Common signs include frequent deposits just under the reporting threshold, use of multiple accounts, transfers across different banks or jurisdictions, and repeated cash activity that does not match the customer’s profile. Another warning sign is when funds are moved in a way that creates little economic purpose beyond avoiding detection. Analysts should look for repetition, dispersion, and threshold avoidance together.
How structuring shows up in transaction patterns
structuring is usually visible not as one dramatic transfer, but as a pattern built to stay below scrutiny while still moving value. The strongest signal is repetition: many small deposits, withdrawals, or transfers that appear intentionally fragmented, especially when the amounts cluster just under a reporting threshold. When those movements are combined with multiple accounts, different branches, or different jurisdictions, the pattern becomes more suspicious than any single transaction on its own.
What matters is the sequence and the relationship between transactions. Repeated cash activity, rapid movement between accounts, and funds that are quickly consolidated or re-divided can indicate an attempt to disguise origin or destination. Analysts should pay close attention when the activity has little apparent business or personal purpose, because that is often what separates ordinary cash use from deliberate threshold avoidance.
- Look for repeated deposits or withdrawals that fall just below common reporting or review thresholds.
- Compare the pattern across accounts, counterparties, branches, and jurisdictions for coordination.
- Check whether the volume and timing of cash activity match the stated customer profile.
- Flag cases where the funds are fragmented and then reassembled with no clear economic reason.
Patterns like these are most useful when reviewed over time. A single below-threshold deposit may be normal, but a repeated pattern of small transactions across related accounts is much more telling.
Why repetition, dispersion, and threshold avoidance matter
The core investigative logic is that structuring tries to defeat visibility by making each individual transaction look ordinary. That means the analyst has to focus on the pattern, not just the amount. Threshold avoidance, dispersion across channels, and repeated cash activity together are strong indicators because they show planning, not coincidence.
In practice, the key question is whether the activity is consistent with a real commercial or personal purpose. If the customer normally does not handle cash, does not operate across multiple institutions, or has no clear need for repeated fragmented transfers, the pattern becomes harder to explain legitimately. Financial Crimes Enforcement Network guidance and similar AML frameworks emphasize this pattern-based review because structuring often only becomes visible when transactions are viewed as a sequence rather than in isolation.
Source context can also strengthen detection. For example, NHI Mgmt Group notes that the Ultimate Guide to Non-Human Identities reports that 79% of organisations have experienced secrets leaks, which is a reminder that hidden or distributed activity often creates detection gaps. While that statistic comes from a different security domain, the same operational lesson applies here: fragmented behavior becomes more dangerous when visibility is weak.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM — Security Continuous Monitoring | Pattern-based detection of repeated suspicious transfers fits continuous monitoring. |
| Recommendation — Tune monitoring rules to detect repeated threshold-avoidance patterns and unusual transaction dispersion. | ||
| CIS Controls v8 | 8 — Audit Log Management | Transaction review depends on retaining and correlating logs across accounts and venues. |
| 13 — Network Monitoring and Defense | Cross-bank or cross-jurisdiction movement requires monitoring of unusual flows and routing. | |
| Recommendation — Centralise and correlate transaction logs so fragmented activity can be reconstructed. Monitor for anomalous transfer paths that indicate intentional dispersion or layering. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Customer profile verification affects whether the activity matches the stated identity and expected behaviour. |
| Recommendation — Validate customer identity and expected activity profile before accepting repeated cash movement as normal. | ||
Practitioner Guidance
What to prioritise: Treat the pattern as the signal, not the value of any one transaction. Build alerts that look for repeated sub-threshold activity, account hopping, and cross-jurisdiction movement together, because those combinations are far more predictive than a single cash event.
What to verify: Confirm whether the customer’s stated profile can plausibly explain the cadence, routing, and cash intensity. If the activity is frequent, fragmented, and economically redundant, escalate for deeper review rather than waiting for a larger transaction to appear.
Practitioner takeaway: Structuring is rarely proven by one movement alone; it is usually established by a repeated pattern that is deliberately engineered to look ordinary, so the review must be sequence-based and context-aware.
Related resources from NHI Mgmt Group
- How should compliance teams operationalise crypto sanctions when exchanges and payment providers are used to move funds for a designated state network?
- What happens when illicit actors move funds through cross-chain bridges instead of centralized services?
- Who is accountable when a compromised SaaS integration is used to move across multiple clouds?
- Who is accountable when mule accounts are used to launder stolen funds?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org