Human Trafficking Typology Referral
Human trafficking is not a transaction type. It is a crime in which people are recruited, moved, transferred, harboured or received for exploitation through means such as force, coercion, deception or abuse of vulnerability. Under the UN Trafficking in Persons Protocol, the adult offence is commonly understood through three elements: an act, a prohibited means, and an exploitative purpose. For children, the Protocol does not require proof of the means element. Exploitation includes, at a minimum, sexual exploitation, forced labour or services, slavery or similar practices, servitude and removal of organs.
For a bank, the practical challenge is that exploitation itself may not appear explicitly in a payment message. The bank sees accounts, devices, merchants, employers, cash deposits, wages, transfers, travel purchases, remittances, business revenues and counterparties. It may also see behavioural information through branch or contact-centre interactions. Those fragments can expose a financial relationship between a possible victim, a controller and the proceeds of exploitation, but they rarely prove trafficking by themselves.
This is why the right mental model is signal plus context plus relationship, not “one red flag equals trafficking.” FATF’s 2018 report on financial flows from human trafficking makes the same core point: different forms of trafficking generate different financial patterns, and no single indicator should be treated as conclusive. FinCEN’s U.S. advisories likewise tell financial institutions to evaluate indicators together with the customer profile and expected activity. A bank should therefore detect, investigate, document and refer. It should not pretend that a monitoring scenario can make a criminal-law determination on its own.
The second principle is equally important: a person whose account is being used in trafficking-related activity may be a victim, a facilitator, a controller, a business beneficiary, or some combination that is not immediately clear. Standard fraud or mule-account reflexes can therefore cause harm if they automatically freeze, exit or accuse a possible victim before the institution has considered safeguarding, access to essential funds, controller access and local legal duties.
Trafficking is different from smuggling
Human trafficking and migrant smuggling are often confused because both can involve movement across borders, facilitators and payments. They are not the same concept. Smuggling generally concerns the facilitation, for financial or material benefit, of irregular entry into a country. Trafficking concerns exploitation. Trafficking does not require an international border crossing; it can take place within one city, region or country. A person can also begin a journey through smuggling and later become a victim of trafficking if exploitation and coercive control emerge.
This distinction matters operationally. A payment to a travel facilitator may relate to legitimate travel, migrant smuggling, trafficking, or another crime. The bank needs surrounding evidence: who paid, who benefited, whether the customer controls their own account, whether wages are diverted, whether the same organiser appears across multiple people, whether travel and accommodation patterns line up with exploitation indicators, and whether law-enforcement or adverse information changes the context.
It also matters for reporting. A jurisdiction may have different offences, filing instructions and information-sharing rules for trafficking and smuggling. U.S. FinCEN, for example, has issued separate trafficking and smuggling advisories and specific SAR key terms. Those U.S. instructions should not be copied into another jurisdiction’s STR process unless local law and FIU guidance require them.
What a bank can realistically detect
A bank normally has stronger visibility of money movement than of the underlying human interaction. Detection therefore works best when several dimensions are connected.
Customer context can include occupation, employer, business activity, expected income, beneficial ownership, address, contact details and the reason for opening the account. A person presented as an independent worker but whose account is operated from the same device, phone number or address as several unrelated workers may require further review. A business claiming a large workforce but showing little or no payroll may also deserve scrutiny, although outsourcing, cash payroll, seasonal labour and other legitimate explanations must be considered.
Transaction behaviour may reveal wages that are immediately swept to a third party, repeated ATM withdrawals soon after credits, concentrated peer-to-peer receipts followed by rapid transfers to one controller, unexplained cash deposits, travel and hotel patterns, or payments that do not fit the stated customer or business activity. None of these is unique to trafficking. Their value comes from combination and persistence.
Network relationships can be more revealing than any single account. Repeated use of the same employer, recruiter, beneficiary, device, address, branch, ATM location, merchant, wallet, telephone number or remittance recipient can connect people who appear unrelated when accounts are reviewed separately. Graph or relationship analysis is therefore useful, provided the underlying data is reliable and analysts can distinguish verified links from probabilistic associations.
Behavioural observations may also matter. FinCEN’s May 2026 notice for the U.S. financial sector highlighted that customer-facing employees may sometimes observe behavioural indicators that transaction monitoring cannot see. Examples can include another person controlling the interaction, holding identification, answering every question, or preventing the customer from speaking independently. Such observations should be recorded factually, without amateur diagnosis or confrontational questioning.
Exploitation types and financial visibility
The UN and FATF frameworks cover several exploitation types. Banks should understand how financial visibility differs across them rather than forcing every case into one generic scenario.
Forced labour and services
Forced labour can appear in agriculture, construction, hospitality, domestic work, manufacturing, logistics, care work and other sectors. The financial clue is not simply “low wages.” Low pay can be lawful or unlawful without trafficking. Stronger indicators arise when wage behaviour is combined with evidence of control: pay sent to accounts that workers do not control, immediate onward transfers to the same organiser, repeated deductions that leave workers with little usable income, recruitment debts, accommodation charges that appear excessive, shared contact details across unrelated employees, or business payroll patterns inconsistent with the apparent scale of operations.
FinCEN’s 2026 World Cup notice gives a current U.S. example: labour-trafficking indicators can include wages being withheld or moved from a victim’s account to a trafficker, together with minimal spending on essential needs because the trafficker controls the victim’s finances. That is useful typology information, but it is not a universal legal test. A bank in another country should use it as risk intelligence and map it to its own legal and reporting framework.
Sexual exploitation
Sex trafficking can produce financial footprints through cash, peer-to-peer transfers, card payments, digital assets, prepaid products, travel, accommodation, online advertising and other services. The bank should avoid treating sex-work-related activity as automatically indicative of trafficking. The critical issue is exploitation and control, not moral judgement about a customer’s lawful activity.
More useful indicators are patterns showing that one person or entity controls multiple individuals’ earnings, travel or accounts; repeated movement between locations under common funding; rapid transfer of incoming payments to a central beneficiary; or financial behaviour that aligns with verified intelligence about an organiser or venue. FinCEN’s 2026 U.S. notice also highlights cash deposits into accessible ATMs followed by transfers to another account and unusually intensive travel-related transactions as examples that may merit attention in the specific major-event context.
Domestic servitude
Domestic servitude may be difficult for financial institutions to detect because the victim may have little independent access to banking. The absence of transactions is therefore not itself proof. Potential indicators may instead appear when a person’s wages are paid to another individual, when an employer controls the worker’s account access, or when branch staff observe that the customer cannot communicate independently. Banks should be cautious about inventing household-spending profiles or inferring servitude from grocery purchases, family size or ethnicity. Those approaches are intrusive, weak and prone to bias.
Trafficking for removal of organs
FATF’s 2018 typologies include trafficking for organ removal, but this is a specialist and comparatively difficult area for a bank to identify. Medical travel, clinic payments or family transfers are not suspicious merely because they involve treatment abroad. A bank should escalate only where medical payments combine with credible intelligence, unusual third-party control, inconsistent purpose, suspicious intermediaries or other evidence. Technical questions about transplant legality, licensing or medical practice belong with competent authorities, not transaction-monitoring analysts making assumptions from merchant descriptions.
Forced criminality and cyber-enabled exploitation
Victims can be forced to commit crimes themselves. This matters increasingly in cyber-enabled scam operations and other organised-crime environments. A bank may therefore see apparently criminal transactions in an account whose holder is also being controlled. OSCE’s 2026 report on trafficking involving virtual assets discusses how trafficking and forced criminality can intersect with digital assets and scam-compound activity. The operational lesson is not that suspicious transactions should be ignored; it is that investigators should keep open the possibility that the account holder is being exploited by organisers.
