100 AML Scenario Based Interview Questions and Answers
100 AML Scenario Based Interview Questions and Answers
AML scenario questions test whether you can work an alert rather than define one. You are given a transaction pattern with an incomplete picture and asked what you would do — and interviewers listen for whether you test the innocent explanation as rigorously as the suspicious one.
These AML scenario based interview questions come with full model answers: what you would check, what would make it legitimate, what would make it reportable, and where the decision sits.
How to structure an AML scenario answer
Start with the customer baseline — what is normal for them — then say what the pattern suggests, what innocent explanation you would test, what evidence would resolve it either way, and where the decision sits. Answers that jump straight to "I'd file a SAR" score badly: reasonable suspicion is a conclusion you reach, not a starting position.
Alert investigation (Q1–14)
1You receive an alert on a customer whose profile you know nothing about. Walk me through your first steps.
I'd start with the customer, not the transactions, because without knowing what is normal I can't judge whether anything is abnormal. So I'd read the profile first: occupation or business type, declared income or turnover, expected activity, geography, risk rating, and how long the relationship has existed.
Then I'd look at why the alert triggered — which scenario, on what data, and what threshold was crossed. That tells me what the system thought was unusual.
Only then would I look at the transactions themselves: amounts, counterparties, timing, geography, and how they sit against the declared pattern.
I'd also check history — previous alerts, previous escalations, whether this pattern has been reviewed and closed before. Closing something as normal that was escalated three months ago would be a serious miss.
Working in that order matters. Analysts who open the transaction list first tend to anchor on the numbers and lose the context that actually explains them.
2An alert triggers on a customer whose activity has been consistent for five years. Do you close it quickly?
Not quickly, though the history is relevant context. A long consistent record makes a legitimate explanation more likely, and I'd weigh that.
But consistency isn't a clearance. Criminals deliberately use established accounts precisely because they attract less scrutiny, and account takeover or a change in who controls the account produces exactly this profile — a long clean history followed by something out of pattern.
So I'd focus on what changed. Is this a scale increase in the same behaviour, or genuinely different behaviour? New counterparties, new geographies, a different transaction type, or a change in timing patterns all read differently from a larger version of the usual activity.
I'd also check whether anything changed on the customer side — a new signatory, a change in ownership, updated contact details, or a recent password reset if that data is available.
If the change is explicable and consistent with their business, I'd close with reasoning. If I can't explain the shift, tenure doesn't resolve it.
3The customer's explanation for an alerted transaction sounds plausible but you cannot verify it. What do you do?
Unverified is not the same as verified, and I'd be careful not to let a comfortable-sounding story close the case.
First I'd try to verify it. If they say the funds are proceeds of a property sale, there may be a completion statement, a solicitor's client account as the sender, or land registry records. Most explanations leave some trace, and a customer with a genuine one can usually point to it.
If evidence genuinely isn't obtainable, I'd assess how material the gap is. An unverified explanation for a modest transaction on a low-risk customer is different from an unverified explanation for a large payment on a high-risk one.
I'd also test internal consistency — does the explanation fit the amount, the timing, the sender, and what we already know about the customer?
I'd document the explanation, that it could not be corroborated, and my reasoning. Where it remains unexplained on a material point, that supports escalation rather than closure.
4You are 80 percent confident an alert is a false positive. Do you close it?
It depends what the remaining 20 percent consists of, and I'd be uncomfortable framing it as a percentage at all.
If the residual doubt is generic — I can't rule out that any customer might be doing something wrong — that's not a reason to escalate, because that doubt exists on every file.
But if the 20 percent is a specific unresolved element — a counterparty I couldn't identify, a payment reference that doesn't fit, an amount that doesn't reconcile — then it isn't a false positive at all. It's a partially investigated alert, and I'd resolve that element before deciding.
So my approach would be to name what the doubt is. If I can articulate it, I investigate it. If I can't, and everything checks out against the profile with evidence, I'd close with clear reasoning.
What I wouldn't do is close on balance of comfort. The standard is whether the activity is explained, not whether it's probably fine.
5An alert involves a product or industry you do not understand. What do you do?
Research it and ask, rather than guess. Guessing produces errors in both directions — I might close something genuinely suspicious because I don't recognise the pattern, or escalate something entirely normal for that sector.
I'd start with what's available internally: procedures, sector guidance, or previous cases on similar customers. Often someone has already worked this type of business.
Then I'd ask colleagues or a subject matter expert. In most teams someone has sector experience, and a five-minute conversation is faster and more reliable than an hour of speculation.
Externally I'd look at how the industry normally operates — typical payment cycles, counterparty types, whether cash or international transfers are normal.
What I'd record is what I learned and where it came from, so the reasoning is transparent and the next analyst benefits.
And I'd rather flag that a case needs more time than close it on a shallow understanding — that's the honest position and it's usually respected.
6You have 30 alerts due today and can properly investigate 20. How do you handle it?
I'd prioritise by risk rather than by order of arrival, and be transparent about the shortfall rather than absorbing it.
Prioritisation would consider customer risk rating, transaction value, whether there's sanctions adjacency, whether the customer has prior escalations, and any regulatory deadline attached.
Then I'd complete those 20 properly and flag the remaining 10 to my supervisor with the reason, rather than rushing all 30 to a standard that wouldn't survive quality review.
That's the key point: 30 poorly reviewed alerts is worse than 20 done well and 10 reported as outstanding. Rushed closures create false assurance — the file says reviewed when nothing meaningful happened.
