A corporate customer passes onboarding. Its incorporation documents are valid, no direct sanctions match appears, and its ownership structure looks straightforward. The customer receives a moderate risk rating.
Months later, separate facts emerge. Its director is linked to three other recently formed companies. Two use the same registered address. Several send payments to one overseas beneficiary. An intermediate shareholder has ties to a higher-risk jurisdiction, and the beneficiary appeared in an earlier investigation.
None of those facts necessarily indicates wrongdoing. Reviewed separately, each may also look unremarkable. The risk becomes more meaningful when the relationships are connected.
Graph intelligence helps compliance teams analyse how people, companies, accounts, transactions, ownership structures and risk events are connected. It does not create reliable risk information from nothing or replace professional judgement. It helps teams find meaning in information they already hold or can lawfully access, so they can investigate and document decisions with better context.
What is graph intelligence in compliance?
Graph intelligence is the use of connected data to understand relationships between entities such as individuals, companies, beneficial owners, accounts, transactions and counterparties. In compliance, it helps analysts identify indirect exposure, shared identifiers, ownership links and suspicious patterns that may not be visible in isolated records.
The model has three basic parts:
Entities: people, companies, directors, beneficial owners, accounts, transactions, addresses, devices, counterparties, jurisdictions, screening results and cases.
Relationships: owns, controls, directs, transacts with, shares an address with, uses the same account as, is a subsidiary of, or appeared in the same case as.
Context: ownership percentages, transaction values, dates, jurisdictions, screening results, customer risk ratings, source evidence and investigation history.
Put together, the information can form paths such as:
Customer -> Company -> Shareholder -> Holding company -> Beneficial owner -> Sanctions exposure
or:
Account -> Transaction -> Counterparty -> Shared beneficiary -> Related customer
Graph intelligence is therefore more than a network diagram. The diagram may help an analyst navigate the evidence, but the substantive value comes from resolving entities, connecting records, analysing paths and patterns, and making the supporting sources available for review.
Why traditional compliance reviews can miss connected risk
Compliance data is fragmented
Relevant evidence commonly sits across onboarding records, corporate registries, screening tools, transaction monitoring systems, case management platforms, spreadsheets, email and internal databases. External sources may add corporate ownership, sanctions, politically exposed person (PEP) or adverse media information.
When these sources are disconnected, an analyst has to reconstruct relationships manually. A name in a closed screening case may not be linked to a new transaction alert. A change of director may sit in a registry feed without affecting a customer view. A repeated beneficiary may be visible only by comparing several accounts.
Alerts are often reviewed one at a time
Many workflows organise work around one alert, one customer or one company. That is operationally convenient, but financial crime and ownership risk often operate through networks. The analyst may reach a reasonable conclusion about an individual record while missing a wider pattern across customers, counterparties or earlier cases.
Risk can sit several relationships away
Direct and indirect exposure are different. A customer may not be sanctioned, while an owner higher in the corporate chain is designated. A company may have no adverse information of its own but share controllers with higher-risk entities. A transaction may fit expected activity, while its beneficiary appears across apparently unrelated customer networks.
This distinction matters because the existence and legal effect of an indirect connection depend on the facts and the applicable regime. For example, the US Office of Foreign Assets Control explains that entities owned 50% or more, directly or indirectly and in aggregate, by blocked persons are themselves treated as blocked under its 50 Percent Rule. UK financial sanctions guidance applies its own ownership and control tests. Analysts should trace the path and obtain jurisdiction-appropriate advice rather than treat any graph connection as a sanctions conclusion (OFAC FAQ 401; UK financial sanctions general guidance).
Manual relationship analysis does not scale consistently
Registry searches, spreadsheet comparisons and hand-drawn ownership charts can work for a small case. At volume, they create repeated effort, application switching and inconsistent methods. They also make it harder to preserve the exact evidence, assumptions and relationship path that supported a decision.
The problem is not always that the organisation lacks data. Often, the data is not connected at the point where the analyst needs to interpret it.
How does graph intelligence work?
1. Collect relevant entities and events
The process starts with a defined investigative purpose and authorised sources. Depending on the use case, these may include KYC and KYB records, corporate registry information, beneficial ownership declarations, screening results, transaction records, device or contact identifiers, adverse media findings, customer risk assessments and case history.
Data collection should not become indiscriminate. Teams need to know why each source is relevant, how current it is and whether its use is lawful.
