Cash-Intensive Businesses, MSBs and Informal Value Transfer
Cash-intensive businesses, money or value transfer services and informal value-transfer networks can all support legitimate economic activity. They can also create financial-crime exposure because cash is difficult to trace before it enters the regulated system, remittance businesses move value on behalf of others, agent networks can fragment visibility, and informal mechanisms may transfer value without the conventional bank-to-bank trail a monitoring system expects.
The key control principle is simple: cash intensity, remittance activity or informal settlement is not itself suspicious. The bank needs to understand the business model, customers, agents, corridors, source of funds, settlement mechanics and transaction behaviour.
Cash-intensive businesses
Restaurants, convenience stores, petrol stations, markets, transport businesses, entertainment venues and other businesses can legitimately receive substantial cash. Risk depends on whether cash activity makes sense for the industry, location, turnover and customer base.
A restaurant depositing cash daily is different from a software consultancy suddenly depositing large amounts. The bank should compare observed behaviour with the customer’s expected model rather than apply one threshold to every business.
Cash does not equal criminal proceeds
Banks should avoid a common analytical shortcut: high cash volume equals money laundering. Cash can be entirely legitimate. The stronger signal is inconsistency, such as cash volume that materially exceeds plausible sales, deposits made far from business locations, unexplained third-party depositors, or rapid conversion of cash into unrelated cross-border payments.
The control should ask what changed and whether the customer can explain it.
Structuring
Structuring can involve deliberate division of transactions to avoid a threshold, report or control. Repeated sub-threshold activity can be a relevant indicator, but intent cannot be inferred from amount alone.
Monitoring should examine timing, location, depositor identity, customer profile, subsequent movement and whether the pattern clusters around known thresholds. Internal detection thresholds must not be confused with legal thresholds.
Cash deposit channels
Cash can enter through branches, ATMs, deposit machines, night safes and third-party arrangements. Each channel can have different data quality. Branch deposits may capture depositor information; ATM deposits may have device or card identifiers; bulk-cash services may use aggregated files.
A financial-crime control should understand these differences rather than pretend all cash transactions are equally observable.
Cash withdrawal
Large or rapid cash withdrawal can break the electronic trail, but it is also normal for many customers. Risk strengthens when withdrawals follow suspicious inbound funds, occur across multiple locations, or do not fit customer behaviour.
Money services businesses
Money services businesses, remitters and other money or value transfer services can provide vital access to cross-border payments, especially for migrant workers, small businesses and communities with limited banking access.
For a bank, an MSB customer is not merely another corporate customer. The bank may be indirectly exposed to many underlying senders, beneficiaries, agents and corridors that it does not know as direct customers.
Know the MSB business model
Due diligence should understand licensing or registration where applicable, ownership, management, products, customer types, corridors, agent network, cash exposure, settlement arrangements, sanctions controls, AML/CFT programme and expected transaction volumes.
The exact requirements depend on jurisdiction and risk. A bank should not assume all MSBs are equivalent.
Agent networks
Remitters often use agents. Agents can improve reach but can also weaken control if onboarding, training, monitoring and discipline are poor.
A bank serving the principal MSB may need to understand how the customer governs agents, how transactions are attributed to agents, how suspicious behaviour is escalated and whether high-risk agents are identified.
Nested exposure
A bank may provide services to an MSB that in turn serves other remitters or payment intermediaries. This can reduce transparency.
Nested activity is not automatically prohibited. The bank should understand whether it is expected, how the customer controls downstream relationships and what transaction data is available.
Settlement accounts
MSBs may collect customer funds and settle through bank accounts in aggregate. A bank may see large transfers that represent many underlying transactions.
Monitoring should therefore distinguish settlement behaviour from ordinary corporate payments. The relevant question may be whether aggregate activity, corridors and counterparties match the remitter’s expected business.
Corridors
Remittance corridors can reflect migration, family support and trade. Higher-risk countries or regions can affect risk assessment, but geography should not be used as a substitute for evidence.
Banks should avoid blanket de-risking solely because a corridor has elevated risk. The risk-based approach calls for proportionate controls.
Customer data visibility
Some banks receive underlying originator and beneficiary information; others see only settlement activity. Control claims must reflect this reality.
A bank cannot claim to screen every underlying remittance if it does not receive the underlying parties.
Informal value transfer
Informal value-transfer systems can move value through networks of brokers, traders or agents, sometimes settling obligations through trade, netting, cash or bank transfers rather than one direct payment from sender to recipient.
Such systems can have legitimate cultural and economic uses. They can also be misused for laundering, terrorist financing, sanctions evasion or unlicensed activity.
The control challenge is that the bank may see settlement between brokers rather than the original sender and beneficiary.
Hawala and similar systems
Hawala is often used as a general label for informal value transfer, but practices differ by geography and community. Banks should avoid stereotypes and focus on actual business activity, licensing requirements, counterparties, settlement patterns and legal status.
Where a customer is operating a remittance or value-transfer business, the bank should assess whether that activity is declared and permitted.
Informal networks settle through visible channels — trade goods, invoices, third-party payments — and declaration status is itself the first finding.
Trade settlement and informal transfer
Informal value-transfer networks can settle balances through trade transactions. One broker may owe another and use goods, invoices or third-party payments to balance accounts.
This creates overlap with TBML. Investigators should follow the economic value rather than assume every trade-linked settlement is criminal.
Cash couriers
Physical movement of cash can be part of legitimate commerce or personal activity, but it can also support criminal proceeds or terrorist financing. Border-declaration requirements differ by jurisdiction.
Banks may encounter the financial side of courier activity through repeated cash deposits, foreign-currency exchange or settlement accounts.
Foreign exchange
Currency exchange businesses can be legitimate and regulated. They can also be used to convert or fragment value.
Banks should understand expected currencies, cash volumes, counterparties and settlement patterns.
Prepaid and e-money interaction
MSBs and remittance businesses may use prepaid or wallet products. These can expand access but also increase speed and cross-channel complexity.
Controls should follow the value across cash, bank transfer, wallet and cash-out points where data is available.
Fraud proceeds and remitters
Scam or fraud proceeds can move through remittance channels. Fraud intelligence can therefore be relevant to AML monitoring, particularly where beneficiaries, agents or settlement accounts appear repeatedly in victim reports.
Terrorist financing
Remittance and informal-transfer channels can be relevant to terrorist financing because lawful funds can be moved to support prohibited purposes. Detection therefore cannot rely only on identifying criminal proceeds.
Customer, counterparty, network, sanctions and destination context matter.
Sanctions exposure
MSBs can face sanctions risk through customers, beneficiaries, agents, countries and settlement routes. The bank’s sanctions obligations depend on the applicable legal regime and its role.
AML risk scoring does not replace sanctions screening.
Monitoring cash-intensive businesses
Useful scenarios can include sudden cash growth, cash inconsistent with turnover, deposits from distant locations, third-party depositors, cash followed by rapid international transfer, and material divergence between merchant or tax-related information and cash receipts where such data is legitimately available.
Monitoring MSBs
MSB monitoring can consider volume by corridor, unusual settlement counterparties, unexplained changes in cash exposure, agent concentration, activity beyond licensed scope, new jurisdictions, sanctions or fraud intelligence, and deviations from expected settlement behaviour.
The bank should distinguish the MSB’s own operational transactions from customer-remittance settlement where possible.
Peer groups
Peer comparison can be useful only if peers are genuinely comparable. A large digital remitter and a small cash-based local agent should not share one behavioural baseline.
Scenario: restaurant with rising cash
A restaurant has stable card and cash turnover. Over several months, cash deposits triple while card sales remain flat and reported business expansion cannot explain the change. Funds are then transferred to unrelated overseas companies.
The bank should investigate the mismatch, not simply the absolute amount of cash.
Scenario: legitimate remittance growth
An MSB launches in a new migrant corridor after obtaining required permissions. Volumes rise sharply, but customer acquisition, agent rollout and settlement partners support the growth.
The change should be understood and incorporated into expected activity rather than generate permanent false positives.
