Warning signs include repeated deposits just below reporting thresholds, inconsistent invoice values in trade transactions, unusual payment patterns, and account behavior that does not match the customer profile. Weak staff escalation processes and poor technology coverage also indicate gaps. If these indicators are not reviewed together, suspicious activity can look routine until losses or regulatory issues appear.
What the warning signs usually look like
Missing laundering activity is rarely signaled by one metric alone. The strongest indicators are patterns that look ordinary in isolation but become suspicious when combined: structuring just under reporting thresholds, trade invoices that do not fit the goods or counterparties, payment flows that are unusually circular, and customer behavior that diverges from stated business activity. A framework gap often shows up when those signals are not connected across channels.
Teams should also watch for control blind spots that let activity pass as routine. If escalation thresholds are vague, case review queues are inconsistent, or transaction monitoring rules cover only part of the product set, suspicious activity can blend into normal throughput. That is especially true when staff rely on manual judgment without enough data coverage to test whether the pattern is isolated or repeated.
For AML programmes, the practical question is not whether a single transaction is abnormal, but whether the system can reconstruct intent across deposits, payments, invoices, counterparties, and account behavior. Where the framework is weak, the same customer can appear compliant in one channel and suspicious in another, which makes detection depend on someone noticing the pattern late.
Why these gaps matter in practice
Important laundering activity is often hidden by fragmentation. If payment monitoring, customer due diligence, trade documentation review, and escalation processes are not joined up, the programme may miss layering behavior, pass-through accounts, or transactions that are deliberately kept below obvious thresholds. The gap is usually not a total absence of alerts, but a failure to correlate them into a case that justifies action.
Weak coverage also creates governance risk. Poorly calibrated controls can produce either too many false positives, which exhaust review capacity, or too few meaningful alerts, which leaves suspicious activity unexamined. In both cases, the institution loses confidence in the control framework, and the gap can persist until regulators, auditors, or law enforcement identify the pattern first.
That is why a strong AML framework should be judged by its ability to explain behavior, not just count alerts. A useful control environment can show whether the customer profile, transaction pattern, and supporting documents all make sense together, and whether staff escalation is actually happening when the pattern stops making business sense.
What a sound detection approach needs to connect
A credible framework links transaction monitoring, customer risk scoring, trade finance checks, case management, and escalation rules into one review path. The most effective control design uses multiple signals, because laundering techniques are often built to avoid any single threshold or rule. A transaction can be small, but still meaningful if it repeats, clusters, or fits a known placement or layering pattern.
It also needs coverage across products and channels. Payments, cash activity, trade flows, and account behavior should not be assessed in separate silos if the same customer can move value across them. Where technology only sees one part of the picture, investigators are forced to infer intent from partial evidence, which makes it easier for suspicious activity to look routine.
External guidance from FATF Recommendations and FinCEN reinforces the need to combine customer due diligence, monitoring, and suspicious activity reporting into a consistent control model. For institutions operating in Europe, EBA AML/CFT Guidance is a useful reference for aligning controls with supervisory expectations.
Risk and Threat Considerations
When AML controls miss laundering activity, the risk is not just regulatory non-compliance. It can also mean the organisation becomes an enabler of placement, layering, or integration, especially when suspicious transactions are split across accounts, products, or jurisdictions to avoid notice.
Failure mechanism: Gaps usually appear when monitoring rules are too narrow, escalation is inconsistent, or case reviewers lack the context to connect repeated low-value events, inconsistent trade data, and profile mismatches into one suspicious pattern.
Impact: The result can be delayed detection, weak SAR quality, repeat exposure to the same typology, regulatory findings, and higher remediation cost once the activity is finally reconstructed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | AML monitoring depends on reviewing activity and escalating suspicious patterns. |
| AC-6 — Least Privilege | Access to AML case handling and overrides should be tightly limited. | |
| SI-4 — System Monitoring | Transaction monitoring is a detection problem that relies on continuous visibility. | |
| Recommendation — Review transaction and case audit data for recurring borderline patterns. Restrict alert suppression and case disposition authority to approved reviewers. Monitor payment, customer, and trade signals for correlated suspicious behavior. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | AML case workflows need controlled access and review authority. |
| A.8.16 — Monitoring activities | Continuous monitoring is central to spotting laundering patterns across channels. | |
| Recommendation — Limit who can review, override, or close suspicious activity cases. Correlate alerts across payment, customer, and trade monitoring outputs. | ||
Practitioner Guidance
What to verify: Test whether alerts from deposits, payments, trade finance, and account behavior can be linked to the same customer and the same underlying pattern. If a case review process cannot explain why repeated borderline activity was closed as normal, the control is not giving you enough evidence to trust the decision.
Decision rule: If the only reason an activity is not escalated is that each event looks small on its own, treat that as a monitoring weakness, not as reassurance. The control should be able to show why the combined pattern is acceptable, not just why each fragment passed a threshold.
Practitioner takeaway: AML programmes fail most often when they measure transactions instead of behavior, so the real test is whether the framework can connect small signals into a credible account-level story before the pattern hardens into missed suspicious activity.
Related resources from NHI Mgmt Group
- What are the signs that VMware ESXi security monitoring is missing important activity?
- What are the signs that money laundering controls are missing suspicious activity?
- What are the signs that cloud API hunting is missing important attacker activity?
- What are the signs that a cloud risk assessment is missing important control gaps?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org