Jurisdicción de Estados Unidos,
explicada con claridad.

U.S. jurisdiction,
explained clearly.

Money Laundering Red Flags: 20 Signals Your Team Should Catch

red flags

The FFIEC BSA/AML Examination Manual provides an authoritative starting point for money laundering red flags. Appendix F publishes examples used to help banks and examiners recognize potentially suspicious activity, while warning that the list is not exhaustive and that a flag is not proof of criminal conduct.

The appendix supplies every signal below. We group the signals by what each one reveals, because a red flag helps only when a reviewer knows what to do next. Compliance Officers runs the counterparty investigation that turns a flag into an answer.

Red flags read differently depending on where in the process they appear. Placement, layering and integration leave distinct traces, and knowing which of the three stages of money laundering a pattern suggests is often what turns an ambiguous signal into a decision.

The caveat the manual insists on — and so do we

Appendix F states it directly: “The mere presence of a red flag is not by itself evidence of criminal activity.” These are examples of potentially suspicious activity that may warrant additional scrutiny. Closer examination should help determine whether the activity is suspicious or one for which there is no reasonable business or legal purpose. Treating a flag as a verdict creates a compliance failure of its own and can produce wrongful account closures and discriminatory outcomes.

Group 1 — Confirm the Customer's Identity

These signals share a theme: the information you need is not arriving.

  1. A customer uses unusual or suspicious identification documents that cannot be readily verified.
  2. A customer first uses a Social Security number and later provides an individual taxpayer identification number.
  3. A customer uses different taxpayer identification numbers with variations of his or her name.
  4. A business is reluctant, when establishing a new account, to provide complete information about the nature and purpose of its business, anticipated activity, prior banking relationships, its officers and directors, or its business location.
  5. A customer’s home or business telephone no longer works.
  6. A trust, shell company or private investment company is reluctant to provide information on controlling parties and underlying beneficiaries. The manual notes that beneficial owners may hire nominee incorporation services to establish shell companies and open accounts while shielding the owner’s identity.

What to do: this group is answerable. Identity, legal existence and ownership are verifiable facts. A refusal to supply them is information; an inability to verify them independently is more.

Group 2 — Somebody Is Avoiding the Paperwork

These flags have direct legal significance because intentionally structuring a transaction to evade a reporting or recordkeeping requirement can itself violate 31 U.S.C. 5324.

  1. A customer or group tries to persuade an employee not to file required reports or maintain required records.
  2. A customer refuses to provide information needed for a mandatory report or abandons the transaction after learning about the filing requirement.
  3. A customer asks for an exemption from reporting or recordkeeping requirements.
  4. A person customarily uses the ATM to make several deposits below a specified threshold.
  5. A customer deposits funds into several accounts, usually in amounts of less than $3,000, subsequently consolidated into a master account and transferred outside the country.
  6. A customer accesses a safe deposit box before making currency deposits structured at or just under $10,000, to evade CTR filing requirements.

What to do: escalate immediately, and do not explain the escalation to the customer. Signals 7 to 9 are also a live reminder of the confidentiality rule.

red flags

Group 3 — The Money Moves in a Way the Business Does Not Explain

  1. The customer sends many funds transfers in large, round hundred-dollar or thousand-dollar amounts.
  2. Funds transfer activity occurs to or from a higher-risk geographic location without an apparent business reason, or inconsistently with the customer’s business or history.
  3. The account receives many small transfers or deposits by check and money order, then quickly wires most of the funds to another city or country in a pattern inconsistent with the customer’s business.
  4. Funds transfers contain limited content and lack related party information.
  5. The currency transaction patterns of a business show a sudden change inconsistent with normal activities.
  6. The customer deposits or purchases a large volume of cashier’s checks, money orders or funds transfers that the nature of the business does not appear to justify.

What to do: compare the activity with the customer’s documented profile, expected transaction pattern and available commercial explanation. Without a current profile, the reviewer lacks a reliable baseline for deciding whether the activity is unusual.

Group 4 — The Commercial Story Does Not Hold Together

  1. The business buys goods or services that do not match the customer’s stated line of business, or pays with instruments that do not come from the purchasing entity’s account.
  2. In trade finance: obvious over- or under-pricing of goods and services, misrepresentation of quantity or type of goods, a transaction structure that appears unnecessarily complex and designed to obscure the true nature of the transaction, or a request to pay proceeds to an unrelated third party.

What to do: transaction data alone cannot resolve this group. It requires knowing what the counterparty actually does — which is background investigation, not monitoring.

Turning Red Flags Into Decisions

What the flag is aboutCan software answer it?What resolves it
Identity and documentsNoIndependent verification of identity and legal existence
Ownership and controlNoBeneficial ownership research; the 25 percent and control test at 31 CFR 1010.230
Reporting avoidancePartlyEscalation and staff training; potentially a SAR within 30 calendar days
Transfer patternsYes, if a profile existsMonitoring against the customer risk profile
Commercial coherenceNoBackground investigation of the counterparty's real activity

Software can organize alerts and transaction data, but it cannot independently establish identity, legal existence, ownership or commercial purpose. Those questions require documented evidence, human review and an authorized decision-maker.

