A practitioner guide to the 12 money laundering red flags, grouped by where each one surfaces, why the flags that matter most now appear long after onboarding, and what to do when one shows up.
A customer opens an account and passes every check you run, because at that moment there is nothing wrong with them. Six weeks later, the same account is taking money in from people they have never met and passing it straight out again. Money laundering red flags like that one never appear on an application form, so no amount of rigour at onboarding would have caught it.
That pattern now has its own reporting category in the UK, and the volume behind it is significant. According to Cifas, the UK’s fraud prevention service, more than 106,000 misuse of facility cases were recorded to the National Fraud Database in 2025, a rise of 43% and one of the sharpest increases of any fraud type. Misuse of facility is the category used when an account is opened honestly and later turned to criminal use, and while those cases climbed, identity fraud filings over the same period fell 3%.
This guide sets out the 12 money laundering red flags that recur across regulatory guidance, explains where each one actually surfaces, and covers what to do when one appears.

What Is an AML Red Flag?
An AML red flag is an indicator that a customer, a transaction, or a business relationship may involve money laundering or terrorist financing, and it is a prompt to look closer rather than a verdict. The Federal Financial Institutions Examination Council (FFIEC) states the point plainly in Appendix F of its Bank Secrecy Act and anti-money laundering examination manual, noting that the mere presence of a red flag is not by itself evidence of criminal activity and that closer scrutiny should determine whether the activity is suspicious or whether there is a reasonable business or legal purpose behind it. This distinction, however, matters operationally, because both extremes are bad. A programme that treats every anomaly as a conclusion will drown its analysts, and one that treats none as serious will eventually be asked why it did not act.
Red flags exist because the alternative does not scale. According to the United Nations Office on Drugs and Crime (UNODC), the estimated amount of money laundered globally in one year is 2% to 5% of global GDP, or 800 billion to 2 trillion US dollars.
No regulated firm can test every transaction against that backdrop, so supervisors publish indicator sets and expect firms to apply them proportionately.
What Are the 12 Money Laundering Red Flags?
The 12 money laundering red flags below fall into four families, covering identity and behaviour, money movement, ownership and counterparties, and geography and asset type. They are drawn from published regulatory indicator sets rather than invented, and the grouping matters because each family surfaces at a different point in the customer lifecycle.
Identity and Behaviour Red Flags
These are the flags most programmes are already built to catch, because they appear during customer due diligence rather than after it.
- The customer will not explain who is behind the account: Reluctance to provide identity documents, inconsistent answers across a single application, or a corporate applicant that routes control through nominees and will not name its beneficial owner. The FFIEC lists exactly this pattern, describing a trust, shell company, or private investment company that is reluctant to provide information on controlling parties and underlying beneficiaries.
- The source of funds or wealth does not add up: The customer cannot or will not explain where a large sum originated, and the explanation offered does not survive a basic sense check. A salaried applicant moving six-figure sums with no business, inheritance, or asset sale behind it is the textbook version, and the FFIEC records a comparable indicator where a customer makes frequent or large transactions and has no record of past or present employment experience.
- The stated nature and purpose of the account does not match the customer: Firms are expected to record what an account is for at opening, and the FFIEC treats a business that is reluctant to provide complete information about the nature and purpose of its business, its anticipated activity, or its prior banking relationships as a warning sign in its own right. This flag is often collected diligently and then never referred to again, which is a point we return to below.
Transaction and Money Movement Red Flags
These flags are behavioural, and almost all of them appear weeks or months after the customer has been approved.
- Deposits shaped around the Reporting Threshold: Structuring, sometimes called smurfing, breaks a larger sum into smaller amounts that sit just under a reporting limit, often across several days, branches, or channels. The FFIEC devotes a separate appendix to structuring because it is both common and specifically criminalised, and its red flag list includes currency deposited or withdrawn in amounts just below identification or reporting thresholds.
