SardineCon SF/2026

Learn More
Sardine ToolsFraud & AML Glossary

Fraud & AML glossary

The working vocabulary of fraud, risk, and financial-crime compliance. Search a term, jump by letter, or filter by topic.

548 términos en18 temas

#

5 términos

3-D Secure (3DS)

Card & payment fraud

3-D Secure is an extra identity check on online card payments, where the shopper proves it is really them by approving the purchase in their banking app or typing in a one-time code. It cuts card-not-present fraud from stolen card numbers, and when a payment is authenticated this way, the chargeback liability usually shifts from the merchant to the card's issuer.

The catch is friction: every added step makes some real customers give up and abandon checkout, so teams set 3DS to challenge risky payments and wave low-risk ones straight through. Fraudsters still try to beat it by tricking victims into reading out the one-time code in real time, so a passed 3DS check is strong evidence the buyer is genuine, not proof.

314(a) request

Monitoring & investigations

A 314(a) request is when US law enforcement, through FinCEN, sends banks a list of names tied to serious money laundering or terrorism and asks them to search their records for a match. It turns your own customer and transaction data into a search tool for live federal cases, and a hit can be your first link between a customer and a real investigation.

When one arrives, search your records over the set look-back window and report only the hits to FinCEN, usually within 14 days. Do not tip off the subject or freeze anything on a match alone. A match is not an automatic SAR, but it is a strong reason to review. Do not confuse it with 314(b), which is voluntary sharing between banks.

314(b) information sharing

Monitoring & investigations

314(b) is a voluntary program that lets registered financial institutions share information with each other to spot and report money laundering or terrorist financing, with legal protection so they cannot be sued for that sharing. Criminals move funds across many banks, and no single bank sees the whole picture on its own.

Use it to fill gaps when money leaves for another bank, or to confirm a pattern across counterparties before you file. You must register with FinCEN and check the other party is registered too. It only covers money laundering and terrorist financing, not general fraud, and it does not replace filing a SAR.

419 fraud

Fraud types

This is an advance-fee scam, named after a section of Nigerian law. The victim is promised a big payout, like an inheritance or lottery win, but first has to pay fees or hand over bank details. Once the money leaves, it is almost never recovered.

In casework it looks like funds coming in from unrelated strangers, or a customer wiring money abroad to someone they have never met. Watch for elderly or isolated account holders, vague payment reasons, and pushback when staff ask questions. Repeated small fees to one far-off counterparty is a classic red flag.

50 Percent Rule

Sanctions & screening

The 50 Percent Rule is OFAC guidance under which any entity owned 50 percent or more, directly or indirectly, by one or more blocked persons is itself treated as blocked, even if it is not named on the SDN list. It stretches sanctions across a wide web of unnamed subsidiaries and affiliates.

Ownership adds up across multiple blocked owners, so several partial stakes can combine to cross the line. In practice the rule demands beneficial-ownership analysis. Its main traps are indirect and aggregated ownership chains that a name-only screen will miss entirely, letting a blocked entity through simply because its name is not on any list.

A

45 términos

Above-the-line testing

Monitoring & investigations

Above-the-line testing checks whether a rule, set at its current threshold, is actually catching the risk it was built for. You do this by reviewing the alerts the rule fires and seeing how many turn out to be genuine hits. A rule that produces mostly noise, or misses the real behavior, is a coverage gap an examiner will find.

Use it during tuning and model validation to defend keeping a threshold as-is. Always pair it with below-the-line testing, which samples activity just under the threshold to expose what the rule is missing. Above-the-line alone is biased, because it never looks at what the rule ignored.

Account aging

Account & access fraud

Account aging is when a fraudster opens or buys an account and sits on it quietly, letting its old signup date and thin history make it look like a trusted, established user. Risk models often go easy on long-standing accounts, so an aged one slips past checks meant for new signups.

Aged accounts trade on fraud marketplaces, where more age means a higher price. Watch for a long gap between signup and first real use, or a sudden burst of activity on an idle account. Recheck device, IP, and funding the moment it wakes up.

Account farming

Account & access fraud

Account farming is the mass creation of accounts, usually with bots, emulators, and throwaway phone numbers or emails, to stockpile them for later fraud, promo abuse, or resale. One farmed batch can fuel many attacks, so catching it early stops a lot of downstream harm.

Farmed accounts share tells: signups clustered in time, reused device fingerprints, the same IP ranges or proxies, and copy-paste profile data. Teams fight it with device intelligence, signup speed limits, and phone and email reputation checks. Cluster accounts by shared traits so you can take down a whole batch at once, not one by one.

Account opening

Due diligence & onboarding

This is the moment a customer is onboarded, when identity verification, due diligence, and initial risk scoring are applied before the account can transact. It is the main gate that keeps bad actors out of the system in the first place.

Rushed or fully automated openings that skip verification are a classic weakness, exploited by synthetic identities and mules. Make sure the risk data captured here, such as the stated purpose of the account and expected activity, is kept as a baseline for later monitoring, not thrown away after approval. Without that baseline, you have nothing to compare against when the account starts behaving oddly later.

This is when someone opens an account using a stolen, made-up, or altered identity so they can commit fraud later, such as a bust-out, mule activity, or credit abuse. A bad account created now becomes a loss down the road, and one fraudster often opens many.

Teams catch it with identity checks, device and IP reputation, and by spotting many applications that share the same details or device. The trap: trusting a clean credit-bureau match as proof of a real person, since synthetic identities pass that check. Also watch for accounts linked by a shared device or funding card.

Account selling

Account & access fraud

Account selling is the trade of verified, aged, or already-funded accounts to other bad actors, often on underground forums, so the buyer inherits clean history and passed KYC without doing the work. The account looks trustworthy on paper while its real owner has changed.

The giveaway is an ownership handoff: after the sale, logins come from new devices, locations, and habits that do not match the original user. Watch for changes to recovery email and phone, and for accounts that pass onboarding then quickly swap contact and payout details. Treat a sudden shift in login location and device on a seasoned account as a strong flag.

This is when a fraudster seizes control of a real customer's account, usually through stolen passwords, credential stuffing, a SIM swap, phishing, or by tricking support staff. Because the account is trusted, the theft can move fast before anyone notices.

Tell-tale signs are a new device or location at login, a password or contact change followed quickly by a payment or a new payee, and turned-off alerts. Teams detect it with behavioral biometrics, device fingerprinting, and extra checks on risky changes. The classic pattern to alert on is a changed email or phone right before a cash-out.

ACH fraud

Card & payment fraud

ACH fraud is theft that moves money over the ACH network, the system US banks use for direct deposits and bill payments. It works because ACH only needs an account and routing number, not a password, and the money takes a day or more to settle. That slow window is what fraudsters exploit.

Watch for first-time large debits, unknown companies pulling funds, and tiny test deposits used to check that stolen bank details work. Because a consumer can dispute an unauthorized debit for up to 60 days, losses can surface long after the payment posts. Teams track return codes like R05, R07, and R10 and watch how fast new payees get added.

Active liveness

Identity verification

Active liveness is a check that asks the user to do something on camera, like blink, smile, or turn their head, to prove a real live person is present. That blocks the simplest spoofs, where a fraudster holds up a printed photo or a static mask to pass as someone else.

The weak spot is that the motion can be faked. Deepfake tools and injection attacks can now render a blink or a head turn in real time and feed it in. So pair active liveness with device and injection checks, and never treat a pass on its own as proof the video came from a real camera.

Ad fraud

Fraud types

This is faking ad views, clicks, or app installs using bots, click farms, or fake devices, to drain an advertiser's budget or pad a publisher's revenue. Real money gets spent on traffic that will never become a real customer.

It shows up as odd click or conversion rates, traffic from data-center IPs or emulators, installs that happen impossibly fast, and users who never spend a cent. Teams fight it with device and IP reputation, close review of install tracking, and checking what users actually do after install. Related terms are click fraud, affiliate fraud, and bot traffic.

Address poisoning

Crypto & blockchain crime

Address poisoning is when an attacker plants a fake address in your transaction history that closely mimics one you already use, usually by sending a tiny or zero-value transfer. You might later copy that lookalike from your history and send funds straight to the thief.

It preys on wallet apps that shorten addresses and on people who copy from recent activity instead of a verified source. Investigators spot it as an unsolicited near-lookalike counterparty appearing in history. The fix is simple but easy to skip: verify the full address, use saved contacts or allowlists, and never paste an address from transaction history.

Address verification

Identity verification

Address verification checks a customer's stated home or business address against trusted records like credit files, utilities, or postal data. A bad address is often the first thread in synthetic identity and money mule cases.

Watch for mismatches, mail-drop or mailbox-store addresses, one address shared by many unrelated applicants, and brand-new addresses with no history. But real people move, use PO boxes, and live with family, so one mismatch alone rarely proves fraud. Weigh it with other signals before you act.

This is a scam that gets a victim to pay upfront for a promised loan, prize, inheritance, or job that never arrives. The fees keep growing as the victim is strung along. Once sent, the money is usually gone for good.

In transaction monitoring it looks like outbound payments to unfamiliar people, repeated fees to one recipient, and a victim who seems coached. It overlaps heavily with 419 fraud, romance scams, and loan-fee scams. The main defense is stepping in to warn the customer at the moment of payment, before the funds leave.

Adverse media

Due diligence & onboarding

This is negative-news screening across public and media sources for signs of crime, sanctions exposure, corruption, or reputational risk tied to a customer, counterparty, or connected party. It adds real-world signals that structured databases can miss.

The cost is heavy false positives from common name matches and old or low-quality stories. Assess each hit for source reliability, how recent it is, and whether it actually relates to your customer, then document why you cleared or escalated it. Unassessed hits are as much a finding as missed ones; a pile of ignored alerts is not a defense. The work is in judging the hits, not just generating them.

Adverse media screening

Sanctions & screening

Adverse media screening checks customers, counterparties, and related parties against negative news and public sources for links to financial crime, corruption, terrorism, sanctions, or other risk, feeding onboarding and ongoing due diligence. It can surface risk before any formal designation exists.

The downside is heavy noise: stale, irrelevant, or same-name articles flood the queue. Operators tune it by relevance category, recency, and entity matching, and usually require an analyst to confirm the article is really about the subject and actually material. The risk is either drowning in false hits or, by over-filtering, missing a genuinely damaging story.

Affiliate fraud

Fraud types

This is gaming an affiliate or partner program to collect payouts on fake or forced conversions, using tricks like cookie stuffing, fake leads, and self-referrals. You pay commissions for customers who are not real, quietly bleeding the marketing budget.

Red flags include a sudden spike in conversions from one affiliate, clicks and conversions from mismatched locations, high refund or chargeback rates on referred users, and signups that share a device or card. Handle it by scoring conversion quality, holding payouts for a waiting period, and linking related accounts. It is closely tied to referral fraud and ad fraud.

Affinity fraud

Fraud types

This is a scam that abuses trust inside a shared community, such as a church, ethnic group, or profession. It is often an investment or Ponzi scheme, with respected members vouching for it and pulling others in. Trust makes victims lower their guard and hand over more.

It is hard to catch early because victims defend the fraudster and rarely report losses. In the data it shows as clusters of people from the same community all funding one person or entity. Watch for many related parties pushing money to a common recipient and refusing to cooperate with review.

Age verification

Identity verification

Age verification confirms a user is old enough for a regulated product like gambling, alcohol, tobacco, or adult content. Letting a minor through is both a fraud problem and a compliance and licensing risk.

Methods range from weak self-typed birth dates to document scans and data checks that confirm or estimate age. Self-declared dates are trivial to fake, so higher-risk products pull the date from an ID, match it to data, or estimate it from a selfie. Teams also watch for minors coached by an adult, or many accounts reusing one verified adult's identity.

Agentic AI fraud

AI & emerging fraud

This is fraud run by AI agents that can plan and act on their own across many steps, with little human help. One agent might scout your site, open fake accounts, and cash out, all in one smooth run. The attack adapts to your controls while it is happening, so fixed rules and simple speed limits fall behind fast.

Watch for timing no human could hit, behavior that seems to test your defenses, and the same patterns repeating across sessions. Teams lean on behavioral biometrics, agent detection, and step-up checks that get harder as risk rises. The trap is trusting static thresholds; the agent will find the edge of them and walk right past.

Agentic commerce risk

AI & emerging fraud

This is the risk that shows up when AI agents shop, pay, or manage accounts for a user. It blurs who really approved an action and who pays when it goes wrong. Your device and behavior signals were built assuming a human is present, and honest agent traffic can look automated or headless, like a browser with no screen.

It relates to how you prove an agent was truly authorized to act. Teams use delegated-authority checks, agent login or allowlisting, and spend caps per agent. One catch: blanket-block all automation and you break the very agent purchases your customers asked for, so you have to separate approved bots from bad ones.

AI fraud agent

AI & emerging fraud

This is an AI system aimed at fraud jobs: blasting out scam messages, poking at your control gaps, or auto-filling stolen data into signup forms. Unlike a plain script, it changes its inputs, reacts to error messages, and copies human timing, so it slips past defenses that only catch known signatures or simple speed spikes.

It relates to onboarding and login abuse at scale. Detection leans on behavior that looks off, device and environment details that do not add up, and consortium signals showing the same actor hit others. The trap: assuming a session that looks human is human. Treat that as a question, not an answer.

Alert

Monitoring & investigations

An alert is a flag the system raises when activity breaks a rule, scenario, or model threshold, marking it for an analyst to review. It is the raw front of the monitoring funnel and the starting point for every investigation and SAR. For fraud teams, alert volume, how fast they age, and how many are real hits are core signs of whether your program is working.

Most alerts are false positives, so the job is sorting signal from noise. Every alert needs a documented outcome. Watch for backlogs, which examiners treat as a program weakness, and for duplicate alerts firing on the same underlying activity.

Alert disposition

Monitoring & investigations

Alert disposition is the documented decision that closes an alert: close with no action, escalate to a case or enhanced due diligence, or refer for a SAR, plus the written reason why. The reason, not the outcome itself, is what proves your program is making sound calls.

Make sure the narrative actually supports the decision, since examiners and QA teams sample dispositions to test whether closes were justified. Common pitfalls are copy-paste rationales, closing without addressing every flagged transaction, and analysts applying different standards. Disposition quality drives how defensible your program is far more than raw alert volume.

Alias

Sanctions & screening

An alias is an alternate name, spelling, transliteration, or known-as identifier that a sanctioned or high-risk party uses. Sanctions lists publish these as AKAs so screening can catch names other than the primary one. A party rarely shows up under just one exact name.

Aliases cut both ways: they cause missed hits when a used name is not screened, and false positives when a common alias collides with unrelated people. Handling them well means screening every listed name variant and applying fuzzy, phonetic, and transliteration logic. The real problem is weak aliases, which are so common they can bury real hits in noise.

Allow list

Sanctions & screening

An allow list is a maintained set of pre-approved parties, values, or already-cleared matches that are exempted from blocking or repeat alerts, the counterpart to a deny list. It cuts recurring false positives, like a known-good customer who keeps matching a common sanctioned name.

It has to be tightly governed, with a documented reason, an owner, and periodic review for every entry. The stakes are high: a sloppy allow list can silently suppress a real future hit on the same identifier, so an entry added for convenience today could wave through a genuinely sanctioned party tomorrow.

An alternative remittance system moves money outside the regular banking system. Migrants and people without bank accounts use it for cheap, fast transfers, but for AML the concern is that value can move with little traceability and no wire or SWIFT trail.

Operators settle up among themselves through trust, trade, or bulk cash, so one transfer rarely maps to a bank record. Red flags include third-party cash deposits, round-number funding, and payment corridors that do not fit the customer. Hawala and hundi are examples, and the risk is treating every such system as criminal instead of checking the operator's license, controls, and traffic.

This is the full set of controls a firm runs to catch and stop financial crime: policies, risk assessment, customer checks, transaction monitoring, screening, SAR filing, training, and independent testing. It is the whole machine regulators judge you on, not any single piece.

Examiners test whether it really works day to day, not just whether it is written down, so gaps between the manual and real practice are a common finding. Anything the program forgets to cover becomes a blind spot that later shows up as a missed report or a costly lookback. Keep its scope honest and current.

AML policy

AML programs

This is the top-level document, approved by the board, that states the firm's AML duties, how much risk it will accept, who owns what, and the minimum standards every procedure must meet. It is the yardstick auditors and examiners hold you to.

In practice, trouble starts when the policy and how monitoring or customer checks actually run drift apart; that gap is a frequent exam criticism. Keep it dated and version-controlled. A stale policy that predates a new product or rule is a recurring weakness, so refresh it when the business changes, not years later.

This is a structured, evidence-based read of where money laundering and terrorist financing risk sits across customer types, products, regions, and channels. You rate the raw risk, then subtract the controls in place to land on the risk that remains. It steers staffing, monitoring thresholds, and how deep customer checks go.

A weak or stale assessment quietly miscalibrates controls everywhere downstream. Watch for scores that never change, credit given to controls with no proof they work, and new products launched before the assessment is refreshed. If the assessment is wrong, the whole program is aimed at the wrong targets.

AML training

AML programs

This is role-based teaching that helps staff spot laundering and terrorist-financing red flags, follow procedures, and meet their reporting duties. Good training is tailored, so front-line, operations, and senior people each get content matched to what they actually see. Your controls are only as sharp as the people running them.

Examiners look at completion tracking and testing, so generic training that ignores role and new fraud patterns is a common gap. Judge it by whether escalations and internal suspicion reports get better, not by attendance numbers. Attendance proves people showed up, not that they learned anything.

Anomaly detection

Device & behavioral

Anomaly detection flags activity that strays from an established baseline for a user, a segment, or the whole population. It can catch new or unseen fraud that fixed rules miss, like an odd transaction time, amount, or speed.

The downsides are real: it tells you something is off but not why, and it tends to throw false positives. Baselines also drift over time, so retrain and recalibrate regularly, and route anomalies to a human for investigation rather than automatic action.

AML is the body of laws, rules, and firm controls built to catch and deter criminal money moving through the financial system, usually framed around three stages: placement, layering, and integration. It is the umbrella discipline that ties together customer checks, monitoring, screening, and reporting.

Keep it separate in your head from sanctions and counter-terrorist financing, which have different triggers and urgency, and from plain fraud loss prevention. AML is regulatory and reporting-driven: you can file a report even when the firm loses no money. Treating AML as just another way to cut losses is a common framing mistake that leads to missed obligations.

The AMLA is the biggest overhaul of US AML law since the USA PATRIOT Act. It modernized the Bank Secrecy Act by creating the beneficial-ownership reporting regime through the Corporate Transparency Act, expanding whistleblower rewards and penalties, and pushing programs to be risk-based and driven by national priorities. It reshaped what a strong US program is expected to look like.

Day to day, it means collecting beneficial-ownership information, treating FinCEN's national AML priorities as program expectations rather than suggestions, and facing greater personal and institutional accountability. It also widened subpoena reach over foreign banks. Read it as raising the bar on both structure and accountability.

This is putting false, stolen, or altered information on a credit, deposit, or loan application to get a product the person could not honestly qualify for or plans to abuse. The bad application is the front door to later losses.

Signals include details that fail identity or bureau checks, income that is inflated or cannot be verified, many applications from shared devices or addresses, and data matching known fraud rings. Detect it with identity verification, income and document checks, and linking applications together. Note it covers both first-party fraud, where people inflate their own details, and third-party fraud using a stolen identity.

Approval phishing

Crypto & blockchain crime

Approval phishing tricks a user into signing a token approval that gives a malicious contract or address permission to move their tokens. The attacker can then drain the wallet later, with no further action from the victim.

Unlike a one-time transfer, an unlimited approval is a standing permission that lasts until it is revoked, so a single signature can enable repeated theft. On-chain it shows up as approvals granted to fresh or flagged spenders, followed by transferFrom sweeps that empty the wallet. Defend by reading approval prompts carefully, setting spend limits, and revoking old, unused approvals before they get used.

Approval rate

Detection & metrics

This is the share of good applications or transactions you approve. It is your main read on how much real business your controls let through, so it is the counterweight to fraud and loss numbers. Squeezing fraud usually drops approvals, and loosening up usually lets more fraud in.

A rate that is too low means you are over-blocking and leaving revenue on the table; too high can mean fraud is leaking. The trade you are managing is good customers approved versus fraud stopped. Read it by segment, not just overall, and always next to false-positive and loss metrics, since approval rate alone can look healthy while fraud quietly rises underneath it.

Art and antiquities laundering uses expensive, hard-to-price art or artifacts to store and move dirty money. Because value is subjective, sales are often private, and buyers can stay anonymous, a big transfer gets an easy cover story.

Red flags include buying through middlemen or shell companies, prices far off the appraised value, quick resale, and free-port storage where the piece never surfaces. Antiquities add looting and terrorist-financing exposure. It is a form of luxury asset laundering; the real opacity sits in private, agent-brokered deals, so do not lean on auction records.

Asia Pacific Group (APG)

Regulation & bodies

The APG is the FATF-style regional body for the Asia-Pacific and one of the largest such groups. It promotes and checks how well member countries put FATF standards into practice, using peer reviews called mutual evaluations. It is a credible outside read on how strong a given Asia-Pacific country's AML controls really are.

The APG publishes regional typologies and follow-up reports that flag which members have serious AML/CFT gaps. Use its assessments and typologies to set country risk ratings and to shape enhanced due diligence for customers and correspondent banks tied to Asia-Pacific jurisdictions, especially where it has called out deficiencies.

Asset freeze

Sanctions & screening

An asset freeze blocks a designated party's access to funds, accounts, or other assets, barring withdrawal, transfer, or use while they keep legal ownership, so the value is locked in place rather than seized. It is the operational core of targeted financial sanctions.

In the US it is carried out through blocking. Compliance means identifying assets the target owns or controls, including via the 50 Percent Rule, freezing them promptly, reporting, and refusing any further dealings unless a license allows it. The gap most often missed is indirectly held assets, since ownership can reach beyond the obvious accounts in the target's own name.

Audit trail

Monitoring & investigations

An audit trail is a complete, time-stamped, tamper-resistant record of every action taken on an alert, case, or decision: who did what, when, and the data and reasoning behind each step. It lets you rebuild a decision years later for an exam, a look-back, or a law enforcement request.

Confirm that system changes, threshold edits, and manual overrides are all logged, not just analyst notes. Gaps in the trail, especially around overrides where someone changed the system's call, are a frequent exam finding. If you cannot show how and why a decision was made, the program looks unmanaged even if the calls were right.

AUSTRAC

Regulation & bodies

AUSTRAC is Australia's AML/CTF regulator and financial intelligence unit. It runs the AML/CTF Act, receives threshold reports, suspicious-matter reports, and IFTIs, and supervises reporting entities. It is both the rule-maker and the enforcer, and it has handed down very large penalties for reporting and program failures.

If your business touches Australia, you must meet AUSTRAC enrolment, reporting, and program duties. Watch its guidance and enforcement actions closely; they signal where supervisory attention is heading. Its record of major fines shows that reporting gaps and weak programs are treated as serious, not technical, failures.

Authorization fraud

Card & payment fraud

Authorization fraud is when a payment gets approved using stolen or tested card details before any goods or money actually move. The point is to slip past the issuer's checks so the transaction looks clean at the moment of sale. The loss lands later, as a chargeback, not at approval.

It often shows up as approved payments that dispute later, clustered by card range (BIN), IP, or device after a card-testing run. Mismatched address or security-code results are a tell. A rising approval rate paired with rising disputes is the classic sign that stolen credentials are clearing your checks.

Authorized push payment fraud is when a scammer tricks a victim into sending money themselves to an account the fraudster controls. Because the real customer approves the transfer, the payment looks legitimate, and the money is very hard to claw back once it lands. That is what makes it so damaging.

Standard unauthorized-transaction controls miss it, so teams lean on behavior: new or mule payee accounts, odd urgency, and out-of-pattern payment reasons. Common types include fake invoices, safe-account tricks, and romance or investment scams. In some markets, rules now force the sending and receiving banks to refund victims.

Auto-decision

Detection & metrics

This is an approve, decline, or step-up outcome made by the system with no human reviewer, driven by rules and model scores at the moment of decision. It sets your speed and cost ceiling: the more you can safely auto-decide, the less you spend on manual review.

Track the auto-decision rate right alongside its error rates. Push automation too far and you either wave through fraud or block good customers, so borderline cases should route to review or step-up instead. The trade is throughput and cost against accuracy. A high auto-decision rate is only good news if the errors it hides stay low, so never read the two apart.

Autonomous fraud agent

AI & emerging fraud

This is an AI agent that runs on its own to commit or enable fraud, picking its next move with no human in the loop. In practice it scales and adapts far faster than a manual fraud ring, and it can hit signup, login, and payment flows all at once. Your response window shrinks from hours to seconds.

It is close cousin to agentic AI fraud and large bot attacks. Mitigation centers on friction that adapts to risk, agent detection, and watching for decisions made at machine speed. The pitfall is chasing single bad transactions; here you need to spot the pattern of fast, self-directed activity across many events.

B

32 términos

Backtesting

Monitoring & investigations

Backtesting means running a new or changed rule against past transaction data to estimate how it would have performed before you switch it on. You measure how many alerts it would fire, how many would be real, and what it would catch. That lets you size the false-positive load and justify a threshold change without disrupting live monitoring.

One limit stands out: history is incomplete, so activity nobody caught at the time was never labeled, and the data understates what you missed. Past behavior also may not match today's typologies. So backtesting supports, but does not replace, above- and below-the-line testing.

Baiting

Scams & social engineering

Baiting lures a victim with a tempting offer or object, a free download, a planted USB stick, or a deal too good to pass up, to get them to install malware, enter credentials, or pay. It works on curiosity or greed rather than fear, which sets it apart from urgency-based scams.

In casework it usually shows up as the entry point that comes before account takeover or a device getting compromised. The standard defenses are user awareness, endpoint controls, and blocking unknown USB or media so a planted device cannot run.

Bank impersonation scam

Scams & social engineering

A bank impersonation scam is a fraudster pretending to be the victim's own bank, often spoofing the real phone number or texting from a lookalike sender, to pressure them into moving money or handing over credentials and one-time codes. Posing as your bank borrows instant trust.

It often turns into a safe-account scam, where the victim is told to move funds to protect them. Red flags include the bank calling you out of the blue demanding urgent action, asking for one-time codes, or pushing payments to a new payee. A real bank never asks you to move money to a safe account.

Bank Secrecy Act (BSA)

Regulation & bodies

The BSA is the foundational 1970 US AML law. It requires recordkeeping and reporting, including CTRs and SARs, and underpins customer due diligence, monitoring, and the whole idea of a written program. It is the statute examiners measure your program against, with FinCEN as administrator and various agencies as supervisors.

Treat the BSA as the backbone of the US regime: most US AML obligations you handle trace back to it, later amended and strengthened by the PATRIOT Act and the AMLA. When a requirement seems to come from nowhere, it usually descends from the BSA, so knowing it helps you see why the rules exist.

Banknote laundering

Money laundering

Banknote laundering is physically handling and recirculating dirty cash to hide its criminal origin before it enters the system. Launderers break up hoards, clean worn or tainted notes, and feed them through cash-heavy businesses.

It shows up as large unexplained cash deposits, deposits that do not fit a business's stated model, and notes with drug residue or sequential serial numbers. This is the problem that structuring and smurfing exist to solve. It relates to placement and bulk cash smuggling; the key point is that getting bulk cash into the system is the launderer's hardest step, so cash patterns are among the richest signals.

Basel Committee

Regulation & bodies

The Basel Committee on Banking Supervision, hosted at the Bank for International Settlements, sets global prudential standards for banks and issues guidance on soundly managing money-laundering and terrorist-financing risk. While it is not an AML rule-maker with direct legal force, its guidance shapes the expectations national regulators then adopt.

In practice, operators reference its guidance on customer due diligence, correspondent banking, and risk management as a benchmark for what supervisors consider good practice. Think of it as a signal of where standards are heading rather than a rulebook you file against; regulators often turn its principles into binding local rules.

Batch monitoring

Monitoring & investigations

Batch monitoring reviews transactions in grouped runs on a schedule, such as nightly or daily, instead of checking each one the moment it happens. It fits after-the-fact AML detection, where the goal is spotting patterns over a period rather than stopping a single payment. That makes it efficient for pattern work but blind to anything happening right now.

Know its limit: it cannot stop a payment before it settles. That makes it unsuitable on its own for real-time fraud or sanctions blocking, where transaction screening and real-time monitoring are required. Use batch for trends, not for interdiction.

Bearer shares

High-risk payments

Bearer shares are company shares owned by whoever physically holds the paper certificate. There is no registered owner, so control passes just by handing over the document, which leaves no record of who really owns the company.

This is a classic blind spot for finding the ultimate owner, and it lets control change hands quietly during a deal. Most countries have now banned or locked them down, so live bearer shares are themselves a red flag that calls for enhanced due diligence. Worth noting: shares held and immobilized by a custodian carry lower risk than true physical certificates.

Behavioral analytics

Device & behavioral

Behavioral analytics studies patterns of user activity over time to surface fraud and account-compromise signals, comparing current behavior to the account's own history and to peer norms. It catches takeovers, mule activity, and scripted abuse that look fine on any single event.

Think of a sudden shift in login timing, navigation, or who money is sent to. The pitfall is telling a genuine life change from a real compromise, so combine it with device and identity signals to hold down false positives.

Behavioral biometrics

Device & behavioral

Behavioral biometrics are risk signals drawn from how someone types, swipes, holds, and moves through a device, rather than what they enter. It runs quietly in the background to spot account takeover, remote-control tools, bots, and scam victims acting under pressure.

It is probabilistic and drifts with the device, an injury, or the situation, so treat it as one weighted signal, not a verdict. Look specifically for remote-control patterns and the hesitation typical of a scam-in-progress session.

Below-the-line testing

Monitoring & investigations

Below-the-line testing samples activity that falls just under a scenario threshold to check whether truly suspicious behavior is slipping through undetected. It is the counterpart to above-the-line testing and a core part of tuning and model validation. It is the evidence that a threshold is not set so high it creates a blind spot criminals can hide in.

Sample enough volume for the result to be meaningful, and document what you find. Examiners expect to see below-the-line results before they will accept a threshold as reasonable. Skipping it means you can only prove what you catch, never what you miss.

Benami transaction

High-risk payments

A benami transaction, rooted in South Asian practice, is when an asset sits in one person's name while a hidden owner actually funds and controls it. It hides who really owns wealth and helps people dodge tax or launder criminal money.

Red flags include a nameholder whose income or profile does not match the asset, funding traced to a third party, and a registered owner who makes no real decisions. This is a form of nominee holding; the core investigative job is to establish the true source of funds and who actually directs the asset.

Beneficial ownership

Business verification

Beneficial ownership is the real people who ultimately own or control a company, whether through direct shares, indirect layers, or effective control like voting or management rights. It is where launderers hide, behind nominees, trusts, and cross-border chains.

Identifying these people is the goal of UBO analysis. Trace control as well as ownership percentages: someone holding less than any equity threshold can still run the company, so a purely numeric test misses them.

BOI reporting is the US requirement, created under the Corporate Transparency Act and run by FinCEN, for many companies to report their beneficial owners and controlling persons to a central registry. It aims to strip the anonymity from shell companies that criminals use to launder money, giving a way to see who really owns an entity.

Understand that the registry supports your own CDD beneficial-ownership work; it does not replace it. Scope, exemptions, and who can access the data have shifted over time, so track the current requirements carefully rather than relying on how it worked before. Assuming last year's rules still apply is a real risk here.

Beneficial ownership obfuscation is stacking companies, nominees, trusts, and countries to hide the real person who ultimately owns or controls the money. It defeats customer due diligence and verifying the ultimate owner, the whole point of knowing who you deal with.

Red flags include circular or many-layered ownership, nominee directors and shareholders, one formation-agent address shared by many companies, and ownership that stops at another company instead of a person. It relates to shell companies and nominees; the trap is accepting a parent company as the owner instead of drilling down to the controlling individual.

BIN attack

Card & payment fraud

A BIN attack is when fraudsters take a known card-number prefix (the BIN, which identifies the issuing bank) and mass-generate full card numbers, guessing the expiry and security code. They then fire these guesses at weak checkout or verification pages to find combinations that work. One leaked BIN can spawn thousands of live cards.

The tell is bursts of declines clustered on one or few BINs, card numbers in sequence, and heavy attempts from few devices or IPs. Slow it with velocity limits per BIN and IP, CAPTCHA or device checks on payment forms, and rate limiting. It is a close cousin of enumeration and card testing.

Biometric authentication

Device & behavioral

Biometric authentication verifies a returning user by matching a live trait like face or fingerprint against a stored reference, often using on-device sensors. It is convenient and cannot be stolen the way a password can.

But it needs liveness to resist spoofing, and secure enrollment so a fraudster cannot register their own face or finger during a takeover. Focus your controls on the enrollment and recovery paths: that is where attackers pivot when beating the live match is too hard.

Biometric verification

Device & behavioral

Biometric verification confirms identity by matching a captured trait to a reference, either one-to-one against a claimed identity or one-to-many against a gallery. It ties a real physical trait to an account.

Its reliability rests on capture quality, liveness, and where you set the threshold between wrongly accepting and wrongly rejecting people. A match is probabilistic evidence, not proof: without liveness it can be beaten by photos, masks, replays, or injection, so combine it with device and provenance checks.

Black market peso exchange

High-risk payments

The black market peso exchange is a scheme that cleans drug money by swapping currencies through brokers and import-export invoices, classically between the US and Latin America. Cartels get clean local cash without ever sending a cross-border wire.

It shows up as third-party payments for goods, invoices paid by unrelated parties, and importers paying suppliers with money from unknown US sources. It is a form of trade-based money laundering. The hard part: each leg looks like normal business, so the pattern only appears when you line up the payer, the buyer, and the flow of goods together.