That distinction changes the questions asked, the escalation path and the potential customer treatment. It can also improve network analysis by shifting attention from the visible account to the controller, recruiter, infrastructure and ultimate beneficiaries.
Coercion is usually inferred from a pattern, not a payment field
Banks rarely receive a field labelled “coercion.” Investigators instead look for evidence consistent with loss of control or exploitation, while remembering that the bank is not making the final legal finding.
One category is control of access. The same device, telephone number, email address or correspondence address may be used across several nominally independent customers. Another person may repeatedly conduct branch interactions or control authentication. These signals can also have innocent explanations such as family assistance or shared accommodation, so context matters.
A second category is control of value. Money credited to the possible victim may be rapidly transferred to one beneficiary, withdrawn under a repeatable pattern, or used almost entirely for the benefit of another person. Again, the pattern becomes stronger when it repeats across multiple people or is consistent with other evidence.
A third category is debt and deductions. Recruitment fees, transport costs, accommodation, penalties or other obligations may be used to create dependency. The bank should not attempt to decide whether a debt is legally enforceable from transaction data alone. It can, however, identify repeated transfers to recruiters or employers, unusually large deductions relative to income, or flows that suggest the customer cannot exercise meaningful control over their earnings.
A fourth category is movement and network coordination. Travel bought by a common organiser, multiple customers moving through the same locations, or clusters of payments around the same hotels, merchants or remittance recipients can strengthen an investigation when combined with other indicators.
The bank should not try to “prove” victimhood
A common control-design error is to create a field such as confirmedVictim=true based only on a monitoring score. That is too strong. Victim identification is a legal and safeguarding matter that can require specialist authorities, trained investigators and support organisations. The bank’s job is to record what it actually knows.
A better case model separates facts from assessment. Facts might include “three wage credits from Employer A were followed within 30 minutes by transfers to Beneficiary B,” “the same device is linked to four employees,” or “customer-facing staff recorded that another individual retained the customer’s identification.” Assessment can then state that the pattern is consistent with possible financial control and exploitation and requires escalation under the bank’s human-trafficking procedure.
This distinction is important for fairness, auditability and downstream use. Law enforcement, FIUs and safeguarding teams can rely on evidence more effectively when the bank has not overstated certainty. It also reduces the risk that a customer is labelled permanently on the basis of a weak inference.
Customer and business risk lifecycle
Human-trafficking risk can surface at several points in a banking relationship.
At onboarding, the bank may see a business with opaque ownership, implausible staffing information, unexplained recruiters or agents, or multiple individuals using shared contact details. These facts should be assessed in the normal CDD framework rather than converted into a trafficking accusation. For individuals, control by an accompanying person may justify a private interaction where policy and safety allow, but staff should not confront a suspected controller or conduct a detailed victim interview.
During ongoing monitoring, changes matter. A previously normal payroll account may start receiving wages from a new employer and immediately transferring most funds to a third party. A business may rapidly expand revenue without corresponding labour costs. A cluster of new accounts may share devices or beneficiaries. Event-driven review can connect these changes to updated KYC information or external intelligence.
At alert and case stage, investigators should widen the lens beyond the triggering transaction. Relevant history can include linked accounts, beneficiaries, devices, merchants, cash activity, remittances, employer relationships, previous fraud or AML alerts, law-enforcement requests and branch observations. The objective is to understand the network and determine the correct legal, financial-crime and safeguarding actions.
At relationship action stage, the bank may need to decide whether to maintain, restrict or exit accounts, block specific access, reset credentials, preserve funds, or continue monitoring. Those actions depend on local law, contractual rights, safety considerations and the evidence. A blanket “close every account connected to trafficking” rule can remove a victim’s only safe access to money and can destroy intelligence value.
Product and channel risk
Different banking products reveal different parts of the picture.
Retail accounts can show wages, remittances, cash deposits, peer-to-peer receipts and controller-benefit transfers. Business accounts can show payroll gaps, unusual cash intensity, recruitment or accommodation payments and movement of profits to owners. Merchant acquiring can expose payment flows linked to venues or online services, but merchant-category data is too coarse to establish trafficking by itself. Remittance services may reveal repeated transfers between recruiters, facilitators and controllers. Cards and prepaid products can show travel and hospitality activity. Digital assets can create an additional value-transfer layer, but blockchain analytics results must be treated as intelligence with documented attribution confidence, not as self-proving evidence.
The most effective detection therefore joins data across products where lawful and technically possible. Siloed scenarios can miss a network in which wages enter a deposit account, funds leave through peer-to-peer transfers, travel is paid on a card and proceeds move through a virtual-asset service provider.
Geography: use context, not stereotypes
Country and corridor information can be useful, but trafficking is not confined to “high-risk countries.” FATF emphasises that trafficking occurs domestically as well as across borders. Country risk should therefore be one contextual feature rather than the primary decision rule.
Good geographic analysis asks specific questions: Is the customer’s activity consistent with their stated employment and travel? Are counterparties linked to a known investigation or typology? Does a business recruit workers from particular locations through a common agent? Are transfers concentrated around venues or periods that match credible intelligence? Weak analysis simply assigns suspicion to nationality or migration status.
This distinction is essential for both effectiveness and fairness. Overbroad geographic rules generate false positives and can push vulnerable customers out of regulated finance while doing little to identify controllers.
Detection design: from indicators to scenarios
A trafficking scenario should combine several pieces of evidence rather than search for one magic threshold. A labour-trafficking scenario, for example, might look for payroll credits followed by rapid onward transfers to a common beneficiary across multiple employees, combined with shared contact or device data and unusual deductions. A business-front scenario might compare revenue patterns with payroll, counterparties, cash activity and ownership flows. A sexual-exploitation scenario might combine repeated travel, hospitality, peer-to-peer receipts and common-controller links where the institution has lawful access to those data.
Scenario design should include exclusions and innocent explanations. Family members may share devices. Migrant workers may remit most of their income home. Seasonal businesses may have unusual payroll cycles. Shared accommodation may produce common addresses. The purpose of monitoring is to identify cases for investigation, not to encode assumptions about vulnerable groups.
Detection should also be tested for false negatives. If the bank only looks at high-value payments, it may miss exploitation built around many low-value transfers. If it only looks at cash, it may miss digital channels. If it only looks at the victim account, it may miss the controller network.
Alert triage and case investigation
A trafficking alert should be triaged with two questions in parallel: What is the financial-crime risk? and Could a person be at risk of harm? The second question is what differentiates this typology from many ordinary AML alerts.
Investigators should build a chronology. Start with the trigger and work backwards and forwards through transactions, customer-profile changes, device events, beneficiaries, linked accounts and relevant interactions. Separate observed facts from hypotheses. Identify whether the activity is isolated or networked. Determine whether possible victims and possible controllers should be handled differently in the case-management system.
The investigation should also examine whether the bank has prior information elsewhere. Fraud teams may have reported account takeover or coercion concerns. Branch staff may have recorded unusual interactions. Another line of business may know the employer. A law-enforcement request may provide an external anchor. Cross-functional intelligence often turns a weak single signal into a coherent case.
Where the evidence remains ambiguous, the case should say so. “Possible exploitation indicators present; controller relationship unresolved” is more useful than an unsupported definitive label.
Reporting and referral are jurisdiction-specific
The legal reporting route depends on where the bank operates. FATF sets the global AML framework, but SAR/STR thresholds, urgency procedures, confidentiality, victim handling and law-enforcement referral differ by jurisdiction.
