Methodology

Productopedia has been developed to help users understand the inherent risk of money laundering and financial crime associated with financial products, and the controls that could be applied to mitigate these risks. Productopedia identifies how a product is structured and evaluates the exposure of a product to different risk indicators that increase the likelihood that a financial product could be misused for criminal ends, before any controls or safeguards are applied to mitigate the risk. It also identifies controls that could be applied to mitigate identified risks.

Productopedia's methodology underpins the creation, validation and maintenance of Productopedia's product risk intelligence, based on the following:

  1. Product Selection and Research
  2. Fund Flow Diagrams
  3. Risk Identification
  4. Calculation of Inherent Risk Rating
  5. Controls Identification
  6. Risk & Controls Matrix
  7. Quality Assurance and Testing
  8. Governance and Accountability
  9. Sources of Data

Guiding Principles

Productopedia's methodology is governed by four core principles:

  1. Accuracy — all intelligence is based on regulatory, supervisory, and practitioner sources and subject to validation and 4-eyes checks.
  2. Human-in-the-loop — no intelligence is published without senior subject matter expert (SME) review and sign-off, ensuring clear human accountability for every output.
  3. Explainability — each product is risk-rated using a documented formula that scores inherent risk factors consistently across all products.
  4. Continuous improvement — the data and methodology are subject to ongoing review and testing to reflect evolving financial crime risks, new regulatory guidance, product innovation, and user feedback.

1. Product Selection and Research

Products are selected for inclusion based on a combination of:

  • Product complexity
  • Regulatory relevance
  • Risk significance
  • User demand

Analysts carry out open-source, desk-based research and gather HUMINT from product experts (as needed) to define a product description, key parties to the product, delivery mechanisms, and any legal documentation that may govern a particular product.

2. Fund Flow Diagrams

Fund flow diagrams are produced for each product to transform product data into visualisations that illustrate how funds move through the product. Analysts map out the key actors, legal relationships and fund flows associated with each product. Diagrams are then constructed by analysts and financial crime practitioners in consultation with financial product experts. These are subject to four-eye review by a senior SME and designed to be easy to understand and accessible to all audiences.

3. Risk Identification

A taxonomy of financial crime risk indicators has been developed across key risk areas: anti-money laundering (including placement, layering and integration), terrorist financing, sanctions, and anti-corruption. Each risk indicator includes a risk name and a high-level description of the risk. Risk indicators to which this type of product could be exposed, without adequate controls in place, are identified for each product. As emerging risks are identified, these are added to the database and products are subject to review to identify whether new risks apply.

4. Calculation of Inherent Risk Rating

Inherent risk is calculated based on the number of risks that are identified for each product against thresholds established through domain knowledge. The banding is as follows:

Inherent Risk Rating # of Risk Indicators % Score
Low 0 to 8 0% to 33%
Medium 9 to 16 34% to 66%
High 17+ 67% to 100%

This banding has been validated with financial crime prevention experts based on their in-depth knowledge and expertise, and is therefore subjective.

To produce a continuous, normalised percentage score across all products, piecewise linear interpolation (PLI) is applied between anchor points.

5. Controls Identification

A taxonomy of controls has been developed which includes control name and description. Controls include:

  • Regulatory controls — including requirements prescribed under applicable AML/CFT frameworks (e.g. CDD, on-going monitoring measures, filing of suspicious activity)
  • Industry controls — recognised good practice drawn from industry guidance and standards
  • Product-specific controls — mitigants tailored to the specific product and how it has been structured, based on practitioner insights

For each product, controls are identified which could be applied to limit the likelihood that products can be used for financial crime.

6. Risk & Controls Matrix

A risk and controls map has also been generated that offsets specific risk indicators. Controls are mapped to risks, generating a structured risk-control matrix that enables users to identify the residual risk rating after controls are applied. The controls map has been validated with the MLROs of top-tier financial institutions in 10 different countries. All new mappings are subject to SME review and approval before being released on the platform.

This feature can be made available for enterprise licenses to support the ability to carry out both inherent risk and residual risk assessments.

7. Quality Assurance and Testing

All product risk intelligence undergoes a structured quality assurance process prior to publication:

  • Stage 1: Input — analyst documents the product and drafts the initial risk assessment, identifying applicable risk indicators and controls
  • Stage 2: Query — senior SME reviews and conducts independent challenge
  • Stage 3: Update / Approve — changes to the product profile (description, risk indicators, controls, fund flow diagram) are updated and/or approved
  • Stage 4: Release — updated data is released on the platform

Ad hoc testing is carried out to ensure that the documented risk intelligence data has been uploaded to the platform correctly, to guard against human error and/or hallucinations.

Independent testing is carried out on an ad hoc basis to validate the consistent application of the formula.

Published intelligence is subject to review to ensure continued accuracy and regulatory alignment:

  • Triggered review — initiated when the FATF, UN, World Bank, or a national authority releases updated product risk guidance, a significant enforcement action, a risk assessment report, etc.
  • User feedback — user feedback is encouraged to enable platform users to flag potential inaccuracies for SME review.

8. Governance and Accountability

Accountability for the methodology and its outputs is assigned as follows:

  • CEO — accountable for the accuracy, integrity, and publication of all product risk intelligence
  • CTO — accountable for the technical infrastructure supporting data preparation, indexing, and delivery
  • Senior SMEs — responsible for research, drafting, and first-line review of product risk intelligence
  • Data Lead — responsible for data governance, taxonomy, and quality standards

9. Sources of Data

Product intelligence is assembled from a defined set of authoritative sources, including:

  • FATF Recommendations, Reports, and Guidance Notes
  • UN, World Bank, IMF reports and toolkits
  • UK Joint Money Laundering Steering Group Guidance Notes, Money Laundering Regulations (MLR2017) and FCA Financial Crime Guide (FCG)
  • Other national guidance and risk assessments (HM Treasury, FinCEN, OCC, and equivalents)
  • Supervisory publications, enforcement actions, and thematic reviews
  • Academic and practitioner literature on financial product development and financial crime risks
  • Proprietary SME knowledge drawn from careers in banking, law enforcement, and financial crime compliance