• Jul 24, 2026
  • 13 min read

AML Red Flags: Common Indicators, Industry Examples, and Detection Best Practices

Discover the most critical AML red flags, from suspicious transactions to PEPs and high-risk jurisdictions. Learn how to detect money laundering and stay compliant in 2026.

Money laundering has evolved far beyond its traditional associations with cash-heavy businesses and offshore accounts. Criminal proceeds are now moved through virtually any sector via increasingly complex, layered channels that are difficult to detect and trace. This makes monitoring for red flags of money laundering a universal concern. 

For regulated industries such as financial services and crypto, it is more than a concern. Detecting suspicious activity and reporting it to the authorities is a legal obligation, imposed on these firms under anti-money laundering laws. Monitoring for red flags is one core component of that effort. 

In July 2025, the UK's Financial Conduct Authority fined Barclays Bank PLC around £39.3 million over its handling of Stunt & Co, a gold-trading client whose account received £46.8 million from Fowler Oldfield, a business at the center of a major money-laundering operation. The warning signs were there to see. The payments far exceeded the client's expected turnover and included hundreds of round-sum transfers of £100,000, a classic laundering red flag, yet the account remained rated as low-risk and triggered no enhanced monitoring. Barclays didn't reassess the relationship even after learning that law enforcement had raided the firms involved. The case shows that spotting a red flag on paper is not the same as acting on it. The controls have to catch the signal, escalate it, and change what the bank does next.

Not a legal obligation in themselves, red flags, however, help obliged entities identify suspicious activity.

This article outlines the most common AML red flags and the processes that surface them. Customer due diligence (CDD) catches the static signs at onboarding, such as document mismatches, undisclosed beneficial ownership, or an opaque ownership structure. Ongoing transaction monitoring catches the behavioral ones later—such as structuring, or activity that departs from a customer's expected pattern—once there is a baseline to measure against. Governing both is the risk-based approach, which is not a source of red flags but the framework that decides how much scrutiny each customer receives in the first place.

What is an AML red flag?

An AML red flag is an indicator that a customer, transaction, or business relationship may involve money laundering, terrorist financing, fraud, or another form of financial crime. A red flag is not proof of illegal activity. Rather, it is a warning sign that warrants further review and, where appropriate, enhanced due diligence or investigation.

Red flags can arise during customer onboarding, throughout the customer relationship, or when monitoring transactions. They may relate to unusual customer behavior, inconsistencies in customer information, complex ownership structures, abnormal transaction patterns, or activity involving high-risk jurisdictions.

A single red flag is rarely sufficient to conclude that suspicious activity is taking place. Many legitimate customers occasionally exhibit behaviors that resemble common indicators of money laundering. For example, a sudden increase in transaction volume may reflect genuine business growth rather than criminal activity. For this reason, AML red flags should always be assessed holistically, taking into account the customer's profile, expected activity, transaction history, source of funds, and other relevant information.

Disclaimer: The indicators presented in this article are general examples and should not be considered an exhaustive list of AML red flags. Relevant indicators vary depending on industry, products and services, customer type (individual or legal entity), delivery channels, geographic exposure, and applicable regulatory requirements.

Common AML red flags

Below are some common AML red flags identified by the Financial Action Task Force (FATF), an international AML/CFT watchdog, and national regulators in their guidance. These sources matter because they operate at different levels: FATF sets the global standards that shape AML regimes worldwide, while national regulators translate them into the specific rules and supervisory expectations that firms actually have to meet.

1. Customer identity red flags

Most of these come down to one question: is the customer who they claim to be, and does their account of themselves hold together? The flags surface when identity, ownership, or source of funds won't reconcile.

Identity inconsistencies

  • Customer information is inconsistent, unverifiable, or contradicts other available information.
  • Identification documents appear suspicious or of unusually poor quality, although forgery cannot be confirmed.
  • Customer frequently changes identification details, email addresses, IP addresses, or payment information.