In the United States, FinCEN’s 2014 and 2020 advisories provide trafficking-specific indicators and SAR instructions. The 2014 advisory states that a potential victim should not be identified as the SAR subject; available victim information should instead be included in the narrative. FinCEN’s 2026 World Cup notice introduced the event-specific key term FIN-2026-HTWORLDCUP and urged vigilance around host-city activity. Those are U.S. filing instructions, not global rules.
In Canada, FINTRAC publishes trafficking indicators and in May 2026 issued a special bulletin on human-trafficking risks associated with major sporting and entertainment events. Canadian reporting entities must follow FINTRAC’s own suspicious transaction reporting rules and guidance.
In Australia, AUSTRAC requires reporting entities to monitor unusual transactions and behaviours as part of ongoing customer due diligence and to submit suspicious matter reports where the statutory test is met. Human trafficking is one of the serious-crime contexts relevant to that framework, but the exact reporting obligation is Australian law.
A global bank should therefore configure jurisdiction-aware case playbooks rather than one universal “human trafficking SAR” workflow.
Safeguarding and customer treatment
Where a possible victim is involved, account action should be designed with safety in mind. A controller may have access to the customer’s phone, credentials, statements or physical mail. Resetting access without a safe-contact plan can alert the controller. Closing an account can remove access to wages or emergency funds. Sending standard adverse-action messages can reveal that an investigation is under way.
The bank’s safeguarding procedure should therefore define who can approve contact, what communication channels are considered safe, when specialist teams or authorities must be involved, how urgent threats are handled, and how confidentiality and anti-tipping-off obligations interact with customer support. These decisions must be based on local law and policy.
Customer-facing staff should not be turned into trafficking investigators. Their role is to observe, record facts, preserve safety, avoid confrontation and escalate. Detailed interviews, victim-status determinations and rescue activity belong with trained specialists and competent authorities.
Data and system touchpoints
A mature control needs more than a monitoring rule. It needs data lineage and case-management design that preserve the evidence behind the decision.
Useful data can include customer identifiers, KYC profile, occupation, employer, beneficial ownership, account relationships, transactions, counterparty details, merchant information, cash locations, device and authentication events, contact details, address history, branch notes, fraud cases and relevant external intelligence. Each field should have a source, timestamp and reliability status. Derived relationships should be distinguishable from verified relationships.
Case systems should support role labels such as “possible victim,” “possible controller,” “linked employer” and “unknown relationship” without forcing premature certainty. They should allow investigators to record safeguarding restrictions on who can contact the customer, link related cases, preserve the chronology and capture which legal entity and jurisdiction owns the reporting decision.
Access control is especially important because trafficking cases can contain sensitive personal and safeguarding information. Teams that do not need that detail should not receive it automatically. Retention and sharing should follow applicable privacy, AML and law-enforcement rules.
Roles and governance
The first line owns customer relationships, operational observations and execution of approved account actions. Branch, contact-centre and operations staff need concise escalation guidance rather than a catalogue of criminal-law tests.
Financial-crime operations triage alerts, assemble evidence and identify linked activity. AML investigations decide whether the bank’s suspicion threshold is met and prepare the relevant report. Fraud teams contribute device, scam and account-control intelligence. Safeguarding or vulnerable-customer specialists, where present, advise on customer contact and harm reduction. Legal and compliance interpret jurisdiction-specific obligations. Data, model and technology teams maintain scenarios, lineage and case tooling. Quality assurance and internal audit test whether the control works as designed.
Governance should track more than alert volumes. Useful measures include the quality of referrals, network links identified, repeat missed indicators, timeliness of urgent escalations, control gaps and feedback from competent authorities where available. Banks should be cautious about claiming “victims rescued” as a performance metric unless they have reliable evidence; downstream outcomes usually belong to law enforcement and support services, not the bank alone.
Failure modes to avoid
The first failure is single-indicator thinking. A cash deposit, hotel payment, remittance or shared address is not proof of trafficking. Controls should combine signals and test innocent explanations.
The second is stereotyping. Nationality, occupation, migration status, sex-work-related activity or poverty should not become proxies for trafficking. Such rules create discrimination and poor detection.
The third is treating every suspicious account holder as a perpetrator. Possible victims can be forced to move money, receive proceeds or commit offences. The investigation should consider control and benefit, not only account ownership.
The fourth is overstating bank authority. Banks can detect and report; they do not replace law enforcement, immigration authorities, child-protection agencies or specialist support services.
The fifth is unsafe customer contact. A controller may monitor the customer’s device or communications. Contact rules therefore need safeguarding input.
The sixth is poor case data. If device links, employer relationships and transaction chronology cannot be reconstructed, the investigation becomes narrative guesswork.
The seventh is using outdated typologies as fixed rules. Payment methods evolve. FinCEN’s 2024 analysis of convertible virtual currency, OSCE’s 2026 work on virtual assets and trafficking, and the 2026 FinCEN/FINTRAC major-event guidance all show why typology libraries need periodic review.
What a Business Analyst should specify
A BA should start with the decision the control must support. Is the scenario intended to identify potential controller networks, possible victim financial control, suspicious business activity, or all three? The requirement should state the data needed, the relationship logic, how uncertainty is represented and which jurisdictional workflow follows an escalation.
Acceptance criteria should test both detection and harm. A scenario should identify a seeded network when payroll credits are swept to a common controller, but it should not escalate every legitimate remittance family. A case system should allow separate handling of possible victims and possible controllers. A contact restriction should prevent routine outbound messages where the safeguarding team has marked the channel unsafe. Reporting fields should map to the correct FIU for the legal entity handling the case.
Architects should make relationship evidence traceable. Developers should avoid hard-coded country or demographic assumptions. Testers should include positive, negative, boundary and degraded-data cases. Product owners should understand customer-impact consequences of false positives. Operations teams should have a clear urgent-escalation route when immediate harm is suspected.
Composite case study: payroll diversion becomes a network investigation
Consider a fictional bank with six retail customers who all recently began receiving weekly wage credits from the same labour contractor. Each customer has a different home address, but four accounts use the same mobile device identifier and five transfer between 70 and 90 percent of each wage to the same beneficiary within an hour of being paid. The beneficiary is the director of a small recruitment company that is not disclosed as the employer.
The first alert is generated by a rapid-funds-movement scenario. On its own, the alert looks like ordinary remittance behaviour. The analyst widens the review and finds the common beneficiary, shared device pattern and repeated deductions described as “accommodation.” Branch notes show that two customers attended with the same accompanying person, who answered most questions. The bank does not conclude that trafficking is proven. It records that the combined pattern is consistent with possible financial control and labour exploitation.
The case is escalated to AML investigations and the bank’s safeguarding specialist. The team checks whether the customers can be contacted safely and avoids sending a routine message that could expose the review. The investigator maps the recruitment company, employer, beneficiary and linked accounts and prepares the jurisdiction-appropriate suspicious activity report based on the available evidence. Any urgent threat or safeguarding referral follows local procedures.
The bank also reviews the business customer relationship with the labour contractor and recruitment company. It does not automatically close the six workers’ accounts. Instead, it considers controller access, essential-funds availability and legal obligations before any restriction.
The case teaches the central lesson of this chapter: trafficking detection is strongest when the bank moves from isolated transactions to relationships, from labels to evidence, and from standard AML processing to a combined financial-crime and safeguarding response.
Key takeaways
Human trafficking can generate financial indicators, but those indicators are rarely unique to trafficking. Detection should therefore combine customer context, transaction behaviour, network relationships and credible external intelligence.
The bank should distinguish a possible victim from a possible controller and avoid automatically treating account ownership as proof of culpability. Safeguarding, safe contact and access to essential funds can matter alongside AML reporting and account-risk decisions.