2. Resolve duplicate or related identities
Entity resolution is the process of determining whether records refer to the same real-world person, company or object. It can link spelling variations, transliterations or different company-name formats, while distinguishing people with similar names.
This is probabilistic in many systems, not infallible. A match should carry source details and, where relevant, a confidence measure. Analysts also need a way to correct a mistaken merge or confirm that two similar records are separate.
3. Create relationships
The system represents connections such as a person owning or directing a company, a company paying a counterparty, two customers sharing a telephone number, or an account appearing in a previous case. Each relationship should retain its source and, where possible, its date or period of validity.
4. Apply risk context
Connections become decision-useful when combined with risk context: sanctions or PEP status, adverse media, jurisdiction exposure, unusual activity, ownership complexity, customer risk ratings, internal watchlists and previous investigation outcomes.
5. Identify relevant paths and patterns
Graph analytics for AML may surface indirect ownership paths, repeated beneficiaries, circular flows, clusters of companies, common controllers, shared identifiers or links to historical cases. The objective should determine which patterns matter; displaying every possible link usually creates noise.
6. Present evidence for human review
An investigator should be able to inspect the relationship path, open the supporting source, check dates and ownership percentages, review connected alerts and record a conclusion. The output of graph intelligence should be an explainable investigation path, not an unexplained risk label.
What can graph intelligence reveal?
Hidden beneficial ownership and control
Connected analysis can help trace ownership through intermediate companies, calculate indirect interests, identify common owners across customers and show where declared information conflicts with reliable source data. This supports questions such as who ultimately owns or controls an entity, whether ownership is divided among related parties, and whether nominee arrangements or cross-border layers require closer review.
The Financial Action Task Force (FATF) says competent authorities should have access to adequate, accurate and up-to-date beneficial ownership information. A graph can help organise and test that information, but its conclusions remain only as sound as its sources and ownership logic (FATF guidance on beneficial ownership of legal persons).
Indirect sanctions exposure
Graph intelligence may reveal ownership, control, subsidiary, director, counterparty or related-entity paths to a designated party. It can make the path easier to examine and update when a list or corporate structure changes.
A connection alone does not establish a breach. Ownership thresholds, control tests, prohibitions, licences and reporting duties vary by jurisdiction. The system should expose the facts and applicable rule logic so qualified compliance or legal reviewers can assess the result.
Shared identifiers
Addresses, telephone numbers, email addresses, accounts, devices, IP addresses, directors, shareholders, company secretaries and authorised signatories can connect records that otherwise look unrelated.
Shared identifiers require context. A corporate services provider or co-working office may legitimately serve many companies. A family may share contact details. The relevant question is whether the connection is expected and supported, or whether it combines with other indicators to justify further review.
Transaction networks
Graph-based transaction monitoring can help analysts see many accounts paying one beneficiary, one account receiving funds from unrelated customers, rapid pass-through activity, circular movements, layered intermediaries or repeated payments among related companies. It complements alert rules by adding cross-entity and historical context.
Links to previous alerts and cases
A new customer, counterparty or identifier may be connected to a closed case, an earlier escalation, an internal watchlist or a previously observed typology. Making that history visible can prevent repeated research and help an investigator understand whether an apparently isolated event is part of a recurring pattern.
Seven compliance use cases for graph intelligence
Graph intelligence is most useful when attached to a defined workflow and investigative question.
1. KYC and KYB onboarding
During onboarding, connected KYC and KYB data can support ownership validation, director and shareholder checks, related-party identification and customer risk assessment.
For example, a new trading company may disclose two shareholders and one director. A connected review shows that the director controls several other newly formed applicants using the same contact details. That does not prove misrepresentation, but it gives the analyst a specific reason to verify the commercial rationale, related parties and expected activity before approval.
2. Beneficial ownership analysis
For multi-layer structures, graph intelligence can calculate indirect ownership percentages, distinguish ownership from other forms of control and identify a beneficial owner shared across several entities. Analysts should be able to inspect every intermediate entity, percentage and evidence source rather than receive only a final score.
3. Sanctions and PEP investigations
A graph can extend a direct name-screening result with ownership, control, related-entity, business-relationship and historical context. It may also help teams assess whether multiple minority holdings aggregate under a relevant sanctions rule.
PEP status or association is not evidence of wrongdoing. It is a risk factor that may require proportionate enhanced measures, depending on the relevant law, policy and circumstances.