- Fan in and fan out across unrelated accounts: Funds arrive from a large number of unrelated payers and are then dispersed to a similarly large number of unrelated payees, or the reverse. The FFIEC describes the same shape in its funds transfer indicators, where many small incoming transfers are received, and almost all of them are then wired onward in a manner inconsistent with the customer’s business or history. This is the classic signature of a money mule account rather than a laundering customer in the traditional sense.
- High velocity with low retention: Money passes through the account quickly and almost none of it stays. A balance that returns to near zero after every cycle, combined with a high number of transactions relative to the customer’s stated income, is a stronger indicator than transaction size alone, because the laundering value of the account lies in the throughput rather than the balance.
Dormancy that ends suddenly: An account that sits idle and then experiences a large deposit and withdrawal cycle is a well-documented pattern, and the FFIEC records it directly, noting that an account with little activity may suddenly experience large deposit and withdrawal activity. Dormant accounts are attractive precisely because their history looks clean.
Structure and Counterparty Red Flags
- Ownership layered to obscure the beneficial owner: Shell companies, nominee directors, and holding structures spread across several jurisdictions while they do not have any commercial logic behind the arrangement. The FFIEC flags multiple high-value payments or transfers between shell companies with no apparent legitimate business purpose, and notes that transacting businesses sharing a single address or providing only a registered agent’s address is itself an indicator.
- Third parties with no reason to be in the transaction: Payments made to or received from counterparties that have no logical connection to the customer, or a persistent pattern of intermediaries standing between the customer and the money. The FFIEC records payments for goods or services made by instruments not drawn from the account of the entity that made the purchase.
- Politically exposed person exposure with no explained source of wealth: A politically exposed person (PEP), or a close associate or family member of one, transacting at a level that their public role does not explain. PEP status is not itself suspicious and does not warrant exit, but it does warrant enhanced due diligence and a documented source of wealth.
Geography, Product, and Asset Red Flags
- Funds routed through high-risk or monitored jurisdictions: Money moving to or from a jurisdiction that is subject to a Financial Action Task Force call for action, or routed through several jurisdictions with no legitimate commercial reason. The FATF refreshes its lists of high-risk jurisdictions and jurisdictions under increased monitoring several times a year, most recently in June 2026, so a control built on a list downloaded once and never refreshed will drift out of date within months.
- Virtual assets used to break the audit trail: Rapid conversion between crypto and fiat currency, transfers through mixing or tumbling services, chain-hopping between blockchains, and the use of anonymity-enhanced coins. The FATF published a dedicated set of virtual asset red flag indicators in September 2020, drawn from more than 100 case studies contributed by its global network, and it groups them under technological anonymity features, geographical risk, transaction patterns, transaction size, sender and recipient profiles, and source of funds.
A timing dimension most jurisdiction rules never apply
Flag 11 is almost always implemented as a question about the location. Shufti’s Identity Fraud Report 2026 adds a second question about how fast, and it is the one that separates a routing pattern from a travelling customer.
Within cross-border groups of fraudulent verification attempts that share identity or infrastructure attributes, the typical gap between activity in one jurisdiction and the next is 9 minutes 33 seconds. The fastest observed was 38 seconds. Nobody crosses a border in 38 seconds, so two jurisdictions appearing that close together is more consistent with shared infrastructure than with one person moving between them. The report is careful to describe these as observed relationships rather than proven coordination, and a firm applying the signal should keep the same caution.

