Skip to main content
Category: Money Laundering Typologies

Typology

Also known as: Money laundering typology, Financial crime typology
Simply put

A typology is a way of classifying things by shared characteristics. In the anti-money laundering context, the term generally refers to recognized patterns or methods used to launder money or finance illicit activity, described so that compliance professionals can recognize similar behavior. These patterns are illustrative rather than exhaustive, and matching one does not by itself prove wrongdoing.

Formal definition

In its general sense, a typology is a system of classification that organizes items according to similar or dissimilar characteristics. Within financial crime compliance, the term is typically used to describe documented methods, schemes, or behavioral patterns associated with money laundering, terrorist financing, or related predicate offenses, often used to inform risk assessments, transaction monitoring scenarios, and staff training. Typologies function as analytical and operational reference models rather than legal tests or definitive indicators; they should be treated as non-exhaustive and context-dependent, and the presence of behavior consistent with a typology is a basis for further review, not a conclusion of criminal conduct. The specific application, terminology, and authoritative catalogues of typologies vary by jurisdiction and by the issuing body, and firms should map any typology to the requirements applicable to their obliged-entity category.

Why it matters

Typologies give compliance professionals a shared vocabulary for describing how money laundering, terrorist financing, and related predicate offenses may be carried out. By classifying observed methods and behavioral patterns according to their common characteristics, typologies help firms translate abstract risk into recognizable indicators that can inform risk assessments, transaction monitoring scenarios, and staff training. This makes them a practical bridge between high-level regulatory expectations and the day-to-day work of identifying activity that warrants closer examination.

At the same time, the value of typologies depends on using them correctly. Because they are illustrative and non-exhaustive, they cannot capture every method by which illicit funds move, and reliance on a fixed catalogue can create blind spots as methods evolve. Just as importantly, a typology is an analytical and operational reference model rather than a legal test. Behavior that is consistent with a documented typology is a basis for further review, not a conclusion of criminal conduct, and treating a match as proof of wrongdoing risks both unfair outcomes and poor-quality escalations.

Who it's relevant to

Compliance officers
Compliance officers use typologies to inform risk assessments and to design controls that reflect recognized methods of money laundering and terrorist financing. They are responsible for mapping typologies to the requirements applicable to their firm's obliged-entity category and for ensuring that staff treat typology matches as prompts for review rather than conclusions of wrongdoing.
Financial intelligence analysts and transaction monitoring teams
Analysts and monitoring teams rely on typologies to build and calibrate monitoring scenarios and to interpret alerts. Because typologies are non-exhaustive and context-dependent, these teams apply them as reference models to guide further investigation rather than as definitive indicators of illicit activity.
Investigators
Investigators use typologies to recognize patterns consistent with laundering or illicit financing when examining flagged activity. They must distinguish behavior that is merely consistent with a typology from evidence of criminal conduct, since matching a typology is a basis for closer scrutiny, not proof of an offense.
Training and staff development functions
Those responsible for training use typologies to help staff recognize behavioral patterns associated with financial crime. Effective training emphasizes that typologies are illustrative and evolving, and that consistency with a typology should trigger escalation and review rather than assumptions about wrongdoing.

Inside Typology

Method or pattern description
A typology describes a recognized method, scheme, or pattern by which money laundering, terrorist financing, or related financial crime is carried out. It is a descriptive tool rather than a legal test, and its presence does not establish that a crime has occurred.
Illustrative indicators or red flags
Typologies are frequently accompanied by indicators or red flags associated with the pattern. These are non-exhaustive and context-dependent; an indicator suggests heightened attention or further review, not proof of criminality.
Source and issuing context
Typologies are often published by standard-setting bodies and FIUs, such as FATF and FATF-style regional bodies, as well as national regulators and financial intelligence units. FATF outputs are standards and guidance rather than binding law, so typologies inform practice but do not themselves create legal obligations.
Relationship to the money laundering model
Many typologies map to one or more stages of the conceptual placement, layering, and integration model. That model is an explanatory framework, not a legal element of an offence, and typologies should not be treated as establishing any stage as a matter of law.
Application within a risk-based approach
Typologies feed into risk assessments, transaction monitoring scenarios, and customer due diligence by helping obliged entities recognize known patterns of misuse. They support the detection and mitigation of risk but do not guarantee prevention.