4. Transaction monitoring
Connected analysis can reveal clusters, transaction chains, repeated counterparties, circular flows, mule-account indicators or concentration around a shared beneficiary. This can make a rule-based alert more meaningful by showing activity across related accounts or customers, while preserving the need to examine legitimate explanations.
5. Alert prioritisation
Relationship context may help prioritise alerts using factors such as proximity to a higher-risk entity, several independent risk indicators, previous case history, ownership complexity, cross-border exposure or repeated network behaviour. The method requires validation: a dense network is not necessarily a risky network, and weak entity resolution can amplify error.
6. Investigations and case management
Investigators can use a common relationship view to trace evidence, connect alerts, assign follow-up work and document why they escalated or closed a case. When the graph, notes, approvals and evidence remain linked, teams can collaborate without repeatedly rebuilding the same network.
7. Ongoing customer monitoring
Risk relationships change after onboarding. New directors, ownership changes, counterparties, jurisdictions, adverse media, sanctions designations or links to emerging cases can alter the assessment. Continuous or event-driven monitoring can bring those changes into the customer and case context, subject to the organisation's risk-based controls.
Practical example: a low-risk company with a higher-risk network
Initial onboarding. A recently incorporated trading company provides apparently valid registration documents. It declares two shareholders, has no direct sanctions match, expects cross-border payments and receives a moderate initial risk rating.
New activity. Several months later, it sends payments to multiple overseas entities. Individual values remain below internal escalation thresholds and do not look unusual when reviewed separately.
Connected analysis. A relationship view shows that one director is linked to three other recently formed companies. Two share a registered address. Several transact with the same overseas beneficiary. An intermediate shareholder is associated with a higher-risk jurisdiction, and one counterparty appeared in an earlier investigation.
Analyst assessment. These findings do not prove misconduct. They increase the relevance of the alerts, provide a defined network to test and justify a proportionate review. The analyst can verify the ownership path, compare expected activity, inspect the previous case and assess whether the shared address has a legitimate explanation.
Possible outcomes. The team might request more information, perform enhanced due diligence, review source of funds, assess ownership and control, increase monitoring, escalate the case, or document why no escalation is necessary. The value lies in a better-supported decision, not in claiming that the graph has found a criminal.
Benefits for compliance teams
A more complete view of risk. Relationships add context to isolated customer, screening and transaction data. Analysts can see both the indicator and the path that makes it relevant.
Potentially faster investigations. Connected information can reduce time spent reconstructing ownership, comparing counterparties, searching prior cases and drawing relationship maps manually. The benefit depends on data quality, integration and workflow design.
Better alert prioritisation. Teams may distinguish an isolated alert from one connected to recurring patterns, several risk indicators or relevant case history.
More consistent work. Standard relationship types, evidence links and investigation steps can reduce variation between analysts while preserving room for judgement.
Improved collaboration. Onboarding, screening, transaction monitoring and investigation teams can work from a shared view instead of separate copies of the facts.
Stronger audit readiness. Source evidence, relationship paths, analyst notes, decisions, approvals, timestamps and case history can form a clearer record of what was known and why action was taken.
Better management visibility. Aggregated network insights may show recurring counterparties, interconnected cases, concentrations of exposure and operational bottlenecks that are difficult to see in individual queues.
Can graph intelligence reduce false positives?
Graph intelligence does not automatically eliminate false positives. It can add context that helps an analyst determine whether an alert is isolated, connected to other risk indicators, part of a repeated pattern or explained by a known legitimate relationship.
A shared address illustrates the point. It might represent a legitimate corporate services provider, a co-working office, a company-formation network or a cluster of related shell companies. The link is a starting point. Its meaning comes from source quality, surrounding relationships and the business context.
The design objective should be better context, not simply more alerts.
How does graph intelligence support risk scoring?
Traditional customer risk scoring may consider geography, industry, customer type, ownership, product use, screening results and expected transaction levels. Relationship-based risk scoring can add the number and type of higher-risk connections, distance from a designated or high-risk entity, ownership concentration, shared identifiers, repeated counterparties and links to previous cases.
Graph-derived features require the same discipline as other risk models. Teams should document the purpose, data and logic; validate performance; test for unintended bias; monitor changes; and provide meaningful human review. Analysts need to know which path or evidence affected a score. A relationship score should support a decision, not become an unchallengeable black box.
Does graph intelligence replace compliance analysts?
