<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Graph Mining for Detection of a Large Class of Financial Crimes</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Czeslaw Jedrzejek</string-name>
          <email>Czeslaw.Jedrzejek@put.poznan.pl</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maciej Falkowski</string-name>
          <email>Maciej.Falkowski@put.poznan.pl</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jaroslaw Bak</string-name>
          <email>Jaroslaw.Bak@put.poznan.pl</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Poznan University of Technology, Institute of Control and Information Engineering</institution>
          ,
          <addr-line>Curie Sq. 5, 60-965 Poznan</addr-line>
          ,
          <country country="PL">Poland</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Financial crime perpetrators use many different and sophisticated types of schemes, techniques and transactions to accomplish their goals. However, for a large class of financial crimes, such as doing harm to a company, they cannot escape a powerful principle: illegal proceeds have to return to or be under control of managers to achieve a personal gain. This circular flow of transaction attributes is characteristic of another type of financial crimes: such as a VAT carousel or a Polish fuel mafia scheme. In this work we propose a minimal model of descriptions of a doing harm to a company crime, combined with money laundering. Such a model uses sufficient ontology to build evidence and assign legal qualifications to criminal activities and nothing more. The scheme can be described by using 8 layers of concepts and relations that follow in logical order of uncovering a crime. For example, on the first level that describes money transfers there are only 6 parameters necessary assuming that certain operations can be grouped. Using conceptual graphs with subsumption and negation operations, one can reason on people involvement in a crime and choose between strategies of building a case. The model captures over 90% of relevant information for a typical use case of issuing fictitious invoices, the so called Hydra case and is able effectively reason over relevant facts, which means that legal qualification for this case is basically correct. To what extent the model can be generalized to more complex schemes will be a subject of a further study.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>1.1</p>
    </sec>
    <sec id="sec-2">
      <title>Introduction</title>
      <p>
        Financial Crimes
Money laundering (ML) as a criminal activity accompanying most serious crimes
is seriously undermining economic and social order. There are many schemes
of complex nature that are recognized by FATF [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] and new schemes appear
exploiting ever increasing richness of money forms and economic activity.
Altogether currently up to possibly 50 basic schemes could be identified. Trade-based
money laundering is defined as ”the process of disguising the proceeds of crime
and moving value through the use of trade transactions in an attempt to
legitimize their illicit origins”. For money laundering [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] FATF developed over the
years indicators [
        <xref ref-type="bibr" rid="ref5 ref6 ref7">5-7</xref>
        ], that are frequently observed signs of suspicious activity.
Representation of facts is important for a financial crime description in terms
of uncovering mechanisms (modus operandi) and data collection for building
evidence. In this work we propose focusing analysis of a large class of financial
crimes on looking for chain graphs representing flows of money, invoices and
goods/services. We demonstrate on a few examples that such a representation
largely facilitates asking relevant questions on connections between financial
entities and people associated with them, which is conducive to evidence building
and a crime qualification. To study these relations we propose a data model
(called a minimal model), based on conceptual graphs [13]. This means that an
ontology is crafted to a task rather that attempting to describe whole
conceivable space of concepts and relations (top ontologies). The methodology consist
of several steps:
1. Design of a hierarchical data representation with minimal ontology,
constructed in sequence of uncovering of a crime scheme. In the first stage,
goods/services transfer data is analyzed with relation to 3 basic flows: money,
invoices, and documents (i.e. confirming that the service or goods have been
delivered - particularly important for a fuel mafia type of crimes). In
addition, responsible or relevant people within companies are associated with
particular illegal activities..
2. Construction of a multigraph of the data flow and looking for cycles or
potential cycles when a chain of transactions strongly indicates a ”closure
path”.
3. Provision of a framework in which the graph building process and queries
are executed
4. Relating answers to queries with crime qualifications.
      </p>
      <p>
        This approach is preliminary and limited, but provides an essential model
for evidence building of a very important class of financial crimes: among them
money laundering and acting to a harm to a company. Our approach is an
extension of an approach used by Badia and Kantardzic [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] to analysis of the
Enron [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] dataset.
