Skip to main content
Category: Money Laundering Typologies

Prepaid Card Laundering

Also known as: Prepaid Access Laundering, Money Laundering via Prepaid Cards
Simply put

Prepaid card laundering is the misuse of prepaid cards or prepaid access products to move or disguise the origins of illicit funds. Because prepaid cards can be loaded, spent, and transferred in ways that resemble cash, they can be exploited by criminals seeking to convert or move value while obscuring its source. This is a typology or risk concept describing how such products may be abused, not a legal finding that any particular transaction is criminal.

Formal definition

Prepaid card laundering refers to the exploitation of prepaid access and prepaid card programs to facilitate money laundering, terrorist financing, or other criminal activity, as recognized in the FFIEC BSA/AML Examination Manual's treatment of prepaid access risks. As a typology, it describes how the cash-like characteristics of prepaid products, including loading, redemption, and cross-border portability, may be used to place, layer, or integrate illicit value while limiting traceability; foreign-issued cards, in particular, have been encountered in criminal investigations and may fall outside the scope of certain domestic obliged-entity controls. The concept overlaps with, but should be distinguished from, broader 'prepaid card abuse,' which encompasses fraud, scams, and unauthorized transactions in addition to laundering. Obligations relating to prepaid access, such as registration, customer due diligence, and monitoring for issuers, providers, and sellers, vary by jurisdiction and product type, and applicable thresholds and requirements should be confirmed against the relevant regulations. Identification of prepaid activity as a red flag or typology does not, by itself, establish that a transaction or customer is engaged in wrongdoing.

Why it matters

Prepaid cards occupy a distinctive position in the payments landscape because they can behave much like cash while also being portable across borders. The FFIEC BSA/AML Examination Manual recognizes that money laundering, terrorist financing, and other criminal activity may occur through prepaid access and prepaid card programs, placing these products squarely within the risk considerations that obliged entities are generally expected to assess. For compliance officers, this means prepaid programs cannot be treated as inherently low-risk; the appropriate level of scrutiny depends on the product's features, funding methods, redemption options, and the controls applied by issuers, providers, and sellers.

A particular concern arises with foreign-issued prepaid cards, which may fall outside the scope of certain domestic obliged-entity controls. Reporting has noted that U.S. officials have confiscated foreign-issued prepaid cards during investigations, including into child sex trafficking inside the United States. This illustrates why an exclusive focus on domestically issued products can leave gaps: value stored on a card issued in another jurisdiction may not be subject to the same registration, due diligence, or monitoring expectations, complicating detection and traceability.

As with any typology, it is important to stress that the presence of prepaid activity is not, by itself, evidence of wrongdoing. Prepaid card laundering is a risk and typology concept describing how these products may be abused; identifying prepaid transactions as a red flag supports risk assessment and further inquiry, but it does not establish that a customer or transaction is criminal. The value of understanding this typology lies in helping compliance teams design measures to detect, deter, and mitigate potential misuse rather than in labeling activity as illicit.

Who it's relevant to

Prepaid Program Issuers, Providers, and Sellers
Entities that issue, provide, or sell prepaid access products may be subject to registration, customer due diligence, and monitoring obligations, though these vary by jurisdiction and product type. Understanding how their products could be exploited helps them calibrate controls to the specific features, loading, redemption, and portability, that drive risk. Exact requirements and thresholds should be confirmed against the applicable regulations.
AML Compliance Officers and Risk Analysts
Compliance professionals use this typology to assess the money laundering and terrorist financing risks that prepaid products can present, as recognized in the FFIEC BSA/AML Examination Manual. It informs risk-based controls and transaction monitoring, while reinforcing that prepaid activity is a factor for inquiry rather than proof of wrongdoing.
Financial Investigators and Law Enforcement
Investigators encounter prepaid cards, including foreign-issued cards that may fall outside certain domestic controls, in the course of criminal investigations. Awareness of how such products can obscure the source and movement of value, and of the traceability challenges they pose, supports investigative work and asset tracing.
Financial Institutions Handling Prepaid Activity
Banks and other institutions that fund, service, or process transactions involving prepaid products should recognize how these instruments can be misused, particularly cross-border movements and foreign-issued cards, and apply proportionate measures to detect and mitigate potential exploitation.

Inside Prepaid Card Laundering

Prepaid (Stored-Value) Cards
Payment instruments that store or provide access to monetary value paid in advance, which may be open-loop (usable across networks such as major card schemes) or closed-loop (restricted to specific merchants). The money laundering exposure differs significantly between these types, with open-loop and reloadable products generally presenting higher risk.
Placement via Loading
The conceptual stage in which illicit funds may be introduced into the financial system by loading cash or other value onto cards. This is part of the placement/layering/integration model, which is an analytical framework rather than a legal test.
Anonymity and Value-Portability Features
Characteristics that can heighten risk, including cards obtained without full customer identification, cards transportable across borders without the physical movement of cash, and products permitting anonymous reloading or cash withdrawal. The presence of these features does not by itself indicate criminal activity.
Applicable Obligations and Thresholds
Obligations on issuers, program managers, and distributors derive from the relevant regime rather than a single global rule. In many jurisdictions certain low-value, non-reloadable prepaid products may benefit from simplified or exempted customer due diligence up to defined limits, while reloadable or higher-value products typically attract fuller CDD. Exact thresholds vary by regime and should be confirmed against the applicable regulation.
Obliged Entities in the Prepaid Chain
The parties potentially subject to AML/CFT obligations, which may include the card issuer, program manager, distributor, and agents. Scope depends on how each jurisdiction defines the regulated activity, and some participants in a distribution chain may fall outside direct obligation.
Monitoring and Screening Controls
Measures used to detect, deter, and manage risk associated with prepaid products, such as transaction monitoring for structuring or rapid load-and-withdraw patterns, sanctions screening, and cross-border usage review. These are risk-mitigation measures and do not guarantee prevention.