If it were a one-off peak I'd manage it. If it's persistent, I'd raise it as a capacity issue, because a chronic gap between volume and capacity is a control problem rather than a personal workload problem.
Unmanaged backlogs are among the most common findings in enforcement actions.
7You discover a previous analyst closed a similar alert on the same customer six months ago. Does that change your assessment?
It's relevant but not determinative, and I'd read the previous case rather than just noting its existence.
What I'd look for is the reasoning. If the earlier analyst investigated properly, obtained an explanation, verified it, and documented why it was legitimate, that's genuinely useful — the same explanation may apply and I'm not starting from nothing.
If the closure was thin — a one-line note with no evidence — then it tells me little, and I'd treat this as effectively unexamined.
The more important question is what the repetition means. A pattern recurring after being reviewed and explained may be entirely consistent with the business. But a recurring pattern that was never properly explained is a different picture, and the repetition itself becomes evidence.
I'd also consider whether the two alerts together reveal something neither showed alone.
If I concluded the earlier closure was wrong, I'd say so and flag it, rather than quietly reaching the opposite conclusion.
8A customer contacts you directly asking why their payment is being reviewed. What do you say?
I'd follow the firm's approved wording and say nothing beyond it. Typically that means referring to standard internal checks that apply to transactions from time to time, and that we'll be in touch as soon as they're complete.
What I would not do is improvise. Saying anything that suggests a report has been made or is being considered risks tipping off, which is a criminal offence in most jurisdictions — and improvised reassurance is exactly how people stray into it.
I'd also be careful about tone. Being evasive or unusually formal can itself signal something, so a calm, routine response is better than a defensive one.
If they press for detail, I'd hold the line politely and offer to escalate their query to the relationship team rather than expanding my own explanation.
I'd record the contact and what was said, because the fact that a customer chased a delayed payment can itself be relevant, and the record protects me on the tipping-off point.
9An alert shows a large payment to a charity in a high-risk jurisdiction. Suspicious?
Not on its own, and I'd be careful here because this is an area where over-reaction causes real harm. Legitimate humanitarian work happens in high-risk and conflict-affected regions by definition.
I'd start with the customer — is charitable giving consistent with their profile and history? A customer who has donated regularly to related causes reads very differently from one making an unprecedented large transfer.
Then the recipient: is it a registered charity, does it have a genuine operational presence, and does it appear on any screening lists?
The specific risk with charitable flows to high-risk regions is diversion at the delivery end rather than the donor's intent, so I'd look at whether the organisation is established and accountable.
Concerns would be an unregistered recipient, funds going to individuals rather than an organisation, or a donation inconsistent with the customer's means.
Absent those, I'd document the assessment and close. Treating charitable giving as inherently suspicious is exactly the de-risking regulators criticise.
10A customer's transactions are entirely normal in isolation but the pattern feels wrong. How do you approach that?
I'd do the work of turning that feeling into something specific, because unease alone can't be escalated or acted on.
Usually the discomfort reflects something identifiable I haven't articulated. Common candidates: the timing is too regular for genuine commercial activity, or too irregular for salary; amounts are just below a threshold consistently; funds arrive and leave with nothing retained; counterparties have no evident connection to the stated business; or the activity is technically consistent but economically pointless.
That last one matters. A transaction can be entirely normal in form while making no commercial sense — money moving in a circle, or costs incurred for no benefit.
So I'd map the flows visually if needed, and ask what the economic purpose is.
If I can name it, I investigate it and escalate with specifics. If after that effort I still can't articulate anything, I'd discuss it with a colleague rather than either escalating on instinct or closing to move on.
11You find the customer's account was accessed from an unusual location shortly before the alerted transaction. What does that add?
It shifts my thinking toward account takeover or third-party control, which is a different investigation from ordinary laundering.
If the customer's account is being operated by someone else, the transaction may not be theirs at all — they may be a fraud victim rather than a subject. That changes both the assessment and the response, since the customer might need protecting rather than reporting.
So I'd look at the wider access pattern: is this a one-off or has activity been coming from that location for a while, were there recent credential or contact detail changes, and does the transaction behaviour change at the same point.
A password reset, a new device, a changed phone number and then an unusual payment is a classic takeover sequence.
Travel is the obvious innocent explanation, and I'd check whether other activity supports that.
Given the possibility of fraud in progress, I'd escalate quickly rather than complete a leisurely investigation — and involve the fraud team, since this may need both.
12An alert relates to a transaction that has already settled and cannot be recovered. Is there still value in investigating?
Yes, and I'd push back on any suggestion otherwise. Recovering funds isn't the purpose of transaction monitoring.
The purpose is intelligence and control. Even where funds have gone, the investigation may reveal an ongoing pattern, identify a network involving other customers, establish that the relationship should be reassessed, or produce a suspicious activity report that contributes to law enforcement intelligence.
A great deal of what FIUs use comes from reports about activity that already happened.
Practically I'd investigate as normal, with particular attention to whether the pattern is continuing and whether other accounts show it.
The one thing settlement changes is urgency around prevention — there's no payment to hold. But it doesn't reduce the reporting obligation, and closing an alert because the money has gone would be a serious error.
If the pattern suggests more transactions are coming, that's actually a reason to work it faster.
13Your investigation is complete but you cannot decide between closing and escalating. What do you do?
I'd escalate, and I'd frame it as a referral for decision rather than an assertion of suspicion.