How to Turn Red Flags Into a Controlled Review Process

A list of red flags has little value unless each signal has an owner and a response path. Start by mapping the signal to the data the business actually possesses. A customer-profile mismatch requires current KYC information. A transfer pattern requires relationship-level transaction data. An ownership concern requires entity and beneficial-owner records. A geography alert requires the correct location and counterparty context.

Next, define escalation by risk rather than by dramatic wording. An existing invoice or updated business explanation can resolve some alerts. Others require enhanced due diligence, management review, account restrictions or a SAR assessment by a covered institution. The first reviewer should not improvise a legal conclusion or tell the customer that the institution may file a SAR.

Aggregation matters because transactions that look ordinary in isolation can become meaningful when grouped by customer, related entity, agent, device, address or time period. The reverse is also true: an apparently unusual payment can become coherent when matched to a seasonal business cycle or documented acquisition. Record the pattern and the explanation tested by the reviewer. The review record should separate facts observed by the institution, information supplied by the customer, independently verified evidence and unresolved gaps. That distinction prevents a preliminary concern from being restated later as an established fact.

Finally, test the process itself. Sampling should ask whether staff reviewed alerts on time, preserved evidence, applied the same standard, escalated concerns and completed remediation. Money laundering red flags are not convictions. They are prompts for a disciplined inquiry that either resolves the concern or moves it to the person authorized to make the next decision.

How Compliance Officers Closes the Gap

Compliance Officers provides documented AML checks and due-diligence support for U.S. and international clients. We examine the legal, financial and reputational background of the person or company in scope, verify identity and legal existence from available records, and organize the findings in a written report for the client’s decision file.

The service does not issue a legal opinion, determine guilt, replace the institution’s designated decision-maker or guarantee a regulator’s response. It helps establish facts, identify inconsistencies and preserve a review record before the company commits to a transaction or closes an alert.

A useful engagement begins with a defined subject, purpose and risk question. The client defines the review subject—a person, entity, transaction or relationship—and provides the available identifiers and context. The resulting work can address legal existence, ownership information, relevant public-record findings, sanctions and adverse-information indicators, and inconsistencies that require clarification. The report records its scope and limitations so readers do not mistake an absence of findings for proof that no risk exists.

Due diligence is also time-specific. A report reflects the sources and facts available during the review; it does not remain current indefinitely. A new owner, jurisdiction, product, payment route, regulatory event or material adverse fact can justify an update. The client should connect the report to its own risk classification, escalation process, retention rules and authorized decision-maker. That creates an auditable handoff between external research and the company’s internal compliance responsibility.

For related context, review our resources on corporate KYC, FinCEN filing and compliance and FinCEN requirements for small businesses. These topics overlap, but they are not interchangeable: counterparty due diligence, BSA program duties and beneficial-ownership reporting each have their own trigger and scope.

Frequently Asked Questions

Does a red flag mean the customer is laundering money?

No. The FFIEC manual states that the mere presence of a red flag is not by itself evidence of criminal activity. A flag indicates activity that may warrant additional scrutiny; closer examination determines whether it is genuinely suspicious.

No. The filing duty arises when the institution knows, suspects or has reason to suspect one of the conditions in 31 CFR 1020.320(a)(2) or 1022.320(a)(2), above the applicable threshold. A flag is an input to that judgment, not the judgment.

Appendix F of the FFIEC BSA/AML Examination Manual, the interagency manual used by the federal banking agencies. The appendix also notes that FinCEN issues advisories containing further red flag examples.

No, and the manual says so: the lists are not all-inclusive. The appendix offers examples that help institutions and examiners recognize possible schemes.

Be extremely careful. You may ask ordinary business questions, but the regulations protect a SAR and any information revealing its existence and prohibit disclosure (31 CFR 1020.320(e); 1022.320(d)). Explaining a decision by reference to a filing breaches the rule.

Yes. That is the core of our AML Checks and Due Diligence work: legal, financial and reputational background, verification of identity and legal existence, and a written report for your file. We can arrange the review remotely.

Resolve the Flag Before You Decide

Has a counterparty triggered a signal you cannot close from the data you hold?

Compliance Officers investigates the legal, financial and reputational background of individuals and companies, verifies identity and legal existence, and documents the review in a written report.

Request an evaluation

Phone and WhatsApp: +1 305-647-3000
Email: info@complianceofficers.org

Legal disclaimer: This article provides general information about United States anti-money laundering rules and does not constitute legal advice, a legal opinion or a guarantee of any regulatory outcome. Obligations depend on the type of institution, its activities and its regulator, and the rules change. Citations reflect the text in force on the date shown. Confirm current requirements with FinCEN, your functional regulator or qualified counsel before acting.

Related News

Compliance Officers

Consulta sin ningún costo!

Request information with no commitment

QR-Compliance Officers

Do you want to talk with us?

Últimas publicaciones