Common questions

Answers to the questions practitioners most commonly ask about Prepaid Card Laundering.

Does using a prepaid card automatically indicate money laundering?
No. Prepaid cards are legitimate, widely used payment products, and their use is not evidence of criminal activity. The term "prepaid card laundering" refers to the potential misuse of these products to place, layer, or integrate illicit funds, but the presence of a prepaid card, or even patterns that resemble known typologies, does not establish wrongdoing. Typologies and red flags are indicators that may warrant further review, not proof of a predicate offense. Any suspicion should be assessed through your institution's risk-based procedures and, where warranted, escalated for a suspicious activity or transaction report as required by the applicable regime, without presuming criminality.
Are all prepaid cards anonymous and therefore high-risk?
Not necessarily. The risk profile of a prepaid product depends on factors such as whether it is reloadable, whether it permits cross-border use or cash withdrawal, applicable load and spend limits, and the extent of identification collected at issuance. Many programs apply customer due diligence, and some jurisdictions permit simplified due diligence only for lower-risk products below certain thresholds, with those specifics varying by regime and best confirmed against the applicable regulation. Distinguishing among product features is central to a risk-based assessment; treating every prepaid card as uniformly high-risk is neither accurate nor consistent with a risk-based approach.
How should an obliged entity approach customer due diligence for prepaid card programs?
CDD expectations generally scale with the assessed risk of the specific product. In many jurisdictions, standard CDD applies, and simplified measures may be permitted only for lower-risk, limited-function products falling below defined thresholds, while enhanced measures may apply to higher-risk features such as reloadability, cross-border functionality, or cash access. Exact thresholds and the availability of simplified due diligence differ across regimes, for example under the EU AML framework, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations, and should be confirmed against the applicable instrument. CDD measures are designed to help identify and verify the customer and to support ongoing monitoring; they mitigate but do not eliminate risk.
What transaction monitoring signals may be relevant to prepaid card products?
Monitoring is typically tailored to the product's functionality. Indicators that may warrant review include patterns consistent with structuring around load limits, rapid loading followed by immediate spending or withdrawal, use of multiple cards linked to a common party, and geographic activity inconsistent with the customer's expected profile. These are illustrative indicators drawn from published typologies, not an exhaustive list, and none on its own confirms illicit activity. Alerts are inputs to a risk-based review process, not determinations of wrongdoing, and thresholds and rules should be calibrated to the specific program's risk profile.
What are the beneficial ownership and identification considerations for prepaid products used by businesses or third parties?
Where a prepaid program is issued to or used by a legal entity, identifying the customer generally involves distinguishing legal ownership from beneficial ownership and, where applicable to the assessed risk, taking reasonable measures to identify the natural persons who ultimately own or control the entity. Products that allow one party to load funds for use by another can obscure the connection between the source of funds and the ultimate user, which is a relevant risk consideration. The specific obligations and thresholds for identifying beneficial owners vary by regime and should be confirmed against the applicable regulation.
How does a suspicious filing obligation apply to prepaid card activity, and does filing imply the customer is guilty?
Where activity involving a prepaid product gives rise to knowledge or suspicion of money laundering, terrorist financing, or a related predicate offense, the obliged entity is generally required to report it, as a suspicious activity report (SAR) in some jurisdictions such as the US, or a suspicious transaction report (STR) in others, under the applicable reporting regime and to the relevant financial intelligence unit or competent authority. A filing reflects a suspicion warranting disclosure; it does not establish that a crime occurred or that the customer is culpable. Reporting is a compliance measure to support detection and investigation, and it is distinct from any criminal-law finding of wrongdoing.

Common misconceptions

All prepaid cards present the same, uniformly high money laundering risk.
Risk varies materially by product design. Closed-loop, non-reloadable, low-value cards generally present lower risk than open-loop, reloadable products that permit cash withdrawal or anonymous reloading. Many jurisdictions reflect this through tiered or simplified due diligence for lower-risk products, subject to defined limits.
Detecting suspicious prepaid card activity or filing a report establishes that laundering occurred.
A monitoring alert, a screening match, or a suspicious activity/transaction report reflects a compliance judgment that activity warrants reporting; it does not prove a criminal offence. Load-and-withdraw or structuring-type patterns are indicators for further review, not conclusive evidence of wrongdoing.
A single global rule governs prepaid card due diligence and thresholds.
Requirements stem from divergent regimes and standards rather than one universal rule. The FATF Recommendations are standards, while binding obligations arise from instruments such as the EU AML framework, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations. Applicable thresholds and exemptions differ and must be confirmed against the governing regulation.

Best practices

Risk-rate prepaid products by design features, distinguishing closed-loop from open-loop and non-reloadable from reloadable cards, and calibrate due diligence accordingly rather than applying a single standard across all products.
Confirm the applicable customer due diligence thresholds, exemptions, and simplified-diligence conditions against the specific governing regime, and document the basis for any reliance on simplified measures.
Map every participant in the distribution chain (issuer, program manager, distributor, agents) and clarify which parties carry AML/CFT obligations under the relevant jurisdiction, addressing any scope gaps.
Deploy transaction monitoring tuned to prepaid-specific indicators such as structured loading, rapid load-and-withdraw activity, and cross-border usage, while treating alerts as triggers for review rather than proof of criminality.
Apply enhanced measures to higher-risk features such as anonymous reloading, cash withdrawal capability, and cross-border portability, and reassess risk when product functionality changes.
Maintain sanctions and PEP screening across the card lifecycle as distinct controls, and document escalation and reporting decisions so that a report reflects a compliance assessment and not a determination of guilt.