Scenario: undeclared remittance activity
A small retail customer receives cash from many people and sends repeated transfers to a narrow set of overseas beneficiaries, while describing the account as a grocery business.
The bank should examine whether the customer is operating an undeclared value-transfer service, but should not reach that conclusion solely from transaction shape.
Scenario: broker settlement
Two businesses repeatedly exchange large round-value transfers that do not match their stated trade relationship. Customer explanations indicate they are settling obligations for third parties.
The bank should understand the underlying business, legal status, parties and purpose and escalate where unlicensed or suspicious activity is indicated.
Customer fairness and de-risking
MSBs and cash-intensive businesses can be subject to broad risk aversion. Banks should avoid automatic exit simply because a sector is higher risk. The risk-based approach requires understanding and managing risk where possible.
Where risk cannot be managed, exit may be appropriate, but the decision should be evidence-based and governed.
Data model
Useful data includes customer type, licence or registration details, agent network, expected corridors, expected volumes, cash percentage, settlement accounts, underlying transaction-data availability, countries and ownership.
These fields should be structured enough to support monitoring.
Business analyst view
A BA should distinguish direct customer, underlying remitter customer, agent, beneficiary, settlement counterparty and downstream institution. If systems collapse these roles, monitoring and screening can become misleading.
Requirements should define when the bank receives underlying transaction data and what controls rely on it.
Case management
Investigations may need to group activity by agent, corridor or settlement account. One alert per transaction can be ineffective for high-volume remitters.
Case tools should support aggregation without losing transaction-level evidence.
Metrics
Useful metrics can include alert quality, corridor changes, agent-risk concentrations, data completeness, repeated cash anomalies, fraud-linked beneficiaries and aged investigations.
Alert count alone is not a measure of effectiveness.
Common mistakes
The biggest mistakes are equating cash with crime, treating all MSBs as one risk category, assuming the bank sees underlying remittance parties when it sees only settlement, and using country risk as a blanket reason to exit customers.
Another mistake is failing to distinguish formal regulated remittance from undeclared or unlicensed value-transfer activity.
Learning checkpoint
A reader should be able to explain why cash-intensive businesses and MSBs require contextual rather than threshold-only monitoring, describe agent and settlement-account risk, distinguish direct from underlying-customer visibility, and explain how informal value transfer can move value without a conventional end-to-end bank trail.
Reference links
- FATF — The FATF Recommendations: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF — Guidance for a Risk-Based Approach for Money or Value Transfer Services: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Rba-money-or-value-transfer.html
- FATF — Guidance on Correspondent Banking Services: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Correspondent-banking-services.html
- FATF — High-risk and other monitored jurisdictions: https://www.fatf-gafi.org/en/topics/high-risk-and-other-monitored-jurisdictions.html
Educational note: MSB licensing, cash reporting, cross-border declarations and informal-value-transfer laws differ by jurisdiction. Apply the rules relevant to the bank entity and customer activity.
Deep dive: operating a risk-based model for cash, remitters and informal value transfer
The strongest control framework separates three questions that are often mixed together: whether a customer legitimately operates a cash-intensive business, whether a regulated or registered money-or-value-transfer business is operating within its expected model, and whether an account appears to be providing undeclared or opaque value-transfer services. These populations can look similar in transaction data while requiring very different investigation and governance.
Build the expected economic model first
For a cash-intensive business, expected activity should include business type, operating locations, opening hours, approximate turnover, expected cash share, card or merchant-acquiring flows, seasonality and normal suppliers. For an MSB or remitter, the bank should understand products, customer types, sending and receiving corridors, agent footprint, cash exposure, settlement model, currencies and expected transaction volumes.
A monitoring rule without this context is likely to generate either excessive noise or blind spots.
Cash-to-sales reconciliation
Where the bank legitimately has relevant information, investigators can compare cash deposits with card settlement, declared turnover, historical patterns or known business events. The objective is not to audit the customer's books. It is to identify material inconsistencies that the customer profile does not explain.
A restaurant whose cash deposits rise during a festival period may be behaving normally. The same restaurant receiving unexplained third-party cash deposits in distant cities and sending the funds rapidly overseas presents a different pattern.
Depositor identity
Some channels record who made the deposit; others do not. Where depositor data is available, repeated deposits by unrelated people can add context. The absence of depositor data should be treated as a coverage limitation rather than silently assumed away.
Branch and ATM fragmentation
A customer can spread cash across branches and ATMs. Monitoring should aggregate relevant activity at customer or related-account level where legally permitted. Channel-by-channel rules can miss the overall pattern.
Cash logistics and bulk deposits
Large retailers and cash-handling businesses may use cash-in-transit or bulk deposit services. Those flows can be large and highly regular. They should be segmented separately from ordinary branch cash.
Foreign currency
Foreign-exchange businesses, tourist businesses and remitters may legitimately handle multiple currencies. Currency variety alone is not suspicious. The bank should understand expected currency mix, source, settlement and any material change.
Licensing and registration lifecycle
For MSBs, remitters and exchange businesses, licensing or registration status can be a core due-diligence dependency. Systems should record authority, licence or registration number, scope, jurisdiction, effective date and expiry or review date where relevant.
A licence does not eliminate risk; it establishes part of the legal and supervisory context. Likewise, the absence of a licence is meaningful only after confirming whether the activity actually requires one in that jurisdiction.
Agent onboarding
An MSB's agents can create material risk because they interact with underlying customers and may handle cash. The principal should have a process for agent selection, due diligence, training, monitoring, suspension and termination.
A bank does not necessarily need to duplicate every agent control, but it should understand how the MSB governs the network where risk warrants it.
Agent-level monitoring
Useful measures can include volume, cash percentage, corridor distribution, complaint rate, fraud links, unusual beneficiary concentration and deviations from peer agents. High volume is not inherently problematic; unexplained change is more informative.
Agent termination
When an agent is terminated for misconduct or control failure, the bank may need to consider whether related settlement activity or linked accounts require review. The precise information available depends on contractual and legal arrangements.
Pooled and settlement accounts
MSBs can use pooled accounts to receive or settle many underlying transactions. A bank should know whether funds are customer money, corporate money or mixed according to the product model and local rules.
Monitoring should avoid interpreting every large bulk transfer as a customer-level payment. The account's role matters.
Underlying transaction data
Where the bank receives originator, beneficiary, amount, corridor, agent or purpose data for underlying remittances, controls can use it. Where the bank receives only aggregate settlement, it should not claim full underlying screening or monitoring coverage.
Coverage statements should explicitly identify which populations and fields are available.
Payment transparency
Cross-border payment-transparency requirements can affect what originator and beneficiary information accompanies a transfer. Requirements differ by payment type and jurisdiction, and evolving FATF Recommendation 16 implementation should be mapped into local obligations rather than treated as one global operating date.
Nested remittance relationships
An MSB can provide services to another remitter or payment intermediary. This can introduce downstream customers and agents that the bank does not directly know.
The bank should understand whether nesting is permitted, expected and controlled. The existence of a nested relationship is not automatically prohibited.
Corridor analytics
Corridor analysis can compare volume, average value, cash share, beneficiary concentration, fraud reports and change over time. Country risk should be one input among several.
A higher-risk country does not make every transfer suspicious. FATF's risk-based approach discourages indiscriminate de-risking where proportionate controls can manage risk.
Humanitarian and family remittances
Remittance corridors often support family maintenance and humanitarian needs. Control design should recognise the legitimate social purpose of these flows and avoid using nationality or geography as a proxy for criminality.
Informal value-transfer systems
Informal systems can settle obligations through brokers without one end-to-end bank transfer. The sender gives value to one broker; another broker pays the beneficiary; the brokers later settle between themselves through bank transfers, cash, trade or netting.
This creates a visibility challenge: a bank may observe only broker settlement, not the original customer-to-beneficiary instruction.
Hawala terminology
Hawala and similar service providers vary significantly by region and operating model. Some may be legitimate or regulated; others may operate outside legal requirements or be exploited by professional money launderers. Investigators should establish the actual service and legal status rather than infer criminality from the label.