Blockchain analytics

Crypto & blockchain crime

Blockchain analytics is the practice and tooling for tracing, grouping, and risk-scoring on-chain activity, so investigators can follow illicit money, tie addresses to real-world entities, and measure exposure to sanctioned or criminal counterparties. It powers crypto investigations, transaction monitoring, and sanctions and KYC controls.

Core methods include clustering wallets by shared behavior, tracing flows across many hops, and spotting known laundering patterns. The key limit is uncertainty: attribution is a best estimate, not proof, and it can be blurred or broken by mixers, bridges, and privacy tech. Treat every attribution as carrying a confidence level, not a guarantee.

Blocking

Sanctions & screening

Blocking is the US sanctions action of freezing a prohibited party's property and interests in property that come within reach, then holding and reporting it, rather than returning or processing it. It is how OFAC sanctions are actually enforced against SDNs and entities caught by the 50 Percent Rule.

It differs from rejection, where a transaction is simply declined and no funds are held. Operators must know when to block versus reject, park blocked funds in a segregated account, and file the required report within the set deadline. Confusing the two is costly: rejecting when you should block lets property go that the law required you to hold.

Bonus abuse

Fraud types

This is milking promotions, sign-up bonuses, or free credits beyond their intended use, usually by creating many accounts, some of them fake, to farm the reward at scale. Each abused offer is a direct cash cost with no real customer behind it.

Tell-tale signs are clusters of accounts sharing the same device, IP, card, or behavior, very little genuine activity, and a cash-out the moment the bonus lands. Mitigate it by linking devices and payment methods, capping rewards per identity, and delaying when a reward can be withdrawn. It is close cousin to promotion abuse, multi-accounting, and referral fraud.

Bot attacks at scale

AI & emerging fraud

These are mass automated attacks like credential stuffing, card testing, and bulk account creation, made cheap by easy tools and rented proxy networks. Volume alone can overwhelm controls and find the one weak account or live card among thousands of tries.

Red flags include spikes in failed logins or tiny test charges, the same device or IP fingerprint across many accounts, and speed no human could match. Teams counter with rate limits, device fingerprinting, behavioral biometrics, and step-up challenges. The tradeoff: throttle too hard and you block real bursts too, like a payday rush or a promo, so tune limits to the moment, not just the average.

Bot detection

Device & behavioral

Bot detection separates automated scripts, bots, and headless browsers from real human users across signup, login, and checkout. Bots drive credential stuffing, account testing, card testing, and scalping at massive scale.

It draws on device fingerprinting, behavior, challenge responses, and velocity to spot them. But sophisticated bots mimic human timing and rotate identities, so layer your signals and expect an ongoing arms race rather than one reliable tell.

Brute force attack

Account & access fraud

A brute force attack is when software rapidly tries many passwords, PINs, or one-time codes against an account until it hits the right one by sheer volume. Weak lockout rules and short numeric codes can be guessed fast, handing an attacker the keys.

It is loud and easy to spot: failed attempts spike in a short window. Stealthier cousins include credential stuffing and password spraying. Blunt it with rate limits, progressive lockouts, CAPTCHA, and device or IP throttling, plus strong MFA that does not lean on short, guessable codes. The tradeoff is that tight lockouts can also frustrate real users, so tune them.

BSA Officer

AML programs

In the US, this is the person formally named to run and answer for the firm's Bank Secrecy Act compliance and reporting; naming one is a required pillar of the program. They own SAR and CTR filing decisions, program oversight, and the relationship with examiners. Someone with real authority has to own these calls.

To be effective they need genuine seniority, independence, and enough staff. A common exam criticism is a BSA Officer in title only, with no power or resources to actually oversee the program. If the role is a name on an org chart rather than a funded function, the whole program is exposed.

BSA/AML program

AML programs

This is a US financial-crime program built to meet the BSA pillars: internal controls, a named BSA/AML officer, ongoing training, independent testing, and risk-based customer due diligence including beneficial ownership. Examiners grade each pillar on its own.

A strong monitoring system will not make up for, say, missing independent testing; a weak pillar drags the whole program down. Map your controls to each pillar clearly, because pillars that are undocumented or unstaffed are among the most frequent enforcement findings. Do not assume that being good at one pillar buys you slack on another; it does not.

Bulk cash smuggling

Money laundering

Bulk cash smuggling is physically carrying large amounts of currency across borders to dodge reporting and place the money in a country with weaker AML rules, skipping the financial system entirely at the border.

Signs include travel to cash-friendly countries, cash deposits soon after a border crossing, and trade or logistics firms used as cover for courier routes. It relates to placement, alternative remittance, and cross-border currency reporting. The catch: once the cash lands abroad it re-enters through local deposits, so a home-country bank may only ever see the clean-looking inbound leg.

This is impersonating an executive, vendor, or partner through a spoofed or hacked email to trick staff into redirecting payments, changing bank details, or leaking data. Its danger is that it turns a trusted email into a large, fast loss that is hard to claw back.

On the receiving side it looks like wires or ACH payments to a newly added payee, a sudden change to a known vendor's bank account, and urgency or secrecy in the ask. Controls include calling back on a known number to verify any payment-detail change, requiring two approvers on wires, and scoring payee risk. CEO fraud and invoice redirection are common variants.

Bust-out

Money laundering

A bust-out is when someone builds up good credit on cards or accounts over time, then suddenly maxes every limit with no intent to repay and walks away. The identity used may be real, stolen, or synthetic, and the loss lands all at once.

The tell is a stretch of on-time payments followed by fast balance-building, cash advances, and payments made with bad or fake checks to free up more credit right before cashing out. It relates to synthetic identity fraud and first-party fraud. One catch: bust-outs look like model customers until the final burst, so watch velocity and payment reversals near credit limits.

Buy now pay later (BNPL) fraud

Card & payment fraud

Buy now pay later fraud abuses instant-approval installment credit, where a shopper gets goods now and pays in a few payments later. Fraudsters use stolen, made-up, or their own identities to grab goods with no intent to pay. The light, fast approval checks are exactly what makes it easy.

Watch for brand-new accounts, shipping that does not match billing, and the same device or email across many applications. A missed very first payment is a strong signal. It overlaps with account takeover of existing BNPL profiles and synthetic identity. First-party never-pay abuse looks like credit risk but is really fraud, so code it correctly.

Buyer fraud

Fraud types

This is when a buyer abuses payment, dispute, refund, or return rules to get goods or money they should not. It includes chargeback abuse, false item-not-received claims, and refund tricks. Losses hide inside normal-looking orders and add up fast.

It shows as a customer with a high dispute rate, claims that clash with delivery or tracking records, and repeat refund requests across orders. Mitigate it with delivery proof, fighting disputes with evidence, scoring accounts for abuse, and blocklisting repeat offenders. Related terms are friendly fraud, chargeback fraud, and refund fraud.

C

55 términos

Caller ID spoofing

Scams & social engineering

Caller ID spoofing is faking the phone number shown on someone's screen to look like a bank, agency, or known contact and manufacture trust. It is a core enabler of voice phishing and bank-impersonation scams; the fake number makes the caller seem legitimate.

Since the displayed number cannot be trusted, defenses focus on customer education (hang up and call the number on your card), call-authentication systems like STIR/SHAKEN, and treating any inbound caller who asks for funds or codes as suspect no matter what the screen says.

Card checking

Card & payment fraud

Card checking is testing stolen card numbers with tiny or zero-dollar charges to see which ones still work before using them for bigger fraud. It is the same thing as card testing. Finding live cards first saves the fraudster from wasting dead ones on a real purchase.

It shows up as a spike in small approvals or account-verification calls, high decline rates, and the same cards reused fast across a merchant. Catch it with velocity rules, decline-rate monitoring, and grouping by device or IP. It is usually the first step; the working cards get sold or cashed out somewhere else.

Card cloning

Card & payment fraud

Card cloning is copying data from a real card, usually the magnetic stripe, onto a fake card to use in person. A cloned card lets a criminal spend at a store or ATM as if they held the genuine card.

Cloned cards cannot pass chip checks, so fraudsters force a swipe fallback or target old magstripe-only terminals. Watch for stripe use on chip-capable cards, swipe fallbacks, and locations that are impossible given the last transaction. Chip (EMV) rollout cut this sharply in chip markets and pushed fraud online instead. It is tied to skimming, dumps, and stolen track data.

Card cracking

Card & payment fraud

Card cracking is a scam where a victim is recruited, often through social media ads promising easy money, to hand over their card or account. The fraudster runs money through it, and the victim then falsely disputes the charges as unauthorized to keep a cut. The account holder is in on it.

That mix of first-party dispute abuse and mule recruitment makes it tricky. Red flags include accounts with a deposit-then-withdraw pattern, disputes filed soon after odd incoming funds, and holders linked to known mule networks. It sits on the line between fraud and money laundering.

Card fraud

Card & payment fraud

Card fraud is a catch-all term for any unauthorized use of a payment card or card account, whether the card is used in person or online. It works as a heading, but the label alone does not tell you how the fraud happened or who pays.

In practice you split it into subtypes such as counterfeit, lost or stolen, card-not-present, account takeover, and first-party, because each has different signals and liability rules. Treat it as a category, not a root cause. Case notes should name the actual method so trends and controls line up with the right threat.

Card shimming

Card & payment fraud

Card shimming is stealing chip-card data with a paper-thin device slipped inside a card reader's slot, capturing the data the chip exchanges during a transaction. Its danger is that it attacks the chip, which people assume is safe, rather than the magnetic stripe.

Chip data alone cannot reliably recreate the one-time code each chip transaction generates, so shimmed data is mostly used for online fraud or against weak fallback flows, not perfect clones. Catch it with terminal inspections, tamper alerts, and watching for odd activity on affected terminals. It is like skimming but aimed at the chip instead of the stripe.

Card skimming

Card & payment fraud

Card skimming is capturing card data with a hidden device attached to an ATM, gas pump, or checkout terminal, often paired with a tiny camera or fake keypad to grab the PIN too. One rigged machine can feed a wave of later fraud.

Compromised terminals produce clusters of fraud that share one common point of purchase, which is the key thread investigators follow. Fight it with tamper-proof hardware, regular terminal inspections, and common-point-of-purchase analysis. Skimmed data feeds cloning, dumps, and later in-person or ATM fraud.

Card testing

Card & payment fraud

Card testing is running small, trial, or zero-dollar charges to find out which stolen cards are still live before committing to bigger fraud. It is usually automated against checkout or account-verification pages. It turns a pile of stolen numbers into a shortlist of working ones.

It shows up as spikes in tiny approvals, more declines, and cards cycling fast from few devices or IPs; it can also run up your processing fees and drag down approval rates. Counter it with velocity limits, CAPTCHA, device fingerprinting, and rate limiting on payment forms. It is the same thing as card checking.

Card-not-present (CNP) fraud

Card & payment fraud

Card-not-present fraud is fraud where the physical card is never read, as in online, in-app, or phone orders. The criminal only needs the card number, expiry, security code, and billing details. Since chip cards made in-person fraud hard, this is now the main card-fraud channel.

Detection leans on address and security-code checks, 3DS, and device or behavior signals. Watch for billing and shipping that do not match, a new device or account, package-forwarding addresses, and the same card hitting many merchants fast. The merchant usually eats the loss unless the payment was authenticated through 3DS.

Card-present (CP) fraud

Card & payment fraud

Card-present fraud is fraud at a physical checkout using a counterfeit, lost, or stolen card. It matters less than it used to in chip markets, but it still bleeds through weak spots.

After chip (EMV) rollout, the tells are magstripe fallback, stripe-only or unattended terminals, and swipes far from the cardholder's usual area; a location that is impossible given recent activity is a strong signal. Liability usually falls on whichever party is least chip-compliant. It is related to cloning, skimming, and shimming, and is far rarer than online fraud where chips are in use.

Carding

Card & payment fraud

Carding is the whole criminal business of buying, selling, and cashing out stolen card data. It includes automated testing on small purchases to find live cards before they are resold or used. This is an organized supply chain, not one-off theft.

It plays out across dark-web shops, testing scripts, and mule networks. On the merchant side it looks like card-testing bursts, high declines, and small orders from throwaway identities. It is linked to dumps, fullz, BIN attacks, and enumeration. Cards tested at one merchant often move to a different, higher-value merchant for the real loss.

Case management

Monitoring & investigations

Case management is the end-to-end workflow that carries suspicious activity from alert through investigation, documentation, decision, and, where warranted, a SAR filing. It usually bundles related alerts and subjects into one case. This is where analysts pull KYC, transaction history, and 314(b) input together to build the record that backs the outcome.

Care about case aging and SLA tracking, and about linking related alerts so you do not review the same subject in fragments. Keep a clean audit trail throughout. Poor linkage is the classic pitfall: it causes missed patterns, duplicate work, and inconsistent decisions on the same customer.

Casino laundering

Money laundering

Casino laundering turns dirty cash into chips with little or no actual gambling, then cashes out as fake winnings or a check to make the money look like it came from the casino.

Red flags include buying in but barely betting, passing chips between players, asking for large payouts by check, and multiple cash-in sessions kept under reporting limits. It relates to structuring and placement. The nuance is that patron play records and the ratio of buy-in to real wagering are the key evidence, because a genuine gambler leaves a very different footprint from a launderer.

Catfishing

Scams & social engineering

Catfishing is running a fake online persona, with stolen photos and an invented backstory, to trick a victim into a relationship or trust. It is often the front end of a romance or pig-butchering scam. It builds real emotional dependence before any money is ever mentioned, so the early stage shows no financial signal.

Investigators look for reused stock or stolen images, excuses to avoid video calls, and a storyline that keeps steering toward money or crypto. It overlaps with romance scams and social engineering.

CCPA

Regulation & bodies

The CCPA is the California Consumer Privacy Act. It gives California residents rights over their personal data, including access, deletion, and opting out of sale, and puts obligations on covered businesses. For fraud and KYC teams, a customer's deletion or access request can collide with AML retention duties and fraud-prevention needs.

In practice, AML recordkeeping and fraud-detection uses generally have carve-outs, so you usually do not have to delete records you are legally required to keep. But the data you handle in monitoring and identity programs must still respect applicable privacy limits. Know where the fraud and AML exceptions end and ordinary privacy duties begin.

CEO fraud

Fraud types

This is a type of BEC where the fraudster poses as a senior boss, usually the CEO or CFO, to pressure staff into urgent, secret, off-process payments or gift-card buys. People rarely question the boss, so the request gets rushed through.

The hooks are authority, urgency, and secrecy, often timed for when the executive is traveling or hard to reach. Detect it with firm payment-verification rules, callbacks to known numbers, and flags on first-time payees requested by senior staff. The real fix is an enforced process, not just hoping employees stay alert under pressure.

CFTC

Regulation & bodies

The CFTC is the US Commodity Futures Trading Commission, the federal regulator of derivatives markets including futures, swaps, and options, with jurisdiction over some crypto activity treated as commodities. It enforces against fraud and market manipulation and coordinates with other agencies on AML expectations for the firms it registers.

If you are at a futures commission merchant or a similar firm, note that CFTC-driven expectations sit on top of your BSA obligations, not instead of them. It also plays a growing role in commodity-based crypto fraud cases, so its enforcement actions are worth watching for where the line falls between commodity and security oversight.

Chain hopping

Crypto & blockchain crime

Chain hopping is quickly moving funds across different blockchains and assets, often through bridges, swaps, or exchanges, to break the tracing trail and make attribution harder. Each cross-chain jump creates a gap that simple single-chain tracing cannot follow.

Launderers lean on it right after a theft or ransom payout, hopping funds before investigators catch up. Countering it needs cross-chain analytics that stitch a bridge deposit on one chain to the matching withdrawal on another, plus close watch on the bridge and swap venues criminals favor. Trace one chain in isolation and you lose the money at the first hop.

Charge-off

Detection & metrics

This is a loss booked when a debt is judged uncollectible, including confirmed fraud written off after recovery attempts fail. It is where fraud finally lands on the profit-and-loss statement, so reconciling charge-offs back to fraud tags is how you learn your true loss rate versus what your alerts actually caught.

Watch for fraud hiding inside credit charge-offs, especially first-party fraud and bust-out, where someone builds credit then vanishes owing the max. Call that credit loss and you understate fraud, which starves your models of labels and skews your whole strategy. Reconcile carefully so the loss lands in the right bucket.

Chargeback

Card & payment fraud

A chargeback is when the card issuer reverses a payment and returns the money to the cardholder, using set reason codes. This is how card fraud losses and disputes actually land on a merchant, and too many can trigger network penalty programs.

Teams sort chargebacks by reason code to tell true fraud (unauthorized use) apart from first-party abuse and delivery or service complaints, since each needs different evidence. Track your chargeback rate against network thresholds to stay out of monitoring programs. Merchants can contest with representment, and a rising ratio often points to an upstream fraud or dispute-abuse problem.

Chargeback fraud

Fraud types

This is disputing a real card purchase to get a refund while keeping the goods or service. It is a form of first-party abuse, different from a genuine complaint about an unauthorized charge. The merchant loses both the product and the money.

It surfaces as customers with repeated disputes, claims that clash with delivery or usage logs, and dispute reason codes that do not fit the evidence. Teams fight it with representment packages showing proof of delivery, device, and login data, plus pre-dispute alerts and abuse scoring. Do not confuse it with true fraud chargebacks, or you will overstate your fraud rate.

Chargeback rate

Detection & metrics

This is chargebacks as a share of your transactions or volume. It is watched hard because card networks set monitoring thresholds, and breaching them brings fines and forced program placement. It is your direct tie to network health, not just internal loss.

It is a lagging indicator: disputes surface weeks after the fraud, so a clean current month can still hide a bad batch of customers. Segment it by merchant, card BIN, and reason code, and split true fraud disputes from friendly fraud, where a real buyer disputes their own purchase, and plain service complaints. Each needs a different fix, so a blended rate can point you at the wrong problem.

Charity fraud

Fraud types

This is collecting donations for a fake or misrepresented cause, often spiking after disasters or tragedies when donors give quickly and check less. It preys on goodwill and can also move dirty money.

On the payments side it looks like many small donations into a new account followed by a fast cash-out, or victims sending money to unregistered groups. Watch for charity names that copy real ones, high-pressure appeals, and a mismatch between the stated cause and where funds actually go. It overlaps with mass-marketing fraud.

Check fraud

Fraud types

This is forging, altering, counterfeiting, or washing checks, or depositing checks with no real funds behind them. It is often paired with mail theft or account takeover. Checks clear slowly, so money can be pulled out before the fraud is caught.

Red flags include altered payee or amount fields, signatures that do not match, deposits that do not fit the account's history, and fast withdrawal before the check clears. Controls include positive pay, hold periods, image and MICR analysis, and cross-bank deposit checks. Related terms are check kiting, mobile deposit fraud, and check washing.

Check kiting

Fraud types

This is abusing the delay, or float, between banks by writing and depositing checks against money that is not really there, creating a fake balance. The account holder spends funds they do not have until the scheme falls apart.

It shows as frequent circular transfers between two or more accounts, deposits and withdrawals timed to clearing windows, and balances that swing without any real money underneath. Detect it with float analysis, cross-account transfer monitoring, and hold policies. The scheme collapses the moment holds tighten or one check bounces.

The CCO is the senior executive accountable for the whole compliance function, financial crime included, and usually the escalation point above the BSA Officer or MLRO. They set the compliance agenda, report to the board, and increasingly carry personal liability under individual-accountability rules. This is who owns risk-appetite and resourcing at the top.

For front-line teams, that means chronic under-resourcing of investigations is a CCO-level governance problem, not just a team gripe. If cases pile up because there are never enough investigators, the fix sits above the queue. Point the issue where the real decision authority lives.

Clean fraud

Fraud types

This is card-not-present fraud that uses valid stolen card data behind a polished, believable profile, with matching billing, a plausible device, and an aged account, all built to pass fraud checks and manual review. Left unchecked, it slips past rules and quietly inflates your approval numbers.

It is dangerous precisely because static data looks fine, so catching it needs behavioral signals, device intelligence, and links to past confirmed fraud. Contrast it with sloppy, high-speed fraud; clean fraud is the patient, low-and-slow kind. A profile that looks too perfect deserves a second look, not automatic trust.

Click fraud

Fraud types

This is generating fake clicks on pay-per-click ads, using bots, click farms, or rivals, to drain a competitor's budget or pad a publisher's payout. Advertisers pay for every click, real or not.

It shows as odd click volume from narrow IP ranges or data centers, lots of clicks with zero conversions after, and repetitive click timing. Mitigate it with IP and device reputation, click-quality scoring, and checking that clicks lead to real conversions. It is a subset of ad fraud and shares tools with bot-traffic detection.

Close associate

Business verification

A close associate is someone with a tight business or personal link to a politically exposed person, such as a joint business partner or a known confidant. PEPs often move funds and hold assets through associates to keep their own name off the transaction.

Associates are harder to spot than the PEP directly, since you find them through adverse media and network links rather than a clean list. Factor them into enhanced due diligence rather than screening only the named PEP.

CoinJoin

Crypto & blockchain crime

CoinJoin is a shared bitcoin transaction where many people combine their inputs and outputs into one, so it is no longer clear which input paid which output. It is a legitimate privacy tool that criminals also use to launder funds, so exposure to it usually raises a wallet's risk score rather than proving guilt.

Analysts treat funds coming out of a CoinJoin as mixed, with lower confidence about their origin, and weigh the surrounding context. Poorly built rounds can sometimes be partly unwound by heuristics. The tradeoff is real: legitimate privacy and laundering look alike, so judge the whole picture, not the mix alone.

Collusion

Device & behavioral

Collusion is two or more parties working together to commit fraud, like a merchant and cardholder running friendly-fraud schemes, employee and customer theft, or a ring coordinating a bust-out. Each participant can look completely legitimate on their own.

That is why collusion hides from single-account controls and shows up mainly through link and network analysis of shared attributes and coordinated timing. Investigate the relationships and the money flow between parties, not just each account in isolation.

Collusion fraud

Fraud types

This is fraud run by two or more people working together, whether staff plus an outsider, a buyer and seller, or linked accounts, to beat controls that assume everyone acts alone. Each player can look clean on their own.

The signal is in the relationship, not the individual: shared devices, addresses, funding sources, or repeated deals between the same parties. Detect it with link analysis, network graphs, and segregation-of-duties monitoring. It is common in procurement, marketplaces, and insider fraud, where trusted access meets a willing partner.

Collusion ring

Account & access fraud

A collusion ring is a group that works together across several accounts or insider roles to pull off fraud one person could not, like fake buyer-seller pairs, mutual chargeback scams, or an employee waving through a friend's activity. Each member can look harmless alone.

The signature is unnatural closeness: parties who only ever deal with each other, share devices or payout accounts, and act in sync. Because per-account scoring misses it, detect it with link analysis and graph techniques that expose the hidden connections. The trap: judging accounts in isolation, which lets the ring hide in plain sight.

Commingling

Money laundering

Commingling mixes dirty money with legitimate business income so the criminal portion hides inside a genuine cash flow and is hard to pull back out.

It is the hallmark of front and cash-heavy businesses. Red flags include deposits bigger than plausible sales, revenue out of line with sector benchmarks, and margins or turnover that do not fit the stated model. It relates to front companies, placement, and integration. Real activity provides the cover, so detection relies on benchmarking financials against realistic peer baselines rather than hunting for obviously illicit transactions.

Compliance culture

AML programs

This is how much a firm's people, incentives, and everyday choices genuinely back its compliance duties instead of treating them as a box to tick. Culture, not the manual, decides what actually happens when money and rules collide.

You see it in whether staff escalate concerns freely, whether sales pressure overrides control decisions, and how the firm reacts when compliance says no. Weak culture is a leading root cause in enforcement actions. Warning signs include punishing people who raise concerns, alert backlogs that management just tolerates, and revenue teams overruling risk calls. Strong culture shows when the firm backs a no even when it costs money.

Consortium data

Detection & metrics

This is data pooled across many institutions that strengthens fraud and identity signals through network effect. It lets you see an entity's behavior beyond your own walls, so a device, account, or identity already tied to fraud elsewhere shows up even if it looks clean to you. It catches mules and synthetics you would otherwise miss.

Value grows with the size of the network and how fresh the data is. The nuances are coverage gaps, matching accuracy, that is, correctly resolving whether two records are the same person, and how you act on a hit. Treat a consortium match as a strong signal to investigate, not an automatic decline, since matching is never perfect.

The CTA is the US law, enacted within the AMLA framework, that requires many companies to report beneficial-ownership information to FinCEN in order to fight the use of anonymous shell entities in illicit finance. It is the statutory basis for the whole BOI reporting regime; the reporting duty flows from this law.

It created a national ownership registry that complements, but does not replace, an institution's own CDD. Its scope, deadlines, and enforcement posture have shifted over time, so track the current state rather than assuming. This is an area where relying on an outdated understanding can leave you either over- or under-collecting.

CPF is the set of controls aimed at catching and stopping money that funds weapons of mass destruction programs and the networks behind them. FATF standards increasingly treat it as its own area, apart from general sanctions and terrorist-financing work. These flows are among the highest-stakes and hardest to see.

Detection leans on dual-use goods red flags, opaque trade structures, front companies, and links to sanctioned regimes. It is hard because the underlying goods often look perfectly legitimate, so you watch shipping, end-user, and network anomalies rather than the payment alone. The transaction by itself usually looks clean; the story around it does not.

CTF is the set of controls to catch and stop money being raised, moved, or used for terrorism, whether the cash starts clean or dirty. It does not behave like classic laundering.

Amounts are often small and the source may be legitimate, so value-based thresholds miss it; detection leans instead on names, networks, geographies, and behavior patterns. Speed is critical: suspected terrorist financing often needs immediate escalation and law-enforcement contact rather than the routine SAR timeline. Treating it like ordinary laundering, and waiting for a big-dollar trigger, is exactly how it slips through. When in doubt here, move fast.

Counterfeit card

Card & payment fraud

A counterfeit card is a fake physical card made from stolen stripe or chip data and used at in-person checkouts. It lets a criminal spend in stores as if they held the real card.

It surfaces as magstripe or fallback use on accounts that have a chip, locations that are impossible given recent activity, and clusters tied to one point of compromise. Chip (EMV) largely killed this in chip markets by requiring a one-time code per transaction; the leftover risk sits in stripe-only, fallback, and non-chip regions. It is related to cloning, dumps, and skimming.

Credential cracking

Account & access fraud

Credential cracking is software guessing passwords for one or more known usernames, using dictionaries, leaked password lists, or rule-based tweaks on common words. It targets accounts the attacker already knows exist, so a hit is more likely than blind guessing.

It overlaps with brute force but aims at real, confirmed usernames. A low-and-slow version spreads attempts out to dodge lockouts. Defend with breached-password screening, anomaly detection on login patterns, bot management, and MFA, so a cracked password on its own is not enough to get in. The tradeoff is balancing strict lockouts against blocking real users.

Credential stuffing

Account & access fraud

Credential stuffing is replaying username and password pairs stolen in other companies' breaches across many sites, betting that people reuse the same password. Reuse is common, so attackers quietly find working logins at scale.

It is high-volume and bot-driven, so tells include a surge in login traffic, a low success rate, headless browsers, and rotating residential proxies. Fight it with breached-credential checks, device fingerprinting, bot detection, and MFA. The accounts it cracks often feed account takeover next, where payout and contact details get changed right after login, so treat a hit as the start, not the end.

Crime-as-a-Service

AI & emerging fraud

This is criminal capability packaged up and sold or rented, so a low-skill actor can run a high-skill attack. It is the umbrella term over fraud-, phishing-, and deepfake-as-a-service. Both the volume and the quality of attacks go up even as the average attacker gets less skilled.

The operational upside for you is that these kits and templates get reused, which leaves shared fingerprints across otherwise unrelated fraud. That reuse is detectable. Consortium and cross-institution data help you spot a kit you have seen before at another firm. The pitfall is treating each attack as unique when many trace back to the same rented toolset.

Cross-chain bridge

Crypto & blockchain crime

A cross-chain bridge is a protocol that moves value between separate blockchains, usually by locking or burning an asset on one chain and minting or releasing a matching version on another. Bridges are central to chain hopping and hold large pooled balances, which makes them both a laundering tool and a top target for huge thefts.

Those big locked balances sit behind contract code that can be exploited. For monitoring, bridge deposits and withdrawals are key tracing chokepoints, and a spike in unusual bridge flows right after an exploit is a strong laundering signal. The trail can go cold where a bridge hands off between chains.

Crypto drainer

Crypto & blockchain crime

A crypto drainer is malicious code, often sold as a ready-made kit or drainer-as-a-service, that empties a victim's wallet once they connect it to a fake site or sign a malicious transaction or approval. It turns one bad click into a total loss, and the kit authors take a cut of everything stolen.

Drainers ride phishing campaigns spread through fake airdrops, ads, and cloned apps. The tell is a sudden full-balance sweep to a fresh consolidation address. Defenses include wallet-drain detection, blocklists of known malicious sites and contracts, and clear warnings before a user signs anything risky.

Crypto scam

Scams & social engineering

A crypto scam is any scam that pushes victims into fake crypto investments, bogus exchanges or wallets, phony airdrops, or transfers to an attacker's wallet address. Crypto is irreversible and pseudonymous, which makes it the preferred way for fraudsters to cash out and for victims to lose money for good.

It underpins most pig-butchering losses. Tells include unsolicited high-return pitches, fake trading dashboards showing pretend gains, and pressure to deposit more before you can withdraw. Blockchain tracing and screening for flagged wallet addresses support investigation and any recovery attempt.

Cuckoo smurfing

Money laundering

Cuckoo smurfing settles dirty money into the accounts of innocent customers who are expecting a legitimate incoming transfer. The deposit looks normal to the receiving bank, and the launderer's own cash never touches a monitored account.

It is common in remittance corridors where a crooked broker intercepts the payment instruction and drops in criminal cash instead. Red flags include cash or third-party deposits funding an expected wire, deposits split across branches, and depositors unrelated to the real sender. Since the account holder is usually innocent, the signal is the mismatch between the expected sender and who actually paid in.

Currency Transaction Report (CTR)

Monitoring & investigations

A CTR is a mandatory US filing to FinCEN for cash moving in or out above 10,000 dollars in a single business day, by or for one person, including several transactions that add up to that. It is a hard, objective rule: it is not about suspicion, so it differs from a SAR, and missing one is a clear compliance failure.

Aggregate a customer's cash activity correctly across the day, and apply exemptions properly for eligible business customers. Watch for structuring, where someone splits cash to stay just under 10,000 dollars; that behavior itself warrants a SAR even though no single CTR was triggered.

Customer Due Diligence (CDD)

Due diligence & onboarding

CDD is the core process of identifying and verifying a customer, understanding the purpose of the relationship, and judging its laundering and terrorist-financing risk, with the depth scaled to that risk. It feeds the customer risk rating and sets the baseline for ongoing monitoring, so weak CDD undermines everything downstream.

Common failures are verifying identity but never establishing what activity to expect, and treating CDD as a one-time onboarding chore rather than a living record. If you never define normal for a customer, you cannot tell when their behavior turns abnormal. Keep the record current, because risk verified once decays as circumstances change.

Customer Identification Program (CIP)

Due diligence & onboarding

CIP is the minimum US requirement to collect and verify core identifying details, such as name, date of birth, address, and an ID number, at onboarding. It is the identity floor beneath fuller due diligence. It confirms who the customer claims to be.

But it does not, on its own, assess risk or beneficial ownership. Treat it as necessary but not sufficient: a passing CIP check says nothing about whether the identity is synthetic or the account is a mule. Someone can clear CIP with real-looking data and still be exactly the person you were trying to keep out. Verification of details is not the same as trust.

Customer lifecycle management

Due diligence & onboarding

This is managing a customer's identity, risk, and due diligence from onboarding through ongoing review, trigger events, and eventual offboarding, keeping the record current across the whole relationship. Risk does not sit still, and neither should the record.

Gaps between stages are where stale risk hides: onboarding data that never reaches monitoring, or reviews that never trigger a re-rating. Make sure material changes, such as new products, ownership shifts, or big changes in behavior, flow back into re-assessment rather than being handled in isolation. A customer who looked low risk at signup can drift into high risk without anyone updating the file unless the process forces it.

Customer risk profile

Due diligence & onboarding

This is the combined view of what makes a customer risky for laundering or terrorist financing: who they are, where they operate, what products they use, and how they transact. It sets how much control and monitoring they get. It should move as the customer changes, not stay frozen at onboarding.

Watch for profiles that never budge even when behavior clearly shifts. A stale profile mis-tunes every downstream control, including the monitoring thresholds that decide which transactions even get looked at. If the profile still says low risk while the activity screams otherwise, your alerts are calibrated for a customer who no longer exists.

Customer risk rating

Due diligence & onboarding

This is the risk tier assigned to a customer, usually low, medium, or high, that decides how much diligence and monitoring they get and how often they are reviewed. The rating methodology drives the entire risk-based model, so opaque or unjustified scoring is a frequent exam finding.

Make sure ratings can be re-triggered by events, not only by periodic cycles, and that any manual override carries a documented, defensible reason. A rating that can only change once a year misses risk that shifts in a week. And an override with no rationale looks to an examiner like someone quietly downgrading a customer to avoid the extra work.

CVV/CVV2

Card & payment fraud

The CVV is the short security code on a card. In online orders it acts as a possession check, offering some proof the buyer actually has the card in hand. A correct code raises confidence the payment is genuine.

But a good code does not prove the buyer is legitimate: it can be phished, captured by keyloggers, or sold bundled in a full identity package (fullz). PCI rules ban storing it after approval. Treat a CVV match as one weighted signal alongside address checks, 3DS, and device data, not an automatic approve. Repeated code failures across cards point to testing or number-guessing.

