Financial crime glossary
Plain-English definitions of the terms used across the lab. Each is cited to an authoritative source; open the badge to see and copy the reference. This is guidance, not legal advice.
Beneficial owner
Also: beneficial ownership, ubo, ultimate beneficial owner, beneficial owners
Identifying beneficial owners pierces nominee and corporate layers so the firm knows who is really behind a customer. The 25% threshold is the common trigger across UK, EU and US rules; control can also arise by other means.
CDD
Also: customer due diligence
CDD is required before a business relationship begins or an occasional transaction is executed above the applicable threshold under MLR 2017. It has three core elements: identifying the customer and verifying their identity using reliable, independent source documents; identifying any beneficial owners and taking risk-based steps to verify their identity; and understanding the nature and purpose of the relationship to build a baseline for ongoing monitoring. Firms must refresh CDD when circumstances change, when doubts arise about existing information, or on a risk-based periodic schedule.
Correspondent banking
The correspondent bank cannot know the ultimate customers of the respondent institution, creating a nested exposure problem where illicit funds can pass through as payment instructions with no customer-level visibility. The Wolfsberg Correspondent Banking Principles set out the due-diligence standard, including understanding the respondent's AML programme, ownership, management and jurisdiction risk before establishing the relationship. FATF Recommendation 13 prohibits correspondent relationships with shell banks and requires senior management approval and satisfactory respondent due diligence before establishing or continuing any correspondent relationship.
EDD
Also: enhanced due diligence
EDD is triggered by a higher-risk finding in the customer risk assessment: examples include PEPs and their associates, customers or transactions linked to high-risk third countries, complex or opaque ownership structures, and correspondent banking relationships. Specific EDD measures include obtaining senior management approval before establishing or continuing the relationship, establishing source of wealth and source of funds, and increasing the frequency and depth of ongoing monitoring. JMLSG Guidance and MLR 2017 leave firms discretion on the form EDD takes, provided it is genuinely proportionate to the identified risk.
Integration
Integration completes the money laundering cycle by re-introducing funds into the legitimate economy in a form that appears indistinguishable from lawful wealth. Common integration vehicles include real estate purchases, luxury goods, business investments, and professional services fees paid from layered accounts. Because integration blends into normal commercial activity, it is the hardest stage to detect; EDD on high-value transactions, source-of-funds checks, and behavioural monitoring of long-standing customers are the main controls.
KYC
Also: know your customer
KYC is the collective term for the policies, procedures and controls a firm uses to know who its customers are, what they do, and what to expect from the relationship. It encompasses initial identification and verification, beneficial ownership checks, risk profiling, ongoing monitoring, and periodic review. While the term originates in banking practice, it applies across all regulated sectors and is used largely interchangeably with CDD in many jurisdictions, including in the FATF Recommendations.
Layering
Common layering techniques include wire transfers across multiple jurisdictions, conversion between asset classes such as cash to cryptocurrency to real estate, use of shell companies and nominees to obscure ownership, and back-to-back loans. FATF mutual evaluation reports consistently identify weak beneficial-ownership registers and inadequate correspondent-banking controls as key enablers of successful layering. Transaction monitoring rules targeting rapid in/out movement, geographic dispersion and complex ownership structures are the principal detective controls.
MLRO
Also: money laundering reporting officer, nominated officer
The MLRO (termed the Nominated Officer in MLR 2017) must be of sufficient seniority and independence to exercise genuine judgment on internal disclosures and SAR decisions, without commercial pressure to delay or suppress reporting. They receive internal disclosures from staff, determine whether the knowledge or suspicion threshold is met, and file externally with the NCA. The FCA also expects MLROs to report regularly to the board, maintain the firm's risk assessment and AML policies, and be consulted on high-risk customer decisions. In larger firms an experienced deputy MLRO is a common control.
Money mule
Also: mule account, mule network
Mule networks typically involve an organiser directing the scheme, one or more mule account holders who receive and forward the funds, and sometimes additional layers of onward transfer to further obscure origin. The FCA expects firms to have controls that detect accounts being used as mules, including behavioural monitoring for new accounts that rapidly receive and forward funds with no apparent economic purpose. Mule detection is both an AML and a fraud control: many mules are unwitting victims of social-engineering scams and may not understand that receiving and forwarding funds on instruction is a criminal offence.
Nominee
Nominees are commonly used in combination with shell companies and trusts to create opaque ownership chains that disguise who ultimately controls or benefits from an asset or account. FATF Recommendations 24 and 25 require countries to hold adequate, current and accessible information on beneficial owners of legal persons and arrangements, precisely because nominee arrangements frustrate that transparency. Firms must look through nominee arrangements to identify and verify the ultimate beneficial owner rather than accepting the face of the legal documentation.
PEP
Also: politically exposed person, politically exposed persons, peps
A PEP is defined in the UK's MLR 2017 and JMLSG Guidance as an individual entrusted with a prominent public function, such as a head of state, government minister, member of parliament, senior judiciary, senior military officer, or executive of a state enterprise. Their position gives them access to public funds and decision-making that creates elevated bribery and corruption exposure. UK firms must apply EDD to PEPs and maintain it for at least 12 months after they leave office; family members and known close associates are captured by the definition too.
Placement
Classic placement methods include cash deposits split across branches or ATMs, cash-intensive businesses used to commingle illicit funds with legitimate revenue, currency exchange, and purchase of monetary instruments. The placement stage is typically the most visible and carries the most risk for the criminal, which is why cash reporting obligations and cash-acceptance limits exist. Firms handling large amounts of physical cash, acting as payment intermediaries, or operating in sectors with high cash turnover face the greatest placement risk.