Common questions

Answers to the questions practitioners most commonly ask about Typology.

Does a transaction matching a known typology prove that money laundering has occurred?
No. A typology is a descriptive pattern or method associated with money laundering or terrorist financing, not a legal test or proof of criminality. A transaction or customer behavior that matches a typology indicates that further review may be warranted, but it does not by itself establish that an offense has been committed. Matching a typology is an operational risk indicator; determinations of wrongdoing are matters for competent authorities under the applicable criminal law.
Are published typologies an exhaustive list of the ways money can be laundered?
No. Typologies capture observed methods and patterns identified through case studies, investigations, and analysis, but they are illustrative rather than complete. Laundering methods evolve, and offenders adapt to controls, so no set of typologies should be treated as covering every possible scheme. Reliance solely on known typologies may leave novel or emerging methods undetected, which is why typology-based indicators are generally used alongside broader risk-based measures.
How can typologies be incorporated into transaction monitoring?
Typologies can inform the design of monitoring scenarios and detection rules by describing the behaviors and patterns those rules are intended to surface. In practice, an obliged entity may translate relevant typologies into parameters, thresholds, or behavioral indicators tuned to its own risk profile, customer base, and product mix. Because typologies are descriptive rather than prescriptive, the resulting scenarios generally require calibration and periodic review, and any alert produced should be treated as a prompt for analysis rather than a conclusion.
Where can compliance teams source relevant typologies?
Typologies are commonly drawn from materials published by bodies such as the FATF and FATF-style regional bodies, from national financial intelligence units and supervisors, and from industry information-sharing forums, in addition to an entity's own case experience. The relevance of a given typology depends on the jurisdictions, sectors, products, and risks to which the entity is exposed, so teams typically prioritize sources aligned with their operating context and risk assessment.
How should typologies feed into a business-wide risk assessment?
Typologies can help identify and characterize the threats and vulnerabilities an entity faces, supporting the risk-identification component of a risk assessment. They may inform how an entity understands its exposure across customers, products, delivery channels, and geographies. Because typologies describe methods rather than measure an entity's specific risk, they are generally used as inputs to be weighed against the entity's own data and context rather than as standalone risk ratings.
How often should typology-based indicators and scenarios be reviewed?
Because laundering methods evolve and offenders adapt, typology-based indicators and monitoring scenarios generally benefit from periodic review to remain relevant and effective. Review may also be prompted by new typologies from authoritative sources, changes in the entity's products or customer base, or findings from its own alerts and investigations. The appropriate frequency is typically driven by an entity's risk profile and internal governance rather than by a single universal standard.

Common misconceptions

Matching a typology proves that money laundering or terrorist financing has taken place.
A typology is a descriptive pattern, not a legal test or evidentiary standard. Alignment with a typology may warrant further review or, where applicable, a suspicious activity or suspicious transaction report, but it does not establish wrongdoing, which is a matter for criminal-law processes.
Published typology and red-flag lists are exhaustive and can be applied mechanically.
Typologies and their associated indicators are illustrative and evolve as methods change. They should be applied with judgment and in context, and the absence of a listed indicator does not mean risk is absent.
Typologies are legally binding requirements that obliged entities must implement directly.
Typologies are generally issued as guidance or standards, for example by FATF, FATF-style regional bodies, or national FIUs. Legal obligations derive from the applicable instruments in each jurisdiction, and typologies inform how those obligations are met rather than replacing them.

Best practices

Treat typologies as inputs to your risk-based approach, using them to inform risk assessments, monitoring scenarios, and due diligence rather than as standalone conclusions about customer conduct.
Document that any escalation, alert, or reporting decision reflects analysis in context, and avoid recording that a typology match alone establishes criminality.
Regularly review typology publications from relevant bodies such as FATF, FATF-style regional bodies, and your national FIU or regulator, and confirm applicability to your jurisdiction and business lines.
Tailor typology-derived indicators to your institution's products, customer base, and geographic exposure, recognizing that lists are non-exhaustive and that relevant indicators may not be listed.
Keep monitoring rules and red-flag guidance under periodic review so they reflect emerging methods, and retire or refine indicators that no longer add value.
Confirm any specific thresholds, reporting triggers, or obligations against the applicable regulation in your jurisdiction rather than inferring them from a typology description.