- Sep 08, 2026
- 11 min read
Money Laundering vs. Embezzlement: Differences, Examples & Penalties (2026)
Compare money laundering, embezzlement, and fraud, including key differences, penalties, and red flags, and learn how compliance teams detect and prevent each.

For 20 years, Rita Crundwell, the comptroller of Dixon, Illinois – a town of only about 15,700 people – secretly transferred municipal money into a fake account she controlled, generating bogus invoices to make the payments look routine. She stole $53.7 million, an extraordinary sum for a city whose annual budget was only around $8–9 million. She was eventually sentenced to 19 years and 7 months in federal prison.
Taking the money is embezzlement. What happens to it afterward is usually money laundering.
The UN Office on Drugs and Crime estimates that around 2–5% of global GDP is laundered each year. This is around $2.5 to $6.3 trillion. For reference, Germany’s GDP at the time of writing is approximately $5.45 trillion. Meanwhile, the Association of Certified Fraud Examiners’ 2026 global study found that asset misappropriation, which covers many employee embezzlement schemes, occurred in 90% of occupational fraud cases, with a median loss of $100,000.
The two crimes sit in the same chain often enough to be discussed as one problem. They may be committed by different people; they are caught by different controls and charged under different statutes.
What is money laundering?
Money laundering is the concealment or disguise of the origin of money or property obtained through crime, so that it can be used without attracting attention.
The predicate offense can be almost anything: drug trafficking, bribery, tax crimes, fraud, embezzlement. The laundering is what happens next. Value moves through bank accounts, companies, payment platforms, digital assets, property, trade transactions, or high-value goods. Illicit and legitimate funds get commingled so the criminal portion becomes difficult to isolate. A person may launder their own proceeds or handle someone else's.
How money laundering works: The three stages
The traditional three stages of money laundering are:
- Placement: Criminal proceeds enter the financial system, perhaps through cash deposits, cash-intensive businesses, casinos, asset purchases, or financial institutions with weak AML controls
- Layering: Transactions, entities, jurisdictions, or asset conversions are used to obscure the trail between the property and its criminal source
- Integration: The value returns to the criminal in an apparently legitimate form, such as business income, investment returns, loans, or sale proceeds
But how does money laundering work in practice? Increasingly, it does not follow a neat sequence. The traditional money laundering process remains a useful teaching model, but modern schemes may skip, repeat, combine, or run steps simultaneously across fiat currency, digital assets, legal entities, and jurisdictions.
Some frameworks also describe four stages of money laundering, adding “extraction” to refer to the point at which criminals retrieve or use the laundered funds.
Suggested read: The Three Stages of Money Laundering: How Placement, Layering, and Integration Work in 2026
What is embezzlement?
Embezzlement is the intentional, fraudulent conversion of money or property by someone lawfully entrusted with it.
The defining element is the breach of trust. The offender obtains possession or control legitimately, then uses the asset for an unauthorized purpose. Employees, executives, trustees, public officials, and accountants all sit in positions where that is possible.
Suggested read: Employee Fraud: Detection, Prevention, and Compliance Strategies in 2026
How embezzlement occurs: Common schemes
The offender first receives legitimate access to an asset or financial process. They then exploit that access to divert value, often using false records, approval overrides, or their knowledge of control gaps to conceal the loss. Small unauthorized transactions may go undetected for years.
Types of embezzlement schemes
Common schemes include:
- Fund misappropriation: Diverting company, client, pension, trust, or escrow funds into a personal or controlled account, or otherwise using them without authorization
- Skimming: Taking incoming money before it is entered in the organization’s records
- Cash larceny: Stealing recorded cash receipts before or after deposit
- Billing and vendor schemes: Creating fictitious suppliers, approving false invoices, inflating legitimate bills, or diverting vendor payments to an account controlled by the offender
- Payroll schemes: Adding ghost employees, manipulating hours or commission, or issuing unauthorized salary and bonus payments
- Expense and corporate-card abuse: Submitting fabricated or duplicate expenses, disguising personal purchases as business costs, or approving one’s own claims
- Check and electronic-payment tampering: Forging payees, changing bank details, initiating unauthorized transfers, or misusing payment credentials
- Inventory and asset misappropriation: Taking stock, equipment, securities, data, intellectual property, or other assets for personal use or resale
Most real schemes combine several. Someone creates a shell vendor, approves its invoices, releases the payments, and adjusts the reconciliation that would otherwise expose them.
