In short. AUSTRAC’s Operation Claw uncovered a coordinated mortgage fraud whose clearest warning sign was not a forged document but a pattern, the same brokers, accountants and law firms recurring across unrelated applications and across different banks. That pattern lived in the network of entities and relationships, which is the one layer a point-in-time questionnaire cannot see, and the layer that evidence-led trust intelligence is built to surface.
This week the financial-crime regulator went public with the results of an operation it called Operation Claw, a coordinated mortgage fraud that ran across multiple banks and is now the subject of hundreds of referrals to police. Read the regulator’s own account of what gave it away, and the striking thing is not the forged payslips or the inflated incomes, because fraud has always leaned on a fake document somewhere. The striking thing is the warning sign the regulator named first, which was the same mortgage brokers, the same accountants and the same law firms turning up again and again, across unrelated applications and across different banks. The fraud was not really hiding in any single file. It was hiding in the network, in plain sight, and no questionnaire was ever going to find it there.
The signal lived between the files, not inside them
A bank assessing a home loan does a great deal of work on that loan, on the borrower, the income, the documents and the security, and it does that work one application at a time. A referral-partner or supplier questionnaire, where one exists at all, asks the intermediary to describe itself once, on a form, and files the answer. Both of those controls look at a slice in isolation, and the fraud the regulator described does not live inside any one slice. It lives in the relationships that connect them, in the single broker who appears on twenty applications that should have nothing to do with each other, the accountant whose clients keep producing suspiciously similar income statements, and the funds that arrive for settlement from an offshore account belonging to none of the parties on paper. Each of those is invisible to a control that only ever looks at one file, or takes one entity at its own word, and it stays invisible precisely because no single bank sees the whole picture and no questionnaire was ever built to reveal what its author would rather it did not.
Why this kind of fraud defeats the questionnaire by design
It is worth being clear that this is not a case of the form being filled in badly. The questionnaire fails here because of what it is, which is a self-description, captured once, of one entity, assessed on its own. The recurring intermediary does not volunteer the other nineteen applications, because volunteering them is the last thing they want to do, and no one asks the question that would join the dots, because the dots sit in different files, in different teams, and often in different institutions. Point-in-time due diligence has the same blind spot in time that it has in scope, since an intermediary who looked clean at onboarding and turned later leaves no mark on a form that was signed and filed a year ago. The fraud is a pattern that runs across entities and across time, and the questionnaire is a snapshot of a single entity on a single day. They were never going to meet.
The fraud was legible in the relationships the entire time, to anyone who was looking at the entities rather than the forms. The reason it ran as long as it did is that almost no one was.
The fraud was legible in the entities, to anyone looking there
Here is the part that matters for anyone now examining their own book. The signals in Operation Claw were not exotic. They were entity signals and relationship signals: who an intermediary really is and who stands behind them, how often the same names recur across a portfolio, where funds genuinely originate when they cross a border, and whether an adviser’s own profile carries exposure that a light-touch screen would never surface. These are exactly the things that can be resolved from independent evidence rather than taken on attestation, and resolved continuously rather than once. It is the discipline of doing so, of treating the network behind a book of business as something to be understood rather than a stack of forms to be filed, that turns a pattern like this from an after-the-fact police referral into something you could have watched forming.
What Enterprise Trust Management actually does here
This is the ground Enterprise Trust Management is built to hold. Rather than assess an intermediary or a counterparty by asking it to describe itself, it resolves who that entity actually is from independent evidence, maps the ownership and the relationships sitting behind it, surfaces the offshore and third-party links that a settlement statement hides, and keeps that picture live rather than frozen at onboarding. It will not read a forged payslip, and it is not a replacement for a bank’s transaction monitoring, and it would be dishonest to pretend otherwise. What it does is the layer those controls cannot reach, the entity and the network, which is precisely the layer where this fraud actually lived, and precisely the layer the regulator pointed to when it named the recurring intermediaries as the thing to watch. The forged document is the symptom. The network is the disease, and it is the network that ETM is built to see.
And now it is the profession’s problem, not just the bank’s
There is a second reason this lands now, and it is regulatory. The intermediaries at the centre of Operation Claw, the accountants, the lawyers and the real estate agents, are the very professions being brought inside the anti-money-laundering regime under its Tranche 2 reforms, and the regulator has said as much, describing those reforms as aimed at long-standing vulnerabilities in professional services that can be exploited to facilitate money laundering, including in real estate, legal and accounting. For those firms the obligation is no longer to trust that their clients and counterparties are what they appear to be, it is to be able to show that they looked. And for the banks, the exposure Operation Claw laid bare is intermediary and referral-partner risk, which is third and fourth-party risk under another name, sitting in a channel most institutions have never assessed with anything like the rigour they bring to a technology vendor.
The lesson is not that someone forged a document
People will always forge a document, and no platform stops that at the source. The lesson of Operation Claw is quieter and more uncomfortable, which is that the fraud was legible in the relationships the entire time, to anyone who was looking at the entities rather than the forms, and the reason it ran as long as it did is that almost no one was looking there. Trust built from evidence looks there by default. It is the difference between filing the attestation and being able to prove, when the regulator comes asking, that you actually saw who you were dealing with. At BayRisk that is the whole point of how we work, and Operation Claw is simply the most expensive reminder in a while of why it matters.
Common questions
What was AUSTRAC’s Operation Claw?
Operation Claw was an investigation by AUSTRAC, Australia’s financial-crime regulator, into coordinated mortgage fraud running across multiple banks, which led to hundreds of referrals to police. The warning signs AUSTRAC named were falsified documents and the repeated appearance of the same mortgage brokers, accountants and law firms across unrelated loan applications, alongside offshore and third-party funds used to settle purchases.
Why can’t a supplier questionnaire catch this kind of fraud?
A questionnaire assesses one entity, once, on its own word. The fraud in Operation Claw lived in the pattern across entities, the same intermediary recurring across many applications and across different banks, which no single self-description and no single-application check can see. The signal sat between the files, not inside any one of them.
What does the Tranche 2 reform mean for accountants, lawyers and real estate agents?
Australia’s anti-money-laundering Tranche 2 reforms bring accountants, lawyers, real estate agents and other professional-service providers inside the regime, requiring them to perform customer due diligence and report suspicious activity. AUSTRAC has described the reforms as aimed at long-standing vulnerabilities in professional services. The obligation is to be able to show that you looked at who you were dealing with, not simply to trust that they are what they appear.
How does Enterprise Trust Management help, and what can it not do?
Enterprise Trust Management resolves who an intermediary or counterparty really is from independent evidence, maps the ownership and relationships behind them, surfaces offshore and third-party links, and keeps that picture current rather than frozen at onboarding. It works at the entity and network layer where this fraud lived. It does not read a forged document, and it does not replace a bank’s transaction monitoring; it addresses the layer those controls cannot reach.
Sources
- AUSTRAC, statement on Operation Claw and coordinated mortgage fraud (recurring use of the same brokers, accountants and law firms across applications and across banks, offshore and third-party settlement funds, and a call to every mortgage lender to review their books, report suspicious activity and strengthen controls), August 2026, as reported by ABC News, https://www.abc.net.au/news/2026-08-19/asx-markets-business-live-news/107051926
- Capital Brief, AUSTRAC chief executive on the Tranche 2 reforms and long-standing vulnerabilities in professional services, including real estate, legal and accounting, https://www.capitalbrief.com
- AUSTRAC, anti-money-laundering and counter-terrorism financing Tranche 2 reforms, https://www.austrac.gov.au