Professional money laundering
Professional laundering networks can use remittance businesses, underground banking, cash collectors, companies and trade settlement to move funds for third parties. A recurring signal can be an account that appears to settle obligations for numerous unrelated parties without an understandable legitimate business model.
Net settlement
Two brokers may owe each other multiple obligations and settle only the net amount. The resulting bank transfer can be much smaller than the underlying gross customer activity.
Investigators should therefore avoid assuming bank transaction value equals the total economic value transferred through the network.
Trade settlement
Broker balances can be settled through import/export transactions. This creates overlap with trade-based money laundering. Banks should connect the settlement rationale, related companies, invoices and ownership where relevant rather than treat the trade payment in isolation.
Fraud and mule interaction
Fraud proceeds can pass through remittance businesses or informal networks. Victim-linked beneficiary information, receiving-account intelligence and remitter-agent data can help identify repeated misuse.
Fraud information should be incorporated lawfully and with clear provenance.
Terrorist-financing interaction
Because terrorist financing can use lawful funds, remittance and informal-transfer controls should not focus only on criminal-proceeds indicators. Network, destination, sanctions and intelligence context can matter even when the source appears ordinary.
Sanctions controls
Sanctions screening can involve direct customers, underlying parties where data is available, agents, settlement counterparties and ownership. The bank's legal obligations depend on its role and applicable regime.
A high AML-risk score does not determine a sanctions outcome.
Cash courier and bearer value
Some customers may legitimately move physical cash across borders subject to declaration rules. Repeated cross-border cash activity can also warrant review. Banks should understand relevant legal requirements without pretending to enforce customs declarations they cannot observe.
Prepaid, wallet and e-money flows
Value can move from cash into prepaid products or wallets and back into cash or bank transfers. Controls should follow the customer and economic value across product silos where data and law permit.
Scenario: well-controlled remitter
A licensed remitter serves two mature corridors, uses a documented agent network, provides underlying transaction data and has stable settlement patterns. Volumes rise 20% after a marketing campaign. The increase is consistent with the business explanation and supporting operational data.
A generic high-volume rule should not repeatedly escalate this as unexplained pass-through activity.
Scenario: rogue agent
One agent's volume triples, cash use rises sharply and many transfers converge on a small beneficiary set. Several complaints are linked to the location. The bank should assess how the MSB investigated the agent and whether linked settlement activity requires escalation.
Scenario: undeclared remitter
A grocery-store account receives cash from many unrelated individuals and sends repeated transfers to overseas personal accounts. The customer states that the payments are for suppliers, but no supplier relationship is established.
The investigation should determine whether the customer is operating a value-transfer service, whether such activity is permitted and whether the transaction pattern creates suspicion.
Scenario: legitimate high-cash merchant
A seasonal market trader has large cash deposits during annual events, followed by supplier payments consistent with inventory purchases. Historical behaviour supports the explanation.
This is a useful negative case for testing cash scenarios.
Scenario: broker settlement through trade
A company described as an importer sends recurring round-value payments to a foreign exporter, while investigators identify links to a network of remittance brokers. The bank should examine trade substance, ownership, invoices, goods and the customer's explanation before drawing conclusions about settlement activity.
Customer restrictions
Restrictions can include limits, enhanced review, product constraints or relationship exit depending on risk and law. The bank should document why the selected action is proportionate.
De-risking governance
Sector-based exit can push activity outside regulated channels and reduce transparency. Senior governance should distinguish unmanageable customer-specific risk from broad discomfort with a business category.
Management information
Useful MI can include high-risk MSB population, licence status, agent concentrations, corridor changes, data coverage, aged alerts, repeat fraud links, cash anomalies and remediation actions.
MI should support decisions, not simply report volumes.
Data lineage
Settlement data, underlying remittance data, cash transactions and customer attributes may come from different platforms. Lineage should identify source, transformations, aggregation and timing.
A delayed underlying feed can create a monitoring blind spot even if settlement data is timely.
Reconciliation
Where controls depend on underlying transaction files, reconciliation should verify that expected files and records were received and processed. Missing data should create an operational exception, not silent control failure.
BA object model
Useful entities include direct bank customer, MSB legal entity, agent, underlying sender, underlying beneficiary, settlement account, corridor, licence, payment, alert and case. Each role should be explicit.
BA failure scenarios
Test expired licence, missing agent ID, delayed underlying transaction feed, duplicate settlement file, changed corridor, closed agent, customer merger, payment reversal and sanctions-list update during processing.
Quality assurance
QA should verify that investigators distinguish cash intensity from suspicious cash, MSB settlement from ordinary pass-through activity, formal remittance from undeclared transfer services, and high-risk geography from actual suspicious behaviour.
Regulatory examination readiness
The bank should be able to explain population identification, due diligence, data visibility, monitoring, country/corridor methodology, agent risk, sanctions dependencies, alert outcomes and de-risking governance.
Final deep-dive exercise
Build three customer profiles: a cash-heavy restaurant, a licensed remitter with agents and a business suspected of undeclared value transfer. For each, define expected activity, available data, monitoring scenarios, investigation questions and escalation outcomes. The exercise demonstrates why one generic 'high cash / rapid transfer' model cannot manage all three populations effectively.
Advanced practice: cash, remittance and underground-settlement investigations
The most difficult cash and remittance cases are not the ones in which a single large transaction obviously contradicts the customer profile. They are the cases in which each transaction can be explained individually but the combined operating model no longer makes sense. This section develops that investigation skill by moving from isolated alerts to customer, agent, corridor and settlement analysis.
Case 1: a legitimate cash business that changes shape
A family-owned restaurant group has banked with the institution for eight years. It operates four locations, receives both cards and cash and historically deposits cash three or four times a week. Over six months, cash deposits increase by 85% while card turnover rises only 8%. The customer explains that it has started catering private events and that those events are often paid in cash.
A weak investigation would either close the case because the customer is a cash business or escalate it because the percentage increase is large. A stronger investigation tests the explanation. Did the business actually begin catering? Do website, merchant, invoice or account records support the new activity? Are deposits occurring near the operating locations? Are depositors employees or unexplained third parties? Did supplier payments, payroll or tax-related outflows change in a way consistent with higher turnover? What happens to the additional cash after deposit?
Suppose the review shows that the restaurant did begin catering, but 60% of the new cash is deposited hundreds of kilometres from its operating area by people with no known connection to the business. Within hours, similar values move to companies in two countries that have never supplied the restaurant. The case is no longer about high cash. It is about an unexplained collection and settlement model that the customer has not disclosed.
The analyst should document that distinction clearly. The original catering explanation may be partly true. Suspicion can still remain because the depositor geography, third-party behaviour and downstream payments do not align with the stated business.
Case 2: an MSB with rapid corridor growth
A licensed remitter serves several migrant communities. A new corridor grows from 2% to 18% of the firm's volume in three months. The settlement bank's monitoring generates repeated alerts because both volume and country risk have increased.
The bank should not assume that growth into a higher-risk corridor is improper. Relationship management and compliance can establish whether the MSB launched a new product, added agents, signed a new payout partner or experienced a genuine customer migration. The review should examine licensing scope, agent onboarding, settlement counterparty, expected customer profile and whether underlying transaction data is available.
If the growth is supported by a documented launch and the MSB's controls have expanded accordingly, the bank should update expected activity rather than allow the same false positive to repeat indefinitely. If, however, the MSB cannot identify the payout partner, settlement occurs through unrelated trading companies, or agents generate transactions inconsistent with their locations, the investigation has a different basis.
This illustrates a core principle of risk-based monitoring: unusual does not mean suspicious, and once legitimate change is understood the model should learn from it.
Case 3: agent concentration reveals the real risk
An MSB has 400 agents. Aggregate transaction volumes appear stable, but analysis by agent shows that five outlets generate 42% of transfers to one corridor and a disproportionate share of transactions followed by cancellation, rebooking or beneficiary changes.
At customer level, no single sender looks extreme. The risk appears only after agent-level aggregation. The bank should ask how the MSB monitors these outlets, whether staff have been retrained or disciplined, whether customer identity or source-of-funds evidence is weaker there, and whether the same beneficiaries appear across different senders.