D

34 términos

Darknet market (DNM)

Crypto & blockchain crime

A darknet market is an illegal online marketplace, usually hosted on Tor and paid in crypto, selling drugs, stolen data, fake documents, malware, and criminal services, often using escrow to hold funds until delivery. These markets are a common source of illicit money entering the crypto system, and exposure to one is a high-severity risk flag.

In wallet screening, links to a known market wallet weigh heavily. Investigators trace deposits to and withdrawals from these wallets and watch for laundering that spikes after a market is seized or pulls an exit scam. Watch for indirect exposure that reaches a market a few hops away.

Data enrichment

Identity verification

Data enrichment adds outside information, like phone, email, address, and device intelligence, to the data a customer submits. A bare application hides risk that enrichment brings into view.

It surfaces things you cannot see on the form: a phone number only days old, a throwaway email domain, or an address never once tied to that name. But quality varies by country and by how fresh the data is. When results are thin or stale, lower your confidence rather than auto-approving or auto-declining on them.

De-listing

Sanctions & screening

De-listing is the removal of a party from a sanctions list once the issuing authority lifts the restrictions, after which dealings and any frozen assets may be allowed again, subject to the terms. Screening data must be updated promptly so a de-listed party stops generating alerts and any freeze is released properly.

The main hazard is stale list data: if the update lags, a de-listed party stays flagged and you keep blocking dealings you are now allowed to process. The flip side is unfreezing too soon, before the change is properly confirmed and documented, so timing and recordkeeping both matter.

Decentralized identifiers (DID)

Identity verification

A decentralized identifier is an ID the user controls directly, proven with cryptography, instead of one handed out and looked up by a central authority. It underpins self-sovereign identity, where a person can prove they own an identifier without a central database.

In practice they usually show up alongside verifiable credentials, and adoption is still early. The real risk areas are key loss, account recovery, and revocation: if the private key is stolen or lost, so is control of the identity, so probe how those cases are handled.

Decision engine

Detection & metrics

This is the system that combines signals, model scores, and rules to make a real-time risk decision and route what happens next. It is the operational heart of decisioning, where your strategy is actually deployed, versioned, and tuned. Its logic, ordering, and speed shape both how much fraud you catch and how much friction customers feel.

Key concerns are explainability, change control, and testing. A single bad rule pushed here can shift losses or approvals instantly across all your traffic, with no warm-up. The trade is agility against safety: you want fast changes, but every change needs review and a clean way to roll back, because the blast radius is your entire volume.

Deduplication

Identity verification

Deduplication finds and merges records or applications that trace back to the same person or business, using shared identifiers and fuzzy matching. It exposes one actor quietly running many accounts.

In fraud terms it reveals bonus and promo abuse, ban evasion, and synthetic clusters that share a phone, device, or address. The tradeoff is tuning: match too loosely and you merge different people who share a common name; match too tightly and a fraudster slips through by tweaking one field.

Deepfake

AI & emerging fraud

This is AI-made fake audio, image, or video used to impersonate a real person. Fraudsters use it to beat selfie or liveness checks, pass video ID checks, or approve a payment over a call. Any control that trusts a face or a voice as proof can now be fooled.

Tells include odd lighting, strange edges, unnatural blinking or lip-sync, and audio with no room noise, though quality is climbing fast. Defenses combine liveness detection, injection-attack detection that spots media fed straight into the camera feed, device checks, and out-of-band confirmation for risky actions. Do not rely on the human eye or ear alone; good fakes now pass both.

Deepfake-as-a-Service

AI & emerging fraud

This is ready-made deepfake creation sold for fraud, by subscription or per job. It removes the need for any technical skill, so more actors produce convincing face swaps and voice clones, aimed straight at onboarding, account takeover, and executive-impersonation payments where a boss is faked to approve a wire.

Because these kits share the same underlying models, the media they make often carries common artifacts, small tells you can learn to catch. Detection leans on liveness and injection-attack checks plus intel on known providers and templates. The catch is that polish does not mean real; a slick fake is often a bought one, not a built one.

Defensive filing

Monitoring & investigations

Defensive filing is filing a SAR mainly to protect the institution from criticism or blame, rather than from a genuine, spellable-out suspicion. It is usually driven by fear that an examiner will second-guess a decision not to file. It quietly damages the whole system.

Too many low-value filings inflate volumes, dilute the intelligence value for FIUs and law enforcement, and can bury the reports that actually matter. Ground every filing in specific facts stated in the narrative. The cure for uncertainty is a well-reasoned analysis and a clear disposition, not filing on reflex to cover yourself.

DeFi exploit

Crypto & blockchain crime

A DeFi exploit is the abuse of weaknesses in decentralized finance protocols, from smart-contract bugs to price and oracle manipulation to governance attacks, to pull out more funds than the system intended. DeFi is open and interconnected, so an exploit can execute in seconds and the stolen funds move instantly.

After the hit, money usually flows straight into mixers, bridges, or swaps to launder it. Response centers on fast on-chain tracing, flagging attacker addresses, and coordinating with venues to freeze cash-out points. One key judgment call is telling a genuine external exploit apart from an insider rug pull dressed up to look like one.

Denied Persons List (DPL)

Sanctions & screening

The Denied Persons List is a US Commerce Department list, from the Bureau of Industry and Security, of people and entities whose export privileges have been revoked, barring them from deals involving items covered by the Export Administration Regulations. It is an export-control list, separate from OFAC's financial sanctions, and it bites hardest in trade, shipping, and dual-use goods.

Because it sits under a different authority, financial-only screening can miss it. Strong programs include it alongside the Entity List and OFAC lists so export and trade-finance activity is checked against the right rules. Never assume OFAC coverage alone is enough for export decisions.

Deny list

Sanctions & screening

A deny list is a maintained set of prohibited parties, addresses, or values that must be blocked or rejected on a match, the counterpart to an allow list. It is usually built from sanctions lists plus internal, risk-based additions. It is the enforcement backbone of screening.

Its coverage, freshness, and match tuning directly decide how well screening works. Pitfalls include stale entries that no longer reflect the current lists, over-broad values that flood analysts with alerts, and, worst of all, gaps where a required list was never loaded, leaving a whole category of prohibited parties unchecked.

This is a group of related reporting firms that some regimes allow to share core AML program pieces, such as policies, customer checks, and reporting arrangements, instead of each building fully separate ones. It cuts duplicated work across the group.

The tradeoff is that shared setups need clear governance over which entity owns each duty. Confirm exactly what is shared versus entity-specific, because a gap in that split can leave one member technically non-compliant while everyone assumes the shared program has it covered. Shared does not mean automatic; someone still has to own each obligation by name.

These are non-financial sectors, such as lawyers, accountants, real estate agents, company service providers, and dealers in precious metals and stones, that FATF pulls under AML/CFT rules because criminals can use them to place or launder money. They are common weak points in the chain.

Coverage and enforcement vary a lot by country, which creates cross-border gaps launderers exploit. For a bank, DNFBPs are often higher-risk customers or introducers, so how mature their own AML controls are becomes a due-diligence factor. A DNFBP that cannot show a real AML program is bringing its risk to you.

Designation

Sanctions & screening

Designation is the formal act of a sanctions authority adding a party to a list, which switches on the related prohibitions, such as asset freezes and dealing bans, from the effective date. It can instantly make an existing customer or counterparty off-limits.

A new designation calls for a fast list update and a rescreen of your current customer and transaction base to catch any newly sanctioned relationships. The risks are lag between the designation and your screening-data refresh, and failing to look back at existing exposure. It is easy to treat designations as forward-only and miss relationships you already have.

Device binding

Device & behavioral

Device binding ties an account or credential to a specific trusted device, so use from an unrecognized device triggers a step-up or a denial. It shrinks the value of stolen passwords and codes: the attacker also needs the enrolled device.

The critical control is the binding and re-binding flow itself. Fraudsters go straight for the device-change and recovery paths to enroll their own device during a takeover, so scrutinize those flows closely.

Device fingerprinting

Device & behavioral

Device fingerprinting identifies a device from a mix of hardware, software, and network attributes, so you can recognize it across sessions and attach a risk history. It links accounts run by one actor, catches returning fraudsters, and flags spoofed or inconsistent setups.

Fingerprints degrade as users update their devices, and anti-detect browsers, spoofing tools, and emulators deliberately scramble attributes. So weight it alongside behavioral and network signals rather than trusting it as a stable unique ID.

Device ID

Device & behavioral

A device ID is a lasting identifier assigned to a device so you can recognize it across sessions and tie activity back to one piece of hardware. It underpins duplicate-account detection, velocity checks, and device reputation.

Stability varies, though: app reinstalls, factory resets, and privacy controls can rotate it, while spoofing tools forge or reset it on purpose. Treat a shared device ID as a strong link and a freshly reset one as a possible evasion signal, not proof either way.

Device intelligence

Device & behavioral

Device intelligence is risk signals built from a device's attributes, history, and reputation, folding fingerprint, integrity checks, and past fraud links into one risk view. It exposes emulators, rooted or jailbroken devices, tampered app environments, and devices tied to known abuse.

Coverage and freshness matter, and determined fraudsters spoof attributes to hide. So blend device intelligence with behavioral, network, and identity signals rather than trusting it on its own.

Device reputation

Device & behavioral

Device reputation is a risk rating for a device based on its past links to fraud, abuse, or good behavior across accounts and time. A device tied to old chargebacks, takeovers, or multi-account farming carries that risk forward even under a fresh identity.

But reputation can be shed by resetting or spoofing the device, and it can be unfairly inherited by second-hand or shared hardware. Weigh it with current-session signals rather than treating it as permanent guilt.

Digital identity

Identity verification

A digital identity is a verified electronic version of a person or business that can be asserted and reused across services, bundling their attributes, credentials, and verification history. It is exactly what fraudsters try to fake or steal.

They either build a fake one from scratch (synthetic identity) or hijack a real one (account takeover). Its strength depends entirely on how well the underlying attributes were checked at the start. Treat any reused identity with care: it is only as trustworthy as its weakest setup step and how well it resists takeover.

Digital identity wallet

Identity verification

A digital identity wallet is an app the user holds that stores verifiable credentials and shares proofs on demand, so they present a confirmed attribute instead of raw documents. Its promise is cutting repeat KYC and reducing how much personal data gets exposed.

The catch is that a slick wallet screen proves nothing on its own. You still have to check that the issuer is trusted, the credential is current, and it has not been revoked. Beware cloned or coerced wallets: holding a credential is not proof the person presenting it is its rightful owner without a liveness or holder check.

Dirty money

Money laundering

Dirty money is the proceeds of crime before any laundering, still directly traceable to the underlying offense, which makes it the riskiest stage to hold or move.

It is the input that placement, layering, and integration try to disguise, and it usually shows as unexplained cash, funds with no legitimate source, or value tied to a known crime. It relates to proceeds of crime and the predicate offense. Bear in mind, proving the illicit origin, the source of funds, is what separates dirty money from activity that is merely unusual but lawful.

Disposition

Monitoring & investigations

Disposition is the final recorded outcome on an alert or case, such as closed with no action, escalated, or referred for a SAR, together with the reasoning that supports it. This is the exact decision QA and examiners sample to judge whether your program reaches sound, consistent conclusions.

Make sure every flagged element is addressed and the reason is specific to the facts, not a template. A common quality-assurance focus is whether analysts reach the same call on similar activity; wide inconsistency across a team signals weak procedures or training. Strong dispositions are what make a program defensible.

Dispute

Card & payment fraud

A dispute is when a cardholder formally challenges a transaction with their bank. It may settle quietly or grow into a chargeback. For fraud teams, how you handle disputes drives both fraud losses and how much money you can win back.

Teams separate genuine fraud disputes from first-party abuse (friendly fraud) and plain service complaints, because the evidence and win rates differ a lot. Solid order, delivery, device, and past-purchase records support contesting a dispute. A jump in disputes on certain products, regions, or acquirers is an early warning of fraud or a customer-experience problem.

Division

Device & behavioral

Division is splitting a payment or amount into smaller pieces to stay under reporting or approval limits, a tactic close to structuring. It is a deliberate way to dodge the review thresholds that are supposed to catch large or suspicious movements.

It shows up as clusters of just-below-threshold transactions, rapid sequences across accounts or cards, or amounts engineered to slip past review. Detection needs velocity and aggregation across the whole relationship and network, since each piece looks harmless by design when judged alone.

Document authentication

Identity verification

Document authentication decides whether an ID is genuine and unaltered by inspecting security features, fonts, microprint, the machine-readable strip, and signs of tampering or full fakery. A forged or edited document is a foundation many other frauds are built on.

It is a different question from whether the ID belongs to the person holding it: a real, authentic ID can still be stolen. The recurring attacks are template counterfeits, digitally edited fields, and photos of a screen, so combine it with face match, liveness, and chip or strip cross-checks.

Document deepfake

AI & emerging fraud

This is a fake or altered ID document built to pass verification, from small edits on real fields to a whole ID rendered from a template. It shows up in onboarding and step-up checks and can beat basic scan-the-text and match-the-photo tools. It is a top driver of synthetic-identity and first-party fraud.

Detect it with document forensics, metadata and template analysis, and cross-checks against the issuing source or consortium data showing the same doc used elsewhere. Remember that a clean, sharp image is not proof of a real document. Fakes are made to look good on screen, so judge the underlying signals, not just how the picture looks.

Document verification

Identity verification

Document verification confirms an ID is valid, unexpired, and consistent, and that it matches the person presenting it, usually by pairing document authentication with a face match. This ties a real document to a real, present human.

Common failures in casework are a selfie that does not match the ID photo, expired or edited documents, and the same document image reused across many accounts. Cross-check the extracted data against the application and other sources: a document passing on its own does not prove the person is who they claim to be.

Domestic PEP

Due diligence & onboarding

A domestic PEP is someone holding a prominent public role inside the firm's own country, plus their relatives and close associates. While many regimes allow a more nuanced, risk-based treatment than for foreign PEPs, domestic ones still carry raised corruption risk.

So they generally still warrant enhanced scrutiny. The common pitfall is under-screening local officials on the assumption that home-country equals lower risk, when local corruption exposure can be substantial. Treating your own country as automatically safe is exactly how home-grown corruption slips past. Base the treatment on assessed risk, not on the comfort of familiarity.

Dormant account abuse

Account & access fraud

Dormant account abuse is exploiting accounts that have sat unused for a long time, because the real owner has stopped checking statements and alerts. Nobody is watching, which gives fraud a long head start before anyone notices.

These accounts are prime targets for takeover and for use as money mules or pass-through channels. The main red flag is reactivation itself. Detect it by learning each account's normal baseline and alerting when a quiet account suddenly wakes up, especially with a new device, changed login details, or unusual money movement. One catch: treating any reactivation as fine without a second look.

Dump

Card & payment fraud

A dump is stolen magnetic-stripe data, taken through skimming or breaches, sold in criminal markets to be encoded onto fake cards. It is the raw material for in-person cloning fraud.

Listings are often priced and sorted by card range (BIN), issuer, region, and how fresh the data is. A surge of fraud sharing one common point of purchase can mean a breach is feeding dumps. It is related to track data and cloning, and to fullz, which by contrast bundle a full stolen identity rather than just the card stripe.

Duplicate account detection

Identity verification

Duplicate account detection finds multiple accounts run by one party. That is a classic sign of promo and bonus abuse, ban evasion, mule networks, or synthetic clusters.

It leans on shared device fingerprints, IPs, payment cards, addresses, and behavior rather than name alone, since fraudsters change the obvious fields. The pitfall is enforcement: separate real abuse from legitimate cases like a shared household or someone with both a personal and a business account before you shut anything down.

Dusting attack

Crypto & blockchain crime

A dusting attack is sending tiny, unsolicited amounts of crypto to many wallets, so that when the dust is later spent alongside other funds, the sender can use clustering to link addresses and unmask or profile the owners. It can chip away at the privacy that protects legitimate users.

It often sets up targeted phishing, extortion, or surveillance, and its mechanics overlap with address poisoning. The best defense is simple: leave dust unspent or mark it do-not-spend so it never mixes with your real funds. The trap is spending it by accident and handing the attacker the link they wanted.

E

22 términos

Economic sanctions

Sanctions & screening

Economic sanctions are restrictions on financial, trade, and economic dealings imposed by governments or international bodies to advance foreign-policy or national-security goals, ranging from targeted measures against specific parties to broad country programs. They define what a compliance program must screen for and block.

They vary by issuing jurisdiction, so a party can be sanctioned by one authority and not another. Programs must track the specific regimes that apply to them and reconcile overlapping or conflicting requirements across jurisdictions. Assuming one country's list covers you everywhere is the error; the same party may be clear in one regime and prohibited in another.

Egmont Group

Regulation & bodies

The Egmont Group is the global network of financial intelligence units. It lets FIUs exchange financial intelligence across borders securely through a protected channel, and it sets standards for how FIUs operate and cooperate. It is the plumbing that lets one country's suspicious-activity intelligence reach another's investigators.

Operators do not deal with Egmont directly, but it affects you: a SAR or STR you file at home can, through Egmont channels, support an investigation abroad. An FIU's Egmont membership also signals how capable it is of sharing intelligence internationally, which quietly feeds into how much weight cross-border cooperation carries for that jurisdiction.

EIN verification

Business verification

EIN verification checks a US Employer Identification Number against IRS and business-registry data to confirm it exists and matches the legal business name. A fabricated or borrowed EIN is a staple of business-loan, merchant-onboarding, and BNPL fraud.

Mismatches between the EIN, the legal name, and the formation records are a warning sign. But a valid EIN only proves the business is registered, not that it actually operates, so pair it with footprint and ownership checks.

eKYC

Identity verification

eKYC is fully digital, remote KYC that swaps in-person checks for document capture, biometric liveness and face match, and data-source checks. It lets you onboard customers anywhere without a branch visit.

But it concentrates the risk at the capture step, where injection attacks, deepfakes, and coached applicants all aim. Strong eKYC layers document, biometric, device, and data signals and cross-checks them against each other, because any single channel can be spoofed on its own.

Elder fraud

Scams & social engineering

Elder fraud is scams that deliberately target older adults, exploiting trust, isolation, cognitive decline, or unfamiliarity with digital tools. Losses are often huge, drawn from retirement savings or home equity.

Common forms include grandparent, tech-support, romance, and government-impersonation scams. Operationally, watch for out-of-pattern large withdrawals or transfers, new payees, a third party on the call, and signs the customer is being coached. Many places allow protective holds on suspicious payments and require reporting suspected elder abuse.

Electronic identity verification checks a person by matching submitted data, like name, birth date, address, and national ID, against authoritative electronic sources, instead of inspecting documents. Its appeal is that it scales cheaply for low and medium risk.

Its weakness is data coverage: records are thin for young adults, recent immigrants, and many markets outside the US. A pass confirms the identity exists and the data lines up; it does not prove the applicant is that person. For higher risk, add a document or biometric check.

Embargo

Sanctions & screening

An embargo is a broad prohibition on trade and financial dealings with an entire country or region, unlike measures that target named parties, effectively barring most or all transactions that touch the jurisdiction. It forces country- and geography-based controls, not just name checks.

That means screening addresses, IPs, routing, and counterparties tied to the sanctioned territory. Common evasion uses transshipment, front companies, and misrepresented origin or destination, so operators pair party screening with geographic and trade-flow analysis. The weakness is name-only screening, which misses funds and goods routed to dodge the geography while the parties themselves look clean.

Emergency scam

Scams & social engineering

An emergency scam invents an urgent crisis, often pretending to be a relative in trouble, to pressure the victim into paying right away before they can check. The manufactured panic is designed to bypass calm, rational thinking.

It overlaps with grandparent scams and increasingly uses AI voice cloning to imitate a loved one. Countermeasures include agreed family verification phrases, cooling-off prompts on urgent transfers, and staff trained to spot payments driven by distress. Slowing the victim down is the single most effective defense.

Employment scam

Scams & social engineering

An employment scam is a fake job offer used to extract money, through bogus training fees, equipment charges, or overpayment tricks, or to steal personal data, or to recruit the victim as a money mule. Worst of all, mule recruitment turns the victim into a laundering channel.

Signs include unsolicited offers, being asked to pay to work, and requests to receive and forward funds through your own account. It overlaps with task scams and mule networks. Any job that asks you to move money for the company should be treated as a red flag.

Emulator detection

Device & behavioral

Emulator detection identifies virtual or emulated devices that fraudsters use to fake environments, script actions, and scale attacks cheaply across many fake devices. An emulator in a normal consumer mobile flow is itself a strong risk signal.

It is common in bonus abuse, account farming, and automated fraud. Detection reads inconsistencies in hardware, sensors, and runtime, while attackers work to mask them, so pair it with behavioral and velocity signals and expect constant evasion.

EMV

Card & payment fraud

EMV is the global chip-card standard. For in-person payments it creates a unique one-time code for each transaction, which makes copied card data far harder to reuse. It slashed counterfeit fraud wherever chips are used.

EMV also shifted liability to whichever party is least chip-compliant, and it pushed fraud toward online (card-not-present) channels instead. Watch for magstripe fallback abuse and non-chip corridors as leftover risk. Think of EMV alongside the liability shift, tokenization, and the post-chip rise in online card fraud it helped cause.

Enhanced Due Diligence (EDD)

Due diligence & onboarding

EDD is heightened diligence and closer ongoing monitoring for higher-risk customers, relationships, or transactions, such as PEPs, high-risk jurisdictions, and complex ownership structures. Standard checks are not enough when the risk is elevated.

It usually means deeper source-of-funds and source-of-wealth inquiry, senior sign-off, and tighter monitoring thresholds. The recurring failure is EDD that is triggered on paper but shallow in practice: collecting documents without genuinely testing whether the money and activity make sense for that customer. A folder full of statements is not diligence if nobody asked whether the story they tell actually holds together. The scrutiny is the point, not the paperwork.

An EWRA is a firm-wide laundering and terrorist-financing risk assessment that pulls together and reconciles risk across every business line, legal entity, and jurisdiction into one group view. It sits above the individual product or unit assessments. It drives group risk appetite and where resources go.

For the roll-up to mean anything, units must score risk the same way; inconsistent scales make the group picture misleading. Common pitfalls are double-counting the same risk, mismatched scoring between units, and an EWRA refreshed so rarely it misses new acquisitions or products. A group view built on apples and oranges is worse than none, because it looks authoritative.

Entity List

Sanctions & screening

The Entity List is a US Commerce Department list, from the Bureau of Industry and Security, that restricts exports, reexports, and transfers to named foreign parties seen as national-security or foreign-policy concerns, with license requirements that vary by entity. It is an export-control tool separate from OFAC financial sanctions.

So a party can be on it without being blocked for payments. Trade and export compliance must screen against it specifically and apply each entity's particular license policy rather than a single blanket rule. Treating it like a financial block list backfires, either over-restricting payments or missing the specific export license each listing demands.

Entity resolution

Identity verification

Entity resolution links scattered records across systems back to one real person or business. It defeats deliberate fragmentation and exposes synthetic identities stitched together from mismatched pieces.

It powers investigations and network views by clustering shared phones, addresses, devices, and ownership links. The core tension is precision versus recall: merge too aggressively and you blur distinct people together; merge too little and a fraud ring hides behind tiny data variations.

Enumeration attack

Card & payment fraud

An enumeration attack is automated guessing of card details, the number, expiry, and security code, to find valid combinations, often starting from a known card range (BIN). That makes it a way for criminals to manufacture working cards out of partial data.

It looks like high-volume authorization or verification attempts with numbers in sequence, lots of declines, and concentration by BIN, IP, or device. Card networks now flag and fine merchants with too much of this traffic. Slow it with rate limits, CAPTCHA, device checks, and velocity rules. It is closely tied to BIN attacks and card testing.

Escalation

Monitoring & investigations

Escalation is moving an alert or case up to a higher level of review, to enhanced due diligence, or to a SAR decision when the risk is more than a first-line analyst can resolve alone. Clear, timely escalation is what stops risky activity from stalling in a queue.

Delayed escalation is a frequent cause of late SAR filings, which draw penalties. Document why an item was or was not escalated. If analysts use different bars for when to escalate, that inconsistency points to a training or procedure gap, and it means similar cases get treated very differently.

EU AML Authority (AMLA)

Regulation & bodies

The EU AML Authority, based in Frankfurt, is a new body created to centralize and strengthen AML/CFT supervision across the EU. It can directly supervise certain high-risk cross-border institutions and coordinate national supervisors, and it supports consistent application of the EU AML rulebook. It reduces the patchwork of uneven supervision that existed across member states.

If your firm operates in the EU, expect more harmonized oversight, and for the highest-risk institutions, more direct EU-level supervision instead of purely national regulators. Note this is the EU authority, not to be confused with the US AMLA law; both abbreviate the same way, which trips people up.

These are successive EU directives setting AML/CFT duties that member states must write into their own national laws. Each round tightened the rules, on beneficial ownership, risk assessment, and virtual assets, and 6AMLD harmonized predicate offenses and criminal liability. Being directives, each country implemented them a bit differently, so obligations historically varied across the EU.

For operators, that divergence is the practical headache: the same directive could look different country to country. The newer, directly applicable AML Regulation is designed to shrink that gap, but the directives still matter for understanding each member state's existing framework and why national rules differ from one another.

EU AML Regulation (AMLR)

Regulation & bodies

The AMLR is the directly applicable EU regulation that creates a single, harmonized AML rulebook across every member state. It standardizes customer due diligence, beneficial ownership, and other duties without the transposition gaps that directives allowed. As a regulation, it applies uniformly and directly, rather than being filtered through each country's national law.

For a firm operating across several EU countries, this brings welcome consistency, but you must align your policies to the common standard rather than to any one national regime. Read it alongside the new EU-level AMLA supervisory structure, since the single rulebook and the central supervisor are designed to work together.

EU Consolidated List

Sanctions & screening

The EU Consolidated List is the European Union's single list of persons, entities, and bodies subject to EU financial sanctions, pulling designations from across EU regimes into one place for screening. It applies to EU persons and activity and can differ in scope and named parties from US, UN, or UK lists.

Programs operating in or through the EU screen against it alongside other regimes and must reconcile the differences. It is a mistake to assume lists are equivalent across jurisdictions: a party listed in the US may not appear here, and one listed here may be absent elsewhere, so relying on a single list leaves gaps.

Exit scam

Crypto & blockchain crime

An exit scam is when the operators of an exchange, project, protocol, or darknet market suddenly shut down and run off with user funds, usually after spending time building trust. Victims often have no warning and little recourse once the money is gone.

Warning signs include withdrawal delays or freezes, sudden moves of liquidity to fresh wallets, and unexplained downtime, though the theft is usually only confirmed after funds vanish. It overlaps with rug pulls in DeFi and drives a wave of laundering right afterward. The cruel part is that trust built over time is exactly what makes the final grab work.

F

51 términos

Face match

Identity verification

Face match compares a selfie to the photo on an ID and returns a similarity score against a threshold, to confirm the same person is present. It is a core defense against impostors using someone else's document.

But it only means something with liveness attached, since a fraudster can match a face using a photo, a mask, or a deepfake. Watch for morphing attacks that blend two faces so one ID passes for both people, and set your threshold against how much false accept and false reject you can tolerate.

Face swap

AI & emerging fraud

This is swapping one face for another in an image or video to beat face-match or impersonate a specific person during a check. It shows up in selfie checks, video ID checks, and account-recovery flows. It is increasingly injected straight into the camera feed rather than held up to the lens, which fools tools that assume a real camera.

Countermeasures include liveness detection, injection-attack detection, and consistency checks across the face, the document, and the device. Passive liveness alone, the kind that just studies a still selfie, can be spoofed, so pair it with active prompts and feed-integrity checks.

Facial recognition

Identity verification

Facial recognition matches a face against a reference image or searches it across a gallery, used for one-to-one verification or one-to-many search like spotting a repeat fraudster. It can both confirm identity and surface known bad actors.

Accuracy shifts with image quality, pose, lighting, and demographic factors, which can push error rates unevenly across groups. Treat scores as probabilities, govern data retention and consent carefully, and always pair it with liveness: a high match is strong evidence, not certainty, and is spoofable without a liveness check.

Factoring

Card & payment fraud

Factoring is running one merchant's transactions through a different merchant's account to hide where the sales really come from, a form of transaction laundering. It lets a banned, high-risk, or undisclosed business hide behind a clean-looking account and slip past underwriting and monitoring.

Tells include a payment description that does not match the goods sold, transaction sizes or locations that do not fit the stated business, and sudden volume spikes. It is closely related to transaction laundering and hiding a merchant's true identity, and it is both a fraud and a compliance concern.

False negative

Sanctions & screening

A false negative is a true match that screening fails to surface, letting a sanctioned or prohibited party slip through undetected. It is the most serious screening failure: it can mean a prohibited transaction actually went through.

Causes include matching thresholds set too strict, missing name variants or aliases, stale list data, and input data that is truncated or not normalized. Programs guard against it with fuzzy, phonetic, and transliteration matching, careful threshold calibration, data-quality controls, and testing against known-positive samples. Tuning thresholds so tight to cut false positives that you quietly start missing real hits is the classic failure.

False negative rate

Detection & metrics

This is the share of real fraud, or real matches, your system fails to catch, in other words the fraud that slips through as approved. It is the direct measure of missed fraud and ties straight to your loss rate.

It is harder to see than false positives, because misses surface late through chargebacks and reports rather than at decision time. It trades off against the false-positive rate: loosen controls to cut friction and you catch less fraud; tighten up and you annoy more good customers. So the two are tuned together against a set loss appetite. A low number is only trustworthy once the cohort has matured and the late misses have shown up.

False positive

Sanctions & screening

A false positive is a legitimate party wrongly flagged as a possible match to a list entry. It is the biggest source of alert volume in screening and the main day-to-day operational cost, tying up analysts on clears.

It is common with common names, weak aliases, and loose fuzzy-matching thresholds. Teams manage it with better matching logic, secondary identifiers like date of birth or address to disambiguate, and governed allow-listing of cleared matches. The balancing act: do not cut thresholds so aggressively that you create false negatives instead. The two errors must be balanced on purpose, not by accident.

False positive rate

Detection & metrics

This is the share of legitimate cases your system wrongly flags. It is the main driver of review cost, customer friction, and abandonment, when a good customer gives up and leaves. A flag can be technically correct yet useless if it burns dozens of good customers to catch one fraudster.

So operators watch the ratio of false positives to true catches, not just the raw count. Cutting it usually means accepting more missed fraud, so you tune it against your loss appetite. The better fix is not blunt threshold changes but stronger features and segmentation, so you separate risky from safe more cleanly instead of just flagging less across the board.

FAR is the False Acceptance Rate, how often the wrong person is accepted; FRR is the False Rejection Rate, how often the right person is rejected. The two move in opposite directions as you set a threshold, and that tradeoff is yours to own.

Loosen it to reduce friction and you let more impostors through; tighten it to block fraud and you turn away more genuine customers. Pick the operating point by the value at risk and the friction you can absorb, and monitor error rates across demographics to catch skew that harms specific groups.

Faster payments fraud

Card & payment fraud

Faster payments fraud exploits instant or near-instant payment systems, where money clears in seconds and is very hard to recall once sent. That speed collapses the time you have to spot, hold, or reverse a bad payment.

With almost no window after the fact, controls move to before the payment: behavior scoring, checking the risk of the payee, and spotting mule accounts. It overlaps heavily with authorized push payment scams and mule cash-out. Watch for new payees, odd urgency, and money that gets moved onward fast after it arrives.

FATCA

Regulation & bodies

FATCA is the US Foreign Account Tax Compliance Act. It requires foreign financial institutions to identify and report accounts held by US persons, or face withholding on certain US-source payments. Although it is a tax-transparency law and not an AML law, it drives customer identification and documentation that overlaps heavily with KYC.

Recognize that FATCA classification and reporting sit alongside your AML customer due diligence, using much of the same information. Gaps in one often reveal weaknesses in the other, so weak FATCA data can be an early warning that your KYC is thin too. Treat them as related identity-data duties, not fully separate silos.

FATF 40 Recommendations

Regulation & bodies

The FATF 40 Recommendations are the global baseline standards for AML, counter-terrorist-financing, and counter-proliferation, covering customer due diligence, beneficial ownership, reporting, supervision, and international cooperation. They are not law themselves but are put into effect through national regimes and checked in mutual evaluations. Nearly every country's rules trace back to them.

For operators, a country's rating against these Recommendations shapes its jurisdiction risk and the expectations placed on correspondent relationships with it. When you see a national rule, it usually maps back to one of these; knowing them helps you understand why local requirements look the way they do and where a weak jurisdiction is likely exposed.

FATF black list

Regulation & bodies

The FATF black list names high-risk jurisdictions subject to a call for action: countries with serious, strategic AML/CFT deficiencies where FATF urges countermeasures or enhanced due diligence. Being listed carries heavy correspondent-banking and reputational consequences, and it directly raises the risk of anything connected to that country.

Treat customers and transactions tied to these jurisdictions as high risk, and apply enhanced due diligence or the required countermeasures. Monitor the list, which FATF updates periodically, for additions and removals, since a change flips a country's risk level overnight. This is the most severe of FATF's jurisdiction lists, a step above the grey list.

FATF grey list

Regulation & bodies

The FATF grey list names jurisdictions under increased monitoring that have committed to fixing identified AML/CFT weaknesses within agreed timeframes. It sits one step below the black list but is still a strong signal to raise your scrutiny. Grey-list status is a clear, official flag that a country's controls are not yet where they should be.

Factor grey-list status into your country risk models and into enhanced due diligence for exposed customers and correspondents. Track the periodic updates closely, because additions and removals directly change risk ratings and the level of diligence expected. A country coming off the list should ease your treatment; one going on should tighten it.

An FSRB is a regional organization, such as APG or MONEYVAL, that promotes and assesses how well its members implement FATF standards within a geographic area, running mutual evaluations of those members. FSRBs extend FATF's reach into regions and produce region-specific typologies and follow-up reports that FATF alone could not cover.

