Layering: How It Works, Red Flags, and How to Detect It
Layering is the second stage of money laundering, in which illicit funds are moved through a rapid sequence of transactions to break the audit trail connecting them to their criminal origin. It sits between placement and integration in the three-stage model. Each individual transaction can appear legitimate in isolation, which is what makes layering hard to detect and prosecute.
What is Layering?
Layering is the second of three stages in the money laundering process, in which a criminal moves illicit funds through a sequence of transactions designed to sever the audit trail connecting the money to its illegal origin. The three stages are placement (introducing dirty money into the financial system), layering (disguising the trail through transaction complexity), and integration (spending cleaned funds as apparent legitimate wealth). The Financial Action Task Force first named it as a discrete stage in its 1990 Forty Recommendations, and that framework has remained the foundation of global AML compliance since.
Layering is the most technically complex stage for both the launderer and the investigator. The goal is distance: each transaction hop adds a layer of apparent legitimacy and makes tracing the original source progressively harder.
The mechanics vary, but the logic is consistent. Funds move rapidly through a sequence of accounts, institutions, and jurisdictions: multiple wire transfers between accounts held by nominee entities, currency conversions, conversions between asset classes (cash to crypto, crypto to real estate, real estate back to cash), the purchase and quick re-sale of high-value assets like art or property, shell company chains with nominee directors, trade finance instruments used to obscure fund flows, and payments routed through correspondent banking chains spanning several countries. In crypto-native schemes the same goal is accomplished through chain hopping across blockchains or passing assets through mixers. Layering frequently intersects with smurfing and structuring at the placement stage, and with trade-based money laundering as funds approach integration.
A concrete example: a fraud ring deposits $3 million across 60 accounts in two countries during placement. During layering, those funds move to nominee accounts, are converted into euros, transferred to a securities firm in Luxembourg, used to buy bonds sold within 48 hours, and the proceeds wired to a holding company in the Cayman Islands. Each transaction appears independently legitimate. The criminal pattern is only visible in aggregate.
FATF has identified layering as one of the most prevalent techniques in significant money laundering cases globally, and the pattern appears across traditional banking, fintech platforms, and crypto exchanges, its mechanics broadly stable even as the specific tools have changed. According to FATF's 2018 report on professional money laundering networks, financial institutions are most frequently exploited during layering because individual transactions stay within normal parameters while the overall pattern constitutes a serious crime. That gap between transaction-level legitimacy and scheme-level criminality is exactly what makes layering so difficult to detect with conventional controls.
How does Layering work?
The mechanics follow a consistent logic even when the specific instruments vary. The launderer starts with funds already inside the financial system, placed there via cash deposits, money mule networks, or other methods, and then moves them repeatedly to create confusion about their origin.
A typical sequence:
- Funds in a domestic bank account are wired to a foreign account at a low-disclosure jurisdiction institution.
- That account converts the funds to a different currency and transfers to a second foreign institution.
- The second institution purchases cryptocurrency and transfers to a self-hosted wallet.
- The crypto is converted via a cryptocurrency mixer or through chain hopping to a different token type.
- The converted crypto is sold at a separate exchange for fiat, deposited into a third-country account.
- That account wires the funds back to the originating jurisdiction labeled as an "investment return" or "loan repayment."
Illustrative scenario: A drug trafficking network places $2 million in cash through a network of retail businesses. The proceeds are wired from a US business account to a Hong Kong shell company, converted to euros, wired to a Latvian bank, used to purchase bitcoin, converted through a mixer to Monero, reconverted to bitcoin, sold at a European exchange for euros, and finally wired to a Dubai holding company as an "investment return." By step six, the funds appear to originate from legitimate overseas investment. Each individual step is defensible in isolation; the chain is not.
Layering frequently combines with structuring to stay below reporting thresholds at each node, and it overlaps significantly with nested correspondent laundering when the scheme exploits correspondent banking relationships to move funds across borders with minimal documentation.
How is Layering (Money Laundering Stage) used in practice?
In compliance operations, "layering" is the label analysts apply when a customer's transaction activity has no plausible business rationale. The fund flow is the evidence. Money arrives, moves rapidly through accounts with no offsetting economic purpose, and exits in a different form or to an unrelated destination. When that pattern appears across multiple accounts or time periods, the investigation centers on layering.
