How banks detect and prevent financial crime: from money laundering and KYC to sanctions screening, transaction monitoring, and risk.
AMLKYCComplianceFraudFinance
9 min read
If you've ever opened a bank account, you've been subject to KYC. If you've ever wondered why banks ask for proof of address, or what actually happens when a suspicious transaction is flagged, this guide answers those questions.
Financial crime is estimated to cost the global economy trillions of dollars annually. Banks sit at the frontline of detection and prevention, and they've built an entire infrastructure to do it: AML programs, KYC processes, transaction monitoring systems, sanctions screening, and fraud operations. This is a breakdown of how all of it works.
Foundation
What financial crime covers
Financial crime covers any illegal activity involving money, banks, companies, or financial systems. The range is broad, from street-level fraud to state-level corruption:
Money Laundering
Making illegal money appear legitimate by passing it through the financial system.
Bank Fraud & Identity Theft
Deceiving banks or stealing identities to access accounts and credit illegally.
Terrorist Financing
Moving money, even from legitimate sources, to fund terrorist activity.
Corruption & Bribery
Abuse of power for financial gain, often involving public officials or corporate misconduct.
Tax Evasion
Illegally hiding income, assets, or activity from tax authorities.
Online Scams & Fake Accounts
Digital fraud schemes targeting individuals or institutions through deception.
Banks are legally required to detect and prevent these activities. Failure to do so can result in massive regulatory fines, loss of operating licences, and reputational damage. This obligation is why every financial institution maintains dedicated teams in AML, KYC, Compliance, Risk, and Fraud Operations.
AMLKYCComplianceRiskFraud Operations
The bank teams responsible for financial crime prevention
AML
Anti-Money Laundering: how dirty money gets "cleaned"
Money laundering is the process of making illegally obtained money appear legitimate. It always follows the same three stages, each with a different goal and different detection vulnerability:
01
Placement
The illegal money enters the financial system for the first time, the riskiest stage. Common technique: breaking large cash sums into smaller deposits to avoid reporting thresholds ("structuring").
02
Layering
The money is moved many times (across accounts, institutions, jurisdictions, and asset types) to obscure its origin. Shell companies, offshore accounts, and crypto are commonly used.
03
Integration
The money re-enters the legitimate economy appearing "clean," invested in property, a business, or luxury goods. At this stage it's extremely hard to distinguish from lawful wealth.
AML programs target all three stages: monitoring deposits, analyzing transaction patterns, verifying source of funds
AML programs are designed to detect and disrupt this process at each stage: catching placement through deposit monitoring, layering through transaction pattern analysis, and integration through source-of-funds verification.
KYC
Know Your Customer: verifying who you're dealing with
Before a bank can open an account or conduct business with a customer, it must verify three things: who the customer is, where their money comes from, and whether they represent a financial crime risk. This process is called KYC (Know Your Customer), and it's mandatory in virtually every jurisdiction.
Identification
Proof of who you are:
Passport
National ID card
Driving licence
Proof of Address
Confirmation of where you live:
Utility bill
Bank statement
Source of Funds
Where the money comes from:
Salary / payslips
Business income
Investment statements
KYC is not a one-time event. Banks are required to perform ongoing due diligence and refresh KYC information periodically, or when a customer's risk profile changes, for example if they begin dealing with high-risk jurisdictions or their transaction patterns shift significantly.
Beyond verifying identity, banks must also check whether a customer appears on sanctions lists, official lists of individuals, companies, and countries that governments have restricted from the financial system, typically for national security or foreign policy reasons.
OFAC
U.S. Office of Foreign Assets Control. One of the most far-reaching globally due to the dollar's role in international transactions.
United Nations
Multilateral sanctions applied by UN Security Council resolutions, binding on all member states.
EU Sanctions Lists
Maintained by the European External Action Service, aligned with EU foreign and security policy.
What triggers it
A customer whose name or profile matches a sanctions list entry, whether an individual, an entity, or a link to a sanctioned country.
What happens
The bank freezes assets and/or declines to process the transaction, then reports the match to the relevant authorities. Failure to screen (or transacting with sanctioned parties) can result in severe penalties for the bank.
Transaction Monitoring
Watching every transaction for suspicious patterns
KYC and sanctions screening happen at onboarding, but banks also continuously monitor transactions using automated systems that look for behavior deviating from established patterns or known red flags:
Structuring
Many small transfers designed to stay below reporting thresholds, a classic money laundering technique called "smurfing."
High cash deposits
Unusually large cash amounts inconsistent with the customer's declared income or stated business activity.