The settlement bank does not become the direct supervisor of every agent. Its role is to understand whether the MSB customer can control its own distribution network and whether the bank's exposure remains within appetite.
Case 4: settlement that resembles trade
A wholesale electronics business receives cash and domestic transfers from many individuals. It then pays a small group of exporters overseas. The customer says it sells imported electronics locally, but purchase invoices are generic and turnover materially exceeds the scale of the premises. Interviews reveal that the business also settles obligations for community members whose families receive value abroad through a network of brokers.
This can raise several distinct questions. Is the customer operating an undeclared money or value transfer service? Is that activity licensed or permitted in the jurisdiction? Are the electronics purchases genuine trade, settlement for remittances, or both? Are customer funds being commingled with business revenue? Is the bank exposed to underlying senders and beneficiaries it cannot identify?
The investigation should not jump from "informal transfer" to "money laundering." It should establish the operating model and legal status, then assess whether the transactions, counterparties and source of value create suspicion.
Case 5: cross-border settlement without a matching payment trail
Two brokers in different countries settle customer remittance obligations without sending a bank transfer for each remittance. Broker A pays beneficiaries locally for customers of Broker B; Broker B does the reverse. Periodically, they settle the net balance through trade payments or transfers between businesses.
A bank can therefore see a EUR 500,000 corporate transfer that economically represents hundreds of small remittances. Monitoring based only on the corporate payment can misclassify it as ordinary trade or, conversely, as inexplicable corporate activity.
Where the customer is a declared remitter, the bank should understand the settlement method and data available behind the aggregate. Where the customer claims to be a normal trading business, the same settlement pattern may indicate undeclared financial intermediation.
Correspondent and nested exposure
A bank can also be indirectly exposed through another financial institution. A respondent bank may process payments for an MSB, which in turn serves agents or other remitters. Each layer can reduce direct visibility. The correspondent should understand the respondent's business, downstream access, control framework and expected payment activity rather than assume that every underlying customer has been identified directly by the correspondent.
Transaction monitoring should be calibrated to the correspondent's actual data. Repeated generic originator or remittance information, unexplained nested access, or activity inconsistent with the respondent's declared customer base can justify further review. The objective is transparency and risk understanding, not blanket rejection of indirect payment models.
Monitoring design beyond simple thresholds
Useful cash/MSB scenarios can combine several dimensions:
- cash growth relative to sales or merchant turnover;
- deposit location relative to customer operations;
- number and identity of third-party depositors;
- rapid movement from cash to cross-border payment;
- corridor growth relative to declared business strategy;
- agent concentration and agent-specific exception rates;
- beneficiary concentration across apparently unrelated senders;
- settlement through parties that are not expected financial institutions or payout partners;
- activity outside declared or licensed product scope;
- fraud complaints, recalls or victim-linked beneficiaries;
- sudden use of virtual-asset services or cash-out methods inconsistent with history.
The model should not score all factors identically. Some are structural customer risks; others are behavioural changes or event-level signals. Combining them without distinction can create noisy alerts that investigators cannot explain.
Investigation evidence hierarchy
When reviewing a remitter or informal-transfer case, separate evidence into levels. Direct bank evidence includes account transactions, KYC/KYB records, payment messages and bank-held communications. Customer-provided evidence includes licences, agent lists, contracts and explanations. External evidence can include regulator registers, company registries, official advisories and credible public information. Intelligence from an FIU or law-enforcement body may carry different confidentiality and access requirements.
The case should identify the source of each fact. "Customer is licensed" should be supported by the relevant registry or evidence, not simply repeated because the customer said so. Similarly, a negative media article should not be treated as an adjudicated fact.
False-positive exercise: what would normal look like?
Before escalating a high-volume remitter, construct the legitimate operating model. If the business is genuine, one would expect customer transactions to aggregate into settlement, corridors to align with customer demographics, agent volumes to vary, payout partners to recur, and rapid movement of funds to be normal. This counterfactual gives the investigator a baseline.
Suspicion emerges when observed activity repeatedly diverges from that legitimate model without credible explanation—for example, unexplained trading-company counterparties, activity outside licensed scope, agents operating far beyond plausible capacity, or customer funds moving into owner-controlled assets.
Architecture and data lineage exercise
A BA should map the data objects needed to reconstruct the flow:
sender or underlying customer where available → agent → MSB transaction → MSB principal → settlement batch → settlement account → payout partner → beneficiary.
If the bank receives only the settlement batch and account transfer, that limitation should be visible to users of the monitoring system. If the bank receives underlying transaction files, identifiers should link them to the aggregate settlement so an investigator can drill down without manual spreadsheets.
For cash-intensive businesses, the model should distinguish cash transaction, depositor where captured, deposit channel, business location, account booking and subsequent payment. This allows analysts to ask whether distant deposits, third-party activity or rapid onward movement form a coherent pattern.
Decision-writing exercise
A strong case conclusion should answer five questions in plain language: What changed? Why is that change inconsistent with the declared business? What evidence supports or contradicts the customer's explanation? What part of the activity can the bank actually observe? What action follows under policy and applicable law?
Avoid conclusions such as "high-risk corridor and cash business; therefore suspicious." A better narrative explains the specific behavioural inconsistency and the unresolved economic question. That makes the decision useful to the MLRO, auditors, regulators and any later law-enforcement review.
Practitioner close: cash, MSBs and informal value transfer
Case lab: expected cash becomes unexpected cash
A restaurant customer has always deposited cash, so cash activity by itself is not suspicious. Over six months, however, deposits rise sharply while card-acquiring turnover remains flat, cash arrives at branches far from the trading locations, and funds begin leaving quickly through international transfers to counterparties that do not fit the restaurant’s suppliers.
The correct investigation does not begin with “cash business equals high risk.” It compares observed behaviour with the customer’s business model. The analyst should examine turnover information, acquiring data where available, branch and deposit geography, denomination and frequency, outgoing counterparties, stated supplier relationships, tax or financial information available through KYC, and any reasonable explanation from the customer. The risk comes from the combination of inconsistency, movement and unexplained change.
For monitoring design, the useful signal is therefore not a universal cash threshold. It is deviation from expected activity combined with velocity, geography, counterparty and customer context. Static thresholds can support detection, but behavioural baselines and peer comparisons can make the scenario far more precise.
Case lab: MSB corridor growth
A regulated money-service business has a long-standing relationship with the bank. Transaction volume grows rapidly in one corridor after the MSB appoints several new agents. The corridor itself is legitimate and heavily used by migrant workers. The bank should not equate high remittance volume with laundering.
The investigation should ask whether growth is commercially plausible, whether new agents were onboarded under the MSB’s control framework, whether customer or agent concentration changed, whether unusual funding sources appeared, whether settlement accounts show pass-through behaviour inconsistent with the business, and whether the MSB can explain material changes. The bank may also consider regulatory status and the quality of the MSB’s own AML controls according to its risk-based due-diligence framework.
A strong review separates risk in the business model from evidence of misuse. De-risking an entire category can remove legitimate financial access without improving the quality of financial-crime detection.
Informal value transfer: understand the settlement mechanism
Informal value-transfer systems can support legitimate remittances and commerce, particularly where formal banking access is limited. They can also be exploited by criminals or terrorist financiers. The bank’s task is not to label every informal transfer as illicit but to understand how value is settled.
Settlement can involve cash, bank transfers, trade transactions, netting, third parties or movement across several jurisdictions. A bank may see only one part of the mechanism. This is why investigation should connect customer activity, counterparties, trade-like payments, agent relationships and network behaviour rather than search for one “hawala payment” field that does not exist.
Correspondent and nested exposure
An MSB may bank through another financial institution, creating indirect exposure for the correspondent bank. The correspondent may have limited visibility of the MSB’s end customers. Requirements should therefore distinguish direct customer due diligence from respondent-bank due diligence and transaction-monitoring visibility.
Where nested or downstream relationships are identified, the bank should assess them according to its correspondent-banking framework. The control should not claim that the correspondent can perform end-customer CDD on populations it cannot directly access. Instead it should understand the respondent’s controls, available transaction data, unusual patterns and escalation routes.
