Football bodies should reduce risk by tightening transfer oversight, screening owners and intermediaries, and forcing payments through auditable channels. The article points to clear gaps in transparency around agent commissions, third party ownership, and club finances. A practical response is to combine licensing rules, investigative checks, whistleblowing, and monitored payment flows so suspicious money cannot move through the sport unnoticed.
Why transfer and ownership controls matter for money laundering
Football transfers and club ownership create a high-value, cross-border payment environment with multiple intermediaries, opaque beneficial ownership structures, and legitimate-looking commercial flows. That combination makes the sector attractive for placement, layering, and integration of illicit funds, especially when commissions, loans, and ownership changes are difficult to trace end to end.
Money laundering risk rises when regulators or governing bodies cannot reliably see who is paying, who benefits, and whether the transaction value matches the sporting rationale. The practical problem is not just the presence of cash, but the lack of clean audit trails across transfer fees, agent compensation, and club control changes.
How governing bodies should tighten the transfer chain
Governance needs to start with a simple rule: if a transfer payment cannot be traced, verified, and reconciled against the underlying deal, it should not clear. That means stronger due diligence on player contracts, intermediary disclosures, source of funds checks, and payment routing through monitored accounts rather than side agreements or informal settlement channels.
Oversight is strongest when the governing body treats each transfer as a linked set of obligations, not a single fee. The relevant questions are whether the buying club can justify the payment, whether the seller is the true recipient, whether agent fees are transparent, and whether any third-party interest could distort the transaction or conceal value transfer.
Independent review should focus on anomalies that often matter more than the nominal fee itself: unusual commission structures, repeated use of the same intermediaries, payments split across multiple entities, and transfers that appear disconnected from market value or sporting need. Those are the patterns that can turn a normal transfer into a laundering channel.
How club ownership and payments should be controlled
Club ownership screening should go beyond name checks and verify beneficial ownership, control rights, and source of wealth before approval. Hidden controllers, nominee structures, and layered holding companies can allow illicit proceeds to enter the game while presenting a compliant front at the licence stage.
Payment control matters just as much after approval. Governing bodies should require auditable payment flows, retain records on ownership changes and related-party transactions, and insist on reporting that makes dividends, loans, sponsorships, and asset sales visible enough to test for circular movement or disguised value transfer. FATF Recommendations, the AML and KYC framework is the clearest external reference point for beneficial ownership, customer due diligence, and suspicious transaction reporting in this type of environment.
For governance bodies, the hardest cases are often not outright criminal transactions but commercially complex ones that mix legitimate football business with opaque funding. That is why licensing, sanctions checks, beneficial ownership review, and ongoing monitoring need to work together rather than as separate compliance tasks. ISO/IEC 27002:2022 Information Security Controls is useful here as a control model for record integrity, monitoring, and access to transaction evidence, even though the subject is financial crime rather than cyber only.
What effective detection and enforcement looks like
Reducing laundering risk is not just about pre-approval checks. Governing bodies need continuous detection capability, including whistleblowing routes, transaction monitoring, and the power to investigate payment anomalies after the fact. If suspicious value moves through a club structure, the body should be able to freeze approval, request supporting records, and escalate to the relevant financial crime authority.
The best enforcement models connect sporting governance to financial crime controls. That means correlating ownership changes, agent relationships, club insolvency signals, and unusual payment patterns so the body can see whether the same network appears across multiple clubs or transfers. NIST Cybersecurity Framework 2.0 is not a football-specific standard, but its govern, identify, protect, detect, respond, and recover structure maps cleanly to an investigative and monitoring programme.
Where clubs operate across jurisdictions, the control problem gets harder because records, regulators, and banking routes may differ by country. In practice, that means the governing body should set a minimum evidentiary standard that applies across all participants, so an opaque structure in one market does not become the weak link for the entire competition.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Transfer and ownership checks depend on reviewing transaction evidence and anomalies. |
| AC-6 — Least Privilege | Limits who can approve, modify, or override high-risk transfer and payment decisions. | |
| IA-2 — Identification and Authentication (Organizational Users) | Controls access to licensing, approval, and investigative systems used in oversight. | |
| Recommendation — Review transfer and ownership records for anomalies and escalate suspicious payment patterns. Restrict approval and override rights to the smallest set of accountable officials. Require strong authentication for staff who approve or investigate transfer and ownership cases. | ||
| NIST CSF 2.0 | GV.OV-01 — Oversight of Security Risk Management | Governance bodies need oversight of laundering risk controls and accountability. |
| DE.CM-09 — Monitoring for anomalous activity | Continuous monitoring is needed to spot suspicious transfer and payment patterns. | |
| Recommendation — Define board-level oversight for transfer and ownership risk controls. Monitor payment and ownership activity for anomalies that warrant investigation. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control supports segregation of duties around approvals and evidence handling. |
| A.5.34 — Privacy and protection of PII | Ownership and due diligence files often contain sensitive personal and financial data. | |
| A.8.15 — Logging | Auditability depends on logs for transfers, approvals, and payment changes. | |
| Recommendation — Limit who can approve, alter, or view sensitive transfer records. Protect sensitive ownership and due-diligence records from improper disclosure. Log ownership changes, approvals, and payment actions in a tamper-resistant way. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Immutable logging supports investigation of transfer and ownership activity. |
| CIS-6 — Access Control Management | Least privilege reduces the chance of hidden or unauthorized payment approvals. | |
| Recommendation — Centralize and protect logs for transfer approvals and payment workflows. Restrict transfer and ownership approval rights to approved roles only. | ||
Practitioner Guidance
What to prioritise: Start with the transaction points that combine high value and low transparency, especially agent commissions, related-party payments, and ownership changes. Those are the places where laundering risk is most likely to hide in plain sight.
What to verify: Require documentary proof for beneficial ownership, source of funds, payment recipient, and commercial rationale before approval. If any one of those cannot be reconciled, treat the case as higher risk until it is resolved.
Decision rule: If a transfer or acquisition depends on undocumented side payments, opaque intermediaries, or a structure that cannot be audited end to end, the governing body should not rely on trust or reputation as a control.
Practitioner takeaway: The control objective is not to block every complex football deal, but to make sure every material payment and ownership change is explainable, traceable, and challengeable before illicit funds can disappear into the sport.
Related resources from NHI Mgmt Group
- How should teams reduce the risk from overprivileged NHIs?
- How should crypto firms screen wallets and transactions to reduce fraud and money laundering risk?
- Why do AML transaction monitoring rules reduce fraud and money laundering risk?
- How should banks combine KYC, CDD, and eKYC to reduce money laundering risk in digital channels?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org