AML Red Flags: The Complete Guide to Money Laundering Indicators

AML Red Flags: Common Indicators, Industry Examples, and Detection Best Practices

Discover the most critical AML red flags, from suspicious transactions to PEPs and high-risk jurisdictions. Learn how to detect money laundering and stay compliant in 2026.

Money laundering has evolved far beyond its traditional associations with cash-heavy businesses and offshore accounts. Criminal proceeds are now moved through virtually any sector via increasingly complex, layered channels that are difficult to detect and trace. This makes monitoring for red flags of money laundering a universal concern.

For regulated industries such as financial services and crypto, it is more than a concern. Detecting suspicious activity and reporting it to the authorities is a legal obligation, imposed on these firms under anti-money laundering laws. Monitoring for red flags is one core component of that effort.

In July 2025, the UK's Financial Conduct Authority fined Barclays Bank PLC around £39.3 million over its handling of Stunt & Co, a gold-trading client whose account received £46.8 million from Fowler Oldfield, a business at the center of a major money-laundering operation. The warning signs were there to see. The payments far exceeded the client's expected turnover and included hundreds of round-sum transfers of £100,000, a classic laundering red flag, yet the account remained rated as low-risk and triggered no enhanced monitoring. Barclays didn't reassess the relationship even after learning that law enforcement had raided the firms involved. The case shows that spotting a red flag on paper is not the same as acting on it. The controls have to catch the signal, escalate it, and change what the bank does next.

Not a legal obligation in themselves, red flags, however, help obliged entities identify suspicious activity.

This article outlines the most common AML red flags and the processes that surface them. Customer due diligence (CDD) catches the static signs at onboarding, such as document mismatches, undisclosed beneficial ownership, or an opaque ownership structure. Ongoing transaction monitoring catches the behavioral ones later—such as structuring, or activity that departs from a customer's expected pattern—once there is a baseline to measure against. Governing both is the risk-based approach, which is not a source of red flags but the framework that decides how much scrutiny each customer receives in the first place.

What is an AML red flag?

An AML red flag is an indicator that a customer, transaction, or business relationship may involve money laundering, terrorist financing, fraud, or another form of financial crime. A red flag is not proof of illegal activity. Rather, it is a warning sign that warrants further review and, where appropriate, enhanced due diligence or investigation.

Red flags can arise during customer onboarding, throughout the customer relationship, or when monitoring transactions. They may relate to unusual customer behavior, inconsistencies in customer information, complex ownership structures, abnormal transaction patterns, or activity involving high-risk jurisdictions.

A single red flag is rarely sufficient to conclude that suspicious activity is taking place. Many legitimate customers occasionally exhibit behaviors that resemble common indicators of money laundering. For example, a sudden increase in transaction volume may reflect genuine business growth rather than criminal activity. For this reason, AML red flags should always be assessed holistically, taking into account the customer's profile, expected activity, transaction history, source of funds, and other relevant information.

Disclaimer: The indicators presented in this article are general examples and should not be considered an exhaustive list of AML red flags. Relevant indicators vary depending on industry, products and services, customer type (individual or legal entity), delivery channels, geographic exposure, and applicable regulatory requirements.

Common AML red flags

Below are some common AML red flags identified by the Financial Action Task Force (FATF), an international AML/CFT watchdog, and national regulators in their guidance. These sources matter because they operate at different levels: FATF sets the global standards that shape AML regimes worldwide, while national regulators translate them into the specific rules and supervisory expectations that firms actually have to meet.

1. Customer identity red flags

Most of these come down to one question: is the customer who they claim to be, and does their account of themselves hold together? The flags surface when identity, ownership, or source of funds won't reconcile.

Identity inconsistencies

Beneficial ownership and transparency

Source of funds and customer profile

Customer behavior

2. Transaction pattern red flags

Identity tells you who you're dealing with; transactions tell you what they actually do. These matter less in isolation than as a departure from what the account normally looks like.

Unusual transaction activity

Structuring and layering

Third-party and account activity

3. Geographic risk red flags

Where money comes from and where it goes can carry as much risk as how much of it there is. These flags track exposure to places and routes that don't fit the customer's stated footprint.

High-risk jurisdictions

Cross-border inconsistencies

AML red flags by industry

The indicators above may apply across the board. Each sector also has its own tells, shaped by how money moves through it and where the gaps are. The lists below draw on FATF's sector guidance, as well as FIU practice.

Financial services red flags

Banks see the widest range of activity, which makes the baseline hard to define and the outliers easy to bury. These flags cluster around accounts that move money without holding it and ownership that resists explanation.

Virtual asset red flags

Crypto compresses the timeline and runs on different technology: funds can be layered and pushed across borders in minutes, and anonymity tools are built into the rails. The flags below reflect speed, obscured ownership, and exposure to services designed to break the trail.

Transactions (size and frequency):

Transaction patterns:

Anonymity:

Senders/recipients:

Source of funds or wealth:

Geographical risk:

Gambling red flags

Casinos and gaming operators take in large volumes of cash and hand back instruments that look clean, which is the entire appeal to a launderer. These flags track value going in and coming out in a different form, with little real play in between.

