AML Red Flags

In anti-money-laundering practice, red flags are the specific indicators that suggest a transaction or relationship may involve illicit funds. They are not evidence of wrongdoing — they are the patterns that oblige an institution to look harder, and the vocabulary regulators use when assessing whether it did.

Context Anti-money laundering, sanctions and fraud compliance
What a flag is An indicator warranting further review, not a finding
Customer flags Reluctance to provide information, unexplained wealth, an address or occupation inconsistent with activity
Transaction flags Structuring below reporting thresholds, rapid movement through accounts, round-number transfers, activity inconsistent with the business
Geographic flags Funds moving to or from high-risk or sanctioned jurisdictions
Behavioral flags Sudden change in pattern, dormant account reactivating with volume, third-party control of an account
Where they come from FATF and FinCEN advisories, regulator guidance, institutions’ own typologies
What they trigger Enhanced review, and a SAR filing where suspicion persists

How it works

Red flags exist because money laundering has no single signature. What it has is a set of behaviors that recur across cases, and compliance programs encode those into detection rules and analyst training.

Structuring is the clearest example. Cash deposits kept just below a reporting threshold, repeated across days or branches, describe someone who knows where the threshold sits. Individually each deposit is unremarkable. The pattern is the flag.

Inconsistency is the broadest family: activity that does not fit the customer as described. A retail business with no cash. A salaried employee moving sums their income cannot explain. A dormant account waking up with international transfers. None is proof, and each is a mismatch between what the institution was told and what it observes.

Behavioral flags at onboarding matter more than they get credit for. Reluctance to explain a source of funds, evasiveness about beneficial ownership, unusual haste, or a customer who appears to be acting on someone else’s instructions — these are among the oldest indicators in AML practice and among the hardest to capture in a remote channel, because the cues that surface them are conversational.

A flag obliges review, not action. The institution investigates, documents what it found, and either resolves the concern or files a suspicious activity report. Failing to document why a flag was dismissed is itself a common regulatory finding.

Why it matters for identity verification

A substantial share of AML red flags are identity flags in disguise, and they only surface if the identity data is trustworthy.

“Activity inconsistent with the customer profile” assumes there is a real profile to be inconsistent with. If the customer was never properly verified, the profile is whatever they typed at signup, and the comparison means nothing. Third-party control of an account — a classic mule indicator — is only detectable if you know who the account holder is supposed to be.

Remote onboarding removes the conversational cues entirely. There is no hesitation to observe, no evasiveness in the room. What replaces them is what the session itself reveals: a device used across many applications, an identity presented in several places at once, behavioral patterns that do not match a first-time customer. Those are the remote equivalents of an evasive answer, and screening against sanctions, PEP and adverse media sources covers the counterparty side of the same question. Microblink’s AML and sanctions workflow runs both against verified identity rather than self-reported data.

Red flags vs suspicious activity

  Red flag Suspicious activity
What it is An indicator warranting review A conclusion reached after review
Obligation created Investigate and document File a SAR
Certainty None — most resolve innocently Reasonable suspicion
Who identifies it Monitoring systems and front-line staff Compliance, after investigation
Customer notified No No — disclosure is an offense
Record required Yes, including why a flag was cleared Yes, with supporting analysis

The distinction matters because the obligations differ. A flag requires that you look; suspicion requires that you file. Institutions get into difficulty by treating flags as noise rather than as a documented decision point.

What they can’t do

They are not evidence. Most red flags have innocent explanations, and a great many resolve on a single question. Treating them as findings produces unjustified account closures and pushes legitimate customers out of the banking system.

They do not cover novel typologies. Flag libraries encode known patterns. A laundering method nobody has seen produces no flags, which is why typologies are revised continually and why over-reliance on a static list is itself a weakness.

They are gameable once known. Published advisories are read by both sides. A launderer who knows structuring triggers a flag simply avoids the threshold pattern, which is why behavioral and network analysis increasingly matter more than rule libraries.

They cannot substitute for the underlying data being right. A flag comparing activity to a customer profile is only as good as the profile, and a profile built on unverified self-reported information generates both false flags and silence where there should be noise.

Frequently asked questions

What are the most common AML red flags?

Structuring transactions below reporting thresholds, activity inconsistent with a customer’s stated business or income, reluctance to provide source-of-funds information, rapid movement of funds through an account, and transfers to or from high-risk jurisdictions.

Does a red flag mean money laundering has occurred?

No. A red flag means further review is warranted. Most resolve with an innocent explanation. The obligation it creates is to investigate and document, not to conclude.

Who is responsible for identifying red flags?

Both systems and people. Transaction monitoring surfaces pattern-based flags automatically; front-line staff and relationship managers identify behavioral ones. Compliance then investigates and decides whether suspicion is warranted.

What happens after a red flag is identified?

The institution investigates and records what it found. If suspicion persists, it files a suspicious activity report and cannot inform the customer. If the concern resolves, the reasoning must still be documented — undocumented dismissals are a frequent examination finding.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data