Beneficial ownership and transparency

  • Refuses to disclose beneficial ownership.
  • Provides implausible or inconsistent UBO (Ultimate Beneficial Owner) information.
  • Shares addresses, phone numbers, email addresses, wallet addresses, or other identifiers with multiple unrelated customers.

Source of funds and customer profile

  • Refuses or cannot explain the source of funds or the source of wealth when required.
  • Customer's income, occupation, business activity, or residence is inconsistent with requested products or expected transaction volumes.

Customer behavior

  • Asks unusual questions about reporting obligations to regulators or government authorities.
  • Appears nervous, evasive, defensive, or confused during onboarding or due diligence.
  • Does not understand the product or transaction they are requesting.
  • Cannot reasonably explain transactions that lack apparent economic or commercial purpose.

2. Transaction pattern red flags

Identity tells you who you're dealing with; transactions tell you what they actually do. These matter less in isolation than as a departure from what the account normally looks like.

Unusual transaction activity

  • Transactions have no apparent business, personal, or economic rationale.
  • Large or frequent transactions occur despite unusually high transaction fees.
  • Transactions occur at unusual hours or outside normal customer behavior.

Structuring and layering

  • Multiple transactions are conducted just below reporting thresholds (structuring/smurfing).
  • Funds rapidly enter and leave an account with no clear purpose.
  • Transactions reverse, loop back, or return to the originating account without commercial logic.
  • Frequent large deposits followed by immediate full or near-full withdrawals.

Third-party and account activity

  • Payments involve unrelated third parties without a plausible business explanation.
  • Activity is inconsistent with the customer's known profile or stated business.
  • Multiple accounts across different financial institutions are used to aggregate or disperse funds.
  • Transactions appear deliberately timed around reporting thresholds, regulatory reviews, or compliance controls.
  • Customer applies unusual urgency or pressure to execute transactions without reasonable explanation.

3. Geographic risk red flags

Where money comes from and where it goes can carry as much risk as how much of it there is. These flags track exposure to places and routes that don't fit the customer's stated footprint.

High-risk jurisdictions

  • Transactions involve FATF-greylisted or blacklisted jurisdictions without a legitimate business rationale.
  • Funds are routed through multiple high-risk or non-cooperative jurisdictions without commercial justification.
  • Customer's address or IP is linked to jurisdictions associated with sanctions evasion or proliferation financing.
  • Transactions involve conflict zones or territories associated with terrorist activity.

Cross-border inconsistencies

  • Customer claims residence in one country but consistently transacts from another.
  • Unexplained cross-border transfers unrelated to the customer's business or personal activities.
  • Use of payment or transfer services operating in jurisdictions with weak AML/CFT controls.
  • Geographic patterns are inconsistent with the customer's expected business operations.

AML red flags by industry

The indicators above may apply across the board. Each sector also has its own tells, shaped by how money moves through it and where the gaps are. The lists below draw on FATF's sector guidance, as well as FIU practice.

Financial services red flags

Banks see the widest range of activity, which makes the baseline hard to define and the outliers easy to bury. These flags cluster around accounts that move money without holding it and ownership that resists explanation.

  • Accounts used as pass-through or funnel accounts: rapid in-and-out flows inconsistent with the stated business, leaving little or no resting balance.
  • Cash intensity out of step with the customer's declared business model, including frequent deposits structured below reporting thresholds.
  • Correspondent banking relationships where the respondent's customer base, jurisdiction, or downstream "nested" clients are opaque or higher-risk.
  • Wire activity with no apparent economic purpose: round-number transfers, rapid movement through multiple accounts or jurisdictions, or transfers to and from high-risk locations.
  • Sudden, unexplained changes in account behavior, dormant accounts reactivating with high-value activity, or activity spiking around onboarding then ceasing.
  • Beneficial ownership that cannot be established, or ownership structures that change without commercial rationale.
  • Trade finance documentation that is inconsistent, vague, or shows pricing detached from market value.
  • Customer evasiveness on source of funds or wealth, or third-party control of an account inconsistent with the stated relationship.

