Network analysis
Network analysis
Network analysis, also called link analysis, is the practice of mapping relationships between people, accounts, businesses and transactions to reveal connections that aren’t visible when each entity is reviewed on its own. In AML work, it’s how investigators spot money mule networks, shell company chains, and layering schemes that look unremarkable one transaction at a time. The value is in the pattern across many entities, not any single one.
Key takeaways
- Network analysis (or link analysis) maps relationships across people, accounts and entities to reveal patterns a single-entity review would miss.
- It depends on accurate entity resolution first; if the same person appears as multiple “different” entities, the network graph is wrong from the start.
- Common patterns it surfaces include money mule hubs, shell company chains, and shared identifiers like addresses or devices linking unrelated accounts.
- The signal is in the pattern across many entities, not in any single transaction looked at alone.
- It’s used well beyond money laundering, including fraud rings and sanctions evasion networks.
- Machine learning is increasingly layered on top of network graphs to flag anomalous structures automatically.
On this page
What network analysis actually doesWhy single-entity review misses so muchWhat network analysis relies on: entity resolution firstCommon patterns network analysis surfacesHow investigators build and read a network graphWhere network analysis fits in an AML programmeFAQsRead more
What network analysis actually does
Network analysis takes individual data points, people, accounts, addresses, devices, transactions, and plots them as a graph of connections. Patterns that are invisible when you review one customer’s file in isolation often become obvious once you see how that customer connects to dozens of others.
Why single-entity review misses so much
A traditional case review looks at one customer or one transaction at a time. A money mule sending a modest transfer looks unremarkable alone. The same transfer, seen as one of fifty similar transfers converging on the same destination account from otherwise unconnected senders, looks completely different.
What network analysis relies on: entity resolution first
None of this works without accurate entity resolution first. If the same real person or business appears as several different “unique” entities across a firm’s records, due to typos, name variants, or duplicate onboarding, the resulting network graph is wrong before analysis even starts. Getting entity resolution right is the foundation, not an afterthought.
Common patterns network analysis surfaces
Typical findings include mule networks organised around a small number of hub accounts, layering chains that route funds through several shell companies before reaching a final destination, and shared identifiers, the same address, phone number or device, linking accounts that otherwise look completely unrelated.
How investigators build and read a network graph
Modern tools plot entities as nodes and relationships as edges, then let an investigator visually trace paths between them. Graph databases and visualisation software make this practical at scale, and increasingly machine learning is layered on top to flag structurally unusual patterns automatically, rather than relying purely on manual review.
Where network analysis fits in an AML programme
It typically sits downstream of alert generation, used by investigators working escalated cases rather than as a first-line screening step. It’s especially valuable for typologies that depend on coordination across many accounts, such as money mule operations, where no single transaction tells the full story.
Frequently asked questions
What is network analysis in AML?
Network analysis, or link analysis, maps relationships between people, accounts, businesses and transactions to reveal connections that aren’t visible when each entity is reviewed on its own, such as money mule networks or shell company chains.
What is the difference between network analysis and link analysis?
The terms are generally used interchangeably in AML investigation work, both describing the practice of mapping relationships across entities to surface hidden patterns.
Why does network analysis need entity resolution first?
If the same person or business appears as multiple separate “entities” in a firm’s records due to typos or duplicate onboarding, the resulting network graph will be wrong from the start. Accurate entity resolution has to come first.
What red flags does network analysis typically reveal?
Common findings include hub-and-spoke mule networks, layering chains routed through several shell companies, and shared identifiers such as an address, phone number or device linking accounts that otherwise look unconnected.
Is network analysis only useful for money laundering?
No. The same technique is widely used to investigate fraud rings, sanctions evasion networks, and other financial crime that depends on coordination across multiple accounts or entities.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Network analysis, also called link analysis, is the practice of mapping relationships between people, accounts, businesses and transactions to reveal connections that aren’t visible when each entity is reviewed on its own. In AML work, it’s how investigators spot money mule networks, shell company chains, and layering schemes that look unremarkable one transaction at a time. The value is in the pattern across many entities, not any single one.