No. It can organise connected information, surface unusual patterns, prioritise investigation paths and consolidate evidence. Analysts must still verify the data, distinguish legitimate from suspicious relationships, apply jurisdiction-specific rules, challenge automated findings, request further evidence and document the decision.
Human review is particularly important where entity resolution is uncertain, lawful activity creates dense networks, or a connection could affect a person's access to financial services. The purpose is to give analysts better context for applying judgement.
Limitations and governance requirements
Data quality and missing relationships
Incorrect names, stale ownership data, duplicate entities, inconsistent identifiers and incomplete records can produce misleading paths. A graph also cannot reveal a relationship absent from the available data. Teams should display source provenance and freshness, reconcile conflicts and make uncertainty visible.
False associations
Two entities may share an address, director or service provider for legitimate reasons. Systems should avoid converting a common identifier into an unsupported allegation, and analysts should test alternative explanations.
Visual and analytical complexity
Large networks quickly become unreadable. Effective tools filter by relevance, time, relationship type and risk context. Investigation views should guide the analyst towards the material path without concealing the wider evidence.
Explainability
Analysts should understand why two records were linked, where the source came from, when it applied and how any risk score or priority was calculated. This is necessary for quality assurance, challenge and defensible decisions.
Privacy and data governance
Connected datasets can increase both utility and sensitivity. Organisations should assess lawful purpose, access controls, data minimisation, retention, lineage, security and cross-border processing under the rules that apply to them. Singapore's Personal Data Protection Commission summarises obligations including purpose limitation, protection, retention limitation and access/correction; other jurisdictions impose their own requirements (PDPC data protection obligations).
FATF has also examined how collaborative analytics and data protection can coexist, emphasising safeguards and responsible information sharing rather than treating privacy as an afterthought (FATF, Partnering in the Fight Against Financial Crime).
Integration and overreliance
A graph has limited operational value if it is disconnected from onboarding, screening, transaction monitoring, cases and audit records. Technology also requires governance, testing and human oversight. A visually persuasive network can still be wrong.
What to look for in a graph intelligence solution
Use the following questions to test whether a platform supports real compliance work rather than graph visualisation alone.
Data connectivity: Can it connect the KYC, KYB, ownership, screening, transaction, risk and case data required for the defined use cases?
Entity resolution: Can users see match logic or confidence, distinguish similar identities and correct errors without losing the audit history?
Ownership analysis: Can analysts trace direct and indirect ownership, control relationships, percentages, intermediate entities and source data?
Explainability: Does every material relationship, score and alert priority have an inspectable reason, date and evidence source?
Investigation workflow: Can users create or update a case, assign ownership, preserve evidence, record decisions and obtain approvals from the connected view?
Configurable rules: Can the organisation apply its risk indicators, ownership thresholds, jurisdictions, relationship types and escalation criteria?
Historical analysis: Can users see how directors, ownership, counterparties, screening results, risk ratings and case outcomes changed over time?
Governance and security: Are access, permissions, audit logs, retention, lineage, validation and model governance appropriate to the data and decisions?
Operational usability: Can compliance analysts answer their questions without becoming graph-database specialists?
Outcome measurement: Can the organisation evaluate investigation quality, relevant-alert yield, decision consistency and time spent without relying on a vendor's generic benchmark?
A useful proof of concept starts with a small number of representative cases and agreed success criteria. Include normal legitimate networks as well as known high-risk patterns; otherwise, the test may reward a system for surfacing complexity rather than relevance.
How graph intelligence fits into the compliance workflow
Onboarding -> Verification -> Screening -> Ownership analysis -> Risk scoring -> Monitoring -> Investigation -> Case decision -> Audit record
Graph intelligence should connect these stages, not sit beside them as an isolated visual tool. During onboarding, it can inform ownership and related-party checks. During screening and monitoring, it can add relationship context. During an investigation, it can preserve the evidence path. At case closure, it can support a consistent, explainable record.
The graph is not the final product. The final product is a better-informed decision, a clearer investigation and stronger operational control.
How WIDTH approaches Risk Graph Intelligence
WIDTH Risk Graph Intelligence is designed to help compliance teams connect customer, company, ownership, screening, transaction and case information within a wider compliance workflow.
Graph intelligence is most valuable when its insights can be acted on. WIDTH's approach is designed to connect relationship-led risk insights with screening, investigations, case management and audit-ready records, helping teams move from identifying a connection to making and documenting a decision within one workflow.
