The transaction patterns that show up most often on suspicious activity reports are structuring, rapid in-and-out fund movement, round-tripping, unusual cross-border flows, mismatches between a customer's stated profile and their actual activity, heavy reliance on third parties, and transactions clustered just below reporting thresholds that often indicate suspicious behaviour. Any one of these on its own might have an innocent explanation. Two or three appearing together on the same customer file rarely do.
Speed matters here. Under EBA consolidated guidelines, transactions that are complex, unusually structured in an unusual pattern or lacking any apparent economic or lawful purpose must be treated as higher risk and pushed through enhanced measures without delay.
Here's the shortlist worth pinning above your desk:
- Structuring or smurfing (splitting funds to dodge reporting thresholds)
- Rapid in-and-out movement with no holding period
- Round-tripping funds through multiple accounts back to origin
- Transfers to or from high-risk jurisdictions
- Customer behavior that doesn't match stated occupation or business
- Frequent use of intermediaries, mules, or nominee accounts
- Repeated transactions sitting just under the reporting line
- Sudden, unexplained shifts in transaction volume or frequency
Escalate immediately to enhanced due diligence, or move straight to filing a suspicious transaction report, the moment you see clustered indicators, an unusually large or structurally complex transaction, or any sign of layering through anonymous intermediaries.
Pro Tip: Don't wait for a single alert to hit a severity threshold before acting. Three moderate-risk signals on one customer file usually outweigh one high-severity alert in isolation.
Key Takeaways
Suspicious transaction patterns are rarely single events. They're clusters of behavioral, structural, and timing indicators that only become visible when analysts compare transactions across time and accounts rather than reviewing each one in isolation.
| Point | Details |
|---|---|
| Watch for clustering | Two or three moderate indicators together outweigh one isolated high-severity alert. |
| Triage fast, escalate faster | Use the five-question triage check before any file sits idle in the queue. |
| Match evidence to the STR narrative | Structure reports around who, when, what, why, and how, backed by transaction logs and CDD records. |
| Sector context changes the signal | Currency exchange and crypto operators face distinct red flags requiring tailored monitoring. |
| Centralize monitoring across branches | Platforms like Currexchanger connect alerts network-wide so structuring across locations doesn't go unnoticed. |
Regulator Guidance Worth Bookmarking
Key sources behind this article include EBA's risk factor guidelines, FATF's currency exchange sector research, FINTRAC's MSB indicators, and EBA's crypto-specific amending guidance. Confirm procedural specifics with your national FIU before filing.
Table of Contents
- Quick Triage Checklist for First-Pass Review
- Concrete Examples of Suspicious Transaction Patterns by Category
- How to Review, Escalate, and File an STR
- Sector Red Flags for Currency Exchange and Crypto Operators
- Investigation Checklist and Documentation Standards
- How Transaction Monitoring Software Reduces Missed Red Flags
- Sources
Quick Triage Checklist for First-Pass Review
Before an alert becomes a full investigation, run it through five yes/no questions. Does the transaction match the customer's known profile? Is the value or timing out of character? Does it rely on third parties or intermediaries? Is the counterparty located in a high-risk jurisdiction? Does the pattern resemble structuring?
A "yes" on two or more should move the file out of the routine queue.
Minimum documentary checks during triage:
- Re-verify CDD data against the current transaction
- Prompt for source-of-funds documentation if not already on file
- Pull recent transaction history for pattern comparison
- Cross-check the counterparty against sanctions and PEP lists
EBA's risk-based supervision guidelines recommend sampling transactions and customer files during review rather than relying solely on policy checks, since patterns often surface only when files are compared side by side.
One more thing: triage is not the moment to tip off the customer. Never reference an internal review, an STR, or a "compliance flag" in any communication with the account holder, even indirectly.
Concrete Examples of Suspicious Transaction Patterns by Category
Money laundering typically moves through three stages, and the transaction patterns look different at each one.
Placement is where dirty cash first enters the financial system. Watch for structuring and smurfing (multiple deposits kept just under reporting thresholds), cash couriering (a single individual making deposits on behalf of several unrelated parties), and unusually large denomination requests with no business rationale.
