Skip to main content
90 Wire Transfers Per Operation Isn't UnusualAML and KYC
5 min readFor AML/KYC Compliance Officers

90 Wire Transfers Per Operation Isn't Unusual

You've probably heard a compliance colleague say something like "we flag layering patterns" or "our transaction monitoring catches structuring." But when the Italian mafia organization Ndrangheta executes an average of 90 transactions per money laundering operation, your rule-based system isn't catching patterns, it's drowning in them.

The myths around anti-money laundering detection persist because they're comforting. They suggest that if you follow the checklist, file your Suspicious Activity Reports (SARs), and run your transaction monitoring software, you're covered. The reality is messier. Modern money laundering operations exploit the gaps between what your compliance program assumes and what actually happens in your systems.

Wire Transfer Monitoring: It's Not Just About Large Transactions

Professional launderers vary amounts, keep transfers under reporting thresholds, and use reputable organizations specifically to avoid your large-transaction alerts.

Your Bank Secrecy Act monitoring probably flags wire transfers above $10,000. That's required. But the layering stage, where funds move from account to account, bank to bank, jurisdiction to jurisdiction, doesn't rely on large transfers. It relies on volume and complexity.

When you're reviewing alerts, you're looking for the wrong signal. The question isn't "Is this transfer large?" It's "Why are 15 transfers of $4,800 each moving through this account in 72 hours?" The pattern matters more than the threshold, but most transaction monitoring systems aren't designed to correlate sequences across time windows that extend beyond a single business day.

Private Banking: Less Scrutiny, More Risk

Private banking clients often receive less scrutiny because the business model incentivizes relationship preservation over compliance friction.

Private banking operates semi-autonomously in most institutions. Relationship managers earn fees based on assets under management. When two private bankers formerly employed by American Express Bank International were convicted of money laundering for the Mexican drug cartel of Juan Garcia Abrego, it wasn't because the bank lacked policies. It was because the incentive structure rewarded asset retention over enhanced due diligence.

Your Know Your Customer (KYC) procedures might require Source of Wealth documentation for private banking clients, but if the relationship manager can satisfy that requirement with a single attestation letter and move on, you haven't actually verified anything. The pressure works both ways: the client pressures the banker to minimize inconvenience, and the banker pressures compliance to expedite reviews because delayed onboarding means lost revenue.

If your private banking division uses different KYC thresholds, different transaction monitoring rules, or different approval workflows than retail banking, you've created a structural vulnerability. Criminals know this. That's why they target private banking relationships.

Credit Cards: A Hidden Money Laundering Tool

Credit cards are layering tools, and prepayment refunds create legitimacy for already-placed funds.

The placement stage, getting dirty cash into the financial system, is hard with credit cards. But layering and integration are straightforward. A launderer prepays a credit card with funds already in the banking system, creates a positive balance, then requests a refund. That refund becomes a documented, traceable source of funds.

When the launderer uses those funds to purchase goods or transfer money elsewhere, the origin story is clean: "It's a credit card refund." Your transaction monitoring system sees a refund from a major card issuer, a reputable organization, and assigns it low risk.

The control gap is in your refund approval process. Do you flag prepayment refunds above a certain threshold? Do you review accounts that cycle through prepayment-refund patterns multiple times per quarter? If your fraud prevention team monitors for refund abuse but your AML team doesn't correlate those same patterns, you're missing the integration stage entirely.

Money Services Businesses: Your Responsibility Too

If you bank Money Services Businesses (MSBs), their compliance gaps are your compliance gaps.

MSBs, currency exchanges, money transmitters, check-cashing services, are required to register with FinCEN and maintain their own AML programs under the Bank Secrecy Act. But when you provide banking services to an MSB, you're responsible for understanding their customer base and transaction patterns.

Money launderers use MSBs to convert criminal proceeds into local currency at the destination country. The launderer sells dollars to foreign businessmen making legitimate export purchases, and the funds emerge clean on the other side, documented as foreign exchange transactions tied to import-export deals.

Your customer due diligence on the MSB itself might be thorough. But do you understand the MSB's customers? Do you know which jurisdictions their transactions touch? If an MSB customer is sending $2 million per month to three countries with weak AML enforcement, and your monitoring system only sees the MSB as the direct customer, you're not seeing the risk.

The FFIEC BSA/AML Examination Manual requires banks to apply risk-based due diligence to MSB customers, including understanding the MSB's own customer base. That's not a courtesy, it's an obligation.

Machine Learning: A Tool, Not a Solution

Machine learning identifies anomalies, but you still need to define what constitutes suspicious activity in your specific context.

Advanced analytics and machine learning can surface complex patterns that rule-based systems miss. A model trained on historical SAR data might flag accounts with behavioral similarities to known laundering cases. But the model can't tell you whether 90 wire transfers in a month is suspicious for a particular customer type. You have to teach it that.

If your training data includes mostly Structuring (Smurfing) cases and large cash deposits, your model will optimize for those patterns. It won't catch the private banking client whose Source of Wealth documentation is inconsistent, or the MSB whose transaction velocity doubled after onboarding three new agents in high-risk jurisdictions.

Technology enhances detection when it's paired with subject matter expertise. Your compliance team needs to define the risk indicators, validate the model outputs, and investigate the alerts. The machine surfaces the pattern; you provide the context.

What to Do Instead

Start with your transaction monitoring rules. Map them against actual laundering typologies, not just regulatory thresholds. If your system flags individual transactions but doesn't correlate sequences, you're missing layering patterns.

For private banking, separate the incentive structure from the compliance function. Relationship managers shouldn't approve their own KYC exceptions or escalate their own SAR decisions. Require independent review for all Politically Exposed Person (PEP) relationships and all clients whose Source of Wealth involves jurisdictions with weak AML enforcement.

For credit cards, add prepayment refund monitoring to your AML program. Flag accounts that cycle through prepayment-refund patterns, especially when the refund recipient differs from the original payor.

For MSBs, enhance your customer due diligence to include the MSB's customer base. Require documentation of the MSB's own AML program, including their Watchlist Screening procedures and their SAR filing history. If the MSB can't demonstrate effective controls, you're inheriting their risk.

And for technology: use machine learning to surface anomalies, but don't outsource judgment. Your compliance team defines what's suspicious. The model just helps you find it faster.

You Might Also Like