The escalation route exists precisely for cases sitting on the line. Closing something I genuinely can't resolve puts my uncertainty into a file marked "no concerns," which misrepresents the position.
What matters is how I escalate. I'd set out what I found, what I could and couldn't verify, the arguments each way, and why I couldn't reach a conclusion. That's far more useful to an MLRO than either a bare escalation or a confident position I don't actually hold.
I'd also be honest about the limits — what evidence would have resolved it and why it wasn't available.
One caveat: if I'm escalating a high proportion of cases, that's a signal in itself — either the scenarios are poorly tuned, or I need more training on where the threshold sits. I'd want to know which.
14You realise mid-investigation that the alerted activity is only part of a longer pattern predating the alert period. What now?
I'd expand the review period to follow the conduct rather than restricting myself to the alerted window.
The alert window is a system artefact — it reflects when a threshold was crossed, not when the behaviour began. If the pattern runs back two years and I only look at two months, I'll materially understate what's happening, and the two-month view may look far less significant.
So I'd map the full period and quantify the total, because scale often changes the assessment entirely.
I'd also check whether earlier alerts fired on this pattern and were closed. If they were, and I now think the pattern is suspicious, those closures need flagging — both because the earlier assessment may have been wrong and because it suggests a scenario or training gap.
If no alerts fired across that period despite the pattern, that's a detection gap worth raising separately from the case itself.
Practise reasoning out loud
Scenario answers are delivered live, with follow-up questions probing your reasoning. Practise a live AI voice and video interview on AGZIT:
- A real spoken interview that follows up on what you say
- A 10-competency scorecard showing where your reasoning is thin
- A free ATS-friendly resume builder once you register
- Your first AI interview is free
Cash and structuring (Q15–28)
15A customer makes fifteen cash deposits of 9,500 over three weeks where the reporting threshold is 10,000. Your assessment?
This is textbook structuring and I'd treat it as a strong indicator rather than a coincidence. Fifteen deposits consistently just below a threshold is not how legitimate cash arises — genuine takings vary.
I'd confirm the pattern precisely: exact amounts, dates, locations, and whether deposits were split across branches or channels, which strengthens it further.
Then I'd check the customer profile. Even for a cash business, this pattern is odd — real takings fluctuate with trade, and a business would normally deposit actual daily totals rather than a repeated round-ish figure below a line.
The total also matters: roughly 142,500 over three weeks needs to make sense against declared turnover.
There's essentially no innocent explanation for amounts clustering just under a threshold repeatedly, though I'd still give the customer an opportunity if our process allows contact.
I'd escalate with the pattern documented clearly, and I'd expect this to proceed to a report.
16A restaurant's cash deposits double over three months. Suspicious?
Not necessarily, and this is where testing the innocent explanation properly matters.
Restaurants have genuine reasons for cash increases: a second site, extended hours, a refurbishment reopening, seasonal trade, a change in menu or pricing, or simply better business.
The most useful test is the relationship between cash and card. Most restaurants take both, and genuine growth normally lifts both together. If card revenue is flat while cash has doubled, that's the pattern that concerns me — because it means more cash without more customers.
I'd also look at supplier payments and payroll. A restaurant genuinely doing twice the trade buys more stock and usually pays more staff. Revenue rising with costs flat is difficult to explain.
Deposit timing helps too — daily banking consistent with trading days is normal; large round deposits at irregular intervals is less so.
If cash and card moved together and costs rose proportionately, I'd document that and close it as evidenced growth.
17A customer deposits cash at multiple branches on the same day. What does that suggest?
It's a recognised structuring indicator, because the obvious purpose of splitting deposits across locations is to avoid aggregation and reduce the chance any one branch notices.
That said, I'd check the innocent explanations. A business with multiple sites may legitimately bank locally at each — a retail chain does this routinely. Someone travelling for work might bank wherever they are.
So I'd look at whether the customer has operations near those branches, and whether this is a consistent long-term pattern or a recent change.
The concerning version is deposits at several branches with no operational connection to those locations, particularly if the individual amounts are below reporting or attention thresholds while the aggregate is substantial.
I'd also check whether different people are making the deposits, since that adds a smurfing dimension.
If there's no operational explanation and the amounts pattern below thresholds, I'd escalate. If the branches map to genuine sites, I'd document that and close.
18Several different individuals deposit cash into the same account across a short period. Your read?
This is a smurfing pattern and it concerns me more than a single customer structuring, because it implies coordination.
I'd establish who the depositors are and whether there's any connection to the account holder. Some explanations are legitimate — a business where staff bank takings, a club or association collecting subscriptions, or family contributing to a shared expense.
So the account type matters. A community organisation receiving deposits from members is entirely normal; a personal account receiving cash from a dozen unconnected people is not.
I'd look at whether the depositors appear elsewhere in our records, whether the same individuals also deposit into other accounts, and whether the amounts follow a pattern suggesting instruction rather than independent activity.
What happens to the money next is equally important. Deposits accumulating and then leaving in one transfer, or being withdrawn as cash, suggests collection rather than legitimate receipts.
Absent a clear organisational explanation, I'd escalate — and I'd look for related accounts showing the same structure.
19A customer with no declared business receives regular cash deposits from a single source. How do you assess it?
The single source is actually the useful feature here, because it narrows the innocent explanations considerably.
Regular deposits from one person often have legitimate explanations — maintenance payments, family support, rent from a lodger, or repayment of a loan. These are common and unremarkable.
