Money Laundering Stages in Bank Operations
How the classic placement, layering and integration model helps bank practitioners understand laundering — and why real cases often do not follow a neat three-step sequence.
Why this chapter matters
The three-stage model of money laundering — placement, layering and integration — is one of the most widely taught ideas in AML. It is useful because it gives learners a simple way to think about how criminal value can enter, move through and eventually reappear in apparently legitimate economic activity.
But the model can also be misused. Real laundering does not always begin with cash. Criminal proceeds may be created directly inside digital channels through fraud, cybercrime or corruption. Layering can happen within minutes through several bank accounts, payment institutions, virtual assets or trade structures. Integration may never look like a final clean investment. Criminal funds can remain mixed with legitimate business activity for years.
For bank practitioners, the important question is therefore not “Which stage is this transaction?” The better question is: what is happening to the value, what information does the bank have, what control should operate at this point, and what evidence would help an investigator understand the wider pattern?
The classic model
Placement traditionally describes the introduction of criminal proceeds into the financial system. The classic example is physical cash generated by crime being deposited, exchanged or used to purchase financial instruments.
Layering describes transactions or structures intended to make the source, ownership, movement or control of criminal proceeds harder to understand. Funds may move through multiple accounts, companies, jurisdictions, currencies or assets.
Integration describes criminal value returning to the economy in a form that appears legitimate, for example through property, business investment, loans, securities or apparently normal income.
The model is easy to teach because it creates a narrative. But a bank should use it as a conceptual tool, not as a rule that every case must fit.
Placement in modern banking
Placement is most obvious when illicit cash enters an account, but the concept is broader.
Criminal proceeds can enter banking through deposits, cash-intensive businesses, money service businesses, prepaid products, payment institutions, merchant activity, third-party transfers or the proceeds of fraud.
In cyber-enabled fraud, there may be no physical placement at all. The proceeds may already exist as legitimate bank money in the victim's account before being transferred to a mule account. The moment the fraud proceeds arrive, the receiving institution is already handling criminal value.
This matters because an AML programme focused only on cash placement can miss modern digital laundering.
Cash placement
Cash remains important in many typologies.
A criminal may break a large amount into smaller deposits, use multiple branches or accounts, mix illicit cash with legitimate cash business revenue, purchase monetary instruments or use third parties to deposit funds.
Banks look for context rather than one threshold. Repeated deposits just below a reporting threshold can be relevant, but the bank should not assume every sub-threshold transaction is structuring. The wider behaviour, customer profile, business model and jurisdiction matter.
A cash-intensive restaurant, convenience store or transport business can legitimately deposit significant cash. The control question is whether the volume and pattern are plausible for the known business.
Placement through mule accounts
Mule accounts are one of the most important modern entry points for criminal proceeds.
Victims of scams or fraud may send funds to accounts controlled by criminals, recruited money mules or people who do not fully understand the activity. The receiving account may then move funds rapidly to other accounts, cash, virtual assets or overseas beneficiaries.
The receiving bank can therefore see the earliest laundering stage even if it never sees the original deception.
Fraud and AML teams should share relevant intelligence because the fraud event and the laundering event can be different sides of the same payment.
Layering
Layering is often described as complexity for the purpose of obscuring origin or ownership.
Examples can include rapid transfers between accounts, movement through shell companies, cross-border payments, currency conversion, securities purchases, virtual-asset conversion, trade transactions, loans between related entities or transfers through several payment service providers.
But complexity alone is not suspicious. Multinational companies, treasury centres and investment firms can have highly complex legitimate flows. The bank needs to understand whether there is an economic rationale.
The strongest layering analysis asks whether each step adds legitimate business purpose or merely adds distance between the value and its source.
Rapid layering in instant payments
Instant payments compress the timeline dramatically.
Fraud proceeds can enter a mule account and be split across several beneficiaries within minutes. Funds can then move again before a manual investigator could review the first alert.
This creates a need for real-time or near-real-time controls, beneficiary intelligence, network analytics, velocity monitoring and post-transaction investigation.
The classic image of criminals patiently moving money through layers over weeks is no longer sufficient.
Cross-border layering
Cross-border payments can make investigation harder because several institutions and jurisdictions may hold different pieces of the story.
A payment may pass through correspondent banks, intermediary institutions or payment service providers. Each participant sees only part of the chain.
Payment transparency therefore matters. Originator, beneficiary, account, agent and purpose information should be preserved accurately enough for screening and investigation.
ISO 20022 can carry richer structured information, but the control benefit depends on the data actually being populated, transported and retained.
Corporate layering
Companies can be used to create distance between criminal proceeds and the individuals who benefit.
A chain of legal entities, nominees, trusts or related parties can make ownership difficult to understand. Payments may be labelled as consulting fees, loans, dividends, royalties or trade invoices.
The bank should not treat complex ownership as criminal by itself. It should understand who ultimately owns or controls the entities and whether the transactions make economic sense.
Beneficial ownership, related-party analysis and source-of-funds evidence can be central.
Trade-based layering
Trade can provide both legitimate commercial explanation and complexity.
Value can be transferred through over-invoicing, under-invoicing, multiple invoicing, misdescription of goods, phantom shipments or other manipulation. Payments can appear commercially justified unless the bank understands the goods, counterparties, route and pricing.
Trade-finance controls therefore combine customer knowledge, document review, sanctions and proliferation checks, vessel or port information where relevant, and transaction monitoring.
Virtual assets and asset conversion
Criminal value can move between fiat currency and virtual assets or between different virtual assets.
The presence of a crypto exchange does not automatically make a transaction suspicious. The relevant questions include the customer's profile, purpose, counterparties, velocity, source of funds and known risk indicators.
The broader lesson is that laundering can involve repeated conversion between forms of value. Investigators should follow the economic value rather than stop at one asset type.
Integration
Integration describes the point at which criminal proceeds are used or held in ways that appear legitimate.
Examples can include property, luxury goods, business investment, securities, loans, dividends, salaries or apparently normal company revenue.
A bank may see integration through mortgage repayment, large investment portfolios, unexplained business capital, property-related transfers or loan structures.
The challenge is that integration often looks more ordinary than placement or layering. The value may have passed through several steps before reaching the bank.
Integration through business activity
A criminal can invest proceeds into a legitimate or partly legitimate business.
The business may then generate real revenue alongside illicit funds. Over time, the distinction becomes harder to see.
This is why source-of-wealth analysis matters for some high-risk relationships. A customer's current assets may look legitimate even though the path by which the wealth accumulated is unclear.
Integration through property
Property can store significant value and can involve companies, trusts, lawyers, agents, lenders and cross-border funding.
A bank may see deposits, mortgage repayments, transfers to lawyers, property-sale proceeds or refinancing.
The key question is whether the source and movement of funds are consistent with the customer's known wealth and activity.
Commingling breaks the neat model
One of the most important real-world concepts is commingling.
Illicit and legitimate funds can be mixed in the same account or business. A restaurant can have real customers and still be used to introduce criminal cash. A company can perform genuine consulting work and also receive corrupt payments. A payment business can process thousands of legitimate transactions while a small subset relates to fraud or laundering.
This means the bank should not classify an account as entirely “clean” or entirely “criminal” based only on one transaction.
Investigators need to isolate the suspicious activity and understand the wider economic context.
Self-laundering and third-party laundering
The person committing the predicate offence may launder their own proceeds, or another person or professional intermediary may assist.
Third-party laundering can involve money mules, professional money launderers, accountants, lawyers, corporate-service providers, money service businesses or other intermediaries.
Banks need to understand not just the customer but the network around the customer.
Circular movement
Funds sometimes move through several entities and return to a party connected to the starting point.
Circular flows can create the appearance of trade, investment or loan activity while ultimately returning value to the original controller.
