Why Shadow Banking Networks Blur the Line Between Fraud and Sanctions Risk

Enterprise Fraud and Risk Strategy  ·  October 2026  ·  Global

The US action against the A7 Network shows sanctions evasion surfacing in fraud, KYB, document and transaction signals, and why risk leaders need to connect them.

Fraud and sanctions risk convergence now has a clear reference case. On 1 October 2026 the US Treasury took coordinated action against the A7 Network, which the Financial Crimes Enforcement Network (FinCEN) describes as a global wholesale sanctions evasion and money laundering service with ties to Russia, used by a range of illicit actors including Iran.

The Office of Foreign Assets Control (OFAC) designated the network a significant transnational criminal organisation. FinCEN proposed a special measure that would prohibit covered US institutions from transmitting funds involving A7-controlled “Sub-Agents”, and issued an alert listing red flags.

The case matters well beyond the United States because of how the network operates. Its Sub-Agents are built to look like ordinary trading companies with no visible connection to a sanctioned party, so list-based sanctions screening will rarely catch them. The signals that do expose them sit mostly in places sanctions teams do not usually look: device and network data, onboarding records, trade documents and transaction behaviour. For organisations that run fraud, AML and sanctions as separate functions, that is a structural weakness.

Fraud and sanctions risk convergence visual showing how A7 Network payments move through Sub-Agents and where fraud, KYB, monitoring and sanctions signals appear

How A7 Network payments move through Sub-Agents. The signals that expose them appear across fraud, onboarding, monitoring and document controls rather than in sanctions-list matches.

1

Customer instructs

A customer in a heavily sanctioned jurisdiction provides supplier details and trade documents.

2

Network settles

The network settles the obligation internally.

3

Sub-Agent pays

A Sub-Agent appears as the paying party on invoices and payment instructions.

4

Funds move

Payment leaves non-Russian bank accounts through correspondent banking and SWIFT.

Quick answer

The A7 Network case shows sanctions evasion surfacing mainly in fraud, onboarding, document and transaction signals rather than sanctions-list hits. Each signal is weak on its own and usually sits with a different team, so organisations that run fraud, AML and sanctions separately can miss the pattern. Shared typologies, shared triage and entity-level linking of signals close that gap without merging the teams.

What is fraud and sanctions risk convergence?

Fraud and sanctions risk convergence describes cases where sanctions exposure shows up first as signals owned by fraud, onboarding, document or monitoring teams, rather than as a match against a sanctions list.

The A7 case illustrates it well. Very few of the red flags FinCEN lists are sanctions-list hits. Most look, to the team that sees them, like fraud indicators, data quality issues or unusual but explainable business behaviour.

How the A7 model hides the sanctions nexus

FinCEN’s alert describes a straightforward pattern. A customer in Russia or another heavily sanctioned jurisdiction gives the network supplier details and trade documents. The network settles the obligation internally, then assigns a Sub-Agent to appear as the paying party on invoices and payment instructions, so the payment leaves from non-Russian bank accounts through correspondent banking and SWIFT. In parallel, a ruble-backed stablecoin, A7A5, moves value between network-linked actors where banking channels are harder to use.

The scale is what makes the pattern hard to ignore. According to FinCEN, by June 2026 A7-controlled companies held accounts at around 435 financial institutions in at least 83 countries, using companies formed or acquired in places including Hong Kong, Indonesia, the Kyrgyz Republic, the Seychelles, Türkiye and the United Arab Emirates. They are typically presented as owned or managed by non-Russian nationals. FinCEN characterises the activity as a form of trade-based money laundering.

The legal status of each part of the action differs.

OFAC designation

Took effect immediately. A7 property and interests in property within US jurisdiction are blocked.

FinCEN special measure

The proposed prohibition on transmittals involving Sub-Agents is a notice of proposed rulemaking, not a final rule.

FinCEN red-flag alert

The alert is guidance, listing indicators institutions should consider.

EU and UK sanctions

FinCEN notes the three Russia-based companies at the core of the network are also sanctioned by the EU and the UK.

Where the red flags actually surface

FinCEN’s red flags fall into three groups: the use of Sub-Agents, mis-invoicing and invoice falsification, and digital asset abuse. Mapped against the functions that usually see each signal first, a pattern emerges.

Red flag theme (from the FinCEN alert) Type of signal Function that usually sees it first
Account access from VPN infrastructure linked to the network, or servers in jurisdictions hosting its infrastructure Device and network Fraud, cyber security, digital channels
Email addresses on domains resolving to network-linked mail servers Identity data Onboarding and KYC
Business websites that are blank or minimally active on identified IP ranges Business verification Onboarding and KYB
A recently formed company suddenly processing high volumes of large transactions Behavioural Transaction monitoring
Payments routed through several possible shell companies across jurisdictions Network Transaction monitoring and investigations
Goods descriptions inconsistent with the supplier’s business, vague product details or implausible prices Trade documentation Trade finance and payment operations
Invoices with an analog stamp on a digital document, stray Cyrillic characters, or signs of AI generation Document forensics Fraud and document verification
Exposure to A7A5 or wrapped versions of it, or stablecoins used for large trade purchases Blockchain analytics Digital asset compliance

Very few of these are sanctions-list hits. Most look, to the team that sees them, like fraud indicators, data quality issues or unusual but explainable business behaviour.

FinCEN’s three red-flag groups

FinCEN groups its indicators into three themes and is clear that they should be read together.