So I'd want to know who the depositor is and what the relationship is. If the customer says it's rent, does the customer own property? If it's family support, is the depositor a relative?
What would concern me is cash specifically. Rent and family support usually move by transfer; cash suggests the payer is avoiding a record, which raises the question of where their money comes from.
I'd also assess scale against the customer's known circumstances. Modest regular amounts read very differently from substantial ones.
If the explanation is coherent and proportionate, I'd document and close. If the customer can't explain who is paying them or why in cash, that's escalation territory.
20A car wash deposits far more cash than similar businesses of its size. What do you do?
Car washes are a known higher-risk cash business, so I'd approach this with that context but still test it properly.
I'd benchmark against realistic capacity. A car wash can only process so many vehicles in a day — site size, number of bays, staff, and opening hours all constrain it. If the deposits imply washing more cars than the site could physically handle, that's a concrete, evidenced concern rather than a general suspicion.
I'd also look at costs. Genuine volume means water, electricity, consumables and staff. Revenue rising with flat costs is difficult to explain, and payroll is often the clearest tell.
Card versus cash ratio is useful too, though car washes legitimately skew cash more than most sectors.
Legitimate explanations exist — an additional site, contract work for a dealership or fleet, or valeting services at higher prices. Each is evidenceable.
Without an explanation supported by capacity and cost data, I'd escalate. The capacity argument is what makes this case strong.
21A customer withdraws large amounts of cash regularly with no apparent purpose. Concern?
Cash withdrawals get less attention than deposits, but they matter — they're how funds leave the traceable system, and that's the point at which the trail ends.
I'd look at the customer's profile and whether cash use is consistent with it. Some businesses genuinely operate in cash: those paying day labour, buying from cash-only suppliers, or operating in cash-dominant economies. Some individuals prefer cash for cultural or generational reasons.
Scale and pattern matter. Regular round-sum withdrawals just below a reporting threshold read very differently from variable amounts consistent with living expenses.
I'd also look at where the money comes in from. Funds arriving by transfer from multiple sources and leaving as cash is a classic layering-to-extraction pattern.
The concerning combination is unexplained credits followed by prompt cash extraction, with no evident business need.
If the customer can explain the cash need and it fits their profile, I'd document and close. If not, I'd escalate.
22Cash deposits stop abruptly after you contact the customer about them. What does that tell you?
It's meaningful and I'd document it carefully, though I'd be measured about what it proves.
There's an innocent reading: a customer told their banking is being reviewed may reasonably change behaviour to avoid inconvenience, or may have been unaware their pattern looked unusual.
But the more concerning reading is that contact alerted them, and activity moved elsewhere. Cessation immediately following an enquiry is a recognised indicator.
So I'd check whether the money genuinely stopped or simply changed form — smaller amounts, different channel, different branches, or transfers replacing cash. Behaviour that adapts rather than ceases is more telling than behaviour that stops.
I'd also check for related accounts, since activity often migrates to another entity or individual.
Importantly, this raises a process question: if my contact prompted the change, was that contact appropriate? Where suspicion exists, enquiries can prejudice an investigation, so I'd want guidance on customer contact going forward rather than treating it as routine.
23A customer asks to make a deposit just under the reporting threshold and asks whether that avoids paperwork. What do you do?
This is close to an admission of intent, and I'd treat it very seriously.
In most jurisdictions structuring is an offence in itself, separate from whatever the money represents. A customer explicitly asking how to avoid a report has effectively stated the purpose.
I would not advise them, confirm thresholds, or help structure the transaction. I'd also avoid indicating that the request itself is a problem, because that risks tipping off.
I'd process or decline the transaction per procedure and document the exact words used, in quotation marks where possible. The precise wording matters enormously here — "does under ten thousand avoid the form" is very different from "will this be delayed."
Then escalate immediately. This isn't something to note and continue with.
I'd also check whether the customer has made prior deposits fitting the pattern, since the request suggests knowledge they've likely acted on before.
24A business customer's cash deposits are perfectly consistent every week — identical amounts. Suspicious?
Yes, counterintuitively. Perfect consistency in cash takings is unnatural, and it's one of those patterns that looks reassuring until you think about it.
Genuine trade fluctuates — weather, holidays, weekdays versus weekends, seasonality. A business banking exactly the same figure every week isn't reflecting real trading; it's depositing a decided amount.
That's characteristic of laundering, where a fixed sum is placed regularly, sometimes mixed with genuine takings.
I'd check whether the amounts are truly identical or merely similar, since some regularity is normal for a stable business. Identical to the pound is the concerning version.
I'd compare against card takings, which should show natural variation even if cash doesn't, and against the business type — some sectors are more stable than others.
A subscription-based or contract business might legitimately show consistency, so context matters.
Absent an explanation for that regularity, I'd escalate. It's a subtler indicator than structuring but a well-recognised one.
25Cash deposits are made by someone other than the account holder. How do you approach it?
I'd want to establish who they are and on what basis they're depositing, because third-party deposits raise the question of who actually controls the funds.
Legitimate explanations are common: an employee banking business takings, a family member helping an elderly or unwell relative, or a bookkeeper handling a small company's banking.
So I'd look at whether the depositor's role is consistent with the account. Business takings banked by staff is routine; a personal account receiving cash from someone unconnected is not.
The concerning versions are multiple different depositors, depositors who also pay into other unrelated accounts, or a customer who can't identify who is paying money in.