1.2
      </p>
      <p>Data and Red Flags Used in Financial Crime Investigations
The analysis begins with information from banks on suspicious operations
symptoms of financial crimes (red flags) - that are transferred to countries’
Financial Intelligence Units (FIUs). The common red flags detected by financial
institutions and designated non-financial businesses and professions using data
mining of transaction records are:
– Unconventionally large currency transactions, particularly in exchange for
negotiable instruments or for the direct purchase of fund transfer services;
– Apparent structuring of transactions to avoid identification requirements or
regulatory record-keeping and reporting thresholds;
– Introduction of a client by an overseas associate or financial institution based
in a country or jurisdiction known for drug trafficking and production, other
financial crimes and ”bank secrecy”.</p>
      <p>
        FIUs employ data mining techniques of suspicious activity patterns (over 750
in case of the Polish FIU - GIIF). These employ rule-based systems, customer
profiling, and statistical techniques [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Other FATF indicators require financial
audits, analysis of tax information, testimonies and more difficult to obtain or
correlate information, such as:
– Transactions that appear inconsistent with a client’s known legitimate
(business or personal) activities or means; unusual deviations from normal account
and transaction patterns;
– Any situation where personal identity is difficult to determine;
– Unauthorized or improperly recorded transactions; inadequate audit trails;
– Transactions passed through intermediaries for no apparent business reason.
2
      </p>
    </sec>
    <sec id="sec-3">
      <title>General Crime Model for Selected Crimes</title>
      <p>We define concepts only to the level necessary to ask questions and reason
on the main mechanisms of financial crimes. We assume from the start that
we capture 80-95% of relevant knowledge - but this type of knowledge will be
universal. In some cases deciding whether a work has been done or not is left to
a human. Although less ambitious, such a procedure opens a provision of using
an opinion of an expert (i.e. expert accountant). The class of crimes we consider
is presented in Fig. 1 (modeled after a real case, the so called Hydra case with
real data).The fraudulent scheme is based on invoicing work not done.</p>
      <p>The CEO of company A subcontracts construction work which the company
A does itself. The work is then consecutively subcontracted though a chain of
phony companies. Each of them is getting a commission for money laundering
and commits that contracted work has been done with fictitious statements.
At the end of a chain an owner of a single person company D attempts to
withdraw cash, and there is a suspicion that this cash reaches ”under the table”
the management of company A (possibly through a trusted intermediary, here
associated with company C). People associated with company D may not know
full details of a case. In this scenario money leaves companies and goes to physical
persons.</p>
      <p>The knowledge base (KB) is modeled at several (here 8) levels to describe a
mechanism of crime, that are presented in Section 3.</p>
      <p>The concepts come in a hierarchy according to a prevailing mode of gathering
data.
3</p>
    </sec>
    <sec id="sec-4">
      <title>Hierarchies of Submodels</title>
      <p>The facts for a case we analyze (the Hydra case) can be presented in 7 pages
of a natural language text. This case is one of the easiest for which we have
data (only 4 companies and 10 people involved) but contains all elements of the
financial crime mechanisms. The full analysis is beyond the scope of the paper,
however, in the minimal model the first 3 layers are described by the following
top level concepts:</p>
      <p>General concepts related to layers 1-3:
– General Flow (From Entity, To Entity, Date, Flow),
– Flow (Money Transfer, Invoice, Work/Service).</p>
      <p>Specifically layer 1 concepts are modeled as follows:
– MoneyTransfer (From Entity, To Entity, Method of Transfer, Date, Value,</p>
      <p>Title of transfer, i.e. for Work, registered/unregistered)
– MethodOfTransfer (Electronic transfer, Cash)
– ElectronicTransfer(Account1, Account2)
– Account (Time of setting, History)
The unregistered transfer could be cash or a transfer to tax heavens banks. We
model the remaining layers in a similar way (to be presented in future
publications). At each level we assign concerns, and type of analysis. Answers to
questions infer assignment of relevant penalty as sanctioned by articles of the
Polish Penal Code (”Kodeks Karny” in Polish).</p>
    </sec>
    <sec id="sec-5">
