Fraud and sanctions risk convergence now has a clear reference case. On 1 October 2026 the US Treasury took coordinated action against the A7 Network, which the Financial Crimes Enforcement Network (FinCEN) describes as a global wholesale sanctions evasion and money laundering service with ties to Russia, used by a range of illicit actors including Iran.
The Office of Foreign Assets Control (OFAC) designated the network a significant transnational criminal organisation. FinCEN proposed a special measure that would prohibit covered US institutions from transmitting funds involving A7-controlled “Sub-Agents”, and issued an alert listing red flags.
The case matters well beyond the United States because of how the network operates. Its Sub-Agents are built to look like ordinary trading companies with no visible connection to a sanctioned party, so list-based sanctions screening will rarely catch them. The signals that do expose them sit mostly in places sanctions teams do not usually look: device and network data, onboarding records, trade documents and transaction behaviour. For organisations that run fraud, AML and sanctions as separate functions, that is a structural weakness.
How A7 Network payments move through Sub-Agents. The signals that expose them appear across fraud, onboarding, monitoring and document controls rather than in sanctions-list matches.
Customer instructs
A customer in a heavily sanctioned jurisdiction provides supplier details and trade documents.
Network settles
The network settles the obligation internally.
Sub-Agent pays
A Sub-Agent appears as the paying party on invoices and payment instructions.
Funds move
Payment leaves non-Russian bank accounts through correspondent banking and SWIFT.
The A7 Network case shows sanctions evasion surfacing mainly in fraud, onboarding, document and transaction signals rather than sanctions-list hits. Each signal is weak on its own and usually sits with a different team, so organisations that run fraud, AML and sanctions separately can miss the pattern. Shared typologies, shared triage and entity-level linking of signals close that gap without merging the teams.
What is fraud and sanctions risk convergence?
Fraud and sanctions risk convergence describes cases where sanctions exposure shows up first as signals owned by fraud, onboarding, document or monitoring teams, rather than as a match against a sanctions list.
The A7 case illustrates it well. Very few of the red flags FinCEN lists are sanctions-list hits. Most look, to the team that sees them, like fraud indicators, data quality issues or unusual but explainable business behaviour.
How the A7 model hides the sanctions nexus
FinCEN’s alert describes a straightforward pattern. A customer in Russia or another heavily sanctioned jurisdiction gives the network supplier details and trade documents. The network settles the obligation internally, then assigns a Sub-Agent to appear as the paying party on invoices and payment instructions, so the payment leaves from non-Russian bank accounts through correspondent banking and SWIFT. In parallel, a ruble-backed stablecoin, A7A5, moves value between network-linked actors where banking channels are harder to use.
The scale is what makes the pattern hard to ignore. According to FinCEN, by June 2026 A7-controlled companies held accounts at around 435 financial institutions in at least 83 countries, using companies formed or acquired in places including Hong Kong, Indonesia, the Kyrgyz Republic, the Seychelles, Türkiye and the United Arab Emirates. They are typically presented as owned or managed by non-Russian nationals. FinCEN characterises the activity as a form of trade-based money laundering.
The legal status of each part of the action differs.
OFAC designation
Took effect immediately. A7 property and interests in property within US jurisdiction are blocked.
FinCEN special measure
The proposed prohibition on transmittals involving Sub-Agents is a notice of proposed rulemaking, not a final rule.
FinCEN red-flag alert
The alert is guidance, listing indicators institutions should consider.
EU and UK sanctions
FinCEN notes the three Russia-based companies at the core of the network are also sanctioned by the EU and the UK.
Where the red flags actually surface
FinCEN’s red flags fall into three groups: the use of Sub-Agents, mis-invoicing and invoice falsification, and digital asset abuse. Mapped against the functions that usually see each signal first, a pattern emerges.
| Red flag theme (from the FinCEN alert) | Type of signal | Function that usually sees it first |
|---|---|---|
| Account access from VPN infrastructure linked to the network, or servers in jurisdictions hosting its infrastructure | Device and network | Fraud, cyber security, digital channels |
| Email addresses on domains resolving to network-linked mail servers | Identity data | Onboarding and KYC |
| Business websites that are blank or minimally active on identified IP ranges | Business verification | Onboarding and KYB |
| A recently formed company suddenly processing high volumes of large transactions | Behavioural | Transaction monitoring |
| Payments routed through several possible shell companies across jurisdictions | Network | Transaction monitoring and investigations |
| Goods descriptions inconsistent with the supplier’s business, vague product details or implausible prices | Trade documentation | Trade finance and payment operations |
| Invoices with an analog stamp on a digital document, stray Cyrillic characters, or signs of AI generation | Document forensics | Fraud and document verification |
| Exposure to A7A5 or wrapped versions of it, or stablecoins used for large trade purchases | Blockchain analytics | Digital asset compliance |
Very few of these are sanctions-list hits. Most look, to the team that sees them, like fraud indicators, data quality issues or unusual but explainable business behaviour.