Global standards provide the framework, but reporting and referral are jurisdiction-specific. FinCEN, FINTRAC, AUSTRAC and other authorities each operate under their own legal regimes. A global bank needs local playbooks supported by common evidence standards.
Finally, the most useful investigation output is not a dramatic label. It is a defensible chronology showing what the bank observed, why the pattern is concerning, how people and accounts are linked, what uncertainty remains, what action was taken and which competent authority received the information.
Operational deep dive: financial control, network evidence and safe investigation
The base chapter established the central discipline: a bank should detect and investigate activity consistent with exploitation without pretending that a transaction-monitoring engine can determine criminal victim status. This deep dive develops the analytical methods that make a trafficking referral useful while keeping the bank inside its proper role.
Follow the controller, not only the visible account
A trafficking investigation often begins with the account that triggered an alert, but the strongest evidence may sit elsewhere. If a possible victim receives wages and immediately transfers most of them to another person, the relevant question is not simply whether the transfer is unusual. It is whether the beneficiary also receives similar transfers from other workers, controls shared devices or contact details, funds travel or accommodation, owns the employer or recruiter, or receives value through businesses linked to the same network.
This is where relationship analysis becomes important. A case graph can connect customers, employers, recruiters, beneficial owners, beneficiaries, devices, addresses, phone numbers, cards, merchants and external intelligence. Each relationship should be labelled by evidence quality. “Same verified beneficial owner” is different from “same IP address once,” and “named in a law-enforcement request” is different from “similar surname.” Mixing those relationship strengths produces confident-looking graphs that are analytically weak.
The objective is to identify patterns of control and benefit. A possible victim may generate the revenue, but a controller may receive the economic benefit. A business may employ the workers, while a separate recruitment company collects deductions. A payment service may move the funds, while a third party controls the credentials. The network view helps the investigator see that structure.
Financial control indicators
Financial control is one of the most useful concepts for bank investigators because it can be observed without requiring the bank to prove physical coercion. Examples include repeated wage diversion, common beneficiaries across unrelated workers, systematic deductions, shared account access, credential control or spending patterns showing that the nominal account holder has little practical use of their own funds.
These indicators still require caution. Families pool money. Workers use community remittance channels. Employers may lawfully deduct accommodation or other costs. Shared devices can reflect low-income households or workplace access. The investigator therefore asks whether the explanation is coherent with the whole profile and whether the pattern repeats across people.
The most persuasive bank evidence is usually longitudinal. One transfer can be innocent. Six months of wages credited on Friday and swept to the same organiser within minutes across ten workers is different. Repeated control patterns are more useful than isolated anomalies because they show structure rather than coincidence.
Debt bondage and recruitment fees
Debt can be used as a mechanism of control, especially where workers pay recruiters for travel, placement, documents, accommodation or other services. Banks should avoid claiming that any recruitment fee equals trafficking. The relevant financial question is whether debt-related payments combine with other indicators of dependency or exploitation.
An investigator can examine who receives the payments, how often they recur, whether several workers pay the same recruiter, whether deductions continue long after the stated debt should have been repaid, and whether the worker retains enough control over their income to meet normal needs. The bank should document the observed pattern rather than attempting to adjudicate employment or immigration law.
Where local authorities or credible external sources identify a recruiter, employer or intermediary as high risk, the financial history becomes more meaningful. Intelligence-led monitoring can then identify additional linked customers and counterparties, subject to local privacy and information-sharing rules.
Behavioural information belongs in the evidence stack
Branch and contact-centre observations can strengthen a case when recorded objectively. Useful observations describe behaviour, not conclusions: another person held the customer’s identity document; the accompanying person answered every question; the customer appeared unable to access their own phone; several unrelated customers were brought to the branch by the same person.
Poor notes say “customer looked trafficked” or make assumptions about nationality, dress, language or occupation. Those labels are subjective and hard to defend. Good case design gives staff structured fields for observable facts and a clear escalation route.
Customer-facing staff should not attempt to separate a customer physically from an accompanying person if doing so could create danger, nor should they conduct a detailed interview about exploitation. The bank’s procedure should tell staff when to seek a private conversation, when not to, and who owns urgent safeguarding escalation.
Virtual assets and technology-facilitated trafficking
Virtual assets can appear in trafficking-related financial flows, but they should be treated like any other channel: analyse the specific behaviour and evidence. FinCEN’s 2024 financial trend analysis described U.S. BSA reporting involving convertible virtual currency, online child sexual exploitation and human trafficking. OSCE’s 2026 report on trafficking investigations involving virtual assets also highlights the growing importance of digital payment and blockchain evidence, including scam-compound contexts in which victims may be forced to participate in fraud.
For a bank, the practical touchpoints include transfers to or from virtual-asset service providers, known wallet-attribution information received from trusted sources, unusual conversion patterns, and links to a broader trafficking or forced-criminality case. Blockchain analytics should have documented provenance and confidence. A vendor label is not proof that a customer controls a wallet or participated in a crime.
The same caution applies to online advertising, peer-to-peer payments and platform data. These can be useful context, but platform behaviour should not be converted into a trafficking conclusion without corroboration.
Possible victims who also appear to commit offences
Forced criminality creates one of the hardest judgement problems. A customer may receive fraudulent funds, operate accounts used by a scam network, or move criminal proceeds while being controlled by organisers. The bank still has AML and fraud obligations. It may need to restrict transactions, report suspicion or protect other customers. But the case should preserve the possibility that the visible account holder is not the organiser.
Benefit-flow analysis helps. Does the customer retain the proceeds, or are funds rapidly moved to others? Are the same controllers linked across multiple accounts? Is there evidence of recruitment, shared devices, restricted communications or externally reported coercion? A bank should record those facts and escalate them rather than deciding that “victim” and “offender” are mutually exclusive categories.
Evidence packages for FIUs and law enforcement
A useful trafficking referral is specific. It identifies the relevant customers and counterparties, explains how they are linked, gives a clear transaction chronology, describes the concerning indicators, distinguishes possible victims from possible controllers where evidence supports that distinction, and states what the bank does not know.
It should also explain why the activity is inconsistent with the expected profile. A list of transactions with no analytical narrative is less useful than a concise explanation showing the control pattern. Where the jurisdiction’s reporting format allows, the bank should include identifiers that help authorities connect the network across institutions.
The bank should follow local reporting instructions. U.S. FinCEN has trafficking-specific SAR guidance and key terms. Canadian reporting entities follow FINTRAC rules. Australian entities follow AUSTRAC suspicious matter reporting requirements. Other jurisdictions have their own FIUs and thresholds. The common principle is evidence quality, not a universal filing template.
Safe contact and account access
Where a case suggests that another person controls the customer’s device, telephone or mail, normal servicing can create risk. A password-reset message, fraud alert or closure notice may reach the controller. Systems therefore need a way to mark unsafe channels and route contact decisions to the appropriate specialist team.
That does not mean a bank should secretly maintain an account in all cases. Legal, sanctions, fraud, contractual and operational obligations may require action. The point is that the decision should consider safety as well as financial-crime risk.
A strong operating model separates three decisions: whether suspicious activity must be reported, what account action is appropriate, and what safeguarding action is appropriate. Those decisions can be related without being identical.
Quality assurance questions
Quality review should ask whether the investigator relied on one red flag, whether innocent explanations were tested, whether network links are evidence-based, whether possible victims were distinguished from possible controllers, whether customer contact was handled safely, whether jurisdiction-specific reporting rules were followed and whether the case narrative is factual rather than dramatic.
The best trafficking cases are not the ones with the most alarming language. They are the ones where another reviewer can reconstruct the evidence and understand exactly why the bank escalated.
