SardineCon SF/2026

Learn More

What is Typology?

SUBSCRIBE

A typology is a recognized method or pattern of laundering, fraud, or terrorist financing, such as trade-based laundering, funnel accounts, or mule networks. Typologies describe how illicit actors actually operate, and they drive scenario design, red-flag lists, and analyst training.

What is a typology, in plain English?

A typology is a documented pattern of how financial crime is actually carried out. Rather than a single transaction, it describes a method: the steps, structures, and behaviors that criminals use to launder money, commit fraud, or move funds to terrorists. Trade based laundering, funnel accounts, cuckoo smurfing, and mule networks are all typologies.

Typologies are the bridge between real world criminal behavior and your detection systems. Bodies like FATF and financial intelligence units study cases and publish typology reports, and firms turn those patterns into scenario logic, red flag lists, and analyst training. The idea is to aim your detection at how criminals really behave instead of at guesswork.

Because criminals adapt, typologies are not fixed. New methods emerge as products, technologies, and controls change, so keeping typology knowledge current is part of keeping a program effective. A scenario built on an outdated typology defends against a threat that has moved on.

Common laundering typologies

A handful of typologies show up again and again. Here is a quick breakdown of a few and what they look like:

Typology

How it works

Structuring

Breaking large amounts into smaller transactions to stay under reporting thresholds.

Funnel accounts

Many senders deposit into one account, then funds are rapidly withdrawn elsewhere.

Trade-based laundering

Mis-invoicing goods to move value across borders under cover of legitimate trade.

Mule networks

Recruited individuals move illicit funds through their own accounts for a cut.

What it looks like in practice

In practice

An analyst attends a briefing on a newer typology: laundering through peer to peer marketplace listings, where criminals sell fake goods to move money between complicit buyers and sellers. The team had no scenario for it because their rules were built years earlier around classic cash structuring.

Armed with the fresh typology, they design a scenario for accounts with high marketplace payment volume, thin shipping activity, and rapid cash out. Within weeks it surfaces a cluster of accounts running exactly that pattern. The catch only happened because the typology knowledge was current; the old rulebook would have waved the activity straight through.

Why typologies matter to operators

Typologies decide what your detection actually looks for. Scenarios, red flags, and training all descend from them, so if your typology intelligence is stale, your whole program is aimed at yesterday's threats. Criminals adapt faster than rulebooks, and blind spots open exactly where a program stopped updating its understanding of how crime is done.

There is a human dimension too. Analysts who only know old patterns will confidently clear new ones, because the behavior does not match anything they were taught to flag. Fresh typology intelligence, from FATF, FIUs, and your own case learnings, is what keeps both the systems and the people pointed at today's real methods.

What to watch with typologies

  • Stale scenarios. Detection built on old typologies leaves predictable blind spots that criminals exploit.
  • Emerging methods. New products and technologies breed new typologies; watch published reports and your own cases for them.
  • Training gaps. Analysts who only know classic patterns will clear novel ones; refresh training as typologies evolve.
  • Local relevance. Not every published typology applies to your business; map the ones that fit your products and geographies.
  • Feedback loop. Confirmed cases are a source of new typology intelligence; feed investigation learnings back into scenario design.

Quick questions

Where do typologies come from?

They are drawn from real cases and published by bodies like FATF, FATF-style regional bodies, and national financial intelligence units, as well as learned from a firm's own confirmed investigations. Together these keep the picture of criminal methods current.

How is a typology different from a red flag?

A typology is the overall method, such as trade-based laundering. A red flag is a specific observable sign that the method may be present, such as goods priced far above market value. Typologies generate the red flags you watch for.

How do typologies feed monitoring?

They drive scenario design. Each scenario should target a real typology mapped to your risk assessment, so the detection logic is aimed at how criminals actually operate rather than at arbitrary rules.

Why do typologies keep changing?

Because criminals adapt to new products, technologies, and controls. As one method gets detected, they shift to another, so typologies evolve and programs must update their scenarios and training to keep pace.

Do all published typologies apply to my firm?

No. Relevance depends on your products, customers, and geographies. Part of using typologies well is filtering the published set down to the ones that genuinely fit your risk profile and building detection around those.

Can machine learning find new typologies?

Anomaly detection and network analysis can surface patterns that hint at methods you had not defined, which can then be studied and turned into formal typologies. But human analysis is still needed to interpret and validate what the models flag.

Go deeper

What to know alongside Typology