Virtual asset red flags

Crypto compresses the timeline and runs on different technology: funds can be layered and pushed across borders in minutes, and anonymity tools are built into the rails. The flags below reflect speed, obscured ownership, and exposure to services designed to break the trail.

Transactions (size and frequency):

  • Structuring of virtual assets transfers in small amounts below record-keeping or reporting thresholds.
  • Multiple high-value transfers in rapid succession, or immediate withdrawal with no other activity.
  • Deposits that are promptly converted and moved out, inconsistent with the customer's profile.

Transaction patterns:

  • New accounts funded, then fully emptied, immediately.
  • Funds split across many addresses or consolidated from many sources with no business rationale.
  • Conversion between many VA types in succession, incurring losses, in a way consistent with layering rather than trading.

Anonymity:

  • Use of mixers, tumblers, anonymity-enhanced coins, or privacy wallets.
  • Peer-to-peer exchange platforms, decentralized exchanges, or services with weak or absent KYC.
  • Transactions traced to or from darknet marketplaces.

Senders/recipients:

  • One person operating multiple accounts under different names, or repeatedly failing to onboard at the same VASP (virtual assets service provider).
  • Incomplete or inconsistent KYC information, or refusal to provide it.
  • Mismatch between the IP address used and the customer's stated location, or use of IPs tied to illicit infrastructure.

Source of funds or wealth:

  • Funds sourced directly from or destined for online gambling services, mixers, or third-party wallets.
  • No transparency over the origin or ownership of funds.
  • VA sourced from addresses linked to fraud, scams, ransomware, or sanctioned entities.

Geographical risk:

  • Customer funds originating from, or sent to, jurisdictions with weak or absent VA regulation.
  • Counterparties registered in jurisdictions inconsistent with the customer's stated activity.

Gambling red flags

Casinos and gaming operators take in large volumes of cash and hand back instruments that look clean, which is the entire appeal to a launderer. These flags track value going in and coming out in a different form, with little real play in between.

Cash and value instruments:

  • Buying in with large amounts of cash, minimal or no play, then cashing out as a cheque or a credit transfer ("refining" dirty cash into clean instruments).
  • Requesting winnings in a form different from the buy-in, or in another person's name.
  • Purchasing chips and later redeeming them with little gaming activity in between.

Structuring and threshold avoidance:

  • Multiple buy-ins or cash-outs kept below identification or reporting thresholds.
  • Several patrons appearing to act together to keep individual transactions below thresholds.

Accounts, winnings, and currency:

  • Discrepancy between amounts brought in and amounts claimed as winnings.
  • Casino deposit accounts used as quasi-banking facilities: deposits and withdrawals unrelated to gaming.
  • Currency exchange through the casino with no corresponding gaming, exploiting the cage as a money changer.
  • Use of foreign holding accounts so that funds deposited in one jurisdiction are drawn in another without a cross-border remittance trail.

Higher-risk channels and people:

  • VIP / junket programs where the source of high-roller funds is opaque.
  • Use of agents or third parties to play or to move funds on a patron's behalf.
  • Employee complicity in processing transactions or suppressing reporting.

Online-specific:

  • Multiple accounts opened by a single person or coordinated networks of accounts.
  • Deposits funded from anonymity-enhanced VA or mixers, then withdrawn as apparent winnings.
  • Rapid deposit-then-withdrawal with negligible play, treating the operator as a layering tool.

Real estate red flags

Real estate is a high-risk sector for money laundering and is subject to anti-money laundering (AML) regulations in many jurisdictions. Property absorbs a large sum in a single transaction and rarely invites questions on its own, which is what makes it useful for layering. These flags indicate deals where the buyer, the structure, or the price doesn't align with the purchase.