| # | Red flag | Where it usually surfaces | What it looks like in the data |
| 1 | Will not explain who is behind the account | Onboarding | Missing UBO, nominee directors, inconsistent answers |
| 2 | Source of funds or wealth does not add up | Onboarding and EDD | Value moved is disconnected from declared income |
| 3 | Nature and purpose do not match the customer | Onboarding, then drift | Declared use and observed use diverge over time |
| 4 | Deposits shaped around the threshold | Post-onboarding | Repeated amounts just under a reporting limit |
| 5 | Fan-in and fan-out | Post-onboarding | Many unrelated payers in, many unrelated payees out |
| 6 | High velocity with low retention | Post-onboarding | High throughput, balance returns to near zero |
| 7 | Dormancy that ends suddenly | Post-onboarding | Idle account, then a large in-and-out cycle |
| 8 | Ownership layered to obscure the owner | KYB and periodic review | Shared addresses, multi-jurisdiction holding chains |
| 9 | Third parties with no reason to be there | Post-onboarding | Payer or payee unconnected to the customer |
| 10 | PEP exposure with unexplained source of wealth or source of funds | Screening and rescreening | PEP or associate match with no documented wealth |
| 11 | Unexplained exposure to high-risk or monitored jurisdictions | Screening and monitoring | Routing with no commercial rationale, and jurisdictions appearing minutes apart |
| 12 | Virtual assets used to obscure transaction origin or ownership | Post onboarding | Mixers, chain-hopping, rapid crypto to fiat |
Why the Red Flags That Matter Now Appear After Onboarding
Seven of the twelve flags above cannot be seen at account opening, and that is the structural reason well-run programmes still miss financial crime. A firm can run an excellent identity check, satisfy every customer due diligence obligation, approve a genuine person with genuine documents, and still be holding a laundering account six weeks later, because the customer was recruited after they were verified rather than before.
The Cifas figures make that shift measurable, because alongside the 43% rise in misuse of facility cases, the same dataset also recorded more than 22,000 filings in 2025 under a newly introduced money mule category, with recruitment running largely through social media using job scams, so-called business opportunities, and offers to overpay sellers on online marketplaces. Those recruits are not synthetic identities but real people with real documents and clean histories, which is precisely why an onboarding control cannot see them.
Tom Gadsden, VP of Product at Shufti, frames the detection problem in behavioural terms rather than identity terms.
“Against muling, you look at fan-in, fan-out behaviours, or high velocity, low value through,” he says.
He further goes onto saying,
“You see high velocity, low retention of funds, multiple flows from the same accounts, or money pooling into one account, enough to trigger an escalation.”
The pattern is visible, but only to a control that is still watching after the customer has been approved.
There is a second failure that follows from the same root. Firms are required to establish the nature and purpose of an account at opening, and most do it conscientiously, but that record is rarely joined to what the account then does.
Ray Blake, a former head of compliance and money laundering reporting officer who now writes and speaks on financial crime, makes a related point about the limits of automated detection.
“If a firm makes it hard to create a synthetic identity, a criminal finds somebody with an immaculate identity and gets them to onboard for them,” he says. “The machine can’t see that happened, but a human putting together the output from two or three machines and looking at behaviour can spot it.”
Red flags are therefore most valuable in clusters, and the analyst’s job is to read across signals that no single system owns.
How Do AML Red Flags Differ by Industry?
The four families of red flags apply everywhere, but the specific patterns that dominate vary by business model, and a monitoring rule set copied from another sector will usually generate noise rather than detection.
| Sector | AML red flags that dominate | Why this sector |
| Banking | Structuring, funnel accounts, dormancy that ends suddenly | Cash access and branch networks make threshold games viable |
| Fintech and payments | Mule networks, device and location mismatches, rapid multi-account opening | Fast digital onboarding lowers the cost of creating accounts |
| Crypto and exchanges | Mixers, chain-hopping, transfers to or from sanctioned wallets | Obfuscation services, rapid chain-hopping without rationale, and exposure to sanctioned or high-risk wallet addresses |
| Gaming and gambling | Minimal play followed by a large cash-out, chip dumping between colluding accounts | The platform can be used as a conversion layer rather than a game |
| Marketplaces and B2B | Collusive buyer and seller pairs, fabricated merchants, invoice mismatch | Trade flows disguise value transfer as commerce |
| Real estate | All-cash purchase, corporate buyer, price inconsistent with the market | Unexplained all-cash purchases, opaque corporate ownership, and pricing inconsistent with market value |
The difference between those sectors is measurable, not just descriptive. Shufti’s data for the first half of 2026 puts identity fraud at 17.08% of all verification requests in lending and investment and 14.87% in payments, against 4.24% in banking. Three business models in the table above, and a fourfold spread in how often a verification attempt turns out to be fraudulent. A threshold that produces a manageable queue inside a bank will produce a very different queue inside a payments business.
