Financial Intelligence Units (FIUs), the national bodies that collect financial information relating to potentially illicit activity, analyse it, and share the results with law enforcement and international partners, are increasingly being pressured to demonstrate that their work leads to investigations being advanced, prosecutions supported, and criminal assets identified and frozen. Open source intelligence (OSINT), and the technologies that support it, are one part of how FIUs can prove that.
The Financial Action Task Force (FATF) sets the global AML/CFT standard and periodically assesses countries through peer-led Mutual Evaluations. The assessment regime takes roughly two years, and a poor result carries real consequences. Countries can be placed on FATF’s public list of jurisdictions under increased monitoring, which triggers mandatory enhanced due diligence from banks worldwide, harder and costlier access to international finance and reputational damage that can take years to shake off. Across much of Europe, that evaluation is carried out by Moneyval, the Council of Europe body that applies FATF's own methodology to its regional membership.
Assessors check two things: technical compliance, whether a country's laws meet FATF's 40 Recommendations, and effectiveness, tested through eleven Immediate Outcomes that measure whether those laws translate into real-world results. For FIUs specifically, that effectiveness test is predominantly focused on Immediate Outcome 6 (IO.6), built around four pillars:
Naturally, the criteria map onto the intelligence cycle, the decades-old framework intelligence professionals use to manage the direction of intelligence activity: collecting, processing and analysing information, then producing and disseminating actionable intelligence to decisionmakers.
This article looks at where OSINT, the application of that same cycle to sources like news, corporate records and social media, and the technology that enables it, can help FIUs demonstrate greater effectiveness and improve real-world outcomes.
Recommendation 29 (R.29), FATF's binding standard for how FIUs must operate, requires that an FIU have access to the widest range of information it needs to do its job. FATF's own methodology is explicit that this includes open-source information, alongside financial, administrative and law enforcement data.
In practice, most FIUs draw first on formal channels: banking, tax, customs and law enforcement databases. But that information has its own limits. SARs are sometimes filed defensively, with an institution reporting first and investigating later, only for the FIU's own follow-up to surface documents that would have resolved the suspicion from the start. And a request from a domestic agency or a foreign FIU can arrive with limited context of its own, leaving the FIU to fill in the gaps itself.
OSINT can be used to fill those gaps: augmenting and enriching the information in a SAR or adding context a partner request left out. Egmont's own 2023 survey is a good snapshot of where things stand in relation to the use of OSINT by FIUs: 92% of FIUs already utilise OSINT. However, only 26% have a dedicated OSINT team, and only 31% have a shared OSINT database accessible to their analysts. The picture that paints is of a widely used, but thinly resourced capability.
This is where OSINT, and the technology built to support it, adds the most value. Videris, for example, acts as a secure gateway into a genuinely wide range of sources, including corporate registries, news archives, social media, sanctions and PEP lists, court records, and more specialised sources like vessel tracking and dark web data. It spans 50+ integrated data partners and 200+ social media sources from a single interface, rather than each analyst manually juggling separate tools, tabs and browser windows to cover the same ground at the volume today's caseloads demand.
Turning information into something a relevant national enforcement authority or international partner agency can actually use is the central premise of IO.6's production element. FATF's Recommendation 29 defines what that means in practice: two distinct types of analysis, operational (following the money to specific targets and transactions) and strategic (spotting the patterns that shape wider policy).
In practice, FIU use of OSINT still skews heavily toward the operational level: profiling entities, mapping networks, tracing assets, with strategic use lagging.
However, caseloads are increasing without a corresponding increase in FIU headcount. Another challenge faced by FIUs is that whatever the source - a SAR, a request from a domestic agency, or an enquiry from a foreign FIU - the information arriving is often incomplete, and the FIU is left to build out the picture itself. That gap-filling work is manual and time-intensive, and becomes harder to sustain as case volumes rise.
This challenge is compounded by a broader shift in the nature of the threat itself: financial crime has industrialised, and criminal groups increasingly diversify and cooperate across fraud, money laundering and other predicate offences, sharing infrastructure, professional enablers and specialist laundering services. The result is a shift away from analysing transactions in isolation, towards understanding the networks behind them. This makes network visualisation and analysis a critical capability - not an optional add-on, but something tooling needs to build into operational analysis as a default.