Use FSRB evaluations and typology reports to sharpen your country risk assessments and enhanced due diligence for customers and correspondents in a given region, especially where a jurisdiction has been flagged for deficiencies. Think of them as FATF's regional arms: same standards, closer local knowledge of how money actually moves there.

FDIC

Regulation & bodies

The FDIC is the US Federal Deposit Insurance Corporation. It insures bank deposits and acts as the primary federal supervisor for many state-chartered banks that are not members of the Federal Reserve. In that supervisory role, it examines those banks for BSA/AML compliance.

If you are at an FDIC-supervised bank, expect BSA/AML exams run using the shared FFIEC standards, the same playbook other federal banking agencies use. Watch FDIC enforcement actions and guidance, since they signal the supervisory expectations for the institutions it oversees. Knowing your primary regulator tells you whose exam manual and enforcement patterns to study first.

Feature

Detection & metrics

This is an input variable built from raw data and fed to a model or rule, for example transaction speed, how old a device is, or how well a name matches an account. Feature quality and freshness drive detection performance more than the choice of algorithm, so most real modeling work is feature engineering, not picking a fancier model.

The pitfalls are leakage, where a feature secretly encodes the answer and looks great in testing but fails live; features that drift or go stale; and training-versus-production mismatch. If a feature is computed one way in training and another way at serving time, the model quietly gets worse with no obvious alarm, so watch that parity closely.

Federal Reserve

Regulation & bodies

The Federal Reserve is the US central bank and a federal banking supervisor. Alongside running monetary policy, it oversees bank holding companies, state member banks, and the US operations of many foreign banks. It examines those institutions for BSA/AML compliance using the shared FFIEC standards.

If you are at a Fed-supervised entity, track its enforcement actions and guidance. Together with the OCC and FDIC, the Fed sets the tone for US banking-sector AML expectations, so its actions ripple across the industry even for firms it does not directly supervise. Knowing which of the three supervises you tells you whose signals to weight most.

Fei ch'ien

High-risk payments

Fei ch'ien, literally flying money, is a Chinese informal system that settles cross-border debts through trusted brokers without physically moving cash. It has long served trade and diaspora communities, and the risk is that value can move while leaving almost no records.

Brokers offset what they owe each other on private ledgers, so at each end the money looks like it came from inside the country. Watch for structured cash funding and settlement routes tied to Chinese trade. It is like hawala; honest use is common, so risk depends on the broker's controls and the real source of funds.

FFIEC

Regulation & bodies

The FFIEC is the Federal Financial Institutions Examination Council, the interagency US body that sets uniform principles and standards for examining financial institutions, most famously the BSA/AML Examination Manual. It aligns how the federal banking agencies actually conduct AML exams, so different regulators test to a common standard.

Treat FFIEC standards as the practical rulebook examiners apply on the ground. Use its manual to anticipate what they will test in monitoring, customer due diligence, and reporting, and to self-check before they arrive. It is not a single regulator you report to; it is the shared standard-setter behind the exam you will eventually face.

This manual is the standard reference US examiners use to assess BSA/AML programs. It lays out expectations and testing procedures across risk assessment, customer due diligence, monitoring, reporting, and program governance. It is effectively the playbook exams follow, which means it doubles as a ready-made self-assessment and audit checklist for you.

Map your program controls to the manual's procedures so you can anticipate exactly what an exam will focus on and fix gaps first. Remember it reflects supervisory expectations rather than being law itself, and it is updated periodically, so work from the current version rather than an older copy you happen to have on file.

FATF is the intergovernmental standard-setter for AML, counter-terrorist-financing, and counter-proliferation. It issues the 40 Recommendations, runs and coordinates mutual evaluations, and maintains the black and grey lists of high-risk and monitored jurisdictions. It shapes national laws worldwide even though it does not directly regulate any institution.

For operators, FATF standards drive your local rules, and its jurisdiction listings and typology reports feed straight into country risk models, enhanced due diligence triggers, and correspondent-banking decisions. When a country is greylisted or a new typology is published, expect it to flow through to your risk ratings. FATF sets the direction the whole system follows.

The FCA is the UK conduct regulator for financial firms and markets. It supervises AML compliance for the firms it authorizes, sets conduct expectations, and enforces failures with fines and restrictions. For UK-regulated firms, it is a primary source of both the standards you must meet and the penalties for missing them.

Track FCA enforcement actions, thematic reviews, and guidance closely; these reveal current supervisory priorities and the expected standard for financial-crime systems and controls. It works alongside other UK bodies in the wider AML framework, so its signals tell you where UK attention is focused right now and what your controls will be judged against.

An FIU is the national agency that receives, analyzes, and passes on suspicious-activity and threshold reports such as SARs and STRs. It is the hub connecting institutions to law enforcement and, through the Egmont Group, to foreign FIUs. In the US, the FIU is FinCEN. The FIU is the destination and the quality bar for everything you file.

For operators, the FIU's feedback, priorities, and typology publications shape what you should report and how. Filing is not just a box to tick; it feeds a real intelligence pipeline. Understanding what your FIU values helps you write filings that are actually useful rather than merely compliant.

FinCEN

Regulation & bodies

FinCEN is the Financial Crimes Enforcement Network, the US Treasury bureau that serves as the national FIU. It administers the Bank Secrecy Act, issues regulations and advisories, and runs mechanisms like 314(a), 314(b), GTOs, and BOI reporting. It receives SARs and CTRs and sets national AML priorities. It sits at the center of nearly everything a US AML program does.

Operators interact with FinCEN constantly, through filings and information requests. Treat its advisories and priority statements as direct signals of current reporting expectations and emerging typologies; when FinCEN publishes an advisory on a scheme, expect it to become an exam and filing focus soon after.

Fingerprint recognition

Device & behavioral

Fingerprint recognition is biometric verification using fingerprint patterns, usually via an on-device sensor for quick repeat logins. It resists password theft and is low-friction for real users.

It can be beaten by lifted-print spoofs, but the bigger fraud risk is an attacker enrolling their own fingerprint during an account takeover. Focus controls on the enrollment and recovery flow and on device binding, since the sensor match itself is rarely the weak point in real casework.

FINRA

Regulation & bodies

FINRA is the Financial Industry Regulatory Authority, the US self-regulatory organization overseeing broker-dealers. It sets and enforces AML program rules for its member firms and examines them for compliance, operating under SEC oversight. For broker-dealers, FINRA is the body writing and testing the specific AML rules you live by.

Note its rule requiring a written AML program and independent testing. Track its enforcement actions and exam priorities, which spotlight recurring securities-sector problems such as suspicious trading and microcap fraud. Because it is a self-regulatory organization backed by the SEC, its expectations carry real teeth even though it is not a government agency itself.

FINTRAC

Regulation & bodies

FINTRAC is the Financial Transactions and Reports Analysis Centre of Canada, the country's AML regulator and financial intelligence unit. It receives suspicious-transaction and threshold reports, supervises reporting entities, and shares intelligence with law enforcement and foreign FIUs. It is both the body that sets reporting expectations in Canada and the one that enforces them.

If your business touches Canada, you must meet FINTRAC registration and reporting obligations. Watch its guidance and penalties, which point to current Canadian supervisory priorities. As with other national FIUs, understanding what FINTRAC expects, and where it has recently penalized firms, tells you which parts of your Canadian program to shore up first.

This is the customer-facing and business staff, including sales, relationship managers, and operations, who own and manage financial-crime risk right where customers and transactions happen. They run initial customer checks, spot red flags, and raise the first escalations, making them the earliest detection layer. They see problems before any system does.

The constant tension is commercial incentives pulling against risk decisions; the people paid to win business are also asked to slow it down. Supervisors increasingly expect the first line to be accountable for risk itself, not just leaning on second-line oversight to catch what they miss. Ownership has to sit where the activity is.

First-party chargeback

Card & payment fraud

A first-party chargeback is a dispute filed by the real cardholder, not a third-party fraudster. It can be honest confusion (an unrecognized descriptor or forgotten subscription) or deliberate abuse (keeping the goods and disputing anyway). It is hard to catch: the login, device, and authentication all look legitimate.

Also called friendly fraud, you fight it with clear billing descriptors, delivery and usage evidence to contest the dispute, and tracking repeat disputers. Keep it separate from true unauthorized-use fraud when you code the reason and decide remediation, since the fix is different.

This is when a person uses their own real, or lightly tweaked, identity to get credit, goods, or services with no plan to pay. It includes bust-out, deposit fraud, and chargeback abuse. Because the identity is genuine, it hides inside your good-customer base.

Since KYC and identity checks pass, detection leans on behavioral, affordability, and account-lifecycle signals, like maxing a credit line fast right before default. It is badly under-reported and often booked as credit loss instead of fraud. Telling it apart from third-party fraud, where a real victim exists, is a constant operational headache.

Flash loan attack

Crypto & blockchain crime

A flash loan attack borrows a huge, uncollateralized sum inside a single transaction, uses it to manipulate prices, oracles, or protocol state, and repays it in the same block, all with almost no money down. It lets an attacker move markets and drain protocols with borrowed funds they never truly held.

Atomic transactions make it possible: if any step fails, the whole thing reverts. Detection focuses on same-block borrow-manipulate-repay patterns and sharp, unnatural price or liquidity swings. Response prioritizes tracing and freezing the extracted funds downstream, since the attack itself is over the instant the block confirms.

Foreign PEP

Due diligence & onboarding

A foreign PEP is someone holding a prominent public role in another country, generally treated as higher risk and requiring enhanced due diligence, including senior approval and source-of-wealth verification, under most regimes. The core concern is moving the proceeds of foreign corruption across borders.

Screen their relatives and close associates too, not just the official, because illicit money is often routed through connected parties rather than the PEP directly. Focusing only on the named person misses the more common route the money actually takes. The people around the PEP are frequently where the funds land, so the screening net has to be wide enough to catch them.

Foreign terrorist fighter

Terror & proliferation

A foreign terrorist fighter is someone who travels to a conflict zone to join or support a terrorist group. For financial institutions, that journey creates financing, travel, and material-support activity that can pass through accounts, giving you a chance to spot it.

Related indicators include one-way travel to high-risk corridors, small cross-border transfers, purchases of tactical gear, and account activity that suddenly stops around travel dates. Tie travel and spending patterns to sanctions and watchlist data, and consider TF-focused SARs. Single indicators are weak on their own, so corroboration and context are what turn a hunch into something reportable.

FRAML

AML programs

FRAML is an operating model that joins fraud and AML functions, data, and controls so financial crime is handled as one problem instead of in silos. It reflects that the same events, such as scams, mule accounts, and account takeover, feed both teams. Splitting them creates blind spots between the two.

Upside is shared signals, unified alerting, and fewer gaps. One snag: fraud and AML answer to different regulatory drivers, data rules, and metrics, so merging them is not free. Watch that a combined team still keeps its distinct SAR duties and fraud-loss duties separate rather than blurring them into one. Integrate the work, not the obligations.

This is a synthetic identity stitched from pieces of several real and fake people, for example one person's SSN, another's name, and a made-up birth date, built to pass checks that only look at one field at a time. It creates a persona with no single real victim to raise the alarm.

It is a specific build pattern inside synthetic identity fraud, usually grown slowly to build credit before a coordinated bust-out. Detect it by checking whether records are consistent with each other, linking shared PII across applicants, and tracking how often identity pieces get reused. Single-source bureau checks alone will miss it.

Fraud

Fraud types

This is intentional deception used to gain money or something of value unlawfully, or to cause someone a loss. It is the umbrella over every specific type, from account takeover to synthetic identity. It is the core risk your controls exist to manage.

Teams run it as a lifecycle: prevention, real-time detection, investigation, recovery, and reporting, all balanced against customer friction and false positives. Keep it separate from credit loss, where there is no deceptive intent, and from money laundering, which moves illicit money rather than obtaining it. In real casework the three often overlap.

Fraud factory

Scams & social engineering

A fraud factory is an organized, often physically coercive operation that runs scams at industrial scale, notably compounds in Southeast Asia staffed by trafficked and enslaved workers. It mass-produces romance, investment, and pig-butchering scams across many victims and countries at once.

For operators this means highly scripted, multi-account, cross-border patterns and mule networks rather than lone actors. It is both a fraud and a human-trafficking problem, sometimes called a scam compound, which shapes how law enforcement and reporting respond.

Fraud rate (bps)

Detection & metrics

This is fraud losses or incidents shown in basis points of volume, where one basis point is 0.01 percent. Putting it in bps normalizes the number so you can compare across products and over time. It is the headline figure teams target and benchmark against peers.

The catch is definition. Attempted versus approved fraud, count versus dollars, and the maturation window all change the number, so two teams quoting bps may not mean the same thing. Because disputes lag, recent periods understate the true rate. Read fraud bps on matured cohorts, where late fraud has surfaced, and always state the denominator plainly so the figure can be trusted and compared.

Fraud ring

Account & access fraud

A fraud ring is an organized group that shares identities, devices, funding, addresses, or methods across many accounts to run coordinated fraud at scale, from bust-out schemes to whole portfolios of synthetic identities. The volume and coordination cause far more loss than a lone fraudster.

Members look independent one at a time but cluster tightly on shared traits, so graph and entity-resolution tools, not single-account rules, are the main way to see them. Handling focuses on ring-level takedowns: block the shared elements so the whole network drops at once instead of chasing one account at a time.

Fraud score

Detection & metrics

This is a number estimating the fraud risk of an entity, transaction, or session, produced by a model or blended scoring logic and used to drive decisions. It turns messy signals into one value you can act on. But its worth lives entirely in where you set the thresholds; the score is only as good as its calibration and the actions mapped behind it.

Mind drift, score compression where values bunch together and lose meaning, and population shifts that quietly change what a given score represents. Do not trust the raw distribution. Monitor how scores map to actual outcomes, not just their spread, or a stable-looking score can hide fading accuracy.

Fraud-as-a-Service (FaaS)

AI & emerging fraud

This is fraud tools, data, and infrastructure sold to less-skilled actors: stolen logins, bot kits, drop accounts to receive funds, and cash-out services. It puts proven playbooks in many more hands, so you face the same attack run over and over.

That repetition is a gift for detection: reused tooling leaves repeatable patterns and shared fingerprints across many attempts. It relates closely to crime-as-a-service and phishing-as-a-service. Consortium data and pattern-matching on reused tools are among the strongest responses. The mistake is treating each hit as a one-off instead of connecting them to a common source you can block in bulk.

Free trade zone abuse

Money laundering

Free trade zone abuse exploits the lighter customs and AML oversight inside free trade zones to mis-invoice, reroute, relabel, or repackage goods as a way to launder money or dodge sanctions.

Signs include goods entering and leaving with changed descriptions or origin, invoice values that do not match market prices, and shell entities registered in the zone with no real operations. It relates to trade-based money laundering, transshipment, and sanctions evasion. Because authorities see little inside these zones, investigators must match inbound and outbound manifests and payment flows to expose where value shifted.

Friction

Detection & metrics

This is any added step or check in a flow, like a one-time code, a document upload, or a step-up verification. It lowers risk but can deter or lose good users. Friction is a cost you spend, not a free win: every extra step drops some real customers.

The operator's job is to apply it selectively through risk-based decisioning, spending friction only where the risk earns it. Too little and fraud leaks; too much and conversion falls and good users go elsewhere. The trade is protection versus completion. Measure friction by its effect on abandonment and completion rates, not only by the fraud it blocks, or you will over-apply it and never see the customers you lost.

Friendly fraud

Fraud types

This is when a real cardholder disputes a real purchase, either by mistake, such as not recognizing the merchant name or forgetting a subscription, or on purpose to get free goods. It looks like fraud but comes from your actual customer, so intent is hard to prove.

It differs from criminal third-party fraud because the true account holder made the buy. Mitigate it with clear billing descriptors, delivery and usage evidence, representment, and pre-dispute alerts. It overlaps with chargeback fraud, and mislabeling it throws off both your fraud and dispute metrics.

Front company

Money laundering

A front company is a business with real or apparent operations used to mix in and legitimize dirty money, giving criminal cash a believable commercial source. Unlike a pure shell, it may actually trade, which makes it harder to spot.

Red flags include revenue that does not fit the sector, cash deposits larger than realistic sales, thin margins with high turnover, and expenses that do not match a working business. It relates to shell companies and commingling. Surface activity passes basic KYC, so you only catch it by benchmarking the financials against a true peer baseline.

FTC

Regulation & bodies

The FTC is the US Federal Trade Commission. It tackles consumer fraud, deceptive practices, and data-security and privacy failures, and enforces rules such as the identity-theft red-flag requirements for certain businesses. Although it is a consumer-protection and competition authority rather than an AML regulator, its actions shape fraud, scam, and data-handling expectations.

For operators, FTC guidance and enforcement influence how you handle scams and personal data, and its identity-theft red-flag rules intersect directly with account-opening and KYC controls. It is worth watching even if AML is your main focus, because fraud and identity abuse rarely stay neatly on one side of the AML-versus-consumer-protection line.

Fullz

Card & payment fraud

Fullz is criminal slang for a complete stolen identity package, usually name, address, date of birth, a government ID or Social Security number, and financial or card data. The reason it counts: it sells for more and unlocks higher-value fraud than card data alone.

Fullz enable making synthetic identities, taking over accounts, opening new accounts, and abusing loans or BNPL, not just cloning cards. Finding fullz in a breach signals downstream application and takeover risk. It contrasts with dumps, which are card data only, and it feeds identity-theft and synthetic-identity schemes.

Funds flow analysis

Monitoring & investigations

Funds flow analysis traces money as it moves across accounts, banks, and people to reconstruct where it came from, how it was layered to hide the trail, and where it ended up. It is central to investigating layering, mule networks, and schemes that turn dirty money into clean-looking assets, and it directly feeds the how and why of a SAR narrative.

Analysts combine internal records with counterparty data, sometimes gathered through 314(b). Two pitfalls stand out: losing the trail when funds cross into another institution you cannot see, and mistaking normal business flows for layering without first establishing purpose.

Funnel account

Money laundering

A funnel account takes in many small, often structured deposits from different people and places, then is quickly emptied to gather the proceeds in one spot. It collapses a spread-out collection network into a single payout.

The tell is fast money in and out, deposits in one region and withdrawals in another, and many unrelated payers feeding one beneficiary. It relates to structuring, smurfing, and mule networks. Speed and geographic spread, not deposit size, are the strongest signals here, because each individual deposit is kept deliberately small.

Fuzzy matching

Sanctions & screening

Fuzzy matching is approximate string-matching that scores how similar two names are instead of demanding an exact match, so screening can catch misspellings, name variants, reordered words, and transliteration differences. Sanctioned names rarely arrive perfectly formatted.

It is a tuning tradeoff: looser thresholds catch more real hits but flood the queue with false positives, while tighter ones do the reverse. Operators calibrate the scoring, often blend it with phonetic and token-based methods, and validate settings against known-positive and known-negative test sets. Setting and forgetting the thresholds is the error, since the right balance shifts with your data and lists.

G

9 términos

Gait analysis

Device & behavioral

Gait analysis is a behavioral biometric based on how a person moves, or how they hold and move a device, read from motion sensors. As a passive, continuous signal it can flag when a session is handed off or driven by a bot or a remote tool.

That feeds takeover and scam detection. But it is noisy and context-dependent, easily thrown off by posture, injury, or a new device, so use it as a supporting weight rather than a standalone decision.

Gambling laundering

Money laundering

Gambling laundering cleans money through betting, online wagering, or cashing out credits to hide where the funds came from. Launderers use low-risk bets, bets that cancel each other out, or transfers between players on the same platform.

Red flags include deposits far bigger than actual play, little net betting before withdrawal, chip or credit transfers between users, and cashing out to a different method than the deposit. It relates to casino laundering and mule activity. Online platforms allow fast layering across accounts, so deposit-to-wager ratios and cross-account transfers tell you more than raw volume.

Gatekeeper

AML programs

A gatekeeper is a professional such as a lawyer, accountant, notary, or company service provider who sits in a position to either catch or unknowingly enable illicit money, because they set up companies, property deals, and complex structures. Their involvement can lend a shady arrangement an air of legitimacy.

So a gatekeeper's presence in a structure is itself worth a closer look, not a reassurance. Where legal privilege or professional secrecy limits what you can see, focus on the structure and the money flow rather than assuming the professional acts as a control. Do not treat a respected name as proof the deal is clean.

GDPR

Regulation & bodies

GDPR is the EU General Data Protection Regulation. It governs how personal data of people in the EU is processed and grants rights including access, correction, and erasure, with heavy penalties for breaches. It directly touches KYC, monitoring, and screening, all of which process large amounts of personal data.

AML obligations generally give you a lawful basis to process that data and a justification to retain it, so GDPR does not stop financial-crime work. But data minimization, purpose limitation, and cross-border transfer rules still constrain how you handle identity and monitoring data. The tension is real: collect and keep what AML requires, but no more, and only for permitted purposes.

Generative AI fraud

AI & emerging fraud

This is fraud that uses generative AI to mass-produce fake identities, documents, messages, or media cheaply. It powers synthetic-identity signups, phishing and scam scripts tailored to each victim, and made-up support or dispute stories. Scale and polish both jump at once.

The hard part operationally is that the content no longer has the old giveaways, like clumsy grammar or bad formatting, so inspecting the message itself catches less. The response shifts toward behavior, device, and network signals, which are harder for the attacker to fake than the words on the screen. Trusting content as proof still fails here; treat the surrounding signals as the real evidence.

Geographic Targeting Order (GTO)

Monitoring & investigations

A GTO is a temporary FinCEN order that imposes extra recordkeeping and reporting on specific transaction types, often above a set dollar amount, inside a defined geographic area. It is used to target emerging risks such as real-estate laundering or money-transfer corridors. For covered businesses, it changes your reporting and identity-collection duties for as long as the order runs.

If your business is in scope, adjust procedures for the order's area and timeframe. GTOs are time-limited and can be renewed or changed, so track effective dates and scope closely; a lapsed or misread order leads straight to missed filings.

Geolocation

Device & behavioral

Geolocation places a user or device by IP, GPS, or network data to assess risk and catch anomalies, like impossible travel, a login far from the account's norm, or a gap between stated and observed location. It is central to takeover and mule detection.

But it is easy to manipulate with VPNs, proxies, and GPS spoofing. Corroborate across IP, device, and behavioral signals rather than trusting one source, and remember that VPN use by itself is common and not automatically fraud.

Government impersonation scam

Scams & social engineering

A government impersonation scam is a fraudster posing as a tax authority, police, immigration, or benefits agency to force payment or disclosure through threats of arrest, fines, or lost benefits. Fear and authority are powerful levers, and victims often comply fast.

It usually pairs threats with demands for unusual payment methods like gift cards, wires, or crypto. Red flags include contact out of the blue, threats demanding immediate payment, and non-standard payment channels. Real agencies do not demand instant payment by gift card or crypto.

Grandparent scam

Scams & social engineering

A grandparent scam is a type of emergency scam that pretends to be a grandchild, or someone acting for them, in urgent trouble like an accident or arrest, to get fast cash from an older victim. It exploits emotion, urgency, and secrecy (do not tell my parents), and increasingly uses voice cloning to sound convincing.

Watch for panicked large cash withdrawals, payment by gift card or cash handed to a courier, and elderly customers coached to keep the reason vague. It overlaps with elder fraud.

H

5 términos

Hawala

High-risk payments

Hawala is an informal way to send money across borders through a network of brokers called hawaladars, who work on trust and settle up with each other later. It leaves little or no transaction record, and while it is widely used for honest remittances, its danger is that value moves without funds actually crossing borders, which defeats wire tracing.

Red flags include third-party cash deposits, no real link between sender and receiver, and routes to high-risk regions. Hundi and fei ch'ien are cousins. The common mistake is assuming a hawala user is a criminal; the real risk is an unlicensed operator and an unverified source and purpose of funds.

Healthcare fraud

Fraud types

This is faking claims, billing, diagnoses, or eligibility to pull improper healthcare payments. It includes phantom billing, upcoding, unbundling, and kickbacks. It drains large sums and often feeds money laundering as a source crime.

In financial monitoring it can look like unusual payments into provider accounts, sudden billing spikes, or proceeds washed through related entities. Detection uses claims analytics, comparing a provider to its peers, and mapping referral relationships. It frequently involves collusion, so look at the network of providers, not just one bad actor.

High-risk exchange

Crypto & blockchain crime

A high-risk exchange is a crypto service with weak, spotty, or missing AML and KYC controls, which gives it heavy exposure to illicit funds and makes it a favorite cash-out spot for criminals. Money flowing to or from such a venue raises a wallet's risk score and can trigger enhanced review or a report.

Assessing one weighs its KYC rigor, jurisdiction, sanctions posture, and observed links to illicit clusters. Related types include no-KYC, nested, and parasite exchanges. Do not treat all exchanges alike; a venue's controls, not just its size or name, determine how much risk its flows carry.

HM Treasury/OFSI list

Sanctions & screening

The HM Treasury/OFSI list is the UK's consolidated list of targets subject to financial sanctions, maintained by the Office of Financial Sanctions Implementation within HM Treasury. It applies to UK persons and activity, and since diverging after Brexit, it can differ in named parties and scope from the EU, US, and UN lists.

Programs with UK exposure screen against it specifically and reconcile it with other regimes rather than assuming the lists match. Treating UK, EU, and US coverage as interchangeable leaves gaps; a party sanctioned in the UK may not appear elsewhere, so leaning on one list leaves UK obligations unmet.

Hundi

High-risk payments

Hundi is a South Asian money-transfer and credit tool older than modern banks, much like hawala. It moves value and extends trade credit through trusted middlemen, settling outside regulated payment rails, so the money's real path stays hidden.

It appears in remittance corridors to and from the subcontinent and can involve offsetting trade invoices, so a bank only sees the local funding and payout legs. It is a form of informal value transfer. Investigators should focus on who the operator is, who settles with whom, and whether the flow is a genuine remittance or layering.

I

22 términos

Identity fraud

Fraud types

This is using stolen, synthetic, or altered identity data to commit fraud. It is different from identity theft, which is the act of grabbing that data in the first place. It powers account opening, account takeover, and application fraud alike.

Detect it with identity verification, document and biometric checks, and linking PII across applications and devices. A key nuance: it includes synthetic identities that belong to no single real victim, so waiting for a victim to report will never catch them. You need behavioral and network signals to find those.

Identity proofing

Due diligence & onboarding

This is establishing that a claimed identity is real, belongs to an actual person, and that the person presenting it is its true owner, using a mix of document, biometric, and data checks. It is the front-line defense against synthetic identities, stolen credentials, and impersonation.

The key gap to watch is between confirming a document is valid and confirming the presenter actually owns it. Sophisticated fraud often uses genuine data bound to the wrong person, so a real document in the wrong hands still passes a shallow check. Proving the ID is authentic is only half the job; you also have to prove the human holding it is who it belongs to.

Identity theft

Fraud types

This is stealing someone's personal information, through data breaches, phishing, skimming, or mail theft, for later fraudulent use. It is the setup step before most third-party identity fraud. One breach can arm fraudsters against thousands of people.

Victims often find out only when they spot accounts, credit inquiries, or charges they never made. Operationally, watch for surges in applications using breached data, credentials showing up on the dark web, and mismatches between the applicant's device or behavior and the claimed identity. Keep the theft, meaning data acquisition, separate from the fraud, meaning data use.

Identity verification (IDV)

Identity verification

Identity verification confirms a claimed identity is real and that the person presenting it is its rightful owner, usually by combining document, biometric, and data checks. It is the gate that keeps fake and stolen identities out at onboarding.

Separate the two failure modes, because they need different controls: a made-up or synthetic identity, versus a real identity used by an impostor. Match the checks to the risk: over-verifying adds friction and drives customers away, while under-verifying opens the door to takeover and synthetic onboarding.

Illicit address exposure

Crypto & blockchain crime

Illicit address exposure measures how much a wallet has transacted, directly or through intermediate hops, with addresses tied to crime, sanctions, or other high-risk categories like darknet markets, scams, or ransomware. It is central to risk scoring and drives whether funds get allowed, reviewed, or blocked.

It is usually reported as both direct and indirect exposure, shown as a percentage or dollar share. Read it carefully: hop distance, attribution confidence, and the type of activity all shape whether the exposure means real risk or just incidental proximity. The bigger risk is blocking on any faint, far-off link while missing close, high-confidence ones.

Impersonation scam

Scams & social engineering

An impersonation scam is a fraudster posing as a trusted person or institution, a bank, agency, employer, family member, or vendor, to manipulate the victim into paying or handing over sensitive data. It is the parent category behind bank, government, and known-person impersonation, all built on borrowed authority or trust.

Detection centers on verifying through a separate known channel, awareness of spoofing, and treating any unexpected request for money or credentials as suspect, no matter how legitimate the sender looks.

This is a periodic, independent test of whether the AML program is well designed and actually works, and it is one of the BSA pillars. It is run by internal audit or a qualified outside party with no stake in the result. A self-review by the people who run the program is not credible.

Examiners scrutinize scope, tester skill, and genuine independence. Treat audit findings as a tracked remediation backlog you actually work down. The same finding showing up cycle after cycle is a serious governance red flag: it means problems get noted but never fixed. An audit that changes nothing is just paperwork.

An informal value transfer system is any way of moving value outside regulated institutions, covering hawala, hundi, fei ch'ien, and similar broker networks. It is a recognized money-laundering and terrorist-financing risk because value moves with little or no auditable trail.

In practice it looks like local cash paid in on one side and local cash paid out on the other, with brokers settling between themselves so the cross-border link stays hidden; one bank rarely sees the whole chain. The real task is telling licensed money service businesses that run clean IVTS apart from unregistered operators, since only the latter is inherently high risk.

Inheritance scam

Scams & social engineering

An inheritance scam promises a fake inheritance or windfall that the victim can only collect after paying advance fees, taxes, or legal costs, a form of advance-fee fraud. The promised money never arrives while the fees keep climbing.

Tells include an out-of-the-blue notice about an unknown benefactor, requests for upfront payment to release the funds, and forged official-looking documents. It is related to lottery, prize, and other advance-fee scams. The rule of thumb: you should never have to pay to receive money that is genuinely yours.

Injection attack

Identity verification

An injection attack skips the real camera and feeds pre-recorded, edited, or AI-generated media straight into the verification pipeline, often through a virtual camera, an emulator, or an intercepted API call. It is one of the fastest-growing ways to beat remote identity checks.

Unlike a spoof held up to a lens, injection leaves no physical artifact, so liveness alone rarely catches it. Defenses focus on device integrity, capture provenance, virtual-camera and emulator detection, and tamper checks on the capture software, not just analyzing the image.

Insider fraud

Fraud types

This is fraud by an employee or contractor who abuses legitimate access to systems, data, or money. It ranges from data theft and account tampering to teaming up with outside fraudsters. These people are already inside your perimeter controls.

Since they are trusted, detection depends on access logging, anomaly detection on privileged actions, segregation of duties, and unexplained lifestyle or behavior changes. Red flags include after-hours access, opening accounts with no business reason, and overriding controls. It often surfaces alongside collusion and occupational fraud.

Insurance fraud

Fraud types

This is faking claims, applications, or losses to collect improper insurance payouts. It includes staged accidents, inflated damages, phantom policies, and premium fraud. It drives up costs for everyone and often funds organized crime.

Detection relies on claims analytics, prior-claim history, links between claimants, providers, and repairers, and gaps in loss documentation. Watch for claims filed soon after a policy starts, phone numbers or addresses shared across unrelated claims, and pressure for a fast settlement. It frequently involves organized rings and is a common source crime for money laundering.

Integration

Money laundering

Integration is the final laundering stage, where cleaned funds re-enter the economy as seemingly legitimate assets or income, having been distanced enough from their source to survive scrutiny.

It appears as investment in real estate, businesses, or luxury goods, loan-backs, and payments dressed up as legitimate income, which makes this the hardest stage to catch. It relates to placement, layering, and loan-back schemes. The funds now look clean, so investigators work backward through source of wealth and asset provenance rather than transaction anomalies alone.

Internal controls

AML programs

These are the policies, procedures, and system controls that turn AML duties into daily action, covering customer checks, monitoring, screening, thresholds, escalation, and reporting workflows. They are the connective tissue between what policy intends and what actually happens. Control gaps are exactly where risk turns real.

Look for controls that exist on paper but have no clear owner, no tuning, and no evidence they ever run. Undocumented or untested controls fail both examinations and real-world detection. A control nobody owns is a control nobody runs, and that is the gap a launderer walks through. If you cannot show it operating, assume it is not.

An IFTI is a reportable instruction to move funds into or out of a country, used under regimes such as Australia's AML/CTF framework overseen by AUSTRAC. It captures cross-border transfers no matter the amount. It is an objective, threshold-style duty, separate from suspicion-based reporting: you file because the transfer crossed a border, not because it looked suspicious.

If you are a reporting entity, file within the required window and make sure the underlying data, including who sent and who received, is complete. Weak cross-border data quality is a recurring supervisory complaint, and incomplete originator or beneficiary details are a common gap.

Investigation

Monitoring & investigations

An investigation is the structured review of suspicious activity, pulling together KYC, transaction history, and outside and counterparty information to reach and document a conclusion you can defend. It sits between the alert and the final disposition or SAR. This is where the who, what, when, where, why, and how are actually established.

Follow a repeatable method and record every source and reasoning step as you go. The investigation file is the primary evidence examiners and law enforcement rely on later, sometimes years later. A sound conclusion with no documented work behind it is nearly as weak as no conclusion at all.

Investment fraud

Fraud types

This is luring victims to put money into fake or badly misrepresented opportunities, including Ponzi and pyramid schemes, fake crypto platforms, and pig-butchering scams. Losses are often large, life-changing, and hard to reverse.