That reflects a practical principle: one platform, one workflow, one source of truth. The purpose is not to display the largest network. It is to help the right person see the relevant path, inspect the evidence and decide what happens next.
The future of connected risk intelligence
Compliance operations are moving from periodic checks towards more event-driven monitoring, from isolated alerts towards connected patterns, and from static customer profiles towards changing relationship views. Progress will depend less on producing increasingly complex diagrams and more on joining reliable data, explainable analysis and controlled workflows.
Teams will still need to answer the same fundamental questions: Who is this entity? Who owns or controls it? Who does it interact with? How have those relationships changed? What do the connections mean under our policy and the applicable rules?
The value of graph intelligence is not found in producing the largest or most complex network diagram. It lies in helping compliance teams identify the relationships that matter, understand why they matter and act on them through a controlled and explainable workflow.
Frequently Asked Questions
What does graph intelligence mean in compliance?
It means analysing connected information across people, companies, beneficial owners, accounts, transactions, counterparties and risk events. By representing both entities and the relationships between them, graph intelligence can help analysts find indirect exposure, common identifiers and network patterns that may be missed when records are reviewed separately.
How is graph intelligence different from traditional screening?
Traditional screening commonly compares an individual name or entity with sanctions, PEP or adverse media data. Graph intelligence adds relationship context. It can show, for example, whether a screened entity owns another company, shares identifiers with another customer or is connected to a relevant counterparty or previous case.
How does graph intelligence support AML investigations?
It helps investigators trace ownership, shared identifiers, transaction paths, common counterparties and links to earlier cases. This may reveal a broader network around an alert and reduce repeated research. The connections still require verification and contextual assessment; they do not, by themselves, establish suspicious activity.
Can graph intelligence identify beneficial owners?
It can help map direct and indirect ownership or control when accurate, sufficiently complete source data is available. It can calculate ownership paths and show intermediate companies, but analysts must validate the data, apply the relevant definition of beneficial ownership and investigate control that may not be captured by shareholding alone.
Can graph intelligence detect indirect sanctions exposure?
It can surface ownership or control paths and related entities that warrant assessment. Whether the connection creates a prohibition depends on the applicable sanctions regime, ownership and control tests, aggregation rules, facts and any relevant licence. Compliance and legal review remain necessary.
Can graph intelligence reduce false positives?
It can add context and help prioritise alerts, but it cannot guarantee the removal of false positives. A shared address, for example, may indicate a legitimate service provider or a higher-risk cluster. Analysts still need to test the explanation and review supporting evidence.
What data does graph intelligence require?
Useful inputs may include customer and company profiles, directors and owners, screening results, transactions, counterparties, addresses, contact or device identifiers, customer risk ratings and case history. The appropriate data depends on the defined purpose, legal basis and risk appetite.
Does graph intelligence use artificial intelligence?
It may use graph analytics, rules, entity resolution, machine learning or a combination. The exact method depends on the platform. Buyers should focus on source quality, explainability, validation and workflow fit rather than treating the use of AI as evidence of effectiveness.
Does graph intelligence replace transaction monitoring?
No. It can complement transaction monitoring by connecting activity and alerts across entities, accounts and counterparties. Rules or models may identify an event; graph analytics can help show whether it belongs to a wider pattern and which investigation path is most relevant.
Does graph intelligence replace compliance analysts?
No. It supports investigation and decision-making. Analysts remain responsible for verifying sources, understanding legitimate business relationships, applying jurisdiction-specific requirements, challenging automated findings and documenting proportionate decisions.
Which industries can use graph intelligence?
It can be relevant to banks, payment and fintech firms, insurers, corporate service providers and other regulated businesses with complex customer, ownership or transaction relationships. The value depends on having a clear use case, suitable data and an operational process for acting on findings.
What are the main limitations?
The main limitations are poor or incomplete data, false associations, entity-resolution errors, unreadable network complexity, privacy concerns, limited explainability and weak workflow integration. Governance and human oversight are essential because a graph can make an incorrect relationship look persuasive.
How should a company evaluate a graph intelligence platform?
Assess data connectivity, entity resolution, ownership analysis, source lineage, explainability, historical views, case workflow, configurable rules, security, governance and usability. Test the platform on representative legitimate and higher-risk cases, using outcome measures agreed before the proof of concept.
See connected risk more clearly
Discover how WIDTH can help your compliance team connect KYC, KYB, screening, ownership, risk and case information within one controlled workflow.