Evidence hierarchy for a defensible decision
A good case file separates verified facts, customer statements, external information and analyst inference. For example, a business licence confirms legal status; it does not prove every transaction is legitimate. A customer explanation can be plausible while still requiring corroboration. A monitoring alert is a lead, not proof.
The final decision should state what changed, why that change matters, what evidence was reviewed, whether the explanation fits the observed activity, what uncertainty remains and what action follows. Possible outcomes can include closure, continued monitoring, KYC refresh, enhanced due diligence, account restrictions according to policy, or escalation for suspicious-activity reporting where the legal threshold is met.
BA and control-design checkpoint
A BA designing controls for cash-intensive businesses and MSBs should model customer type, expected activity, cash-deposit events, branch/location, agent relationships, settlement accounts, counterparties, corridor, funding source, transaction velocity, KYC changes, alerts, investigations and outcomes. Monitoring should support changes over time and network relationships rather than a single cash amount.
The strongest learner takeaway is that cash, remittances and informal value transfer are not suspicious merely because of their form. Risk emerges when the observed financial behaviour, ownership, counterparties, settlement mechanism or explanation does not fit the legitimate economic story.
Practitioner masterclass: separating cash, remittance and informal-transfer risk
The fastest way to create poor financial-crime controls in this area is to treat every cash-heavy customer, every remitter and every informal value-transfer pattern as one risk category. They are not the same. A restaurant, a licensed digital remitter, a foreign-exchange business and an underground settlement network can all move large values, but the expected activity, data, regulatory perimeter and control response are very different.
Cash-business reconstruction
Start with what the business sells, how customers pay, where it operates, expected turnover, seasonality and card-versus-cash mix. Then compare actual deposits and withdrawals with that model.
A sudden cash increase becomes meaningful only when the bank understands whether the business expanded, opened a new location, changed payment mix or experienced a genuine seasonal event.
Structuring exercise
A customer makes repeated deposits just below a known threshold. Do not stop at the amounts. Examine dates, deposit locations, who made the deposits, historical behaviour and what happens to funds afterwards.
The pattern may create a reason for review, but the investigator should not infer deliberate threshold evasion without supporting context.
MSB due-diligence map
A strong review covers licence or registration where required, legal entities, owners, management, products, customer types, agents, corridors, expected volumes, settlement accounts, sanctions controls, monitoring, suspicious-reporting process and audit history.
Agent concentration
Suppose one agent produces 35% of an MSB’s volume, has unusually high cash usage and sends to a narrow beneficiary set. That concentration deserves analysis. It does not prove misconduct.
The bank should understand how the MSB monitors the agent, whether the activity fits local customer demand and whether complaints or alerts cluster there.
Settlement-account exercise
An MSB’s bank account receives millions daily and sends large bulk transfers. A generic corporate-monitoring rule may treat this as pass-through behaviour. For the MSB, pass-through is the business model.
The stronger questions are whether aggregate volume, corridors, counterparties and cash exposure fit the expected model and whether meaningful changes are investigated.
Underlying transaction visibility
Document exactly what the bank receives. Does it have underlying sender and beneficiary information? Agent ID? Purpose? Corridor? Or only net settlement?
A control cannot truthfully claim to screen or monitor data it never receives.
Underground banking and hawala
FATF’s September 2026 report on professional money laundering, underground banking and hawala emphasises that these systems vary in sophistication and can serve legitimate value-transfer needs while also being exploited by professional money launderers. That distinction should shape the bank’s language: the mechanism alone is not proof of criminal activity.
Where a bank customer appears to operate a value-transfer business outside the expected regulated framework, the investigation should establish legal status, counterparties, settlement method, source and purpose rather than rely on cultural labels.
Broker settlement exercise
Broker A receives cash locally. Broker B pays a beneficiary in another country. The two brokers later settle through trade or bank transfers. A bank may only see the settlement leg.
Investigators should understand that the bank payment may represent net obligations from many underlying transfers. This can reduce transparency and requires a different evidence model from a normal corporate payment.
Corridor change
A remitter historically serves three countries and suddenly adds two new corridors with high cash volumes. The correct response is event-driven risk review: permissions, business rationale, agent footprint, expected customers and sanctions/country exposure.
Do not assume the new corridor is suspicious merely because country risk is higher.
De-risking discipline
A sector can be higher risk without every customer being unmanageable. Review whether controls, transparency and governance can reduce residual risk. Exit should be based on the institution’s risk framework and facts, not a blanket sector label.
BA requirements exercise
Model principal MSB, agent, sender, beneficiary, corridor, settlement account and downstream partner as different roles. Define which are direct customers and which are underlying parties. Add effective dates for licences and agents, and identify which controls depend on each data element.
Quality assurance test
Review closures that say “cash business — expected” or “MSB — high risk.” Both are weak. A defensible case explains why the actual behaviour is or is not consistent with the expected business model.
Final practitioner test
A strong learner should be able to distinguish cash risk from remittance risk, identify agent and settlement-account dependencies, explain the bank’s visibility limits and discuss informal value transfer without equating informality with criminality.
60-minute mastery extension: cash-intensive businesses, MSBs and informal value transfer
This extension makes the chapter a minimum 60-minute guided learning experience. Spend about 25 minutes on the core material, 15 minutes on the MSB and cash-business cases, 10 minutes on corridor/agent analysis and 10 minutes on the final risk test.
Similar transaction patterns can represent very different business models
A restaurant, remittance company, foreign-exchange business, payroll provider and informal-value-transfer network can all show high transaction volumes and rapid movement. The bank should not treat them as one generic "high-risk cash" population. Expected activity, licensing, underlying-customer visibility, settlement model, agent structure and geographic corridors differ materially.
Worked case: cash-intensive retail business
A convenience-store group deposits substantial cash every day. Historical sales and merchant-acquiring data broadly support the volumes. Deposits later begin occurring in distant locations and by unrelated people, while same-day transfers to overseas companies increase. The change matters because geography, depositor identity and onward movement no longer align with the verified business model.
The investigation should test whether the company opened new stores, uses cash-collection services or changed suppliers. A cash-intensive business is not suspicious merely because it uses cash.
Worked case: regulated remitter
A licensed remittance business receives millions into a settlement account and sends large aggregate transfers to overseas partners. Generic monitoring can misclassify this as high pass-through activity. For the remitter, pass-through is the business model.
The bank should instead understand ownership, licensing where required, products, agents, customer base, corridors, expected volume, settlement partners, sanctions controls, transaction monitoring, suspicious reporting and audit history. The direct bank may not see every underlying sender and beneficiary, so the exact data available should be documented.
Agents and sub-agents
Agent networks can create concentration and control risks. A single agent producing a large share of volume, unusually high cash usage or repeated payments to a narrow beneficiary set can merit review. The bank should understand how the MSB performs agent due diligence, ongoing monitoring and termination.
Shared ownership or common devices across agents can matter, but common geographic location may simply reflect customer demand. Network signals should be interpreted in business context.
Informal value transfer and hawala
Informal value-transfer mechanisms can serve legitimate economic needs, especially where formal banking access is limited. They can also be exploited by professional money launderers and terrorist financiers. The mechanism itself is not proof of criminality.
A bank should assess whether the customer is operating a money/value-transfer activity, whether licensing or registration is required, how settlement occurs, which counterparties are involved and whether the business is transparent enough to manage. Cultural or geographic labels are not substitutes for evidence.
Broker-settlement example
Broker A receives local cash from customers. Broker B pays beneficiaries abroad. The two brokers settle later through trade, netting or bank transfers. A bank may only see the settlement leg, not the underlying remittances. This creates a visibility problem rather than automatic suspicion.
The control should ask whether the settlement activity is expected, lawful and supported by a credible business model, and whether the bank has enough information to manage residual risk.
Corridor-change exercise
A remitter historically serves three countries and adds two new corridors. Build an event-driven review covering licensing/permissions, customer demand, agents, partner institutions, sanctions exposure, country risk, expected value/volume and monitoring coverage. Define what must be updated before the bank treats the new corridors as normal activity.