Transaction monitoring systems typically detect layering through a combination of velocity rules and counterparty risk scoring. The most common triggers: funds in/funds out within 24-48 hours with no documented business purpose, wire transfers to or from high-risk jurisdictions without a corresponding business relationship, and multiple accounts receiving and forwarding near-identical amounts in a short window.
When an alert fires, the analyst's task is chain reconstruction. That means pulling transaction history across linked accounts, checking counterparty connections (shared addresses, directors, beneficial owners), comparing the customer's declared business model against their actual behavior, and benchmarking the pattern against known typologies from FinCEN advisories or FATF guidance.
If layering is confirmed or strongly suspected, the output is almost always a Suspicious Activity Report (SAR). The narrative must document the complete chain: entry point, movement sequence, exit points, and why the activity can't be reconciled with a legitimate business explanation. Under FinCEN's 2021 AML/CFT Priorities, published June 30, 2021, professional money laundering networks that offer layering as a service are listed as a top enforcement priority.
The bottleneck in high-volume institutions is almost always the investigation phase. Analysts manually map fund flows across accounts that existing systems don't link automatically. Teams that have cut layering investigation time from three days to under four hours have typically done so by generating network visualizations at the alert stage, giving analysts the complete picture before they start digging, rather than requiring them to assemble it by hand.
Red flags and indicators
Transaction-level signals
- Rapid sequential transfers with no business purpose, sometimes within minutes of receiving funds
- Multiple transactions just below reporting thresholds (structuring indicators)
- Currency conversion at a loss, immediately followed by re-conversion
- Wire transfers to high-risk jurisdictions within 48 hours of receiving funds
- Transactions that reverse: funds sent out return via a different route at near-identical value
- Round-dollar wires with no supporting invoice or commercial relationship
Account-level signals
- Account opened, used intensively for pass-through transfers, then dormant within 60-90 days
- No income source consistent with transaction volume
- Multiple accounts at the same institution all forwarding funds to a single final destination
- Negligible net balance change despite high gross transaction volume
Network-level signals
- Graph analysis reveals hub-and-spoke or chain structures across otherwise unrelated entities
- Same device ID linked to accounts at multiple institutions transacting with each other
- Shell company chains across three or more jurisdictions, each adding a single pass-through hop
- Funds entering crypto, converting to a privacy coin, then re-entering fiat through a separate exchange
Behavioral signals
- Customer cannot explain the business purpose of a wire when asked
- Customer asks whether a transaction will trigger a Suspicious Activity Report
- Sudden change in transaction behavior following a news event about law enforcement activity
- Transaction timing requested close of business on a Friday or before a public holiday
Notable real-world cases
Deutsche Bank mirror trading, FCA fine (2017). Deutsche Bank's Moscow and London branches facilitated the movement of approximately $10 billion out of Russia through a mirror trading operation. Clients purchased Russian securities in rubles through the Moscow office, while a related party simultaneously sold the same securities in London for dollars. The mechanics were a textbook layering sequence: each leg of the trade appeared legitimate, but together they converted rubles to dollars and moved the funds offshore. The FCA fined Deutsche Bank £163 million for serious AML control failures. The FCA final notice sets out the full pattern.
Wachovia / Sinaloa Cartel deferred prosecution (2010). US prosecutors found that $378 billion of drug money had moved through Wachovia's correspondent banking operation via Mexican casas de cambio between 2004 and 2007. Funds were layered through wire transfers and bulk cash shipments across multiple account hops before entering the US financial system. Wachovia paid $160 million to avoid prosecution. The case remains one of the largest AML enforcement actions in US banking history.
Danske Bank Estonia (2022). An estimated €200 billion in suspicious transactions moved through Danske Bank's Estonian branch between 2007 and 2015, primarily from Russia, Moldova, and Azerbaijan. The branch was used as a layering node: funds entered via shell companies, transferred across multiple internal accounts, and exited to Western European banks. In December 2022, Danske Bank pleaded guilty to fraud and agreed to pay $2 billion. The DOJ press release documents the layering mechanics in detail.
FATF typology guidance. The FATF's published Money Laundering and Terrorist Financing typologies document recurring layering patterns across sectors, including real estate, virtual assets, and trade finance, providing compliance teams with a practical reference for red-flag calibration.