Advanced practice: control design, public-private intelligence and survivor-aware banking
The base chapter and deep dive established how to recognise possible exploitation and build a defensible case. This supplement focuses on the difficult operating-model questions: how to convert typologies into maintainable controls, how to use external intelligence without turning it into a blacklist, how to protect vulnerable customers while meeting AML obligations, and how to keep the control current as payment methods and trafficking methods change.
From typology to monitoring logic
A typology report should not be copied directly into a transaction rule. FATF, FinCEN, FINTRAC and other authorities publish indicators to help institutions recognise patterns. Those indicators still need to be translated into the bank’s products, data and customer base.
Take wage diversion. A bank could design logic that looks for recurring payroll credits followed by rapid transfers to one beneficiary. That would generate many legitimate cases unless it also considers relationship structure, repeated behaviour across multiple workers, shared devices or addresses, the percentage of wages diverted, and whether the recipient is linked to an employer, recruiter or other known party. The rule should be calibrated against real customer behaviour and tested for both missed risk and over-escalation.
A second scenario could examine businesses with revenue growth that is not matched by payroll, suppliers or other operating costs. Again, this is not automatically trafficking. It can indicate outsourcing, owner-operated businesses, seasonal patterns or data-quality gaps. The purpose is to identify cases where the business story and financial activity deserve investigation.
The same principle applies to travel, cash, cards, peer-to-peer transfers and virtual assets. The scenario should be built around a hypothesis that can be tested, not a collection of sensational keywords.
Event-related risk without event panic
Major sporting and entertainment events illustrate how typology intelligence can become time-sensitive. FinCEN’s May 2026 notice and FINTRAC’s May 2026 special bulletin both addressed human-trafficking risks around major events. They highlighted short-term surges in hospitality, travel, labour and payment activity that can create both opportunities for exploitation and large volumes of legitimate transactions.
A good bank response does not suddenly flag every hotel payment near a stadium. It updates relevant typologies, briefs customer-facing staff, reviews known high-risk networks, adjusts case prioritisation where appropriate and ensures investigators understand the event context. Any temporary scenario change should have a documented start, rationale, calibration approach and exit date.
This is a useful model for other intelligence-led changes. Controls should be able to react to credible new information without becoming permanent emergency rules that continue generating noise long after the underlying event has passed.
Public-private information sharing
Trafficking investigations often improve when banks, FIUs, law enforcement and other financial institutions can share information lawfully. The legal basis differs by country. U.S. institutions, for example, may use Section 314(b) for qualifying information sharing under its rules; that mechanism is not a global safe harbour.
A global bank should maintain a jurisdiction map showing what can be shared, with whom, for what purpose and under which approval. The technology should support controlled export of case information rather than analysts copying sensitive data into email or informal channels.
External intelligence should also have provenance. A law-enforcement request, FIU feedback, verified court record and commercial adverse-media alert are not equivalent. Case systems should preserve the source and date so later reviewers understand why a link was considered material.
Protecting possible victims from financial exclusion
Possible victims can have damaged or unusual financial histories because another person controlled their accounts. A rigid de-risking model can therefore compound harm. The bank still has to manage fraud, AML and legal risk, but customer treatment should be proportionate to what is actually known.
Where policy and law allow, options can include credential reset, safe re-registration of devices, removal of unauthorised delegates, tighter transaction limits, enhanced monitoring or controlled continuation of essential banking while the case is assessed. These measures should never be improvised by an analyst. They need product, legal, fraud, safeguarding and operations design.
The reverse risk also matters: traffickers can exploit any special process intended to support vulnerable customers. Controls should therefore verify identity and authority carefully without making support inaccessible. The goal is neither automatic closure nor automatic retention; it is an evidence-based decision that considers the customer’s safety and the institution’s obligations.
Privacy and sensitive-data governance
Trafficking cases can contain highly sensitive information about exploitation, immigration, sexual activity, family relationships, health or law-enforcement involvement. More data does not automatically mean better detection.
Banks should apply purpose limitation, role-based access and retention controls. A monitoring team may need to know that a customer is linked to a safeguarding case without seeing every detail. A product team tuning a scenario may need anonymised outcome data rather than identifiable victim information. A data scientist should not use trafficking-case labels for unrelated credit or marketing models.
Derived attributes need particular care. A model-generated “possible controller” score should not silently propagate into unrelated systems. The data lineage should show where the assessment came from, when it was created and who is allowed to use it.
Model and analytics fairness
Trafficking typologies can easily become demographic proxies if they are poorly designed. Migrant workers may remit a high share of wages. Extended families may share devices and addresses. Certain industries may be cash intensive. Sex workers may use hotels, travel and peer-to-peer payments without being trafficked.
Fairness testing should therefore compare detection rates and false positives across relevant customer groups, but the objective is not to force identical alert rates. It is to identify whether the rule is using weak proxies where stronger behavioural evidence is available.
Analysts also need decision support that encourages contextual review. A screen that presents nationality in large red text while hiding relationship evidence three clicks away will bias decisions even if the underlying model is technically neutral.
Control-library governance
Each trafficking scenario should have a named owner, documented typology source, rationale, data inputs, known limitations, calibration history and review frequency. When an authority publishes new intelligence, the owner decides whether the scenario needs change. When a rule produces repeated false positives, the owner investigates the root cause rather than simply raising thresholds.
A periodic review should ask whether payment channels have changed. The growth of peer-to-peer payments, digital wallets, virtual assets and embedded payment services can move exploitation-related flows away from the data fields that older rules use. OSCE’s 2026 work on virtual assets and trafficking is a useful reminder that typology libraries must evolve with the financial ecosystem.
Retired scenarios should also be documented. Removing a rule without preserving the reason can cause the same weak control to be reintroduced years later.
Multi-line-of-business investigations
Human-trafficking cases can touch retail banking, business banking, cards, merchant acquiring, remittances, fraud, financial crime and vulnerable-customer teams at once. The operating model should allow one lead case to link evidence from those areas without duplicating investigations that reach contradictory conclusions.
Case ownership needs to be explicit. AML may own the suspicious-activity decision, fraud may own immediate payment protection, business banking may own customer due diligence, and safeguarding specialists may own safe-contact guidance. One team should coordinate the overall chronology so the institution does not contact the customer five times from five different functions.
This is also where service levels matter. A normal 30-day review queue is not appropriate if the case suggests immediate harm. Conversely, not every trafficking-related alert is an emergency. Triage should distinguish urgent safeguarding indicators from ordinary analytical priority.
Feedback from authorities and internal outcomes
Where FIUs or law enforcement provide feedback, the bank should capture it in a form that can improve controls without overfitting future cases to one investigation. Useful feedback may reveal new counterparties, explain why a pattern was valuable, or show that the suspected offence was different from the bank’s initial hypothesis.
Internal outcomes matter too. If a case repeatedly clears because shared devices are common in a customer segment, scenario design should learn from that. If investigations repeatedly discover the same controller only after manual network expansion, the bank may need better graph features or cross-customer linkage.
The control should therefore operate as a learning loop: intelligence informs scenarios; scenarios generate cases; investigations produce evidence; outcomes refine detection and procedures.
Survivor-informed design without tokenism
Banks can improve policies by consulting specialist organisations and, where appropriate and safely arranged, people with lived experience. That input can help teams understand why standard communications, account restrictions or branch interactions may create unexpected risks.
Such engagement should be professional, compensated where appropriate, voluntary and designed to avoid extracting traumatic detail for institutional benefit. Survivor input does not replace legal analysis or statistical testing, and one person’s experience should not be turned into a universal typology. Its value is to challenge assumptions and improve customer treatment.