Money laundering vs. embezzlement: Key differences
Money laundering and embezzlement differ, but they may overlap in practice. Embezzled money from an investment fund, for example, may be laundered to conceal the fraudulent origin of the proceeds.
| Feature | Money laundering | Embezzlement |
| Act | Concealing, moving, or disguising criminal proceeds | Fraudulently converting property that was entrusted to the offender |
| Status of the property | Usually criminal proceeds or other value connected to unlawful activity | Generally received or controlled lawfully |
| Purpose | Conceal the source, ownership, or control of illicit assets | Obtain or use another party’s assets without authorization |
| Typical target of controls | Customers, accounts, counterparties, transactions, and networks | Employees, vendors, payments, ledgers, access rights, and company assets |
Embezzlement vs. theft
Whether embezzlement counts as "theft" depends on how a jurisdiction defines it. Common law recognized several separate property crimes – larceny, which required a wrongful taking from the outset, and embezzlement, in which the defendant lawfully received or possessed the property before fraudulently converting it. Under this traditional framework, "theft" is an umbrella term covering both offenses, and "larceny" refers to the wrongful-taking variant. So, embezzlement is theft, not larceny.
Many US states have moved away from this, consolidating larceny, embezzlement, and false pretenses into a single statutory offense following the Model Penal Code. New York's penal code is one example, defining larceny broadly enough to absorb all three.
Money laundering vs. fraud vs. embezzlement
These are three different dimensions of conduct, often present in the same case.
Fraud is deception used to obtain an unauthorized benefit or cause a loss.
Embezzlement is the misappropriation of property by someone entrusted with lawful possession. Depending on the jurisdiction, it may be classified as a form of fraud.
Money laundering is what is done with the proceeds afterward, whatever the predicate offense was.
Rita Crundwell's case shows the division. The theft of municipal funds was embezzlement. Had she also run transactions designed to conceal where that money came from, that could have been charged separately as money laundering.
Real-world cases of money laundering and embezzlement
In January 2026, police in India identified 44 money mule accounts linked to an alleged international cybercrime network. Investigators verified ₹750 crore (approximately $80 million) in fraud and estimated that the total could exceed ₹2,000 crore (approximately $220 million). Police said the network used a textile company, NGOs, fintech firms, credit societies, and shell companies to conceal the movement of funds.
Examples of embezzlement also show how it often relates to money laundering. In May 2026, Nigeria’s former power minister, Saleh Mamman, was sentenced to 75 years after being convicted of laundering 33.8 billion naira (approximately $24.7 million) through private companies. Prosecutors said the money was connected to government-financed hydroelectric projects. Although prosecuted as fraud and money laundering rather than embezzlement, the case illustrates how the diversion of funds intended for public purposes can generate proceeds that are subsequently laundered.
The Rita Crundwell case we discussed above ran on a much smaller stage and for far longer. The money went on quarter horses above all, along with houses, vehicles, and a luxury motorhome, and the spending was visible to anyone in Dixon who cared to look. What sustained the scheme for two decades was not sophistication, but a single official holding authorization, payment, and reconciliation at once. No one checked her against the bank statements.
Not every case reaches a courtroom. Employers who discover embezzlement often resolve it privately through restitution, resignation, or a negotiated settlement, which is one reason the reported figures understate the problem.