In transaction monitoring it looks like a customer making bigger and bigger payments to investment sites or crypto exchanges, often after grooming, then being unable to withdraw. Mitigate it by warning customers at the point of payment, detecting mules on the receiving side, and watching new accounts that collect many incoming investor deposits. It overlaps with affinity fraud and securities fraud.

Investment scam

Scams & social engineering

An investment scam persuades victims to put money into a fake, non-existent, or rigged investment, crypto, forex, precious metals, or pre-IPO shares, by promising outsized or guaranteed returns. It is the loss engine behind pig-butchering and many crypto scams.

Fake dashboards show pretend gains to encourage bigger deposits, while withdrawals get blocked or hit with surprise taxes. Red flags include unregistered platforms, pressure to reinvest, and guaranteed-return language, which real investments never promise. Legitimate returns are never guaranteed, so that promise alone is a warning.

Invoice fraud

Fraud types

This is submitting false, inflated, duplicate, or altered invoices to get paid improperly, either through a fake vendor or a manipulated real one. Payments look routine, so the theft can run for a long time before anyone notices.

It shows as invoices priced just under approval limits, duplicate invoice numbers or amounts, vendors sharing bank details with employees, and sudden payment-detail changes. Controls include three-way matching, duplicate-payment detection, verifying vendor bank accounts, and segregation of duties. It is closely tied to vendor fraud, procurement fraud, and invoice redirection.

This is changing the payment details on an otherwise real invoice, often after hacking or spoofing a vendor's email, so the money lands in an account the fraudster controls. Everything else about the invoice is genuine, which makes it easy to miss.

The classic tell is a change-of-bank-details request that arrives near a real payment cycle, sometimes with a nudge of urgency. Defend against it by calling a known contact to verify before updating any vendor bank details, requiring two approvers, and flagging the first payment to a changed account. It is the payment-side result of BEC and vendor-email compromise.

IP intelligence

Device & behavioral

IP intelligence is risk signals drawn from an IP address, including proxy, VPN, Tor, hosting or datacenter origin, geolocation, and reputation history. It helps expose anonymization, bot infrastructure, and location spoofing behind fraudulent sessions.

The signals are noisy and shared: plenty of legitimate users sit behind VPNs, corporate networks, or mobile carrier IPs. So treat IP as contextual risk that adds weight, not a decision you make on its own.

Iris scan

Device & behavioral

An iris scan is biometric verification using iris patterns, a high-accuracy method usually reserved for controlled or high-assurance settings rather than everyday consumer onboarding. It is very precise where it is used.

Like any biometric, it needs liveness to resist high-resolution photo and replay spoofs, and secure enrollment so an attacker cannot register their own iris. It is rare in mainstream digital fraud flows, so most operators only meet it in specialized access-control settings.

J

2 términos

Jailbreak/root detection

Device & behavioral

Jailbreak and root detection spots mobile devices whose built-in security controls have been stripped, handing apps and attackers elevated access to memory, storage, and traffic. A rooted or jailbroken device raises the risk of tampering, hooking, and injection.

That makes it a meaningful signal in fraud and takeover flows. But detection and evasion are an arms race, with tools built to hide root status, so combine it with app-integrity and behavioral checks rather than treating a clean result as a guarantee.

Job scam

Scams & social engineering

A job scam is a fraudulent employment offer used to steal money or personal data or to recruit money mules. It overlaps heavily with employment and task scams. It can hit the victim three ways: lost fees, stolen identity, or getting pulled into laundering.

Victims may pay bogus fees, hand over ID that fuels identity theft, or receive and forward illicit funds through their own accounts. Signs include unsolicited offers, upfront payments, and requests to move money. The mule outcome makes it both a scam-victim and a laundering-conduit problem.

K

7 términos

Keystroke dynamics

Device & behavioral

Keystroke dynamics is a behavioral biometric based on typing rhythm, how long keys are held, and the timing between them, used passively to recognize a user and flag anomalies. A shift in typing pattern can point to account takeover, a bot replaying credentials, or a session under remote control.

It is probabilistic and varies with the device, keyboard, and the user's state. Treat it as one weighted signal within a broader behavioral profile rather than a standalone verdict.

Know Your Agent (KYA)

Due diligence & onboarding

KYA is due diligence on an autonomous AI agent or third party acting on a customer's behalf, establishing its identity, the scope of its authority, who controls it, and the risk it brings. As agentic and delegated transactions grow, the party actually initiating activity may not be the accountable human.

Confirm the chain of authority and accountability behind the agent, because an unverified agent can obscure who is really directing the funds. If you cannot trace an action back to a responsible person, you have lost the thread that the rest of your controls depend on. Knowing the customer is not enough when something else is pushing the buttons on their behalf.

Know Your Business (KYB)

Business verification

Know Your Business verifies a business customer's legal existence, ownership, control structure, and legitimacy before and during the relationship. Onboarding a fake or hidden-owner business exposes you to fraud losses and AML liability.

It combines registry checks, tracing who really owns the company, sanctions and adverse-media screening, and confirming the business actually operates. Red flags include shell entities with no real footprint, rapid ownership changes, one address shared by unrelated firms, and structures layered on purpose to hide the true controller.

Know Your Customer (KYC)

Due diligence & onboarding

KYC is the overall process of verifying a customer's identity and understanding the relationship well enough to manage financial-crime risk across its life. It includes CIP-style identity checks and the broader due diligence around them. It is foundational to everything else.

It is often misused as shorthand for onboarding alone, as if it ends once the account opens. Treat KYC as continuous instead: identity and risk verified once at signup decay as ownership, circumstances, and behavior change over time. A customer you knew accurately two years ago may be a stranger today. Knowing your customer is a habit you maintain, not a box you tick once.

Know Your Employee (KYE)

Due diligence & onboarding

KYE is the screening and ongoing monitoring of staff, including background checks, sanctions and adverse-media screening, and behavioral indicators, to reduce insider financial-crime risk. Insiders can bypass controls, leak information, or help launder money, making them a distinct and often under-addressed threat.

Staff in sensitive roles warrant heightened attention. Lifestyle or access anomalies that do not fit an employee's known circumstances, such as sudden unexplained wealth or access to systems outside their job, are worth escalating. The threat inside the building can defeat controls built to stop outsiders, so the same skepticism you apply to customers has a place with staff who hold the keys.

Know Your Transaction (KYT)

Due diligence & onboarding

KYT is real-time or near-real-time screening of a transaction's parties, counterparties, and, in crypto, on-chain exposure, to judge illicit risk at the point the money moves rather than only after the fact. It adds transaction-level context that customer-level KYC alone misses.

Even a clean customer can route risky funds, and KYT is what catches that. Tune it for exposure to mixers, high-risk exchanges, and sanctioned addresses, balancing detection against false positives that stall legitimate payments. Set it too loose and bad flows pass; set it too tight and you choke real customers. The skill is catching the movement that matters without freezing the ones that do not.

Knowledge-based authentication verifies a person by asking things only they should know, like a past address or an old loan amount. It was once a common step-up, and it still lingers in many flows.

It is now considered weak: that data is widely exposed through breaches and data brokers, so fraudsters often answer more accurately than the real customer. Use it as a low-assurance step-up at best, and prefer possession or biometric factors for anything sensitive.

L

15 términos

Layered ownership

Money laundering

Layered ownership stacks holding companies and middlemen across several countries to put distance between an asset and its true owner. Each tier adds legal and geographic separation that makes tracing harder.

It looks like ownership chains running through secrecy jurisdictions, companies whose only asset is another company, and structures with no business reason for their complexity. It relates to beneficial ownership obfuscation and shell companies. The pitfall is stopping the trace at the first offshore layer, when the whole design is meant to wear investigators out before they reach the controlling person.

Layering

Money laundering

Layering is the laundering stage that puts distance between funds and their source through complex transfers, conversions, and country hops, deliberately building confusion between origin and destination.

It shows as fast movement between accounts and entities, currency and instrument conversions, and cross-border hops with no business reason. It relates to placement, integration, and layered ownership. Layering is built to defeat straight-line tracing, so network analysis and following value across products, not just single transfers, is what rebuilds the chain.

Liability shift

Card & payment fraud

Liability shift is the rule that decides who absorbs a fraud loss based on authentication and compliance. Under chip (EMV) rules the least-compliant party pays; under 3DS the issuer usually eats authenticated online fraud. It changes who is on the hook, sometimes without changing the fraud itself.

Teams weigh this when tuning controls, since routing a payment through 3DS can move chargeback exposure off the merchant. Remember it shifts who pays, not whether fraud happens. Misreading the rules leads to surprise losses and contested representments.

List matching

Sanctions & screening

List matching is the core screening step of comparing customer, counterparty, and transaction data against sanctions and watchlists to find potential hits, using exact, fuzzy, phonetic, and transliteration logic. It is where prohibited parties are actually caught or missed.

Its effectiveness rests on input data quality, list coverage and freshness, and threshold tuning, which together set the balance between false positives and false negatives. Recurring pitfalls include poorly normalized data, missing secondary identifiers to tell common names apart, and untuned thresholds. The takeaway: good matching is as much about clean data and calibration as about the algorithm itself.

Live video deepfake

AI & emerging fraud

This is a fake video stream manipulated in real time to beat a live check, like video ID review or an agent-assisted identity call. It is harder to pull off than a pre-made clip, but it defeats liveness prompts that assume a real camera, and it is often paired with tools that inject the feed directly.

Detect it with injection-attack detection, challenge-response prompts that ask for an unexpected action, device and telemetry integrity checks, and analysis of latency or visual artifacts. Treat a passed live session as one strong signal, not proof. A determined attacker can pass the call, so weight the other evidence too.

Liveness detection

Identity verification

Liveness detection confirms a real, present human is being captured rather than a photo, mask, screen replay, or deepfake, and comes as active (the user does an action) or passive (a single capture). It is the frontline defense against spoofs held up to the camera.

On its own it does not prove the capture came from a genuine camera, which is exactly how injection attacks slip past it. Pair liveness with device integrity and capture-provenance checks, and keep tracking its spoof rates as deepfake tools improve.

Loan fraud

Fraud types

This is getting a loan through false information, a stolen or synthetic identity, or with no real intent to repay. It spans both third-party fraud and first-party bust-out. The loss often looks like a normal default until you dig in.

Signals include fabricated or unverifiable income and employment, many applications sharing devices or PII, and a fast drawdown followed by default. Detect it with identity and income verification, bank-transaction analysis, and linking applications together. The core difficulty is telling deliberate loan fraud apart from ordinary credit default.

Loan-back scheme

Money laundering

A loan-back scheme lends dirty money to yourself through a company you secretly control offshore, so repayments look like normal loan servicing. It turns criminal cash into what appears to be borrowed capital and even deductible interest.

Red flags include loans from opaque offshore lenders, terms out of line with the market, a lender and borrower sharing the same owner, and no real underwriting. It relates to round-tripping, integration, and shell companies. The paperwork can look proper, so the decisive test is whether the lender is truly independent and the loan has real economic substance.

Look-back review

Monitoring & investigations

A look-back review is a backward look at historical activity over a set period, usually required after a control gap, missed filings, or a regulator finding. The goal is to find and fix suspicious activity that went undetected the first time. It is how a program cleans up after a failure, and it often ends in a batch of late SARs.

These reviews are resource-heavy, need documented scoping, and sometimes require independent parties. Treat the scope, method, and results as deliverables that will be heavily scrutinized, and keep a clean audit trail throughout. Weak scoping is the fastest way to have a look-back rejected.

Loss rate

Detection & metrics

This is realized fraud or credit losses as a share of volume, the bottom-line measure of what actually got through and cost money. Unlike alert-based numbers, it reflects net losses after recoveries, so it is the truest read on damage done. Alerts can look busy while real losses tell a different story.

It lags the fraud event and needs matured cohorts to read accurately, since recoveries and late fraud both take time. Keep fraud and credit losses separate and reconcile back to charge-offs. A classic red flag: loss rate climbing while alert volume stays flat usually means a new fraud pattern is getting past detection that has not learned it yet.

Lottery scam

Scams & social engineering

A lottery scam tells the victim they have won a lottery, sweepstake, or prize they never entered, then demands upfront fees or taxes to release the winnings, a form of advance-fee fraud. The prize is fake and the fees keep escalating.

Red flags include winning a contest you never entered, being asked to pay in order to receive, and pressure to keep it secret. It is related to prize, inheritance, and other advance-fee scams. If you have to pay to collect a prize, it is not a real prize.

Love bombing

Scams & social engineering

Love bombing is flooding a target with intense affection, attention, and talk of a shared future early in a romance scam, to speed up emotional attachment and lower their guard before any money is asked for. It compresses the grooming timeline so the eventual ask feels natural.

As a tactic it comes before any financial signal, so awareness and pacing red flags, rapid intensity or refusing to meet or video-call, matter more than transaction monitoring. It is related to romance scams and catfishing.

Loyalty fraud

Fraud types

This is stealing or fraudulently cashing in loyalty points, miles, or rewards, usually by taking over dormant loyalty accounts or farming points through fake activity. Points are real value, yet customers watch them far less than cash.

It surfaces as logins from new devices on rarely used accounts, bulk or rapid point redemption, and transfers to unfamiliar recipients. Because nobody checks points often, the fraud can run unnoticed for a long time. Mitigate it with extra authentication at redemption, velocity limits, and anomaly detection on dormant-account activity.

Luxury asset laundering

Money laundering

Luxury asset laundering parks dirty money in high-value goods like watches, jewelry, cars, or yachts that hold value, are easy to move, and can be resold later to integrate the proceeds.

Red flags include cash or third-party purchases, buyers hiding behind intermediaries, quick resale, and putting title in the name of a shell company or nominee. It relates to art laundering and integration. Private resale markets and cross-border portability make these assets an easy way to move value, so establishing the source of funds at purchase and tracking the resale trail is essential.

M

30 términos

Machine learning model

Detection & metrics

This is a model trained to predict risk from patterns in past data, used to score transactions, entities, or sessions at decision time. It generalizes to new fraud better than static rules, catching variations a hand-written rule would miss.

But it needs labels, monitoring, and retraining, and it can inherit bias or leakage from its training data. In practice models and rules run together: models for nuanced scoring, rules for hard policy and clear explanations, since a model's reasoning is harder to spell out. The trade is adaptiveness against transparency and upkeep. Watch constantly for drift and decay, because a model degrades silently as fraud shifts away from what it learned.

Machine Readable Zone (MRZ)

Identity verification

The Machine Readable Zone is the coded strip on passports and many IDs, printed in a fixed format with check digits so systems can pull and validate the holder's details. It gives you a second copy of the data to cross-check.

Operators compare it against the OCR and the visual part of the page; a mismatch between the strip, the printed page, and the chip is a strong tampering sign. But check digits only catch clumsy edits, not sophisticated fakes that recompute them, so treat a valid strip as necessary, not sufficient.

Man-in-the-browser

Scams & social engineering

Man-in-the-browser is malware living inside the victim's browser that quietly rewrites web sessions in real time, changing the payee or amount while still showing the victim the screen they expect. Its danger is that it works inside an already-logged-in session, so it beats passwords and many one-time-code controls.

Tells include a gap between what the customer meant to do and what actually settled, plus device-integrity anomalies. Fight it with transaction signing (confirm the real beneficiary through a separate channel), behavioral biometrics, and malware detection.

Man-in-the-middle

Scams & social engineering

Man-in-the-middle is intercepting communication between two parties, over rogue Wi-Fi, spoofed sites, or compromised networks, to steal or quietly change data like credentials, one-time codes, or payment details. The victim thinks they are talking to the real party.

Real-time code-relay phishing, which forwards a stolen one-time code instantly, is a common variant that defeats basic two-factor authentication. Countermeasures include TLS and certificate checks, phishing-resistant login like FIDO2, and treating anything typed over an untrusted network as compromised. It is related to session hijacking and man-in-the-browser.

Manual review

Detection & metrics

This is a human looking at cases the automated system cannot resolve confidently, inspecting the evidence and making the final call. It handles ambiguity and edge cases, and it produces high-quality labels that feed model training. But it is slow, costly, and hard to scale.

Manage it with review rate, queue SLAs, how often analysts agree with each other, and decision accuracy. The key insight: over-routing to review is usually a signal that your thresholds or features need tuning, not that you need more headcount. Throwing people at a rising queue treats the symptom; fixing why so many cases land in the gray zone treats the cause.

This is fraud across two-sided platforms, involving fake listings, fraudulent sellers, buyers and sellers in cahoots, or steering payment off-platform to dodge protections. The platform's trust and its buyers are both at risk at once.

It shows as new sellers with sudden high volume, buyer-seller pairs who only deal with each other, and pressure to pay outside the platform. Detect it with seller onboarding checks, transaction-graph and collusion analysis, and monitoring for dispute and refund abuse. It blends seller fraud, buyer fraud, collusion, and triangulation patterns.

MAS

Regulation & bodies

MAS is the Monetary Authority of Singapore, the country's central bank and integrated financial regulator. It supervises AML/CFT across banks, payments, and capital markets, issues notices and guidelines, and enforces against failures. It is a leading standard-setter in the region, so its expectations often shape wider Asian practice.

If your firm touches Singapore, you must meet MAS AML notices and guidelines. Watch its enforcement actions, industry partnerships, and typology guidance for current expectations, particularly around digital assets and trade finance, two areas where MAS has been notably active. Treat its guidance as a strong read on where sophisticated regional supervision is heading.

This is large-scale scams blasted out to many potential victims by mail, phone, email, text, or social media, including lottery, prize, romance, and advance-fee cons. Even a low hit rate pays off when the reach is huge.

On the money side, victims send payments to the scammers, while accounts collecting the proceeds show many small deposits from unrelated senders. Detect it with scam-warning prompts at payment, mule-account monitoring, and clustering victims who all pay one common recipient. It overlaps with advance-fee, charity, and investment fraud.

MiCA

Regulation & bodies

MiCA is the EU Markets in Crypto-Assets regulation. It creates a harmonized licensing and conduct framework for crypto-asset service providers and issuers across the EU. It brings crypto firms into a clear market-regulation regime, but it sits alongside AML rules that apply to those firms rather than replacing them.

For crypto operators, understand MiCA authorization and conduct duties as the market-regulation layer, while your AML/CFT obligations, including travel-rule and customer due diligence requirements, come from the separate EU AML framework and must be met in parallel. A common trap is assuming MiCA compliance covers AML; it does not, and both must be satisfied at once.

Micro-structuring

Money laundering

Micro-structuring breaks proceeds into very small transactions, kept below both transaction-monitoring rules and mandatory reporting limits, to stay under automated and legal radar alike. It is the fine-grained version of structuring.

It appears as high volumes of tiny transfers, repeated near-identical amounts, and coordinated timing across accounts or channels. It relates to structuring, smurfing, and funnel accounts. The pitfall: alerts based on transaction value miss it completely, so detection has to rely on velocity, frequency, and network aggregation rather than the size of any single payment.

Mirror trading

Money laundering

Mirror trading places offsetting trades in different markets or currencies to move value with no genuine economic purpose, for example buying a security in one country and selling the same thing elsewhere to shift funds across borders.

Red flags include matched buy-sell pairs with no market rationale, trades between related accounts, and consistent no-profit-no-loss results that only achieve a transfer. It relates to layering and round-tripping. It mimics real trading, so detecting it means linking the paired legs and questioning the economic logic rather than reviewing trades one at a time.

Mixer

Crypto & blockchain crime

A mixer is a service that pools crypto from many users and pays it back out in a way that breaks the on-chain link between sender and receiver, hiding where funds came from. While some use is for privacy, mixers are a core laundering tool, so exposure to one is a significant risk flag and, for sanctioned mixers, possibly prohibited.

Mixers range from custodial services to decentralized protocols. Analysts trace funds into and out of them, treat mixed funds as lower-confidence, and weigh volume, timing, and the specific mixer's reputation and legal status. The key is not to ignore the difference between a sanctioned mixer and a merely risky one.

This is abusing remote check deposit, most often by depositing the same check image at several banks, called double presentment, or depositing altered or counterfeit checks, then pulling the money before the item bounces back. The convenience of phone deposits also removes friction for fraudsters.

Signals include duplicate check images across banks, deposits that do not fit account history, and fast withdrawal against uncollected funds. Mitigate it with cross-bank duplicate-detection networks, image forensics, funds-availability holds, and velocity limits on new or thin-file accounts. It is a modern twist on classic check fraud.

Model drift

Detection & metrics

This is a model getting worse over time as customer behavior or fraud tactics move away from what it was trained on. It covers data drift, when the inputs shift, and concept drift, when the very meaning of fraud shifts. Untreated drift quietly erodes how much fraud you catch while attackers keep adapting.

It shows up as rising misses or false alarms and score distributions that pull apart from what you expect. Detect it with population-stability and performance monitoring plus score-versus-outcome tracking. Remedies are recalibration, retraining, or new features. The danger is a set-and-forget model; without continuous monitoring the decay is invisible until losses spike.

Model validation

Monitoring & investigations

Model validation is independent testing that a detection model is soundly designed, correctly built, and still fit for its job, covering the data going in, the logic, the outputs, and how it performs over time. A model drifts as behavior and typologies change, and a stale or broken model quietly misses risk while looking like it works.

Expect it periodically and after any material change; it is a standing examiner focus for firms using models rather than simple rules. Make sure the people validating are independent of those who built the model, and cover above- and below-the-line testing. Overdue or undocumented validation is a common finding.

Money laundering

Money laundering

Money laundering is the process of disguising the origin of criminal proceeds so they appear to come from a legitimate source. It is conventionally modeled in three stages: placement, layering, and integration.

It spans everything from cash deposits to shell structures to trade schemes, and detecting it means spotting activity that does not fit a customer's expected profile and source of funds. It relates to the predicate offense, proceeds of crime, and the three-stage model. In reality the stages overlap, and modern methods like mules, crypto, and TBML rarely follow the textbook sequence cleanly.

Money laundering as a service describes professional networks that launder money for other criminals for a fee or a cut, offering laundering as an outsourced, off-the-shelf capability complete with mule networks, shell structures, and cash-out channels.

It shows up as reusable infrastructure serving many unrelated criminal clients, so the same accounts, devices, and corridors turn up across otherwise disconnected cases. It relates to professional money laundering and mule networks. Taking down the service provider hurts many downstream crimes at once, which makes network-level attribution more valuable than acting on a single transaction.

The MLRO is the accountable officer for AML compliance and suspicious activity reporting, mainly a UK and EU role. They receive internal suspicion reports and decide whether to disclose externally to the financial intelligence unit. One named person has to own that disclosure call.

The role often carries personal regulatory liability, so independence, seniority, and real resourcing are essential, not nice-to-haves. Make sure there is a clear, documented path from a front-line concern to the MLRO's decision, because any break in that chain weakens both detection and your ability to defend it later. If reports cannot reach the MLRO quickly, the whole reporting system is exposed.

Money mule

Money laundering

A money mule is a person who receives dirty money into their own account and forwards it on. Some are knowingly recruited, some are complicit, and many are tricked by a fake job or a romance scam. The mule adds a real-name layer that breaks the trail back to the criminal.

Signs include money passing straight through with little kept, activity that does not fit the account's history or the holder's profile, and in-and-out patterns matching known scams. It relates to mule accounts, herders, and networks. The nuance: many mules are victims, which shapes both how you detect and how you handle the case.

An MSB is a regulated non-bank financial business, such as a money transmitter, currency exchanger, or check casher, that is itself subject to AML rules and registration or licensing. For a bank, MSBs are a classic higher-risk customer segment: they pool third-party money flows.

Servicing one calls for enhanced due diligence on the MSB's own AML program, not just onboarding it like any customer. A known pitfall is blanket de-risking, dropping the entire category to avoid the work. Supervisors expect a risk-based look at the individual MSB instead of a wholesale exit. Judge the specific business in front of you, not the label on the industry.

MONEYVAL

Regulation & bodies

MONEYVAL is the Council of Europe's FATF-style regional body. It assesses the AML/CFT compliance and real-world effectiveness of its member states, mainly in Europe, through mutual evaluations and follow-up reports. It applies FATF standards to European jurisdictions outside the core FATF membership, extending credible assessment across the continent.

Use MONEYVAL evaluations to gauge how mature a European jurisdiction's AML controls actually are, and to inform country risk ratings and enhanced due diligence for customers and correspondents in those countries. Where an evaluation flags specific weaknesses, treat exposure to that jurisdiction accordingly; the reports are a practical, independent read you can lean on.

Morphing attack

Identity verification

A morphing attack blends two or more faces into one document photo so the ID matches multiple people. A single genuine-looking document can then serve several accomplices and quietly defeat face match.

It usually targets the enrollment or document-issuance stage, where the morphed image is submitted before any downstream check can catch it. Detection needs morph-specific analysis and, where possible, comparing the chip photo against the printed one, since a morphed image can still sail through an ordinary face match.

Mortgage fraud

Fraud types

This is misrepresenting or hiding facts in a mortgage application, appraisal, or deal. It splits into fraud-for-housing, where a borrower lies to qualify, and fraud-for-profit, where insiders extract value through straw buyers, inflated appraisals, or quick flips. Loan sizes are large and losses are steep.

Signals include inflated income or appraisals, straw-buyer patterns, undisclosed ties between parties, and fast resale at marked-up prices. Detection uses income and asset verification, appraisal review, and mapping the network of parties. It often involves collusion and serves as a vehicle for money laundering.

Mouse dynamics

Device & behavioral

Mouse dynamics is a behavioral biometric based on cursor movement, speed, and click patterns in desktop sessions. Robotic or perfectly straight movement suggests a bot, while a sharp change from the account's usual pattern can flag takeover or remote-tool control during a scam.

It applies mainly to pointer-driven interfaces and it is noisy on its own. It works best combined with keystroke, device, and network signals rather than read in isolation.

Mule account

Money laundering

A mule account is an account used to receive and pass on dirty money, often opened with a real, synthetic, or coerced identity. It works as a relay point in the laundering chain.

Red flags include sudden activity after being dormant, fast in-and-out flows with little balance kept, a mismatch with the stated purpose, and shared devices or contact details across several accounts. It relates to money mules, funnel accounts, and mule networks. Reviewing each flagged account alone misses it; linking shared identifiers across accounts is what exposes the wider network.

Mule herder

Money laundering

A mule herder is the organizer who recruits, directs, and pays money mules and then gathers up the laundered proceeds. The herder sits above the mules and below the ultimate criminal.

Herders surface through shared contact points, funding or instructions flowing into many mule accounts, and reused devices, IPs, or payment references across accounts that otherwise look unrelated. It relates to mule networks and money mules. Catching individual mules barely dents the operation, so investigations try to pivot from the mules to the herder and the point where money is consolidated.

Mule network

Money laundering

A mule network is a coordinated set of mule accounts used to split up and move dirty money fast across many banks, built so no single bank sees enough of the flow to act.

It reveals itself through shared devices, addresses, funding sources, and timing that link accounts that look unrelated, often with quick fan-out and fan-in patterns. It relates to mule accounts, herders, and funnel accounts. Single-bank blind spots are the core problem, which is why shared industry data and cross-account link analysis are central to seeing the full network.

Multi-factor authentication requires two or more independent factors: something you know (a password), something you have (a phone or token), and something you are (a biometric). It sharply cuts account takeover from stolen passwords alone.

It is not bulletproof. SIM swaps, intercepted one-time codes, real-time phishing proxies, and push-bombing that wears the user into approving all target it. Prefer phishing-resistant factors like passkeys or hardware keys over SMS codes, and watch the enrollment and reset flows fraudsters use to swap factors.

Multi-modal biometrics

Device & behavioral

Multi-modal biometrics combines two or more biometric traits, like face plus voice, to raise assurance and make spoofing harder, since an attacker has to beat several traits at once. It improves resilience against single-channel attacks like a face deepfake or a voice clone, and can lower error rates.

The tradeoff is added capture friction and cost. And every trait still needs its own liveness, since a match without liveness can be spoofed one channel at a time.

Mutual evaluation

Regulation & bodies

A mutual evaluation is a peer review, run by FATF or an FSRB, that assesses a country's AML/CFT regime on two things: technical compliance with the Recommendations and effectiveness in actual practice. It produces a detailed report and ratings. Poor outcomes can lead to grey- or black-listing and follow-up processes that raise the risk of dealing with that country.

For operators, mutual-evaluation findings drive jurisdiction risk ratings and expose specific weaknesses, such as a weak beneficial-ownership regime, that should shape your enhanced due diligence for exposure to that country. Read the findings, not just the headline rating, since the detail tells you exactly where the gaps are.

N

12 términos

Name screening

Sanctions & screening

Name screening matches a party's name against sanctions, PEP, and other watchlists to catch prohibited or high-risk people and entities, usually at onboarding and continuously after. Names are the most common identifier you have, but also the noisiest.

Names are non-unique and vary by spelling and script, so it leans on fuzzy, phonetic, and transliteration matching plus secondary identifiers to tell people apart. It differs from transaction screening, which checks payment-message content; strong programs run both and confirm hits with extra data before deciding. Acting on a raw name match without disambiguating either floods analysts or clears real hits.

Negative news

Due diligence & onboarding

This is derogatory information pulled from public and media sources for use in screening; in practice it means the same thing as adverse media. It flags potential crime, sanctions, or reputational risk that structured databases may not reflect yet.

You face the same core challenges as with adverse media: false positives from common names, old or unreliable stories, and the need to document why each hit was cleared or escalated rather than quietly dismissed. A hit you drop without a recorded reason is a gap an examiner can point to later. The value is not in surfacing news; it is in judging it and leaving a trail that shows you did.

Nested exchange

Crypto & blockchain crime

A nested exchange is a business that offers trading to its own customers by operating through accounts it holds at a larger host exchange, so its clients' activity hides behind the host's onboarding. These services often run weak or no KYC of their own, creating a laundering channel inside an otherwise compliant venue.

The host, not the nested service, sees the accounts, so it must spot them itself. Detect them by finding accounts that behave like mini-exchanges: many counterparties and high pass-through volume that make no sense for a single individual. Never assume a compliant host means every account inside it is clean.

Network analysis

Monitoring & investigations

Network analysis studies connected entities and their transactions as a graph to detect coordinated behavior, such as money cycling through a cluster of accounts or many accounts pointing to the same beneficiary. It extends link analysis toward spotting organized rings, layering structures, and smurfing networks that isolated alerts never reveal. Serious laundering is usually a network, not a lone transaction.

Use it to rank the highest-risk clusters so analysts work the worst first. Pitfalls include heavy computational noise at large scale and treating a dense but legitimate commercial network, like a busy marketplace, as suspicious without first establishing intent.

This is opening an account with a stolen or synthetic identity, planning to defraud from day one, through first-payment default, mule use, or bust-out. The account is bad before it ever behaves normally.

It is caught at and just after onboarding using identity verification, device and funding-source reputation, application-velocity links, and watching early activity for cash-out behavior. One catch: synthetic NAF passes standard identity checks, so behavioral and network signals matter most. It overlaps heavily with account opening fraud and synthetic identity fraud.

NFC chip verification

Identity verification

NFC chip verification reads the cryptographically signed chip inside an e-passport or ID and checks its signature to confirm the document is genuine and its data unaltered. It is one of the strongest document checks available: the chip data is very hard to forge.

You can also compare the chip against the printed page and the machine-readable strip. The limits are practical: not every document has a readable chip, you need the access keys, and a cloned-but-valid chip still does not prove the presenter is the rightful holder without liveness.

No-KYC exchange

Crypto & blockchain crime

A no-KYC exchange lets people trade or convert crypto without verifying who they are, which makes it attractive for laundering and sanctions evasion because funds move with no identity attached. That missing attribution is exactly what investigators need and criminals want to avoid.

Even weak or easily bypassed verification can land a venue in this category. In screening, exposure to no-KYC venues raises risk: analysts treat withdrawals from them as low-attribution funds and deposits into them as possible layering or cash-out steps. The source-of-funds trail can vanish the moment money passes through one.

Nominated officer

AML programs

This is the UK term for the person designated to receive internal suspicion reports and decide whether to file an external suspicious activity disclosure. The role is often held by or alongside the MLRO. This person is the internal choke point for disclosures.

They also handle consent, or defense-against-money-laundering, requests. Make sure staff know exactly who this is and that reports reach them promptly, because delayed internal reporting can itself create liability. If people do not know where to send a concern, or it sits in an inbox, the firm can be on the hook even when someone did spot the problem. Clear routing is the whole point.

Nominee

Money laundering

A nominee is a person or company that holds an account, asset, or title on behalf of a hidden principal to conceal who is really in control. It shows a legitimate face while the real party stays off the record.

Red flags include a holder with no financial means for the asset, instructions coming from a third party, and several unrelated holdings tracing back to one controller. It relates to nominee directors and shareholders and beneficial ownership obfuscation. A lawful nominee and a concealment device look identical on paper, so the real test is who actually funds and directs the asset.

Nominee director

Money laundering

A nominee director is appointed to front for the real controller of a company. They sign papers and appear on the record but hold no genuine authority, which hides the true owner.

Red flags include one person holding directorships across many unrelated firms, formation-agent nominees, and directors based in a country with no link to the business. It relates to nominee shareholders, shell companies, and beneficial ownership obfuscation. Taking the registered director at face value is the error; finding who actually issues instructions and controls the accounts is what reveals the real principal.

Nominee shareholder

Money laundering

A nominee shareholder holds shares on the record on behalf of an undisclosed real owner, often under a declaration of trust, so the register hides the true economic interest.

Signs include professional or formation-agent shareholders, shares held for parties in secrecy jurisdictions, and ownership that does not line up with who actually benefits from company money. It relates to nominee directors, layered ownership, and ultimate-owner obfuscation. Legitimate nominee shareholding exists, so risk turns on how transparent the arrangement is and whether the true owner can be identified.

Nonprofit/NPO abuse

Terror & proliferation

NPO abuse is the misuse of charities or nonprofits to raise, move, or hide funds meant for terrorism, exploiting the sector's cross-border reach and the good-faith trust people extend to charities. That same trust and global footprint make the sector attractive cover for moving money quietly.