      <title>Money Transfer Flow</title>
      <p>In this Section we show details of modeling and data querying for layers 1-3. The
source of data is twofold: structured documents, eg. Excel or Calc spreadsheets
containing flows data and additional, manually entered data about persons and
companies. That data is stored in relational database and is further converted
to Conceptual Graphs relations.[13, 14]. We use elements of graph theory to
effectively process and query details of financial data. Our goal is to find
suspicious behavior, described by patterns (discussed later). There are three basic
parts in our system: a knowledge base, a set of rules and a set of patterns. The
knowledge base contains facts about companies: their cash flow, invoice flow,
work or goods flow and related physical persons. Facts are represented by entity
nodes connected with relation nodes. Fig. 2 contains visualization of a fragment
of knowledge base. Formally, we can describe Fig. 2 with a formula:</p>
      <p>KB = MoneyTransfer(CompanyA, CompanyB, 01.02.2007, ”Invoice no 18/07”,
500000) Nodes can be typed such as Company, Transfer, Person and other. This
kind of data description is an extension of conceptual graphs [13] that preserves
its soundness and decidability. We use simple query and ontological constructs
(subsumption and negation) that are needed for our data analysis and
computing crime qualifications. Knowledge base can contain thousands of facts about
transactions and for our analysis the crucial thing is the transaction flow. Such
flows can be described by rules of form as in Fig. 3. The main part of a rule is a
pattern, which can contain variables. Pattern can be complemented with
additional variable constraints (date d1 is earlier than d2). Rule in Fig. 3 states that
if a company transfers money to another company, and that company transfers
later the same amount of money to a third company, then the middle company
acts as a broker and in fact the first company transfers money to the third
company (minus a provision). This pattern can be easily extended to include more
intermediary companies, as shown in Fig. 4. Application of such rules to the KB
produces a web of transfers and shows the real starting and ending points of a
money flow. Presented transitive rules can be set to include only transfers above
minimum value or within a period of time. For the sake of clarity we used simple
less and equal operators to compare dates and values, but in fact they can be far
more complex. We developed sophisticated algorithms that can aggregate small
transfers (technique often used to disguise real money flow), not discussed here.
One of patterns that exploits such a transitive use of broker companies is money
laundering where additional physical persons and unregistered money transfer
are involved. Such a pattern is shown in Fig. 5: Transfer from one person to
another can also be more complex and involve intermediary persons.</p>
      <p>After applying specified rules to the KB, the crime detection phase takes
place. In this phase we try to find homomorphism between data collected in KB
and defined crime patterns. Our computational machinery searches for crime
symptoms described by a pattern (like VAT fraud or money laundering). Data
sets that are closest to match the pattern are presented to a user. At this level
the user can judge probability of crime and provide additional data, such as
bank transfers and invoices from other companies that look suspicious, or data
from expert analysis (e.g. that work or service was fictitious). System works in
cycles: data input, analysis, propositions of directions of further investigation.
After gathering enough information additional functionality is triggered, that is
a crime qualification for humans involved. The qualifications are proposed based
on roles persons play in a discovered crime schema.
In this paper we have presented a computational background and an use case
of our tool that is still being developed. Although it is not fully completed yet,
we have obtained first promising practical results. The success is due to several
reasons:
1. Guidance of legal experts as to legal procedures and crime schemes [12].
2. Existence of an invariant in the scheme (the cycle of money transfers).
3. The minimal model description.</p>
      <p>
        The first feature bootstraps relevant questions. The second one introduces clarity
to a description, at a price of some decrease of power of expression. The problem
with complete ontologies is that a formulation relevant questions becomes very
difficult [
        <xref ref-type="bibr" rid="ref2 ref3">2, 3</xref>
        ]. Take an invoice, for example. Company A issues an invoice, and
company B receives an invoice. These operations are described as 2 RDF triples.