AML laws vs. internal financial controls
Money laundering laws and internal anti-embezzlement controls address different sides of financial risk. Anti-money laundering (AML) frameworks generally require covered businesses to understand customers and beneficial owners, assess risk, monitor activity, keep records, investigate warning signs, and report suspicions to the relevant authorities. Internal financial controls govern how the organization authorizes, records, reconciles, and safeguards its own assets to protect against embezzlement.
In the US, the Bank Secrecy Act (BSA) authorizes reporting and record-keeping requirements intended to help detect and prevent money laundering. The Financial Crimes Enforcement Network (FinCEN) administers the BSA and issues implementing rules and guidance. The Sarbanes-Oxley Act, meanwhile, strengthens accountability in public company reporting. Section 302 requires principal executive and financial officers to certify periodic reports, while Section 404 requires management to assess internal control over financial reporting.
Both AML and internal financial controls are necessary. Customer due diligence may identify a shell company receiving embezzled funds, but it will not correct an employer’s failure to obtain payment approvals. Conversely, segregating accounting duties may deter insider theft but will not satisfy a regulated institution’s customer monitoring and suspicious activity reporting obligations.
Requirements vary substantially by location and sector. See our guides below for more details:
North America
Latin America
Europe
Asia-Pacific
Middle East
Africa
Legal penalties for money laundering and embezzlement
Money laundering and embezzlement penalties depend on the country, the applicable statute, the value involved, the offender’s role and intent, the type of victim or institution, and any other related crimes. The consequences can be severe in jurisdictions around the world and may include imprisonment, fines, restitution or compensation, asset forfeiture, professional disqualification, license restrictions, and civil or regulatory action.
In the US, for example, a conviction under 18 USC §1956 can carry up to 20 years’ imprisonment and a fine of up to $500,000 or twice the value of the property involved, whichever is greater. Section 1957, which covers certain transactions exceeding $10,000 in criminally derived property, provides for up to 10 years’ imprisonment.
Meanwhile in Brazil, private-sector embezzlement may be prosecuted as misappropriation, which carries one to four years’ imprisonment and a fine under Article 168 of the Penal Code. When a public official embezzles assets entrusted to them, the offense can carry two to twelve years’ imprisonment and a fine. Money laundering is punishable by three to ten years’ imprisonment and a fine under Law No. 9,613/1998.
In India, embezzlement may constitute a criminal breach of trust under Section 316 of the Bharatiya Nyaya Sanhita. The basic offense carries up to five years’ imprisonment. Offenses committed by employees carry up to seven years' imprisonment, and public servants, bankers, brokers, and other entrusted professionals may face life imprisonment, as well as a fine. Money laundering is punishable by three to seven years’ imprisonment and a fine under Section 4 of the Prevention of Money Laundering Act.
Is embezzlement a federal or state crime?
In the United States, embezzlement can be either a federal or state crime. State authorities commonly prosecute the misappropriation of private property under embezzlement, larceny, theft, or fraud statutes. Federal jurisdiction may arise when the conduct involves:
- US government money, records, or property
- an officer or employee of a federally insured bank
- an organization or government receiving covered federal-program funds
- an employee benefit plan, labor organization, or other federally protected assets
- interstate communications or transactions supporting charges such as wire fraud
Theft or embezzlement of US government property (often involving bribery) worth more than $1,000 can carry up to 10 years under 18 USC §641. Theft, embezzlement, or willful misapplication by an officer or employee of a covered bank can carry up to 30 years under 18 USC §656.
As for whether money laundering is a felony, federal offenses under Sections 1956 and 1957 are felonies. However, a business’s AML control failure is not automatically equivalent to committing money laundering: depending on the facts and the law, compliance failings may result in civil, regulatory, or separate criminal liability.
Red flags of money laundering and embezzlement
Common AML red flags include:
- customer identity, beneficial ownership, or source of funds information that is inconsistent, unverifiable, or unnecessarily opaque
- activity that does not match the customer’s income, business, risk profile, or expected account use
- rapid movement of money through an account without a clear purpose
- repeated transactions just below reporting or review thresholds
- round-sum, looping, reversed, or unusually complex transfers
- unexplained payments involving third parties, multiple accounts, high-risk jurisdictions, shell companies, or anonymity-enhancing services
- unusual urgency, evasiveness, or resistance to reasonable due-diligence questions.