  • Purchases through corporate vehicles, trusts, or layered structures that conceal the beneficial owner, particularly offshore entities with no commercial purpose.
  • All-cash purchases, or large unexplained cash components, inconsistent with the buyer's profile.
  • Use of complex loans or credit finance, including back-to-back or intra-group loans, to disguise the origin of funds.
  • Purchase price inconsistent with market value (over- or under-valuation), or values manipulated between contract and completion.
  • Third parties settling the purchase, or funds arriving from unrelated company accounts (the FATF example of unsolicited payments into a solicitor's client account from a company controlled by an associate).
  • Rapid resale or "flipping" with unexplained price increases, consistent with layering.
  • Buyer indifference to the property itself, its condition, or its price, where the transaction appears to be a vehicle for moving funds.
  • Reliance on non-financial professionals (lawyers, notaries, accountants) to add distance between the buyer and the funds.
  • Transactions involving PEPs (politically exposed persons), their family members or close associates, especially where the source of wealth is unclear.
  • Property used as a base for further criminal activity, or sub-let in ways inconsistent with declared use.

High-value goods red flags (dealers in precious metals and stones, and other luxury goods)

Metals, stones, and luxury items pack high value into something portable and easy to resell, often in another market. The flags below follow cash, hidden buyers, and pricing or sourcing that won't stand up.

  • Large cash purchases, or purchases split into amounts below identification or reporting thresholds.
  • Mixed payment methods for one purchase (cash plus wire plus card) without economic logic.
  • Purchases via nominees, intermediaries, or shell companies that obscure the true buyer.
  • Buying goods that are easily resold in another market, or quickly returning or exchanging items for a refund in a different form.
  • Trade-based manipulation: over- or under-invoicing of metals, stones, or jewelry to shift value under the cover of commercial trade.
  • A dealer or business customer that cannot explain its customer base, expected cash volume, sourcing channels, or rationale for dealing with high-risk intermediaries.
  • For refineries and the supply chain: weak verification of the source of goods, misrepresentation of origin, and inadequate beneficial-ownership review of suppliers, allowing illicit metal to acquire a clean commercial identity.
  • Portability exploited for cross-border value transfer: high value concealed in small, undetectable form (the diamond and bullion cases FATF cites).
  • PEP-linked acquisition of high-value assets inconsistent with declared source of wealth or normal lifestyle.

Payment services red flags

Prepaid cards, e-money, and transfer services move value fast and across providers, usually on a thinner audit trail than a bank's. These flags follow funds that load, hop, and exit in ways the stated business doesn't account for.

Prepaid cards:

  • Loading or funding consistently structured just below reporting thresholds, repeated by the same person across multiple occasions.
  • A single customer holding an unusual number of cards or accounts with the same provider.
  • Funding from many diverse sources (multiple banks, cities, credit cards, cash) feeding the same account.
  • Loading always performed by third parties, or multiple third-party loads followed by immediate transfer out to unrelated accounts.
  • Loads followed shortly by ATM withdrawals, especially cross-border, exploiting the limited audit trail.
  • Credit-balance build-up then refund (overpayment used to extract "clean" funds).

Internet-based and mobile payment services:

  • A prepaid or payment company holding a large number of flow-through bank accounts, sometimes across countries, consistent with layering.
  • Back-and-forth movement of funds between accounts held by different payment companies in different jurisdictions, with no business model that explains it.
  • Person-to-person transfers used to circumvent the provider's own funding or value limits, including funding via a VA exchanger or other third party.
  • Cash volume and frequency run through a payment company's accounts that make no economic sense for the stated business.
  • Account access or transactions from IPs inconsistent with the registered customer location.

Money or value transfer services (MVTS):

  • Structuring remittances below thresholds, or splitting a transfer across multiple agents or senders.
  • Senders or receivers appearing across many otherwise unrelated transactions (smurfing networks).
  • Transfers to or from higher-risk corridors inconsistent with the customer's known links.