Red flags include a mismatch between a charity's stated purpose and where its money actually goes, payouts to high-risk conflict zones, opaque leadership, and cash-heavy fundraising with little documentation. Risk-rate NPO customers individually rather than treating the whole sector as suspect; FATF warns against blanket de-risking that pushes legitimate charities out of the regulated system.

O

14 términos

Obliged entity

AML programs

This is an EU-style term for any business legally required to apply AML/CFT measures, including customer checks, monitoring, and reporting, under the applicable regime. It covers both financial institutions and designated non-financial sectors. Whether you are an obliged entity decides the full set of duties you carry.

So scoping errors at the edges hurt: a new product or subsidiary that nobody recognized as in-scope creates direct compliance exposure. Periodically confirm which group entities and activities actually fall within scope. The dangerous gap is not the business you know is covered; it is the one everyone quietly assumed was not.

OCC

Regulation & bodies

The OCC is the Office of the Comptroller of the Currency, a US Treasury bureau that charters and supervises national banks, federal savings associations, and the US branches of foreign banks. It examines those institutions for BSA/AML compliance using the shared FFIEC standards.

If you are at an OCC-supervised bank, expect FFIEC-based AML exams and track OCC enforcement actions and bulletins. Together with the Federal Reserve and FDIC, the OCC defines federal banking-sector AML expectations, so its signals matter across the industry. Knowing that the OCC is your primary supervisor tells you whose bulletins and enforcement patterns to prioritize when planning your program.

This is fraud committed by employees, managers, or owners against their own organization. It is classically split into asset misappropriation, corruption such as bribery and kickbacks, and financial-statement fraud. Insiders know the controls and can run schemes for months.

It is usually found through tips first, then confirmed with audits, anomaly detection, and segregation-of-duties controls. Red flags include control overrides, living beyond one's means, favoring certain vendors, and refusing to share duties or take vacation. It overlaps with insider fraud, payroll fraud, and procurement fraud.

Off-ramp

Crypto & blockchain crime

An off-ramp is a service that turns crypto back into regular money, like an exchange withdrawal, payment processor, or OTC desk. It is the point where illicit funds try to leave crypto and enter the banking system, which makes it a prime spot to catch or stop them.

Off-ramps usually require KYC and can freeze or reject a cash-out, so they are key interdiction points. In tracing, following funds to an off-ramp is often the goal, because that is where you can attach a real identity and recover money. The catch is that once funds clear the off-ramp, both attribution and recovery get much harder.

OFAC is the US Treasury office that administers and enforces US economic and trade sanctions, publishes the SDN and other lists, issues guidance like the 50 Percent Rule, and grants licenses. Its rules apply broadly to US persons and often to any USD-denominated activity, giving them wide reach across global finance.

That extraterritorial reach means firms far outside the US can still be bound by it. Compliance programs treat OFAC lists and guidance as a baseline, watch its enforcement actions to gauge expectations, and use its licensing process to authorize otherwise-prohibited dealings. It is easy to underestimate how far USD flows pull you into OFAC's scope.

On-chain analysis

Crypto & blockchain crime

On-chain analysis is examining public blockchain data to trace how funds move, group addresses under common control, tie activity to entities, and judge risk. It is the investigative backbone for crypto AML, fraud response, and sanctions compliance, blending heuristics, known patterns, and off-chain intelligence.

Its limits matter in practice: privacy coins, mixers, bridges, and transfers that happen off-chain or inside an exchange create blind spots. Address attribution always carries a confidence level, never certainty. Treat a probable cluster as a hypothesis, not fact, and weigh how strong each link is before acting on it.

On-ramp

Crypto & blockchain crime

An on-ramp is a service that turns regular money into crypto, like an exchange deposit, card purchase, or broker. It is the entry point where traditional money becomes crypto, and a key control spot since these venues usually run KYC and payment-fraud checks.

At the on-ramp, teams can catch stolen cards, mule funding, and sanctioned actors before funds ever hit the chain. In investigations, finding the on-ramp helps pin down the source of funds and tie an address to a verified identity. The catch is that once funds are on-chain past the on-ramp, tracing the origin gets much harder.

Onboarding

Due diligence & onboarding

Onboarding is the full process of bringing on a new customer, covering identity verification, due diligence, screening, and initial risk scoring before any activity is allowed. It is the primary chance to keep bad actors out.

So control has to be balanced against conversion pressure from the business, which wants signups fast and easy. Make sure the risk data gathered here feeds monitoring and is not lost after approval, because onboarding decisions set the baseline every later control leans on. If you throw away what you learned at signup, downstream monitoring is flying blind. Get it right once here and everything after has something solid to work from.

One-time password (OTP)

Identity verification

A one-time password is a single-use code sent to something you have, like a phone or email, to authenticate you or approve an action. It is everywhere, so its weaknesses are everywhere too.

It is among the weaker factors, exposed to SIM swaps, malware, social-engineering handoff, and real-time phishing that relays the code the instant you enter it. Look out for users coached to read a code aloud, and treat a passed OTP as a step-up signal, not strong standalone proof of identity.

Ongoing due diligence

Due diligence & onboarding

This is the continuous review of an established relationship to keep risk ratings current and catch changes in behavior, ownership, or circumstances that call for action. It is distinct from monitoring individual transactions; it watches the customer, not just the payments. Risk drifts between formal reviews.

It bridges the gap between periodic reviews, catching change as it happens rather than waiting for the calendar. The classic failure is due diligence frozen at onboarding while the customer's real activity moves somewhere very different, leaving an outdated profile that mis-tunes monitoring and delays escalation. A file that never changes on a customer who clearly has is a quiet, standing risk.

Optical character recognition pulls printed text off an ID image to auto-fill and validate fields like name, birth date, and document number. It speeds onboarding and feeds cross-checks against the strip, the chip, and the application data.

But errors from poor image quality or clever edits can seed mistakes further down the line. Reconcile OCR output against the other zones and sources: a field that reads cleanly is not proof it was not altered before capture.

Orchestration

Detection & metrics

This is coordinating your identity, risk, and verification services into one decision flow, calling the right checks in the right order and combining their results. It lets you add, swap, or fail over vendors and adjust routing without rebuilding your core logic, which controls both cost and coverage.

The nuances are managing latency across chained calls, since each vendor adds delay, avoiding redundant checks that cost money for no new information, and building clean fallback logic for when a provider is slow or down. The trade is flexibility against complexity. Done well it is invisible; done poorly it stacks delays and duplicate checks that raise both cost and customer friction.

OTC broker

Crypto & blockchain crime

An OTC broker is an over-the-counter dealer that arranges large crypto trades directly between two parties, off the public order book, offering privacy and little price slippage on big blocks. While legitimate for institutional flow, OTC desks are also used to launder large sums or cash out illicit funds, especially poorly regulated or nested ones.

Red flags include desks that accept funds from high-risk sources, operate through a host exchange's accounts, or help clients structure trades to dodge thresholds and monitoring. Do not assume size and privacy alone are normal; weigh where the funds come from and how the desk is set up.

Over-invoicing

Money laundering

Over-invoicing inflates the price or quantity on trade documents to move value to the exporter. It is a core trade-based laundering technique that shifts money under the cover of real trade.

It shows up as invoice values above fair market price, quantities bigger than the shipment could hold, and payments that do not match the goods actually delivered. It relates to under-invoicing, phantom shipping, and TBML overall. Each shipment looks like normal business on its own, so you catch it by benchmarking prices against market data and reconciling invoices with customs and logistics records.

P

41 términos

P2P payment fraud

Card & payment fraud

Peer-to-peer payment fraud is scams and unauthorized transfers over apps like Zelle, Venmo, or Cash App, where money moves fast, is often irreversible, and is hard to recall. That speed and finality give victims little room to recover funds.

It splits into two types: unauthorized sends driven by account takeover, and scam-driven sends where the victim pays willingly. Each needs different controls. Watch for new or high-risk payees, out-of-pattern amounts, linked-account changes, and urgency. It overlaps heavily with authorized push payment fraud, mule cash-out, and social-engineering scams.

Parasite exchange

Crypto & blockchain crime

A parasite exchange is an exchange-like service that runs through accounts at a larger platform to move and hide illicit volume, sheltering behind the host's compliance and infrastructure. It smuggles dirty flow inside a legitimate venue, and it is closely related to a nested exchange, with the emphasis on deliberately parasitic, laundering-focused use.

The host has to surface these itself. Detect them by clustering accounts that behave like exchanges: dense counterparty graphs and pass-through flows that do not fit a normal customer. The danger is that the host's good reputation can mask the parasite riding on top of it.

Passive liveness

Identity verification

Passive liveness spots spoofing from a single ordinary capture by analyzing texture, depth cues, and artifacts, without asking the user to do anything. It cuts friction and abandonment compared with active liveness, and gives fraudsters no scripted motion to pre-render.

The tradeoff is that pure frame analysis can be fooled by high-quality deepfakes and injection attacks. Combine it with device integrity and capture-provenance signals rather than leaning on the image analysis alone.

Password spraying

Account & access fraud

Password spraying is trying a few common or seasonal passwords across a huge number of accounts, keeping attempts per account low so no single account trips its lockout. Its danger is that it hides inside normal failure rates and slips past defenses tuned to watch one account at a time.

It is the distributed, low-and-slow cousin of brute force. Catch it by looking across the whole user base at once, correlating failed logins by IP or ASN rather than per account. Blunt it with MFA and bans on breached or common passwords. Per-account monitoring alone simply cannot see the pattern.

Payment diversion

Card & payment fraud

Payment diversion is rerouting a genuine payment to an account the fraudster controls, usually by hacking or faking emails and swapping the bank details on an invoice at the last second. Why risk teams care: it targets big business and supplier payments and often surfaces only when the real vendor asks why they were not paid.

Stop it by confirming any change of bank details through a separate, known channel (an out-of-band callback), requiring two approvers, and validating the payee account. It is closely related to business email compromise, invoice fraud, and authorized push payment fraud.

Payroll fraud

Fraud types

This is manipulating payroll to divert wages, create ghost employees who do not exist, inflate hours or pay rates, or falsify commissions and expenses. Payroll runs on a trusted schedule, so small ongoing thefts blend in.

Detection uses payroll analytics, such as employees sharing bank accounts or addresses, pay going to terminated staff, duplicate direct-deposit details, and hours that are not physically possible. Controls include separating HR from payroll, periodic active-employee audits, and validating bank accounts. It is a common form of occupational and insider fraud, usually enabled by weak oversight.

Peel chain

Crypto & blockchain crime

A peel chain is a laundering method that moves a large balance through a long string of transactions, peeling off a small amount to a cash-out address at each step while the bulk rolls on to the next fresh wallet. The trail of many small transfers is built to hide the money and stay under monitoring thresholds.

Analysts recognize the shape: a repeating two-output pattern, one small peel and one large remainder, hop after hop. They follow it step by step toward the eventual off-ramps. Threshold-only monitoring fails here, since each small peel is designed to slip beneath it.

PEP screening

Sanctions & screening

PEP screening checks customers and related parties against politically exposed person lists, covering senior officials, their family, and close associates, to trigger enhanced due diligence given the higher corruption and bribery risk. PEP status is a risk flag, not a ban, so a match calls for a closer look, not an automatic block.

A hit typically means reviewing source of wealth and getting senior sign-off. Challenges include inconsistent PEP definitions across jurisdictions, capturing associates and family, and deciding when someone stops being a PEP after leaving office. It cuts both ways: treating a PEP match like a sanctions hit, or the reverse, waving it through with no extra diligence.

Periodic review

Due diligence & onboarding

This is a scheduled refresh of a customer's due diligence, timed by risk tier, such as yearly for high risk and less often for lower risk, to keep records and ratings current. It works as a safety net, but it is not the primary defense.

Risk can shift long before the next scheduled date, so calendar-based cycles alone leave stale, high-risk profiles unreviewed between dates and tend to create backlogs. Combine periodic reviews with event-driven triggers that fire when something actually changes. Waiting for the anniversary to notice a problem that started months ago is too slow. The schedule catches what nothing else did; it should not be the only thing looking.

Perpetual KYC (pKYC)

Due diligence & onboarding

pKYC is an event-driven model that continuously refreshes customer due diligence as the underlying data changes, such as new adverse media, an ownership shift, or a change in behavior, rather than on fixed periodic cycles. It aims to keep risk ratings current in near real time and cut the review backlogs that calendar-based models pile up.

The practical limit is data quality and trigger tuning. Noisy or poorly calibrated triggers can flood analysts with low-value reviews, trading one problem for another. Done right it reviews the customers that actually changed; done wrong it just generates busywork. The value lives entirely in how well the triggers separate real change from noise.

Phantom shipping

Money laundering

Phantom shipping invoices and settles trade for goods that are never actually shipped, moving value with no real commerce behind it. The whole deal is paper cover for a transfer.

Red flags include missing or faked bills of lading, shipping documents that do not match carrier records, and repeated trade between related parties with no verifiable logistics. It relates to TBML, over-invoicing, and free trade zone abuse. The real test: checking physical movement against independent carrier and customs data, since the documents themselves are fabricated.

Pharming

Scams & social engineering

Pharming redirects users to fake lookalike sites without any bad link, by poisoning DNS or tampering with local host files, so even a correctly typed web address lands on the attacker's page to harvest credentials. It is stealthier than phishing: the URL can look completely legitimate.

Defenses include DNS security like DNSSEC, keeping endpoints clean of host-file tampering, and checking HTTPS certificates. The credentials it harvests typically feed account takeover, so a spike in logins from odd devices after a redirect campaign is a downstream tell.

Phishing

Scams & social engineering

Phishing is deceptive messages, classically email, that pretend to be from a trusted party to trick people into revealing credentials or data or installing malware. It is the most common entry point for account takeover and business email compromise, and modern kits relay logins in real time to capture one-time codes.

Detect and reduce it with email authentication (SPF, DKIM, DMARC), user reporting, and phishing-resistant MFA. Specialized variants include spear phishing, whaling, smishing (text), vishing (voice), and quishing (QR codes).

Phishing-as-a-Service

AI & emerging fraud

These are subscription kits that hand an attacker ready-to-run phishing setups: spoofed page templates, hosting, and live capture of logins and one-time codes. They industrialize credential theft and increasingly proxy the victim's session in real time to defeat one-time passcodes, which feeds straight into account takeover.

Operational signals include logins using freshly stolen credentials, impossible-travel patterns where one account appears in two far-apart places too fast, and odd device or session traits. Phishing-resistant login, like passkeys, and behavioral monitoring matter more than user training alone. The weak spot is leaning on education to stop theft that now happens live, mid-session, faster than a user can react.

Phonetic matching

Sanctions & screening

Phonetic matching matches names by how they sound rather than how they are spelled, using algorithms like Soundex or Metaphone to catch transliteration and spelling variants of the same name. Names rendered inconsistently across scripts can look different on paper but sound the same.

The tradeoff is sound-alike collisions with unrelated common names, which generate false positives. Operators usually combine it with fuzzy and token-based matching and tune it per language, since phonetic rules depend on the language. Applying one language's phonetic rules everywhere backfires, both missing real variants and creating noise in others.

Pig butchering (sha zhu pan)

Scams & social engineering

Pig butchering is a long con that slowly fattens the victim over weeks or months, mixing romance or friendship with a fake investment, usually crypto, before a big coordinated drain. The name refers to fattening the pig before slaughter. The slow trust-building leads to very large losses.

It typically runs out of organized scam compounds using trafficked labor, with fake trading dashboards showing gains and withdrawals blocked pending fees or taxes. Investigative signals include prolonged grooming, escalating crypto deposits, and cash-out through mules or exchanges. It overlaps with romance baiting and investment scams.

Placement

Money laundering

Placement is the first laundering stage, getting dirty cash into the financial system, and it is generally the riskiest and easiest to detect because bulk cash has to physically enter somewhere.

It appears as large or structured cash deposits, cash-heavy business flows, purchases of monetary instruments, and casino or currency-exchange activity. It relates to structuring, smurfing, and cash-intensive businesses. Because placement is the launderer's hardest step, strong cash-handling and deposit monitoring give the best early signals in the whole laundering cycle.

Politically Exposed Person (PEP)

Due diligence & onboarding

A PEP is someone entrusted with a prominent public function, along with their relatives and close associates, carrying raised corruption and bribery risk and usually triggering enhanced due diligence including source-of-wealth checks. Their access and influence create opportunities to move illicit money.

PEP status is a risk indicator, not proof of wrongdoing, so blanket refusal or exit is discouraged in favor of risk-based handling. Watch for two traps: stale PEP status left in place after someone leaves office, and hidden PEP exposure routed through connected parties. The point is to scrutinize, not to shun; and to keep looking past the named person to the people around them.

Ponzi scheme

Fraud types

This is an investment fraud that pays supposed returns to earlier investors out of later investors' money, not from any real profit. It needs a constant flow of new money to survive. It looks like a winning fund right up until it collapses.

Tell-tale signs are suspiciously steady above-market returns, trouble withdrawing funds, and a vague or secretive strategy. On the banking side, watch for one entity collecting many investor deposits and paying selective redemptions with no real revenue behind it. It differs from a pyramid scheme because returns are not recruitment-driven, and it often rides on affinity fraud.

Port-out fraud

Scams & social engineering

Port-out fraud is moving a victim's phone number to a carrier or SIM the fraudster controls, so text one-time codes and calls route to the attacker and open the door to account takeover. So many accounts still rely on SMS codes for security.

It is a form of number hijacking, close to SIM swap but done through carrier porting. Red flags include suddenly losing mobile service and failed logins. Reduce it with a carrier port-freeze PIN and by moving off SMS codes to app-based or phishing-resistant authentication.

Pre-authorization

Card & payment fraud

A pre-authorization is a temporary hold on a cardholder's funds to confirm the card is valid and money is available before the charge is finalized. For fraud, those small holds are a low-friction way to test stolen cards.

A spike in pre-auths without matching final charges can mean someone is card-testing. Stale or uncaptured holds also generate customer complaints. Keep an eye on the ratio of authorizations to captures, and treat a burst of pre-auth-only activity as a card-testing signal.

Precision

Detection & metrics

This is, of the items you flagged, the share that are truly fraud. It is a core read on how clean your alerts are. High precision means analysts waste little time chasing false alarms.

But chasing precision alone makes you conservative and lets fraud through, which is why it is always read with recall, its coverage counterpart. Precision is also sensitive to base rates: when fraud is rare, even a strong model shows modest precision, because a few false alarms weigh heavily against few real catches. So judge precision against your actual fraud prevalence, not a generic benchmark, or you will punish a good model for a hard population.

Predicate offense

Money laundering

A predicate offense is the underlying crime that generates the money later laundered, such as fraud, drug trafficking, corruption, or tax evasion. In most regimes it is a required element to charge money laundering at all.

In practice, identifying or reasonably inferring the predicate strengthens suspicious activity report narratives and supports the suspicion of illicit origin. It relates to proceeds of crime and self-laundering. Jurisdictions differ on which offenses qualify and whether a foreign crime counts, which shapes both reporting and whether a case can be prosecuted.

Presentation attack

Identity verification

A presentation attack shows a spoof to the camera, like a printed photo, a cutout, a silicone mask, or a screen replay, to beat a biometric check and impersonate someone. It is the most direct way to attack a face or fingerprint capture.

It is the physical-lens counterpart to an injection attack, and it is the main threat liveness and PAD are built to stop. Sophistication ranges from crude printouts to high-resolution replays and 3D masks, so match the strength of your defenses to how much value is at stake.

Presentation attack detection is technology that catches spoofs during biometric capture, deciding whether the subject is a live, genuine person or a fake artifact. It is the measurable defense against masks, photos, and screen replays.

It is often benchmarked against defined attack levels and reported as a spoof-detection rate paired with how often it wrongly rejects real users. PAD handles artifacts held to the lens but not injection attacks that bypass the camera, so cover both threat classes and revalidate as new spoof methods appear.

Pretexting

Scams & social engineering

Pretexting is building a fake but believable scenario and identity, an auditor, IT support, a vendor, or a new executive, to persuade a target to hand over information or take an action. It is researched and interactive, building rapport over one or more contacts rather than blasting out generic lures.

It underpins voice phishing, business email compromise, and help-desk account takeover. Defenses are strict identity-verification procedures and callback policies that no plausible story is allowed to bypass, no matter how convincing the caller sounds.

Privacy coin

Crypto & blockchain crime

A privacy coin is a cryptocurrency with anonymity built into the protocol, like Monero or Zcash, using tools such as ring signatures, stealth addresses, or zero-knowledge proofs to hide the sender, receiver, and amount. That design severely limits or defeats on-chain tracing, so its use in a flow is a notable risk flag.

Many exchanges delist or restrict these coins over AML concerns. Investigators often go blind once funds enter a privacy coin and have to rely on the transparent entry and exit points around it, such as where fiat came in or out. Do not assume you can trace through it; usually you cannot.

Privacy wallet

Crypto & blockchain crime

A privacy wallet is built with obfuscation baked in, such as integrated CoinJoin, coin control, or automatic mixing, to break the traceability of its users' transactions. While legitimate for privacy, it is also used to launder funds, so activity involving a known privacy wallet usually raises a wallet's risk score.

Analysts treat funds that pass through one as lower-confidence and lean on the surrounding context and the wallet software's known behavior to read the flow. The nuance is the same as with mixers: privacy and laundering look alike, so judge the full picture rather than flagging the wallet type alone.

Prize scam

Scams & social engineering

A prize scam promises a prize, gift, or reward that the victim must pay fees or hand over personal data to claim, an advance-fee variant closely related to lottery scams. The prize never arrives and the requests keep escalating.

Tells include unsolicited win notices, pay-to-claim demands, and requests for card or bank details framed as delivery costs. The personal data it harvests often feeds later identity fraud. The core rule: a genuine prize never requires you to pay to receive it.

Proceeds of crime

Money laundering

Proceeds of crime are any property or value that comes directly or indirectly from criminal conduct, including assets bought by converting or reinvesting the original gain. That reach lets laundering and confiscation follow the money into downstream holdings.

Tracing proceeds means following value through conversions and mixing, not just the original cash. It relates to dirty money, the predicate offense, and integration. Note the indirect limb: assets several steps removed from the crime can still count, which is central to asset-tracing and recovery work.

This is rigging the purchasing process through kickbacks, bid rigging, splitting purchases to dodge approval limits, phantom vendors, or false invoicing, usually with insiders and suppliers working together. It corrupts spending at the source and can run for years.

Signals include a vendor winning suspiciously often, bids clustered just under limits, purchases split to avoid approvals, and links between employees and vendors. Detect it with spend analytics, vendor-master validation, bid-pattern analysis, and segregation of duties. It is a core category of occupational fraud and overlaps with vendor and invoice fraud.

Professional money laundering is done by specialist third parties who provide laundering as a commercial service, bringing expertise, reusable infrastructure, and multi-client scale rather than cleaning their own money.

They surface through shared accounts, entities, and corridors linking unrelated criminal groups, and through structures too sophisticated for a lone offender. It relates to money laundering as a service and mule networks. Going after the professional enabler disrupts many crimes at once, so investigations prioritize the shared infrastructure over isolated transactions.

Proliferation financing

Terror & proliferation

Proliferation financing is providing funds or financial services for making, buying, or moving weapons of mass destruction and their delivery systems, in breach of sanctions and export controls. It is how sanctioned programs get paid for, and it usually hides inside ordinary-looking trade.

It typically travels through trade finance using front companies, dual-use goods, falsified documents, and complex routing to hide the real end user. Screen for sanctioned parties and vessels, watch for dual-use goods and trade-based red flags, and treat it as distinct from, though overlapping with, terrorist financing. The paperwork often looks clean, so the routing and counterparties are where the risk shows.

Promotion abuse

Fraud types

This is exploiting promotional offers, discounts, or credits beyond their intended terms, often at scale through many or fake accounts, referral loops, or reselling promo-priced goods. Every abused offer is real margin lost with no genuine customer gained.

It appears as clusters of accounts sharing devices, payments, or addresses all redeeming the same offer, with little real engagement beyond the promo. Mitigate it with per-identity and per-device limits, linkage analysis, and delaying when the benefit vests. It is closely related to bonus abuse, referral fraud, and multi-accounting.

Provisional credit

Detection & metrics

This is a temporary refund given to a customer while a dispute is investigated, often required within set regulatory timeframes for unauthorized transactions. It protects the customer's cash flow, but it also opens a fraud vector: a bad actor can dispute a legitimate charge to grab the funds before the case is resolved.

Look out for dispute abuse and people who claim provisional credit again and again. A sharp signal for first-party fraud, where the real account holder is the fraudster, is how often provisional credits get reversed later versus made permanent. A high reversal rate means many claims were not genuine, so track that ratio as a health check on your dispute process.

PSD2

Regulation & bodies

PSD2 is the EU's revised Payment Services Directive. It requires strong customer authentication for many electronic payments and forces banks to open account access to licensed third parties through open banking. It reshaped both fraud controls and the payments ecosystem at once.

Strong customer authentication materially cuts certain card-not-present fraud, but it also shifts risk toward authorized push payment scams, where the victim is tricked into approving the payment themselves, and toward account-access abuse. Open banking adds new third-party access points your monitoring must cover. So PSD2 does not remove fraud risk; it moves it, and your controls have to follow where it goes.

Pull payment

Card & payment fraud

A pull payment is one the payee starts by drawing funds out of the payer's account, like a card charge or direct debit, under a mandate or stored card. Handing the payee the power to pull money creates risk of unauthorized debits and mandate abuse.

On the plus side, pull rails give the payer recourse: chargebacks or debit-return rights when they object. Contrast this with push payments, where the payer sends the money. Pull gives the payer more protection but exposes them to card testing and unauthorized debits.

Pump and dump

Fraud types

This is inflating an asset's price, typically a thinly traded stock or crypto token, through coordinated false hype, then selling the built-up position into the fake demand before the price crashes, leaving latecomers with losses. It is market manipulation that can move real money through your accounts.

Signals include coordinated promotion, abnormal volume and price spikes in illiquid assets, and concentrated selling by early holders. Detection uses market-surveillance analytics, social-media monitoring, and trading-pattern analysis. It is a form of securities and market-manipulation fraud.

Purchase scam

Scams & social engineering

A purchase scam takes payment for goods or services that are never delivered, typically through fake marketplace listings, bogus online shops, or offers too good to be true, often pushing payment off-platform. It is one of the biggest authorized push payment scam categories by volume.

Red flags include brand-new sellers, unusually low prices, requests to pay by bank transfer outside buyer protection, and pressure to act fast. It overlaps with authorized push payment fraud and non-delivery disputes. Paying outside a platform's protection is the moment the victim loses recourse.

Push payment

Card & payment fraud

A push payment is one the payer starts by sending money to the payee. It is the basis of most real-time transfers and of authorized push payment (APP) fraud. The payer authorizes and initiates the transfer themselves.

Once funds land there is usually little recourse, which is exactly what scammers exploit by tricking victims into sending money. Detection moves to before the send: behavior and payee-risk signals, plus catching mule accounts on the receiving end. Contrast with pull payments, which carry chargeback or return rights.

Pyramid scheme

Fraud types

This is a recruitment-driven scheme where people earn mainly by signing up new members, not by selling a real product. Returns depend on endless recruiting and collapse when it stalls. Most participants lose money by design.

Keep it separate from legitimate direct sales, which have real end-customer revenue, and from Ponzi schemes, where returns come from new investors rather than recruitment. On the payments side, watch for many participants paying an upline entity and payout structures tied to headcount. It is often intertwined with affinity fraud.

Q

1 términos

Quishing

Scams & social engineering

Quishing is phishing through malicious QR codes, printed on stickers placed over legitimate ones or embedded in emails, that send the victim to a credential-harvesting or malware site. QR codes hide the real destination and often slip past email link scanners, which is why attackers like them.

Reduce it by previewing the decoded URL before opening, treating unexpected QR prompts on parking meters, invoices, or emails with suspicion, and applying the same anti-phishing checks to the page it lands on as you would any link.

R

37 términos

Ransomware

Crypto & blockchain crime

Ransomware is malware that encrypts a victim's data or locks their systems and demands a ransom, almost always in crypto, for the key to unlock it, often paired with stealing data too for double extortion. Payments to sanctioned actors carry prohibition risk on top of the loss itself.

The good news for investigators is that ransom payments leave a traceable on-chain trail. Compliance teams screen destination addresses against known ransomware and sanctions clusters, then trace the money through mixers and exchanges toward cash-out points. Paying a sanctioned group can turn a ransom into a separate legal violation, so tread carefully.

Ransomware-as-a-service

Crypto & blockchain crime

Ransomware-as-a-service is a criminal business model where developers build and maintain the ransomware and lease it to affiliates who run the attacks, then split the proceeds. It lowers the skill needed to attack, which is why one strain can show up across many unrelated victims.

On-chain, it appears as ransom payments splitting between affiliate and operator wallets. Investigators use that split pattern to attribute activity and map the network behind a strain. Do not treat each attack as separate; the shared infrastructure and payment splits are what tie them together and reveal the operation.

Real estate laundering

Money laundering

Real estate laundering puts dirty money into property, often through shell companies, nominees, or all-cash deals, to fold large sums into a stable, appreciating asset.

Red flags include purchases well above or below market value, cash or third-party funding, quick resale to add layers, and holding title through opaque corporate structures. It relates to integration, shell companies, and luxury asset laundering. The catch: closing agents and lenders may not see the full source of funds, so tracing where the down payment came from and who really owns the title is essential.

Real-time monitoring

Monitoring & investigations

Real-time monitoring evaluates a transaction as it happens, before or at the moment of authorization, so the institution can decline it, hold it, or add a step-up check while the payment is still in flight. For fraud and sanctions, catching it after settlement is too late; the money is already gone or the breach already made.

It demands low-latency rules and models, and it forces a trade-off: too aggressive and you create friction and false declines that anger real customers. Contrast it with batch monitoring, which is better for pattern-based AML work that does not need to block anything in the moment.

Real-time payment fraud

Card & payment fraud

Real-time payment fraud hits instant rails like FedNow or RTP, where money settles for good within seconds. That finality shrinks the time to detect and step in to nearly zero, and recall after the fact is rarely possible.

Controls move upstream to pre-transaction scoring, checking payee and mule-account risk, and behavior checks. It clusters around authorized push payment scams and fast onward movement of received funds. On these rails, watching inbound funds and spotting mule accounts on the receiving side matters as much as checking the sender.

Recall

Detection & metrics

This is, of all the fraud that actually happened, the share your system caught. It is the coverage counterpart to precision and a direct proxy for how much fraud you stop. It answers the question that keeps managers up at night: how much are we missing?

Raising recall usually means flagging more aggressively, which lowers precision and raises review cost and friction, so the two are tuned together against your loss appetite. The hard part: recall is hard to measure cleanly because the fraud you never caught is invisible. So real recall often looks better on paper than it is in the losses, since the denominator hides your unknown misses.

Recordkeeping

Monitoring & investigations

Recordkeeping is holding on to the records the law requires, such as CTR and SAR support, funds-transfer details, and CDD documents, for a mandated period so activity can be rebuilt later. In the US, many BSA records must be kept for five years. A program is only as good as its ability to prove what it saw and did.

Confirm records are complete, quickly retrievable, and protected from being altered. Being unable to reconstruct a transaction or a decision when a regulator or law enforcement asks is a serious and surprisingly common deficiency; the underlying work does not count if you cannot produce it.

Recovery

Detection & metrics

This is funds you get back after a fraud or loss event, through clawbacks, reversals, disputes won, or restitution. It offsets gross losses to give the net figure that actually hits the profit-and-loss statement, so tracking recovery rate is how you size your true exposure rather than your worst-case one.

Recovery is usually partial and slow, and it varies sharply by payment rail and by how fast you spotted the fraud. Money moved over an instant rail is often gone; a slower rail may still be clawed back. That is exactly why fast detection and the ability to freeze funds are core to limiting net loss, since speed is what makes recovery possible at all.

Recovery scam

Scams & social engineering

A recovery scam targets people who have already lost money to a scam, with a false promise to get their funds back for an upfront fee, sometimes posing as law enforcement, a regulator, or a recovery firm. It re-victimizes known victims, whose contact details often circulate on scammer lists.

Red flags include unsolicited recovery offers, demands for advance payment, and requests for more account access. Legitimate authorities do not charge victims to recover funds, so any upfront fee to get your money back is itself the scam.

Red flag

Monitoring & investigations

A red flag is an indicator that raises the possibility of laundering, fraud, or sanctions risk, such as funds passing rapidly straight through an account, structuring, mismatched ownership, or activity that does not fit the customer's profile. Red flags drive scenario design, analyst judgment, and escalation; they are how you turn vague concern into something you can act on.

But a red flag is a signal, not proof. Context and corroboration decide whether it adds up to reportable suspicion. Keep red-flag lists current as typologies change, and avoid mechanically filing on a single indicator without doing the analysis behind it.

Referral fraud

Fraud types

This is gaming referral or refer-a-friend programs with fake accounts, self-referrals, or circular referral rings to harvest rewards without bringing in real customers. You pay incentives for growth that never actually happened.

Red flags include the referrer and referee sharing devices, IPs, or cards, bursts of signups with no real activity, and rewards cashed out immediately. Mitigate it by linking devices and payment methods, holding rewards for a waiting period before they vest, and scoring the quality of referred users. It is closely related to bonus abuse, promotion abuse, and affiliate fraud.

Refining

Money laundering

Refining swaps small dirty bills for larger ones, or for instruments like cashier's checks, to shrink the physical bulk of cash and make it easier to move. It is a step near placement, before or during entry into the system.