That last one is significant — an account holder unaware of who deposits into their account either isn't controlling it or is a mule.
I'd check whether the depositor appears elsewhere in our records, and whether the account holder has any evident involvement in the activity generating the cash.
26A customer deposits foreign currency cash regularly. Additional concerns?
Foreign currency adds a layer, because it raises questions about how it was acquired and how it crossed borders.
Legitimate explanations exist: a customer with overseas income, a tourism-facing business, someone regularly travelling, or a family receiving remittances in cash.
I'd assess whether the currency matches the customer's known connections. A customer with family and travel history in a country receiving that currency makes sense; one with no connection to it does not.
I'd also consider cross-border cash declaration requirements. Large amounts of physical currency moving between countries usually require declaration, so I'd want to understand how it arrived — and whether the amounts are consistent with lawful movement.
Volume matters too. Occasional leftover holiday money is different from regular substantial deposits.
The concerning pattern is regular foreign cash with no travel or business connection, particularly from higher-risk jurisdictions, since physical cash is a common way to move value outside the banking system entirely.
27A cash-intensive business suddenly shifts to almost entirely electronic payments. Does that reduce your concern?
Not automatically — it's a change worth understanding rather than a reassurance.
There are entirely legitimate reasons. Consumer payment habits have shifted substantially, businesses adopt card and app payments, and some sectors have moved almost fully electronic. A shift like this over a few years is unremarkable.
What I'd look at is the timing and abruptness. A gradual shift tracking wider trends is normal. A sudden change, particularly following an enquiry from us or a change in ownership, is more interesting.
I'd also check whether total revenue held steady. If cash disappeared and overall turnover fell correspondingly, that suggests the cash element was never genuine trade. If turnover held with electronic payments replacing cash, that supports a genuine shift.
There's also a possibility worth noting: the cash may simply have moved elsewhere, to another entity or institution, rather than ceasing.
So I'd assess it as a change in pattern requiring explanation, not as a problem resolving itself.
28You notice several unconnected customers all depositing cash in similar amounts at similar times. What now?
This is a pattern I'd escalate as a linked matter rather than working each file separately, because the connection is the finding.
Individually, each customer may look unremarkable — modest cash deposits that wouldn't alert on their own. Collectively, coordinated amounts and timing across supposedly unconnected people suggests an organised operation.
I'd map what they share: deposit locations, timing windows, amounts, whether they were onboarded around the same time, shared addresses, phone numbers or devices, and whether funds move onward to common beneficiaries.
The onward flow is often the clearest link — separate deposits converging on one destination.
I'd also check whether they share an introducer or were referred through the same channel.
Then escalate as a network case with the linkage documented, and flag it for scenario review — because if this pattern evaded detection at the individual level, the monitoring logic isn't catching coordinated behaviour, which is a broader gap worth raising.
Transaction patterns and networks (Q29–42)
29Funds arrive in an account and leave within hours, repeatedly, leaving almost no balance. Your assessment?
This is a pass-through or funnel pattern, and it's one of the clearer layering indicators — the account is being used to move value rather than hold it.
I'd quantify it: how quickly funds leave, what proportion of each credit moves on, and whether the balance ever accumulates. Money arriving and leaving essentially intact is characteristic; a business retaining margin is not.
Then I'd look at the counterparties on both sides. Are credits coming from many sources and leaving to few, or the reverse? Do the parties have any evident commercial relationship with the customer?
Legitimate explanations exist — payment processors, agents collecting on behalf of principals, or businesses passing through client funds. Each has a documented commercial basis I could verify.
The concerning version is an account with no such role showing this pattern, particularly where counterparties don't connect to the stated business.
I'd also check whether the customer profile ever suggested this activity — if not, that mismatch alone supports escalation.
30A customer receives funds from multiple senders and immediately transfers the total to one overseas account. Read?
This is a collection-and-forward pattern, common in mule networks and in unlicensed money transmission.
I'd look at the senders first: how many, are they connected to each other or to the customer, are the amounts similar, and do they appear elsewhere in our records. Multiple unconnected senders paying one individual is the key feature.
Then the destination: who receives it, in which jurisdiction, and is there any evident relationship.
There are legitimate versions. Someone collecting contributions for a family event or a community fund, or an informal group savings arrangement, can look similar. Those usually have identifiable social connections between the parties.
Unlicensed money transmission is also possible — someone providing informal remittance services, which is itself an offence in most jurisdictions even without underlying criminality.
The concerning version is unconnected senders, rapid consolidation, and onward transfer to a higher-risk jurisdiction with no relationship evident. That I'd escalate, and I'd check for other accounts showing the same shape.
31Two customers transfer identical amounts back and forth repeatedly. What does that suggest?
Circular flows with no net effect are economically pointless, which is what makes them suspicious — legitimate transactions accomplish something.
The usual purposes are creating apparent transaction history to support a later explanation, generating volume to obscure other flows, or manufacturing an audit trail that makes funds appear to have a commercial origin.
I'd first check whether the amounts truly net to zero or whether there's a real underlying flow with the circularity disguising direction.
Then I'd look at the relationship between the parties — common ownership, shared directors, family connection, or shared address. Circular flows between commonly controlled entities are particularly concerning because the "counterparty" isn't independent.
Legitimate explanations are limited but exist: intercompany funding and repayment, a loan drawn and repaid, or corrections of errors.
I'd ask what commercial purpose the transactions serve. The absence of a coherent answer is itself the finding, and I'd escalate on that basis.