National AML red flag guidance and list of sources

Many bodies and regulators publish sector-specific or jurisdiction-specific indicators, including:x

FATF

  • FATF, Virtual Assets: Red Flag Indicators of Money Laundering and Terrorist Financing (2020).
  • FATF, Guidance for a Risk-Based Approach: The Banking Sector (2014). Methodology, not a red-flag list.
  • FATF / APG, Vulnerabilities of Casinos and Gaming Sector (2009); FATF, RBA Guidance for Casinos (2008).
  • FATF, Money Laundering and Terrorist Financing Through the Real Estate Sector (2007); FATF, Guidance for a Risk-Based Approach: Real Estate Sector (2022).
  • FATF, Guidance for a Risk-Based Approach for Dealers in Precious Metals and Stones (2008); FATF, Money Laundering and Terrorist Financing Risks and Vulnerabilities Associated with Gold (2015).

National and regional regulators:

  • Singapore (MAS): Guidelines to MAS Notice PSN02 on Prevention of Money Laundering and Countering the Financing of Terrorism: Digital Payment Token Service.
  • Hong Kong (SFC): Guideline on Anti-Money Laundering and Counter-Financing of Terrorism (For Licensed Corporations and SFC-licensed Virtual Asset Service Providers).
  • UAE (CBUAE): Central Bank AML/CFT guidance containing red-flag indicators.
  • Canada (FINTRAC): Money Laundering and Terrorist Financing Indicators, published by sector.
  • Latvia (FID Latvia): Typologies and sector-specific indicators.
  • Australia (AUSTRAC): Financial crime guides and indicator sets supporting suspicious matter reports (SMRs). 
  • Israel (IMPA): National AML/CFT guidance
  • European Union (EBA): Guidelines on ML/TF Risk Factors (revised under Directive (EU) 2015/849).

Where red flags appear in the AML process

Detecting red flags isn't the goal of AML/CFT obligations. Preventing money laundering is, and the red flags are the indicators that the required procedures surface along the way. So the useful question isn't how to hunt for red flags in the abstract, but where in the process they tend to appear.

They cluster at a few stages. At onboarding, CDD establishes who the customer is, who ultimately owns them, and what their activity should normally look like, which is where evasive identity, opaque ownership, or a profile that doesn't add up first show themselves. For higher-risk customers, enhanced due diligence (EDD) probes the sources of funds and wealth more deeply, surfacing issues such as unexplained affluence. And throughout the relationship, ongoing transaction monitoring measures real activity against that expected baseline.

Monitoring is where the idea of "normal" does most of its work. A transfer that looks alarming for one client is routine for another, so the point isn't to catch any single suspicious-looking transaction. It's to notice when a customer's activity no longer matches their established pattern. That's why detection splits the way it does: automated systems surface the anomalies, and people decide what they actually mean.

Customer due diligence, and when to go further

Customer due diligence (CDD) is where this starts. Before you can tell whether a customer is behaving oddly, you need a clear picture of who they are, what their business does, and why they're using your services. That baseline is what lets you recognize activity that doesn't fit.

Some customers warrant a closer look. Opaque ownership structures, PEP status, or links to high-risk jurisdictions all raise the risk profile and trigger enhanced due diligence. In such cases, you need to verify the source of funds, obtain management approval, and take any other measures required by the applicable regulations. The customer risk assessment is part of that process. If the customer is ultimately assessed as high risk, you may then apply more frequent ongoing monitoring.

Transaction monitoring

Monitoring systems watch for patterns that don't add up: funds moving in and straight back out, deposits broken into amounts that dodge reporting thresholds, sudden spikes in volume, or exposure to sanctioned or high-risk countries. Most combine fixed rules with statistical models and, increasingly, machine learning.

The hard part is calibration. Set the thresholds too tight, and your analysts drown in false positives; set them too loose, and real activity slips through—neither is a one-time fix. Typologies shift, customers change how they behave, and regulatory expectations keep moving, so the rules need revisiting on a schedule, not only when something breaks.

Onboarding is a snapshot, not the whole picture. Ownership changes hands, transaction patterns drift, circumstances change. Refreshing customer information, reassessing risk, and working the alerts your monitoring throws up are what keep that profile accurate over time.