What Are the Real Estate Money Laundering Red Flags?
Real estate money laundering red flags centre around some aspects like who is buying, how the purchase is funded, and whether the price makes sense or not. This is because a single property transaction can absorb more criminal proceeds than months of banking activity.
The FATF published updated risk-based approach guidance for the real estate sector on 26 July 2022. The vulnerabilities it identifies include exploitation by politically exposed persons, purchases of luxury property, the use of virtual assets, and the use of anonymous companies and professional gatekeepers to move criminal proceeds.
The indicators most often cited for the sector are:
- All-cash or non-financed purchase that is inconsistent with the buyer’s declared profile, since a purchase without a mortgage removes the lender’s own due diligence from the chain.
- A corporate or trust buyer whose beneficial owner is not disclosed, particularly where the entity was formed recently or in a jurisdiction unconnected to the property.
- A price that does not match the market, whether well above or well below comparable values, which can be used to move value between parties under the cover of a legitimate sale.
- Payment from an unrelated third party, or funding split across several parties with no stated relationship to the buyer.
- Rapid resale at a materially different price, sometimes across a short chain of connected owners.
- Unexplained urgency to complete, or indifference to the commercial terms and to the condition of the property itself.
The regulatory position in the United States is currently unsettled, and this is where evergreen guidance published before 2026 is most likely to mislead. FinCEN’s Residential Real Estate Rule would have required reports on certain non-financed residential transfers to legal entities and trusts, with obligations due to begin on 1 March 2026, but a federal court set the rule aside.
FinCEN’s own Residential Real Estate FAQ page currently carries an alert stating that, in light of a federal court decision, reporting persons are not required to file Real Estate Reports and are not subject to liability if they fail to do so while the order remains in force, which was still the position as of August 2026.
The underlying risk has not changed, and the FATF guidance still applies, so firms in the sector should treat the pause as a reporting question rather than a risk assessment question. In the European Union, the direction is the opposite, since the Anti-Money Laundering Regulation (EU) 2024/1624 applies directly across all member states from 10 July 2027 and brings real estate professionals into a single harmonised rulebook. Firms handling property transactions should also read this alongside KYC obligations for real estate compliance.
Where Do Red Flags Sit in the Stages of Money Laundering?
Different red flags cluster at different points in the laundering cycle, and reading a flag against its likely stage is a useful way to judge how urgent it is. The classic model describes three stages of money laundering, although the UNODC notes that real cases may not contain all three, that stages can be combined, and that some stages repeat.
| Stage | What is happening | Red flags that cluster here |
| Placement | Criminal proceeds enter the financial system | Structuring, cash inconsistent with the business, dormancy ending suddenly |
| Layering | Ownership and origin are obscured through movement | Fan-in and fan-out, high velocity with low retention, shell structures, third parties, virtual assets |
| Integration | Funds re-enter the economy as apparently legitimate wealth | Property and luxury asset purchases, price inconsistent with the market, corporate buyers |
What Should You Do When a Red Flag Appears?
The correct response to a red flag is investigation rather than either dismissal or accusation, and the FFIEC is explicit that management’s primary focus should be on reporting suspicious activity rather than on determining whether a transaction is in fact linked to a particular crime, and three steps follow from that.
Investigate Before You Conclude
Establish whether the activity has a reasonable business or legal explanation. That usually means enhanced due diligence on the source of funds and the source of wealth, a review of the customer’s declared nature and purpose against what the account has actually done, and a check of the counterparties involved. Where a plausible explanation exists and can be evidenced, the file is closed with that reasoning recorded.