32A customer's incoming payments all carry vague references like "services" or "consulting". Significant?
It's a soft indicator on its own but meaningful in combination, and I'd note it rather than build a case on it alone.
Vague references matter because payment narratives are one of the few pieces of context we get. Legitimate commercial payments often reference invoice numbers, contracts, or specific goods. Generic descriptors provide nothing verifiable.
"Consulting" in particular is worth attention, because it's the standard cover for payments with no deliverable — it's inherently hard to disprove.
That said, plenty of genuine businesses use loose references, and some payment systems truncate them.
So I'd look at the wider picture: do the payers connect to the customer's stated business, are amounts consistent with consulting work, is there any evidence of services delivered, and is the customer's declared activity actually consultancy?
The concerning combination is vague references, unconnected payers, round amounts, and a business that doesn't obviously provide the service described. That's when I'd seek evidence of the underlying engagements.
33Payments to a customer come from an account in a different name to the counterparty on the invoice. How do you treat it?
Third-party payment is a recognised red flag because it breaks the link between the commercial relationship and the money.
There are legitimate explanations. Group companies pay on behalf of subsidiaries, parent companies settle for group entities, factoring and invoice finance arrangements mean a finance provider pays, and agents pay on behalf of principals.
So I'd ask the customer to explain and evidence the arrangement — a group structure showing the relationship, a factoring agreement, or an assignment of the invoice.
What concerns me is a payer with no evident connection to the invoiced party, particularly if the payer is in a different jurisdiction or is an individual paying a corporate invoice.
That pattern allows funds from an unrelated source to be given a commercial appearance through someone else's genuine invoice.
I'd also check whether this is occasional or systematic. Systematic third-party payment across many transactions is much more significant than a one-off, and I'd escalate on that basis.
34A customer's account shows many small round-sum transfers to different individuals. What is your read?
Round sums to multiple individuals suggests distribution rather than commercial payment, since genuine payments usually reflect invoices, hours or negotiated amounts and rarely land on exact figures repeatedly.
I'd look at who the recipients are, whether they're connected to each other, whether they appear in our records, and whether any receive repeatedly.
Legitimate versions exist. Payroll for casual staff, expenses reimbursement, contractor payments, or distributions to family members can look like this — and payroll in particular does involve regular payments to many individuals.
So I'd check whether the customer's business would plausibly involve paying individuals, and whether there's any payroll infrastructure.
The concerning version is a customer with no evident reason to pay individuals, sending round amounts to a changing set of recipients, particularly if funds arrived shortly before from a single source.
That shape — one large credit, many small onward payments — is characteristic of distributing proceeds, and it's what I'd escalate on.
35A student account receives fifteen credits from unrelated senders in two weeks, then withdraws the total in cash. Your assessment?
This has strong mule characteristics and I'd escalate rather than expect an explanation to resolve it.
The combination is what makes it clear: multiple unconnected senders, an account profile that gives no reason to receive money from many people, rapid consolidation, and cash extraction that ends the trail.
Individually each feature might have an explanation. Together they form a recognised pattern, and mule recruitment specifically targets students because accounts are new, activity is unpredictable, and recruits often don't understand what they're participating in.
I'd map the senders and check whether they appear against other accounts, since mule networks usually involve several receiving accounts.
I'd also look at whether the account was recently opened, and whether contact details changed.
Worth noting: the customer may be a victim rather than an organiser. That doesn't change the reporting position, but it may affect how the relationship is handled, and it's a reason to be careful about direct contact.
36You identify the same beneficiary receiving funds from twelve unrelated customers. What do you do?
I'd treat this as a network case and escalate it as one, because the common beneficiary is the finding — no individual file would show it.
First I'd establish what the beneficiary is. A utility company, a landlord, a popular merchant or a government body would legitimately receive from many unconnected customers, and I'd rule that out early.
If it's an individual or an obscure entity, that's different. Twelve unconnected people paying the same private beneficiary needs explanation.
I'd look at what the twelve customers have in common — onboarding period, profile, geography, how funds arrive before being forwarded, and whether references are similar.
I'd also assess the aggregate flowing to that beneficiary, since individually modest amounts can total substantially.
Then escalate with the network mapped rather than filing twelve separate reports, because the connection is the intelligence value.
And I'd flag that our monitoring didn't surface this — beneficiary-level aggregation appears to be a detection gap.
37A dormant account reactivates with high-value activity. How do you handle it?
I'd treat it as a trigger event and act promptly, because dormant reactivation is a well-established pattern — there's no recent baseline to compare against, which is precisely why it's used.
My first concern is whether the customer still controls the account. Dormant accounts are targets for takeover, so I'd check for recent changes to contact details, credentials, or access location before assuming the activity is theirs.
Then I'd establish the source of funds and what's happening next. Money arriving and moving straight out is more urgent than money sitting.
Legitimate explanations exist: an inheritance, a property sale, a customer returning from abroad, or a business restarting after a pause.
I'd also refresh the customer file, since years of dormancy means our information is stale and the profile no longer supports meaningful monitoring.
If the source can't be explained, or the pattern is receive-and-forward, I'd escalate quickly rather than complete a leisurely review while funds move.
38A customer's transactions suddenly involve a jurisdiction they have never dealt with. Concern?
A change in geographic pattern is worth understanding, though it isn't inherently suspicious — businesses expand and people's circumstances change.