Then decide what happens if the bank cannot obtain sufficient transparency. Restriction or exit can be justified where risk is unmanageable, but the reasoning should be customer-specific rather than a blanket sector decision.
Structuring and thresholds
Repeated transactions below a reporting or monitoring threshold can create concern, but intent should not be inferred from amounts alone. Look at timing, locations, actors, historical behaviour and subsequent movement. Thresholds are triggers, not conclusions.
BA data model
Model MSB principal, agent, underlying sender, underlying beneficiary, corridor, settlement account, downstream partner and direct bank customer as different roles. Capture licence/registration effective dates and what data the bank receives for underlying transactions. This prevents the system from pretending that every underlying sender is a direct customer.
De-risking discipline
Higher sector risk does not mean every MSB or cash business is unmanageable. A well-governed, transparent remitter can be better understood than an opaque low-volume company. The bank should assess residual risk and control capability rather than apply broad labels.
Final risk test
For each pattern—high cash deposits, high pass-through ratio, agent concentration, new corridor, shared address, informal settlement and cross-border bulk transfer—write one legitimate explanation, one risk hypothesis and the evidence needed to distinguish them.
A strong learner should finish able to separate cash risk, MSB risk and informal-transfer risk while understanding the bank's actual visibility and regulatory perimeter.
Worked case: the agent network that outgrew its principal
A money-service business customer processes an illustrative 60 million annually through the bank, operating 340 agents across three cities. Monitoring shows 78 percent of volume flowing through just eleven agents, several of which were onboarded by the MSB in the last eight months. Three of the eleven share phone numbers with loan-broker businesses, and one operates from an address that also hosts a travel agency advertising discounted international transfers on social media. The MSB's own compliance reports describe steady, diversified growth and make no mention of concentration.
The investigation focuses on the principal-agent control gap rather than individual transactions. The legal duties of an MSB principal, its agents and any sub-agents are jurisdiction-specific and depend on the service and regulatory perimeter. Some regimes place substantial oversight duties on a principal; some also impose direct obligations on agents; registration or licensing treatment can differ where a person acts only as an agent versus conducting regulated activity on its own account. The bank should therefore map the applicable regime instead of assuming one universal allocation of liability. For relationship-risk purposes, the team assesses whether the customer's agent governance is credible: onboarding standards and their evidenced application to the eleven concentrated agents, transaction limits per agent and whether breaches trigger action, mystery-shopping or site-visit records, agent-training completion, and the MSB's own monitoring alerts on agent-level anomalies.
Findings show governance theatre rather than governance. Onboarding files for the concentrated agents contain identical business descriptions suggesting copy-paste rather than inquiry. Limit-breach reports exist but show no resulting agent review or termination across two years. Site-visit records cover only long-standing low-volume agents, never the high-volume recent additions. The MSB's monitoring aggregates to principal level, so agent-level structuring and third-party-use patterns are invisible to its own controls. Meanwhile transaction analysis of the settlement account shows classic agent-facilitated patterns: split transactions just below identification thresholds clustering at specific agent terminals, rapid-fire sequential transactions inconsistent with walk-in customer flow, and sender-receiver pairings suggesting pooled or third-party-directed activity.
The bank faces a decision with commercial weight: the MSB is a profitable customer and its remittance corridors serve legitimate migrant communities. The response should be graduated, evidence-based and permitted by the applicable legal, contractual and policy framework. Depending on that framework, options can include enhanced monitoring, targeted restrictions or limits, requests for agent-level data, remediation milestones and enhanced due diligence. In this illustrative case the bank requires re-onboarding of high-volume agents to the agreed relationship standard, independent site visits and agent-level monitoring implementation, while preparing a managed-exit contingency if the MSB cannot demonstrate effective remediation.
The lesson generalises to agent-based exposure: a bank should assess the credibility of the principal's agent oversight to the extent relevant to its own customer due diligence, monitoring and risk-management obligations. Agent concentration analytics, onboarding-file sampling, limit-breach outcome tracking and settlement-pattern analysis can form part of an MSB monitoring suite. Concentrated growth among weakly governed agents is a risk signal requiring evidence, not by itself proof that the agents or principal are complicit in crime.
Dynamic corridor risk: limits that follow the risk
Remittance corridors differ enormously in risk: the regulatory environment at each end, the prevalence of informal competition, conflict and displacement dynamics, currency controls creating parallel-market incentives, and the corridor's observed abuse history. Static corridor treatment, identical controls for all destinations, simultaneously over-controls low-risk flows and under-controls high-risk ones. Dynamic corridor risk management adjusts monitoring intensity, documentation expectations, velocity limits and review frequency to current corridor assessments, and updates those assessments on evidence rather than calendar.
Operationalising this requires corridor-level measurement the bank may not currently produce. For each material corridor, the bank should track volume and growth trends, customer-concentration patterns, alert and case rates with outcomes, fraud and scam intelligence, regulatory and sanctions developments at either end, and displacement signals suggesting activity migrating from informal to formal channels or vice versa. Corridor reviews then set concrete control parameters: per-customer velocity limits reflecting legitimate corridor use, documentation triggers for anomalous patterns, enhanced review for new-customer corridor activity, and agent-oversight intensity for agent-served corridors.
Displacement awareness is the sophisticated edge of corridor management. Crackdowns on informal providers can push flows into the banking system, changing the risk profile of formally recorded corridors without any change in underlying activity. New compliance requirements in one jurisdiction can reroute flows through neighbours. Conflict and disaster events create sudden legitimate surges that naive velocity controls will block, harming vulnerable people, while simultaneously creating exploitation opportunities that lax emergency treatment will miss. Corridor management must therefore combine quantitative monitoring with qualitative awareness of events at both ends, and must empower analysts to distinguish surge legitimacy from surge exploitation using sender, purpose and pattern evidence rather than volume alone.
Nested respondent exposure in payment flows
MSB and remittance risk increasingly reaches banks indirectly, through respondent banks whose own MSB customers' flows pass through correspondent accounts. The nested-exposure control problem mirrors the payable-through challenge: the bank sees the respondent's aggregated flow with limited underlying originator detail, and must decide how much opacity to accept. The answer depends on structured assessment of the respondent's MSB business: which MSBs it serves, their licensing and supervision status, the corridors involved, the respondent's own agent-oversight and monitoring capability, and the message-quality evidence showing what originator detail actually arrives.
Message-quality measurement makes this assessment empirical rather than impressionistic. The bank should sample nested flows for originator-field completeness, consistency between stated business and observed patterns, and responsiveness to information requests. Persistent field-stripping, template narratives across supposedly independent originators, or respondent inability to identify underlying senders are findings about the respondent relationship, not merely data-quality notes. Volume tolerances should reflect the assessed nested population: a respondent whose MSB book doubles without explanation triggers review of both the growth and the controls supposedly governing it.
Exit and restriction decisions for nested exposure require the same graduated discipline as direct MSB relationships, with additional attention to legitimate-flow impact. Cutting a correspondent relationship over nested MSB concerns can disrupt entire communities' remittance access; managed approaches include enhanced information requirements with deadlines, flow restrictions to verified sub-populations, and coordinated transition planning where law, contract, scheme rules and policy allow them. But managed approaches are not indefinite tolerance: defined remediation deadlines and documented consequences distinguish genuine remediation from indefinite forbearance.
Worked case: settlement without money movement
A review of a long-standing MSB customer shows remittance volumes to an illustrative South Asian corridor growing 40 percent year on year, while the settlement-account flows funding those remittances grow only 8 percent. The MSB explains the gap as improved netting efficiency. Analysts familiar with informal value-transfer mechanics recognise an alternative hypothesis: the corridor is substantially settled through hawala-style offset rather than through the banked settlement account, with the banked flows representing only the net residual or a shrinking share of gross activity.
