits from it?

That is why beneficial ownership and related-party analysis can become important.


When auditors encounter unusual vendors, customers, investments, intermediaries, consultants, or counterparties, they should consider questions such as:

  • Who owns the entity?

  • Who controls it?

  • Who are its officers?

  • When was it established?

  • Why was it selected?

  • Does it have a legitimate business purpose?

  • Are there undisclosed relationships?

  • Does the address make sense?

  • Are payments consistent with its apparent business?


This is where due diligence and auditing intersect.


Lawrence Burke Files Brings a Due-Diligence Perspective

Lawrence Burke Files' background makes the book especially relevant for auditors.

Files is described as an international financial investigator and due-diligence specialist who has handled matters in more than 130 countries. His professional work encompasses due diligence, AML, finance, risk management, and anti-corruption. He is also the author of Due Diligence for the Financial Professional.


That background brings an important perspective to auditing:

Do not limit your investigation to the information management gives you.

Management-provided information is evidence to evaluate.


It isn't necessarily the entire evidence universe.


Auditors performing higher-risk work may need to corroborate information through appropriate independent sources.


George Cottrell Brings a Very Different Perspective

The book is unusual because the two authors approach the subject from very different backgrounds.


The publisher describes George Cottrell as a British financier and political strategist who was arrested in 2016 on allegations connected with a money-laundering conspiracy; the book's official site says his U.S. prison term for wire fraud informs his perspective on financial crime.


That creates an unusual combination:


Financial investigator


Someone with direct experience of the criminal-justice side of financial crime


For auditors, the combination reinforces the value of examining a control system from both sides:

How was the control designed to work?

versus:

How would someone try to defeat it?

The second question is frequently missing from conventional auditing.


Think Like an Adversary

Cybersecurity professionals use concepts such as penetration testing and red teaming.


The basic principle can be applied to financial controls.


Instead of asking only:

“Does this control operate?”

ask:

“If I wanted to circumvent this control, where would I attack it?”

That doesn't require attempting criminal conduct.


It requires analyzing vulnerabilities.


For example: Control: New vendors require approval.


The conventional auditor tests whether approvals exist.


The adversarial auditor additionally asks:

Could a fictitious vendor obtain approval?
Could an employee control both sides of the process?
Could an existing vendor record be changed?
Could ownership relationships be concealed?
Does anyone independently validate the vendor?

Now the auditor is testing the control objective, not merely the evidence of approval.


Bribery and Corruption Belong in the Auditor's Risk Universe

The book devotes a chapter to bribery.


Auditors should recognize that corrupt payments rarely arrive in the general ledger labeled:


BRIBE EXPENSE — $250,000


They may appear as apparently legitimate business expenses.


That means auditors need to understand areas such as:

  • Consulting arrangements

  • Commissions

  • Agents

  • Intermediaries

  • Professional services

  • Unusual bonuses

  • Charitable contributions

  • Vendor payments

  • Related parties

  • Unexplained reimbursements


The key question becomes:

What is the economic substance of this payment?

That is a much better audit question than simply determining whether an invoice exists.


Real Estate Can Be a Financial-Crime Risk

The book also devotes a chapter to real estate.


Again, auditors should think in terms of value.


Real estate transactions can involve:

  • Large dollar amounts

  • Multiple legal entities

  • Complex ownership

  • Intermediaries

  • Financing

  • Cross-border participants


Auditors involved with financial institutions, investment organizations, insurance organizations, real estate companies, or high-net-worth clients should understand how those characteristics affect AML and fraud risk.


Cryptocurrency Expands the Audit Risk Universe

Cryptocurrency receives its own chapter as well.


Auditors increasingly need at least a working understanding of digital assets.


That does not mean every Internal Auditor needs to become a blockchain specialist.


It does mean the auditor should recognize when specialist knowledge is required.


Questions may include:

  • Does the organization accept digital assets?

  • Does it hold them?

  • Who controls the wallets?

  • How are transactions authorized?

  • What third parties are involved?

  • How are transactions monitored?

  • How are digital assets valued and accounted for?

  • What AML risks exist?


Ignoring cryptocurrency because it falls outside the auditor's traditional accounting background is no longer a sound risk-management strategy.


Anonymity Is an Audit Red Flag

The book's treatment of anonymity also has direct relevance to audit work.


An auditor should become increasingly skeptical as the answer to:

“Who is actually behind this transaction?”

becomes more difficult to determine.


Complexity isn't proof of wrongdoing.


Neither is privacy.


But unnecessary complexity can increase risk.


The auditor should understand why the structure exists.


AML Auditors Need to Look for Control Circumvention

An AML audit should not stop with determining whether policies exist.


The auditor should test whether the program can detect attempts to circumvent them.