It shows up as frequent large-denomination exchanges, buying cashier's checks or money orders with small bills, and currency-exchange activity that does not fit the customer. It relates to placement, structuring, and bulk cash smuggling. Refining comes before movement, so it is an early sign that someone is preparing bulk cash for placement or transport.

Refund fraud

Fraud types

This is abusing refund or return processes to get money or goods you are not owed. It includes claiming items never arrived, returning empty boxes or swapped goods, and exploiting instant-refund policies. Generous refund rules are easy to turn into a payout machine.

It surfaces as customers with unusually high refund rates, claims that clash with delivery or weight evidence, and organized refunding-as-a-service activity. Mitigate it with delivery and inspection evidence, refund-abuse scoring, limits on serial refunders, and blocklisting. It overlaps with return fraud, buyer fraud, and chargeback abuse.

Refund scam

Scams & social engineering

A refund scam is a fraudster posing as customer support or a vendor claiming the victim is owed a refund, then engineering a fake overpayment so the victim sends money back or grants remote access to their account. It combines impersonation with remote-access tricks and often targets older victims.

Tells include unsolicited refund notices, requests to install screen-sharing tools, and a staged overpayment the victim is pressured to return. It overlaps with tech-support and remote-access scams. No real refund requires you to send money back or share your screen.

Regulation E

Detection & metrics

This is the US rule covering electronic fund transfers and consumer liability for unauthorized transactions. It sets error-resolution timeframes and pushes most unauthorized-transaction losses onto the institution, not the customer. It directly shapes your dispute operations, your provisional-credit timing, and where fraud losses ultimately land.

A recurring nuance is scam payments the customer was tricked into authorizing themselves. These often fall outside the unauthorized-transaction protections, so they are handled differently. Mislabeling a dispute, calling an authorized scam payment unauthorized or the reverse, can create both compliance problems and wrong loss attribution, so getting the classification right matters as much as meeting the deadlines.

Regulation Z

Detection & metrics

This is the US Truth in Lending rule covering credit, including billing-error and dispute rights for credit-card transactions. It sets the framework and timelines for how card disputes and chargebacks get handled on the credit side, shaping liability and what remedies the customer gets.

For fraud teams the practical intersection is telling true unauthorized-use disputes apart from friendly fraud, where a real cardholder disputes a purchase they actually made, and ordinary billing disputes. Each carries different handling, liability, and loss attribution. Lumping them together backfires; misclassify a dispute and you both mishandle the case and book the loss in the wrong place, which distorts your numbers.

Regulatory reporting

Monitoring & investigations

Regulatory reporting is submitting the filings the law requires, such as SARs, CTRs, and other threshold or cross-border reports, to the right authority in the required format and timeframe. It is the core output of a monitoring program; everything upstream exists to produce accurate, on-time filings.

It is also a frequent source of findings when reports are late, incomplete, or wrong. Track filing deadlines, check data quality and completeness before submission, and keep proof that you filed. Recurring timeliness failures are among the most common triggers for enforcement, because they are easy for an examiner to see and hard to explain away.

Rejection

Sanctions & screening

Rejection is declining and returning a transaction that has a sanctioned nexus but does not require blocking, so the funds are not processed but also not held, unlike blocking where property is frozen and reported. Choosing the wrong action is a common and costly mistake.

Which one applies depends on the specific prohibition, the parties, and the jurisdiction. Rejected transactions still carry recordkeeping and, in some regimes, reporting obligations, so they cannot just be dropped silently. Rejecting when the rules required blocking lets funds you were supposed to freeze flow back out the door.

Relatives and close associates (RCA)

Due diligence & onboarding

RCAs are the family members and close business or personal associates of a PEP who inherit related corruption risk and so fall within screening and, where relevant, enhanced due diligence. Illicit proceeds are often routed through RCAs precisely to put distance between the money and the PEP.

That makes them a key detection focus, not an afterthought. The practical difficulty is completeness: mapping the full network of associates is hard, and gaps here are a common way PEP-linked flows slip through. If you only screen the official and miss the people around them, you are watching the front door while the money leaves through the side. The network is the risk.

Remote access scam

Scams & social engineering

A remote access scam convinces a victim to install screen-sharing or remote-control software, often under a tech-support, refund, or bank-security pretext, then operates their accounts and payments directly or coaches them through transfers. Because the actions come from the victim's own trusted device, they can slip past device and location fraud checks.

Watch for remote-access tool signatures during sessions and coached, out-of-pattern transfers. It overlaps with tech-support and refund scams. A legitimate company will never need to take control of your device to help you.

Reporting entity

AML programs

This is a regulated business required to file AML reports, such as SARs or STRs, currency transaction reports, and threshold or large-cash reports, to the relevant authority. The exact report types and triggers vary by jurisdiction.

Multinational operators have to map their obligations regime by regime rather than assume one setup covers all. A common pitfall is nailing one obligation, say SAR filing, while missing automatic threshold-based reports that need no suspicion at all, just a dollar amount crossing a line. Those mechanical reports are easy to overlook precisely because they do not depend on anyone flagging something as odd.

Reshipping fraud

Fraud types

This is recruiting people, often through fake work-from-home job scams, to receive goods bought with stolen cards and forward them abroad. It launders physical goods so the proceeds are harder to trace. It turns a card fraud into an untraceable shipment.

The reshipper is usually an unwitting mule whose own identity may also get abused. On the merchant side it shows as billing and shipping mismatches, freight-forwarder or reshipper addresses, and orders going to addresses linked to many cards. Mitigate it with address-reputation data, AVS analysis, and shipping-linkage checks.

Restitution

Detection & metrics

This is court-ordered repayment to victims by a convicted offender, a legal remedy that sits downstream of law-enforcement action. It is one channel in the recovery picture, but a slow and often partial one, so it rarely factors into day-to-day loss forecasting even though it can offset losses eventually.

It is mostly relevant to larger cases and organized fraud, where prosecution actually happens and amounts are big enough to pursue. Treat it as a possible late offset alongside clawbacks and reversals, not as money you can count on. The mistake is baking expected restitution into forecasts; most cases never reach a conviction, and even when they do, collection is uncertain.

Return fraud

Fraud types

This is abusing return policies for refunds or credit you are not owed. It includes wardrobing, meaning using an item then returning it, returning stolen or counterfeit goods, receipt fraud, and price-switching. Returns are high-volume, so abuse hides in the noise.

It appears as high return rates, returns without valid proof of purchase, serial returners, and returned items that do not match what was sold. Mitigate it with return-authorization tracking, serial-returner scoring, checking items on receipt, and policy limits. It overlaps with refund fraud and organized retail crime.

Reusable KYC

Due diligence & onboarding

This is a verified identity credential a customer can reuse across multiple institutions, cutting repeat onboarding friction by relying on verification done elsewhere. It improves customer experience, but it shifts risk in the process.

The relying institution inherits another party's verification quality and timeliness, for better or worse. Confirm what standard the original check met, how fresh it is, and where liability sits, because accepting a stale or weaker credential imports its gaps as your own. Convenience is not the same as assurance; if you never checked how good the original verification was, you have just adopted someone else's shortcuts. Reuse the credential only when you trust what stands behind it.

Reverse money laundering

Money laundering

Reverse money laundering moves clean, legitimate funds to finance crime or terrorism. It is the inverse of classic laundering, so the concern is where the money is going and why, not where it came from.

It defeats source-of-funds checks because the money starts clean. Red flags include otherwise-normal accounts sending funds to high-risk regions, charities or intermediaries tied to a sanctioned or extremist nexus, and small structured outflows to conflict zones. It relates to terrorist financing. Amounts are often small, so behavior and destination matter more than transaction value.

Risk appetite

AML programs

This is how much and what kind of financial-crime risk a firm is willing to take on to meet its goals. It works best stated in concrete, measurable terms rather than vague words. Appetite is meant to guide real decisions, not decorate a policy.

It should translate into hard operating limits, such as customer types you will not take, geographies you exclude, and monitoring thresholds. That way front-line choices line up with what the board actually intended. Trouble comes when stated appetite and real onboarding pull apart, or when the appetite is so vague you cannot test or enforce it. An appetite you cannot measure against is just a slogan.

Risk score

Detection & metrics

This is a number estimating how risky an entity, transaction, or session is, blending model output and signals into one value that drives decisioning. It turns many inputs into a single thing you can set thresholds on and act quickly.

Its usefulness lives in calibration and in the thresholds and actions you map to it, not in the number itself. Beware drift and population shifts that change what a given value means over time, so last quarter's threshold no longer means the same thing. Monitor how scores map to real outcomes; a distribution that looks stable can still hide accuracy that is slowly slipping, which is what to avoid.

Risk signals

Device & behavioral

Risk signals are the individual data points across device, behavior, network, and identity that feed a risk model or rules engine, like an emulator flag, impossible travel, a throwaway email, or an abnormal speed. These are the raw material every fraud decision is built from.

Each one is weak and noisy alone but gains power in combination, and its value depends on coverage, freshness, and how it correlates with others. Guard against over-weighting any single signal, and against fraudsters who tune their behavior to suppress the obvious ones.

The RBA is the core FATF principle of putting AML effort where the risk is: more scrutiny on higher-risk customers and activity, less on those you can show are genuinely lower risk. You cannot treat everything as high risk, so you have to aim.

Done well, it concentrates effort where it counts. Done poorly, it becomes an excuse for under-controlling. You must be able to evidence the reasoning behind each risk-based call, because an RBA with no documented rationale reads to examiners as arbitrary, not risk-based. Lower scrutiny is defensible only when you can show why the risk was lower; otherwise it just looks like cutting corners.

Risk-based decisioning

Detection & metrics

This is driving approve, decline, or step-up outcomes from a risk score rather than fixed rules alone, so the friction and scrutiny scale with the assessed risk. It lets you pass low-risk users smoothly while concentrating checks on high-risk activity, which lifts both conversion and fraud capture at once.

It depends on well-calibrated scores and clear thresholds for what each score triggers. It is normally layered with hard-policy rules for cases that must always pass or fail no matter the score, like a sanctions hit. The trade is nuance against control. Get the calibration wrong and the whole approach misfires, either waving through risk or blocking good users, so the score quality is everything.

Romance baiting

Scams & social engineering

Romance baiting is the industry-preferred term for romance-led investment scams. It frames the crime around the method instead of blaming the victim, and it overlaps heavily with pig butchering. Naming it this way keeps the focus on the fraud, not the person deceived.

A fake romantic relationship builds trust before the target is steered into a fake, usually crypto, investment. Investigative signals mirror pig butchering: prolonged grooming, an online-only partner, and escalating crypto deposits with blocked withdrawals. It is related to romance scams and investment scams.

Romance scam

Scams & social engineering

A romance scam is a fraudster faking a romantic relationship, usually entirely online, to manipulate a victim into sending money through invented emergencies, travel costs, or investment opportunities. Emotional manipulation makes victims willing to pay and often protective of the scammer, which makes intervention hard.

Tells include a partner who never meets or video-calls, escalating money requests, and steering toward crypto or gift cards. It often evolves into romance baiting or pig butchering and is a common driver of authorized push payment losses.

Round-tripping

Money laundering

Round-tripping cycles money out and back through offshore entities so it looks like foreign investment or a legitimate inflow. Domestically sourced dirty money returns wearing the label of foreign capital.

Red flags include investment from jurisdictions tied to the same owner, circular flows with no real commercial change, and inbound capital that matches earlier outbound transfers. It relates to loan-back schemes, mirror trading, and integration. The returning funds look like clean outside investment, so the key check is linking the outbound and inbound legs to a common controller.

Rug pull

Crypto & blockchain crime

A rug pull is a crypto scam where project insiders abandon a token and cash out its value, usually by yanking liquidity, minting and dumping their own holdings, or disabling sells, leaving everyone else with worthless or unsellable coins. It is a common DeFi fraud and overlaps with exit scams.

Warning signs include insiders holding a big chunk of the supply, liquidity that is unlocked or removable, unaudited or malicious contract functions, and anonymous teams. Response focuses on tracing the extracted funds to cash-out venues. Trusting hype over the contract is the mistake; the code and token distribution tell the real story.

Rules engine

Monitoring & investigations

The rules engine is the system component that runs transactions and behavior against configured logic and thresholds to generate alerts. It is where scenarios, thresholds, and typologies actually get turned into working detection. Its configuration directly drives your alert volume, false-positive rate, and coverage, for better or worse.

Make sure changes are governed, tested with backtesting plus above- and below-the-line methods, and logged in the audit trail. Undocumented rule changes and untuned thresholds are frequent causes of both missed activity and analyst overload. A quiet, unreviewed edit to the engine can silently switch off detection nobody notices for months.

Rules-based detection

Detection & metrics

This is detection driven by explicit, human-written logic and thresholds, for example decline if a signal crosses a set limit. Its strengths are transparency, instant deployment, and precise control, which is why it handles hard policy and known patterns and pairs well with models.

The downsides are brittleness against new or adaptive fraud, since a rule only catches what it was written for, and rule sprawl that grows hard to maintain. The trade is control against flexibility. Rules need regular review: a stale rule quietly drives false positives or goes blind to a new tactic, so an unmaintained rulebook slowly turns from an asset into a liability.

S

50 términos

Safe account scam

Scams & social engineering

A safe account scam convinces a victim their account is under attack and instructs them to move funds to a supposedly safe account that the fraudster actually controls, usually after a bank- or police-impersonation setup. The victim authorizes the transfer themselves, making it an authorized push payment scam that unauthorized-transaction controls miss.

Red flags include urgent instructions to move money to protect it and demands for secrecy. No legitimate bank or agency ever asks a customer to move money to a safe account, so that request alone confirms the scam.

Sanctioned address

Crypto & blockchain crime

A sanctioned address is a crypto address specifically placed on a sanctions list, or otherwise tied to a sanctioned person or entity, which makes dealing with it prohibited for regulated parties. A single confirmed hit can require blocking and reporting, not just declining.

Both directly listed addresses and ones clustered to a sanctioned actor count, since real ownership can reach well beyond the published address. Screening has to catch direct and indirect exposure alike. The gap to close is name-only or list-only checks that miss the wider cluster, letting a sanctioned party slip through on an address that was never explicitly listed.

Sanctions

Sanctions & screening

Sanctions are restrictive measures imposed by governments or international bodies against targeted individuals, entities, sectors, or jurisdictions to pursue foreign-policy, security, or law-enforcement aims. They span asset freezes, dealing bans, trade restrictions, and full embargoes. They set hard prohibitions with serious penalties for breaches, including strict-liability exposure in some regimes.

Strict liability means you can be penalized even without intent, so getting it right is not optional. Compliance requires screening against the applicable lists, knowing which regimes apply to you, and reconciling differences across US, EU, UK, and UN measures. Assuming one jurisdiction's rules cover everything you do is where programs slip.

Sanctions evasion

Sanctions & screening

Sanctions evasion is the deliberate use of tricks to get around sanctions, including front and shell companies, intermediaries and nominees, transshipment, hidden ownership, mislabeled trade, and crypto or alternative payment channels. It is built specifically to defeat name-only screening.

So detection depends on beneficial-ownership analysis, network and behavioral patterns, and geographic and trade-flow red flags rather than just matching names. Typical indicators include sudden routing changes, opaque ownership, dual-use goods heading to high-risk regions, and counterparties clustered around a sanctioned nexus. A clean name-screen result cannot be trusted here, since evasion is designed to make the names look fine.

Sanctions screening

Sanctions & screening

Sanctions screening is the process of checking customers, counterparties, and transactions against sanctions lists to prevent prohibited dealings, covering onboarding, ongoing rescreening, and real-time transaction filtering. It is the main control standing between you and a prohibited transaction.

Its effectiveness rests on list coverage and freshness, data quality, and matching-threshold tuning that balances false positives against false negatives. It must also account for indirect exposure via the 50 Percent Rule and evasion structures. The weakness is relying on name-only checks, which miss ownership chains and front companies, letting a blocked party through on a name that never appears on a list.

SAR narrative

Monitoring & investigations

The SAR narrative is the written heart of a SAR that tells the FIU and law enforcement, in plain language, the who, what, when, where, why, and how of the suspicious activity, including amounts, dates, accounts, and why it looks suspicious. A strong narrative stands on its own and can turn a filing into a usable lead.

Keep it chronological and specific, and state clearly what you did and did not determine. Avoid boilerplate and jargon, quantify the activity, and never tip off the subject. A weak, vague narrative can waste an otherwise solid investigation, because the reader cannot see what you saw.

Scam

Scams & social engineering

A scam is a deception that manipulates a victim into willingly handing over money or information. That consent is what sets it apart from unauthorized fraud, where the victim never agrees. When the victim authorizes the action, traditional unauthorized-transaction controls simply do not fire.

Detection instead needs behavioral, contextual, and payee-risk signals plus direct intervention with the victim. It is the umbrella category over romance, investment, impersonation, purchase, and other social-engineering losses. Correctly labeling a case as scam versus unauthorized drives both the investigation and who bears the loss.

Scam compound

Scams & social engineering

A scam compound is a physical facility, often staffed by trafficked and coerced workers, where organized crime runs scams like romance, investment, and pig butchering at scale. It industrializes scripted, multi-account, cross-border operations rather than relying on lone actors.

Also called a fraud factory, its fingerprint for operators is coordinated networks and mule chains, not one-off scammers. It carries a human-trafficking dimension that shapes the law-enforcement and reporting response, so cases can involve victims on both ends: those scammed and those enslaved.

Scenario

Monitoring & investigations

A scenario is a configured detection rule or model aimed at one specific typology, such as rapid movement of funds, structuring, or exposure to a high-risk country, defined by its parameters and thresholds. Scenarios are the building blocks of a monitoring program. Each one should map back to a real risk identified in your risk assessment, or it has no reason to exist.

Document why each scenario exists, tune its thresholds with above- and below-the-line testing, and retire or revise ones that no longer match current risk. Unmapped scenarios and stale scenarios that chase outdated behavior are both common findings.

SEC

Regulation & bodies

The SEC is the US Securities and Exchange Commission, the federal regulator of securities markets, issuers, exchanges, and investment firms. It enforces against fraud, disclosure failures, and market abuse, and oversees the self-regulatory organization FINRA. It sets and enforces expectations relevant to AML in the securities sector.

If you are at an SEC-regulated firm, track its enforcement actions on issues such as microcap and crypto-securities fraud, which frequently intersect with AML monitoring and suspicious-trading detection. Its cases often show where securities fraud and money laundering overlap, which is exactly where your monitoring needs to be sharp. Watch its actions as a guide to emerging risk.

This is the compliance and risk-management functions that set financial-crime policy, define standards, and independently oversee and challenge the first line's risk-taking. They own monitoring frameworks, give guidance, and escalate issues, but they should not own the day-to-day business risk itself. It is the check on the people chasing revenue.

A common structural weakness is a second line without the authority or resources to genuinely push back on the business, so it ends up advisory in name but powerless in practice. If compliance can only suggest and never say no, the challenge is fiction. Real oversight needs teeth, not just a seat at the table.

This is fraud enabled by an account holder who knowingly lets someone else use their identity or account, such as being recruited as a money mule or sharing credentials for a cut. It blurs the line between victim and accomplice, which muddies both liability and detection.

Signals include account behavior that does not fit the stated owner, money coming in from unknown senders followed by a fast cash-out, and links to known mule networks. It is central to mule detection and often overlaps with first-party and third-party fraud. Treat sudden pass-through activity on a quiet account as a warning sign.

Sectoral sanctions

Sanctions & screening

Sectoral sanctions are targeted restrictions on specific sectors or activities of a sanctioned economy, like energy, defense, or finance, that prohibit only certain defined dealings, such as particular debt or equity, rather than blocking a party entirely. They are narrower and more nuanced than a full block.

Compliance turns on the exact prohibited activity, instrument, and tenor, not just whether a name matches. This cuts two ways: treating a sectoral target like a fully blocked party over-restricts legitimate business, while the reverse misses that only particular transaction types are barred and processes one that was prohibited.

Securities fraud

Fraud types

This is deception in the issuing or trading of securities, including misrepresentation, insider trading, market manipulation, and pump-and-dump schemes. It distorts markets and often moves large, hard-to-trace sums.

Detection uses trade surveillance, disclosure review, and analysis of price and volume moves that do not match the news. In financial monitoring it can surface as unexplained trading proceeds, layering of gains, or accounts used to move profits from manipulated assets. It is a source crime for money laundering and overlaps with investment fraud and market abuse.

Segmentation

Detection & metrics

This is grouping customers or activity by shared risk traits, such as product, channel, geography, or how long they have been with you, so controls and thresholds fit each group. One global threshold over-blocks safe segments while under-protecting risky ones, so segmenting lets you lift both fraud capture and customer experience at the same time.

The tradeoff is complexity and thinner data per segment. Slice too finely and each group lacks the volume to tune or monitor reliably, so your thresholds get noisy and unstable. The skill is cutting the population into groups that are meaningfully different yet still big enough to measure, not chasing ever-smaller buckets.

Self-funded terrorism

Terror & proliferation

Self-funded terrorism is an attack financed by the actor's own lawful income, savings, benefits, or petty crime rather than by an organization. It is common in lone-actor and small-cell attacks. The money is clean and small, so it exposes the limits of amount-based transaction monitoring, which is built to catch large or clearly dirty flows.

Because the sums are tiny and the sources look legitimate, do not lean on value thresholds to find it. Look instead for corroborating context, such as purchases of attack-relevant items combined with other intelligence. This typology is a reminder that some of the highest-harm activity leaves the smallest financial footprint.

Self-laundering

Money laundering

Self-laundering is laundering the proceeds of your own crime. In many jurisdictions it is a standalone offense, so the launderer and the underlying criminal are the same person.

The practical effect: in some regimes self-laundering cannot be charged separately, which affects how suspicious activity reports and cases are framed. It relates to the predicate offense, third-party laundering, and proceeds of crime. This is a jurisdictional question: whether self-laundering can be prosecuted on its own directly shapes charging and reporting strategy.

Self-sovereign identity (SSI)

Identity verification

Self-sovereign identity is a model where people hold and control their own verifiable credentials and share only what a given interaction needs, with no central identity authority. It aims to cut repeat KYC and reduce how much personal data is exposed.

It shifts trust to the credential issuers, the revocation system, and how tightly the holder is bound to the credential. Verify issuer reputation and credential status, and require a holder-binding check: possessing a credential is not proof of being its subject.

Selfie capture

Identity verification

Selfie capture collects a live self-portrait as the input for face match and liveness during onboarding or a step-up. It is a prime target: whatever gets injected here flows into every downstream check.

Guard it against uploaded gallery photos, screen replays, and virtual-camera injection rather than trusting the image you receive. Enforce in-session capture, check device and provenance signals, and bind the selfie to the same session as the document so fraudsters cannot stitch a submission together from separate pieces.

Seller fraud

Fraud types

This is when a seller takes payment but never delivers, ships counterfeit or badly misrepresented goods, or lures buyers off-platform to escape protection. It burns buyers and damages trust in the whole platform.

It appears as new sellers with sudden volume, spikes in item-not-received or not-as-described disputes, and pressure to pay off-platform. Mitigate it with seller vetting, payout holds and escrow, dispute monitoring, and delivery verification. It is the merchant-side counterpart to buyer fraud within marketplace fraud.

Session hijacking

Account & access fraud

Session hijacking is taking over an already-logged-in session by stealing or guessing its token, or by intercepting traffic through malware or a man-in-the-middle. The attacker acts as the real user without ever needing the password or MFA.

It overlaps with cookie theft and is dangerous because it sidesteps login-time controls completely. Defend by binding tokens to device and network context, keeping sessions short, requiring reauthentication for risky actions, and revoking sessions when the context looks off. The danger is that a hijacked session can appear legitimate, so watch for sudden changes in device, IP, or behavior mid-session.

Session risk

Device & behavioral

Session risk is the real-time risk score of an active session, computed continuously from its device, behavioral, network, and identity signals. It lets you step up or intervene mid-session, catching takeovers and scams that begin after a clean login.

Because risk keeps changing within a session, especially in remote-access scam scenarios, monitor it continuously rather than scoring only at login, and be ready to challenge or halt an action while it is in flight.

Shelf company

Money laundering

A shelf company is a pre-registered, dormant company sold off the shelf to give a buyer an aged corporate identity with no real trading history. It hands a launderer instant apparent longevity and credibility.

Red flags include an incorporation date long before any activity, immediate high-volume flows right after purchase, and directors or agents that change at the point of sale. It relates to shell companies and beneficial ownership obfuscation. One catch: account age alone reads as low risk, so pair the incorporation history with the timing and pattern of the first real activity to expose the abuse.

Shell company

Money laundering

A shell company is a legal entity with no real operations, staff, or assets, used to hold assets, open accounts, and move funds while hiding ownership.

Red flags include no employees or premises, an address shared with many entities, transactions that do not fit any stated purpose, and pass-through flows with no business reason. It relates to front companies, layered ownership, and ultimate-owner obfuscation. Shells are legal and common for legitimate structuring, so what creates risk is opacity plus unexplained financial activity, not the vehicle itself.

Signal

Detection & metrics

This is a single data point or indicator feeding a risk decision, for example how old a device is, an email address's history, or a velocity count. Signals are the raw material of features, rules, and scores. On its own most any single signal is weak; the power comes from combining them and reading them in context.

Mind coverage gaps, staleness, and correlated signals that add little new lift because they say the same thing. The key point: a single strong hit is usually a reason to investigate, not to auto-decline. Acting on one signal alone drives false positives, so let signals accumulate into a picture before you make the hard call.

SIM swap

Scams & social engineering

SIM swap is hijacking a victim's mobile number by tricking or bribing the carrier into moving it to an attacker-controlled SIM, so text one-time codes and calls reach the fraudster and enable account takeover. It defeats the SMS codes many accounts still rely on for security.

It is often preceded by phishing to gather the personal data needed to pass carrier checks. Red flags include suddenly losing service and a burst of password resets. Reduce it by moving off SMS codes to app-based or phishing-resistant MFA and using a carrier port-protection PIN.

Simplified Due Diligence (SDD)

Due diligence & onboarding

SDD is a reduced level of diligence allowed for customers or products assessed as demonstrably low risk, applying lighter verification and monitoring than standard due diligence. It lets you focus effort where risk is higher, but only when low risk is genuinely evidenced.

It is permitted where low risk can be shown, not assumed, and it never means no diligence or no monitoring. The common pitfall is applying SDD too broadly, or failing to re-assess when a customer's activity outgrows the low-risk basis that justified it in the first place. A customer who qualified for SDD at signup can quietly become one who no longer should. Keep checking that the low-risk assumption still holds.

Sleeper account

Account & access fraud

A sleeper account is one opened on purpose and kept quiet, sometimes running small real transactions to look normal, then switched on later for fraud or laundering once it seems seasoned and low-risk. The patience defeats new-account scrutiny and builds a trusted-looking track record first.

The dormancy is the whole strategy. Detect it by flagging long idle stretches followed by sudden high-value or high-speed activity, especially alongside a changed device, new beneficiaries, or a new funding source. Remember that the early good behavior is bait, so do not let a clean history alone clear the sudden activity.

Smart contract exploit

Crypto & blockchain crime

A smart contract exploit abuses a flaw in contract code, such as reentrancy, integer errors, access-control gaps, or logic bugs, to steal, mint, or misdirect funds beyond what the contract was meant to do. Contracts are immutable and open to all, so an exploit can be irreversible and drain funds in seconds.

It is a leading cause of DeFi losses. Response prioritizes fast tracing of the stolen funds, flagging attacker addresses, and coordinating with off-ramps and bridges to interdict the cash-out. The problem is speed: by the time the exploit is noticed, the money is often already moving to be laundered.

Smishing

Scams & social engineering

Smishing is phishing delivered by SMS or messaging apps, using urgent lures like a failed delivery, a bank alert, or a toll fee, with malicious links to harvest credentials or install malware. Short URLs and the trusted feel of text messages push click rates high, and messages often spoof the sender ID.

Reduce it with awareness, network-level SMS filtering, and never entering credentials through a texted link. It is a variant of phishing alongside vishing (voice) and quishing (QR codes).

Smurfing

Money laundering

Smurfing spreads dirty money across many people and accounts in small amounts to stay under reporting limits, using human helpers called smurfs to make the deposits.

It appears as many individuals depositing similar under-threshold amounts, often at several branches or on the same day, all feeding a common downstream account. It relates to structuring, micro-structuring, and funnel accounts. Each deposit looks unremarkable alone, so detection depends on aggregating across depositors and destinations rather than reviewing single transactions.

Social engineering

Scams & social engineering

Social engineering is manipulating people, rather than breaking technology, into actions or disclosures that compromise security, by exploiting trust, authority, fear, urgency, or greed. It is the common thread behind phishing, pretexting, voice phishing, impersonation, and most scams.

Since the human is the attack surface, defenses combine training, strict verification and callback procedures, and system controls that assume any request could be socially engineered. It is the root technique that most fraud categories build on, so awareness is the single highest-leverage control.

Source of funds (SoF)

Due diligence & onboarding

SoF is evidence of where the specific money in a particular transaction or relationship actually came from, such as a property sale, salary, or business income. It is distinct from overall wealth. It answers a direct question: is this money's story plausible and documented?

Test the explanation against the customer's known profile rather than accepting a stated source at face value. A credible-sounding narrative with no evidence behind it is a red flag, not a clearance. Someone can name a legitimate-sounding source all day; your job is to see whether the paper trail backs it up. If the story and the evidence do not line up, that gap is the finding.

Source of wealth (SoW)

Due diligence & onboarding

SoW is evidence of how a customer built their overall net worth over time, such as a business sale, inheritance, or career earnings. It is central to PEP and high-risk enhanced due diligence. It explains the whole financial picture, not just one transaction.

It is broader than source of funds and harder to satisfy, needing a coherent, documented history rather than the origin of a single payment. The common failure is accepting a plausible narrative with no corroborating evidence, or confusing SoW with SoF and only testing the immediate funds. Understanding where one payment came from is not the same as understanding how someone got rich. For high-risk customers, you need the fuller story, backed by proof.

Spear phishing

Scams & social engineering

Spear phishing is targeted phishing tailored to a specific person or role, using researched personal or company detail to look credible, unlike mass phishing. It commonly aims at finance staff, admins, or privileged users and is a primary route into business email compromise.

Tells include highly relevant context, spoofed or lookalike sender domains, and requests for payments or credentials. Defenses are email authentication, verification procedures, and role-based awareness. Whaling is spear phishing aimed specifically at executives, where the payoff of a success is highest.

The SDN list is OFAC's primary list of individuals, entities, vessels, and, increasingly, crypto addresses whose property is blocked and with whom US persons are generally barred from dealing. It is the central reference for US blocking, and its reach extends via the 50 Percent Rule to unnamed entities that SDNs own.

Screening against it must apply fuzzy and transliteration logic, capture aliases and secondary identifiers, and stay current since OFAC updates it frequently. Exact-match, name-only screening on a stale copy is the failure mode, missing spelling variants, owned-but-unnamed entities, and parties added since the last refresh.

Spoofing

Scams & social engineering

Spoofing is faking identifying data, such as caller ID, sender email, or a domain, so a message or call appears to come from a trusted source. It is an enabling technique across phishing, voice phishing, and impersonation scams, rather than a scam on its own.

Countermeasures depend on the channel: email authentication (SPF, DKIM, DMARC) for email, STIR/SHAKEN for calls, and lookalike-domain monitoring. The core operator rule is simple: displayed identity cannot be trusted without verifying through a separate, known channel.

SSN verification

Identity verification

SSN verification checks a US Social Security number against issuance and identity data to confirm it was actually issued, is internally consistent, and ties to the claimed name and birth date. It is central to catching synthetic identities.

Flag numbers issued to minors or the deceased, one number shared across many identities, and CPNs sold as fake substitutes. A valid SSN on its own is weak proof of a real person, so combine it with credit-header, address, and document checks.

State sponsor

Terror & proliferation

A state sponsor is a government that provides financial, material, or logistical support to terrorist groups. Any activity connected to that country or its state-owned entities carries heightened sanctions and terrorist-financing exposure, and designations such as a state-sponsor-of-terrorism list bring broad prohibitions and secondary-sanctions risk that can reach even non-US firms.

Treat exposure to designated states as high risk in screening and enhanced due diligence. Watch for evasion through front companies and routing through third countries to disguise the real origin or destination. Monitor for changes in designation status, since a country being added or removed shifts your obligations quickly and materially.

Step-up verification

Due diligence & onboarding

This is applying extra verification only when risk signals call for it, such as prompting for stronger authentication or more documentation after anomalous behavior. It balances assurance against customer friction, concentrating scrutiny where risk actually appears instead of burdening everyone equally.

The key is tuning the triggers carefully. Set thresholds too low and you frustrate legitimate customers with needless hurdles; set them too high and risky activity proceeds before the step-up ever fires. The whole value sits in catching the right moments, so the challenge lands on the suspicious session and waves the ordinary one through. A step-up that fires on everyone, or on no one, is not doing its job.

Strong customer authentication is a rule, best known from PSD2 in Europe, that payers be verified with at least two independent factors from three types: something they know, something they have, and something they are. It is meant to cut online card fraud.

3DS is the common way to meet it, with defined exemptions (low value, recurring, low-risk transactions) that limit friction. Teams balance how widely they apply SCA against lost conversions, and watch for exemption abuse. Poorly applied exemptions reopen the very fraud gap SCA was meant to close.

Structuring

Money laundering

Structuring deliberately splits transactions to keep each one below mandatory reporting or detection limits. It is itself a crime, whether or not the underlying money is dirty.

Classic patterns include deposits just under reporting limits, repeated round amounts near a threshold, and transactions timed or spread to avoid being added together. It relates to smurfing, micro-structuring, and reporting-threshold rules. Intent to evade is the legal heart of it, so consistent sub-threshold behavior, not any single transaction, is what supports a structuring finding.