High-risk countries
Transfers to or from jurisdictions with weak AML controls or known links to financial crime.
Unusual behavior
Sudden changes in transaction frequency, size, counterparties, or geography that don't match the customer's normal profile.
US terminology (FinCEN)
SAR: Suspicious Activity Report
The term used in the US and several other regimes. Filed when a customer's overall activity appears suspicious, even without a single specific transaction trigger.
EU & FATF terminology
STR: Suspicious Transaction Report
The equivalent term across the EU and most FATF-aligned countries. Filed when a transaction or pattern triggers concern, and reported to the national Financial Intelligence Unit.
Tipping off is a criminal offence. Banks are legally prohibited from informing a customer that they have been reported or are under investigation. Doing so (even accidentally) is called "tipping off" and can itself result in criminal charges against the employee who disclosed it.
Fraud vs AML
Fraud and money laundering: related but distinct
These two concepts are often confused, but they refer to different phases of financial crime:
Fraud
Deceiving someone to obtain money or assets illegally. The crime itself generates the illicit funds.
AML
Concealing the illegal origin of funds already obtained. What happens after the fraud.
Card Fraud
Illegal use of payment cards: stolen, cloned, or used without the cardholder's authorisation.
Account Takeover
A criminal gains access to a legitimate account through phishing or credential theft, then drains or abuses it.
APP Fraud
Authorised Push Payment: the victim is socially engineered into willingly transferring money to a fraudster.
Identity Theft
Using another person's identity to open accounts, take out loans, or make purchases without their knowledge.
Phishing
Fake emails, SMS, or websites designed to steal credentials, personal information, or payment details.
The link between fraud and AML is direct: fraudulently obtained money almost always needs to be laundered. This is why fraud and AML teams at banks work closely across both disciplines.
Risk
What "risk" means in banking
In banking, risk is defined as the possibility of loss or problems. Effective risk management is central to how financial institutions operate: identifying, measuring, and mitigating risk is a core function, not an afterthought.
Credit Risk
A borrower cannot repay their loan. The most traditional form of bank risk, managed through credit scoring and collateral.
Operational Risk
Losses from system failures, process errors, or people. Includes IT outages, processing mistakes, and internal fraud.
Market Risk
Adverse movements in interest rates, exchange rates, or asset prices that affect the value of the bank's portfolio.
Fraud Risk
Financial losses from fraudulent activity, both external (cybercrime, customer fraud) and internal (employee misconduct).
Compliance Risk
The risk of legal or regulatory penalties from failing to comply with laws, regulations, or internal policies. In financial crime, this means failing to detect and report suspicious activity.
Financial Crime Red Flags
Avoids questions or provides inconsistent, evasive answers
Suspicious or altered documents during onboarding
Multiple small transfers in quick succession (structuring pattern)
Transaction activity inconsistent with stated income or business
Multiple foreign accounts with no clear business rationale
Unclear, shifting, or implausible business activity
Advanced KYC
Beneficial ownership: finding who is really in control
One of the most important (and most challenging) areas of KYC is beneficial ownership: identifying the real person who ultimately owns or controls a company or asset, even when they're hidden behind layers of corporate structures. Three concepts are central:
Source of Funds
Where the money used in a specific transaction came from. Examples: salary, proceeds from a property sale, a business payment.
Source of Wealth
How the person became wealthy overall, the broader picture. Examples: inheritance, long-term investments, building and selling a business.
Beneficial Owner
The real person who ultimately owns or controls a company or fund, even if hidden behind shell companies, nominees, or multiple corporate layers.
Beneficial ownership is increasingly at the center of global financial regulation. The EU's AML directives, the U.S. Corporate Transparency Act, and the UK's Register of Overseas Entities all require companies to disclose their ultimate beneficial owners, precisely because criminals have historically used complex corporate structures to distance themselves from their assets on paper.
Takeaway
A system built on verification and vigilance
Financial crime prevention is not a single check. It's a layered system. Banks verify identity at onboarding (KYC), screen against sanctions lists, monitor transactions continuously, report suspicious activity to authorities, and assess risk at every stage of the customer relationship.
Each layer addresses a different vulnerability. KYC catches bad actors at the front door. Transaction monitoring catches unusual patterns once they're inside. Sanctions screening blocks legally restricted parties. Beneficial ownership rules prevent shell companies from providing cover.
No system is perfect, and financial criminals adapt constantly. But understanding how the framework is constructed (and why) is valuable whether you work in compliance, build financial products, or simply want to make sense of the infrastructure that sits behind every bank account in the world.