Skip to main content
Category: Fraud Typologies

Structuring (Smurfing)

Also known as: Smurfing
Simply put

Structuring is the practice of breaking up a large sum of money into multiple smaller transactions so that each falls below reporting or scrutiny thresholds and appears less suspicious. Smurfing is a form of structuring that typically involves illegally obtained funds and multiple people, often low-level operatives known as 'smurfs,' who carry out the smaller transactions. Both practices are illegal, though structuring can sometimes involve legitimate funds while smurfing generally involves illicit funds.

Formal definition

Structuring refers to deliberately splitting a single large transaction into multiple smaller transactions designed to fall below applicable reporting or suspicious-activity thresholds, thereby evading detection or mandatory reporting. Smurfing is a specific method of structuring in which large sums of illicitly obtained cash are divided into smaller, less conspicuous amounts, commonly distributed across multiple individuals ('smurfs') or accounts. Practitioners generally distinguish the two on two dimensions: structuring is often simpler and may be conducted by a single actor and can involve legitimately sourced funds, whereas smurfing tends to be more complex, involves a group of participants, and characteristically involves illegally obtained funds. Both are illegal under anti-money-laundering frameworks.

Why it matters

Structuring and smurfing directly undermine the transaction-reporting regimes that anti-money-laundering frameworks rely on to surface suspicious activity. By deliberately keeping individual transactions below applicable reporting or scrutiny thresholds, actors attempt to prevent the mandatory reports and reviews that would otherwise flag a large movement of funds. For compliance teams, this means that the absence of any single large, obviously suspicious transaction is not evidence that a customer relationship is low risk; the risk may instead be distributed across many smaller transactions that individually appear unremarkable.

Who it's relevant to

AML Compliance Officers
Responsible for transaction-monitoring programs and suspicious-activity reporting. They must design controls that detect fragmented transaction patterns across accounts rather than relying solely on single large-transaction alerts, while managing the false-positive burden that threshold-based rules place on legitimate customers.
Fraud and Financial Crime Analysts
Investigate alerts and reconstruct activity across accounts and individuals. Understanding the distinction between single-actor structuring and group-based smurfing helps analysts decide whether to expand an investigation to linked parties and whether the underlying funds may be legitimately or illicitly sourced.
Acquirers and Payment Processors
May observe distributed transaction patterns across merchants or accounts within their portfolios. They benefit from monitoring that correlates related activity to identify deliberate fragmentation, recognizing that the presence of many small transactions is not by itself proof of wrongdoing.
Merchant Risk Teams
Assess whether patterns of small, threshold-adjacent transactions across a customer base reflect ordinary behavior or an attempt to evade scrutiny, and must weigh detection sensitivity against the risk of flagging legitimate customers.

Inside Structuring (Smurfing)

Transaction Splitting
The core mechanic of structuring, in which a larger sum is broken into multiple smaller amounts so that individual transactions fall below reporting or monitoring thresholds. In payments contexts this may appear as multiple lower-value charges rather than a single larger one.
Threshold Avoidance
The intent to keep individual transactions under defined reporting or review limits. Note that the specific thresholds and reporting obligations are governed by applicable anti-money-laundering (AML) laws and regulations, which vary by jurisdiction and change over time; these are separate from PCI DSS requirements.
Layering Across Accounts or Channels
Distributing structured transactions across multiple accounts, cards, merchants, or payment channels to obscure the aggregate pattern and reduce the likelihood that any single monitoring point observes the full activity.
Aggregate Pattern Signal
The behavioral indicator detection systems look for, where many sub-threshold transactions together form a pattern inconsistent with normal account or cardholder behavior. Detection depends on correlating activity that individually appears legitimate.
Relationship to Fraud Types
Structuring is a technique that may accompany money laundering or the movement of proceeds and can overlap with account takeover or first-party fraud scenarios. It is distinct from card-present versus card-not-present fraud categories and does not by itself indicate a specific fraud type.

Common questions

Answers to the questions practitioners most commonly ask about Structuring (Smurfing).