What matters is whether the new jurisdiction fits anything we know. A customer expanding into a market adjacent to their existing trade, or with a family connection there, is unremarkable. A jurisdiction with no apparent connection to their business or life is not.
The jurisdiction's own risk profile matters too — a shift toward a country on the FATF grey list or with weak controls carries more weight than a shift toward a well-regulated market.
I'd look at the counterparties there and whether they connect plausibly to the customer's stated activity, and whether the flows are one-directional.
I'd also check for a diversion pattern — payments to a country bordering a sanctioned state, or to a jurisdiction known as a transit point.
If the customer can evidence the new business relationship, I'd update the profile and risk rating rather than escalating.
39Transactions consistently occur outside the customer's normal business hours or trading days. Significant?
It's a supporting indicator rather than a finding on its own, and I'd be careful not to over-read it given how much activity is now automated and around the clock.
Where it matters is mismatch with the stated business. A retail shop generating card transactions at three in the morning, or a business banking takings on days it's closed, is inconsistent in a way that needs explaining.
Automated payments, standing orders and international counterparties in other time zones all produce out-of-hours activity legitimately, so I'd rule those out first.
The pattern I'd focus on is activity clustered at unusual times without an automation or time zone explanation, particularly if it coincides with other indicators — new counterparties, unusual amounts, or access from unexpected locations.
In takeover cases timing is often revealing, because the person operating the account isn't in the customer's time zone.
So I'd note it, check it against the business model, and use it as corroboration rather than the basis of an escalation.
40A customer makes a very large one-off payment entirely out of character. How do you approach it?
One-off large transactions often have straightforward explanations, so I'd start by asking what it relates to rather than treating scale alone as suspicious.
Property purchases, tax payments, vehicle purchases, business acquisitions, school fees and settlements all produce single large payments from otherwise ordinary accounts.
What I'd examine is where the funds came from, since a large outgoing payment usually needs a corresponding credit. If a substantial sum arrived shortly before, that credit is where the real question lies.
Then the recipient — a solicitor's client account, a car dealer or a tax authority supports the stated purpose; an individual or an offshore entity does not.
I'd assess proportionality against known income and wealth. A payment far beyond anything the customer's profile supports raises the source question regardless of the destination.
If the purpose is evidenced and the funding source is explained, I'd document and close. The out-of-character nature is a reason to look, not a conclusion.
41You find the customer's counterparty is a company you cannot verify exists. What now?
An unverifiable counterparty is a significant finding, because it undermines whatever commercial explanation rests on it.
First I'd make sure I've searched properly — registries in the right jurisdiction, alternative spellings and transliterations, trading names versus registered names, and whether it's a branch or division of another entity. Companies do exist without much online presence, particularly small ones overseas.
If it genuinely can't be found, I'd ask the customer for details: registration number, address, contacts, and documentation of the relationship such as contracts or invoices.
A customer trading with a company can normally produce that easily.
The concerning version is a customer who can't provide basic details of an entity they claim to trade with, or who provides details that don't check out.
That pattern suggests either a fictitious counterparty created to justify payments, or a relationship the customer doesn't want examined. Either way I'd escalate rather than accept the transactions on their face.
42Activity in the account maps closely to a typology in a recent FATF report. Does that settle it?
It's strong supporting evidence but I wouldn't treat it as settling anything by itself, and I'd be careful about pattern-matching too readily.
Published typologies describe how criminals have operated, which makes them genuinely useful for recognising a shape. But typologies are necessarily general, and legitimate activity can resemble them — trade finance, remittance and cash businesses all produce patterns that appear in typology reports.
So I'd use it as a lens rather than a conclusion. It tells me what to look for and which specific features distinguish the criminal version from the legitimate one.
Then I'd test those distinguishing features against this customer: does the commercial rationale hold, do counterparties check out, is documentation consistent, does the economic purpose make sense.
If the distinguishing features are present, the typology match strengthens an already evidenced case considerably, and I'd reference it in the escalation because it helps the reader.
If they're absent, the resemblance alone isn't enough.
Corporate and trade scenarios (Q43–50)
43An import company's invoices show goods priced far above market value. What does that suggest?
Over-invoicing is a core trade-based laundering technique, because the inflated element transfers value abroad under the cover of a legitimate-looking trade transaction.
I'd verify the pricing properly rather than relying on impression — commodity prices, trade databases, or comparable transactions where available. The gap needs to be substantial and demonstrable, not marginal.
Then I'd consider legitimate explanations: specialist or bespoke goods, urgent delivery premiums, long-term contracts priced historically, bundled services, or genuinely poor commercial judgement.
What strengthens the concern is a pattern — consistent over-pricing across multiple shipments, particularly with the same counterparty or into a higher-risk jurisdiction.
I'd also look at whether the goods make sense for the buyer's business, whether shipping documents corroborate the transaction, and whether the counterparty is related to the customer.
Related parties transacting at inflated prices is a much stronger indicator than an arm's-length deal.
Where the pattern holds and pricing can't be justified, I'd escalate with the pricing evidence documented.
44A trade transaction involves goods that make no sense for the buyer's stated business. How do you handle it?
This is one of the more accessible trade red flags, because you don't need pricing expertise to see the mismatch.
I'd ask the customer to explain. There are genuine reasons — diversification, acting as an agent or intermediary, buying for a related entity, or a new business line.
What I'd want is evidence: contracts, end-customer details, or agreements showing an agency role.
The concerning version is a customer who can't explain why they're buying goods unrelated to their business, or whose explanation shifts when questioned.
