Prepaid cards often spark debate in compliance discussions. Some see them as minor payment tools that don't need serious anti-money laundering (AML) focus, while others view them as uncontrollable products. Both perspectives are flawed.
The prepaid card market is expected to surpass USD 3.1 trillion by 2021, and every dollar through these cards carries potential money laundering risks. Misconceptions about prepaid card controls can create vulnerabilities in your AML program that criminals exploit. Here's what your team needs to know.
Myth 1: Prepaid cards don't require customer identification
Reality: They do, but requirements differ by card type and jurisdiction.
Confusion arises from differences between reloadable and non-reloadable cards. Non-reloadable cards, like gift cards, may have reduced Customer Identification Program (CIP) requirements under the Bank Secrecy Act due to transaction limits and non-reloadability. Reloadable cards, however, require full CIP compliance.
The EU's 5th Anti-Money Laundering Directive reduced transaction limits for prepaid cards to address identification gaps. This wasn't optional; it was a regulatory response to abuse patterns.
Criminals exploit weak implementation of existing requirements, not regulatory loopholes. Your program should differentiate card types and apply appropriate CIP procedures. Issuing reloadable cards without verifying customer identity is non-compliant.
Myth 2: Transaction monitoring can't detect prepaid card layering
Reality: Prepaid card transactions create data trails like other payment types; you need to monitor for specific patterns.
Layering with prepaid cards follows predictable steps: load funds, buy high-value goods, resell, and repeat. These patterns are visible in transaction data if you look for them.
Red flags for prepaid card layering include:
- Multiple cards linked to the same tax ID with name variations
- Load amounts just below reporting thresholds
- Rapid fund loading and withdrawal
- Geographic anomalies, like simultaneous transactions in different regions
- Purchasing behaviors that don't match the cardholder's profile
The FFIEC BSA/AML Examination Manual expects you to tailor transaction monitoring rules to your products. If your scenarios don't account for prepaid card-specific typologies, examiners will note the gap.
Myth 3: Prepaid cards are untraceable across borders
Reality: Cross-border use creates more detection opportunities.
While prepaid cards are easier to transport than cash, their use generates an ISO 8583 authorization message with details like merchant category code and location. If a card issued in Texas is used in Romania, your monitoring system should flag it.
The real risk isn't the card's portability; it's failing to set geographic controls or monitor for location anomalies. Financial Action Task Force guidance addresses cross-border prepaid card risks and expects issuers to implement proportionate controls.
Effective measures include:
- Geofencing: restrict card use to specific countries unless exceptions are requested
- Velocity limits on international transactions
- Enhanced due diligence for cards shipped outside your primary jurisdiction
- Alerts for authorization patterns suggesting misuse
Myth 4: Third-party loading is always suspicious
Reality: Third-party loading is a risk factor, not inherently suspicious. Context matters.
Legitimate scenarios exist, such as employers loading payroll onto employee cards or family members funding a relative's card. The issue is whether the relationship makes sense based on customer information.
Frequent loading by unrelated third parties, especially followed by immediate withdrawals or purchases, suggests structuring or money mule activity. This warrants closer scrutiny and possibly a Suspicious Activity Report (SAR).
Your Customer Due Diligence (CDD) process should establish expected funding sources at account opening. Investigate deviations from this baseline. Don't file a SAR on every third-party load, but don't ignore patterns either.
Myth 5: Reducing transaction limits solves the problem
Reality: Limits reduce individual transaction risk but don't address anonymity and bulk card acquisition.
The EU's decision to reduce prepaid card transaction limits under the 5th Anti-Money Laundering Directive reflects a belief that smaller transactions carry less risk. This is true for individual cards but not when a network acquires many cards.
Transaction limits make laundering harder but don't eliminate it. A criminal can move $50,000 through 50 cards instead of five. Your monitoring system should detect such patterns.
More effective controls focus on the customer:
- Limit the number of cards one person can register
- Monitor for patterns suggesting a single entity controls multiple cards
- Require enhanced due diligence for multiple card requests or high load limits
- Screen for Politically Exposed Persons and watchlist matches at onboarding
What to do instead
Build your prepaid card AML program around three principles:
Know your product risk. Reloadable cards with international acceptance and high load limits carry more risk than closed-loop gift cards. Calibrate your controls accordingly. Document your risk assessment and update it when introducing new card features or expanding to new markets.
Monitor holistically. Look for patterns across cards, customers, and funding sources. If your system treats each card as isolated, you'll miss networks operating multiple cards in coordination.
Automate what you can, investigate what you must. Machine learning models excel at spotting unusual patterns in high-volume data, but they can't replace human judgment. When your system flags a pattern, assign someone with AML expertise to investigate. If the activity doesn't align with the customer's profile, file a SAR. The threshold for suspicion is reasonable suspicion, not certainty.
Prepaid cards aren't inherently risky or impossible to monitor. They're payment tools with specific risk characteristics that need specific controls. Treat them accordingly.