Cash and value instruments:

Structuring and threshold avoidance:

Accounts, winnings, and currency:

Higher-risk channels and people:

Online-specific:

Real estate red flags

Real estate is a high-risk sector for money laundering and is subject to anti-money laundering (AML) regulations in many jurisdictions. Property absorbs a large sum in a single transaction and rarely invites questions on its own, which is what makes it useful for layering. These flags indicate deals where the buyer, the structure, or the price doesn't align with the purchase.

High-value goods red flags (dealers in precious metals and stones, and other luxury goods)

Metals, stones, and luxury items pack high value into something portable and easy to resell, often in another market. The flags below follow cash, hidden buyers, and pricing or sourcing that won't stand up.

Payment services red flags

Prepaid cards, e-money, and transfer services move value fast and across providers, usually on a thinner audit trail than a bank's. These flags follow funds that load, hop, and exit in ways the stated business doesn't account for.

Prepaid cards:

Internet-based and mobile payment services:

Money or value transfer services (MVTS):

National AML red flag guidance and list of sources

Many bodies and regulators publish sector-specific or jurisdiction-specific indicators.

FATF

National and regional regulators:

Where red flags appear in the AML process

Detecting red flags isn't the goal of AML/CFT obligations. Preventing money laundering is, and the red flags are the indicators that the required procedures surface along the way. So the useful question isn't how to hunt for red flags in the abstract, but where in the process they tend to appear.

They cluster at a few stages. At onboarding, CDD establishes who the customer is, who ultimately owns them, and what their activity should normally look like, which is where evasive identity, opaque ownership, or a profile that doesn't add up first show themselves. For higher-risk customers, enhanced due diligence ( EDD) probes the sources of funds and wealth more deeply, surfacing issues such as unexplained affluence. And throughout the relationship, ongoing transaction monitoring measures real activity against that expected baseline.

Monitoring is where the idea of "normal" does most of its work. A transfer that looks alarming for one client is routine for another, so the point isn't to catch any single suspicious-looking transaction. It's to notice when a customer's activity no longer matches their established pattern. That's why detection splits the way it does: automated systems surface the anomalies, and people decide what they actually mean.

Customer due diligence, and when to go further

Customer due diligence ( CDD) is where this starts. Before you can tell whether a customer is behaving oddly, you need a clear picture of who they are, what their business does, and why they're using your services. That baseline is what lets you recognize activity that doesn't fit.

Some customers warrant a closer look. Opaque ownership structures, PEP status, or links to high-risk jurisdictions all raise the risk profile and trigger enhanced due diligence. In such cases, you need to verify the source of funds, obtain management approval, and take any other measures required by the applicable regulations. The customer risk assessment is part of that process. If the customer is ultimately assessed as high risk, you may then apply more frequent ongoing monitoring.

Transaction monitoring

Monitoring systems watch for patterns that don't add up: funds moving in and straight back out, deposits broken into amounts that dodge reporting thresholds, sudden spikes in volume, or exposure to sanctioned or high-risk countries. Most combine fixed rules with statistical models and, increasingly, machine learning.

The hard part is calibration. Set the thresholds too tight, and your analysts drown in false positives; set them too loose, and real activity slips through—neither is a one-time fix. Typologies shift, customers change how they behave, and regulatory expectations keep moving, so the rules need revisiting on a schedule, not only when something breaks.

Onboarding is a snapshot, not the whole picture. Ownership changes hands, transaction patterns drift, circumstances change. Refreshing customer information, reassessing risk, and working the alerts your monitoring throws up are what keep that profile accurate over time.

What to do when a red flag fires

A red flag is a prompt to look harder, not a verdict. The review is to determine whether there's a reasonable explanation or whether the activity needs to go further.

A typical investigation moves through roles as much as through steps. In a large organization, the work passes from a front-line analyst to the compliance team and finally to the Money Laundering Reporting Officer (MLRO), each with a defined part. In a smaller firm, one person may hold all of these roles, but the sequence of decisions stays the same.

Front-line analyst

Compliance team

MLRO

At every stage

Building an AML program that actually works

Controls on their own don't make a compliance program. What ties them together is a risk-based framework in which due diligence, monitoring, governance, and trained staff reinforce one another, and which you revise as the threats change.

A few things separate programs that work from ones that exist on paper:

FAQ

Examples of AML red flags include unusually large or complex transactions, activity inconsistent with a customer's profile, frequent cash deposits, transactions involving high-risk jurisdictions, and attempts to avoid reporting thresholds. It’s important to know that red flags vary across industries.

Red flags can be detected during customer onboarding, throughout the customer relationship, or when monitoring transactions. They may relate to unusual customer behavior, inconsistencies in customer information, complex ownership structures, abnormal transaction patterns, or activity involving high-risk jurisdictions. A single red flag is usually not sufficient to conclude that suspicious activity is ongoing. AML red flags should always be assessed holistically, taking into account the customer's profile, expected activity, transaction history, source of funds, and other relevant information.

When an AML red flag is triggered, the activity should be reviewed in the context of the customer's risk profile and transaction history, with additional investigation or enhanced due diligence conducted where appropriate. File a report with the FIU (a SAR or STR) where there are reasonable grounds to suspect money laundering or terrorist financing.

A red flag is an indicator of potentially suspicious activity that prompts further investigation, whereas a Suspicious Activity Report (SAR) is a formal report submitted to the relevant authorities when there are reasonable grounds to suspect money laundering or other financial crime.