AIA | News

Fraud Has Learned to Pass the Test

Last updated: 24 Aug 2026 10:00 Posted in:

Phil Cotter (SmartSearch) explains why accountants are increasingly targeted by sophisticated financial criminals, exploring the growing risks posed by AI-generated identities, beneficial ownership and evolving regulatory expectations.

Accountants sit at a point in the financial system that criminals find hard to resist. They advise businesses on the transactions and corporate structures that shape them, and they lend the assurance that gives commercial dealings their credibility. This is a trusted role, which makes the profession critical to legitimate businesses looking to stabilise or grow. It is also what makes it an attractive target for anyone wanting to route illicit activity through verified financial channels.

No reputable firm would knowingly assist money laundering or sanctions evasion. But where a bad actor sits behind a corporate structure, or has quietly infiltrated a genuine client relationship, a firm can end up supporting criminal activity without ever being aware of it. This can lead to regulatory fines, damaged client trust and lasting commercial consequences.

The difficulty is that many of the checks designed to guard against financial crime were built for a more conventional threat landscape. Criminals now build synthetic identities using AI, layer ownership through nominee directors and offshore vehicles, and move funds through digital assets faster than any manual review can follow. Identity checks confirmed at onboarding and during periodic due diligence reviews may satisfy the rulebook on paper, but emerging threats are accelerating at a rate and volume that traditional compliance models were not built for.

For accountants, the question has moved beyond whether compliance, anti-money laundering and identity checks were completed to whether a firm can still be sure who it is dealing with at all. This is no longer simply about meeting an obligation. It is about protecting clients, safeguarding a firm’s reputation and ensuring that the practice never becomes an unwitting gateway for financial crime.

Looking beyond the company name

Start with ownership, because according to our research, this is where uncertainty bites hardest. Some 56% of accountancy firms that we surveyed over the past year said they struggle to verify the ultimate beneficial owner of the businesses they act for, meaning that they cannot say with confidence who ultimately controls a client on their books.

Layered holding companies, trusts, nominee directors and overseas entities all have legitimate uses, but the same arrangements can allow an individual to sit several steps back from a business relationship, obscuring the involvement of a sanctioned individual or an organised crime group moving the proceeds of fraud. Verify the company without pinning down the person controlling it, and the relationship rests on incomplete information.

The criminal risk and financial liability then fall on the firm rather than the client. Even where a name does surface, it can no longer be taken at face value, because fraud itself has changed significantly. Criminals have moved well beyond forged passports to synthetic identities generated with AI, stitching genuine but compromised personal data together with fabricated detail until the persona is built to pass a standard check.

There is also growing concern over the abuse of digital identity and certified ID processes. The systems introduced to make verification faster and more secure are now being manipulated by fraudsters to gain the credibility they were designed to provide.

The two threats feed each other: a convincing synthetic identity is precisely what allows a fraudster to abuse a digital ID system, and a compromised digital ID system gives that fabricated identity an official seal of approval.

That is a difficult backdrop for a profession where 52% of identity checks are still being carried out manually, because experienced staff are being asked to spot fraud engineered specifically to slip past human review. AI compounds this problem by working at scale, turning one convincing fake into thousands, faster than any manual process can keep up with.

The risks extend beyond money laundering

Anti-money laundering tends to dominate compliance conversations, but the risk landscape is now considerably broader. Client wealth increasingly originates in cryptocurrency, where funds can move rapidly through multiple digital wallets and overseas exchanges. This flexibility is a genuine feature for legitimate clients, but it is also exactly what allows criminals to exchange illicit funds at scale and at pace, making the true source of wealth much harder to establish.

Sanctions exposures also shift by the day, as names can be added at short notice and a change of ownership can rewrite an existing client’s profile overnight. Terrorist financing warrants its own attention. Although it surfaces less often in compliance discussions, the legal consequences of becoming involved in transactions linked to terrorism are severe, regardless of whether a firm knowingly facilitated the activity.

These risks are interconnected. Criminals combine fabricated identities, opaque structures and fast-moving money through hard-to-detect financial channels to avoid detection. No single check addresses all of these threats.

Of the regulated firms we surveyed, 87% said they would drop a client after a confirmed instance of money laundering, fraud or a non-compliance breach. Meanwhile, 77% said the reputational fallout from association with a major fraud scandal was a significant concern.

The gap here is less about awareness and more about the difference between who a client claims to be and who genuinely stands behind their business activities. A firm can fall into that gap unknowingly while doing everything it believes the rules require it to do.

Regulators have reached the same conclusion and are raising the bar accordingly. The Economic Crime and Corporate Transparency Act 2023, alongside proposed amendments to the Money Laundering Regulations, places greater emphasis on beneficial ownership and on a firm’s ability to demonstrate that it understands – and can evidence – who its client is throughout the life of a business relationship, not just at onboarding.

The Failure to Prevent Fraud offence will reinforce this further, expecting firms to demonstrate that reasonable steps were taken to identify, manage and mitigate fraud risks, potentially leaving senior individuals and directors personally exposed if those controls are found to be ineffective.

Evidence and continuous oversight are replacing periodic exercises, and this shift follows the logic of emerging threats. A client who presents little concern today can acquire a new beneficial owner, become politically exposed or appear on a sanctions list tomorrow, leaving a firm that waits for its next scheduled compliance review exposed in the meantime.


Turning compliance into an advantage

Continuous monitoring or perpetual Know Your Client (KYC) checks offer a more practical response to this reality. Rather than treating due diligence as a one-off event, firms can monitor live changes in client risk as they occur, creating an ongoing picture of who they are acting for and whether new risks require further investigation.

This is not about creating additional friction or burdening clients with repeated requests for information. Used effectively, technology automates routine monitoring, allowing compliance professionals to focus their expertise where it matters most.

Framed this way, compliance stops being a cost to contain and becomes a strategic capability: one that strengthens client trust, protects a firm’s reputation and enables faster, more confident decision-making. Good verification tools improve the experience for legitimate clients while making it significantly harder for criminals to exploit weaknesses in outdated manual processes.

The firms that thrive over the coming years will be those that pair experienced people with technology built for accurate verification and continuous oversight. Financial crime will keep evolving, and so will regulatory expectations. However, the profession has always adapted to changing risks, and this is simply the next stage of that evolution.


Research referenced is drawn from SmartSearch’s 2026 Compliance Report, a Censuswide survey of 1000 UK decision makers within regulated firms, 250 of which are within accountancy firms.

 

Author bio
Phil Cotter
CEO
SmartSearch

"This is not about creating additional friction or burdening clients with repeated requests for information. Used effectively, technology automates routine monitoring, allowing compliance professionals to focus their expertise where it matters most."

Phil Cotter, CEO, SmartSearch