Skip to main content
Category: AML and KYC

Layering

Simply put

The evidence provided for this entry does not contain any source relevant to payment security, fraud prevention, anti-money laundering, or PCI DSS compliance. The supplied sources describe unrelated uses of the word 'layering' in geospatial mapping, horticulture, and fashion. A reliable in-domain definition cannot be produced from this evidence packet.

Formal definition

No authoritative in-domain evidence is available in the supplied packet to define 'Layering' as it is used in this publication's subject area. In anti-money laundering practice the term commonly refers to a distinct stage of money laundering, but none of the provided sources address that or any other payment-security or fraud usage, and this entry does not assert such a definition without supporting evidence. A definition should be regenerated once appropriate authoritative sources (for example, FATF or FinCEN guidance for AML usage, or applicable card brand and PCI documentation for any payment-specific usage) are supplied and verified against the current published texts.

Why it matters

This glossary entry cannot be completed as a substantive definition because the evidence packet supplied for the term "Layering" contains no source relevant to payment security, fraud prevention, anti-money laundering, or PCI DSS compliance. The five provided sources address geospatial mapping, plant propagation, and clothing, all of which are out of scope for this publication's subject area. Presenting an in-domain definition here would require introducing factual claims that the supplied evidence does not support.

Who it's relevant to

Editorial and research staff
This entry is blocked pending in-domain sourcing. To complete it, supply authoritative references appropriate to the intended usage, then verify the resulting definition against those current published texts before publication. Do not fill the gap with uncited material.
Readers seeking a definition
No reliable definition can be offered from the current evidence packet. Readers should not treat the absence of a definition here as guidance and should consult the relevant authoritative source for the specific usage they have in mind.

Inside Layering

Layering (money laundering stage)
The second stage in the commonly described three-stage money laundering model (placement, layering, integration). Layering refers to conducting a series of transactions intended to distance illicit funds from their criminal origin and obscure the audit trail, making tracing more difficult for investigators.
Transaction distancing
The core objective of layering: moving funds through multiple accounts, entities, jurisdictions, or instruments so that the connection between the money and its predicate offense becomes harder to reconstruct.
Relationship to placement and integration
Layering typically follows placement (introducing illicit funds into the financial system) and precedes integration (returning the funds to the launderer with an apparently legitimate origin). These stages are a conceptual model and may overlap or occur in different sequences in practice.
Relevance to payment and merchant risk
In a payments context, layering activity may surface through complex refund/chargeback cycles, transaction structuring, use of shell merchants, or rapid movement of funds across payment accounts. Detecting it generally depends on transaction monitoring rather than on any single payment control.
Regulatory framing
Layering is addressed under anti-money-laundering (AML) and counter-terrorist-financing frameworks such as those described by the Financial Action Task Force (FATF) and, in the United States, administered by FinCEN under the Bank Secrecy Act. It is distinct from the PCI DSS family of standards, which govern account data protection rather than AML obligations.

Common questions

Answers to the questions practitioners most commonly ask about Layering.

Is layering a defined term within PCI DSS or the payment security standards?
No. Layering is not a control or defined term in PCI DSS, PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS. Within the broader financial-crime domain, layering has an established meaning as a stage of money laundering, but that concept is governed by anti-money-laundering frameworks and regulations rather than by the PCI standards. Readers should not expect to find layering as a numbered PCI DSS requirement, and any AML use of the term should be confirmed against current authoritative AML guidance rather than PCI documentation.
Does 'layering' here mean the same thing as 'defense in depth' or layered security controls?
Not necessarily, and the two should not be conflated. In an information-security context, practitioners sometimes speak informally of layering security controls, which overlaps with the concept of defense in depth. In the financial-crime context, layering refers instead to a stage of the money-laundering process. Because the same word carries different meanings in different domains, an entry that uses it should state which sense is intended and avoid presenting the security-architecture sense and the AML sense as interchangeable.
How does the concept relate to fraud and transaction monitoring programs in a payments environment?
Payment processors and merchant risk teams that operate transaction-monitoring or suspicious-activity programs may encounter layering as part of AML typologies rather than PCI scope. Detection of such patterns typically relies on behavioral analytics and rules that carry inherent false-positive and false-negative trade-offs. Any monitoring obligation, its scope, and its limitations are defined by the applicable AML regulatory framework for the entity and region, not by the PCI standards, so implementation should be aligned to that governing authority.
Where should a compliance officer look to confirm the authoritative definition and obligations?
For the AML sense of the term, confirm the definition and any obligations against current authoritative sources appropriate to your jurisdiction, such as FATF guidance and the relevant national financial-intelligence or regulatory authority. For anything relating to cardholder data protection, consult the current published PCI DSS and the applicable PCI standard directly, since requirement numbering and wording differ between versions. Do not rely on a fixed requirement number or a single secondary summary.
If our program spans both PCI DSS and AML obligations, how should the term be handled to avoid scope confusion?
Keep the two frameworks and their controls documented separately, and label which regime governs each requirement. Cardholder data protection controls fall under PCI DSS and the related PCI standards, while transaction-based financial-crime controls fall under the applicable AML regime. When a policy or glossary references layering, specify the intended domain so that engineers, fraud analysts, and auditors do not misattribute an AML concept to a PCI requirement or vice versa.
What are the known limitations of controls associated with detecting this activity?
Detection controls associated with financial-crime monitoring are intended to help identify suspicious patterns but do not prevent or guarantee elimination of illicit activity. They involve tuning trade-offs, where tighter thresholds increase false positives and looser thresholds increase false negatives. The precise effectiveness, thresholds, and reporting duties depend on the governing AML framework, the institution's risk profile, and the region, and exact performance figures depend on source, period, and methodology.

Common misconceptions

Layering is a term specific to network security or data protection defenses (such as defense-in-depth).
While 'layering' is used informally in security to describe layered controls, in the compliance and financial-crime domain the established meaning refers to the second stage of money laundering. The two usages are unrelated and should not be conflated; AML obligations are governed by AML/CTF regulation, not by PCI DSS.
PCI DSS controls address or detect layering.
PCI DSS focuses on protecting cardholder data and sensitive authentication data, not on detecting money laundering. AML detection of layering is governed by separate frameworks (e.g., FATF recommendations, FinCEN/BSA requirements) and typically relies on transaction monitoring, KYC, and suspicious activity reporting programs that are out of PCI DSS scope.
Effective transaction monitoring guarantees that layering will be identified.
Monitoring can help reduce and surface suspicious activity but cannot guarantee detection. Layering is deliberately designed to evade tracing, and monitoring systems carry inherent false-positive and false-negative trade-offs. The precise effectiveness depends on rules, data quality, methodology, and regulatory context.

Best practices

Treat layering detection as an AML/CTF obligation governed by frameworks such as FATF guidance and, where applicable, FinCEN/BSA requirements, rather than assuming PCI DSS or other payment-security standards cover it.
Implement transaction monitoring capable of identifying patterns associated with layering, such as rapid movement of funds across accounts or entities, while acknowledging and tuning for false-positive and false-negative trade-offs.
Correlate layering indicators with know-your-customer and merchant onboarding data so that anomalous fund movement can be assessed against the expected profile of the account or merchant.
Maintain clear separation between AML controls and PCI DSS account-data-protection controls in policy and documentation, so obligations under each framework are addressed by the appropriate program.
Establish escalation and suspicious activity reporting procedures aligned to the applicable regional regulator, recognizing that reporting thresholds and rules vary by jurisdiction and change over time.
Validate and periodically review monitoring rules against current typologies and published regulatory guidance rather than relying on static thresholds, confirming requirements against the current applicable standards.