How to detect Layering
Rule-based detection is the starting point. Velocity rules that trigger when an account sends more than a defined number of outbound wires within 24 hours, or when a debit is followed by a credit of identical value within two hours, catch the most common patterns. Threshold alerting for transactions just below regulatory reporting limits adds a structuring filter on top.
Behavioral analytics extends coverage meaningfully. By building a statistical baseline for each customer segment, the system flags accounts where current behavior sits well outside the expected range even when no individual transaction breaches a rule. An account that normally processes $5,000 per month and suddenly handles $500,000 in wire transfers in a week is anomalous relative to its peer group, regardless of whether any single transaction triggers an alert.
Graph-based network analysis is the most effective technique for multi-hop layering. When the same dollar value (or a consistent fraction of it) appears at node A, then B, then C within a compressed timeframe, graph traversal algorithms surface the chain even when the accounts appear unrelated in isolation. Community detection identifies clusters of accounts with no apparent commercial relationship that transact primarily with each other. This approach is particularly effective because layering networks, including money mule networks used to move funds across accounts, tend to reuse infrastructure across multiple schemes.
Cross-channel signal correlation ties together events from digital banking, branch activity, and correspondent flows. A branch cash deposit, an online wire, and a crypto purchase at three different institutions can form a coherent layering sequence when correlated by entity, timing, and amount.
Retroactive network analysis on SAR-linked accounts is a practical operational improvement: identifying one confirmed node in a layering chain frequently surfaces several adjacent ones.
Which regulations cover Layering
The FATF 40 Recommendations, specifically Recommendations 10 (customer due diligence), 20 (reporting of suspicious transactions), and 29 (financial intelligence units), set the international standard. The three-stage placement-layering-integration model codified in the 1990 Forty Recommendations has since been embedded into virtually every national AML framework. Jurisdictions are assessed against these recommendations in mutual evaluation rounds, and weak layering detection is a recurring finding in lower-rated countries.
In the United States, the Bank Secrecy Act (31 U.S.C. § 5311 et seq.), enforced by FinCEN, requires institutions to file Suspicious Activity Reports for transactions that appear to involve layering and to maintain AML programs capable of detecting it. FinCEN publishes typology-specific advisories that institutions are expected to incorporate into their monitoring programs. The Currency Transaction Report threshold was designed partly to disrupt simple cash-based layering, though sophisticated schemes moved well beyond cash years ago. Regulators are increasingly specific about what they expect from monitoring configurations: the OCC's BSA/AML examination procedures explicitly address structuring and layering patterns as a supervisory focus area, and examiners now test whether rules can detect multi-account, multi-hop transaction chains rather than single-account anomalies. Institutions whose systems pass only on-threshold checks and miss the network-level picture are being cited with growing frequency.
The EU's Sixth Anti-Money Laundering Directive (6AMLD, effective June 2021) criminalized layering as a standalone predicate offence and extended criminal liability to legal persons, explicitly reaching anyone who knowingly assists with any stage of money laundering: banks, lawyers, accountants, and real estate agents, not just the original criminals. Its predecessors (4AMLD, 5AMLD) established the transaction monitoring and customer due diligence obligations that underpin detection.
In the UK, the Proceeds of Crime Act 2002 criminalizes layering under sections 327-329, the principal money laundering offences, and requires SAR submission via the National Crime Agency's UKFIU. The FCA's SYSC sourcebook requires firms to maintain systems capable of detecting suspicious activity, with layering explicitly in scope.
One regulatory development that has made layering harder to execute is the expansion of beneficial ownership disclosure. When institutions can identify the actual individuals behind shell company accounts, the structure becomes far more transparent. The EU's beneficial ownership registers, now live across most member states, are specifically designed to interrupt schemes that rely on corporate opacity, and the UK's Companies House reform, which moved to verified ownership records in 2023, serves the same function.
The scale is what keeps regulators pressing. The UN Office on Drugs and Crime estimates that between 2% and 5% of global GDP is laundered annually, put at $800 billion to $2 trillion in its 2011 assessment, with layering activity touching banks in every major jurisdiction.
