All insights
15 July 2025·6 min read

Financial crime typologies for neobanks: what to detect and how

Neobanks face a disproportionate share of money mule, fraud and sanctions-evasion risk due to fast digital onboarding and high transaction velocity. Understanding the specific typologies that target them is the starting point for designing effective detection controls.

neobanktypologiesmoney mulefraudsanctions

Neobanks sit at the intersection of several financial crime risk factors: they onboard customers quickly, often with fully digital processes; they serve a broad customer demographic including individuals who may be new to formal banking; and they typically offer real-time payments, which reduces the window for intervention between a suspicious instruction and the transfer leaving the firm.

Understanding which typologies are most relevant to neobanks is essential before designing detection controls, because the controls for money mule detection are different from those for sanctions evasion, even if both involve monitoring the same transaction flows.

Money mule networks

Money mule recruitment is one of the most prevalent financial crime risks for neobanks. Mule accounts are opened, used briefly to receive and forward funds, and then abandoned or left dormant. The accounts are often recruited through social media scams, job advertisements or romance fraud, meaning the account holder may not understand they are participating in a criminal scheme.

The behavioural indicators of a mule account are recognisable: the account receives funds from multiple unrelated sources shortly after opening, the funds are quickly transferred to other accounts or withdrawn, and the balance returns close to zero between activity periods. JMLSG Guidance and the FCA Financial Crime Guide both reference pass-through velocity and new-account-rapid-activity patterns as key indicators for this typology.

Detection requires monitoring rules that track the ratio of credits to debits over short windows, the number of distinct credit counterparties, and the speed with which funds are moved after receipt. These rules need to be calibrated carefully: many legitimate neobank users move funds between accounts regularly, and the threshold needs to reflect the specific customer segment rather than being applied uniformly.

Fraud and account takeover

Neobanks are targeted for account takeover fraud because digital account access can be compromised through credential stuffing, phishing or social engineering. The pattern of an account takeover typically involves a change of contact details or security credentials followed quickly by a large outgoing payment to a new payee.

Authorised push payment (APP) fraud is a particular concern: the customer is manipulated into authorising a payment themselves, which means the transaction appears legitimate from a monitoring perspective. The controls that catch APP fraud are focused on the profile of the payee, the novelty of the payment instruction, and any communications that accompanied the request, rather than just the transaction itself.

The FCA has published guidance on APP fraud through the Payment Systems Regulator, and the introduction of mandatory reimbursement obligations has increased the pressure on neobanks to invest in preventative detection rather than relying on post-facto recovery.

Sanctions evasion

Neobanks that operate cross-border payment services or serve internationally mobile customers carry meaningful sanctions exposure. The risk arises not only from customers who are themselves designated but also from customers who are transacting with or on behalf of sanctioned individuals or entities.

Effective sanctions controls for neobanks require real-time screening of payment counterparties at the point of instruction, not just at onboarding. Lists are updated frequently, and a customer who was clean at onboarding may transact with a newly designated payee six months later. The OFSI and Wolfsberg guidance on sanctions screening both emphasise the need for ongoing monitoring of transactions, not just a one-time check.

Where neobanks use third-party rails or aggregators for international payment routing, the screening obligation extends to the counterparties on those rails, not just the immediate customer. The correspondent banking or pass-through relationship does not remove the obligation.

Designing controls for the neobank context

The common thread across these typologies is that neobank controls need to be faster, more behavioural and more customer-segment-aware than the controls designed for traditional banking. Rules that fire on a fixed value threshold may miss the high-frequency, low-value patterns that characterise mule accounts; screening that runs only at onboarding will miss sanctions exposure that develops later in the relationship.

The starting point for control design is mapping the specific typologies relevant to the firm's products, customer types and geographic footprint, then identifying which detection logic applies to each. The TypologyIQ tool in FinCrime Control Lab does this mapping deterministically based on firm type, product and customer inputs.

Try the tool

Enter your product set and customer types in TypologyIQ to get a scored list of the financial crime typologies most relevant to your firm, with the detection controls for each.

Map typologies for your neobank

Sources

  1. JJMLSG · JMLSG Guidance
  2. FFCA · FCG
  3. OOFSI · OFSI
  4. WWolfsberg · Wolfsberg Principles