Use of Sub-Agents Third-country trading companies appearing as the paying party, with device, domain and website indicators linking them to the network.
Mis-invoicing and falsification Goods, prices and invoice features that do not fit the supplier or the transaction.
Digital asset abuse Exposure to A7A5, wrapped versions of it, or stablecoins used for large trade purchases.
Totality of facts No single red flag is determinative. Institutions should consider multiple red flags together.

Why separate functions miss the pattern

Each signal is weak on its own

FinCEN states that no single red flag is determinative and that institutions should consider the totality of facts and multiple red flags. The value comes from combining signals that are currently held in different systems.

Escalation paths diverge

A fraud analyst who sees an unusual VPN pattern on a business account with no customer loss may close the alert. A document team that spots a doctored invoice may treat it as a fraud risk to the institution, not as a possible sanctions nexus.

The consequences are different

Fraud teams manage loss against appetite. Sanctions exposure is binary and, under US law, enforced on a strict liability basis. A signal routed through fraud logic can be judged acceptable when the same signal routed through sanctions logic would require blocking, rejecting or reporting.

Two reasonable decisions, one missed detection

A fraud analyst closes an unusual VPN alert on a business account because there is no customer loss. Separately, a document team flags a doctored invoice as a fraud risk to the institution.

Neither outcome is unreasonable within its own function. Together, they are a missed detection.

A practical model for connecting the signals

Connecting fraud, AML and sanctions signals does not require merging the teams. It requires a few shared mechanisms.

01

Maintain typologies once, across domains

Record a typology such as A7-style Sub-Agent payments a single time, with each indicator mapped to the system and team that observes it.

02

Route typology indicators to shared triage

When any function sees an indicator from a priority typology, it should reach a shared financial crime triage point, not only its own queue.

03

Link signals to the entity

Device, document, KYB and transaction indicators should attach to the customer or counterparty record so an investigator sees them together.

04

Switch decision logic when a sanctions nexus appears

Once indicators suggest possible sanctions exposure, decisions should follow sanctions procedures rather than fraud loss thresholds.

05

Report coverage, not only volumes

Risk committees should see which priority typologies each domain can detect, alongside screening and alert statistics.

Organisations outside the United States should assess their own obligations under their domestic sanctions and AML regimes, and their exposure through US dollar clearing and correspondent relationships. The structural lesson applies regardless of jurisdiction.

Common gaps when fraud and sanctions controls stay separate

The A7 case points to a handful of recurring gaps in organisations that keep these controls apart:

  • Relying on list-based screening to catch counterparties designed to have no visible link to a sanctioned party.
  • Holding device, document, KYB and transaction signals in separate systems with no link to the customer or counterparty record.
  • Closing fraud alerts that involve no customer loss without considering a possible sanctions nexus.
  • Judging a signal against fraud loss appetite when sanctions procedures should apply.
  • Reporting screening and alert volumes to risk committees without showing which typologies each domain can detect.
Proposed is not final

FinCEN’s prohibition on transmittals involving A7 Sub-Agents is a notice of proposed rulemaking and remains subject to the rulemaking process. The OFAC designation, by contrast, took effect immediately.

How Nexiant supports fraud and sanctions risk convergence

Nexiant brings together specialist capabilities across sanctions and PEP screening, transaction monitoring, identity verification and payment authentication through MemberCheck, FraudShield, NameScan and GPayments.

For operational detail on turning the A7 red flags into monitoring scenarios, read MemberCheck’s practitioner guide.

Questions to ask about your fraud and sanctions controls

Risk leaders can use the A7 case to test how well their current controls connect:

  • Is each priority typology recorded once, with every indicator mapped to the team and system that observes it?
  • Do typology indicators seen by fraud, onboarding or document teams reach a shared financial crime triage point?
  • Are device, document, KYB and transaction signals attached to the customer or counterparty record?
  • Do decisions switch to sanctions procedures once a possible sanctions nexus appears?
  • Can the risk committee see which priority typologies each domain can detect?
  • Have you assessed your exposure through US dollar clearing and correspondent relationships?

The answers show where a weak signal in one function could be the missing piece for another.


Frequently Asked Questions

It describes cases where sanctions exposure shows up first as signals owned by fraud, onboarding, document or monitoring teams, rather than as a match against a sanctions list. The A7 Network is a clear example, because its Sub-Agents are built to look like ordinary trading companies with no visible connection to a sanctioned party.
FinCEN describes it as a global wholesale sanctions evasion and money laundering service with ties to Russia, used by a range of illicit actors including Iran. OFAC designated it a significant transnational criminal organisation on 1 October 2026.
The network uses Sub-Agents in third countries, presented as owned by non-Russian nationals, to appear as the paying party. Unless a Sub-Agent has been publicly identified, its name will not match a sanctions list.
Not yet. It is a notice of proposed rulemaking and remains subject to the rulemaking process. The OFAC designation, by contrast, took effect immediately.
Often, yes. Non-US institutions should assess their obligations under their own sanctions and AML regimes and their exposure through US dollar clearing and correspondent banking. FinCEN notes the core A7 companies are also sanctioned by the EU and the UK.

Connect fraud, AML and sanctions signals

Speak with a Nexiant expert about connecting fraud, AML and sanctions signals in one enterprise risk view.

Speak to our financial crime team

This article was accurate at the time of publication in October 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.