Network analysis is useful because the suspicious feature may only become visible when several transactions are viewed together.
Loan-back schemes
Criminal proceeds can be placed under the control of an offshore company and later returned as an apparently legitimate loan.
The transaction may appear to create a lawful source of funds unless the bank understands ownership and the relationship between lender and borrower.
The key question is whether the lender is genuinely independent and whether the loan has economic substance.
The bank-control lifecycle
Different controls see different parts of laundering.
CDD and KYB establish identity, ownership, business purpose and expected activity.
Sanctions screening addresses legal restrictions on relevant parties and activity.
Fraud controls can identify the predicate offence or mule behaviour at the point of payment.
Transaction monitoring looks for patterns over time.
Case management brings the evidence together.
Suspicious reporting allows the bank to provide relevant information to the FIU where the legal threshold is met.
No single control “detects money laundering” in isolation.
Payment initiation
At initiation, the bank can assess who is instructing the payment, whether the user is authorised, whether the beneficiary is new, whether the payment fits expected behaviour and whether screening or fraud controls raise concerns.
The control window may be very short for instant payments.
For corporate files, the bank may also need to understand batch structure, authorised signers and file-level versus transaction-level controls.
Payment processing
During processing, the bank may perform sanctions screening, fraud scoring, account restrictions, limits and routing controls.
Repairs are important because a manually changed name, account, address or purpose can alter the risk profile. Original and amended values should be retained and relevant controls rerun when screened fields change.
Post-transaction monitoring
Many laundering patterns only become visible after several transactions.
Monitoring can identify rapid movement, structuring, pass-through accounts, unexpected countries, peer-group anomalies, funnel behaviour, circular flows or unusual changes from the expected customer profile.
The monitoring design should connect to known typologies but remain capable of identifying unexpected behaviour.
Investigation
An investigator should reconstruct the movement of value and the relationship between parties.
Useful evidence can include KYC, beneficial ownership, source of funds, payment history, transaction references, device information, fraud intelligence, previous alerts, related accounts and external information.
The narrative should distinguish observed facts from inference.
“Customer received eight unrelated credits and transferred 95% within two hours” is a fact. “Customer is laundering fraud proceeds” is a conclusion that may require additional evidence.
Suspicious reporting
Banks generally do not need to prove every stage of laundering or identify the exact predicate offence before reporting suspicion, subject to local law.
A strong report explains the activity, parties, transactions, context and reason for concern.
It should not force the narrative into the three-stage model if that model does not fit the facts.
Scenario: fraud proceeds through instant payments
A customer who previously used an account for salary receives twelve instant payments from unrelated people. Within minutes, the funds are split between three new beneficiaries and a virtual-asset service provider.
The original predicate offence may be outside the receiving bank's view. But the bank can see possible entry of criminal proceeds, rapid layering and asset conversion.
The investigation should consider victim reports, account history, device changes, beneficiary networks and links to other customers.
Scenario: cash-intensive business
A restaurant deposits large cash amounts consistent with its declared business. Over time, deposits increase by 250% while card turnover remains flat and local footfall has not changed.
The fact that the business is cash intensive does not make the deposits suspicious automatically. The change from expected activity is what requires explanation.
The bank may review sales evidence, tax filings where lawfully available, source of cash, business expansion and related accounts.
Scenario: corporate layering
A newly established trading company receives large payments from unrelated overseas entities and sends most of the funds to companies with shared directors in other countries.
Invoices are generic and goods do not appear to move through expected routes.
The bank should examine beneficial ownership, commercial rationale, trade documentation, counterparties, payment purpose and whether value is moving through a controlled network.
Scenario: integration through property
A customer with modest declared income makes a large property purchase through a company funded by an overseas “loan.” The lender is another company ultimately owned by a close associate of the customer.
The bank should understand the ownership chain, source of the lender's funds, loan terms and economic rationale.
The property purchase itself may be legitimate; the concern lies in whether the funding chain disguises criminal value.
Why the three-stage model can create false confidence
The main weakness of the three-stage model is that learners sometimes expect laundering to be sequential and obvious.
Modern criminal finance can skip stages, repeat stages or combine them. Fraud proceeds can be created directly in the banking system. Layering can happen before the bank sees the funds. Integration can occur gradually through a business.
The practical lesson is therefore to follow the value, the parties and the economic purpose rather than chase a textbook sequence.
BA and architecture view
A system designed around laundering risk should preserve identity, ownership, transaction lineage and decision evidence.
The investigator should be able to move from a monitoring case to the original transaction, from the transaction to the customer and related parties, and from those parties to connected accounts and beneficial owners.
Payment identifiers, timestamps, original message data and repaired values should be retained.
The data model should support many-to-many relationships because one customer can have many accounts and one network can involve many customers.
Testing financial-crime controls
Testing should use realistic scenarios rather than isolated field checks.
A test might simulate several inbound payments to a new account, rapid splitting, a changed beneficiary and a cross-border transfer. The objective is to confirm that each control receives the correct data and that the case can reconstruct the full chain.
The test should also check false-positive behaviour. Legitimate treasury or payment-business flows can resemble layering, so controls need segmentation and context.
Common mistakes
One mistake is assuming placement always means cash.
Another is assuming every laundering case has three sequential stages.
A third is equating complexity with criminality.
A fourth is separating fraud and AML intelligence.
A fifth is losing transaction lineage during payment processing or repair.
A sixth is forcing every suspicious report into a textbook typology.
Takeaway
Placement, layering and integration remain useful teaching concepts, but they are not a mandatory workflow for criminals.
Modern banking sees laundering as movement and transformation of value across customers, accounts, payments, companies, countries and assets. The bank's job is to understand the customer, preserve transaction evidence, identify meaningful patterns, investigate inconsistencies and report or restrict activity when the applicable legal and policy threshold is met.
Advanced practice: investigating money laundering without forcing a three-stage story
The classic three-stage model becomes professionally useful when learners understand its limitations. Real bank cases can begin at any point in the visible chain. The institution may first see criminal proceeds arriving from a fraud victim, a cross-border payment after earlier layering, sale proceeds from an asset bought years ago, or a company whose capital already contains illicit value. The correct workflow begins with the bank-visible event and reconstructs value from there.
Worked case: fraud proceeds that enter digitally
A personal account receives three instant payments from unrelated individuals. The customer immediately creates new beneficiaries and transfers most of the funds onward. One payer later reports an investment scam.
It is tempting to call the incoming credits "placement" and the onward transfers "layering." That can be a useful teaching description, but the investigation should be based on stronger facts: victim-linked inbound payments, customer profile, pass-through speed, new beneficiaries, device history, downstream accounts and explanation.
If the account holder says they are processing payments for an online employer, the case should test that claim. Is there an employer? Is the arrangement commercially credible? Why are third parties paying a personal account? Who controls the downstream beneficiaries? Is the customer retaining a commission?
The three-stage vocabulary can be used after the value flow is understood. It should not substitute for that work.
Worked case: cross-border payment first seen during layering
A corporate customer receives EUR 2 million from an overseas company for "consulting services." The funds have already passed through several institutions before they reach the bank. The customer transfers portions to related entities and buys property.
The bank did not observe the original creation or placement of the proceeds. It should not claim that it did. Its investigation can assess the customer, payer, ownership, service agreement, economic capacity, prior transaction history, related entities and source-of-funds explanation.
If the consulting company has few employees, the contract is generic, the payer shares a hidden beneficial owner and the funds are rapidly redistributed, the pattern can be suspicious without the bank identifying the exact earlier stage or predicate offence.
This is a useful discipline: describe the evidence the institution has, not the full criminal story the investigator imagines.
Worked case: integration visible years later
A customer has a successful property portfolio and investment account. Current income consists of rent, dividends and asset-sale proceeds. During a periodic source-of-wealth review, historical records show that the first properties were acquired through large private loans from companies that no longer exist.