Common Challenges and How to Address Them
The central problem with detecting layering is that it's designed to look normal. Individual transactions pass compliance checks. The criminal pattern emerges only when you connect the dots across multiple accounts, entities, and time periods. Most rule-based monitoring systems aren't built to do that.
The practical result: institutions with high false positive rates are often good at catching structuring but miss layering. They're tuned to transaction-level anomalies rather than network-level patterns. A customer making 50 wire transfers across 20 accounts over three weeks might not trigger any individual rule, but the aggregate behavior is unmistakably layering. This is the detection gap that sophisticated money launderers deliberately exploit.
Network analysis and graph analytics approaches directly address this gap. By mapping relationships between accounts, beneficial owners, addresses, and counterparties, analysts can visualize the entire transaction graph rather than working through one alert at a time. Some institutions have moved from a three-day investigation cycle to under four hours by adopting this model.
Customer risk context matters enormously. A customer due diligence profile that accurately reflects the customer's business model makes layering detection faster, because analysts have a clear baseline to measure against. A shell entity with no declared business purpose, opened three weeks before a layering scheme begins, has a very different risk profile than an established import-export firm with a three-year transaction history. The quality of that baseline determines how quickly anomalous behavior becomes visible.
For higher-risk customers, enhanced due diligence provides the deeper context needed to identify layering before it reaches the monitoring stage. Understanding a customer's counterparty network, jurisdictional exposure, and expected fund flow patterns at onboarding means that anomalous behavior is easier to catch in real time rather than retrospectively.
There's a real tradeoff. More sophisticated monitoring adds review burden. Institutions that adopt network-level detection need case management workflows built for complex multi-entity investigations, not the single-customer alert queues that most legacy systems assume.
Related Terms and Concepts
Layering connects directly to several specific techniques and structural elements that criminals use to execute it, and to the broader Anti-Money Laundering (AML) control framework built to detect and prevent it.
Shell companies are the most common vehicle for banking-sector layering. A criminal organization might control dozens of shell entities across multiple jurisdictions, using each as a relay point. The key compliance response is beneficial ownership identification: tracing who actually controls the accounts behind the corporate structure.
Smurfing overlaps with both placement and layering. Multiple individuals deposit cash in amounts just below reporting thresholds; those funds are then consolidated and forwarded through additional accounts. The deposits are placement. The consolidation and subsequent forwarding are layering.
Trade-Based Money Laundering uses international trade transactions to layer funds, typically through over- or under-invoicing goods so that value moves under the cover of legitimate commerce. FATF identifies this as one of the most widely used layering methods globally, particularly in jurisdictions with weak customs enforcement.
Correspondent banking relationships create layering risk because they extend transaction chains across institutions with limited visibility into each other's customer due diligence. A layering scheme that passes through a nested correspondent chain can be extremely difficult to trace because the originating bank's customer identity never appears in the correspondent's records.
In crypto markets, layering follows the same three-stage logic as traditional banking. Common techniques include moving assets through multiple wallet addresses, swapping across tokens on decentralized exchanges, using privacy coins, and passing funds through mixing services to break blockchain traceability. The Financial Action Task Force published updated guidance on crypto layering typologies in 2021, specifically addressing these methods in the context of virtual asset service providers.
The money laundering reporting officer's investigative responsibilities are centered on layering. The MLRO determines whether a suspicious transaction pattern constitutes layering, whether the activity meets the threshold for a SAR filing, and whether the institution's monitoring controls are adequate for the specific layering methods most relevant to its customer base and product mix.
How FluxForce detects Layering
Aiden Flux, FluxForce's transaction monitoring agent, runs real-time behavioral analytics and velocity checks against every wire and payment event. When a multi-hop transfer pattern surfaces, Nova Sentinel runs network graph analysis across the connected accounts to map the full chain, not just the triggering transaction.
Both agents produce a complete evidence package for every alert: a transaction timeline, the network graph, and a draft SAR narrative ready for analyst review. We've seen compliance teams cut SAR drafting time from hours to minutes using this workflow. This adds a small amount of processing overhead per alert, but the accuracy gain and the reduction in false positives make it the right trade.
If you want to see how this works against a live layering scenario, request a demo.
How FluxForce detects layering
FluxForce AI agents monitor layering-related patterns in real time, surface red-flag activity for analyst review, and produce evidence-backed decisions with full audit trails.