Suggested read: AML Red Flags: Common Indicators, Industry Examples, and Detection Best Practices
Potential embezzlement indicators include:
- unreconciled balances, unexplained shortages, missing receipts, altered statements, or repeated manual journal entries
- duplicate, sequential, round-sum, or just-below-approval invoices and expenses
- vendors sharing bank details, contact information, or addresses with employees
- unauthorized changes to payees, payroll, vendor master data, or access permissions
- one employee controlling authorization, payment, recording, and reconciliation
- repeated control overrides, after-hours system activity, audit-log gaps, or reluctance to take leave or share duties
- unexplained lifestyle changes or defensiveness around records and reviews.
How compliance teams detect and prevent money laundering and embezzlement
A risk-based AML program is calibrated to the organization's products, customers, geographies, and legal obligations. Core measures generally include KYC, KYB, customer due diligence, and beneficial ownership verification; sanctions, PEP, watchlist, and adverse media screening; customer risk scoring with enhanced due diligence for higher-risk relationships; ongoing customer and transaction monitoring; source of funds and source of wealth checks where appropriate; documented alert review, case management, escalation, and financial intelligence unit reporting; and regular training, independent testing, and control validation.
Preventing embezzlement means controlling insiders rather than customers. Organizations should separate authorization, custody, record-keeping, and reconciliation. Sensitive or high-value payments should require dual approval. Access should follow least privilege. Vendor and bank detail changes should be verified independently, through a channel other than the one that requested them. Accounts should be reconciled promptly, and payroll, expenses, refunds, inventory, and journal entries reviewed for anomalies.
Suggested read: AML Policy Explained: A Step-by-Step Guide to AML Compliance
Mandatory leave and job rotation expose schemes that depend on a single person maintaining constant control over a process. Confidential reporting channels matter because colleagues usually notice behavioral or procedural warning signs before analytics do. Access logs, immutable audit trails, surprise audits, and periodic reviews of dormant or excessive permissions all make concealment harder.
Controls also have to be tested against what people actually do with them. Crundwell's fake vendor account and bogus invoices sat inside a functioning municipal accounting process for over twenty years, which is the difference between a control that exists on paper and one that somebody exercises.
Suggested read: Insider Fraud: Why It Happens and How to Prevent It (2026)
The role of AI in fighting financial crime
AI can strengthen defenses against financial crime in general by analyzing the volume and combinations of data that manual reviews cannot consistently cover. In AML, machine-learning models can augment rules-based transaction monitoring by identifying deviations from a customer’s established behavior, mapping relationships between accounts and counterparties, updating risk scores, and prioritizing alerts.
On the embezzlement side, analytics can cross-reference employees, vendors, bank accounts, invoices, payments, access logs, and ledger entries in combinations no manual review would attempt. Models flag duplicate invoices, unusual approval patterns, new vendors receiving immediate high-value payments, employee-vendor links, repeated threshold avoidance, and transactions falling outside a user's normal role or hours. Natural-language processing extends the same treatment to invoice descriptions, case notes, communications, and adverse media.
Analytics can materially improve outcomes. The ACFE reports that organizations using proactive data analytics as an anti-fraud control experienced 53% lower fraud losses than those that did not. AI can make these checks even more efficient.
Yet AI is also strengthening financial crime. Money launderers can use synthetic identities, deepfakes, forged documents, automated transactions, and pattern obfuscation to evade conventional KYC and monitoring controls. Embezzlers and other fraudsters can generate false invoices, receipts, approval messages, and supporting records at scale. This is already visible in expense fraud.