Consider:

Customer Due Diligence

The auditor should not merely determine whether documentation was collected.


Ask whether the information is meaningful and appropriately validated.


Transaction Monitoring

Do not merely confirm that alerts were generated.


Ask whether the scenarios are capable of identifying relevant suspicious activity.


Alert Disposition

Do not merely confirm that alerts were closed.


Examine why they were closed.


Escalation

Determine whether genuinely suspicious activity reaches people with appropriate authority.


Training

Don't merely count completion certificates.


Ask whether personnel understand the red flags they are expected to identify.


That's a much more demanding audit.


Internal Auditors Should Look for Management Override

Financial criminals don't necessarily attack the strongest control.


They look for the weakest point.


Sometimes that weakness is human authority.


The auditor should therefore consider:

  • Who can override controls?

  • Who can suppress alerts?

  • Who can approve exceptions?

  • Who can change customer information?

  • Who can change vendor information?

  • Who can modify monitoring parameters?

  • Who reviews those actions?


The most sophisticated control environment can be undermined if a powerful individual can circumvent it without independent review.


External Auditors Can Learn From This Too

The book isn't only relevant to AML specialists.


Financial statement auditors should also think about how laundering and financial crime could affect:

  • Revenue

  • Cash

  • Related parties

  • Investments

  • Receivables

  • Real estate

  • Legal contingencies

  • Going concern

  • Fraud risk

  • Regulatory exposure

An external auditor doesn't conduct a criminal investigation simply because something unusual appears.


But unusual transactions can require heightened professional skepticism and additional procedures.


Use Data Analytics to Look for the Unexpected

Modern audit technology creates an important opportunity.


Rather than only sampling individual transactions, auditors can analyze populations for unusual characteristics.


For example:

Unusual Counterparty


Unusual Amount


Unusual Geography


Unusual Timing


Unusual Approval


Unusual Transaction Pattern


does not automatically equal money laundering.


But it may equal:

Ask another question.

That is often where good auditing begins.


AI Can Help Auditors Think More Broadly About AML Risk

AI can also assist with financial-crime auditing when used within appropriate confidentiality and governance requirements.


An auditor could use an approved AI environment to help:

  • Develop AML risk scenarios

  • Generate interview questions

  • Analyze policies

  • Compare procedures with regulatory requirements

  • Analyze large collections of narrative information

  • Identify inconsistencies

  • Develop potential red flags

  • Challenge preliminary conclusions

  • Summarize investigation materials


A particularly useful prompt might be:

“Act as a skeptical AML audit manager. Identify ways this control could fail to detect suspicious activity and develop audit procedures to determine whether those vulnerabilities exist.”

That is a much stronger use of AI than:

“Write me an AML audit program.”

Compliance Is Not the Same as Risk Reduction

This brings us back to the book's central challenge.


Cottrell and Files argue that existing AML regulation often imposes significant compliance burdens without stopping enough underlying criminal activity.


Auditors do not have to accept every policy conclusion in the book to benefit from that argument.


We should welcome the challenge.


Because every Internal Auditor should occasionally ask:

Are we auditing whether management complies with the control—or whether the control actually manages the risk?

Those are not always the same thing.


A Different Kind of Book for Auditors

How to Launder Money isn't a traditional auditing textbook.


That is precisely why it may be useful.


Its published table of contents moves through money itself, laundering, bribery, gold, cash, cryptocurrency, anonymity, entities, real estate, the development and consequences of AML laws, and ultimately recommendations for improvement.


That forces auditors to look at financial crime from outside the audit program.


And that perspective matters.


Auditors need to understand not only:

How controls are supposed to work.

They also need to understand:

How people try to get around them.

The Bottom Line for Auditors

The greatest value of How to Launder Money for an auditor is not its provocative title.


It is the mindset behind the subject.


Financial criminals are adaptive.


They look for gaps.


They exploit complexity.


They move value into different forms.


They use intermediaries.


They exploit weak due diligence.


And when controls change, they adapt.


Auditors therefore cannot rely solely upon yesterday's audit program.


A stronger financial-crime auditor thinks:


Understand the Business

Understand How Value Moves

Identify the Financial-Crime Risk

Understand the Criminal's Potential Objective

Identify Control Vulnerabilities

Test the Controls

Look for Circumvention

Follow the Exceptions

Evaluate Whether the Program Actually Reduces Risk


That is the larger lesson.

Don't simply audit the AML program. Audit whether the AML program can actually detect the behavior it was designed to stop.

For Internal Auditors, External Auditors, CFEs, AML professionals, compliance officers, and financial investigators, How to Launder Money provides a provocative way to challenge conventional thinking about financial-crime controls.


 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page