I'd also consider whether the goods themselves raise separate issues — dual-use items, controlled goods, or high-value commodities frequently used to move value. Those carry export control and sanctions dimensions beyond laundering.
Where the goods are dual-use and the destination is sensitive, I'd escalate urgently rather than continue investigating, because sanctions and export control timelines are tighter.
Otherwise, unexplained goods mismatch supports escalation on its own.
45Shipping documents show a route that makes no commercial sense. Your read?
Illogical routing is a recognised indicator of diversion or origin concealment, and it's worth taking seriously because shipping is a cost-driven business — nobody routes inefficiently by accident.
I'd map the route against commercial logic. Goods travelling via a third country that adds cost and time, with no processing or consolidation there, needs explaining.
Legitimate reasons exist: consolidation hubs, transhipment through major ports, capacity constraints, or avoiding a blocked route.
The concerning versions are routing through a country bordering a sanctioned state, transhipment that breaks the documentary chain of origin, or a route where the intermediate country has no plausible connection to either party.
I'd also check whether the intermediate destination has seen unusual growth in this trade generally, since diversion often shows up as a spike in exports to neighbouring markets.
Given the sanctions dimension, I'd escalate to the sanctions team as well as through the AML route if there's any suggestion the ultimate destination is restricted.
46A company's payments do not match its stated business activity at all. What do you do?
This is a fundamental mismatch and I'd treat it as a serious finding rather than a profile update.
First I'd confirm the scale of the divergence. A consultancy occasionally paying a supplier is normal; a consultancy whose entire payment flow consists of goods purchases is not.
Then I'd ask the customer to explain, and be alert to the answer simply redefining the business to fit the payments. That's the common response, and updating our records to match is the wrong reaction — the question is why the stated activity was different.
I'd want evidence for whatever they claim: contracts, invoices, or a documented change in business model.
I'd also consider whether the account is being used by someone other than the customer, or on behalf of a third party, which would explain a complete mismatch.
Where the payments can't be reconciled to any evidenced business, I'd escalate. A company whose money doesn't match what it says it does is close to the definition of a front.
47A newly formed company immediately begins transacting at high volume. Concern?
Worth examining, though not automatically suspicious — new companies with real backing do trade immediately.
What I'd test is whether there's substance behind the volume. Contracts in place, a predecessor business, an established parent, founders with sector track record, premises, staff, and a funding source for working capital.
The funding question is often the most revealing: a new company transacting heavily needs capital from somewhere, and where that came from matters.
I'd also compare actual activity against what was declared at onboarding. Volumes far exceeding the projection suggest either the projection was deliberately understated or the account is being used for something else.
The concerning profile is a recently incorporated entity, no evident substance, high-value flows to and from unconnected parties, and a pass-through pattern.
That's a classic shell profile, and I'd escalate. Where substance is evidenced, I'd update the profile and monitor rather than escalate.
48Payments flow between several companies with the same directors, with no clear commercial purpose. What now?
Intercompany flows between commonly controlled entities aren't inherently suspicious — group treasury, cost allocation and intercompany funding are all normal.
What I'd assess is whether there's an economic purpose. Legitimate group flows correspond to something: shared costs, funding, or trading between entities that genuinely trade.
Circular flows with no net effect, or payments described as services with no evident service, are different.
I'd map the full picture — how many entities, the direction and volume of flows, and whether money ultimately enters or leaves the group from external sources. That last point matters most: internal shuffling with external funds entering at one point and exiting at another is a layering structure.
I'd also check whether each entity has genuine operations, or whether some exist only to receive and forward.
And I'd aggregate exposure across the group rather than assessing each account alone, since the connected position is the real one.
49A customer requests urgent same-day processing of a large international payment with limited documentation. How do you respond?
Urgency combined with pressure to reduce documentation is a recognised technique, so I'd be alert while recognising that genuine urgency exists in business.
I wouldn't process it outside normal requirements. Documentation standards don't flex for timing, and the combination of speed and limited paperwork is precisely how transactions get pushed through unchecked.
I'd ask what's driving the urgency and what documentation is available. Genuine cases — a completion deadline, a contractual penalty, a shipment release — usually come with supporting evidence, and customers can explain the deadline specifically.
What concerns me is vague urgency, pressure applied to me or to the relationship manager, or a customer who becomes agitated when asked routine questions.
I'd also check the destination and counterparty, since urgency into a higher-risk jurisdiction with limited documentation is a much stronger indicator.
If the requirements can't be met, the payment doesn't go. I'd escalate rather than exercise discretion under time pressure, and I'd document the pressure applied.
50An invoice supporting a payment appears to have been altered. What do you do?
I'd stop and escalate rather than seek an explanation from the customer, because a suspected falsified document changes the nature of the case.
I'd document the specific anomalies factually — inconsistent fonts, misaligned figures, a changed amount or date, mismatched totals, or evidence of digital editing. Specific observations are evidence; "looked altered" is not.
I'd also cross-check the invoice against other information: does the amount match the payment, does the counterparty match the shipping documents, does the invoice number fit any sequence we've seen from that supplier.
Innocent explanations exist — a corrected error, a reissued invoice, or poor scanning. So I wouldn't treat it as conclusive.
But an altered document supporting a payment is materially different from an inconsistent one, because it suggests deliberate misrepresentation to obtain processing.
I'd hold the payment pending review, preserve the document as received, and escalate. Where the alteration changes value or parties, that likely supports a report.
leave your comment