We assume that both activities are coupled, so ”invoices” becomes a predicate,
A invoices B. This is the only concept related to invoice. If invoice is lost or
destroyed and it is important for understanding a scheme our model cannot use
such information. We are working on implementation of the rest of analysis levels
and a few more financial crime schemas. One of the most desired schema that
we are developing and that our tool aims to help with, is the VAT fraud schema.
Our practice shows that the current implementation can handle up to with 50
thousand of VAT invoices on a standard PC machine. Currently we are working
on optimization of querying algorithms, which we applied.
      </p>
      <p>Acknowledgments. Our research is supported by the Polish Ministry of Science
and Higher Education, Polish Technological Security Platform grant 0014/R/2/T00/06/02.
We thank drs. J. Cybulka and Jacek Martinek; and Mr. Z. Wieckowski and Mr
T. Dela for guiding information and discussions.
12. Wieckowski J.: Regional Prosecutors Bureau in Katowice, Poland, private
communication, February-May 2008.
13. Chein M., Mugnier M., Graph-based Knowledge Representation Computational</p>
      <p>Foundations of Conceptual Graphs, Springer London 2008
14. Allemang D., Hendler J.: Semantic Web for the Working Ontologist: Effective
Modeling in RDFS and OWL, Morgan Kaufmann Publishers 2008</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Badia</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>M. Kantardzic M. M.</surname>
          </string-name>
          <article-title>: Link Analysis Tools for Intelligence and Counterterrorism</article-title>
          .
          <source>ISI</source>
          <year>2005</year>
          , pp.
          <fpage>49</fpage>
          -
          <lpage>59</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Cybulka</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martinek</surname>
            <given-names>J.:</given-names>
          </string-name>
          <article-title>The core ontology of criminal processes and investigation procedures</article-title>
          . Submitted for publication,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Cybulka</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jdrzejek</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martinek</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <source>Police Investigation Management System Based on the Workflow Technology, Chapter in: Legal Knowledge and Information Systems, Frontiers Artificial Intelligence and Applications</source>
          , vol.
          <volume>189</volume>
          , IOS Press, Amsterdam, Berlin, Oxford, Tokyo, Washington DC,
          <year>2008</year>
          , pp.
          <fpage>150</fpage>
          -
          <lpage>159</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <article-title>Enron data set</article-title>
          . available at http://www-2.cs.cmu.edu/ Enron
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>FATF (The Financial Action Task Force</surname>
          </string-name>
          )
          <source>Report: Trade Based Money Laundering, 23 July</source>
          <year>2006</year>
          ; http://www.fatf-gafi.org/
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>FATF (The Financial Action Task Force) Report: Complex Money Laundering Techniques: A Regional View</surname>
          </string-name>
          ,
          <volume>23</volume>
          February 2007; http://www.fatf-gafi.org/
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>FATF (The Financial Action Task Force</surname>
          </string-name>
          )
          <source>Report: Laundering the Proceeds of VAT Carousel Fraud, 23 February</source>
          <year>2007</year>
          ; http://www.fatf-gafi.org/
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Jedrzejek</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martinek</surname>
            <given-names>J</given-names>
          </string-name>
          .:
          <article-title>On the modelling of money laundering techniques as courses of events</article-title>
          .
          <source>Proceedings of 3rd Language &amp; Technology Conference, October 5-7</source>
          ,
          <year>2007</year>
          , Pozna, Poland, pp.
          <fpage>544</fpage>
          -
          <lpage>548</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Mena</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2003</year>
          )
          <article-title>Investigative Data Mining for Security and Criminal Detection</article-title>
          , Butterworth Heinemann,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <article-title>The Penal Code (in Polish)</article-title>
          .
          <source>Ustawa z dnia 6</source>
          czerwca
          <year>1997</year>
          r. Kodeks karny.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Unger</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Busuioc</surname>
            ,
            <given-names>E. M.:</given-names>
          </string-name>
          <article-title>The Scale and Impacts of Money Laundering</article-title>
          , Publisher:Edward Elgar, May 2007
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>