Proliferation financing
Also: pf
The FATF updated its Recommendation 7 to require countries and financial institutions to implement targeted financial sanctions related to proliferation financing following the 2018 revision, making it an explicit AML/CFT obligation rather than just a sanctions compliance issue. UK firms must screen against PF-related designations under the Sanctions and Anti-Money Laundering Act 2018 and the relevant implementing regulations, and must include PF in their business-wide risk assessment. The risk for most UK financial institutions comes not from directly financing WMD programmes but from exposure through trade finance, complex ownership chains, and correspondent relationships with institutions in higher-risk jurisdictions.
Red-flag indicator
Also: red flag, red flags
FATF and sector guidance publish red-flag indicators for each typology; the JMLSG Guidance contains extensive sector-specific and product-specific lists. A single red flag is rarely conclusive: firms are expected to assess indicators in combination and in the context of everything they know about the customer. Red-flag indicators inform both the rule parameters in transactional monitoring systems and the narrative a nominated officer uses when deciding whether a knowledge or suspicion threshold for a SAR has been met.
Risk-based approach
Also: rba
The FATF Recommendations require both countries and obliged entities to apply a risk-based approach as the foundation of their AML/CFT systems, rather than applying identical measures to all customers. In practice this means completing and documenting a business-wide risk assessment (BWRA) to identify inherent risks, using it to set proportionate policies and controls, and reviewing it when circumstances change. The FCA's Financial Crime Guide and JMLSG Guidance both describe how firms should evidence that their approach is genuinely risk-based and not a tick-box exercise.
Sanctions screening
Also: sanctions
UK firms must not deal with, or make funds or economic resources available to, sanctioned persons or entities under the Sanctions and Anti-Money Laundering Act 2018 and the implementing statutory instruments. Screening must cover customers, beneficial owners, counterparties and payees against HM Treasury/OFSI, UN, OFAC and EU consolidated lists, as relevant to the firm's activities and geographic footprint. Screens must be repeated when consolidated lists are updated, when new designations are published, and on a risk-based periodic basis for existing relationships.
SAR
Also: suspicious activity report, suspicious activity reports, str, suspicious transaction report
In the UK, a SAR is submitted to the National Crime Agency via the SARs Online system when a firm's nominated officer concludes that a knowledge or suspicion threshold is met under POCA 2002 or the Terrorism Act 2000. Filing a SAR may also obtain a defence against money laundering (DAML) when a transaction is involved, allowing the firm to proceed if the NCA does not refuse within the moratorium period. Failure to report when the threshold is met can be a criminal offence, and the firm must not tip off the customer that a report has been made.
SDD
Also: simplified due diligence
SDD is available where a firm has established that a customer, product or transaction presents a demonstrably lower risk of money laundering or terrorist financing, based on a documented risk assessment. Eligible situations under MLR 2017 include regulated financial institutions as customers, companies listed on major exchanges with disclosure obligations, and certain low-risk public bodies. SDD does not mean no due diligence: firms must still collect sufficient information to monitor the relationship and cannot apply SDD to any customer or product that exhibits higher-risk features.
Shell company
Shell companies are not inherently illegitimate: they are widely used for legitimate holding, joint-venture and tax-planning purposes. The financial crime risk arises when they are layered, when their beneficial ownership is concealed, or when they conduct transactions that lack any commercial rationale. FATF Recommendation 24 requires countries to maintain accurate beneficial ownership information on legal persons; UK firms must take risk-based measures to identify and verify the beneficial owners of corporate customers and understand why a layered structure exists.
Source of funds
Also: sof, source of wealth, sow
Source of funds asks where the money for a specific transaction or account relationship originated, for example salary, a property sale, or business income. Source of wealth asks the broader question of how the customer built up their overall net assets over time. Both are central EDD tools: a customer whose stated source of wealth is inconsistent with their transaction history, employment, or apparent lifestyle presents a red flag that should be investigated and documented before the relationship proceeds or continues.
Structuring
Also: smurfing
Structuring exploits the fact that many CDD, reporting and scrutiny obligations are triggered only above a value threshold, so criminals split large amounts into multiple smaller transactions across different times, locations or accounts. The FATF Recommendations identify structuring as a key money-laundering technique that transaction monitoring should detect through cumulative-value rules and frequency analysis. Structuring is itself a criminal offence in the UK under the Proceeds of Crime Act 2002, regardless of whether the underlying funds are illicit.
Three lines of defence
Also: 3lod, three lines of defense, 1lod, 2lod
The three lines model was formally articulated by the Institute of Internal Auditors and is adopted by the FCA in its Financial Crime Guide as the expected governance structure for AML. The first line (the business) owns and manages risk day to day; the second line (compliance and risk) sets policy, monitors, and provides oversight and challenge; the third line (internal audit) provides periodic, independent assurance over both. Each line must be genuinely independent: a function that both generates revenue and signs off on its own controls does not satisfy the model.
Transaction monitoring
Also: tm
JMLSG Guidance and the FCA Financial Crime Guide describe transaction monitoring as a mandatory ongoing obligation and a key detective control for identifying suspicious patterns after onboarding. Effective systems combine automated rules covering velocity limits, geographic risk scoring and behavioural anomalies with periodic manual reviews and clear alert-investigation workflows. The FCA has brought enforcement action against firms whose monitoring was inadequate in coverage, poorly calibrated to the firm's risk profile, or generating alerts that were not genuinely reviewed and closed within a documented timeframe.
Typology
A typology describes a repeatable method criminals use to launder money or move illicit funds. Mapping a typology to controls means the firm can detect the behaviour rather than guess at risk.