Suggested read: AML & Fraud Risk Assessment in 2025: Risk Matrices, Risk Scoring, and Best Practices

What to do when a red flag fires

A red flag is a prompt to look harder, not a verdict. The review is to determine whether there's a reasonable explanation or whether the activity needs to go further.

A typical investigation moves through roles as much as through steps. In a large organization, the work passes from a front-line analyst to the compliance team and finally to the Money Laundering Reporting Officer (MLRO), each with a defined part. In a smaller firm, one person may hold all of these roles, but the sequence of decisions stays the same.

Front-line analyst

  • Don't jump to money laundering. A flag signals possible risk. It isn't proof of anything.
  • Pull the context (where applicable). Gather the documentation and background needed to understand what the customer is actually doing.
  • Check it against the profile (where applicable). Does the activity line up with what you know about the customer's business, expected patterns, and risk level?
  • Escalate when warranted. If the activity still looks off, hand the case to the compliance team per your internal procedures.

Compliance team

  • Apply EDD if needed. Unexplained activity or higher-risk customers may call for further verification and tighter monitoring.
  • Investigate and reach a view. Weigh the evidence against the customer's profile and decide whether a genuine suspicion remains. If it does, refer the case to the MLRO.

MLRO

  • Decide on a SAR (suspicious activity report) or STR (suspicious transaction report). If there are reasonable grounds to suspect money laundering or terrorist financing, file with the relevant authority in line with your reporting obligations.

At every stage

  • Write it down. Keep a clear record of what was reviewed, what was decided, and why. That audit trail is what demonstrates the work was done.

Building an AML program that actually works

Controls on their own don't make a compliance program. What ties them together is a risk-based framework in which due diligence, monitoring, governance, and trained staff reinforce one another, and which you revise as the threats change.

A few things separate programs that work from ones that exist on paper:

  • Put resources where the risk is. Allocate your effort to the customers, products, services, and jurisdictions that pose the greatest money-laundering risk.
  • Read signals together, not in isolation. One indicator rarely tells you much. Customer, transaction, geographic, and behavioral factors are far more revealing in combination.
  • Keep the models honest. Review your scenarios, thresholds, and ML models regularly to keep them sharp rather than generating noise.
  • Train people properly. Staff who recognize current typologies and know your escalation process are the ones who actually catch things.
  • Stay current with the rules. AML frameworks go stale fast. Revisit them as guidance and regulations change.

Identify AML risks with Sumsub

Detect high-risk users by screening them against global watchlists for sanctions, PEPs, and adverse media.

Try our AML Screening now
Identify AML risks with Sumsub

FAQ

  • What are examples of AML red flags?

    Examples of AML red flags include unusually large or complex transactions, activity inconsistent with a customer's profile, frequent cash deposits, transactions involving high-risk jurisdictions, and attempts to avoid reporting thresholds. It’s important to know that red flags vary across industries.

  • How do you detect red flags in AML?

    Red flags can be detected during customer onboarding, throughout the customer relationship, or when monitoring transactions. They may relate to unusual customer behavior, inconsistencies in customer information, complex ownership structures, abnormal transaction patterns, or activity involving high-risk jurisdictions. A single red flag is usually not sufficient to conclude that suspicious activity is going on. AML red flags should always be assessed holistically, taking into account the customer's profile, expected activity, transaction history, source of funds, and other relevant information.

  • What should you do if a red flag is triggered?

    When an AML red flag is triggered, the activity should be reviewed in the context of the customer's risk profile and transaction history, with additional investigation or enhanced due diligence conducted where appropriate. File a report with the FIU (a SAR or STR) where there are reasonable grounds to suspect money laundering or terrorist financing.

  • What is the difference between a red flag and a suspicious activity report?

    A red flag is an indicator of potentially suspicious activity that prompts further investigation, whereas a Suspicious Activity Report (SAR) is a formal report submitted to the relevant authorities when there are reasonable grounds to suspect money laundering or other financial crime.