Escalate, Document, and Report
Where the explanation does not hold, the matter goes to the compliance officer or the money laundering reporting officer (MLRO), who decides whether the threshold for a suspicious activity report has been met. Document the decision either way, because an examiner will assess the reasoning and not only the outcome, and a well-evidenced decision not to report is defensible in a way that silence is not. Where suspicion stands, file within the timeframe your jurisdiction requires, retain the supporting evidence, and consider whether restrictions on the account are appropriate.
Never Tip Off the Customer
Alerting a customer to an investigation or a filed report is a criminal offence in many jurisdictions, so the investigation stays confidential and account handling should not change in a way that signals what is happening. The relationship also stays under monitoring after a report is filed rather than closing it.
Why Red Flags Get Missed
Most compliance teams can recite the indicators, so the failure is rarely conceptual and almost always operational, with four causes accounting for the majority of misses.
- Alert fatigue: Name-only screening and blunt thresholds generate volumes of false positives that no analyst team can review properly, and genuine hits are then lost inside the queue rather than outside it.
- Siloed data: Identity, screening, and transaction signals sit in separate systems with no shared customer record, so nobody sees the cluster of flags that would have made the case obvious.
- Weak matching: Sanctions and PEP checks built on a name and a country alone both miss real matches and bury teams in near matches, particularly where names are transliterated from non-Latin scripts.
- A baseline that is never revisited: The nature and purpose of the account is captured at onboarding, filed, and never compared against what the account subsequently does, which is the disconnect described earlier in this guide.
How Shufti Helps Compliance Teams Act on Red Flags
If a programme checks a customer thoroughly on day one and never looks again, most of the flags in this guide will reach you late or not at all, which is what the gap enforcement action tends to find. Shufti’s AML screening is built to keep running after onboarding rather than to close at it, so every screened customer is automatically rescreened against sanctions, PEP, and adverse media data on a 15-minute refresh cycle instead of a daily batch. A name that becomes designated at lunchtime therefore surfaces the same afternoon rather than the following morning. The engine matches against 3,500 or more curated global watchlists across 215 or more sanction regimes, monitors adverse media in 80 or more languages, and writes every decision to an audit log a supervisor can follow.
Frequently Asked Questions
What are money laundering red flags?
Money laundering red flags are warning signs in a customer's identity, behaviour, ownership, or transactions that suggest funds may be linked to financial crime. They prompt investigation rather than proving wrongdoing, and regulators, including the FFIEC and the FATF, publish indicator sets for firms to apply.
What are the 5 main indicators of money laundering?
The five that recur most often across regulatory guidance are unusual or structured transactions, activity inconsistent with the customer's stated profile, evasiveness about identity or source of funds, links to high-risk jurisdictions, and complex ownership or unexplained third parties.
Can timing alone be a money laundering red flag?
It can be a red flag, especially in cross-border cases. Shufti's data for the first half of 2026 shows that within cross-border groups of fraudulent verification attempts sharing identity or infrastructure attributes, the typical gap between activity in one jurisdiction and the next is 9 minutes 33 seconds, and the fastest observed was 38 seconds. No customer travels that fast, so elapsed time between jurisdictions is worth adding to any rule that already tests which jurisdictions are involved.
Is one red flag enough to file a suspicious activity report?
Usually not. A single flag triggers an investigation, and a report is warranted when the activity cannot be reasonably explained or when several flags cluster together. The FFIEC states that the mere presence of a red flag is not by itself evidence of criminal activity.
What are the red flags for money laundering in real estate?
All-cash purchases inconsistent with the buyer's profile, corporate or trust buyers with undisclosed beneficial owners, prices well above or below market value, payment from unrelated third parties, and rapid resale through connected owners. FATF guidance of July 2022 sets out the sector's risks.
What are common AML red flags in banking and crypto?
In banking, structuring around reporting thresholds and funnel accounts dominate. In crypto, the FATF highlights transfers through mixing services, chain-hopping between blockchains, anonymity-enhanced coins, and rapid conversion between virtual assets and fiat currency.