This is where dedicated OSINT tooling can generate real benefits. Bringing together the same breadth of sources - corporate records, news media, social media and other open sources - in one place, alongside capabilities like entity resolution, network visualisation and AI-driven automation, allows operational intelligence production to happen at a pace and scale manual research can't match. Blackdot's own figures show investigation speed increases of up to 400% using Videris, giving analysts more time to focus on drawing conclusions, and preparing tailored reporting for decision makers.
While the majority of FIU OSINT use sits at the operational level, strategic analysis remains an important part of an FIU's role. It's how an FIU identifies emerging typologies and patterns across cases, feeding directly into national risk assessments and wider policy decisions. It's also how an FIU demonstrates its value beyond individual case outcomes - to law enforcement, government and the broader AML/CFT community - building the kind of institutional profile and credibility that in turn supports cooperation and access to resources.
The same AI-enabled tooling increasingly works in both directions between these two levels. At the case level, it can help draw out conclusions, themes and trends across operational intelligence, which, combined with other information, feeds into the strategic intelligence and horizon-scanning material described above. The reverse is equally valuable: applied to strategic-level source material, such as investigative reporting or criminal analysis reports, the same tooling can surface entity-level detail that links back to subjects and networks already known from previous casework.
Gibraltar's FIU has said that tools like Videris help "enhance both operational and strategic intelligence outputs," while keeping its OSINT work compliant with its own policy and ethical standards. Jersey's FIU has said the platform makes its OSINT work more dynamic, accurate and proactive.
Assessing the extent of an FIU's cooperation with domestic and international partners, and how effectively the resulting intelligence gets used, depends on legal frameworks that allow information to move between agencies and across borders, trust between agencies and partners, the security and interoperability of channels for actually exchanging it, and on what happens once law enforcement receives it.
Recommendations 30 and 31 make clear that whether disseminated intelligence leads anywhere depends heavily on law enforcement's own practice and legal powers; specifically, whether investigators routinely act on what an FIU disseminates, and whether they have the legal authority to obtain the further records and evidence needed to act on it. A 2025 Egmont Group review of 23 European jurisdictions found this to be one of the clearest factors separating stronger and weaker systems: where that engagement between law enforcement and the FIU is inconsistent, disseminations too often produce no follow-up at all.
Latvia's mutual evaluation, adopted in 2025, is a good example: its FIU was rated highly effective on financial intelligence, helped by a standing coordination group it convenes with law enforcement and reporting entities, plus dedicated secure channels for exchanging information. This is precisely the kind of mechanism FATF's own methodology asks assessors to look for under cooperation, which names joint task forces, shared databases and secondments as examples of what full and timely cooperation looks like in practice. That's governance and infrastructure doing the work, not the tools used to produce or analyse the intelligence in the first place.
Where OSINT technology does help is more specific. Intelligence drawn from a diverse range of sources, analysed using network analytics to map the connections between entities, and handled securely throughout - with audit trails, access controls and secure-by-design handling giving it a defensible paper trail once it's shared - is more likely to arrive as a high-quality product a partner can trust and act on directly, rather than something that needs further verification or rework first. That combination strengthens a domestic or international partner's confidence in the intelligence an FIU produces, increasing the chance of it generating tangible downstream impact: investigations advanced, prosecutions supported, and assets seized.
OSINT, and the technology that support it, contribute most directly to how FIUs demonstrate effectiveness in access (6.1) and production (6.2): broadening the range of information available, and helping turn it into operational and strategic intelligence. The contribution to cooperation (6.3) and use (6.4) is less direct, but still real: intelligence that's produced securely and is fully auditable is more likely to be trusted by partners, acted on, and to lead to tangible outcomes downstream.
None of this works on technology alone. It depends on trained, experienced analysts, an intelligence cycle that's run in a structured way, and the governance and oversight that underpin both - the same combination of people, process and technology that effective security and intelligence functions have always depended on. Get that combination right, and OSINT can meaningfully contribute to the outcomes FATF's evaluations are ultimately trying to encourage: investigations advanced, prosecutions supported, and assets seized.
We'll be unpacking these themes in an upcoming webinar series, starting with where OSINT fits into FATF's assessment methodology, and then diving deeper into each of the core elements mentioned above. Register for the webinar here.