Architecture pattern for trafficking controls
A robust architecture typically has five layers. The source layer captures customer, transaction, device, merchant, business and interaction data. The relationship layer resolves customers, employers, beneficiaries, devices and external intelligence into traceable links. The detection layer runs rules, scenarios or models. The case layer supports chronology, role hypotheses, safeguarding restrictions and jurisdiction-aware reporting. The feedback layer captures QA findings, authority feedback, confirmed control gaps and tuning decisions.
Architects should resist shortcuts that bypass those layers. A monitoring model that cannot show which transactions and relationships produced its score is difficult to investigate. A case system that cannot separate a possible victim from a possible controller encourages blunt treatment. A reporting workflow that does not know the legal entity and jurisdiction can send the right suspicion to the wrong FIU.
The design goal is not maximum automation. It is reliable evidence movement from signal to decision.
Practice close: delivery checklist, acceptance criteria and testing
This section turns the chapter into implementation artefacts. Human-trafficking controls fail when requirements are written as awareness statements instead of testable decisions. A BA should be able to show which data enters the control, how a case is created, how uncertainty is represented, who owns safeguarding, how the correct jurisdictional reporting path is selected and how customer harm is reduced when a possible victim is involved.
BA checklist before design sign-off
The requirement should define the control objective precisely. “Detect human trafficking” is too broad. Better objectives include identifying possible wage diversion across linked workers, detecting controller networks across retail accounts, identifying businesses whose payroll and revenue patterns are inconsistent, or surfacing cases where financial-control indicators require safeguarding review.
The requirement should name the data sources needed for that objective. These can include payroll descriptors, transaction timestamps, beneficiaries, device identifiers, customer contact data, employer relationships, business ownership, cash locations, card and merchant information, fraud events and branch observations. For each field, the team should know its source, latency, completeness and legal basis for use.
The requirement should explain relationship logic. If several customers are linked because they share a device or beneficiary, the case should show that evidence. It should not simply label them as a network. Confidence should be proportional to the strength of the relationship.
The requirement should define role hypotheses. Case tooling needs to distinguish possible victim, possible controller, employer, recruiter, facilitator, beneficiary and unknown relationship. These are analytical labels, not criminal findings.
The requirement should specify safe-contact controls. If a case team marks a telephone number, device or address as potentially controller-accessible, ordinary servicing messages should not continue automatically. The allowed actions and approvers should be defined by policy.
The requirement should map jurisdiction and legal entity. A global bank must know which FIU or reporting authority applies, what filing threshold is used, what urgent escalation exists and which information-sharing rules are available. U.S. FinCEN SAR instructions should not be hard-coded into Canadian, Australian, EU or other workflows.
Good acceptance criteria
A useful acceptance criterion describes an observable result. For example: when three or more unrelated customers receive recurring payroll credits from the same employer and transfer a high proportion of those credits to one common beneficiary within a configurable time window, and at least one additional relationship indicator is present, the system creates one linked investigation view showing the underlying transactions and relationship evidence.
Another criterion can test safeguarding: when an authorised safeguarding user marks a contact channel as unsafe, outbound case-generated messages to that channel are suppressed and the servicing team sees the approved alternative-contact instruction.
A reporting criterion can test jurisdiction: when the customer is booked in legal entity A and the suspicious activity is owned by that entity, the case workflow presents only the reporting form and mandatory fields configured for entity A’s FIU, while preserving cross-border linked evidence for the investigator.
Weak criteria say “system should detect trafficking,” “analyst should consider vulnerability,” or “case should be referred to authorities.” Those statements cannot be tested reliably.
Positive testing
Positive tests should use synthetic cases with known ground truth. One case can model six workers receiving wages from the same contractor, with four sharing a device and five transferring most wages to a common recruiter. Another can model a business whose reported staffing is inconsistent with payroll while linked employees transfer funds to a director. A third can model a forced-criminality case in which suspicious incoming payments are rapidly moved to an organiser, testing whether the case view allows the account holder to be treated as a possible victim rather than automatically as the network controller.
Each test should verify more than alert generation. It should confirm that the case contains the correct customers, transactions, relationships, data timestamps and evidence source; that role hypotheses are editable; and that safeguarding and reporting workflows can be invoked independently.
Negative and boundary testing
Negative tests are essential because many trafficking indicators resemble legitimate behaviour. Test family remittances, migrant workers sharing accommodation, seasonal employers, legitimate labour agencies, low-paid workers with lawful deductions, independent sex workers, students sharing devices and businesses that outsource payroll.
The expected result is not always “no alert.” Some cases may reasonably alert but should be cleared quickly because the system presents the innocent explanation and relevant evidence. What matters is that the control does not encode nationality, occupation or migration status as a substitute for behavioural evidence.
Boundary tests should vary proportions, time windows, number of linked customers and data completeness. If one customer lacks device data, the scenario should degrade predictably rather than silently treating missing data as low risk.
Data-quality testing
Data-quality failures can create both false positives and false negatives. Payroll descriptors may be inconsistent. Device identifiers may change after application upgrades. Beneficiary identifiers may differ across payment rails. Business ownership data may be stale.
Testing should therefore include duplicated customers, missing employer fields, delayed device feeds, beneficiary-name variation and account migrations. The case should show data-quality uncertainty rather than presenting a clean but false network picture.
A control that depends on five data feeds should have monitoring for those feeds. If one fails, the system should know which scenarios are affected and whether alerts require manual compensating review.
Investigation workflow testing
Investigators should be able to move from the alert to the underlying evidence without exporting data to spreadsheets. Test the chronology view, linked-account view, customer profile, prior alerts, branch notes, fraud cases and external-intelligence fields.
The system should allow facts and hypotheses to be recorded separately. It should be possible to state, “same device observed on four accounts” as a fact and “possible common controller” as an assessment. This distinction is important for audit and for later authority requests.
Case linking should also be tested. If a second alert arrives on the business customer while the retail worker case is open, the investigator should be able to associate it without creating a contradictory duplicate investigation.
Reporting and referral testing
Use test cases for each supported jurisdiction. Confirm that mandatory fields, key terms, filing notes and victim-handling instructions are correct for that jurisdiction and current version of guidance. In the U.S. test pack, for example, FinCEN-specific human-trafficking SAR handling can be validated. That same logic should not appear in a non-U.S. filing unless local rules independently require it.
Test urgent escalation separately from ordinary STR/SAR filing. A possible immediate threat may require a different operational path under local procedure. The system should not assume that filing a report completes the safeguarding response.
Customer-impact testing
Customer-impact testing should simulate account restrictions, credential resets, device changes and communications. Confirm that a possible victim can retain access to essential funds where policy permits, that a possible controller does not receive confidential case information, and that routine notices do not bypass a safe-contact instruction.
This testing should involve operations and customer-support teams, not only financial-crime technology. A technically correct control can still create harm if the servicing process sends the wrong message or removes access at the wrong moment.
Quality assurance and calibration
QA should review whether investigators considered innocent explanations, separated facts from hypotheses, used relationship evidence correctly, applied the right jurisdictional rules and documented account-action reasoning. Calibration sessions should include ambiguous cases, not only obvious trafficking examples.
Teams should track recurring misses. If reviewers consistently overlook common-beneficiary networks, training or tooling may need improvement. If one scenario overwhelms the queue with legitimate shared-device cases, tuning is required. If cases are technically strong but safeguarding steps are missed, workflow design is the problem.
The aim of testing is not to prove that the bank can label trafficking. It is to prove that the bank can identify concerning patterns, investigate them fairly, protect sensitive customers, report through the right legal route and preserve evidence for competent authorities.
