Financial misconduct can cross borders in seconds, but legal authority remains largely national. A regulator may identify suspiÂcious trading, payments or ownership abroad without having power to compel a foreign bank, question a witness or freeze an asset directly. The resulting delay is not always regulatory failure; it often reflects lawful limits on jurisÂdiction, evidence sharing and due process.
Map the conduct across jurisdictions
Start with an entity-and-event map: suspects, companies, accounts, platforms, interÂmeÂdiÂaries, assets, servers and affected customers. Record where each act occurred and which authority regulates each particÂipant. Separate the regulator that detected the conduct from the authority able to obtain evidence or impose a remedy.
Our guide to financial intelÂliÂgence units explains why an FIU analyses and dissemÂiÂnates intelÂliÂgence but does not replace police, proseÂcutors, regulators or courts. Confusing these roles leads to unrealÂistic expecÂtaÂtions about immediate enforcement.
Identify the legal gateway for every request
For each required record or action, specify the channel: regulator-to-regulator cooperÂation, FIU exchange, mutual legal assisÂtance, a production order, civil disclosure, insolÂvency assisÂtance, extraÂdition or recogÂnition of a judgment. Each has different thresholds, permitted uses, confiÂdenÂtiality rules and timescales.
The IOSCO MultiÂlateral Memorandum of UnderÂstanding is an interÂnaÂtional benchmark for securities-enforcement cooperÂation and inforÂmation exchange. It helps signaÂtories obtain defined categories of inforÂmation, but it does not create a borderless regulator or override domestic law.
Why requests slow down or fail
Common obstacles include incomÂplete legal and factual descripÂtions, dual-crimiÂnality requireÂments, bank or profesÂsional secrecy limits, data-protection rules, transÂlation, incomÂpatible evidence standards, competing invesÂtiÂgaÂtions and insufÂfiÂcient staff. Assets may move again while a request is being clarified. Companies can also place ownership, accounts, data and operaÂtions in different countries.
FATF’s current 40 RecomÂmenÂdaÂtions include interÂnaÂtional cooperÂation, while its consolÂiÂdated inforÂmation-sharing standards call for complete factual and legal inforÂmation and expediÂtious channels. These standards support cooperÂation; actual execution still depends on national impleÂmenÂtation, available powers and the facts of the case.
Build requests that can be executed
State the suspected offence or regulatory breach, relevant dates, persons, accounts, legal basis, records requested, intended use, confiÂdenÂtiality needs and urgency. Explain the connection between the requested country and the conduct. Ask the foreign authority which format and gateway it requires before sending a large package.
Maintain a request tracker showing owner, date, acknowlÂedgement, clariÂfiÂcation, legal deadline and result. Preserve source restricÂtions so intelÂliÂgence is not used as court evidence without permission. Michael Schmitt’s analysis of cross-border enforcement in practice provides useful practiÂtioner context on service, cooperÂation and recogÂnition; case strategy must follow the applicable treaties and domestic laws.
Measure outcomes, not request volumes
Count time to acknowlÂedgement and production, usable records received, assets preserved, duplicate requests avoided and cases reaching an evidence-based decision. A high number of memoranda or inforÂmation exchanges does not prove effective enforcement.
InvesÂtiÂgators should also preserve alterÂnative explaÂnaÂtions and exculÂpatory material. Cross-border complexity must not lower the standard of proof. Effective cooperÂation turns a suspicion into admisÂsible, attribÂutable evidence while respecting the rights of affected parties—and states clearly when legal authority, rather than invesÂtigative effort, limits the result.