AML
Transaction Monitoring
Red Flags
Compliance

AML Transaction Monitoring Red Flags: A Practitioner's Reference Guide

A comprehensive reference of transaction monitoring red flags for AML compliance teams — covering structuring, layering, unusual account behaviour, and typology-specific indicators across payment rails.

RiskLex EditorialJune 28, 2026
AML Transaction Monitoring Red Flags: A Practitioner's Reference Guide

Why Red Flags Still Matter

In an era of machine learning models and real-time analytics, the foundational concept of the AML red flag remains central to compliance. Regulatory expectations — from FinCEN guidance to FATF recommendations to the EBA's guidelines on risk-based supervision — consistently reference red flags as the baseline lens through which suspicious activity must be assessed. Automated transaction monitoring systems ultimately encode red flags as detection rules or training labels. Understanding them rigorously is prerequisite to building effective programmes.

This guide consolidates the most operationally significant red flags across typology categories, payment rails, and customer segments. It is intended as a working reference for compliance analysts, transaction monitoring teams, and technology teams calibrating detection logic.

---

Structuring and Cash-Related Red Flags

Structuring (smurfing) remains the most documented AML typology and the one most directly targeted by Bank Secrecy Act currency transaction report (CTR) thresholds.

Key indicators:
- Multiple cash deposits just below the CTR threshold (USD 10,000 in the US; EUR 10,000 in the EU) within the same day or across consecutive days at the same or different branches
- A pattern of deposits that, when aggregated, would exceed reporting thresholds — even when individual transactions do not
- Customer behaviour consistent with counter-surveillance: asking tellers how much can be deposited without triggering a report, or expressing frustration when approached about unusual transactions
- Sudden onset of high-volume cash activity for accounts that have been dormant or low-activity
- Cash deposits immediately followed by wire transfers out — the "collect and move" pattern
- Third-party cash deposits into accounts where the account holder has no apparent relationship with the depositor

Velocity anomalies in cash-intensive businesses:
- Daily cash receipts that significantly exceed the declared revenue for the business type and size
- Seasonal businesses showing year-round high-volume cash activity inconsistent with their operating model
- ATM withdrawal patterns that consistently occur at the daily maximum limit, particularly in overseas jurisdictions

---

Wire Transfer and International Payment Red Flags

Wire transfers are the primary layering vehicle in sophisticated money laundering schemes. Key red flags include:

Origination and destination anomalies:
- Transfers to or from jurisdictions on FATF grey or black lists, or countries with known AML/CFT deficiencies as identified in FinCEN advisories or EU high-risk country lists
- Transfers routed through multiple jurisdictions without apparent business rationale — particularly where intermediate countries have no relationship to either the sender or recipient
- Round-dollar or round-currency wire amounts (e.g. exactly USD 50,000, EUR 100,000) — natural business transactions rarely produce perfectly round numbers
- Transfers sent shortly after receipt, with minimal or no residual balance — "pass-through" account behaviour

Counterparty red flags:
- Counterparties in jurisdictions with bank secrecy laws or that are known offshore financial centres
- Counterparties with names that do not correspond to any searchable business entity
- Transfers to individual personal accounts in jurisdictions where the business has no declared operations
- Rapid change in counterparty patterns — an account that transacted only domestically suddenly initiating international transfers

Volume and timing:
- Wire transfer volumes that materially exceed the account's historical profile with no documented business event explaining the change
- Wires sent in clusters — multiple transfers to the same destination over a short window, potentially sub-threshold
- Transfers initiated outside normal business hours for commercial accounts, particularly overnight or on weekends

---

Account Behaviour and Onboarding Red Flags

At onboarding:
- Reluctance to provide complete beneficial ownership information for corporate accounts
- Use of corporate structures (shells, nominees, holding companies) in jurisdictions with limited transparency that cannot be explained by legitimate tax or operational rationale
- Customer presents identification documents that appear inconsistent (different dates of issue, inconsistent security features) or that cannot be verified against authoritative sources
- Customer declines products or features that would be standard for their stated purpose (e.g. a business account that declines overdraft facilities, online banking, or business cards — limiting traceability)
- Urgency to open an account quickly without engaging with standard onboarding requirements

During the relationship:
- Account activity that is inconsistent with the purpose stated at onboarding (e.g. a personal savings account used for high-frequency commercial transactions)
- Significant change in transaction volumes or patterns following a change in beneficial ownership
- Multiple accounts at the same institution that receive and redistribute funds — a fragmented "funnel account" structure
- Negative news or adverse media about the customer, counterparties, or associated entities discovered during ongoing monitoring
- Customer contacts to request changes that would reduce monitoring visibility — removing transaction alerts, downgrading to lower-tier products, or requesting account closure when suspicious activity is under investigation

---

Trade Finance Red Flags

Trade-based money laundering (TBML) is widely regarded as one of the largest and least detected AML typologies. Key indicators in documentary trade finance:

  • Invoices that appear inconsistent with market prices for the goods described — either significantly over-invoiced or under-invoiced relative to published trade price indices
  • Goods described in trade documents that do not match the apparent business of either the importer or exporter
  • Multiple alterations or corrections to trade documents — particularly to price, quantity, or party details — after initial submission
  • Mismatch between the country of goods origin on the invoice and the vessel routing or shipping documentation
  • Letters of credit that are repeatedly amended, especially in relation to amount or beneficiary
  • Third-country or routing transactions where the goods pass through intermediary jurisdictions with no apparent logistical rationale

---

Cryptocurrency-Related Red Flags

For institutions that permit crypto-related transactions or service VASPs:

  • Customer deposits of cryptocurrency proceeds from unhosted wallets without the ability to explain the source of funds
  • Transactions involving wallets that blockchain analytics tools flag as having direct or indirect exposure to darknet markets, ransomware payment addresses, or sanctioned entities
  • Rapid conversion between crypto assets and fiat — particularly where the crypto leg is routed through privacy coins or mixers
  • VASP counterparties that are not registered or licensed in any jurisdiction, or that are on FinCEN's list of MSBs with concerns
  • Customers who operate crypto ATMs without a registered MSB licence or who conduct high-volume crypto purchases for third parties

---

Operationalising Red Flags in Transaction Monitoring

Red flags are only useful when operationalised into detection logic that accounts for:

Baseline typicality. A red flag is defined by its deviation from expected behaviour for that customer segment, geography, and product. A large wire transfer is not automatically suspicious for a commercial real estate firm; it may be highly suspicious for a newly opened personal account.

Clustering. Single red flags rarely sustain a SAR filing. Robust detection logic combines multiple indicators — a new account (red flag 1) receiving large deposits from multiple third parties (red flag 2) immediately wired overseas (red flag 3) exceeds the threshold for investigation in most programme frameworks.

Tuning and documentation. Monitoring rules should be documented with the red flag rationale they encode, tuned against historical SAR populations where available, and reviewed at least annually against new typology guidance from FinCEN, FATF, or relevant supervisory bodies.

RiskLex provides structured financial crime intelligence mapped directly to transaction monitoring typologies, helping compliance teams keep detection logic current with evolving threats. Request a demo to see how RiskLex signals translate into actionable monitoring rules.