Masterclass: the labour contractor network hidden behind ordinary payroll
This is a fictional composite case built from recurring patterns described in public trafficking typologies. It is not a description of a real prosecution, bank customer or enforcement outcome. The purpose is to show how a bank can move from a weak payroll anomaly to a defensible network referral without turning suspicion into certainty.
Stage 1: an ordinary alert
A retail monitoring scenario identifies four recently opened accounts receiving weekly salary payments from the same labour contractor. Each account receives a similar amount on Friday afternoon. Within two hours, between 65 and 85 percent of each payment is transferred to one personal account at the same bank.
On its own, the pattern has several innocent explanations. The beneficiary could be a family member, a landlord, a community treasurer or a remittance intermediary. The alert is therefore not labelled “human trafficking.” It is assigned for contextual review.
The analyst compares KYC data. The four customers are unrelated by declared family relationship. Three list different home addresses; one lists accommodation provided by the employer. The common beneficiary is a director of a separate recruitment company. Two customers share the same mobile-device identifier, and branch notes show that three were accompanied at account opening by the same person.
The analyst now has a stronger hypothesis: the accounts may be subject to common financial control. That is still not proof of trafficking.
Stage 2: widen the network
The investigator searches internal relationship data and finds eight additional workers receiving wages from the same contractor. Six send repeated payments to the same recruitment-company director. Several use the same two ATMs shortly after payday. Four have recurring transfers described as accommodation, transport or recruitment costs.
The business-banking team holds an account for the labour contractor. The contractor’s payroll file shows more employees than were disclosed in the most recent KYC review. Its revenue has increased sharply over six months, while payroll costs have not increased proportionately. A second business account belonging to the recruitment company receives transfers from workers and then sends funds to the director’s personal account.
The investigation now has two connected views: the worker side and the business side. The controller hypothesis is stronger because the possible economic beneficiary appears across both.
Stage 3: separate facts from inference
The case file records observed facts first:
- recurring payroll credits from one contractor;
- rapid onward transfers from multiple workers to one beneficiary;
- repeated recruitment and accommodation deductions;
- shared device and branch-accompaniment patterns;
- beneficial-ownership links between the beneficiary and recruitment company;
- business revenue and payroll patterns that require explanation.
The assessment then states that these facts are consistent with possible labour exploitation and financial control. It does not state that the workers are confirmed trafficking victims or that the director is a trafficker. Those are conclusions for competent authorities based on a wider evidence set.
This distinction makes the referral more credible. An FIU or law-enforcement investigator can see what the bank observed and decide how it fits other intelligence.
Stage 4: safeguarding before routine contact
The retail team would normally contact customers to understand unusual transfers. In this case, the safeguarding specialist advises against routine calls until the safe-contact question is assessed because the same devices and accompanying person may be controlled by another party.
The bank does not attempt to organise a rescue or interview the workers about exploitation. Customer-facing teams are told not to confront the accompanying person. If any immediate-danger indicator emerges, the case follows the bank’s local urgent-safeguarding procedure.
This is where a well-designed case system matters. The investigators can mark specific contact channels as potentially unsafe without freezing the entire relationship or exposing the case to unrelated servicing staff.
Stage 5: reporting and account action
The AML investigator determines whether the applicable jurisdiction’s suspicion threshold is met. The report explains the transaction pattern, related customers, business relationships, shared identifiers and why the behaviour is inconsistent with expected activity. It distinguishes possible workers from possible controllers and preserves uncertainty.
The bank separately assesses account action. It considers whether controller access can be reduced, whether essential funds need to remain available, whether the recruitment company or contractor relationships require enhanced due diligence, and whether any fraud, sanctions or other legal obligations affect the decision.
The bank does not assume that filing a report requires immediate closure of every linked worker account. Nor does it assume that possible victim status means all transactions should continue. Reporting, customer treatment and safeguarding are related but distinct decisions.
Stage 6: feedback changes the control
Suppose the bank later receives lawful feedback that the recruitment company is relevant to a wider investigation. The monitoring team can then review whether other customers or businesses are connected through the same beneficiaries, devices or payment patterns.
The control owner also asks what the original scenario missed. The initial alert only triggered because of rapid onward movement. The broader network became visible through device, KYC and business-account data. That insight can support a new relationship-based scenario, provided it is tested against legitimate shared-device and remittance behaviour.
What would have gone wrong with a weaker process
A weak process might have closed the first four worker accounts as mule accounts. That could have removed useful intelligence, harmed possible victims and left the contractor and recruitment company untouched.
Another weak process might have treated the shared device as proof of control. Shared devices are common in many legitimate settings, so the case would have been built on an unreliable assumption.
A third weak process might have contacted the customers using a phone or email controlled by the organiser. That could have created safety risk.
A fourth weak process might have filed a generic suspicious-activity report listing transfers but not explaining the network. The FIU would receive data without the analytical connections that make it useful.
The teaching point
The strongest bank contribution is not a dramatic trafficking label. It is a well-evidenced network picture that connects money movement, customer context, account control and business relationships; protects possible victims from avoidable harm; and routes suspicion through the correct jurisdictional process.
That approach is consistent with the broader message in FATF, FinCEN, FINTRAC and other public typologies: combine indicators, understand the customer and network, and use financial intelligence to support competent authorities.
Knowledge check and glossary
Use these questions to test whether the chapter’s distinctions are clear enough to apply in a real bank.
Does one trafficking red flag prove trafficking? No. Public guidance from FATF and FinCEN repeatedly treats indicators as pieces of a wider pattern. A hotel payment, cash deposit, shared address, wage deduction or remittance can be legitimate. The investigator should combine customer context, transaction behaviour, relationships and credible external information.
What is the simplest difference between trafficking and migrant smuggling? Trafficking centres on exploitation and can occur without crossing a border. Smuggling generally concerns facilitation of irregular border entry for financial or material benefit. A smuggling situation can later become trafficking if exploitation and coercive control emerge.
What three elements are commonly used to explain adult trafficking under the UN Protocol? Act, means and purpose: an act such as recruitment or harbouring, prohibited means such as coercion or deception, and an exploitative purpose. For children, the Protocol does not require proof of the means element.
Why should a bank avoid labelling an account holder a confirmed victim or trafficker from monitoring data alone? Because banking data usually shows financial behaviour, not the full legal and factual picture. The bank can document evidence consistent with exploitation or control and refer it. Competent authorities determine criminal liability and formal victim status under applicable law.
What makes wage diversion more concerning? Repetition, common beneficiaries across unrelated workers, rapid movement after payroll, shared access indicators, unexplained deductions, links to recruiters or employers and a pattern in which the nominal account holder appears to retain little control over income.
Why is a shared device weak evidence on its own? Families, workers, students and people in shared accommodation can legitimately use the same device or network. Device evidence becomes stronger when combined with common beneficiaries, account-opening behaviour, controller access or other relationships.
How can a business account contribute to a trafficking investigation? It can show payroll levels, cash intensity, owner withdrawals, recruiter payments, accommodation flows, business counterparties and revenue patterns. Comparing the business side with worker accounts can reveal a network that retail monitoring alone misses.
Should sex-work-related transactions automatically be treated as trafficking? No. The relevant issue is exploitation and control. Monitoring should avoid moral judgement and look for evidence such as common controllers, diverted proceeds, coordinated movement or credible external intelligence.
How should virtual-asset information be used? As one part of the evidence stack. Transfers to a virtual-asset service provider or blockchain-analytics labels can be relevant, but wallet attribution and risk labels need provenance and confidence. They should not be treated as self-proving evidence.
