SardineCon SF/2026

Learn More
Monitoring & investigations4 分で読めます

Red flagとは?

SUBSCRIBE

A red flag is an indicator that raises the possibility of laundering, fraud, or sanctions risk, such as funds passing straight through an account, structuring, mismatched ownership, or activity that does not fit the customer's profile. It is how you turn a vague concern into something concrete you can act on, but it is a signal, not proof.

What is a red flag, in plain English?

A red flag is a warning indicator: a pattern or characteristic that raises the possibility of money laundering, fraud, or sanctions risk. Classic examples are funds that pass rapidly straight through an account without settling, cash broken into amounts just under a reporting threshold, ownership that does not match who is actually transacting, or activity that simply does not fit what you know about the customer.

Red flags are the vocabulary of detection. They drive how scenarios are designed, they guide analyst judgment during an investigation, and they inform when to escalate. When a program says a customer's behavior looked suspicious, what it usually means is that one or more recognized red flags fired.

The essential caveat is that a red flag is a signal, not a verdict. It raises a question; it does not answer it. Context and corroboration are what decide whether an indicator adds up to reportable suspicion or turns out to have a perfectly ordinary explanation.

How a red flag becomes a decision

  1. Indicator — A red flag appears. Behavior or a characteristic matches a known warning sign, through a rule or an analyst's eye.
  2. Context — Check the customer's story. The flag is weighed against the customer profile, history, and any legitimate explanation for the activity. ExplainedBenignA documented business reason accounts for the activity; the flag resolves and the case can close.UnexplainedSuspiciousNo plausible rationale emerges, and corroborating signals point toward reportable suspicion.
  3. Corroborate — Look for supporting signals. The analyst checks whether other indicators or facts reinforce the concern before drawing a conclusion.
  4. Act — Escalate or close. Based on the full picture, the case is escalated toward a SAR or dispositioned as no action.

What it looks like in practice

In practice

An analyst sees a red flag on a new customer: money arrives and leaves within hours, passing straight through the account with no apparent purpose. On its own that is a signal, not a case. She checks context and finds the customer was onboarded as a personal account, yet the flows look like business pass-through, and the counterparties change constantly.

She looks for corroboration and finds two more flags: several inbound senders were themselves flagged elsewhere, and the amounts cluster just under a threshold. Now the indicators reinforce each other and no legitimate explanation fits. What started as a single red flag, which alone would not justify filing, becomes a corroborated pattern that supports a SAR.

Why it matters to operators

Red flags are the connective tissue of a monitoring program. They translate abstract risk into concrete, recognizable indicators that can be coded into scenarios, taught to analysts, and used to justify escalation. Keeping red-flag lists current as typologies evolve is part of the job, because criminals change tactics and yesterday's indicators go stale while new ones emerge.

The discipline is in resisting the reflex to treat a single flag as an answer. Mechanically filing on one indicator, without doing the analysis behind it, produces low-value reports and defensive filings. A red flag earns its keep only when an analyst uses it as the start of an inquiry, then lets context and corroboration decide whether it amounts to genuine, reportable suspicion.

Common red flags

  • Pass-through funds. Money that arrives and leaves quickly with no apparent business purpose, leaving the account near zero.
  • Structuring. Cash or transfers broken into amounts that stay just under a reporting threshold.
  • Ownership mismatch. The person transacting does not match the stated owner, or the beneficial owner is obscured.
  • Profile mismatch. Activity that does not fit the customer's stated occupation, income, or expected behavior.
  • A flag is not proof. Any single indicator needs context and corroboration before it becomes reportable suspicion.

Quick questions

Does a red flag mean the activity is illegal?

No. A red flag raises the possibility of risk; it does not confirm wrongdoing. Many flags have legitimate explanations. Context and corroboration are what determine whether an indicator amounts to reportable suspicion.

Can one red flag justify a SAR?

Rarely on its own. Mechanically filing on a single indicator, without analysis, produces weak, defensive filings. A red flag should trigger inquiry; the decision to file rests on the full picture, not one flag in isolation.

Where do red flags come from?

From known typologies, regulatory guidance, and a program's own experience. They are distilled into indicators that shape scenario design and analyst training, and they have to be refreshed as criminal tactics change.

How do red flags relate to scenarios?

Scenarios are essentially red flags turned into automated logic. A rule that alerts on rapid pass-through activity is codifying a red flag so the system can surface it at scale, then hand it to an analyst for judgment.

Why keep red-flag lists updated?

Because typologies evolve. Criminals adapt to known indicators, so a static list gradually loses coverage while new patterns go unwatched. Refreshing the list keeps detection aligned with how risk actually presents today.

Go deeper

Red flagと併せて知っておきたい用語