Understanding informal settlement mechanics is prerequisite to assessing such cases fairly. In classic hawala, senders' funds are collected by a hawaladar at origin, beneficiaries are paid by a counterpart hawaladar at destination from local liquidity, and no money crosses borders at the time of transfer. Settlement between hawaladars occurs later through various mechanisms: reverse remittance flows, trade-invoice manipulation, cash couriers, or banked transfers that appear unrelated to the underlying remittances. The system is trust-based, fast and often cheaper than formal channels, serving legitimate migrant communities extensively alongside its criminal exploitation.
The investigation therefore distinguishes three questions that naive analysis conflates. First, is the MSB's banked activity itself suspicious, judged on its own merits through standard monitoring. Second, does the volume gap indicate unbanked settlement activity connected to the customer, assessed through corridor intelligence, sender-behaviour analysis and the plausibility of the netting explanation tested against the MSB's actual bilateral flow data. Third, does any connected informal activity involve criminal proceeds as opposed to legitimate remittances using traditional methods, a distinction that transaction data alone rarely resolves and that requires customer inquiry, corridor intelligence and potentially law-enforcement context.
In this fictional case the inquiry finds legitimate explanation with control gaps rather than criminality: the MSB has genuinely shifted toward bilateral netting with a partner institution, documented through netting agreements and settlement records it had never thought to share, but its own monitoring cannot see the offset activity and its regulatory reporting understates gross flows. The outcome is remediation rather than exit: revised reporting, netting-transparency requirements, and monitoring calibrated to gross rather than net activity. The lesson is that volume-gap analysis is a question generator, not a conclusion, and that informal-settlement literacy prevents both the error of criminalising efficient netting and the error of accepting hawala explanations as conversation-stoppers. An MSB that invokes informal settlement to explain every anomaly without documentation is itself the finding.
De-risking versus managed exit: the fairness discipline
Blanket de-risking of MSB, remittance and cash-intensive customer categories has drawn sustained criticism from standard-setters and policy bodies, and for sound operational reasons beyond fairness: terminated customers may migrate to less transparent channels, reducing system-wide visibility while the bank books a risk reduction it has partly exported rather than eliminated. FATF repeatedly emphasises risk-based, proportionate treatment and states that its standards do not envisage cutting off entire classes of customers merely because a jurisdiction or category is higher risk. A bank must still map the binding law, supervisory expectations, customer-protection rules and risk appetite that apply to each legal entity rather than treating FATF guidance itself as a universal customer-exit rule.
A managed-exit discipline replaces category-based termination with relationship-based decisions supported by evidence. Each exit decision should record the specific risk findings for that relationship, the remediation attempted where appropriate, deadlines and outcomes, legitimate-activity impact where relevant, and approval at the level required by policy and applicable law. Enhanced requirements, volume or corridor restrictions, monitoring upgrades and governance improvements may be appropriate before exit where the legal and risk context permits, but remediation is not a universal prerequisite when immediate legal, sanctions, fraud, safety or other constraints require a different response.
Where exit proceeds, transition management must follow the applicable legal, contractual, sanctions/AML-confidentiality and customer-protection framework. Where permitted and appropriate, notice can give a legitimate customer time to find another provider; in other cases the bank may be unable to give advance notice or disclose the underlying reason. Customer communication should avoid unlawful tipping-off or disclosure of protected suspicious-reporting information. Referral or alternative-provider support is a policy choice, not a universal duty. Portfolio monitoring can also test whether risk reappears through new entities or nested channels, which may require a fresh assessment rather than an assumption that the original exit solved the underlying exposure.
The same discipline applies to onboarding appetite: a higher-risk category should have explicit, risk-based acceptance criteria and enhanced evidence requirements rather than an undocumented blanket refusal attributed incorrectly to FATF. A bank can still decide, consistently with applicable law and its risk appetite, that particular relationships or activities fall outside appetite when the decision is evidence-based, governed and not falsely presented as a global AML rule.
Gift cards and stored-value instruments in informal transfer
Gift cards, prepaid access products and loyalty-point currencies function as informal value-transfer instruments where they can be purchased with cash or criminal proceeds in one location and redeemed, resold or converted in another. The mechanics are straightforward: bulk gift-card purchases with cash, often structured across retailers to evade identification thresholds; resale through online marketplaces at discounts converting cards to banked funds; and cross-border physical movement of high-value cards functioning as cash couriering with reduced bulk and detection risk. Closed-loop cards usable only at specific merchants present lower risk than open-loop network-branded products with ATM access, and product-risk tiering should reflect this functional distinction.
Retail-partnership intelligence provides the detection foundation: bulk-purchase reporting from retail partners, structuring patterns across store locations, purchaser behaviour inconsistent with gifting such as indifference to card design or recipient, and repeat purchasers with no plausible gift-giving profile. Marketplace monitoring examines resale patterns: sellers offering large volumes of gift cards at consistent discounts, seller identities disconnected from legitimate card sourcing, and the velocity of card-to-cash conversion. Redemption analysis at the cash-out end identifies accounts funded predominantly through gift-card redemptions or marketplace proceeds without commensurate legitimate activity.
Product-design controls address the structural capacity: purchase limits with aggregation across locations and time, identification requirements calibrated to bulk-purchase risk, restrictions on cash purchase of high-value open-loop products, and redemption controls preventing rapid bulk conversion. Retailer and distributor oversight ensures policy implementation at the point of sale rather than existing only in programme documents. The category warrants proportionate rather than alarmist treatment: gift cards serve enormous legitimate commerce, and controls should target bulk-anonymous-cash purchase patterns specifically rather than burdening ordinary gifting.
Mobile-money agents: oversight at the last mile
Mobile-money and e-money agent networks extend financial services to populations branches cannot reach, and simultaneously extend placement and layering capacity through thousands of lightly supervised cash-in and cash-out points. Agent-level risks mirror MSB-agent risks with digital amplification: split transactions across agent tills evading identification thresholds, agent-facilitated third-party use of customer wallets, SIM and identity fraud creating mule wallets at scale, and agent collusion in fraud and laundering schemes. The oversight challenge is scale: agent networks number in the tens or hundreds of thousands, individual agents transact small values, and central monitoring sees only electronic records detached from the cash and identity reality at the till.
Effective agent oversight combines data analytics with physical-world controls. Till-level analytics detect the characteristic patterns: structuring signatures across an agent's transactions, velocity inconsistent with the location's footfall and commercial profile, reversed or voided transaction rates suggesting manipulation, and customer-concentration patterns indicating third-party direction. Float-management analysis examines whether agent liquidity patterns match legitimate business: agents consistently requiring extraordinary float top-ups may be processing undisclosed volumes. Agent-lifecycle monitoring tracks onboarding quality, training completion, complaint patterns and disciplinary history, with high-risk-agent designations triggering enhanced requirements or termination.
Mystery shopping, site visits and test transactions provide ground truth that analytics cannot: whether identification is actually checked, whether transaction splitting is offered or accepted, whether records match reality. These physical controls should target analytically identified high-risk agents rather than sampling randomly, concentrating scarce field resources where data indicates problems. Agent contracts should specify applicable compliance obligations and consequences. Where banks partner with telecom-led or fintech-led mobile-money schemes rather than operating networks directly, relationship due diligence should assess the scheme's agent-oversight capability proportionately to the bank's role, contractual rights, data access and applicable obligations.
Foreign-exchange bureaus: small shops, material risk
Foreign-exchange bureaus combine currency conversion, cash handling, tourist services and often money-transfer agency functions in small retail operations with high cash throughput and historically uneven supervision. The placement and layering risks concentrate in rate manipulation facilitating value transfer, structuring across bureau networks, counterfeit-currency placement, and bureau accounts serving as collection points for wider networks. A bureau exchanging currency at rates materially off-market can create a value-transfer signal that requires context and corroboration rather than an automatic finding of misconduct.
Supervision and regulatory treatment of bureaux differ materially by jurisdiction. For bank due diligence, licensing or registration where applicable, transaction-record completeness, identification and reporting controls required under the relevant regime, and observed compliance history can inform the relationship assessment. Bank-account analysis should compare throughput with a credible customer base and location; foreign-currency order patterns inconsistent with the stated business can also create a reason for review.