Today the cash flows can be commercially normal. The relevant question is whether the historical capital was legitimate and whether proportionate evidence can establish the lender relationships and funding sources.
This is why money-laundering controls cannot rely only on recent transactions. Integration can become visible through historical source-of-wealth reconstruction even when no current payment looks suspicious.
Self-laundering and third-party laundering
A person who commits a predicate offence can also launder their own proceeds. In other cases, professional money launderers, relatives, associates, companies, money-service providers or other intermediaries can move value for the offender.
The bank should avoid assuming that the account receiving proceeds belongs to the predicate offender. Ownership and control of each account or entity must be established separately.
Third-party laundering can be particularly difficult where the intermediary has a legitimate business. The bank may need to distinguish genuine customer activity from transactions performed on behalf of others.
Professional laundering changes the control model
Professional money-laundering organisations can provide end-to-end services: collect cash, supply mule accounts, form companies, arrange trade settlement, provide underground banking, convert to virtual assets and invest in property. One provider can serve multiple criminal groups.
FATF's 2026 work on professional money laundering and underground banking reinforces the value of cross-customer network analysis. An account that appears unremarkable alone may become important when it shares beneficiaries, owners, intermediaries or settlement paths with many suspicious cases.
Banks should build mechanisms to identify common nodes without treating every customer connected to a service provider as criminal.
Structuring is about evasion, not just amounts
Repeated transactions below a threshold can be a structuring indicator, but the pattern matters because many legitimate behaviours produce round or repeated amounts. Payroll, savings, retail cash deposits and business collections can naturally cluster.
A stronger analysis considers timing, customer knowledge of a threshold, multiple locations or channels, depositors, subsequent movement and whether the activity appears deliberately divided. The legal meaning of structuring and relevant reporting thresholds differs across jurisdictions.
Internal monitoring rules should not teach investigators that a particular global amount defines suspicious activity.
Funnel accounts as an economic pattern
A funnel account can receive deposits or transfers in multiple locations and rapidly consolidate or move the value elsewhere. The risk question is why those geographically or personally dispersed parties fund one account.
Legitimate explanations include franchise structures, nationwide sales teams, family networks or centralised collections. A case becomes stronger when the customer cannot explain depositors, the pattern is inconsistent with occupation or business, and funds quickly move to unrelated beneficiaries.
Correspondent banking and stage visibility
Correspondent banks often see payment traffic for underlying customers they do not directly onboard. They may identify unusual routing, message-data problems or respondent-level behaviour without knowing the full customer story.
The correspondent's CDD relationship is with the respondent institution. Transaction-level controls use originator, beneficiary, agent and remittance data plus respondent context. Nested relationships and payable-through arrangements should be understood explicitly because they can change who has access and what the correspondent can observe.
The investigation should never imply that the correspondent performed direct KYC on an underlying customer unless it actually did.
ISO 20022 and the myth of the magic AML field
ISO 20022 can improve structured data for debtor, creditor, agents, accounts, addresses, remittance and purpose. That improves screening, analytics and investigation only when the data is captured accurately and preserved across systems.
No ISO 20022 field determines that a transaction is placement, layering or integration. Detection requires context from customer profile, beneficial ownership, history, counterparties, devices or channels, fraud outcomes, sanctions data and external intelligence.
A BA should therefore avoid requirements such as "use Purpose Code to detect money laundering" without a defined risk hypothesis and supporting data.
Pre-transaction, real-time and post-transaction controls
Controls operate at different moments. Onboarding and customer-risk assessment occur before specific transactions. Authentication, fraud scoring, sanctions screening and limits can operate before or during payment processing. Transaction monitoring, graph analytics and customer investigation can operate after settlement.
Not every AML concern should synchronously block a payment. Some require investigation and SAR/STR consideration after settlement. Conversely, sanctions or fraud controls can create immediate payment actions under specific legal or scheme rules.
Architecture should therefore separate signal generation, risk assessment and action authority.
Scenario: instant payment with no time for manual review
A customer initiates an instant payment to a beneficiary with recent confirmed fraud reports. The real-time engine scores the beneficiary as high risk. The institution must decide what actions are permitted: customer warning, step-up verification, hold, reject, allow and monitor, or another scheme-specific response.
The AML team may later review the beneficiary network. That review can be important even if the payment was prevented because the beneficiary may be receiving money from other customers.
The lesson is that the same risk signal can support different actions depending on legal basis, scheme rules and control timing.
Scenario: sanctions match inside a laundering case
An AML investigation into shell-company transfers discovers a possible match to a designated person. The analyst should not simply add "sanctions" to the AML risk score. The match needs sanctions investigation because legal freezing or prohibition obligations can apply independently of AML suspicion.
The case platform should allow the AML and sanctions workstreams to share facts while preserving separate decisions, timestamps and legal rationales.
Evidence chain across systems
For any important payment, an investigator should be able to reconstruct:
customer instruction → authentication and entitlement → payment capture → fraud/limit checks → sanctions screening → enrichment or repair → routing and network message → settlement → account booking → monitoring alert → case → return/recall/investigation → external report where applicable.
This does not mean one system must contain everything. It means stable identifiers and lineage must connect the records.
Repair and transformation controls
Legacy payment formats may be transformed into ISO 20022 or internal canonical models. Names and addresses may be enriched; invalid data may be repaired. The investigation needs original values, transformed values, reason for change and control results.
Without that lineage, a later analyst may see only the final clean message and cannot determine what the bank originally received or screened.
Investigation decision tree
A practical case can follow these questions:
- What event or signal triggered the review?
- What is the customer's expected legitimate activity?
- What value entered, moved or left the institution's view?
- Who owned or controlled each relevant account or entity at the time?
- Which relationships and counterparties are verified?
- What explanation has the customer provided, and what evidence supports it?
- What alternative legitimate explanation remains plausible?
- What facts remain inconsistent or unexplained?
- Does the applicable suspicion threshold require SAR/STR escalation?
- Are separate fraud, sanctions, customer-risk or legal actions required?
The three stages can then help communicate the typology if they genuinely fit.
Final professional standard
A learner should finish able to use placement, layering and integration as flexible explanatory tools while investigating value through real banking systems. If a case can only be described by stage labels but the analyst cannot reconstruct the payment, ownership, customer purpose and evidence, the analysis is not yet complete.
Practitioner close: why the three-stage model is useful but not a transaction rule
Placement, layering and integration are a helpful teaching model, but bank investigators should not force every case into three sequential boxes. Digital fraud proceeds can enter an account and move internationally within seconds. Criminal proceeds may already exist inside the financial system. A customer can spend or invest illicit value without a clearly observable “placement” event. The stages therefore help explain laundering objectives; they are not mandatory transaction states that a monitoring engine can always identify.
Case lab: digital fraud with no classic cash placement
A mule account receives instant transfers from scam victims and sends them immediately to other accounts and a virtual-asset service provider. The incoming victim payments are the point at which criminal proceeds enter this account relationship, but there is no cash deposit. The subsequent splitting and transfer can serve a layering function, while conversion or later investment can make the value harder to connect to the fraud.
The bank should investigate the actual sequence rather than label one payment “placement” and another “layering” solely because a textbook says so. Authentication events, account age, payment velocity, beneficiary creation and linked accounts may be more useful operational evidence than stage labels.
Cross-border payment visibility is partial
A sending bank, correspondent and receiving bank can each see a different part of a cross-border transaction. One institution may know the originator well but little about the ultimate recipient; another may see routing and beneficiary data without the originator’s full KYC history.
Requirements should therefore avoid statements such as “the bank detects the layering stage from the SWIFT message.” A payment message carries transaction data; it does not prove the criminal origin or purpose of funds. ISO 20022 can improve structure and context, but detection still depends on customer, network and behavioural evidence.
Self-laundering and third-party laundering
The person committing a predicate offence may move their own proceeds, or professional launderers and mule networks may provide laundering services for others. This distinction affects investigation hypotheses. A customer directly linked to fraud has a different role from an account repeatedly receiving proceeds associated with several unrelated criminal networks.
Analysts should be precise about role. “Account received criminal proceeds” is a fact pattern; “customer is a professional money launderer” is a stronger conclusion requiring additional evidence.
Controls occur before and after payment execution
Financial-crime controls can operate at onboarding, authentication, beneficiary creation, payment initiation, sanctions screening, fraud decisioning, post-transaction monitoring, network analytics and investigation. No single control sees everything.
A useful architecture therefore joins preventive and detective evidence. A payment that passed sanctions screening can still be suspicious for AML. A fraud control can stop a scam payment without concluding that the beneficiary is laundering. An AML alert can arise days later when network behaviour becomes visible.
Investigations need the system evidence chain
For a meaningful reconstruction, the bank should preserve source customer data, original payment instruction, transformations, repairs, screening events, settlement outcome, fraud alerts, monitoring alerts, analyst notes and subsequent returns or recalls. If each platform stores only its final status, the economic story can be lost.
This is particularly important when payment formats are transformed. An MT-to-MX or proprietary-to-ISO mapping can change representation without changing the economic transaction. Analysts need lineage to avoid treating transformed records as separate events.
Final practitioner checkpoint
A strong learner uses placement, layering and integration to understand laundering objectives while recognizing that real cases can skip, combine or repeat those patterns. They should be able to reconstruct the observable banking events, identify what each control actually knows, avoid claiming that a payment field proves money laundering and connect preventive controls, monitoring and investigation into one evidence chain.
Practitioner masterclass: following value instead of forcing stages
Investigators rarely receive a case labelled “layering.” They receive a customer, alert, payment or network. The professional task is to reconstruct the movement of value and decide whether the activity is economically plausible.
The placement-layering-integration model remains useful because it gives analysts a common vocabulary, but it should never become a substitute for evidence. A good investigator can use the model when it helps and ignore it when it does not fit.
Follow the value
A practical investigation asks where the value came from, where it went, who controlled it at each stage and what changed in form or ownership.
The value may move from cash to bank deposit, from bank deposit to another account, from fiat to virtual assets, from one currency to another, from account balance to property, or from one corporate entity to another.
The investigator should preserve the economic chain even when systems use different identifiers.
Preserve transaction lineage
Payment platforms, card processors, treasury systems and core banking platforms may all create different references for the same economic event.
A financial-crime architecture should maintain enough linkage to connect the original instruction, payment message, booking entry, return or recall, investigation and customer communication.
This becomes especially important after payment repair. If beneficiary name, address or account information changes, the original and corrected versions should both remain visible.
Network analysis
Layering is often a network problem rather than an individual-transaction problem.
Several accounts may receive funds from unrelated victims, send to common beneficiaries, share devices, use the same addresses or move money through the same corridors.
Network analytics can reveal common nodes that are invisible in one account history.
However, network connections are not proof of criminality. Shared addresses can reflect apartment buildings, company offices or family relationships. The analyst must assess context.
Velocity as a signal
Rapid movement can be important because mule accounts and laundering networks often minimise the time funds remain exposed to recovery or freezing.
But velocity must be interpreted against the customer model. Payment companies, treasury centres and marketplaces can legitimately move funds rapidly.
A good monitoring scenario combines velocity with customer type, counterparties, transaction purpose, new-account age, beneficiary novelty and network links.
Dormant-to-active behaviour
A previously inactive account that suddenly begins receiving and forwarding significant funds can be a useful risk indicator.
The control should examine whether the behaviour is consistent with a legitimate life event or business change.
The combination of dormancy, unrelated inbound payments, rapid onward transfer and new devices can be more significant than any individual feature.
Structuring and threshold avoidance
Structuring is often associated with repeated transactions just below a threshold. The key concept is intentional arrangement to avoid a control or reporting requirement.
A monitoring rule can detect sub-threshold patterns, but it cannot prove intent by itself.
Analysts should consider timing, amount patterns, customer explanation, cash behaviour, account history and whether transactions appear deliberately divided.
Professional money laundering
Some networks specialise in laundering for other criminals. They may provide accounts, companies, trade structures, cash collection, virtual-asset conversion or cross-border movement.
For banks, professional laundering can appear as repeated use of the same intermediaries across apparently unrelated customers.
This makes cross-customer intelligence particularly important.
Trade and value transfer
Trade-based laundering can move value without requiring the payment itself to look unusual.
A legitimate-looking invoice can support a transfer that misstates the value, quantity or nature of goods. The economic transfer can occur through the trade relationship rather than through a suspicious payment pattern alone.
Banks involved in trade finance should therefore combine payment data with available trade documentation and customer context.
Real estate and legal intermediaries
Integration through property can involve lawyers, escrow accounts, companies, mortgages and third-party funding.
A transfer to a lawyer's client account is not suspicious by itself. The bank should understand the customer, source of funds, property transaction and relationship between parties.
Source-of-wealth review can become important where the purchase is inconsistent with known financial capacity.
Loan structures
Loans can be legitimate sources of funds or can be used to disguise ownership and origin.
The investigation should consider the lender, relationship to the borrower, terms, repayment behaviour, security and source of the lender's funds.
A loan from a company controlled by the borrower or associate may deserve closer review than a loan from a regulated bank.
Cash and digital interaction
Modern laundering frequently combines old and new channels.
Cash can be deposited and moved digitally. Fraud proceeds can be converted to cash. Virtual assets can be converted back into bank money. Criminal networks use whatever combination reduces traceability or increases speed.
The bank should therefore avoid designing separate control worlds for cash, payments and digital assets when the customer can move between them.
Customer explanation
A customer explanation is evidence, but it is not automatically proof.
An investigator should assess whether the explanation is plausible, consistent with known activity and supported by documents where appropriate.
Repeated explanations that change after challenge can increase concern. A credible explanation supported by independent evidence can reduce concern.
The case file should distinguish customer statement from verified fact.
Counterfactual thinking
One useful investigation technique is asking what the activity would look like if it were legitimate.
If a company says payments are for consulting, would the amounts, frequency, counterparties and countries make sense for that business? Would there normally be contracts, invoices or recurring relationships? Would the company need several unrelated personal accounts to receive funds?
Counterfactual reasoning helps analysts test explanations without jumping directly to accusation.
Scenario: marketplace merchant
A merchant receives many small payments and pays out most funds daily. That pattern can resemble pass-through laundering.
The bank should compare the activity with the marketplace business model, merchant settlements, refund rates, device patterns and expected turnover.
Legitimate high velocity should be distinguished from unexplained third-party movement.
Scenario: mule network expansion
A bank identifies three accounts receiving scam proceeds. Network analysis shows five additional accounts sharing beneficiaries and devices but with no victim complaints yet.
The bank may investigate the wider network proactively. This illustrates how AML intelligence can extend beyond confirmed fraud reports.
Scenario: integration after several years
A customer has accumulated a property portfolio and investment account. Current cash flows look ordinary, but historical review shows unexplained capital introduced through companies years earlier.
Integration can therefore be visible only when source-of-wealth history is examined over a longer period.
Operational handoffs
Cases can cross fraud, AML, sanctions, operations and legal teams.
Handoffs should preserve transaction references, evidence, timestamps and rationale. The receiving team should not have to recreate the case from screenshots or email.
A joined case view can reduce delay while preserving specialist decision rights.
Investigator writing quality
A good investigation narrative is chronological, factual and explicit about reasoning.
It should describe what triggered the review, relevant customer profile, transactions, counterparties, explanations, supporting evidence, contradictory information and the reason for the final decision.
Avoid unsupported labels. “Layering” should be used only when the pattern supports that interpretation.
Practice exercise — work through this before reading on.
Final practitioner test
A strong analyst should be able to follow value across systems, explain who controlled it, identify where the activity diverged from expected behaviour and distinguish fact from inference.
If the analyst can only name the three stages but cannot reconstruct the transactions, the model has not yet become practical knowledge.
Guided practice: money-laundering stages in bank operations
Use these cases to practise evidence-based reasoning. Allow additional time to answer the independent exercises before comparing your reasoning with the explanations.
The three-stage model is a lens, not a law of nature
Placement, layering and integration help learners understand common laundering objectives. Placement traditionally describes introducing illicit proceeds into the financial system. Layering describes transactions or structures that make source, ownership or purpose harder to follow. Integration describes criminal value appearing as apparently legitimate wealth, income or assets.
Real activity can skip, repeat or combine these ideas. Fraud proceeds may already exist as electronic bank money. A criminal can buy property quickly without a long layering chain. Professional money launderers can provide pre-built networks. Digital assets can move value through several transformations in minutes. The analyst should therefore follow the money and evidence rather than ask which textbook box must come next.
Worked case: digital fraud proceeds
A victim sends an authorised payment to Account A after an investment scam. Account A immediately distributes value to Accounts B, C and D. B and C transfer to a virtual-asset service provider; D sends funds to a company whose owner also controls Account A. Two months later, proceeds from virtual-asset sales return to another company controlled by the same network and are used as a property deposit.
A teaching model can describe the victim payment as an entry point, the rapid distribution and conversions as layering-like activity and the property purchase as integration-like activity. But the investigation should lead with facts: victim-linked funds, common control, transaction chronology, conversions, counterparties and final asset acquisition. The labels add explanation; they do not replace evidence.
Cash-generated proceeds versus digital proceeds
The classic placement concept is clearest when crime generates physical cash. A drug-trafficking organisation, illegal gambling operation or cash theft may need to introduce currency into bank accounts, businesses, remitters or other financial channels. Digital fraud is different because the value can originate inside the banking system. The receiving bank may be seeing criminal proceeds for the first time, but that is not identical to a traditional physical-cash placement event.
Teaching should preserve both views. This avoids the inaccurate statement that every inbound scam payment is automatically "placement" in the strict traditional sense.
Practice exercise — work through this before reading on.
Stage-versus-evidence exercise
Take these events: cash deposited through several branches; funds split across accounts; currency converted; loan received from a related company; property purchased; business revenue mixed with illicit cash; securities sold; funds returned to the original owner. For each, write two answers: the possible laundering-stage interpretation and the actual evidence the bank would need before treating the event as suspicious.
This exercise exposes the danger of typology labels. Currency conversion can be legitimate. Cross-border transfers can be normal. Property purchases can be genuine. A stage label becomes useful only when combined with context, ownership, customer purpose and unexplained behaviour.
Bank visibility boundaries
Different institutions see different parts of a laundering chain. A retail bank may see the initial scam receipt. A correspondent bank may see only a cross-border message. A virtual-asset provider may see wallet activity. A private bank may later see apparently legitimate investment wealth. No institution should claim visibility it does not have.
Case narratives should clearly state what the bank observed directly, what was learned from customers, what came from external intelligence and what is inferred. Information sharing through lawful channels can help connect fragments, but the evidence provenance should remain visible.
Control design across stages
Placement-like risks can be addressed by onboarding, cash controls, merchant/acquiring monitoring, fraud intelligence and source-of-funds checks. Layering-like risks often need network analytics, transaction chronology, beneficial ownership, entity resolution and payment lineage. Integration-like risks can require source-of-wealth analysis, asset history, corporate ownership and evidence of economic substance.
A strong AML programme therefore does not build one rule for each textbook stage. It builds controls around observable risk patterns and data.
Scenario: legitimate treasury centre
A multinational treasury entity receives large payments from subsidiaries, converts currencies and redistributes funds the same day. The activity resembles rapid pass-through and cross-border layering. The customer's declared purpose, group ownership, cash-pooling agreements and established counterparties can explain the pattern.
This scenario is essential because typology-driven monitoring can create huge false positives when legitimate business models are not understood.
Practice exercise — work through this before reading on.
Final typology test
Explain why each statement is too strong: "cash deposit means placement"; "multiple banks mean layering"; "property purchase means integration"; "crypto conversion is money laundering"; and "three stages must happen in order." Rewrite each as a risk hypothesis tied to evidence.
A strong learner should finish able to use the three-stage model to explain money laundering while remaining disciplined enough not to force real investigations into a simplified diagram.
Worked case: a cross-border chain seen from the middle
A correspondent banking team reviews a series of US-dollar payments arriving from a respondent bank in an illustrative Gulf jurisdiction. Over six weeks, eleven payments totalling an illustrative 4.2 million arrive for the account of different originators, all described as consultancy or logistics services, all ultimately credited to two beneficiary companies in an illustrative European jurisdiction that share a corporate service provider address. The respondent bank's own screening is assumed but not evidenced, and the payment messages carry limited originator detail beyond names and a shared remittance phrase.
The correspondent bank sees only the middle of a possible chain. It cannot observe placement, whatever form it took, and it cannot see what happens after the European beneficiaries receive the funds. The analytical error to avoid is treating this partial visibility as a complete story. The correct frame is stage-agnostic: the observable facts are structured-looking segmentation just below an illustrative internal review threshold, narrative similarity across supposedly unrelated originators, beneficiary concentration behind apparently distinct companies, and a jurisdiction route that adds distance without obvious commercial logic.
The investigation proceeds by testing innocent explanations with the same seriousness as criminal ones. The respondent bank may be batching legitimate regional consultancy flows through a hub; the shared phrase may be a template from a payroll or billing platform; the service-provider address may host hundreds of legitimate companies. The team therefore requests, through the respondent relationship channel, originator business-purpose information, the underlying commercial documentation for a sample of payments, and confirmation of the respondent's own due-diligence position on the originators. Simultaneously it checks internal data: have the European beneficiary companies appeared in earlier cases, do their account behaviours show pass-through characteristics, and do device, address or ownership links connect them.
Two outcomes are prepared in parallel. If the documentation shows genuine, distinct commercial relationships with credible economics, the case closes as a false positive with the reasoning recorded, and the segmentation pattern is fed back to scenario tuning so the same flow does not re-alert without new information. If the respondent cannot or will not provide documentation, or the beneficiaries show rapid onward movement to unrelated parties, the bank treats the opacity itself as the finding: it assesses restrictions or relationship exit under its correspondent risk policy and files a suspicious report in its own jurisdiction where the applicable legal reporting threshold is met. The lesson is that a bank in the middle of a chain investigates what it can see, documents what it cannot, and never lets limited visibility become an excuse for inaction.
What supervisors expect from stage-aware controls
Supervisory examinations rarely ask banks to recite the three stages. They test whether controls reflect how laundering actually behaves. Examination experience across major jurisdictions converges on several expectations worth internalising. First, the risk assessment must connect predicate-offence exposure to the bank's actual products and customer base: a bank with heavy trade-finance activity should show trade-laundering analysis, while a retail-heavy bank should show fraud-proceed and mule-network analysis. Generic typology lists copied into a risk assessment without this connection are a recurring criticism.
Second, monitoring scenarios must be traceable to stated risks, with documented tuning rationale. An examiner who finds a structuring scenario with a threshold copied from another institution, no local calibration, and no record of why the threshold fits this bank's data will treat the scenario as decorative. Tuning records should show the data analysed, the alternatives considered, the false-positive impact accepted, and the approval. Third, investigations must show evidence-led reasoning rather than label-led reasoning: case files that conclude "layering identified" without reconstructing movement, ownership and purpose will be challenged. Fourth, the bank must demonstrate that typology knowledge stays current: training records, scenario-review cycles, and a process for absorbing new typologies from FIU reports, supervisor publications and internal cases.
These expectations apply regardless of jurisdiction, but the legal machinery around them differs, and analysts should know the framework they operate in. In the United States, the Bank Secrecy Act framework requires banks to file qualifying suspicious activity reports with FinCEN generally within 30 calendar days of initial detection of facts that may constitute a basis for filing a SAR; the bank SAR rule permits filing to be delayed up to 60 calendar days only where no suspect was identified at initial detection. Currency Transaction Reports apply to reportable currency transactions exceeding USD 10,000, including aggregation where the applicable FinCEN rules require it. In the United Kingdom, the Proceeds of Crime Act 2002 creates principal money-laundering offences alongside disclosure obligations. Under the DAML framework, a seven-working-day notice period applies after the authorised disclosure; if consent is refused, an initial 31-day moratorium follows, and the statutory framework allows court extensions in defined circumstances. In the European Union, the 2024 AML package established AMLA and a more harmonised rulebook. AMLA began operations in 2025, is developing common supervisory methods during 2026, is due to select 40 entities for direct supervision during 2027, and plans to begin direct supervision in 2028. These are jurisdiction-specific examples, not global rules, and analysts must verify the current local requirements that actually apply to the legal entity, transaction and customer.
Validating typology scenarios before they cause harm
A typology scenario that has never been validated is an assumption running in production. Validation for stage-related scenarios has a specific shape. Back-testing measures what the scenario would have caught: run it against historical confirmed cases and measure the hit rate, then run it against known-legitimate populations, treasury centres, payroll flows, seasonal businesses, and measure the false-positive rate. A scenario that catches old cases but fires overwhelmingly on legitimate treasury activity is not ready; it needs segmentation, allow-listing of verified entities, or additional conditions before deployment.
Pre-deployment review should also test the scenario against data-quality reality. A scenario that depends on fields the bank does not reliably populate, such as ultimate-originator detail in correspondent messages or structured addresses after a format migration, will underperform silently. The validation record should state the data dependencies, the measured population rates, and the monitoring that will detect decay. Post-deployment, scenario performance needs scheduled review with teeth: alert-to-case conversion rates, investigation overturn rates, time-to-decision trends, and feedback from case outcomes into rule changes. Scenarios that nobody tunes accumulate two opposite failures simultaneously, missing evolving behaviour while drowning analysts in stale patterns.
Model-risk discipline applies where scenarios use machine learning or complex scoring. The validation must cover conceptual soundness for the typology, data representativeness, outcome labelling quality, stability across customer segments, and explainability sufficient for an investigator to write a reasoned narrative. An investigator who cannot explain why a case was selected cannot defend the resulting suspicion decision, and a suspicion decision that rests on an opaque score with no corroborating evidence is fragile.
Integration discovered years later: the wealth-review case
A private-banking relationship review surfaces a client whose declared source of wealth, a business sold eight years ago for an illustrative 12 million, no longer reconciles with the account trajectory. The sale documentation on file is thin: a share-purchase agreement with an unfamiliar buyer, no independent valuation, and completion funds that arrived from a third-party entity rather than the named buyer. Since onboarding, the account has received regular transfers described as investment returns from entities in two jurisdictions where the client has no known business, and has recently funded a property purchase in a third country.
This is integration analysis at its most characteristic: the placement and any layering happened years ago, possibly at other institutions, and the current bank sees only apparently legitimate wealth behaving almost normally. The investigation reconstructs backwards. It verifies the original sale through independent sources: corporate registries, contemporaneous financial statements, press records, and the buyer's identity and funding. It traces the completion funds and each subsequent inflow to underlying economics, asking at every step whether the return profile matches the stated investment and whether the entities have substance. It examines the property purchase as the current integration endpoint, testing price plausibility and funding lineage.
Three alternative hypotheses structure the work. The benign hypothesis is poor record-keeping around a genuine sale and genuine investments; it predicts that independent sources will corroborate the sale price, the buyer, and the investment performance. The layering-legacy hypothesis is that the original sale was genuine but later inflows represent unrelated criminal proceeds being merged into clean wealth; it predicts inconsistencies concentrated in specific inflows rather than the original sale. The criminal-origin hypothesis is that the sale itself was a sham transferring criminal value into apparently legitimate form; it predicts systemic corroboration failure, an unverifiable buyer, and economics that do not withstand scrutiny.
The outcome depends on which hypothesis the evidence supports, and the discipline is to let each fail on facts rather than preference. If the sale corroborates but two inflows do not, the bank reports on the unexplained inflows while retaining the relationship under enhanced monitoring, having separated the verified history from the suspicious residue. If the sale itself cannot be substantiated, the entire wealth proposition collapses and the bank must consider the full relationship, including the property transaction, within its reporting and exit framework. The general lesson is that integration controls are retrospective by nature: they depend on record retention, effective-dated ownership data, and a willingness to reopen onboarding conclusions when later evidence contradicts them.
Jurisdictional machinery: how the same pattern is handled differently
The underlying laundering pattern may be identical across countries, but the bank's obligations, tools and constraints differ materially by jurisdiction, and analysts working in global banks must hold both the universal pattern and the local machinery in mind. Three dimensions vary most. Suspicious-reporting mechanics differ: some jurisdictions use a single FIU report type with a narrative standard, others separate suspicious-transaction and suspicious-activity concepts, and consent regimes such as the United Kingdom's DAML process impose standstill obligations unknown in pure-reporting regimes. A cross-border case team that assumes its home process applies everywhere will miss both obligations and protections.
Tipping-off and confidentiality rules differ in scope and severity. Most jurisdictions prohibit alerting the customer to a report, but the precise boundaries, what may be said in ordinary customer contact, what must be recorded, how long restrictions persist, and the penalties for breach vary. Data-sharing permissions differ equally: some jurisdictions permit intra-group sharing of suspicion-related information with defined safeguards, others restrict it sharply, and cross-border sharing with head office can require specific legal gateways. A network investigation spanning branches in multiple countries must map these permissions before evidence moves, not after.
Record-retention and production obligations complete the picture. Retention periods for transaction and due-diligence records typically run five years after relationship end or transaction date under FATF standards, but local law sets the binding period and legal holds extend it. Law-enforcement production orders, account-monitoring orders and FIU information requests each carry jurisdiction-specific procedures, timelines and challenge rights. The investigation plan for a cross-border stage-spanning case should identify the applicable framework in each affected jurisdiction at the outset, with local legal input where the action constrains customer rights or involves compelled disclosure.
Horizon scanning: keeping stage analysis current
Laundering methods evolve continuously, and stage analysis frozen at training date decays. A proportionate horizon-scanning practice for typology risk has four inputs. Internal case intelligence, the bank's own confirmed cases and near misses, analysed for method innovation rather than merely counted. External typology publications from the FATF, FATF-style regional bodies, national FIUs and supervisors, reviewed on a defined cycle with assessments of relevance to the bank's products and customers. Law-enforcement and industry-forum insights shared through lawful channels, contributing current method detail that publications describe only in general terms. And product-change intelligence from within the bank: new products, new corridors, new customer segments and new technologies each create novel placement, layering and integration possibilities that should be assessed before launch rather than discovered through cases.
Each input needs an owner, a review rhythm and a documented disposition: relevance assessment, control implication, action assigned or consciously deferred with rationale. The output feeds scenario development, training updates and risk-assessment refreshes. Without this loop, monitoring scenarios gradually describe historical crime while current crime moves elsewhere, and training teaches analysts to recognise yesterday's typologies. A short annual typology-refresh note, recording what changed, what was considered and what action followed, demonstrates to supervisors and auditors that the programme learns, and gives investigators current material grounded in the bank's own reality rather than generic warnings.
Emerging methods: AI-enabled deception and the analyst's response
Criminals adopt new technology faster than controls adapt, and the current wave of AI-enabled deception changes placement, layering and integration mechanics simultaneously. Deepfake audio and video can defeat voice and video verification used in onboarding and transaction authorisation, allowing account-takeover and impersonation at scale. Synthetic media supports investment-scam grooming with fabricated personas, live video calls and falsified trading dashboards. AI-generated documentation produces convincing counterfeit invoices, statements and identity documents that can evade visual examination. Automated micro-structuring scripts distribute activity across accounts and institutions with machine precision that evades threshold logic designed for human behaviour.
The control response is layered rather than single-point. Verification must assume media fakery: liveness detection with presentation-attack resistance, multi-channel confirmation for high-risk actions, and behavioural signals that survive media synthesis. Document examination must evolve beyond visual checks toward forensic and data-consistency analysis: metadata examination, cross-document consistency testing, and independent-source verification that does not depend on the document's appearance. Monitoring must detect machine-scale patterns: inhuman timing precision, coordinated multi-account orchestration, and volume-velocity combinations exceeding human capacity. And training must inoculate staff and customers against AI-enabled social engineering with current examples rather than generic phishing material from five years ago.
Critically, emerging-method readiness is organisational, not technological alone. Horizon-scanning must track criminal adoption of new tools through FIU publications, industry intelligence and internal case analysis. Control-change governance must deploy countermeasures faster than annual cycles allow, with modular detection logic that can be updated without full system replacement. And measurement must distinguish genuine AI-enabled cases from hype-driven over-attribution: every incident labelled AI-enabled should record the specific technical evidence supporting the label, preventing both under-reaction to real capability shifts and resource misallocation to fashionable threats. The three-stage model remains useful here precisely because it is technology-neutral: whatever the tools, criminal value must still enter, move and settle, and each transition remains an evidence opportunity for banks prepared to look.
Measuring whether typology training works
Training records proving attendance do not prove competence, and supervisors increasingly test the difference. Effective typology-training measurement assesses analyst performance on realistic exercises: classifying staged cases, writing evidence-led narratives, identifying the additional evidence each scenario requires, and escalating appropriately under time pressure. Pre- and post-training comparison on equivalent exercises quantifies learning rather than assuming it. Error-pattern analysis across cohorts identifies systemic misunderstandings, such as persistent stage-label forcing or consistent neglect of ownership analysis, that training design must address rather than repeat.
Competence measurement extends beyond investigators to the first line, relationship managers, trade processors and branch staff whose observations feed the control chain. Role-specific assessment tests recognition and escalation rather than investigation technique: can a relationship manager spot a business-purpose inconsistency, can a trade examiner recognise a phantom-shipment indicator, can a teller identify structuring behaviour worth recording. Training that teaches everyone investigation produces nothing; training that teaches each role its own contribution builds the chain. Refresher cycles should follow typology change and error patterns rather than calendar alone, concentrating effort where measurement shows weakness. A training programme that cannot demonstrate analyst competence improvement is an attendance system, and examination teams treat it accordingly. Competence evidence also strengthens the bank's position in supervisory dialogue: documented analyst capability, tested against realistic typology exercises with measurable improvement, demonstrates control effectiveness more convincingly than training-hour statistics or policy attestations.
Examination walkthrough: how a supervisor tests stage controls
Understanding how supervisors examine stage-related controls helps banks prepare honestly rather than cosmetically. A typical examination samples across the control chain: the risk assessment's treatment of placement, layering and integration exposure for the bank's actual business mix; the scenario inventory's traceability to assessed risks with tuning rationale; a sample of alerts and cases testing investigation quality; the suspicious-reporting record testing timeliness and narrative quality; and training and governance testing whether typology knowledge reaches the staff who need it. Each sample tells the examination team something specific, and experienced banks prepare by examining themselves the same way.
Risk-assessment sampling looks for the connection between business reality and typology coverage. Examiners ask how the bank's product and customer data informed its typology prioritisation, what analysis supports scenario selection, and how emerging methods enter the assessment. A risk assessment describing all typologies equally, without prioritisation grounded in the bank's data, signals a compliance document rather than a risk tool. Strong assessments quantify where possible: cash volumes by segment, cross-border flow concentrations, trade-finance commodity exposures, virtual-asset touchpoints, each connected to the scenarios designed to monitor them.
Case-file sampling is where examinations are won or lost. Reviewers read investigation narratives asking whether the analyst reconstructed movement before interpreting it, whether alternative explanations were tested, whether evidence provenance is visible, and whether conclusions follow from documented facts. Common findings include narratives that assert stage labels without reconstruction, files closed on customer explanation without verification, network cases treated as isolated alerts, and suspicion decisions without recorded reasoning. Each finding points to training, procedure or resourcing gaps that the bank should already have identified through its own quality assurance. A quality-assurance programme that finds nothing while examinations find much is itself an examination finding about the second line's effectiveness.
Reporting-record sampling tests the end of the chain: filing timeliness against the jurisdiction's requirements, narrative quality measured by whether a reader can understand the suspicion from the report alone, and the relationship between internal case volumes and external filing volumes. Consistently low filing rates relative to case volumes invite questions about decision thresholds; filing delays invite questions about process capacity; thin narratives invite questions about investigation quality. Defence lies in documented decision standards, capacity planning and narrative-quality review, not in post-hoc justification of statistics.
Why stage discipline matters for measurement
Banks that force every case into a stage label corrupt their own management information. Placement-heavy metrics push investment toward cash controls while layering-heavy metrics justify analytics spending, and if the labels reflect analyst habit rather than evidence, the metrics mislead. Better measurement tracks observable phenomena: entry-channel volumes and anomalies, network-case frequency and outcomes, wealth-explanation failure rates, scenario conversion rates, and investigation quality scores. Stage language can remain in training and explanation, but control measurement should rest on facts the bank can verify. A programme measured on evidence rather than labels improves faster, because its feedback loops describe reality instead of vocabulary.
Boundary cases: when the stage label is uncertain
A transaction can support more than one laundering objective at the same time. A mule account that receives scam proceeds, immediately converts part to virtual assets and sends the remainder to a company controlled by the same network may simultaneously introduce criminal value into a new account relationship, create distance from the victim and move value toward apparently legitimate use. Forcing each event into exactly one stage can hide the more useful operational story.
The investigation should therefore describe observable movement first and use placement, layering or integration only where those labels improve understanding. Monitoring scenarios should be triggered by behaviour such as pass-through velocity, third-party funding, unexplained ownership connections or source-of-wealth inconsistency—not by an expectation that the engine can identify a universal “stage.”
This approach also improves model validation. Testers can ask whether the control finds the risky behaviour and whether the investigation can reconstruct the value chain, rather than judging success by whether a transaction received the same textbook label as the test script.
Final practitioner note: do not force the stage label
When a real investigation does not fit neatly into placement, layering or integration, the analyst should not manufacture a stage merely to make the narrative look complete. The stronger method is to describe how value entered the bank's view, how control or form changed, which parties and accounts were involved, what evidence is available and why the activity is inconsistent with the customer's expected purpose. The three-stage model remains a teaching aid; the evidence remains the investigation.
2026 practitioner enhancement: using the stage model without turning it into a rule
The placement-layering-integration model is still useful vocabulary, but modern bank investigations should not be designed around the assumption that every case progresses through three visible phases. Fraud proceeds can arise directly inside the banking system, an instant payment can move through several accounts before the first institution receives a complaint, and illicit value may already have been layered through companies, trade or virtual assets before it reaches a bank. The stage model should therefore help explain a case after the facts are assembled; it should not dictate what the monitoring engine must find.
A stronger operating model follows the value and the evidence. Start with the economic event: who controlled the value, how it entered the institution's view, what form it took, which parties or accounts touched it, what changed, and where it went. Then overlay customer purpose, beneficial ownership, device or channel information, fraud intelligence, payment-message data, transaction history and external intelligence. A single ISO 20022 field, SWIFT message, sanctions result or transaction-monitoring alert cannot establish money laundering on its own. The value comes from joining those sources and preserving lineage between them.
Fraud proceeds do not require a cash-placement story
In authorised push-payment scams, business-email compromise, account takeover and other cyber-enabled fraud, the money may be legitimate immediately before the predicate offence. Once the victim transfers it, the recipient institution may be handling criminal proceeds even though no physical cash has entered the system. The receiving account can then split the proceeds, send them to additional accounts, purchase virtual assets, withdraw cash or move them cross-border within minutes.
This is why fraud and AML controls should exchange relevant intelligence. Fraud teams may know that a payment is victim-linked; AML investigators may see that the receiving account belongs to a broader mule network. Neither view is complete by itself. The architectural requirement is not to merge every fraud and AML decision into one process, but to make reliable evidence reusable across the two disciplines with appropriate access controls and decision ownership.
Professional laundering can collapse several stages into one service
Professional money-laundering networks can provide accounts, companies, cash collection, underground settlement, trade structures, virtual-asset conversion and cross-border movement to multiple criminal groups. In that model, a bank may see only one leg of a service that has already combined placement, layering and integration functions. Repeated use of the same intermediaries across otherwise unrelated customers can therefore be more informative than trying to label each transfer as one stage.
FATF's 3 September 2026 report on professional money laundering, underground banking, hawala and other similar service providers reinforces this network view. Such channels can serve legitimate remittance and community needs, yet criminal actors can also exploit specialist networks to collect, settle and redistribute value. Controls should focus on evidence of undeclared intermediation, third-party settlement, common counterparties, unusual cash or trade links, opaque ownership and inconsistent customer purpose rather than treating a particular cultural or payment channel as inherently criminal.
Correspondent banking and partial visibility
Cross-border investigations often involve partial views. The ordering customer's bank may know the customer and payment purpose; an intermediary bank may see message data and route information; the beneficiary bank may know the receiving account and its subsequent behaviour. Nested relationships or payable-through arrangements can add another layer of indirect exposure.
A correspondent institution should therefore be precise about what it knows. It should not imply direct KYC knowledge of an underlying customer it does not serve. At the same time, it should preserve originator, beneficiary, agent and remittance data accurately enough to support screening, monitoring and later investigation. ISO 20022 can improve structure and richness, but richer syntax is not the same as higher-quality data. Missing, truncated, generic or incorrectly mapped information can still undermine control effectiveness.
Real-time payments change the control window
In instant-payment environments, the distinction between pre-transaction and post-transaction controls becomes operationally important. Authentication, sanctions screening, beneficiary-risk signals, limits and fraud scoring may have only seconds. Transaction monitoring, network analysis and customer-level investigation can continue after settlement, but by then the value may have moved again.
The practical response is layered control: stronger onboarding and customer understanding, event-driven monitoring for early-life accounts, real-time beneficiary and network intelligence where lawful and technically feasible, rapid fraud-to-AML escalation, efficient recalls or freezes where legally available, and post-event graph analysis. The correct design depends on scheme rules and local law; there is no universal right to hold or reverse an instant payment simply because an AML signal exists.
Investigation evidence should be chronological and testable
A good case file can reconstruct the transaction chain without forcing it into stage labels. It should preserve original instruction data, repaired or amended values, timestamps, booking and settlement references, customer and account identifiers, counterparties, device or channel events, related fraud reports, sanctions results, historical alerts and relevant KYC or beneficial-ownership records.
Analysts should distinguish observation from inference. "Eight unrelated credits were received and 94% of the value left within 35 minutes" is an observation. "The customer is layering fraud proceeds" is an interpretation that needs supporting context. This distinction improves suspicious-activity narratives, model validation, quality assurance and auditability.
Final control principle
Placement, layering and integration remain useful teaching concepts. The bank's actual control framework should be built around customer risk, economic purpose, movement of value, relationships, behavioural change and evidence quality. When the three-stage model helps explain the story, use it. When the facts do not fit it, follow the facts.
References and further reading
Global standards and bank risk management
- FATF — The FATF Recommendations, current edition amended June 2026: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF — Methods and Trends, current public typology and threat material: https://www.fatf-gafi.org/en/topics/methods-and-trends.html
- FATF — Cyber-Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks, 24 February 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/cyber-enabled-fraud-digitalisation-ml-tf-pf-risks.html
- FATF — Horizon Scan AI and Deepfakes, 22 December 2025: https://www.fatf-gafi.org/en/publications/Methodsandtrends/horizon-scan-ai-deepfake.html
- FATF — Investigating Professional Money Laundering, Underground Banking, and the Use of Hawala and Other Similar Service Providers, 3 September 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/pml-underground-banking-hawala-hossps.html
- Basel Committee on Banking Supervision — AFS10 Anti-money laundering and counter-terrorist financing, Basel Consolidated Guidelines, published 1 January 2026: https://www.bis.org/committees/bcbs/basel-consolidated-guidelines/module/afs/10
- Wolfsberg Group — Statement on Effective Monitoring for Suspicious Activity, Part II: Transitioning to Innovation, 27 August 2025: https://wolfsberg-group.org/resources/195/202
- Egmont Group — Financial Intelligence Units, explaining the FIU role in receiving and analysing suspicious transaction reports and disseminating financial intelligence: https://egmontgroup.org/about/financial-intelligence-units/
Current jurisdiction-specific examples used in the chapter
- FinCEN — Bank SAR filing timing: a bank generally files within 30 calendar days of initial detection, with the additional period where no suspect is identified subject to the applicable rule: https://www.fincen.gov/system/files/2025-10/SAR-FAQs-October-2025.pdf
- FinCEN — Frequently Asked Questions Regarding the FinCEN Currency Transaction Report, including aggregation of currency transactions exceeding USD 10,000 in a business day where the institution has the required knowledge: https://www.fincen.gov/resources/frequently-asked-questions-regarding-fincen-currency-transaction-report-ctr
- UK Government — Criminal Finances Act / POCA moratorium-period guidance, explaining the seven-working-day notice period, initial 31-day moratorium following refusal, and court-extension framework: https://www.gov.uk/government/publications/circular-0082018-criminal-finances-act-extending-the-moratorium-period-for-suspicious-activity-reports/circular-0082018-criminal-finances-act-extending-the-moratorium-period-for-suspicious-activity-reports
- AMLA — About AMLA, including the 2024 legal establishment, 2025 operational start, 2027 selection cycle and 2028 start of direct supervision for selected high-risk financial entities: https://www.amla.europa.eu/about-amla_en
- AMLA — Common EU enforcement approach, 8 July 2026, on supervisory convergence and the developing EU AML/CFT rulebook: https://www.amla.europa.eu/press-release-amla-introduces-common-eu-approach-enforcing-anti-money-laundering-rules_en
Operational threat context
- INTERPOL — Operation HAECHI VI, 24 September 2025, showing cyber-enabled fraud, bank-account networks, virtual assets and rapid payment intervention in current financial-crime operations: https://www.interpol.int/News-and-Events/News/2025/USD-439-million-recovered-in-global-financial-crime-operation
Educational note: the placement-layering-integration model is a teaching framework. Money-laundering offences, suspicious-reporting thresholds, restraint powers, reporting deadlines and customer-handling obligations depend on applicable law and should not be inferred solely from the stage model.