Is structuring the same thing as money laundering?
No. Structuring refers specifically to breaking up transactions into smaller amounts to evade a reporting or recordkeeping threshold, while money laundering is the broader process of concealing the origin of illicitly obtained funds. Structuring can be one technique used within a laundering scheme, but it is a distinct concept: structuring is defined by the intent to avoid triggering reporting requirements, regardless of whether the underlying funds are illicit. Treat them as related but separate ideas in your controls and documentation.
If each individual transaction stays under the reporting threshold, does that mean no reporting obligation is triggered?
Not necessarily. The purpose of structuring detection is to identify patterns where amounts are deliberately kept below a threshold to avoid a report. Reporting and suspicious-activity obligations are governed by applicable regulations and program rules, which may require action based on aggregated behavior or apparent intent, not solely on whether any single transaction crossed a fixed amount. Whether a specific obligation applies depends on the governing rules and should be confirmed against the current requirements, not assumed from the per-transaction amount alone.
What transaction patterns should detection logic look for to flag potential structuring?
Detection commonly examines patterns such as multiple transactions falling just under a threshold, repeated similar amounts within a short window, activity spread across related accounts or instruments, and timing that appears designed to avoid aggregation. These are indicators that may warrant review rather than proof of structuring. Any rule set produces false positives and false negatives, so tuning thresholds and windows involves trade-offs between review workload and missed patterns. Confirm what qualifies as reportable against the applicable rules rather than relying on a single heuristic.
How should structuring detection be tuned to manage false positives?
Tuning typically involves adjusting the amount bands, time windows, and aggregation logic that group related activity, then reviewing outcomes against confirmed cases. Tightening rules to catch more potential structuring tends to increase false positives and analyst workload, while loosening them risks false negatives. There is no configuration that eliminates both, so tuning is an ongoing balance informed by review results. Document the rationale for chosen thresholds so decisions can be explained and revisited as behavior changes.
How does aggregation across related accounts or instruments factor into detection?
Because structuring may spread activity across multiple accounts, cards, or parties, detection often aggregates behavior using identifiers that link related activity rather than evaluating each account in isolation. The effectiveness of this depends on the quality of the linking data and on how relationships are established. Aggregation across entities may surface patterns that per-account monitoring misses, but it can also introduce false associations. Validate linking logic and treat aggregated alerts as inputs for review under the applicable rules.
What should happen after a structuring alert is generated?
An alert generally initiates a review process rather than an automatic determination. Analysts typically assess the flagged activity, gather context, and decide whether it meets the criteria for escalation or reporting under the governing rules. Because alerts include false positives, disposition workflows and documented rationale for each decision are important. Whether a specific alert leads to a report depends on the applicable regulations and program requirements, which should be confirmed against the current standards for your jurisdiction and program.

Common misconceptions

Structuring detection is a PCI DSS requirement.
Reporting obligations tied to structuring arise from AML laws and regulations, not from PCI DSS. PCI DSS governs the protection of cardholder data and sensitive authentication data; it does not define transaction-reporting thresholds. Practitioners should confirm which regulatory regime applies to a given control rather than attributing it to PCI DSS.
Keeping transactions under a threshold guarantees the activity goes undetected.
Threshold-based rules are only one detection layer. Behavioral and aggregate-pattern analysis is intended to surface sub-threshold structuring, though such detection involves false-positive and false-negative trade-offs and does not guarantee identification of every case.
Any group of small transactions is structuring.
Many legitimate customers make frequent low-value transactions. Structuring implies intent to evade thresholds or monitoring, which cannot be inferred from transaction size alone and typically requires corroborating pattern and context.

Best practices

Correlate activity across accounts, cards, merchants, and channels rather than evaluating transactions in isolation, since structuring is designed to defeat single-point monitoring.
Confirm applicable reporting thresholds and obligations against the current AML laws and regulations for each relevant jurisdiction rather than assuming fixed or universal limits.
Combine threshold-based rules with behavioral and aggregate-pattern analytics, and tune them to manage the trade-off between false positives and false negatives.
Document the rationale and intent indicators behind structuring alerts so investigators can distinguish evasive behavior from legitimate frequent low-value activity.
Keep AML/structuring controls organizationally and technically distinct from PCI DSS data-protection controls, while ensuring both apply to the relevant systems.
Periodically review and update detection logic as network rules, regulatory thresholds, and observed evasion techniques change, and validate changes before deployment.