Why is forced criminality important? A person can appear to be participating in fraud or moving criminal proceeds while also being controlled by organisers. The bank still manages the suspicious activity, but the investigation should examine who benefits and who controls the account rather than assuming the visible account holder is the organiser.
What should customer-facing staff do if another person appears to control the interaction? Record observable facts, avoid confrontation, follow the bank’s safeguarding procedure and escalate. They should not conduct a detailed trafficking interview or make promises about law-enforcement outcomes.
When is customer contact potentially unsafe? When there is reason to believe a controller monitors the customer’s phone, email, device, mail or physical movements. Safe-contact decisions should follow local policy and involve the appropriate safeguarding or legal team.
Does filing an SAR or STR automatically determine account closure? No. Reporting, account action and safeguarding are separate decisions that can interact but have different legal and operational considerations.
Are FinCEN’s human-trafficking SAR key terms global requirements? No. They are U.S. FinCEN instructions. Other jurisdictions use their own FIU rules and reporting formats.
Why should trafficking controls use network analysis? Because exploitation often involves several people and entities: workers, employers, recruiters, controllers, businesses, devices and beneficiaries. Network analysis can expose common control that single-account review misses.
What makes a good referral narrative? A clear chronology, specific transactions, linked parties, evidence sources, explanation of why the pattern is inconsistent with expected activity, distinction between possible victims and possible controllers where supported, and an honest statement of uncertainty.
What should QA test? Whether the investigator used multiple indicators, considered innocent explanations, handled relationship evidence correctly, followed safe-contact rules, selected the right jurisdictional reporting process and documented account-action reasoning.
Glossary for delivery teams
Trafficking in persons: the UN Protocol concept covering recruitment, transportation, transfer, harbouring or receipt of persons through specified means for exploitation. For child trafficking, the means element is not required.
Possible victim: an internal analytical label indicating that evidence may be consistent with exploitation. It should not be treated as a formal legal determination unless the bank has a defined authoritative source for that status.
Possible controller: a person or entity that may exercise financial or other control over a possible victim. The label is a hypothesis supported by evidence, not a criminal finding.
Financial control: behaviour suggesting that the nominal account holder does not exercise normal independent control over funds or access. Examples can include repeated wage diversion, common beneficiaries, credential control or systematic deductions.
Controller benefit: value flowing to a person or entity that appears to benefit economically from another person’s activity. It is useful evidence when repeated across a network.
Debt-bondage indicator: financial evidence that recruitment fees, accommodation, transport or other obligations may be used as a mechanism of dependency or control. The bank should describe the flows and context rather than determine legality from payment data alone.
Relationship evidence: verified or inferred links between customers, accounts, businesses, devices, addresses, beneficiaries or external intelligence. Relationship strength should be visible to investigators.
Safe contact: customer communication designed to avoid exposing the customer or the investigation to a person who may control their device, telephone, mail or movements.
Safeguarding escalation: the bank’s internal route for cases involving potential risk of harm to a customer or another person. Its exact design depends on jurisdiction and institution.
Forced criminality: exploitation in which a person is compelled to commit criminal activity. From a banking perspective, it means apparent offender behaviour may coexist with victimisation.
Typology: a recurring method or pattern of criminal behaviour used to improve detection and investigation. A typology is not a legal presumption.
Network view: a case representation connecting people, accounts, businesses, devices, transactions and intelligence so investigators can assess common control and benefit.
FIU: Financial Intelligence Unit, the national body that receives and analyses suspicious transaction or activity reports under the jurisdiction’s legal framework.
SAR/STR: Suspicious Activity Report or Suspicious Transaction Report. Terminology, thresholds, fields and filing obligations vary by jurisdiction.
Provenance: the documented source and reliability of data or intelligence used in a case. Provenance is essential for external data, blockchain labels and relationship assertions.
Composite case: a fictional educational scenario assembled from recurring public typologies. It should never be presented as a real enforcement or customer case.
References and further reading
The sources below were used to review the chapter. Global standards and typologies are separated from jurisdiction-specific reporting guidance so local obligations are not presented as universal rules.
Global legal framework and typologies
- United Nations Office on Drugs and Crime, Protocol against Trafficking in Persons: international legal framework and definition: https://www.unodc.org/e4j/en/tip-and-som/module-6/key-issues/international-legal-framework.html
- United Nations Office on Drugs and Crime, The crime of trafficking in persons: https://sherloc.unodc.org/cld/en/education/tertiary/tip-and-som/module-6/key-issues/crime-of-trafficking-in-persons.html
- Financial Action Task Force and Asia/Pacific Group, Financial Flows from Human Trafficking: https://www.fatf-gafi.org/content/dam/fatf-gafi/reports/Human-Trafficking-2018.pdf
- Financial Action Task Force, FATF Recommendations: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- Organization for Security and Co-operation in Europe, Following the Money 2.0: A Collaborative Approach to Human Trafficking Investigations Involving Virtual Assets: https://cthb.osce.org/cthb/662782
- Organization for Security and Co-operation in Europe, Financial investigations resources on trafficking in human beings: https://cthb.osce.org/cthb/financial-investigations
- International Labour Organization, Forced labour: https://www.ilo.org/topics/forced-labour-modern-slavery-and-trafficking-persons
United States guidance
- Financial Crimes Enforcement Network, FIN-2014-A008: Guidance on Recognizing Activity that May be Associated with Human Smuggling and Human Trafficking — Financial Red Flags: https://www.fincen.gov/resources/advisories/fincen-advisory-fin-2014-a008
- Financial Crimes Enforcement Network, FIN-2020-A008: Supplemental Advisory on Identifying and Reporting Human Trafficking and Related Activity: https://www.fincen.gov/resources/advisories/fincen-advisory-fin-2020-a008
- Financial Crimes Enforcement Network, Financial Trend Analysis on convertible virtual currency, online child sexual exploitation and human trafficking: https://www.fincen.gov/news/news-releases/fincen-sees-increase-bsa-reporting-involving-use-convertible-virtual-currency
- Financial Crimes Enforcement Network, FIN-2026-NTC1: Notice on the Threat of Human Trafficking During the 2026 FIFA World Cup: https://www.fincen.gov/system/files/2026-05/FinCEN-WCHT-Notice.pdf
- Financial Crimes Enforcement Network, SAR Advisory Key Terms: https://www.fincen.gov/resources/suspicious-activity-report-sar-advisory-key-terms
Canada
- Financial Transactions and Reports Analysis Centre of Canada, Special Bulletin on human trafficking risks associated with major international sporting and entertainment events, FINTRAC-2026-SB003: https://fintrac-canafe.canada.ca/intel/bulletins/sport-eng
- Financial Transactions and Reports Analysis Centre of Canada, Indicators: The laundering of illicit proceeds from human trafficking for sexual exploitation: https://fintrac-canafe.canada.ca/intel/operation/oai-hts-eng
- Financial Transactions and Reports Analysis Centre of Canada, Reporting suspicious transactions to FINTRAC: https://fintrac-canafe.canada.ca/guidance-directives/transaction-operation/str-dod/str-dod-eng
Australia
- Australian Transaction Reports and Analysis Centre, What you must monitor for as part of ongoing customer due diligence: https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/customer-due-diligence/ongoing-customer-due-diligence/what-you-must-monitor
Banking-industry practice
- Wolfsberg Group, Endorsement for United States Banks Alliance Toolkit for Tackling Human Trafficking: https://wolfsberg-group.org/news/endorsement-for-united-states-banks-alliance-toolkit-for-tackling-human-trafficking
These materials are educational reference points. Filing thresholds, confidentiality rules, victim handling, emergency referral routes and information-sharing permissions must always be checked against the law, regulator/FIU guidance and internal policy applicable to the specific bank entity and jurisdiction.