FinCEN’s three red-flag groups
FinCEN groups its indicators into three themes and is clear that they should be read together.
Why separate functions miss the pattern
Each signal is weak on its own
FinCEN states that no single red flag is determinative and that institutions should consider the totality of facts and multiple red flags. The value comes from combining signals that are currently held in different systems.
Escalation paths diverge
A fraud analyst who sees an unusual VPN pattern on a business account with no customer loss may close the alert. A document team that spots a doctored invoice may treat it as a fraud risk to the institution, not as a possible sanctions nexus.
The consequences are different
Fraud teams manage loss against appetite. Sanctions exposure is binary and, under US law, enforced on a strict liability basis. A signal routed through fraud logic can be judged acceptable when the same signal routed through sanctions logic would require blocking, rejecting or reporting.
Two reasonable decisions, one missed detection
A fraud analyst closes an unusual VPN alert on a business account because there is no customer loss. Separately, a document team flags a doctored invoice as a fraud risk to the institution.
Neither outcome is unreasonable within its own function. Together, they are a missed detection.
A practical model for connecting the signals
Connecting fraud, AML and sanctions signals does not require merging the teams. It requires a few shared mechanisms.
Maintain typologies once, across domains
Record a typology such as A7-style Sub-Agent payments a single time, with each indicator mapped to the system and team that observes it.
Route typology indicators to shared triage
When any function sees an indicator from a priority typology, it should reach a shared financial crime triage point, not only its own queue.
Link signals to the entity
Device, document, KYB and transaction indicators should attach to the customer or counterparty record so an investigator sees them together.
Switch decision logic when a sanctions nexus appears
Once indicators suggest possible sanctions exposure, decisions should follow sanctions procedures rather than fraud loss thresholds.
Report coverage, not only volumes
Risk committees should see which priority typologies each domain can detect, alongside screening and alert statistics.
Organisations outside the United States should assess their own obligations under their domestic sanctions and AML regimes, and their exposure through US dollar clearing and correspondent relationships. The structural lesson applies regardless of jurisdiction.
Common gaps when fraud and sanctions controls stay separate
The A7 case points to a handful of recurring gaps in organisations that keep these controls apart:
- Relying on list-based screening to catch counterparties designed to have no visible link to a sanctioned party.
- Holding device, document, KYB and transaction signals in separate systems with no link to the customer or counterparty record.
- Closing fraud alerts that involve no customer loss without considering a possible sanctions nexus.
- Judging a signal against fraud loss appetite when sanctions procedures should apply.
- Reporting screening and alert volumes to risk committees without showing which typologies each domain can detect.
FinCEN’s prohibition on transmittals involving A7 Sub-Agents is a notice of proposed rulemaking and remains subject to the rulemaking process. The OFAC designation, by contrast, took effect immediately.
How Nexiant supports fraud and sanctions risk convergence
Nexiant brings together specialist capabilities across sanctions and PEP screening, transaction monitoring, identity verification and payment authentication through MemberCheck, FraudShield, NameScan and GPayments.
For operational detail on turning the A7 red flags into monitoring scenarios, read MemberCheck’s practitioner guide.
Questions to ask about your fraud and sanctions controls
Risk leaders can use the A7 case to test how well their current controls connect:
- Is each priority typology recorded once, with every indicator mapped to the team and system that observes it?
- Do typology indicators seen by fraud, onboarding or document teams reach a shared financial crime triage point?
- Are device, document, KYB and transaction signals attached to the customer or counterparty record?
- Do decisions switch to sanctions procedures once a possible sanctions nexus appears?
- Can the risk committee see which priority typologies each domain can detect?
- Have you assessed your exposure through US dollar clearing and correspondent relationships?
The answers show where a weak signal in one function could be the missing piece for another.
Frequently Asked Questions
Connect fraud, AML and sanctions signals
Speak with a Nexiant expert about connecting fraud, AML and sanctions signals in one enterprise risk view.
Speak to our financial crime teamThis article was accurate at the time of publication in October 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.




