Productopedia has been developed to help users understand the inherent risk of money laundering and financial crime associated with financial products, and the controls that could be applied to mitigate these risks. Productopedia identifies how a product is structured and evaluates the exposure of a product to different risk indicators that increase the likelihood that a financial product could be misused for criminal ends, before any controls or safeguards are applied to mitigate the risk. It also identifies controls that could be applied to mitigate identified risks.
Productopedia's methodology underpins the creation, validation and maintenance of Productopedia's product risk intelligence, based on the following:
Productopedia's methodology is governed by four core principles:
Products are selected for inclusion based on a combination of:
Analysts carry out open-source, desk-based research and gather HUMINT from product experts (as needed) to define a product description, key parties to the product, delivery mechanisms, and any legal documentation that may govern a particular product.
Fund flow diagrams are produced for each product to transform product data into visualisations that illustrate how funds move through the product. Analysts map out the key actors, legal relationships and fund flows associated with each product. Diagrams are then constructed by analysts and financial crime practitioners in consultation with financial product experts. These are subject to four-eye review by a senior SME and designed to be easy to understand and accessible to all audiences.
A taxonomy of financial crime risk indicators has been developed across key risk areas: anti-money laundering (including placement, layering and integration), terrorist financing, sanctions, and anti-corruption. Each risk indicator includes a risk name and a high-level description of the risk. Risk indicators to which this type of product could be exposed, without adequate controls in place, are identified for each product. As emerging risks are identified, these are added to the database and products are subject to review to identify whether new risks apply.
Inherent risk is calculated based on the number of risks that are identified for each product against thresholds established through domain knowledge. The banding is as follows:
| Inherent Risk Rating | # of Risk Indicators | % Score |
|---|---|---|
| Low | 0 to 8 | 0% to 33% |
| Medium | 9 to 16 | 34% to 66% |
| High | 17+ | 67% to 100% |
This banding has been validated with financial crime prevention experts based on their in-depth knowledge and expertise, and is therefore subjective.
To produce a continuous, normalised percentage score across all products, piecewise linear interpolation (PLI) is applied between anchor points.
A taxonomy of controls has been developed which includes control name and description. Controls include:
For each product, controls are identified which could be applied to limit the likelihood that products can be used for financial crime.
A risk and controls map has also been generated that offsets specific risk indicators. Controls are mapped to risks, generating a structured risk-control matrix that enables users to identify the residual risk rating after controls are applied. The controls map has been validated with the MLROs of top-tier financial institutions in 10 different countries. All new mappings are subject to SME review and approval before being released on the platform.
This feature can be made available for enterprise licenses to support the ability to carry out both inherent risk and residual risk assessments.
All product risk intelligence undergoes a structured quality assurance process prior to publication:
Ad hoc testing is carried out to ensure that the documented risk intelligence data has been uploaded to the platform correctly, to guard against human error and/or hallucinations.
Independent testing is carried out on an ad hoc basis to validate the consistent application of the formula.
Published intelligence is subject to review to ensure continued accuracy and regulatory alignment:
Accountability for the methodology and its outputs is assigned as follows:
Product intelligence is assembled from a defined set of authoritative sources, including: