Placement: Entry of Illicit Value
Placement is the point at which criminal value first enters, or becomes more deeply embedded in, a financial channel that can store, transfer, convert or disguise it. In traditional teaching this is often described as the first stage of money laundering, but a modern bank should treat that description carefully. Not every laundering case begins with cash being deposited into a bank. Fraud proceeds may already arrive as digital money, cybercrime proceeds may begin in virtual assets, corruption payments may be routed through companies from the outset, and professional laundering networks may receive value through established accounts. Placement remains a useful concept because it asks a practical question: where does illicit value first become visible to the bank, and what controls should react at that point?
The important word is value. It can be cash, a bank transfer, card proceeds, merchant settlement, cheque, prepaid balance, virtual asset conversion, loan proceeds, trade receipts or an apparently ordinary business payment. The bank does not normally know at the moment of entry that the value is criminal. It sees facts: who paid, who received, how much moved, which channel was used, whether the behaviour matches the customer profile, and whether other intelligence changes the meaning of the transaction.
Placement is a concept, not a mandatory chronological stage
The placement-layering-integration model is useful for teaching because it helps learners understand different laundering objectives. It should not be treated as a rule that every case follows in order. A scam victim may send money directly from a legitimate bank account to a mule account. There is no physical cash placement. The criminal value appears immediately as an electronic credit. A corrupt payment may be disguised as a consultancy fee and enter a corporate account looking like ordinary revenue. Proceeds from online crime may be held in a crypto wallet before being converted through an exchange and reaching a bank account.
The operational lesson is therefore broader than “look for cash deposits.” Placement can occur whenever illicit value is introduced into a financial relationship or product in a way that creates an opportunity to store, transfer, convert or legitimise it.
What a bank actually sees
Banks usually see one fragment of the story. A teller sees a cash deposit. A payment engine sees an inbound transfer. A merchant-acquiring platform sees card settlement. A fraud system sees the beneficiary receiving victim payments. A KYC platform sees the customer’s occupation and expected account purpose. A transaction-monitoring engine sees repeated activity over time. An investigator may later connect these fragments.
This fragmentation is why placement detection depends on data integration. A cash deposit of EUR 8,000 may look unremarkable in isolation. The same deposit becomes more interesting if the customer is a student with no expected cash activity, the account was opened recently, similar deposits occurred at several branches, and funds are transferred abroad soon after credit. None of those facts proves laundering. Together they create a stronger reason to understand the activity.
Cash placement
Cash remains important because it can be difficult to trace before it enters the regulated financial system. Criminal proceeds from drug trafficking, illegal gambling, theft, bribery, cash-based fraud or other offences may generate physical currency that needs to be converted into usable financial value.
Banks can encounter cash through branches, ATMs, night safes, cash-deposit machines, business cash services and third-party channels. The risk depends heavily on the customer and product. A supermarket, petrol station or restaurant may legitimately deposit substantial cash. A software consultancy that suddenly begins making frequent cash deposits presents a different question.
Cash controls should therefore be contextual rather than purely threshold-based. Transaction size matters, but so do frequency, location, source, occupation, business model, declared turnover, seasonality and subsequent movement of funds.
Structuring and threshold avoidance
One common typology is structuring, sometimes called smurfing, where transactions are deliberately divided to avoid controls, reporting thresholds or scrutiny. The presence of repeated amounts just below an internal or legal threshold can be a useful indicator, but the bank should avoid simplistic conclusions. Customers can have legitimate reasons for similar-value transactions.
A good investigation looks at pattern and context. Were deposits made at several branches? Did different people deposit into the same account? Were amounts repeatedly close to a known threshold? Did the behaviour start suddenly? Were funds immediately transferred onward? Is the activity consistent with the customer’s declared business?
The system should distinguish a detection threshold from a legal reporting threshold. A transaction-monitoring rule may use an internal threshold for efficiency, but that does not mean activity below it is safe or activity above it is criminal.
Mule accounts as placement points
Modern fraud has made mule accounts one of the most important placement points in retail banking. Victim funds may move directly from legitimate accounts into mule accounts controlled, recruited or exploited by criminals. In that case the receiving account is where criminal proceeds enter the laundering network.
Some mules knowingly rent or sell access to their account. Others are recruited through fake jobs, romance scams, investment schemes or social engineering. Some may initially believe they are performing a legitimate service and later become complicit. The legal consequences vary by jurisdiction and facts, so banks should not assume every mule has the same level of intent.
From a bank-control perspective, the receiving behaviour can include multiple unrelated inbound payments, rapid onward transfer, new beneficiaries, cash withdrawal, crypto purchases, device changes, use of several accounts and links to other known mule accounts. Fraud intelligence and AML monitoring are most effective when they can exchange relevant information.
A victim bank may see the fraud. The receiving bank may see the laundering. Both perspectives matter.
Business accounts and disguised revenue
Placement can occur through a business account when illicit funds are made to resemble legitimate sales or service income. Cash-intensive businesses are a classic example, but the principle is broader. A consultancy can receive payments for services that were never delivered. A merchant can process fabricated transactions. A company can receive transfers from unrelated individuals and record them as customer revenue.
The control challenge is that legitimate businesses naturally receive many payments. The bank therefore needs to understand the business model. What does the company sell? Who are its customers? What payment methods are normal? What level of turnover is expected? Which countries are involved? Are receipts consistent with invoices, merchant data or known operations?
KYC quality matters directly. If onboarding captures only “trading company” or “consultant,” monitoring has very little baseline against which to compare behaviour.
Merchant acquiring and payment acceptance
Merchant services can also be used to introduce illicit value. Criminals may create sham merchants, misuse real merchants, process transactions through inappropriate merchant categories, or generate apparently legitimate card sales. Acquiring banks and payment service providers therefore need to understand merchant business models, transaction patterns, refund behaviour, chargebacks, geographic exposure and linked ownership.
Unusual merchant behaviour can include sudden spikes in turnover, high levels of card-not-present activity inconsistent with the business, transactions at odd times, excessive refunds to different cards, repeated round-value transactions or settlement flows inconsistent with the declared activity.
Again, no single indicator proves laundering. The purpose is to identify combinations that justify review.
Prepaid instruments and stored value
Prepaid cards, wallets and stored-value products can provide legitimate convenience and inclusion, but they can also be used to convert cash or other value into transferable balances. Risk depends on functionality. A low-limit closed-loop gift card presents a different risk from a reloadable, cross-border, cash-withdrawable product.
Banks and issuers should consider funding methods, reload limits, identity requirements, transferability, ATM access, cross-border use, third-party funding and the ability to aggregate many instruments.
The principle is the same as elsewhere: product design determines what misuse is possible, and controls should be proportionate to that design.
Virtual assets and conversion points
Illicit value may begin in virtual assets or move between fiat and virtual assets. A bank may see payments to or from virtual-asset service providers, peer-to-peer transfers, card purchases linked to exchanges or customer explanations involving digital assets.
The bank should not treat every crypto-related transaction as suspicious. Legitimate investment and business activity exists. Risk comes from context, counterparties, known typologies, customer profile, transaction behaviour and regulatory status of the service provider.
Conversion points can be important because they connect different financial ecosystems. A customer receiving many unrelated transfers and immediately sending equivalent amounts to virtual-asset platforms may warrant different scrutiny from a long-term investor funding an established exchange from salary income.
Trade and placement
Trade can introduce criminal value through over-invoicing, under-invoicing, false invoicing, phantom shipments, misdescription of goods or use of third parties. In such cases the payment may appear commercially legitimate because it is supported by documents.
Banks involved in trade finance have access to additional evidence such as invoices, bills of lading, goods descriptions and counterparties. Banks processing only the payment may see less. This difference in visibility should shape the control design.
The key is not to assume that documents prove legitimacy. Documents are evidence to assess. Consistency between customer profile, goods, route, value, counterparties and payment behaviour matters.
Placement through loans and capital contributions
Criminal value can also be introduced as a loan, shareholder contribution or investment. A company may receive funds labelled as capital from an associate or offshore entity. The transaction itself can look legitimate.
The bank may need to understand the relationship between parties, the economic rationale, source of funds, source of wealth and whether the lender or investor has the capacity to provide the money.
A loan from a regulated bank is different from a large “loan” from a newly incorporated company with opaque ownership. The label in the payment message is not enough.
Third-party funding
Third-party funding is a common placement risk because value can enter an account from someone other than the customer. Third-party payments can be completely legitimate: family support, marketplace settlements, insurance payments, payroll, corporate group transfers and professional-client accounts all create legitimate third-party flows.
Risk arises when third-party funding is unexplained, inconsistent with the customer profile, unusually complex or rapidly transferred onward.
A strong bank design identifies expected third-party relationships rather than simply treating all third-party payments as suspicious.
Geographic and channel context
Placement risk changes with channel and geography. Cash-heavy economies, areas with high fraud prevalence, border regions, high-risk merchant sectors, weakly regulated intermediaries or jurisdictions with significant predicate-crime threats can affect risk assessment.
Country exposure should not be used mechanically. A payment from a higher-risk country is not automatically suspicious. The bank should understand the connection and apply its risk-based framework.
Channel context also matters. Remote onboarding combined with immediate high-value funding can raise different questions from a long-standing branch relationship. API-originated business payments can require different controls from consumer mobile banking.
Onboarding as the first placement control
The best placement detection often begins before the first transaction. KYC creates the baseline that allows later activity to be judged.
For an individual, the bank may understand occupation, income, expected account use, countries and source of funds where appropriate. For a business, it may understand activity, turnover, ownership, customers, suppliers, products, countries and payment patterns.
If the account is opened with weak information, later monitoring becomes generic and noisy. If expected activity is structured and reusable, the bank can compare actual behaviour with the customer’s stated purpose.
Monitoring design for placement risk
Monitoring scenarios for placement should target defined risks rather than broad unusualness. Cash structuring, rapid movement of newly received funds, multiple unrelated inbound payers, sudden high-value activity in a new account, merchant anomalies and unexplained third-party funding can each be monitored differently.
Segmentation is important. A restaurant should not be compared with a salaried employee. A payment institution should not be compared with a local retailer. The more meaningful the peer group, the more useful the alert.
However, segmentation can also hide risk if it is too broad. A criminal business can look normal within a poorly defined high-cash segment. Scenario governance should therefore review whether segments still make economic sense.
Fraud and AML handoff
Placement is where fraud and AML often meet. When a scam victim sends funds, the fraud team may focus on preventing or recovering the loss. The receiving bank may identify a mule account and AML may investigate the wider network.
The handoff should preserve useful intelligence: victim reports, transaction references, beneficiary details, device data, linked accounts and recovery attempts. The AML team should not need to rebuild the story from screenshots or email.
This is particularly important in instant payments because money can move onward within seconds. Real-time fraud controls and post-transaction AML monitoring need different clocks but should share relevant evidence.
Sanctions and placement
Sanctions is a separate legal discipline. If illicit value enters through a sanctioned party, ownership structure or prohibited activity, sanctions rules may require a specific legal outcome that is not based on the bank’s general ML risk score.
A low-risk customer rating cannot override a legal prohibition. Conversely, a high-risk customer is not automatically sanctioned.
Integrated financial-crime platforms must preserve that distinction.
Investigation approach
A placement investigation should reconstruct the entry of value. Where did it come from? Who sent it? What relationship exists with the customer? Was the source expected? What happened immediately afterwards? Were similar transactions observed previously? Do linked accounts show the same pattern?
A strong investigator distinguishes fact, explanation and inference. “Customer received twelve payments from unrelated individuals and transferred 95% of the value to two overseas beneficiaries within four hours” is a fact pattern. “Customer is laundering scam proceeds” is a conclusion that requires evidence.
Customer explanations should be tested against independent information where appropriate. If the customer says the funds are business revenue, does the business model support that? If the funds are a loan, is there a credible lender and agreement? If cash represents sales, does turnover align with known activity?
Scenario: newly opened retail account
A customer opens an account stating that it will be used for salary and household expenses. During the first week, the account receives fifteen transfers from unrelated individuals, mostly round amounts. The customer then sends funds to two virtual-asset platforms and makes several cash withdrawals.
The activity is not suspicious merely because virtual assets are involved. The concern comes from the mismatch between expected salary activity and actual third-party receipts, the new-account timing, rapid onward movement and lack of a clear economic relationship with senders.
The bank should examine fraud intelligence, devices, customer explanation, sender information, beneficiary relationships and whether connected accounts show similar behaviour.
Scenario: cash-intensive business
A restaurant has deposited cash daily for five years. During a festival period, deposits increase significantly. A simple threshold rule could generate alerts, but historical data and seasonal turnover may support a legitimate explanation.
Two months later, the business begins making large cash deposits at branches far from its operating location and transfers most funds to unrelated overseas companies. The risk picture has changed. The same customer now needs a different investigation.
This illustrates why monitoring should combine customer history with current behaviour.
Scenario: corporate third-party funding
A technology company receives a large transfer from an offshore entity described as “shareholder loan.” The entity is not listed as a shareholder and has no obvious relationship to the company.
The bank should not assume laundering. It should understand the lender, beneficial ownership, loan terms, source of funds, commercial rationale and whether the transaction is consistent with the customer’s corporate structure.
If the funds are quickly used to purchase property for a related individual, additional questions arise.
Data that placement controls need
Good placement detection depends on reliable data. Important elements include customer ID, account ID, onboarding date, risk rating, occupation or industry, expected activity, transaction amount and currency, counterparty, channel, branch or device information, payment references, merchant data, ownership links and case history.
The bank should preserve original values as well as normalised values. If a payment reference is shortened or a counterparty name is overwritten during processing, later investigation becomes weaker.
Data lineage should make it possible to explain which source system produced a field and how it changed.
Business analyst view
A BA working on placement controls should translate risk into testable requirements. “Detect suspicious cash” is not enough. A good requirement identifies the population, data inputs, pattern, threshold or model logic, segmentation, alert payload, decision owner, SLA, audit evidence and feedback loop.
The BA should also map exceptions. What happens if customer-risk data is unavailable? What happens if a payment arrives before KYC enrichment is complete? What happens if a cash-deposit channel sends delayed data? What happens if an account is closed while an alert remains open?
Operational edge cases are part of control design.
Control effectiveness
A placement control should be measured by more than alert volume. Useful questions include whether it identifies relevant typologies, whether investigators receive enough context, whether high-risk cases are prioritised, whether false positives are concentrated in particular segments and whether known incidents reveal blind spots.
A rule that creates 100,000 alerts but little useful intelligence may be less effective than a targeted scenario producing fewer, stronger cases.
Effectiveness also includes customer impact. Unnecessary friction can exclude legitimate customers or businesses without reducing financial crime.
Common mistakes
A common mistake is equating placement with cash only. Another is assuming that any large first deposit is suspicious. Some systems also over-rely on amount thresholds, ignore customer context or fail to connect fraud-originated payments to AML investigations.
Another mistake is treating every unusual transaction as proof of criminal proceeds. Placement controls create signals. Investigation determines what the signal means.
Finally, some banks collect detailed onboarding information but do not make it available to monitoring. That turns useful context into dead data.
Learning checkpoint
At the end of this chapter, the reader should be able to explain placement without reducing it to cash deposits, identify several modern entry points for illicit value, distinguish a red flag from suspicion, explain why customer context matters, and describe how fraud, KYC, transaction monitoring and investigation connect around the first visible movement of criminal proceeds.
Reference links
- FATF — The FATF Recommendations, amended June 2026: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF — Money Laundering National Risk Assessment Toolkit and threat factors: https://www.fatf-gafi.org/en/publications/Methodsandtrends/Money-Laundering-National-Risk-Assessment-Toolkit-Annexes.html
- INTERPOL — Money laundering and financial crime resources: https://www.interpol.int/Crimes/Financial-crime
- INTERPOL — Money mules: https://www.interpol.int/Crimes/Financial-crime/Money-mules-what-are-the-risks
Educational note: money-laundering offences, transaction-reporting thresholds, cash-reporting rules and suspicious-reporting obligations vary by jurisdiction. This chapter explains bank-control concepts and should not be used as jurisdiction-specific legal advice.
Advanced practice: entry-of-value controls across cash, accounts, cards and wallets
Placement controls become stronger when they are designed around entry points rather than around one instrument. Illicit value can enter a bank through branch cash, deposit machines, transfers from victims, merchant settlement, prepaid loading, e-money, remittance settlement, virtual-asset off-ramp activity or third-party funding. The first bank-visible event can therefore look very different depending on the predicate crime and product.
Case 1: structuring around a known threshold
A small retailer deposits cash several times a week. Over two months, deposits increasingly cluster just below an amount used internally for enhanced review. The customer also begins using three branches rather than its normal branch.
The amounts alone do not prove structuring. The investigator should examine whether sales support the cash volume, whether deposit timing follows business activity, who makes the deposits, why locations changed and what happens to funds afterward.
If the customer says branch queues caused the change and sales records support the volume, the pattern may be explainable. If depositors are unrelated individuals, values are deliberately divided and funds rapidly move to unrelated beneficiaries, the concern strengthens.
Legal reporting thresholds differ by jurisdiction. Internal system thresholds are not automatically legal boundaries, and the chapter should never imply that crossing or staying below one number determines suspicion.
Case 2: funnel-account pattern
A personal account receives cash deposits in six cities over two days, followed by a transfer to one business account. The customer lives in one city and has no declared business.
Possible explanations include family members pooling money, a community event, informal business activity or use as a funnel account. The investigation should identify depositors where data is available, customer relationships, purpose and downstream activity.
Geographic dispersion is useful because it creates a question; it is not proof. A national business with cash collectors could show the same physical pattern legitimately.
Case 3: fraud proceeds as digital placement
A beneficiary account receives five instant payments from people who later report scams. No cash is involved. From the receiving bank's perspective, criminal proceeds have entered the account directly through the payment system.
This is why a placement curriculum should not imply that laundering begins only when cash enters a bank. Fraud can transform legitimate victim funds into criminal proceeds at the point of deception and transfer.
The bank can combine victim-linked intelligence, account age, pass-through speed, beneficiaries, device data and customer explanation. If the account holder was recruited through fake employment, the financial role can be established even when intent is uncertain.
Case 4: merchant settlement
A newly acquired online merchant shows rapid volume growth and receives normal card settlement credits. Chargebacks are initially low, but the merchant's products are unclear and settlements are immediately distributed to several personal accounts.
Acquiring teams can review merchant category, website, device or terminal data, card geography, refunds, ownership and settlement accounts. AML teams can examine whether the business account is receiving proceeds inconsistent with genuine commerce.
A card settlement credit can make criminal value look like ordinary merchant revenue. The control therefore needs to connect acquiring evidence with the bank account rather than treat settlement as automatically legitimate.
Case 5: prepaid and e-money loading
A customer repeatedly loads a wallet or prepaid product from several cards and then cashes out or transfers value. Depending on product design, the bank may see only funding and redemption rather than every intermediate transfer.
Relevant context can include permitted funding sources, customer identity, product limits, device data, number of linked cards, velocity and cash-out destinations. Legitimate customers can also use multiple cards or wallets, so model design should focus on patterns inconsistent with the product's normal use.
Case 6: virtual-asset off-ramp
A customer receives a large credit from a regulated virtual-asset exchange after years of modest salary activity. The customer explains that the funds are investment proceeds.
The immediate source of funds can be established as the exchange, but the bank may need to understand the origin of the virtual assets if the value is material and risk warrants it. Exchange statements, acquisition history and customer wealth can be relevant.
The transaction should not be labelled suspicious simply because it comes from crypto. Equally, the exchange name should not be treated as proof of legitimate source of wealth.
Case 7: cash-intensive business and commingling
A car wash has real customers and genuine cash revenue. Criminal cash is gradually added to daily deposits. Total deposits remain plausible because the business has variable sales.
This typology is difficult because there may be no dramatic threshold event. The bank can compare cash deposits with card turnover, seasonality, peer behaviour, business footprint and subsequent owner withdrawals where lawful and useful.
The goal is not to audit the customer's sales ledger in every case. It is to identify material inconsistencies when monitoring or external information creates a reason to review.
Case 8: third-party account funding
A customer receives EUR 150,000 from a relative to fund a home purchase. Third-party funding can be entirely legitimate. The bank should understand the relationship and, where required by risk and policy, the relative's source of funds.
Contrast this with repeated funding from unrelated people followed by rapid onward transfer. The same technical transaction type—third-party credit—can therefore support very different risk conclusions depending on context.
Channel data quality matters
Cash deposited at a branch may capture depositor details. A cash deposit machine may capture card, device or terminal information instead. Bulk-cash services may post aggregated credits. A wallet platform may expose device and funding-source data, while a bank transfer provides structured payment-party information.
Control requirements should identify which fields exist by channel and how they map into monitoring. A scenario requiring depositor identity cannot work for a channel that does not capture it.
Customer lifecycle and early-life monitoring
Accounts created specifically to receive proceeds can show unusual behaviour immediately. Early-life monitoring can focus on activity inconsistent with onboarding information, unrelated incoming payers, beneficiary creation, device changes, cash or virtual-asset movement and sudden high velocity.
The bank should not treat all new accounts as suspicious. A new business, salary account or property transaction can become active quickly for legitimate reasons. Models should use expected purpose and peer groups.
Event-driven change from mature accounts
Placement can also occur through accounts that have existed for years. Recruitment, account rental, fraud or business changes can alter behaviour. Event-driven models can detect dormant-to-active shifts, new cash channels, payer diversity or new merchant settlement patterns.
This is often more informative than absolute thresholds because it measures change relative to the customer's own history.
Operational lineage from entry to investigation
For a suspicious entry event, the case should be able to identify channel, timestamp, customer/account, payer or depositor where available, original payment reference, amount/currency, authentication or device context, screening/fraud results and subsequent movement.
If the value arrives in an ISO 20022 payment, structured party and remittance data can improve the case, but the message does not determine whether the value is illicit. Customer history and external evidence remain necessary.
Monitoring hypothesis workshop
A good placement scenario begins with a hypothesis such as: "A personal account may be used to receive third-party fraud proceeds when it shows a sudden increase in unrelated incoming payments followed by rapid dispersal inconsistent with expected use."
Features can then include payer diversity, victim reports, time-to-outflow, beneficiary novelty, account age, device links and cash/crypto conversion. Define customer segments that should be excluded or treated separately, such as marketplaces or payment intermediaries.
Investigation conclusion standard
The analyst should state what entered the bank, through which channel, from whom if known, why it is inconsistent with the customer's legitimate profile, how it moved afterward, what explanation was received and why the concern remains or is resolved.
Avoid conclusions based on cash, crypto, high value or sub-threshold amounts alone. Placement is a concept for understanding how illicit value enters the financial system; suspicion still depends on evidence and context.
Practitioner close: placement in modern banking is broader than cash deposits
Placement is commonly associated with introducing criminal cash into the financial system. That remains important, but modern criminal proceeds can enter an account through card fraud, scams, merchant acquiring, transfers, prepaid instruments, e-money or virtual-asset conversion. A bank should therefore think about the entry of illicit value into the relationship or controlled financial channel, not search only for physical-cash behaviour.
Case lab: structuring around cash controls
A customer makes frequent cash deposits below an internal monitoring threshold using several branches. The pattern can be consistent with structuring, but the analyst should not conclude that solely because deposits sit below a round amount. The investigation should consider business type, expected cash turnover, branch geography, deposit frequency, denomination where available, related accounts and subsequent movement.
Controls should avoid publishing or operationalising a simple “below X equals suspicious” rule. Criminal behaviour adapts, and legitimate customers can naturally transact below thresholds.
Funnel-account behaviour
A personal or business account receives cash or transfers from geographically dispersed sources and then consolidates funds for onward movement. Funnel patterns can be useful signals, particularly where the customer has no credible reason to collect value across those locations.
The bank should compare deposit and payment geography with the customer’s actual business or personal network. A national retailer, charity or marketplace can legitimately receive dispersed payments. Geography gains meaning only in context.
Digital fraud as entry of criminal value
When scam victims send authorised push payments to a mule account, the proceeds arrive electronically. There may be no observable cash placement stage. The receiving account can nevertheless represent the point where criminal value enters that account network before rapid transfer, cash-out or conversion.
This is why fraud intelligence can be a critical AML input. Victim reports, device data and payment timing can establish the source of incoming funds more clearly than a generic transaction-monitoring rule.
Merchant and acquiring channels
Criminal proceeds can also appear through merchant settlement. A merchant account showing sales inconsistent with the stated business, unusual refund behaviour, third-party funding or sharp changes in turnover may warrant investigation.
Legitimate merchants can grow rapidly or change sales channels, so the bank should compare settlement behaviour with business model, acquiring data and credible commercial evidence rather than infer laundering from growth alone.
Prepaid, e-money and wallets
Prepaid instruments and wallets can provide legitimate financial access and convenience. Risk can arise from rapid loading and unloading, multiple funding sources, third-party funding, linked instruments or behaviour inconsistent with the customer’s expected use.
The investigation should understand product limits and data visibility. A bank servicing an e-money issuer may see settlement-level data while the issuer sees individual wallet holders. Control responsibilities should reflect that architecture.
Virtual-asset off-ramp
A customer receiving fiat from a VASP may be selling legitimate investments or receiving illicit proceeds converted from virtual assets. The bank should not treat every crypto-related credit as suspicious. Customer profile, source-of-wealth history, VASP risk, transaction size and pattern, blockchain evidence where available and customer explanation can help distinguish hypotheses.
Final practitioner checkpoint
A strong placement investigation recognizes cash, transfers, fraud proceeds, merchant settlement, prepaid/e-money and virtual-asset conversion as different ways illicit value may enter banking channels. It avoids universal thresholds, tests legitimate explanations and connects entry behaviour with what happens next.
Practitioner masterclass: placement in real bank operations
In the classic money-laundering model, placement describes the introduction of illicit proceeds into the financial system. That definition remains useful and should not be stretched until every suspicious inbound payment is called placement. Modern banking creates a second, operational question: where does potentially criminal value first become visible to this bank’s customers, accounts, products or payment controls? These two lenses overlap, but they are not identical.
For cash-generated crime, the classic model can be very literal: physical proceeds are deposited or converted into financial value. For digital fraud, however, the victim’s payment may already originate inside the banking system. The receiving bank may be seeing criminal proceeds for the first time even though the wider financial system did not experience a traditional cash-placement event. Analysts should therefore use the three-stage model as a teaching aid while describing the actual transactions precisely.
Placement becomes operational when a bank connects the customer baseline to the first visible movement of value. The most useful way to study it is not to memorise a list of typologies, but to practise distinguishing normal product use from behaviour that requires explanation.
A bank should start with the customer’s expected economic activity. For a salaried individual, salary credits, household spending and occasional family transfers may be normal. For a restaurant, daily cash deposits and card settlements can be normal. For a payment institution, very high pass-through volumes can be normal. Placement controls therefore need a customer model before they can interpret a transaction model.
A control map from onboarding to investigation
At onboarding, the bank establishes identity, purpose, occupation or business, expected activity and relevant ownership. At first funding, it sees how value actually enters. Monitoring compares observed behaviour with the baseline. Fraud intelligence, sanctions screening and other controls contribute additional context. Investigation then decides whether the activity can be reasonably explained or requires escalation.
The quality of each later step is limited by the quality of earlier data. If the account purpose is recorded only as free text, monitoring cannot use it consistently. If a business’s expected cash turnover is never captured, cash scenarios become generic. If beneficial owners are not stored as structured relationships, linked-party analysis is weakened.
Cash-deposit case study
Consider a customer who operates three convenience stores. Daily cash deposits vary between EUR 4,000 and EUR 12,000, with higher amounts on weekends. A threshold-only rule might generate frequent alerts. Historical merchant turnover, branch locations and tax information may show the pattern is commercially plausible.
Now suppose deposits begin appearing at branches hundreds of kilometres away, are made by unrelated individuals and are followed by same-day international transfers to companies unrelated to the stores. The risk changes because the pattern no longer matches the business model.
An investigator should document the change rather than simply label the customer “cash intensive.” The useful question is what changed, when it changed and whether the customer can explain it.
Digital-fraud placement case study
A personal account opened for salary use receives seven instant payments from unrelated victims over two hours. Funds leave within minutes to a virtual-asset exchange and two other personal accounts.
From the receiving bank’s perspective, this is a point at which fraud proceeds become visible in its environment, even though the funds were already inside the financial system at the sending bank. The bank should combine victim reports, account age, device information, payer diversity, pass-through speed and beneficiary relationships rather than force the event into a rigid stage label.
If the customer says the funds came from online sales, the bank can test that explanation against marketplace evidence, transaction descriptions and historical activity.
Merchant-placement case study
A newly onboarded online merchant reports expected monthly turnover of EUR 25,000. Within three weeks it processes EUR 300,000 of card sales, mostly round-value card-not-present transactions from several countries, followed by refunds to different cards.
The acquiring bank should consider fraud, merchant abuse and laundering risk together. The merchant category, website, product offering, chargebacks, settlement accounts and beneficial ownership can all help determine whether the activity is commercially plausible.
Third-party funding case study
A corporate customer receives EUR 1.5 million from a foreign entity labelled “investment.” The sender is not recorded as a shareholder or known group company. The customer says it is a future investor.
The bank should understand the investor, beneficial ownership, source of funds, agreement and commercial rationale. The transaction may be completely legitimate, but the label “investment” should not end the analysis.
Designing a placement scenario
A good scenario starts with a defined risk hypothesis. For example: newly opened retail accounts receiving multiple unrelated credits followed by rapid onward transfer. The scenario should define the population, data inputs, time window, aggregation logic, customer segments, thresholds or model score, exclusions, alert payload and review process.
Testing should include legitimate edge cases. A student collecting group-trip payments may resemble a mule. A small marketplace seller may have many unrelated payers. The scenario should help investigators distinguish these patterns rather than simply generate volume.
When thresholds fail
Thresholds are useful for computational efficiency but dangerous when treated as meaning. Criminals can transact below thresholds, and legitimate customers can transact above them. A threshold should trigger review, not create a conclusion.
Scenario governance should examine distribution around thresholds, false-positive concentration and whether known cases would have been detected. If suspicious cases repeatedly sit below the threshold, the control may need redesign.
Branch and digital channels
Placement controls should not assume one channel. Cash may enter through branches or ATMs, while digital fraud proceeds can first become visible to a receiving bank through instant payments. A customer can use both.
Channel data should be combined at customer level where legally permitted. Fragmented monitoring can miss a pattern where cash enters through one channel and exits through another.
Payment repair and placement
Inbound payments can be repaired when data fails validation. If name, account or address fields are changed, investigators need both original and amended data. Repaired information can affect sanctions screening, fraud analysis and later case reconstruction.
A strong requirement preserves who changed the data, why, when and whether re-screening occurred.
Customer communication
Placement investigations can lead to questions about source of funds. Communication should be clear enough for legitimate customers to respond without revealing protected suspicious-reporting information.
A request such as “Please provide evidence explaining the source and purpose of these deposits” is different from telling the customer that the bank suspects money laundering.
The exact communication rules depend on jurisdiction and policy.
Quality assurance exercise
Review an alert where the investigator closed the case because “customer provided invoice.” Ask whether the invoice explains the payer, goods or services, amount, date and relationship to the customer’s business. Ask whether the document was independently corroborated where risk required it. A document should resolve uncertainty, not merely exist in the file.
BA delivery exercise
Write a requirement for rapid movement of newly received funds. Include the customer population, account age, inbound aggregation, pass-through percentage, time window, excluded business types, data quality handling, alert fields, case-linking logic and audit trail. Then write the negative test cases: missing customer segment, duplicate payment, reversed transaction, delayed posting, repaired beneficiary and closed account.
The exercise demonstrates why financial-crime requirements are operational specifications rather than policy slogans.
Final practitioner test
A strong learner should be able to look at the same EUR 10,000 credit in five different customer contexts and explain why the control response differs. The amount alone is rarely the answer. The account purpose, source, relationship, timing, subsequent movement, channel and evidence create the meaning.
The learner should also be able to state the classic meaning of placement accurately while recognising that a bank’s first observation of criminal proceeds may occur later in the wider movement of value. That distinction keeps the teaching model useful without letting it distort the facts.
60-minute mastery extension: placement and entry of illicit value
This extension is designed to make the chapter a minimum 60-minute guided learning experience. Spend about 25 minutes on the core lesson and diagrams, 15 minutes on the channel cases, 10 minutes on scenario design and 10 minutes on the final evidence test.
Placement starts with the form of the proceeds
Traditional placement risk is easiest to understand when criminal proceeds exist outside the formal financial system—especially physical cash—and must be introduced into accounts, businesses, money-service channels, stored-value products or other financial instruments. Modern financial crime also creates proceeds directly inside digital channels. A scam victim can send funds from one bank account to another without any physical-cash stage. The receiving bank is still seeing potentially criminal value, but analysts should describe the event precisely rather than stretch the classic definition until every inbound suspicious payment becomes "placement."
The useful control question is: how did the value enter this customer relationship, product or bank-visible channel, and does that entry make economic sense?
Current FATF typology work reinforces this wider operational lens without changing the legal definition of money laundering. Its February 2026 paper on cyber-enabled fraud describes the scale of fraud-generated proceeds and the importance of following those proceeds through the financial system. Its September 2026 report on professional money laundering, underground banking and hawala describes increasing use of bank accounts, fintech platforms, payment service providers, virtual IBANs, prepaid instruments and virtual-asset wallets as entry or exit points in laundering networks. These reports are typology and risk material, not jurisdiction-specific legal rules; banks still apply the law, regulatory expectations and reporting framework that govern each legal entity.
Channel case: cash-intensive business
A restaurant deposits EUR 8,000–15,000 in cash most weekends. The pattern is consistent with its location, merchant-acquiring turnover and historical activity. Six months later, cash deposits double, begin occurring at branches in several distant cities and are made by unrelated people. Same-day international transfers also increase.
The relevant signal is not cash alone. The risk comes from a material change in geography, depositor identity, volume and subsequent movement. A strong investigation compares current behaviour with the business model and tests plausible explanations such as expansion, new locations or legitimate changes in customer mix.
Channel case: merchant acquiring
An online merchant reports expected monthly turnover of EUR 40,000 but processes EUR 500,000 within a month through round-value card-not-present transactions. Refunds are sent to different cards and settlement funds move rapidly to unrelated companies.
The acquiring bank should consider fraud, merchant abuse and laundering together. Website content, merchant category, chargebacks, customer complaints, beneficial ownership and settlement behaviour can help determine whether the activity is commercially plausible. A high turnover increase can be legitimate; the investigation should test the business explanation rather than assume criminality.
Channel case: new retail account
A salary account opened two weeks ago receives transfers from eight unrelated people and sends 95% of value onward within minutes. Two senders later report scams. The receiving bank should combine victim-linked information, account age, payer diversity, device history, beneficiary relationships and customer explanation. The account may be a complicit mule, recruited or deceived mule, or compromised account. Those possibilities require different customer treatment.
Structuring and threshold behaviour
Repeated activity just below a threshold can be relevant, but threshold proximity does not prove intent to evade reporting or monitoring. Analysts should examine timing, locations, depositors, historical behaviour and what happens to the funds afterwards. Criminals can also transact above thresholds, and legitimate customers can transact below them.
Control design should therefore avoid making the threshold itself the meaning. A threshold is a computational trigger; investigation provides context. Legal cash-reporting and suspicious-reporting rules are jurisdiction-specific. For example, United States CTR aggregation rules and Australian TTR rules are not identical, even though both jurisdictions treat deliberate structuring to avoid reporting as a serious concern. A global course should teach the principle and make the local legal rule explicit when using a numeric threshold.
Source-of-funds exercise
For five entry types—cash deposit, incoming salary, investment proceeds, shareholder loan and online-sales revenue—write what evidence could make the source credible. Then write what would cause the bank to look deeper. A bank statement may establish the immediate sending account but not the underlying economic origin. An invoice may support a commercial explanation but not prove the service occurred.
The depth of evidence should remain proportionate to risk.
Scenario-design exercise
Design a scenario for newly opened personal accounts receiving unrelated third-party credits followed by rapid onward movement. Define population, account-age window, inbound aggregation, pass-through ratio, time window, exclusions, customer segmentation, alert payload and review process. Add legitimate test cases: marketplace seller, student collecting group expenses, charity fundraiser and salary account receiving family support.
Then define data-quality failures. What happens if customer segment is missing? If one payment is duplicated? If a reversal occurs? If the account is already closed? If transaction timestamps use different time zones? These details determine whether the control works in production.
Customer impact
Placement controls can create significant friction for cash-intensive businesses, migrants receiving family funds, small merchants and newly established companies. Proportionality matters. Request the evidence needed to resolve the risk question; do not collect documents simply because the customer is in a category labelled high risk.
Where concerns remain unresolved, the bank can escalate, restrict or report according to the applicable framework. The case narrative should explain the evidence, not just the customer category.
Final evidence test
For each event, state what is fact and what is inference: cash deposited at three branches; cash deposited by unrelated third parties; multiple victim-linked credits; transfer to a crypto exchange; declared business turnover exceeded; customer provides an invoice; customer refuses to explain source; and funds move out within ten minutes.
A strong learner should finish able to identify the first visible movement of value, understand why entry-channel context matters, and design controls that find meaningful patterns without treating cash, crypto or new accounts as proof of crime.
Worked case: the funnel network across three cities
A monitoring scenario designed around pass-through ratios fires on eleven personal accounts in different branches across three cities. Each account receives multiple small incoming transfers from geographically dispersed senders, aggregates them over two to three days, and forwards nearly the entire balance to one of two business accounts held at another institution. The senders have no apparent connection to the account holders: different surnames, different cities, no shared transaction history. Total throughput over two months reaches an illustrative 3.4 million.
The investigation treats the eleven accounts as a potential collection network rather than eleven unrelated alerts. Sustained many-from-unrelated-senders activity followed by concentrated onward movement can be a meaningful structural indicator when it conflicts with expected account use, but legitimate personal or micro-business activity can sometimes produce similar shapes. Each element therefore needs testing. The account holders' explanations are collected first and recorded accurately: most claim online sales, freelance work or community collections, but none produces platform records, client lists or collection documentation commensurate with the volumes. Device analysis reveals shared device fingerprints across four accounts whose holders deny knowing each other. Two account holders share a residential address with individuals previously exited for suspected mule activity.
The destination analysis is equally important. The two business accounts describe themselves as marketing and logistics firms, but neither shows payroll, tax payments or genuine supplier networks; their activity consists almost entirely of receiving the funnel transfers and forwarding them abroad within hours. Taken together, those facts support a working hypothesis of organised collection and consolidation rather than opportunistic misuse of one compromised account. The response should follow the applicable legal and policy framework: coordinated risk controls where permitted, network-case treatment, organiser identification as an investigative objective, reporting where the legal suspicion threshold is met, and intelligence sharing only through lawful channels.
The scenario-design lesson is specific. Funnel detection can combine inbound-sender diversity with outbound concentration and pass-through measures over suitable time windows; single-day or single-account rules may miss networks designed to fragment activity. Legitimate-exclusion logic must be built in from the start: charity fundraisers, community collections, marketplace sellers and gig-economy workers can all exhibit funnel-like features, and the scenario should incorporate distinguishing evidence such as platform corroboration, historical consistency and sender-relationship plausibility rather than relying on analyst triage to clear predictable volumes. A funnel scenario without useful segmentation can create excessive false positives; a scenario with poorly tested exclusions can create blind spots. Both failure modes are measurable, and the tuning record should show the trade-off explicitly.
Virtual-asset off-ramps: where digital value re-enters banking
A placement investigation may reach the boundary where virtual assets convert back into fiat currency through exchanges, brokers or peer-to-peer arrangements and then enter bank accounts. The receiving bank may see an incoming transfer from a virtual-asset service provider with limited information about the earlier crypto provenance. The assurance that can reasonably be drawn from the immediate sender depends on the provider, the customer, the transaction history and the bank's lawful access to supporting evidence; it should never be inferred from the transfer amount alone.
Provider assessment can consider regulatory standing and supervision in relevant jurisdictions, customer due-diligence controls, transaction-monitoring capability, available blockchain analytics and responsiveness to lawful information requests. A well-supervised provider with demonstrable controls is relevant context, but it is not proof that a particular customer's underlying source of funds or wealth is legitimate. Conversely, an unlicensed or opaque provider may increase risk without proving that the customer has committed an offence. Treatment should follow the bank's documented risk methodology and applicable law rather than a simple safe-versus-unsafe exchange list.
Customer-level analysis complements provider assessment. A customer whose profile includes documented investment history and gradual accumulation presents a different proposition from one with no plausible prior crypto involvement receiving a large first-time exchange transfer. Where materiality and risk warrant it, the bank may seek evidence of acquisition or source of wealth such as purchase records, mining or business activity, employment income, tax records where appropriate, or other evidence consistent with the customer's explanation. Blockchain history, where lawfully and reliably available, can corroborate parts of the narrative but does not replace customer due diligence or legal analysis.
Record-keeping for off-ramp decisions should capture the provider assessment, the customer-profile consistency analysis, the evidence reviewed and the rationale for the conclusion. Weak or undocumented reasoning makes later investigation and supervisory assurance harder, especially if today's accepted transfer later becomes part of a wider network case.
Cash-recycling ATMs: placement through automation
Cash-recycling machines can accept deposits and, depending on design, reuse deposited notes for later withdrawals. Their financial-crime risk differs from a teller channel because the depositor may not interact with staff and transaction patterns can be fragmented across machines, times and accounts. Electronic transaction records still provide an audit trail; what is reduced is the direct human observation available at a staffed counter, while note-level physical provenance may be harder to interpret once cash is recycled.
Potential controls combine machine-level analytics with network-level aggregation. Per-machine analysis can identify unusual velocity, repeated deposits near relevant internal triggers, use of the same card or account across distant machines, or repeated third-party deposit behaviour where the channel captures enough information. Cross-machine aggregation joins activity by card, account, authenticated user, device or depositor identity where available so that fragmentation across terminals does not hide the wider pattern. Cash-handling information such as denomination mix, counterfeit detection and servicing volumes can provide additional context, but these signals should be used carefully because legitimate cash use varies significantly by location and customer segment.
Machine deployment and limit design are also part of the risk assessment. Deposit limits, identification controls, real-time monitoring and review thresholds should reflect product capability, customer populations and location risk within the applicable legal framework. A uniform setting across every machine may be operationally simple but can over-control low-risk locations and under-control exposed ones. Servicing data—such as unexpectedly frequent replenishment or emptying relative to legitimate demand—can supplement transaction monitoring, but it is an investigative clue rather than proof of placement.
Cross-border cash movement and the bank's role
Physical cash crossing borders, whether carried by couriers, concealed in goods or declared through formal channels, interacts with banking controls at the entry and exit points even where the movement itself avoids the financial system. Cash-declaration regimes set thresholds and obligations by jurisdiction. Declaration data can be useful intelligence where lawfully available, but it is neither a complete map of cash movement nor proof that declared funds are legitimate.
The bank's role concentrates on the account activity surrounding physical movement: withdrawals inconsistent with the customer's profile before travel, deposits inconsistent with the profile after travel, unexplained foreign-currency cash, or business cash patterns that correlate with cross-border logistics rather than the stated domestic activity. Cash-intensive businesses near borders, transport hubs and ports may justify corridor-aware analysis where risk assessment supports it. A bureau de change, remitter or logistics company near a border can be entirely legitimate; concern grows when volumes, customer flows, depositor identities or downstream transfers do not make economic sense.
Trade-related cash movement, where cash travels with or as settlement for goods, adds misdeclaration and valuation questions examined in the trade-laundering chapter. The placement-control contribution is recognising when cash deposits might represent the domestic end of a cross-border physical-movement chain rather than ordinary domestic revenue. Currency mix, cash-handling observations, transaction geography and deposit timing can support that hypothesis when combined with customer and commercial evidence.
Event-driven placement monitoring: dormancy, change and first-party fraud
Static placement scenarios can miss the temporal dimension because meaningful risk sometimes appears when behaviour changes. A dormant account that suddenly receives material third-party credits and moves the value onward can be a useful placement or mule-risk signal, but it is not inherently suspicious: inheritance, property transactions, relocation, new employment or legitimate business activity can also reactivate an account. The control should therefore compare the reactivation event with the customer profile, source of funds, linked parties and subsequent movement rather than treat dormancy itself as a conclusion.
Profile-change events can also matter: employment-status changes coinciding with new credit patterns, address changes followed by different transaction geography, or business-purpose changes preceding new products and counterparties. Each change is individually legitimate. The control question is whether the new transaction pattern coherently matches the new profile and whether evidence supports the explanation.
First-party fraud, where a customer misrepresents facts to obtain funds or services, can interact with placement analysis as an alternative or concurrent hypothesis. Bust-out behaviour can involve apparently normal account build-up before extraction; the placement-relevant question is whether inbound funds themselves derive from criminal sources or merely precede the fraud. False or synthetic identity at origination can mean that the customer baseline was unreliable from the start, so an investigation should review the original verification evidence and linked identities. Fraud classification and AML suspicion should remain distinct even when the same account appears in both workflows.
Worked case: funnel activity in a suburban branch network
Over five weeks, a regional monitoring team notices an illustrative 1.9 million in cash deposits spread across fourteen branches, all credited to three business accounts held by two apparently unrelated companies: a wholesale food distributor and a logistics firm. Individual deposits sit below an illustrative internal review threshold, arrive in the late afternoon, and are made by six individuals whose identification documents show different addresses but sequentially close document numbers. Within two days of each deposit cluster, the funds are consolidated by internal transfer and wired to an overseas supplier that was onboarded as a trade counterparty nine months earlier.
The first analytical task is to resist the obvious label. The pattern resembles structuring, but resemblance is not evidence, and wholesale food distribution can legitimately be cash-heavy. The team therefore builds the economic picture before drawing conclusions: declared turnover for both companies, expected cash ratios for the sector in this region, the commercial rationale for the overseas supplier, pricing plausibility for the goods supposedly purchased, and whether the supplier shows credible commercial substance and shipment history.
The evidence accumulates against the innocent explanation in layers. Declared turnover would need to triple to support the observed cash. The depositor identities, checked against account mandates, show that none of the six individuals is an employee, signatory or known associate of either company; two appear as account holders elsewhere in the bank with dormant-to-active patterns of their own. The overseas supplier shares a corporate service provider with multiple other entities, has no verifiable shipment records for the claimed goods corridor, and its account at the beneficiary bank was opened within the last year. Meanwhile the internal consolidation-and-wire rhythm is unusually regular for the stated purchasing cycle.
Alternatives are closed explicitly. The companies claim the cash represents festival-season sales; the team tests this against prior-year seasonality and available business evidence. A claim that the depositors are collection agents is tested against agency records and account relationships. If those explanations remain unsupported and the linked evidence continues to point in the same direction, the case can be treated as a potential placement network using businesses as entry points. Restrictions, customer contact, external reporting and interbank information sharing must follow local law and bank policy, including any confidentiality or tipping-off constraints.
The control lesson extends beyond the case. Branch-fragmented deposits can defeat per-branch monitoring, so customer-level aggregation should span channels where data and law permit. Fixed thresholds can be gamed, so behavioural analysis can supplement them. And onboarding that records only "cash-intensive business" without a usable expectation for cash volumes, locations or deposit channels leaves monitoring with little meaningful baseline. Expected activity should be sufficiently structured to support comparison without pretending it can predict every legitimate transaction.
Third-party funding: documentation standards that decide cases
Third-party funding—value entering a customer's account from someone other than the customer—is common in legitimate banking as well as in laundering typologies. A defensible standard distinguishes categories rather than treating the presence of a third party as suspicious by itself. Family support and gifts may require evidence of the relationship, purpose and funder's capacity proportionate to amount and risk. Business funding from investors or group entities can require investment documentation, the funder's identity, beneficial ownership and source information appropriate to the risk. Settlement of genuine obligations can be tested against the underlying agreement, invoice and customer profile.
Each category needs a defined escalation for refusal or inability to document. A customer who cannot explain a material third-party inflow is not automatically a criminal, but an unexplained inflow can remain a risk finding that requires further review and, where the legal suspicion threshold is met, reporting. Repetition can increase concern when a pattern of new unrelated funders remains unexplained; monitoring should therefore be capable of aggregating third-party funding patterns rather than treating every credit as isolated. Case narratives should record the customer's explanation accurately and then show how the evidence supports, contradicts or leaves uncertainty around it.
Prepaid, e-money and wallet loading as entry points
Stored-value products can convert cash or account funds into prepaid balances, e-money or wallet value that can then move, be spent, transferred or redeemed. The placement-relevant controls sit at three points. Issuance and loading controls establish the customer and permitted funding sources and apply limits appropriate to the product and applicable law. Usage monitoring looks for loading and transfer patterns inconsistent with expected use. Redemption and off-ramp controls examine conversion back into cash, bank transfers or virtual assets, particularly where the product supports rapid or cross-border movement.
Product design is therefore part of the placement-risk assessment. Products that combine limited identity information, third-party loading, meaningful reload capacity, transferability and cash-out can create greater exposure and may be subject to specific legal restrictions or due-diligence requirements depending on jurisdiction. Limits and controls should reflect the product's actual capability rather than assume transaction monitoring can compensate for weak design. Where distributors or agents sell or load products, the institution should understand the control responsibilities, data capture and oversight across that distribution chain.
Branch, ATM, digital and agent channels compared
Placement controls differ by channel because each channel observes different evidence. Branches can observe identity documents, the person presenting the cash, companions and some physical characteristics of the transaction. Teller training on structuring behaviour, third-party deposits and document anomalies remains useful when framed as observation and escalation rather than accusation. ATMs and cash-deposit machines rely more heavily on authenticated instruments, terminal data, account relationships, timing and geographic patterns. Digital channels add device, session and velocity evidence that can help identify onboarding fraud, account takeover or coordinated mule activity.
Agent networks can introduce different visibility and control challenges unless the institution deliberately extends standards and data requirements to them. Contracts and operating procedures should address identification, record-keeping, cash handling, escalation and audit rights as applicable. Agent activity should feed appropriate monitoring, and agent-level analytics can identify patterns such as repeated split deposits or systematically incomplete records. The objective is to map controls to the way value actually enters the institution, not merely to the bank's internal organisation chart.
Boundary case: criminal value already inside the financial system
When fraud, bribery or cybercrime generates proceeds directly as bank money, there may be no observable cash-placement event. The receiving bank should focus on provenance, account role and subsequent movement rather than force the case into a physical-cash model. Placement remains useful vocabulary; it is not a prerequisite for identifying laundering risk.
2026 practitioner enhancement: placement beyond cash
Classic placement describes introducing illicit proceeds into the financial system, often as cash. A bank also needs a separate operational lens: where potentially illicit value first becomes visible within its own customer relationships and channels. Cash remains important, but modern banks also encounter criminal value through fraud payments, merchant settlement, prepaid and e-money products, money-service businesses, virtual-asset conversion, third-party transfers and accounts opened or repurposed to receive proceeds.
The practical control question is therefore: how did the value enter the institution's view, and does the entry pattern make sense for this customer, product and channel? A bank that monitors only traditional cash placement will miss important contemporary entry patterns. Equally, not every suspicious inbound payment should be forced into the classic placement label; the transaction facts should be described precisely.
FATF's February 2026 paper on cyber-enabled fraud is particularly relevant because fraud proceeds can become criminal value inside digital payment rails without a preceding physical-cash stage. FATF's September 2026 report on professional money laundering, underground banking and hawala also describes increasing links between informal value-transfer networks and formal-sector bank accounts, fintech platforms, payment service providers, virtual IBANs, prepaid instruments and virtual-asset wallets. These are typology findings, not universal legal rules.
Cash placement and structuring
Structuring can involve intentionally breaking activity into smaller transactions to avoid a reporting requirement, record-keeping requirement, control or attention. A series of transactions below a known threshold can be relevant, but the amount pattern alone does not prove intent. Analysts should consider timing, locations, depositors, customer occupation or business model, subsequent movement and whether the transactions appear artificially divided.
Legal cash-reporting thresholds and aggregation rules differ by jurisdiction. Internal monitoring thresholds are also not the same thing as statutory reporting thresholds. Two examples show why a global course must avoid one universal number. In the United States, FinCEN explains that certain same-business-day currency transactions are aggregated for CTR purposes when the institution has the required knowledge and the cash-in or cash-out total exceeds USD 10,000. In Australia, AUSTRAC's current guidance treats each individual cash transaction of AUD 10,000 or more as a TTR event and separately requires attention to suspected structuring. Those examples should be taught as jurisdiction-specific rules, not global AML thresholds.
Funnel-account behaviour is another useful pattern. Cash or transfers can be deposited by different people in multiple locations and then consolidated or moved elsewhere. The suspicious feature is not geographic distance by itself. The bank should ask whether the customer has a plausible reason for receiving deposits from those locations and parties, how the pattern compares with expected activity and what happens to the funds afterward.
Digital placement through fraud and mule accounts
For scam or account-takeover proceeds, the receiving bank can observe criminal value as soon as victim funds arrive at a beneficiary or mule account. The payer's funds may have been legitimate before the fraud event; after the deception and transfer, the receiving institution may be holding proceeds of crime. This makes receiving-account intelligence important in real-time payment ecosystems.
Useful signals can include multiple unrelated incoming payments, rapid onward transfer, new beneficiaries, sudden use of virtual-asset services, immediate cash withdrawal, account age, device or credential changes, prior fraud complaints and links to known mule networks. Each signal is contextual. A marketplace merchant, payroll service or payment institution may legitimately receive many unrelated payments and pass funds onward quickly.
INTERPOL's public money-mule material is useful for explaining recruitment through job, romance, investment and impersonation scams, but the legal culpability of a particular mule depends on evidence and local law. Banks should distinguish customer vulnerability, possible deception, account compromise and knowing facilitation rather than assume identical intent across all mule cases.
Merchant acquiring, cards and payment acceptance
Criminal value can also enter through merchant infrastructure. A sham or compromised merchant may process fabricated sales, card-not-present activity, refund abuse or payments that disguise the real source or purpose. Settlement into a business account can then resemble ordinary commercial revenue.
Acquiring controls can connect merchant onboarding, merchant category, terminal or device information, transaction geography, refund and chargeback behaviour, settlement accounts and beneficial ownership. Merchant turnover by itself is not enough. A legitimate rapidly growing merchant can show large changes, while a criminal merchant may remain deliberately small.
Prepaid, wallets and e-money
Prepaid instruments and wallets can support legitimate inclusion and low-value payment use. Risk can increase where products allow rapid loading, transfer, cash-out or cross-border movement with limited identity or transaction visibility. Product limits, permitted funding sources, customer type, device data, distribution model and cash-out patterns all affect risk and may also be subject to jurisdiction-specific legal requirements.
The control should follow the economic value across channels where law and data permit. Cash can load a wallet; a wallet can fund another account; bank funds can be converted into virtual assets; virtual assets can return to fiat. Product silos can hide the wider chain.
Cash-intensive businesses and commingling
A cash-intensive business can mix legitimate revenue with illicit cash. The correct analysis is not "cash business equals high risk" but whether observed cash is plausible for the declared activity. Useful comparisons can include card turnover, seasonal patterns, store footprint, peer behaviour, tax or merchant information where lawfully available, local operating conditions and changes in the business model.
A sudden increase can be legitimate after expansion or a change in customer behaviour. Concern grows when the explanation, supporting evidence and related account activity do not align.
Third-party deposits and source of funds
Third-party funding is common in legitimate life events and business arrangements. Family members fund purchases, group companies centralise treasury activity, agents collect cash and payment institutions settle for customers. The presence of a third party is therefore a question to understand, not a conclusion.
Investigators should identify the relationship, economic rationale and whether the customer is acting as an undeclared intermediary. Repeated receipt of funds for apparently unrelated parties followed by rapid onward movement can be more significant than a single well-explained third-party transfer.
Cross-border entry and correspondent visibility
A bank may first encounter illicit value through a cross-border transfer after the value has already passed through other institutions. The bank should avoid claiming that it observed the original placement if it only sees a later leg. It can still assess the customer, counterparty, source-of-funds explanation, payment purpose, routing and subsequent behaviour.
Structured payment data improves traceability only when populated, mapped and preserved. ISO 20022 can carry richer party and remittance information, but a pacs.008 or any other message does not itself identify money laundering. Detection arises from combining payment content with customer, account, behavioural, network and external intelligence.
Operational workflow
A practical placement investigation can be structured as: identify the entry event → establish the source and payer or depositor → compare with expected customer activity → review channel and authentication or device evidence → trace immediate onward movement → expand to related accounts and beneficiaries → obtain reasonable explanations or supporting evidence → document facts and uncertainty → decide monitoring, restriction, fraud action and SAR/STR escalation according to law and policy.
The workflow should preserve original transaction identifiers and timestamps. If data is repaired or enriched, both original and amended values should remain available so an investigator can reconstruct what was screened and processed at each point.
Basel Committee guidance provides the bank-wide risk-management context: AML/CFT risks should sit within the bank's overall risk-management framework, with internal procedures for detecting and reporting suspicious transactions and with second-line monitoring of control performance. Wolfsberg's 2025 work on effective monitoring is useful as an industry framework for outcome-focused monitoring, responsible model transition, validation and explainability; it is not a substitute for binding local law or supervisory requirements.
References and further reading
Global standards and bank risk management
- FATF — The FATF Recommendations, current Standards including the June 2026 amendments: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- Basel Committee on Banking Supervision — Anti-money laundering and counter-terrorist financing, Consolidated Guidelines AFS10, published 1 January 2026: https://www.bis.org/committees/bcbs/basel-consolidated-guidelines/module/afs/10
- Wolfsberg Group — Second Statement on Effective Monitoring for Suspicious Activity, 27 August 2025: https://wolfsberg-group.org/news/the-wolfsberg-group-publishes-its-second-statement-on-effective-monitoring-for-suspicious-activity/
Current typologies relevant to placement and entry of value
- FATF — Cyber-Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks, 24 February 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/cyber-enabled-fraud-digitalisation-ml-tf-pf-risks.html
- FATF — Investigating Professional Money Laundering, Underground Banking, and the Use of Hawala and Other Similar Service Providers, 3 September 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/pml-underground-banking-hawala-hossps.html
- FATF — Money Laundering Through the Physical Transportation of Cash: https://www.fatf-gafi.org/en/publications/Methodsandtrends/Money-laundering-through-transportation-cash.html
- FATF — Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing: https://www.fatf-gafi.org/en/publications/Methodsandtrends/Virtual-assets-red-flag-indicators.html
- FATF — Money Laundering National Risk Assessment Guidance, updated 28 August 2025: https://www.fatf-gafi.org/en/publications/Methodsandtrends/Money-Laundering-National-Risk-Assessment-Guidance.html
- INTERPOL — Money mules: what are the risks?: https://www.interpol.int/Crimes/Financial-crime/Money-mules-what-are-the-risks
Jurisdiction-specific cash-reporting examples — do not universalise
- FinCEN, United States — Frequently Asked Questions Regarding the FinCEN Currency Transaction Report: https://www.fincen.gov/resources/frequently-asked-questions-regarding-fincen-currency-transaction-report-ctr
- AUSTRAC, Australia — Threshold transaction reports and structuring guidance: https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/reporting-us/threshold-transaction-reports
- AUSTRAC, Australia — Suspicious matter reports, including a current structuring/mule example, updated 9 September 2026: https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/reporting-us/suspicious-matter-reports
These sources support the learning concepts in this chapter. Reporting thresholds, aggregation rules, suspicion standards, filing deadlines, confidentiality rules and customer-action powers differ by jurisdiction and legal entity. Local law and approved bank policy govern the operational decision.