Where bureaux also act as MSB agents, the combined risk assessment should address both functions jointly rather than supervising each in isolation, since the same till can serve conversion, transfer and collection purposes interchangeably. The bank should not assume a universal direction of regulatory change; it should use current local law and supervisor guidance for each entity and jurisdiction.
Authoritative anchors
FATF Recommendations: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
FATF Guidance for a Risk-Based Approach for Money or Value Transfer Services: https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/Guidance-RBA-money-value-transfer-services.pdf
FATF, Investigating Professional Money Laundering, Underground Banking, and the Use of Hawala and Other Similar Service Providers, 3 September 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/pml-underground-banking-hawala-hossps.html
FATF resources on professional money laundering and informal value transfer: https://www.fatf-gafi.org/en/topics/methods-and-trends.html
2026 practitioner enhancement: cash, MSBs and informal transfer without blanket de-risking
Cash-intensive businesses, remitters, money or value transfer services and informal value-transfer systems all have legitimate economic roles. They can also be exploited because they aggregate many underlying customers, move value across borders, rely on agents, use cash or settle obligations outside a simple one-payment-one-beneficiary model. The right response is therefore proportionate risk understanding, not category-based exclusion.
The bank needs to understand whose activity it is seeing
An MSB settlement account can contain the aggregated value of thousands of underlying remittances. A bank monitoring that account should distinguish the MSB's own corporate expenses from customer-funds collection and settlement. If the bank receives underlying originator and beneficiary data, controls can use it. If it sees only aggregate settlement, the bank should not claim to have screened or monitored every underlying customer transaction.
This visibility statement should be explicit in the control design, model documentation and investigator guidance.
Agent networks change the risk surface
Agents extend access but create another operating layer. A strong bank assessment considers how the MSB selects, trains, monitors and disciplines agents; whether transactions are attributable to individual agents; whether unusual cash, customer, corridor or sanctions patterns can be identified; and how the principal responds to problematic agents.
Concentration can matter. A small number of agents generating disproportionate high-risk activity may be more informative than the MSB's aggregate volume. The legal allocation of duties between a principal, agent and sub-agent is not universal: it must be checked against the jurisdiction, service and business model. For example, FinCEN's U.S. rules distinguish a person acting solely as an agent of another MSB from a person conducting MSB activity on its own behalf.
Nested and downstream payment relationships
An MSB can serve other remitters or intermediaries, creating indirect exposure for the settlement bank. Such nesting is not automatically prohibited. The bank should understand whether downstream relationships are permitted, whether they are disclosed, what data is available, how the MSB performs due diligence and whether activity remains consistent with the agreed business model.
The same principle applies to correspondent banking: indirect access should be understood and governed rather than assumed to be inherently suspicious.
Hawala and other similar service providers
FATF's September 2026 report on professional money laundering, underground banking, hawala and other similar service providers is important because it makes two realities clear at the same time. These networks can support legitimate remittance and community needs, particularly where formal access is limited, while criminals and professional money launderers can exploit them to collect, settle and redistribute illicit value.
Banks should therefore avoid using the term "hawala" as a risk conclusion. The relevant questions include whether the activity is declared and legally permitted, who controls the business, how customers and counterparties are identified, how balances are settled, which corridors are used, whether trade or cash is involved and whether the activity matches the customer's stated purpose.
Underground settlement and third-party payments
Informal networks can settle obligations through bank transfers, cash, trade, netting or payments made on behalf of third parties. The bank may never see a direct transfer between the original sender and recipient. This can create unusual patterns: businesses paying unrelated entities, repeated round-value transfers, cash followed by cross-border settlement, or trade transactions that appear disconnected from the account holder's stated business.
These are hypotheses for investigation, not proof. Analysts should map the economic relationships and ask whose obligation is actually being settled.
Cash-intensive businesses and expected activity
Cash should be assessed against the operating reality of the business. Useful context can include sales channels, card-to-cash mix, locations, opening hours, seasonality, peer businesses, merchant-acquiring data, tax information where lawfully available and changes such as expansion or new products.
A restaurant that triples cash deposits after opening three new outlets may have a credible explanation. The same increase with flat card sales, no expansion and rapid payments to unrelated overseas entities creates a different risk picture.
Cash depositors and funnel behaviour
Repeated cash deposits by different people or in distant locations can be relevant. The bank should examine whether the customer uses collectors, franchisees, delivery locations or other legitimate arrangements. Funnel-account patterns become more concerning when third-party deposits are followed by rapid consolidation, cash withdrawal or onward transfers inconsistent with the customer profile.
Remittance corridors and financial inclusion
Higher-risk corridors can require stronger controls, but FATF's risk-based approach does not support indiscriminate de-risking. FATF's 19 June 2026 statement on jurisdictions under increased monitoring explicitly says its standards do not envisage de-risking or cutting off entire classes of customers and instead call for risk-based treatment. Family remittances and humanitarian flows can be essential. Controls should consider corridor risk together with customer type, agent oversight, transaction behaviour, sanctions exposure, fraud intelligence and local regulatory expectations.
The current FATF page for its 2016 MVTS guidance also warns that the document predates later revisions to the Standards, including the 2025 revisions to Recommendation 1. It should therefore be used with the current FATF Recommendations and newer risk-assessment and financial-inclusion guidance rather than treated as a frozen rulebook.
Fraud, mule and MSB interaction
Scam proceeds can move through remitters or informal channels. Repeated fraud complaints linked to the same beneficiary, agent, outlet or settlement pattern can therefore be useful AML intelligence. The bank should have a controlled way to share confirmed fraud indicators with MSB monitoring without assuming that every remittance linked to a high-fraud corridor is criminal.
Real-time and near-real-time controls
Digital remitters can move funds almost instantly. Pre-transaction controls can include sanctions screening, fraud signals, limits and customer or beneficiary checks. Post-transaction monitoring can examine corridor change, pass-through behaviour, agent concentration and network links. Legal rights to delay, reject, freeze or recall differ by scheme and jurisdiction, so operational requirements should not be written as universal AML powers.
BA and architecture requirements
A bank-grade data model should distinguish principal MSB, agent, underlying transaction where available, settlement account, originator, beneficiary, corridor, payment, cash event and downstream intermediary. Aggregated settlement should not be mistaken for one customer transfer. Data lineage should preserve which information the bank actually received at the time of screening or monitoring.
References and further reading
- FATF — The FATF Recommendations, current Standards and amendment history: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF — Guidance for a Risk-Based Approach for Money or Value Transfer Services, 2016. The FATF page itself notes that later Standards revisions must also be considered: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Rba-money-or-value-transfer.html
- FATF — Investigating Professional Money Laundering, Underground Banking, and the Use of Hawala and Other Similar Service Providers, 3 September 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/pml-underground-banking-hawala-hossps.html
- FATF — Jurisdictions under Increased Monitoring, 19 June 2026, including the statement that FATF does not call for blanket de-risking of entire customer classes: https://www.fatf-gafi.org/en/publications/High-risk-and-other-monitored-jurisdictions/increased-monitoring-june-2026.html
- FATF — Risk-Based Approach resources: https://www.fatf-gafi.org/en/topics/risk-based-approach.html
- FinCEN — Money Services Business Registration. U.S.-specific requirements and agent-registration distinctions under the Bank Secrecy Act framework: https://www.fincen.gov/resources/money-services-business-msb-registration
- AUSTRAC — Indicators of suspicious activity for the remittance service providers sector. Australia-specific operational guidance: https://www.austrac.gov.au/industry-and-business/education-and-resources/publications-and-resources/indicators-suspicious-activity-remittance-service-providers-sector
- AUSTRAC — Unregistered remittance service providers. Australia-specific registration and crime-risk context: https://www.austrac.gov.au/industry-and-business/your-industry/remittance-service-providers/unregistered-remittance-service-providers
- Wolfsberg Group — Correspondent banking and financial crime resources: https://wolfsberg-group.org/resources
Jurisdiction note: FATF sets global standards and non-binding guidance; licensing, registration, agent obligations, reporting thresholds, customer-exit rights and supervisory expectations are implemented through local or regional law. Apply the framework relevant to the bank entity, product, customer and corridor.