Layering is where funds get moved to obscure their origin. Common signs include rapid transfers across multiple accounts and jurisdictions within a short window, use of shell companies or nominee accounts with no clear beneficial owner, and round-tripping, where money leaves an account and returns through a different route days or weeks later.
Integration is the final stage, where laundered funds re-enter the legitimate economy. Look for large asset purchases paid in cash or through opaque intermediaries, and conversion into cryptocurrency followed by immediate withdrawal to a self-hosted wallet.
A handful of patterns cut across all three stages:
- Multiple senders wiring funds to the same beneficiary with no apparent relationship
- Transactions that consistently land just under a reporting threshold, repeated over weeks
- Payment instruments inconsistent with the customer's stated business (a retail shop paying suppliers in crypto, for instance)
- A sudden, sharp change in transaction volume or geography with no corresponding change in the customer's business
Three anonymized scenarios show how these show up in practice.
Scenario one: deposit structuring. A retail customer makes six cash deposits across four days, each just under the local reporting threshold, into an account previously used for modest personal transactions. Indicator tags: placement, structuring. Analyst takeaway: the pattern only becomes visible when deposits are aggregated across days, not viewed transaction by transaction.
Scenario two: rapid crypto conversion and immediate withdrawal. A customer exchanges a large sum of fiat currency, converts it to a cryptocurrency the same day, then withdraws the full balance to a self-hosted wallet address within hours. Indicator tags: layering, integration. Analyst takeaway: the absence of any holding period, combined with a self-hosted destination, is the signal, not the transaction size alone.
Scenario three: nominee payments obscuring the beneficiary. A business account receives payments from five apparently unrelated senders, then forwards nearly the full balance to a single overseas account within 48 hours. Indicator tags: layering, third-party use. Analyst takeaway: the account is functioning as a pass-through, not a business collecting revenue.
Watch for signals that tend to travel in packs: a reluctant customer, unusual denomination requests, and rapid outward transfers occurring together is a stronger indicator than any single element. FINTRAC's guidance for money services businesses lists complicated transfers designed to hide the source of funds and multiple small transfers that aggregate into a large sum among the most common indicators reporting entities encounter.
Pro Tip: Build a running behavioral profile per customer instead of scoring each transaction in isolation. A pattern that looks unremarkable transaction by transaction often becomes obvious the moment you plot it on a timeline.
How to Review, Escalate, and File an STR
Once an alert clears triage, the review needs structure. Work through it in order:
- Re-verify identity and CDD records against current documentation
- Map the full transaction timeline, including related accounts
- Collect supporting documents: transaction logs, contracts, communications
- Screen against current sanctions and PEP lists
- Check for linked or related accounts under common control
For the narrative itself, interpretative guidance on STR content points to a simple structure: who was involved, when the activity occurred, what happened, why it's suspicious, and how the funds moved. Attach transaction logs, CDD copies, and any relevant communications as supporting evidence.
Follow your national FIU's filing procedure exactly, and understand your jurisdiction's rules before suspending or refusing a transaction. Under EBA guidance, transactions lacking a sound economic or lawful purpose warrant enhanced scrutiny by default, regardless of size.
Tipping off remains the most common procedural error at this stage. Never disclose to a customer, directly or indirectly, that a report has been filed or is under consideration. Our guide to reporting requirements covers jurisdiction-specific filing windows in more depth.
Sector Red Flags for Currency Exchange and Crypto Operators
Exchange operators face a distinct set of warning signs. FATF research identifies the currency exchange sector as vulnerable across all three laundering stages, largely because of high-velocity cash flow and inconsistent risk-based controls.
Watch for:
- Customers requesting large-denomination notes with no clear reason
- Repeated exchanges with no apparent commercial purpose
- Customers indifferent to exchange rates or fees, a behavioral cue that often signals the funds aren't really theirs
- Scripted or written instructions dictating exact amounts or denominations, which often points to a courier acting on someone else's behalf
- Customers who abandon the transaction the moment they're asked about source of funds
Crypto and CASP operators face a parallel list. EBA's amending guidelines flag transfers to self-hosted addresses, use of mixers or tumblers, sudden spikes in on-ramp and off-ramp activity, and transfers repeatedly staying just under verification thresholds.