Subscription fraud

Card & payment fraud

Subscription fraud is getting recurring goods or services with stolen or made-up identities, or systematically abusing free trials and promo pricing. Left unchecked, recurring billing and easy signups let a small setup drain value over time.

It shows up as clusters of new signups sharing a device, email pattern, or payment method, and as a missed first invoice or an instant dispute. Fight it by linking device and identity across accounts, trial-abuse velocity rules, and card or BIN checks at signup. It overlaps with promo abuse, synthetic identity, and account takeover of existing subscriptions.

Supervised model

Detection & metrics

This is a model trained on labeled outcomes, like confirmed fraud or chargebacks, learning to predict the risk it was shown. It performs well on known fraud types where you have good labels to learn from.

But it is only as good as those labels: slow, noisy, or biased labeling caps its accuracy, and it can miss novel patterns it never saw in training. Label lag, the delay before you know an outcome was fraud, is a core operational nuance, since it means the model always learns from a slightly outdated world. So it is often paired with unsupervised methods that catch emerging fraud outside the training set, giving you coverage on both the known and the new.

Suspicious activity

Monitoring & investigations

Suspicious activity is behavior that has no clear lawful or business purpose, does not fit what you know about the customer, or otherwise points to possible money laundering, fraud, or other illegal conduct. It is the trigger for considering a SAR, and the bar is reasonable suspicion, not proof of a crime.

Analyze the context before you conclude anything, since much unusual behavior has an innocent explanation. The risk runs both ways: under-reporting genuine cases leaves crime unflagged, while defensively filing on merely odd activity that review could explain floods the system with low-value reports. Judgment, backed by documented reasoning, is the whole job.

Suspicious Activity Report (SAR)

Monitoring & investigations

A SAR is a confidential report filed with the financial intelligence unit, in the US to FinCEN, describing activity suspected of involving money laundering, fraud, or other illegal conduct. It is generally due within a set period after you detect the activity. It is how private-sector monitoring feeds real intelligence to law enforcement.

SARs are strictly confidential, and telling the subject one exists is illegal tipping-off. File on time, back the conclusion with a specific narrative, and consider continuing-activity SARs when behavior keeps going. Both late filing and defensive over-filing are recurring problems, and examiners look hard at both.

Suspicious Transaction Report (STR)

Monitoring & investigations

An STR is the suspicion-based report used in many countries outside the US. It does the same job as a US SAR and is filed to the local FIU under that country's AML/CTF regime. A global operator cannot assume US rules apply everywhere; the concept travels, but the details do not.

Thresholds, timeframes, formats, and tipping-off rules all vary by country. If you run across multiple jurisdictions, map each one's STR triggers and deadlines, and keep your underlying analysis consistent while still meeting each local filing standard. Treating every market like the US is how firms miss deadlines and file in the wrong form.

Synthetic account

Account & access fraud

A synthetic account is opened under a made-up persona that blends real and fake data, like a valid but unrelated SSN paired with an invented name, built to commit fraud or launder money while beating identity checks. With no real victim to report it, the fraud stays hidden longer.

These accounts often pass KYC, then patiently build credit or transaction history before busting out and vanishing with the balance. Counter it by verifying identity across multiple sources, checking whether the identity pieces actually correlate, and watching for the slow, quiet buildup that comes before a bust-out.

This is creating a fake identity by blending real and made-up data, for example a real SSN with a fabricated name and birth date, then nurturing it with credit activity before a coordinated bust-out cash-out. No real victim ever reports it, so it hides for a long time.

Because fragmented data checks pass, it slips past traditional KYC. Detection needs cross-record consistency checks, tracking how often identity pieces get reused, thin-file behavioral signals, and network linkage. It is one of the hardest fraud types to measure and is frequently miscoded as credit loss when it defaults.

Synthetic media

AI & emerging fraud

This is any AI-generated content, audio, image, video, or text, made to deceive. It is the broad category that covers deepfakes, voice clones, and document forgeries. It breaks any control that treats a piece of media as proof of who someone is or what they intend.

The practical response is to stop treating content as ground truth. Instead, weight device, behavioral, network, and out-of-band signals, plus provenance checks where you can get them, like content that carries a verified source tag. Building trust on the media itself is the error; assume it can be faked and make the decision rest on evidence the attacker cannot easily manufacture.

T

30 términos

Targeted financial sanctions

Sanctions & screening

Targeted financial sanctions are measures aimed at named individuals or entities, mainly asset freezes and bans on making funds or economic resources available to them, as opposed to broad country embargoes. They are the workhorse of counter-terrorism and counter-proliferation regimes.

They demand precise identification of the target and anything it owns or controls, including through ownership rules like the 50 Percent Rule. Effective compliance combines accurate name screening with beneficial-ownership analysis so indirectly held assets are not missed. The common miss is stopping at the named party and overlooking the assets and entities behind it.

Task scam

Scams & social engineering

A task scam recruits victims for simple online tasks, liking videos, rating products, or completing app-based jobs, with small early payouts, then requires them to deposit their own money to unlock higher earnings that never pay out. It has surged in 2024 to 2025. It blends employment-scam and advance-fee mechanics and often uses crypto deposits.

Red flags include unsolicited task-job offers, small initial payouts to build trust, and any job that requires the worker to pay in. It overlaps with job and employment scams.

Tax evasion

Fraud types

This is illegally dodging tax you legitimately owe, by underreporting income, overstating deductions, hiding assets, or using offshore structures. It is a common source crime for money laundering. The hidden money often has to be washed through the financial system.

In monitoring it shows as unexplained wealth, structuring to obscure income, odd patterns in cash-heavy businesses, and use of shell entities. Detection ties transaction patterns to the customer's declared economic profile. Note the difference from lawful tax avoidance, and remember it is often the underlying crime behind laundered funds.

Tax fraud

Fraud types

This is filing false tax information to cut a bill or claim refunds you are not owed. A common form uses stolen identities to file returns and grab the refund before the real taxpayer files. It steals directly from public funds and from victims.

Signals include multiple refunds landing in one bank account, refunds that do not fit the taxpayer's profile, and bursts of filings sharing a device or contact detail. On the banking side, watch for many tax-refund deposits routed through one account and rapid cash-out. It overlaps with identity fraud and tax evasion.

Tech support scam

Scams & social engineering

A tech support scam is a fraudster posing as support from a well-known company, via pop-ups, cold calls, or search ads, to convince the victim their device is infected, then charging for fake fixes or gaining remote access to accounts. It disproportionately harms older victims and often escalates into refund or remote-access scams.

Tells include unsolicited support contact, scare-tactic pop-ups, requests to install remote tools, and payment demanded in gift cards or crypto. Real tech companies do not cold-call about a virus on your device.

Telemetry tampering

AI & emerging fraud

This is faking the device and signal data your identity and risk checks depend on, spoofing GPS, sensors, the camera feed, or app attestation, instead of forging the documents sitting on top. It poisons the very inputs your models trust, so a risky session can look perfectly clean.

Look for emulators, rooted or jailbroken phones, injection tools, and sensor readings that are inconsistent or plain impossible, like a device that is both still and moving. Device attestation and integrity checks are core defenses. Taking signals at face value is the risk; if the input can be tampered with, verify the device is genuine before you believe what it reports.

Terrorist financing (TF)

Terror & proliferation

Terrorist financing is raising, moving, storing, or providing funds, from either clean or dirty sources, to support terrorist acts, people, or organizations. Unlike money laundering, the defining feature is the destination and intent rather than the origin of the money, and the amounts are often small, which makes value thresholds largely ineffective.

You mostly detect it through counterparty and geography screening, links to designated persons, and behavioral context rather than transaction size. TF-related SARs and sanctions hits usually demand urgent escalation, because the potential harm is immediate and severe. Chasing large suspicious amounts alone will miss most of it.

This is internal audit, giving the board independent assurance on how well the first and second lines manage financial-crime risk. It is separate from the second line's ongoing oversight; audit checks the checkers. The board needs a view it can trust that is not colored by the people running the controls.

Its value depends on independence from both other lines and the skill to actually test technical AML controls, not just confirm a process exists. Track whether audit findings drive real fixes. Recurring or aging findings signal that assurance is being noted but not acted on, which quietly defeats the purpose of having a third line at all.

This is fraud committed with a real victim's stolen identity, credentials, or account, without their knowledge or consent. It is the classic outside-attacker model, spanning account takeover, application fraud, and card fraud. It is the type most people picture when they say fraud.

Because a real victim exists, it usually gets reported and disputed, which helps detection through victim signals, device and behavioral anomalies, and PII-exposure data. Telling it apart from first-party fraud, where the real person is the fraudster, and second-party fraud, where the account holder is complicit, is essential for correct loss classification and liability.

Third-party laundering

Money laundering

Third-party laundering is cleaning money on behalf of someone else who committed the underlying crime. It separates the launderer from the criminal and covers mules, professional launderers, and complicit facilitators.

It shows as people or entities moving funds with no obvious link to the crime and no economic reason to be handling them. It relates to self-laundering, money mules, and professional money laundering. The third party's knowledge or willful blindness is central to how guilty they are, which shapes how mule versus complicit-facilitator cases are handled.

This is the governance model that separates who owns risk (first line, the business), who oversees and challenges it (second line, compliance and risk), and who gives independent assurance (third line, internal audit). It makes clear who does what so accountability does not fall through the cracks.

But it is a framework, not a guarantee. The frequent failure mode is blurred lines: compliance doing first-line tasks, or audit reviewing controls it helped build. Either erodes the independence the whole model depends on. When the lines quietly merge, you lose the separation that made the model useful in the first place. Guard the boundaries, not just the boxes.

Threshold

Monitoring & investigations

A threshold is a configured value, such as an amount, a count, or a velocity limit, that triggers an alert or a reporting duty once activity crosses it. It sets the trade-off at the center of monitoring: catch more risk, or generate fewer false positives. Where you set it shapes both coverage and how much work lands on analysts.

Justify thresholds with data and revisit them through tuning. Set too high, they miss activity; set too low, they bury analysts in noise. Criminals actively probe them, structuring transactions to sit just below reporting levels, so a threshold everyone can guess is a threshold that gets gamed.

Threshold reporting

Monitoring & investigations

Threshold reporting is mandatory filings triggered purely because a transaction, or combined activity, crosses a set value, such as US CTRs at 10,000 dollars or various cross-border transfer reports. It has nothing to do with suspicion. These are hard, objective duties: cross the line and you must file, full stop.

Aggregate activity correctly, apply exemptions where allowed, and file on time in the right format. The key nuance to remember: meeting a threshold duty does not clear your suspicion-based duties. The very same activity may still require a SAR or STR, so filing the threshold report is not the end of the analysis.

Threshold tuning

Monitoring & investigations

Threshold tuning is the disciplined adjustment of scenario thresholds to balance detection coverage against false-positive volume, backed by above- and below-the-line testing and a documented reason for each change. Thresholds decay: as behavior shifts, a setting that once worked starts either missing risk or drowning analysts.

Examiners expect to see tuning as an ongoing, evidenced activity, not a one-time event. Tie every change to data and keep the before-and-after analysis. The classic criticism is loosening thresholds purely to cut alert volume; tuning driven by analyst workload rather than risk, or with no documentation at all, is a frequent finding.

Time-based OTP (TOTP)

Identity verification

A time-based one-time password is a code built from a shared secret and the current time, generated in an authenticator app and rotating every 30 seconds or so. It is stronger than codes sent by SMS: the codes expire fast and never travel over a message that can be intercepted.

It is still not immune. Real-time relay phishing can pass a live code along, and the seed can be stolen or set up under coercion. Protect the setup and recovery flows, since that is where the shared secret is handed out.

TIN verification

Business verification

TIN verification checks a Taxpayer Identification Number for a person or company, confirming the number is legitimate and matches the associated name. A TIN that does not line up with the name is a common thread in synthetic-identity and business fraud.

One tell is the same TIN reused across unrelated applicants, which points to fabrication. Treat a match as one supporting signal: it confirms the identifier is consistent, not that the applicant is the rightful holder or a genuine operating business.

Tokenization

Card & payment fraud

Tokenization swaps sensitive card data for a harmless stand-in value called a token, so the real card number is never exposed in storage, in transit, or at the merchant. It shrinks both breach risk and the damage if data leaks.

Network tokens can be locked to one merchant and auto-updated, improving both security and approval rates on stored cards. It reduces PCI scope but does not stop fraud on the live card itself. A stolen device-bound token or a provisioning-fraud attack, where a fraudster loads a card into their own wallet, can still enable misuse.

Tone from the top

AML programs

This is the board and senior management's real, demonstrated commitment to compliance, not just what they say in a memo. It shapes firm-wide culture and how seriously everyone treats controls. Staff take their cues from what leaders actually do.

You read it from real decisions: how well financial crime is resourced, how the firm treats people who escalate concerns, and whether commercial pressure gets to override risk. Weak tone shows up as chronic under-staffing, tolerated alert backlogs, and business overrides. Strong tone shows as visible support when compliance turns away profitable business. The words are cheap; the budget and the backing are the tell.

Track data

Card & payment fraud

Track data is the information encoded on a card's magnetic stripe, mainly Track 1 and Track 2, including the card number, expiry, and service code. It is exactly what skimmers and shimmers steal to clone cards.

Having track data lets a criminal make counterfeit magstripe cards, so its theft comes right before in-person and fallback fraud. PCI bans storing full track data after a transaction is approved. A breach that exposes it signals imminent cloning risk, and it is what gets sold as dumps.

Trade-based money laundering hides the movement of value through mis-invoicing, over- or under-shipment, multiple invoicing, or misdescribing goods, so illicit value moves under the cover of what looks like real trade.

It is one of the hardest types to detect because each shipment looks normal. Red flags include price and quantity anomalies versus the market, circular trade between related parties, and payments that do not match the goods. It relates to over- and under-invoicing, phantom shipping, and free trade zone abuse. The real test: TBML only surfaces when invoices, customs, logistics, and payments are reconciled together, so siloed review misses it.

Transaction laundering

Card & payment fraud

Transaction laundering is pushing unknown, banned, or illegal sales through a legitimate merchant account so the payments look like they come from a compliant business. It defeats underwriting and monitoring and hides high-risk activity in plain sight.

Also called undisclosed aggregation or factoring, it hides things like illegal goods, unlicensed gambling, or scams behind a clean payment description. Tells include a description that does not match the product, volume or geography that does not fit the stated business, and traffic that does not look like real customers. It is both a fraud and an anti-money-laundering concern.

Transaction monitoring (TM)

Monitoring & investigations

Transaction monitoring is the ongoing, usually automated review of customer transactions against rules, scenarios, and behavioral baselines to spot activity that may signal money laundering, fraud, or sanctions risk. It is a core pillar of a BSA/AML program and the main engine that feeds alerts, investigations, and SARs; if it is weak, everything downstream is starved.

Care about scenario coverage mapped to your risk assessment, threshold tuning, complete data feeds, and alert quality. Gaps in coverage or in the data flowing into monitoring are among the most damaging exam findings, because they mean whole categories of risk were never being watched at all.

Transaction screening

Monitoring & investigations

Transaction screening checks a payment's parties, and often related fields such as banks and countries, against sanctions lists and watchlists before the payment completes, so any hit can be blocked or held for review. It is your real-time gate against sending money to a sanctioned party; unlike transaction monitoring, which studies patterns after the fact, screening acts in the moment.

Tune the matching to control false positives from fuzzy name matches while not letting true hits slip past. A missed real sanctions hit is a strict-liability failure, meaning intent does not matter, and the consequences are severe. That makes over-blocking the safer error, but a costly one for customers.

Transliteration

Sanctions & screening

Transliteration is rendering a name from one script into another, such as Arabic, Cyrillic, or Chinese into Latin letters, which produces several valid spellings of the same name. Sanctioned parties often come from non-Latin-script regions, so transliteration differences are a leading source of screening variation.

Those differences cause both missed matches and false positives. Operators address it by screening multiple transliterations, applying phonetic and fuzzy matching, and normalizing names consistently across languages. Screening only one spelling of a foreign name lets the same party through under an equally valid alternate rendering.

Travel Rule

Crypto & blockchain crime

The Travel Rule is a FATF requirement that crypto service providers collect and pass along sender and recipient information for qualifying transfers above set thresholds, mirroring the long-standing rule for bank wires. It enables attribution and monitoring across providers, closing a gap criminals used to exploit.

In practice it is complicated by uneven implementation, transfers to self-hosted wallets, and gaps between jurisdictions. Compliance means identifying the counterparty provider, exchanging the required data securely, and screening the parties. The recurring pain point is handling transfers to unhosted wallets or to a counterparty that does not comply, where the clean handoff the rule assumes breaks down.

This is a scheme where a fraudster runs a fake storefront that captures real customers' card data on normal-looking orders, then fills those orders by buying the goods with other stolen cards. It hides the operation while harvesting fresh card data for later abuse. It quietly steals card numbers at scale.

Legitimate buyers get their goods and notice nothing until the stolen-card purchases chargeback. Detect it with merchant vetting, spotting mismatched fulfillment sourcing, and clusters of orders shipping to buyers who never authorized the fulfilling card. It is common in marketplace and card-not-present environments.

True match

Sanctions & screening

A true match is a confirmed, correct match between a screened party or transaction and a list entry, established after an analyst reviews and dispositions the alert, as opposed to a false positive that gets cleared. Confirming it triggers the required action, usually blocking or rejection plus reporting.

It demands solid documentation of the decision and the supporting evidence. The key nuance is disciplined disambiguation: clearing a real match as a false positive turns it into a false negative, with serious consequences. Watch out for rushing the review under alert pressure and dismissing a genuine hit as noise.

Tumbler

Crypto & blockchain crime

A tumbler is a mixing service that pools and shuffles crypto to hide where funds came from; it is basically another word for a mixer and is treated the same way in risk analysis. Exposure to a tumbler is a strong illicit-activity signal, and some tumblers have been sanctioned, adding prohibition risk on top.

Analysts trace funds into and out of tumblers, treat the output as lower-confidence about origin, and weigh the specific service's reputation and legal status. One catch: lumping all tumblers together, since a sanctioned one carries legal exposure that a merely risky one does not.

Two-factor authentication (2FA)

Identity verification

Two-factor authentication requires exactly two independent factors, a specific case of MFA. Adding a second factor blocks most attacks that rely on a stolen password alone.

Its strength depends entirely on which factors you pick: a password plus SMS code is far weaker than a password plus a hardware key or passkey. The recurring attacks are SIM swaps, code interception, and account-recovery abuse that lets a fraudster reset or downgrade the second factor, so scrutinize the reset path as hard as the login.

Typology

Monitoring & investigations

A typology is a recognized method or pattern of laundering, fraud, or terrorist financing, such as trade-based laundering, funnel accounts, or mule networks, that describes how illicit actors actually operate. Typologies, published by bodies like FATF and FIUs, drive scenario design, red-flag lists, and analyst training, so your detection aims at real behavior instead of guesswork.

Keep typology knowledge current as methods evolve, because criminals adapt faster than rulebooks. Scenarios built on outdated typologies leave blind spots that get exploited, and analysts who only know old patterns will wave through new ones. Fresh typology intelligence is what keeps a program pointed at today's threats.

U

8 términos

Ultimate Beneficial Owner (UBO)

Business verification

The Ultimate Beneficial Owner is the real person who ultimately owns or controls a customer entity, commonly flagged above a 25 percent ownership stake, though control-based tests apply too. Reaching a real, accountable human is a core AML requirement, and gaps here are exploited by shell companies.

UBO work pierces layered structures to find that person. Beware setups engineered to keep every owner just under the threshold, and confirm the declared UBO against registry and other evidence instead of taking self-attestation at face value.

UN Consolidated List

Sanctions & screening

The UN Consolidated List is the combined list of individuals and entities subject to sanctions imposed by the United Nations Security Council, forming a baseline that many member states build into their own regimes. It is a foundation other lists draw on, but it is not the whole picture.

It can differ from US, EU, and UK lists in scope and named parties, and national implementation may add to it. Programs screen against it as part of multi-list coverage and reconcile the differences. Assuming any single list is exhaustive will burn you; the UN baseline alone misses parties added only at the national level.

Unauthorized payment fraud

Card & payment fraud

Unauthorized payment fraud is a payment made without the account holder's real consent, usually through stolen credentials, account takeover, or intercepted authentication. Unlike a scam where the victim is tricked into paying, here the customer never approved it at all.

That means classic unauthorized-transaction controls apply and the customer usually has stronger refund rights. Detection leans on device changes, impossible travel, reused credentials, and behavior that breaks pattern. Correctly separating unauthorized fraud from authorized (scam) fraud drives both the investigation path and who ends up paying.

Under-invoicing

Money laundering

Under-invoicing understates the price or quantity on trade documents to shift value to the importer. It is a trade-based laundering technique that moves value the opposite way from over-invoicing.

Signs include declared values below fair market price, quantities larger than the invoice states, and importers receiving goods worth more than they nominally paid. It relates to over-invoicing, TBML, and free trade zone abuse. Under-invoicing also enables customs and tax evasion, so check anomalies against market pricing and duty records, not just the relationship between the parties.

Underground banking

Money laundering

Underground banking refers to unlicensed parallel banking networks, such as hawala, that take deposits, extend credit, and settle value outside regulated channels. They run on trust and net settlement with no supervisor watching.

It surfaces as local funding and payout legs while the cross-border link stays hidden in operator ledgers, along with third-party cash and routes to high-risk regions. It relates to hawala, hundi, and IVTS. Lumping all such networks in with crime misses the point: the defining risk is the lack of licensing and controls, not the informal model itself.

Unsupervised model

Detection & metrics

This is a model that finds anomalies or clusters without labeled outcomes, useful for surfacing new fraud and organized rings before any labels exist. It can flag the unusual and link related accounts or devices early, when a supervised model has nothing to learn from yet.

The snag is that an anomaly is not automatically fraud; its outputs still need investigation and can generate noise. So in practice it complements supervised models, acting as an early-warning and discovery layer. What it finds gets confirmed, then fed back into rules and labels. Never treat its alerts as decisions; they are leads to chase, not verdicts to act on blindly.

Unusual activity

Monitoring & investigations

Unusual activity is behavior that departs from a customer's expected pattern or from peer norms but has not yet been judged suspicious. It flags a need to look, not an automatic filing. Telling unusual apart from suspicious is the analyst's core judgment call, and getting it wrong in either direction hurts.

Many unusual patterns turn out to have legitimate explanations found during review, so document how each was resolved. Treat all unusual activity as reportable and you drive defensive filing that clogs the system; dismiss it too quickly and you miss genuine suspicion. The value is in the documented reasoning, not the label.

USA PATRIOT Act

Regulation & bodies

The USA PATRIOT Act is post-9/11 US legislation that greatly expanded AML and counter-terrorist-financing requirements. It added mandatory customer identification programs, correspondent- and private-banking due diligence, the 314 information-sharing framework, and special measures against high-risk jurisdictions and institutions. It amended and strengthened the Bank Secrecy Act and is the source of many controls you use every day.

Recognize it as the origin of core daily obligations: customer identification programs, the 314(a) and 314(b) processes, and enhanced correspondent-banking scrutiny. When someone asks why you must verify identity at onboarding or why correspondent relationships get extra diligence, the answer usually traces to this Act.

V

11 términos

Velocity

Detection & metrics

This is the rate of an activity over an entity or time window, for example transactions per card per hour or signups per device per day. It is one of the oldest and most reliable fraud indicators; spikes flag card testing, bot attacks, and bust-out behavior, so velocity rules sit on the front line.

The nuance is picking the right entity, window, and threshold. Too tight and you block legitimate bursts, like a payday spike or a promo rush; too loose and fast automated attacks slip through. The trade is catching machine-speed abuse without punishing normal human bursts, so the same rule that stops a bot can wrongly stop a busy real customer if it is set carelessly.

Velocity checks

Device & behavioral

Velocity checks watch for an abnormal rate of actions, like logins, payments, applications, or card attempts, over a short window, across an account, device, IP, or payment instrument. It catches card testing, credential stuffing, bust-outs, and application-fraud bursts that no single event reveals.

Aggregate across the right entities and time windows, since fraudsters spread activity out to stay under any single counter. Tune the thresholds so you do not punish legitimate spikes like a payday or a sale.

Vendor fraud

Fraud types

This is fraud involving suppliers, including fake or shell vendors, duplicate or inflated invoices, and collusion between vendors and insiders to pull improper payments. Vendor payments are routine and trusted, so the theft blends into normal spending.

Detection uses vendor-master validation, duplicate-payment and threshold analysis, and linking vendor bank details or addresses to employees. Red flags include vendors with no verifiable footprint, PO-box-only addresses, and banking details that match staff. It overlaps with invoice fraud, procurement fraud, and invoice redirection.

Verifiable credentials

Identity verification

Verifiable credentials are tamper-evident, cryptographically signed digital statements about identity attributes, issued by a trusted party and presented by the holder. A relying party can confirm an attribute without contacting the issuer live, and the holder can disclose only what is needed.

Trust rests on the issuer, the signature, and revocation status. And possession does not prove the presenter is the subject, so pair verification with a holder-binding or liveness check before you rely on the claim.

Verification waterfall

Detection & metrics

This is a sequence of verification checks run in order until identity or risk is resolved, so a cheaper or lighter check runs first and the harder, costlier ones fire only when needed. It optimizes cost and coverage: you avoid running every vendor on every user, and you can fail over when one provider misses or goes down.

Tune it on three things: the ordering, the pass thresholds, and latency. A poorly ordered waterfall raises both cost and friction, for instance by running an expensive check on users a cheap one would have cleared. The trade is thoroughness against speed and spend, so the sequence itself, not just the individual checks, is what you optimize.

Video KYC

Identity verification

Video KYC verifies a customer over a live video session, sometimes with an agent, where they show their document and face in real time. Live prompts and human judgment raise assurance against static spoofs.

But it is a target for deepfakes, virtual cameras, and applicants coached or coerced into reading a script. Train reviewers on deepfake and injection tells, and back the session with device integrity and liveness checks, because a convincing live feed can still be synthetic.

Virtual asset

Crypto & blockchain crime

A virtual asset is a digital representation of value that can be traded or transferred and used to pay or invest, as defined by FATF, generally not counting fiat, securities, or other assets already covered by existing rules. This definition sets the regulatory perimeter for what counts as crypto under AML rules and who qualifies as a service provider.

Operators care because scope drives obligations like KYC, monitoring, and the Travel Rule. Borderline instruments, such as certain tokens or NFTs, create classification gray areas. The risk is misjudging whether something is in scope, which can leave real obligations unmet or apply the wrong controls.

A VASP is a regulated business that exchanges, transfers, or holds virtual assets and is subject to AML/CFT duties, including the FATF Travel Rule, which requires sender and recipient information to travel with transfers. Crypto adds risks banks do not face the same way.

Those include tracing funds with blockchain analytics, exposure to mixers and high-risk exchanges, dealings with unhosted wallets, and patchy Travel Rule adoption across counterparties. Sizing up a VASP counterparty means weighing its licensing, its use of chain analytics, and its jurisdiction, because regulatory maturity varies sharply across the sector. Two VASPs can look alike and carry very different real risk.

Vishing

Scams & social engineering

Vishing is voice phishing over phone calls, using a fabricated pretext and often spoofed caller ID to pose as a bank, agency, or company and extract credentials, one-time codes, or payments. AI voice cloning increasingly makes callers sound like a known institution or even a family member, raising believability.

Defenses include teaching customers to hang up and call back the number on their card, callback verification, and never sharing one-time codes by phone. It is related to smishing (text), phishing, and caller-ID spoofing.

Voice biometrics

Device & behavioral

Voice biometrics verifies identity from the characteristics of a person's voiceprint, used in call-center and voice-channel authentication. It streamlines caller verification without security questions.

But it is increasingly stress-tested by voice cloning and replay, which can reproduce a target's voiceprint from short samples. Pair it with liveness or challenge-response and other call-risk signals, and treat a voiceprint match as one factor rather than standalone proof in an era of cheap synthetic audio.

Voice cloning

AI & emerging fraud

This is AI copying a person's voice to impersonate them on calls or beat voice biometrics, often built from just seconds of sampled audio. It fuels vishing, call-center social engineering, and the approval of high-value transfers, and it increasingly bypasses voiceprint login.

Mitigate it with voice liveness and anti-spoofing detection, out-of-band confirmation for risky requests, like a separate app approval, and step-up that does not rely on the voice channel at all. Treating a voice match as the sole factor is the danger; it is now easy to fake, so make voice one input among several, never the whole decision.

W

10 términos

Wallet clustering

Crypto & blockchain crime

Wallet clustering groups blockchain addresses that are likely controlled by the same entity, using heuristics like common-input-ownership and change-address detection, to collapse many addresses into one actor for tracing and attribution. It is foundational to on-chain analytics and to estimating an entity's true exposure and behavior.

Its accuracy varies and can be deliberately broken by mixers, CoinJoin, and multi-party setups, so every cluster carries a confidence level. Applied naively it backfires: over-eager clustering can wrongly merge unrelated actors, so treat a cluster as a strong hypothesis to be checked, not settled fact.

Wallet screening

Crypto & blockchain crime

Wallet screening checks a wallet's risk and sanctions exposure, before, during, or after a transaction, by weighing its direct and indirect links to illicit or sanctioned addresses and known patterns. It drives real-time calls to allow, review, block, or offboard, and supports monitoring and reporting duties.

Good screening weighs how severe the exposure is, how many hops away it sits, and how confident the attribution is, rather than reacting to any faint proximity. It pairs pre-transaction checks with ongoing rescreening as attributions change over time. Beware the one-time check: labels evolve, so a wallet that looked clean can turn risky later.

Wash trading

Crypto & blockchain crime

Wash trading is trading with yourself or between colluding accounts to fake volume, price, or activity, whether to manipulate a market, pump a token or NFT's apparent demand, or launder funds under cover of fake transactions. It distorts what looks like genuine market interest and can hide dirty money.

On-chain it shows as self-dealing loops, tightly linked counterparties, and volume that does not match real interest. Detection uses graph analysis to expose circular flows and shared control. It works as both a market-manipulation offense and a laundering vector, so the mistake to avoid is reading fake volume as real demand.

Watchlist screening

Sanctions & screening

Watchlist screening matches parties and transactions against a combined set of sanctions, PEP, and internal or third-party risk watchlists to flag prohibited or high-risk relationships for review or action. Different lists carry very different consequences and should not be handled the same way.

Sanctions hits are prohibitive, while PEP and adverse-media hits are risk indicators that call for diligence, not an automatic block, so dispositions must be list-aware. Effectiveness depends on list coverage and freshness, threshold tuning, and data quality to keep false positives and false negatives balanced. Treating every list alike is the failure here, either over-blocking risk flags or under-reacting to real prohibitions.

Weapons of mass destruction financing is the funding of the development, purchase, or spread of nuclear, chemical, or biological weapons and their delivery systems. It is the central target of counter-proliferation controls and sanctions. The harm is catastrophic and the consequences of enabling it are severe, often strict-liability, meaning intent is no defense.

It overlaps heavily with proliferation financing and surfaces in trade finance through dual-use goods, front and shell companies, and falsified shipping and end-user documents. Apply sanctions and export-control screening, scrutinize dual-use trade and vessel data, and escalate any suspected exposure promptly rather than waiting for certainty.

Whaling

Scams & social engineering

Whaling is spear phishing aimed at senior executives, board members, or other high-value targets whose authority or access makes a successful compromise especially damaging. It often impersonates or targets the CEO or CFO to authorize wire transfers or expose sensitive data, a core business-email-compromise tactic.

Defenses include executive-specific awareness, strict payment-verification and dual-approval controls, and email authentication. What sets it apart from ordinary spear phishing is the seniority of the target and the size of the payoff if it works.

Wire fraud

Fraud types

In the strict US legal sense, this is using interstate electronic communications, such as phone, email, or internet, to run a scheme to defraud. In everyday use it also means fraudulent wire transfers, like BEC-driven payments and authorized push-payment scams. Wires are fast and very hard to reverse.

On the payments side, watch for urgent wires to new payees, changed vendor banking details, and outbound transfers made under social-engineering pressure. Mitigate it with callback verification, dual approval, payee risk scoring, and quick recall procedures. Once a wire is sent, speed of response is often all you have.

Wire transfer fraud

Card & payment fraud

Wire transfer fraud is tricking someone into sending, or directly executing, a fraudulent wire, through business email compromise, social engineering, or account takeover. Wires are fast, high-value, and almost impossible to reverse once sent.

That size and finality make it a top target, and recovery depends on speed: a fast recall or freeze request may catch the money before it moves onward. Reduce risk by confirming any change of payment details through a separate known channel, requiring two approvers, and checking the beneficiary's risk. It is related to payment diversion and business email compromise.

Wolfsberg Group

Regulation & bodies

The Wolfsberg Group is an association of major global banks that publishes influential, non-binding guidance and standards on AML, KYC, correspondent banking, and financial-crime risk management, including its widely used correspondent-banking due-diligence questionnaire. While it is industry consensus rather than regulation, its outputs have become practical benchmarks for good practice.

Operators use Wolfsberg principles and questionnaires as reference points for what good looks like, and especially in correspondent banking, as standardized tools for collecting and assessing counterparty due-diligence information. Using its questionnaire is not legally required, but it is so widely adopted that it is often the expected way to exchange due-diligence data.

Workflow orchestration

Detection & metrics

This is configuring and sequencing the steps, services, and decisions in a risk or onboarding process, defining what runs when, under what conditions, and what each outcome triggers. It is how teams put strategy into action across onboarding, transactions, and case handling without hardcoding logic into each system, which enables fast changes and A/B testing of flows.

The key concerns are latency across chained steps, clear branching and fallback paths for when a step fails, and version control so flow changes are auditable and reversible. The trade is flexibility against operational risk: a flow that is easy to change is also easy to break, so treat each change like a code deploy, with review and a clean way to roll back.

Mantente al día con las definiciones de riesgo