Recovery
Editorial · Cross-border process
Across borders: how multi-jurisdiction fraud files actually move
When a fraud file involves more than one jurisdiction, the mechanics that work inside Canada start to apply differently, or stop applying at all. Most clients we hear from with this profile recognise that something has changed, but the change is usually framed as a delay rather than as a structural difference. In practice it is structural. A wire that left a Canadian bank for a receiving institution in Cyprus, or a crypto deposit that cleared from a Canadian exchange to a wallet operating from a privacy-coin gateway in a non-cooperative jurisdiction, is not a Canadian file with a foreign address attached. It is a different category of file, and the available options are different from the start.
This piece is about what crossing a border actually does to a fraud matter, and how the work we do at intake changes accordingly.
The receiving side, not the sending side
Most clients describe their case as a fraud committed against them — a Canadian account, a Canadian client, a transfer initiated under Canadian banking rules. From the client's side this is correct. From the operational side of the file, the question of where the money currently sits is usually more important than where it left from. Canadian banking and securities mechanisms apply to the originating leg of the transaction; they have less reach over the receiving leg, which is where the funds typically still are at the point a client calls.
A wire to a receiving bank in a country with strong cooperation agreements with Canada — the United States, the United Kingdom, several EU jurisdictions — produces a different set of options than a wire to a receiving bank in a jurisdiction with limited or no such agreements. We are direct about this in the first call. Where the receiving institution operates in a cooperative regime and the trail is still fresh, structured requests through correspondent banking channels and through the originating Canadian bank can produce engagement. Where the receiving institution is in a regime that does not recognise that engagement, or is itself unregulated, the correspondent channel does not function the same way.
For crypto, the equivalent question is whether the receiving wallet operated through a centralised exchange that complies with travel-rule and AML reporting frameworks, or through a decentralised endpoint that does not. The first allows for a documented request to the exchange. The second does not. A file's location on this spectrum determines, more than any other variable, what an early-stage cross-border action can realistically do.
What "structured request" actually means
The phrase that recurs in cross-border fraud work is "structured request." This is the operational unit through which a fraud-recovery file moves between institutions in different countries. It is not a single document. It is a packaged set of materials — a documented timeline, the specific transaction references, the originating bank's confirmation of the wire, the receiving institution's identifying details, and a clear statement of what is being requested and why.
The point of structuring the request is not formality. It is that the receiving institution, in any jurisdiction, has its own internal processes for handling external inquiries. A request that arrives in a form that fits those processes is one that gets reviewed. A request that arrives as a narrative or as a complaint without supporting transactional detail is one that, in our experience, does not. Most of the work we do at intake on a cross-border file is the work of preparing materials in a form that the relevant receiving institution's compliance or legal department can act on without further follow-up.
This is also why documentation quality matters disproportionately on cross-border files. A Canadian-only file can sometimes proceed on partial documentation because the originating bank is in a position to fill gaps from its own records. A cross-border file, where the receiving institution does not have an existing relationship with the client, requires more from the client up front. Screenshots of the dashboard, the platform's correspondence, the wire confirmation with reference numbers, the timeline of when each step occurred. Without these, the request cannot be structured at all.
Timelines that change at the border
Inside Canada, the operational windows on a fraud file are measured in days for the first stage and weeks for what follows. Cross-border, both windows extend.
Initial engagement with a foreign receiving institution — even one in a cooperative jurisdiction — takes longer than the equivalent engagement with a Canadian institution, because the request usually moves through correspondent banking channels rather than through a direct relationship. A request that would receive an internal compliance review in five business days from a Canadian bank may take three to four weeks at a foreign one, and that is in cooperative regimes. In non-cooperative regimes, the timeline is open-ended; in some, the channel for a meaningful response does not exist at all.
We tell clients this at intake. The reason is not to manage expectations. It is that, on cross-border files, decisions about which actions to pursue are partially decisions about which timelines a client is willing to accept. A client whose receiving institution is in a five-week cooperative timeline is in a meaningfully different position from a client whose receiving institution is in an open-ended non-cooperative one, and the first call is when that distinction first becomes visible.
Documentation, again
The element that recurs in every productive cross-border file we have worked on is documentation that the client controlled before they reached us. Wire confirmations from the originating bank. Transaction hashes from the originating exchange. Screenshots of the platform dashboard while it was still online. Email correspondence with the operator. Names and phone numbers of the contact persons involved.
Cross-border files are unforgiving of gaps in this documentation. A Canadian file with thin paperwork can sometimes proceed because the relevant institutions are within reach for follow-up. A cross-border file with thin paperwork often cannot, because the institutions whose cooperation is needed are too distant, too busy, and too unconnected to the client to fill the gaps themselves.
The implication, again, is preservation. We ask clients with cross-border profiles to spend the first week capturing what they still have access to. The platform is unlikely to remain accessible for long, and the documentation that is straightforward to gather while the platform is online is, in many files, impossible to reconstruct after it has gone dark. The early-window logic applies to cross-border files with more force, not less.
What we will and will not open
We are direct, at intake, about which cross-border profiles we will open and which we will not. Files involving receiving institutions in cooperative jurisdictions, where the trail is documented and the timeline is still inside the workable window, are the files we work on. Files involving receiving wallets in jurisdictions with no enforcement or banking cooperation, or where the funds have moved through privacy coins or undocumented mixers, are files where we say so and end the call.
This is the harder conversation, because the client has, by the time they reach us, often spent weeks looking for someone who will say the file can move forward. The opportunistic answer would be to take the matter and bill against it. The accurate answer, in cases where the underlying mechanics do not exist, is that the file cannot be moved by us or by anyone else in the legitimate practice. We give that answer when it applies. The honesty of the first call is, on cross-border work, often the most useful thing we provide.
The cases that do work, and that justify the cross-border practice, are the ones where the receiving institution can be reached, the documentation supports the request, and the client called early enough that the file's timeline is still inside the engageable window. Most of the variation between a productive cross-border file and an unproductive one is variation along those three axes. The early call is where they are first assessed.