Red flags are signals, not proof of wrongdoing. The job isn't to treat any single indicator as conclusive. It's to notice when several appear on the same customer file within a short window, and to weigh automated scoring against a human review that catches what the algorithm doesn't.
On the technology side, useful capabilities include real-time alerting, chain-of-custody logging, behavior-based alert profiling, and wallet address tagging tied into blockchain risk tools. Partner resources like this AML compliance guide for crypto firms go deeper on CASP-specific controls. Our own AML compliance guide for exchange offices breaks down enhanced due diligence measures suited to physical branch networks.
Investigation Checklist and Documentation Standards
An STR is only as strong as the file behind it. Essential documentation includes:
- Full transaction logs with timestamps
- The funds movement chain across all involved accounts
- Current CDD/KYC records
- Any communications with the customer
- IP and device data for digital or online transactions
- Screenshots of the original alert and any related system flags
Internally, keep records tight and auditable:
- Versioned analyst notes showing how the assessment evolved
- A chain-of-custody log for every piece of evidence collected
- A decision log recording who reviewed the file, what they decided, and when
Attach the strongest available evidence to the STR itself, and confirm your retention period against national requirements before archiving. Our accounting integration guide covers how centralized records simplify this step across multiple branches.
Prioritizing Alerts Without Missing the Cluster
Most teams over-index on single high-severity alerts and under-index on clusters of moderate ones. That's backward. A new, unexpected counterparty relationship combined with two mid-level flags deserves priority over one isolated high score.
Automated scoring should narrow the queue, not make the final call. Human review catches the false negatives scoring models miss.
Pro Tip: Track customer behavior over months, not transactions. Isolated alerts miss the slow drift that a rolling profile catches immediately.
How Transaction Monitoring Software Reduces Missed Red Flags
Everything above depends on catching patterns across accounts, branches, and time windows, which is exactly where manual review breaks down at scale. Currexchanger centralizes transaction monitoring, AML/KYC checks, and audit trails into one system, so alerts triggered at one branch get flagged network-wide instead of sitting in a single office's queue.

The platform generates real-time alerts on the patterns covered here, structuring, threshold clustering, unusual counterparties, and attaches supporting documentation automatically, so your STR file is built as the investigation happens rather than assembled after the fact. Multi-branch visibility means a customer structuring deposits across three locations shows up as one connected case, not three unrelated alerts. Compliance teams at currency exchange networks can request a demo of Currexchanger to see how tailored workflows fit their specific branch structure and reporting obligations.
Sources
- Guidelines on ML/TF risk factors (EBA)
- Money laundering through money remittance and currency exchange providers (FATF/MONEYVAL)
- Money laundering and terrorist financing indicators — Money services businesses (FINTRAC)
FAQ
What Are Examples of Suspicious Activity?
Common examples include structuring deposits to avoid reporting thresholds, rapid movement of funds through multiple accounts, transactions with no clear economic purpose, and customers who avoid questions about source of funds.
What Is an Example of an Unusual Transaction?
A customer converting a large fiat sum to cryptocurrency and immediately withdrawing it to a self-hosted wallet, with no holding period, is a classic example flagged under EBA's crypto-specific guidance.
What Counts as Suspicious Bank Activity?
Activity counts as suspicious when it's complex, unusually large, structurally out of pattern, or lacks a lawful economic purpose, the threshold EBA guidelines set for triggering enhanced due diligence.
When Should a Compliance Officer File an STR Instead of Just Escalating to EDD?
File an STR once clustered indicators, evidence of layering, or use of anonymous intermediaries make the activity look deliberately concealed rather than merely unusual; EDD alone fits cases still requiring more information before that judgment can be made.
Can Software Help Detect These Patterns Across Multiple Branches?
Yes. Platforms like Currexchanger consolidate transaction data across branch networks so a customer structuring deposits at different locations appears as one connected alert instead of scattered, unrelated flags.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
