Skip to main content
Category: AML and KYC

Trade-Based Money Laundering

Also known as: TBML, trade money laundering, trade-based ML
Simply put

Trade-based money laundering (TBML) is a form of financial crime in which criminals move and disguise the proceeds of crime through trade transactions, often across borders. By misusing the international trade system, illicit funds are made to appear as if they came from legitimate commercial activity.

Formal definition

Trade-Based Money Laundering (TBML) is the process of disguising the origin and movement of illicit proceeds and transferring value through the use of trade transactions, typically within the international trade system, in order to legitimize criminally derived funds. It exploits global trade flows to obscure the source and destination of value, and is recognized as an increasingly significant vector through which international trade is misused for laundering illicit proceeds.

Why it matters

Trade-based money laundering matters because it exploits the vast, complex, and cross-border nature of the international trade system, where the sheer volume of legitimate transactions can obscure illicit value transfers. As recognized by bodies such as the FATF and the IFC, TBML is an increasingly significant vector through which global trade is misused to launder illicit proceeds. Because trade transactions involve multiple parties, jurisdictions, and documents, illicit funds can be made to appear as though they originated from legitimate commercial activity, complicating detection and enforcement.

For institutions involved in trade finance and cross-border payments, TBML presents a distinct challenge from more familiar payment fraud typologies. It does not necessarily rely on compromised cards or account credentials; instead, it abuses the ordinary mechanics of buying and selling goods and services. This means controls designed for transaction-level fraud detection may not surface TBML activity, and dedicated trade-monitoring and due-diligence processes are typically required to help identify it.

The scale and financial impact of TBML depend on source, period, and methodology, and precise figures are difficult to establish given the concealment inherent to the activity. What the available evidence consistently emphasizes is that TBML is a recognized and growing concern in the misuse of international trade, which is why regulators, financial institutions, and trade-finance providers continue to prioritize it as a financial crime risk.

Who it's relevant to

Trade finance and supply chain finance providers
Institutions that finance and facilitate international trade are directly exposed to TBML risk, as their products and processes can be misused to move illicit value. Bodies such as the IFC highlight countering TBML as a priority within trade and supply chain finance, reflecting the sector's role in identifying and mitigating this abuse of global trade.
Financial crime and AML compliance officers
Compliance teams responsible for anti-money-laundering programs need to account for TBML as a distinct laundering typology that exploits trade transactions rather than conventional payment channels. Understanding it helps inform due diligence, monitoring, and risk-assessment processes aimed at detecting the misuse of trade flows to legitimize illicit proceeds.
Cross-border payment processors and acquirers
Firms handling cross-border commercial payments may encounter transactions connected to trade activity used to disguise the movement of illicit funds. Awareness of TBML supports more informed risk evaluation, recognizing that this activity often operates across borders and may not be captured by controls designed for card-based transaction fraud.
Regulators and financial intelligence bodies
Standard-setting and intelligence organizations, including the FATF, define and study TBML as a recognized and increasingly significant means by which the international trade system is misused to launder proceeds of crime, guiding how institutions are expected to address the risk.

Inside TBML

Trade-Based Money Laundering (TBML)
A method of disguising the proceeds of crime and moving value through the trade system by misrepresenting the price, quantity, or quality of goods or services in commercial transactions. TBML is distinct from payment card fraud and is primarily governed by anti-money-laundering (AML) frameworks rather than by PCI DSS or card brand rules.
Over- and under-invoicing
Deliberately stating a price on an invoice that is higher or lower than the fair market value of the goods, allowing value to be transferred between parties in excess of, or below, the actual value exchanged.
Multiple invoicing
Issuing more than one invoice for the same shipment of goods to justify multiple payments for a single underlying transaction.
Over- and under-shipment
Misrepresenting the quantity of goods shipped, including phantom shipments where no goods actually move, to misalign documented value from delivered value.
Misrepresentation of quality or type
Describing goods on trade documents as being of a different quality, grade, or category than what is actually shipped, creating a gap between documented and real value.
Trade documentation
Invoices, bills of lading, letters of credit, customs declarations, and related paperwork that establish the terms of a trade transaction and that can be falsified or manipulated to obscure value movement.

Common questions

Answers to the questions practitioners most commonly ask about TBML.