As a tool against crime, AI must still remain governed and explainable. Models can reproduce bias, drift as behavior changes, miss unfamiliar schemes, or generate false positives. Recent incidents and experiments involving AI agents also demonstrate why systems with access to business functions require tightly controlled permissions and meaningful human oversight.
Organizations remain accountable for their decisions and should validate models, protect personal data, document alert logic, monitor performance, and retain meaningful human review, particularly for high-risk decisions and regulatory reports.
Over the next few years, institutions are likely to connect customer, employee, vendor, device, payment, and case data more closely and use AI to triage alerts and assemble evidence. Fully autonomous decisions should, however, remain limited.
Suggested read: How AI is Revolutionizing Anti-Money Laundering and Compliance
Money laundering and embezzlement: What to expect in 2027 and beyond
Money laundering and embezzlement controls will increasingly overlap as regulators demand demonstrable prevention, and AI adds a new layer of uncertainty around trust and attribution.
Agentic AI is complicating trust and accountability
AI agents with access to vendor records, payment systems, and approvals may be manipulated through compromised credentials or malicious instructions hidden in emails, invoices, and websites. This is a risk known as agent hijacking. A compromised agent could alter payment details, create supporting documents, or initiate transfers within its existing permissions. The AI would not itself be legally “embezzling” or “laundering,” but its involvement could obscure whether an action resulted from legitimate instructions, criminal manipulation, poor configuration, or system error.
Synthetic documents are becoming commonplace
AI-generated receipts rose from 0% of fraudulent receipts flagged by AppZen in March 2025 to 70.8% by mid-May 2026. These claims averaged around $100, helping them remain below common automatic-approval thresholds. Similar tactics are likely to spread to invoices, bank letters, and KYC documents.
Insider-enabled fraud is becoming a corporate criminal risk
To combat an escalating fraud crisis, the UK’s failure to prevent fraud offense took effect on September 1, 2025. It allows large organizations to be held liable when an associated person commits specified fraud with the intent to benefit the organization or its clients, without prosecutors having to prove that senior management knew of it. Early cases will clarify what constitutes reasonable prevention procedures. Regulators elsewhere are also strengthening their response to financial crime. In the EU, AMLA will select 40 high-risk cross-border financial institutions in 2027 for direct supervision beginning in 2028, bringing their AML controls under more consistent scrutiny across the bloc.
Virtual IBANs face greater scrutiny
Virtual IBANs are also coming under tighter regulatory scrutiny. From July 2027, the EU’s new AML framework will require financial institutions to identify and verify users of virtual IBANs and make virtual IBAN account information accessible through centralized account registers. This will make transparency around who controls and uses virtual IBANs increasingly important for detecting money laundering, fraud, and illicit fund flows.
AML and internal fraud teams are converging
Detecting an employee-controlled shell vendor may require that customer and HR data be in the same analytical view. The organizational barriers separating AML, fraud prevention, and internal audit are likely to erode. Shared investigations and data environments should follow, and the supporting technology will need to catch up.
Money laundering vs. embezzlement FAQ
-
Is embezzlement a felony?
Embezzlement can be a felony or a misdemeanor depending on the jurisdiction, the value of the property, the victim, and the circumstances. In the US, larger thefts and offenses involving federal property, federally insured banks, or other protected assets are generally prosecuted as felonies.
-
What are the stages of money laundering?
The traditional stages of money laundering are placement, layering, and integration. Sometimes extraction is mentioned as a fourth stage. However, modern money laundering is often a multi-layered process in which stages overlap, repeat, occur simultaneously, or are skipped entirely.
-
Is money laundering a felony?
Money laundering is a felony under US federal law, with convictions under 18 USC §§1956 and 1957 carrying substantial prison sentences and fines. Other jurisdictions also treat it as a serious criminal offense, although classifications and penalties vary.
Relevant articles
- Article
- 2 weeks ago
- 10 min read
Discover how AI helps institutions adapt to evolving AML compliance demands and financial crime risks in 2026.

- Article
- Jun 16, 2026
- 10 min read

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


