Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should financial institutions design AML controls to…
Identity Beyond IAM

How should financial institutions design AML controls to catch money laundering across placement, layering, and integration stages?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Financial institutions should map controls to each stage of the laundering lifecycle. Placement needs detection of unusual cash movement and structuring. Layering requires transaction monitoring for rapid transfers, offshore routing, shell entities, and opaque ownership. Integration needs stronger customer due diligence, source-of-funds checks, and ongoing monitoring so illicit money is identified before it appears legitimate.

Designing AML controls for the full laundering lifecycle

Effective AML control design works best when the institution treats laundering as a staged process, not a single event. Placement, layering, and integration each create different observable patterns, so the control stack should be stage-specific: cash and deposit behaviour at the front end, transactional movement and network structure in the middle, and customer legitimacy checks at the point where illicit funds try to blend into normal business activity.

At placement, the goal is to spot indicators that funds are being introduced in ways that are inconsistent with the customer profile, product purpose, or branch behaviour. That means comparing cash activity, frequency, denomination patterns, and account usage against expected norms rather than relying on one isolated threshold.

At layering, institutions need transaction monitoring that can follow speed, dispersion, and concealment patterns. Rapid in-and-out transfers, repeated routing through offshore or high-risk corridors, movement across many accounts, and use of shell entities or opaque ownership structures are all signals that the system should score together, not in isolation.

At integration, controls should focus on whether illicit value is being normalised through apparently legitimate ownership, business revenue, investment activity, or asset purchase. Stronger customer due diligence, source-of-funds and source-of-wealth checks, and ongoing monitoring matter here because the risk is no longer just movement, it is successful re-entry into the regulated economy.

What good control design looks like in practice

For institutions, the most effective design choice is to map typologies to data and decision points. Placement controls should be anchored in cash, deposit, and onboarding data. Layering controls should bring together payments, counterparties, jurisdictions, device and channel patterns, and entity relationships. Integration controls should connect transaction behaviour back to KYC files, ownership data, adverse information, and account purpose.

That also means avoiding a narrow “rules only” mindset. Rules are useful for known patterns such as structuring, but effective AML programs usually need risk scoring, network analysis, threshold tuning, scenario review, and analyst escalation paths so that unusual behaviour can be assessed in context. The best controls are those that can explain why a pattern is suspicious, not just that a threshold was crossed.

Institutions should also FATF Recommendations as the baseline for how CDD, beneficial ownership, and monitoring expectations fit together, and use FinCEN and EBA AML/CFT Guidance to align controls with the supervisory expectations in their operating jurisdictions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v88 — Audit Log ManagementTransaction monitoring depends on complete, reliable activity records.
5 — Account ManagementAML control quality depends on knowing who owns and controls accounts and entities.
6 — Access Control ManagementBeneficial ownership and role-based control help prevent hidden account abuse.
Recommendation — Centralize and retain transaction logs so AML scenarios can detect staged movement patterns. Maintain accurate account ownership and review dormant or unusual account activity. Restrict privileged access to AML systems and review exceptions tied to high-risk activity.
NIST CSF 2.0PR.AC — Access ControlCustomer and transaction governance depends on controlling who can move and alter value.
DE.CM — Continuous MonitoringAML detection relies on continuous monitoring of transaction behavior across stages.
GV.RM — Risk Management StrategyAML control design is a risk-based program that prioritizes higher-risk products and typologies.
Recommendation — Apply access control governance to transaction workflows and high-risk account actions. Continuously monitor transactions and customer behavior for layering and integration indicators. Align monitoring depth and escalation thresholds to documented AML risk appetite.
NIST SP 800-63IAL — Identity Assurance LevelCDD and beneficial ownership checks rely on assurance about who the customer really is.
AAL — Authenticator Assurance LevelSensitive financial workflows need stronger assurance for who is initiating activity.
FAL — Federation Assurance LevelCross-institution and third-party relationships affect the trustworthiness of shared identity assertions.
Recommendation — Set assurance expectations for customer identity proofing and ownership validation. Require stronger authentication for account changes, high-risk transfers, and privileged review. Validate federated identity assertions before relying on external customer or partner signals.
MITRE ATT&CKT1020 — Automated ExfiltrationLayering often uses repeated, automated movement to conceal the origin of funds.
Recommendation — Hunt for repeated automated transfer patterns that indicate concealment or dispersion.

Practitioner Guidance

What to prioritise: Build scenarios around stage transitions, not just alert volume. A single customer can generate weak signals at placement, layering, and integration that only become meaningful when reviewed as a sequence.

What to verify: Make sure each alert path has the underlying data needed to support investigation, especially ownership data, counterparty relationships, jurisdiction context, and reason-for-account documentation. If analysts cannot explain the business rationale for the activity, the control is too thin.

Common mistake: Treating source-of-funds checks as a one-time onboarding exercise. In higher-risk relationships, the source of funds can change with the transaction pattern, so the control needs to be revisited when activity shifts rather than when the customer profile is first created.

Practitioner takeaway: The strongest AML programs do not try to detect “money laundering” as a single label, they detect whether the customer’s financial behaviour is evolving in a way that breaks the expected story from placement through integration.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org