Is trade-based money laundering the same thing as payment fraud or card fraud that our fraud team already monitors?
No. Trade-based money laundering (TBML) is the process of disguising the proceeds of crime and moving value by misrepresenting the price, quantity, or quality of goods or services in trade transactions. It is a money laundering typology addressed under anti-money laundering (AML) programs and regulations, not a payment card fraud type such as card-present or card-not-present fraud, account takeover, or chargeback fraud. The controls, teams, and rules that govern TBML (AML/CFT frameworks) are separate from PCI DSS and from card brand fraud and chargeback rules. A fraud team monitoring cardholder transactions is looking at different signals than an AML function reviewing trade documentation and payment flows, so treating them as interchangeable can leave gaps in both programs.
Does TBML only involve moving physical goods across borders?
Not necessarily. While classic TBML descriptions involve over- or under-invoicing of physical goods, the same value-transfer logic can apply to services and intangibles, where valuation is harder to verify, and to phantom shipments where no goods move at all. Because the misrepresentation is in the documentation and stated value rather than strictly in the physical movement, focusing only on physical cross-border shipments may miss service-based or fictitious-trade schemes. The precise techniques observed depend on the sector, jurisdiction, and how a given scheme is structured.
How should we scope TBML risk relative to our PCI DSS and card payment controls?
TBML risk sits within your AML/CFT program rather than within PCI DSS scope. PCI DSS governs the protection of cardholder data and the security of the cardholder data environment; it does not define TBML controls. When trade payments touch card rails or stored cardholder data, PCI DSS obligations still apply to that data, but the TBML analysis, such as evaluating trade documentation, counterparties, and pricing anomalies, is driven by AML regulation and your institution's risk assessment. Keep the two workstreams distinct so that neither is assumed to satisfy the other's requirements.
What data would a monitoring approach for TBML typically examine?
TBML detection generally draws on trade and payment context rather than card authentication data. This can include invoice values and unit prices compared against reference benchmarks, shipment and quantity details, counterparty and beneficiary information, routing and jurisdiction data, and consistency between payment amounts and stated trade terms. Note that this is different from sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, or PINs, which must not be stored after authorization and are not the inputs for trade-value analysis. The specific data available depends on your role in the transaction and the systems you operate.
What are the practical limitations of automated TBML detection?
Automated TBML monitoring is intended to help surface anomalies, but it carries meaningful trade-offs. Price benchmarking can produce false positives where legitimate goods vary in quality, specification, or market conditions, and false negatives where mispricing stays within plausible ranges. Service-based and intangible trade can be difficult to value at all, limiting rule effectiveness. Detection typically informs investigation and reporting rather than making a definitive determination on its own, so human review of documentation and context remains important. No single control should be treated as eliminating TBML risk.
How do TBML controls relate to other authentication and fraud controls in a payment stack?
TBML controls address a different risk at a different point than transaction authentication controls. Measures such as EMV chip authentication, 3-D Secure, strong customer authentication, and multi-factor authentication are designed to confirm that a party is authorized to initiate or complete a payment; they do not assess whether the underlying trade value or documentation is legitimate. TBML analysis focuses on the substance of the trade, its pricing, counterparties, and value flows, and is handled within AML/CFT processes. Layering these functions matters, but authentication controls should not be assumed to detect or mitigate TBML, and vice versa.

Common misconceptions

TBML is a payment card fraud problem that PCI DSS controls help address.
TBML operates through the trade and commercial payment system rather than through cardholder data flows. It falls under AML and sanctions compliance obligations, which are separate from PCI DSS, card brand rules, and the sensitive authentication data protections those frameworks govern.
TBML always requires falsified or forged trade documents.
TBML can occur even where documents are authentic, because the manipulation may lie in the price, quantity, or quality represented rather than in the document itself. Detection therefore depends on comparing documented terms against expected market value and trade patterns, not solely on verifying document authenticity.
Screening transactions against a watchlist is sufficient to detect TBML.
Watchlist screening addresses known sanctioned or flagged parties but does not by itself reveal value manipulation embedded in pricing or shipment details. Effective detection typically combines multiple signals, and any single control may produce false positives and false negatives.

Best practices

Treat TBML detection as an AML and trade-finance responsibility distinct from PCI DSS scoping, and align controls with the applicable AML regulatory framework rather than card brand or payment security rules.
Compare invoiced prices against independent fair-market-value benchmarks for the relevant goods, recognizing that pricing outside expected ranges is a risk indicator rather than proof of laundering.
Cross-check trade documents against one another and against shipment and customs data to identify discrepancies in price, quantity, and description that may indicate over- or under-invoicing, multiple invoicing, or phantom shipments.
Apply a risk-based approach that layers party screening, transaction pattern analysis, and document review, since no single control detects TBML reliably on its own.
Document and tune detection thresholds to manage the trade-off between false positives and missed activity, and periodically review outcomes against current typologies.
Confirm obligations, reporting duties, and any thresholds against the current applicable AML regulations for the relevant jurisdiction rather than assuming fixed figures or requirements.