A note on terminology
The FATF canon describes three stages of money laundering: placement, layering and integration. Structuring is not a fourth stage. It is the dominant technique by which placement is executed, and in a digitised economy it has largely displaced the suitcase of cash. Treating structuring as the operational face of placement is analytically sound, and it is how monitoring systems actually encounter the problem – not as a stage, but as a pattern.
Scale is worth stating once, carefully. UNODC places annual global laundering at 2 to 5 per cent of global GDP, roughly USD 800 billion to USD 2 trillion1. That range originates in an IMF “consensus” estimate published in 1998 and should be read as an order of magnitude rather than a measurement2. The Basel AML Index 2025, covering 177 jurisdictions with data collected to 10 November 2025, put the global average risk score at 5.28 on a 0-10 scale, statistically unchanged year on year3. The problem is large, persistent and poorly measured. That is precisely why detection has to rest on analysis rather than on headline numbers.
Stage one: placement, executed as structuring
Indian law fixes the reference points the launderer works around. Rule 3 of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 requires every reporting entity to maintain records of all cash transactions above Rs 10 lakh; all series of integrally connected cash transactions individually below Rs 10 lakh where the series occurs within a month and the monthly aggregate exceeds Rs 10 lakh; all receipts by non-profit organisations above Rs 10 lakh; all cash transactions involving forged or counterfeit instruments; all cross-border wire transfers above Rs 5 lakh where either origin or destination is in India; and all purchases and sales of immovable property of Rs 50 lakh or more4.
The integrally connected limb is the anti-structuring provision, and it is the one most often under-implemented. A rule that fires on a single Rs 10.5 lakh deposit is trivial to defeat. A rule that aggregates across accounts, across related parties, across a rolling month and across channels is not.
What the analyst should be doing at this stage:
- Aggregate before you threshold. Cash deposits, UPI credits, cash-equivalent instruments and third-party transfers must be summed at customer, related-party, device and beneficiary level before any limit is applied. Structuring is invisible at transaction level and very obvious at aggregate level.
- Baseline against the declared profile, not the population. A Rs 8 lakh monthly cash cycle is unremarkable for a jewellery retailer and inexplicable for a salaried customer. The KYC record is the control. The Reserve Bank of India (Commercial Banks – Know Your Customer) Directions, 2025, which together with nine sibling directions for other entity types replaced the 2016 Master Direction on 28 November 2025, retain ongoing due diligence and the obligation to keep the customer profile aligned to observed activity. The NBFC equivalent carries the same architecture6.
- Score threshold proximity. Repeated activity clustering just below Rs 10 lakh, or just below Rs 5 lakh on cross-border wires, is not evidence of compliance. It is evidence of knowledge of the threshold. Near-miss density deserves a scenario of its own.
- Test the entry channel. Cash-intensive businesses, prepaid instruments, AePS and business correspondent channels, and newly onboarded accounts receiving immediate high-value credits are the standard placement doors.
Stage two: layering, executed through mule networks
Layering is where the Indian problem has changed shape. UPI processed 24,161.69 crore transactions worth Rs 314.23 lakh crore in FY2025-26, up from 18,586.60 crore transactions worth Rs 260.56 lakh crore in FY2024-257. At that density a launderer does not need offshore trusts. Twenty mule accounts and four hours will probably do the job.
The regulatory response is already explicit about the method. RBI has rolled out MuleHunter.AI, an AI/ML solution for mule account detection developed by the Reserve Bank Innovation Hub, live in 26 banks as at March 2026 and is being scaled further. The Indian Digital Payment Intelligence Corporation was incorporated as a Section 8 company on 16 October 2025 to detect, prevent and analyse payment fraud in real time using AI, machine learning and big data analytics. Most importantly for practitioners, banks have been advised to deploy robust real-time transaction monitoring software, AI/ML tools for detecting suspicious patterns, and network analytics to identify mule networks. In May 2026 the Indian Cyber Crime Coordination Centre and RBIH signed a memorandum of understanding to feed Suspect Registry intelligence into AI-driven fraud-risk models. Parliamentary replies indicate the Suspect Registry had shared details of approximately 27.37 lakh Layer-1 mule accounts as at 31 January 202610.
How mules are actually traced:
- Entity resolution first. Shared mobile numbers, device fingerprints, IP ranges, address strings, beneficiary accounts, nominees, introducers and email domains. Most mule networks are discovered through identity overlap, not through transaction analysis.
- Then the graph. Mule networks are structurally distinctive: high in-degree from unrelated remitters, negligible balance retention, fan-in followed by fan-out within hours, and a small set of terminal cash-out nodes. Account-by-account review cannot see this. Community detection, centrality scoring and shortest-path analysis can.
- Then velocity and dormancy. The classic signature is an account dormant for months that suddenly cycles credits down to a zero balance, repeatedly, within a single day.
- Then behaviour. Session, device and behavioural biometric signals separate a genuine account holder from an operator working forty accounts.
- Then the exit. Layering ends somewhere. ATM clusters, merchant settlements, prepaid loads, remittance corridors and virtual asset off-ramps are where the network becomes visible.
Stage three: integration
Integration is the hardest stage to detect because, by design, it looks legitimate. Property purchases, loan repayments from unexplained sources, over-invoiced trade, capital infusions into thinly traded entities, bullion, and settlement through securities intermediaries. This is why the Indian perimeter is deliberately multi-regulator. SEBI’s Master Circular on AML/CFT obligations of securities market intermediaries, dated 6 June 2024, applies the same PMLA architecture across the securities chain11, just as the RBI directions do across banking and NBFC channels.
Analyst focus at integration:
- Source of wealth versus source of funds. Integration fails on provenance, not on pattern. The question is not where the money came from last week, but how the customer came to have it at all.
- Reverse the flow. Start from the asset and work backwards to the funding leg. Registration and settlement records are usually better evidence than account statements.
- Look for the round trip. Funds exiting as loans and returning as equity, or repayments exceeding declared income, are the classic tells.
- Test economic rationality. Loss-making trades, uncommercial pricing, and early repayment funded by a new counterparty are among the strongest integration indicators.
How analysts piece it together
FATF’s Mutual Evaluation Report of India, published on 19 September 2024, placed India in regular follow-up and found a high level of technical compliance, while identifying supervision and the implementation of preventive measures as areas needing major improvement12. The gap is not rules. It is analysis.
The RBI’s Internal Risk Assessment Guidance for ML/TF Risks of 10 October 2024 supplies the analytical spine: inherent risk, control effectiveness and residual risk assessed at both enterprise and business-line level, with factor weighting and cross-functional input13. An analyst who has read the institution’s own internal risk assessment knows which products carry which typologies and can prioritise accordingly. An analyst who has not is perhaps working blind or shooting in the dark.
Globally the direction of travel is explicit. The Wolfsberg Group’s Statement on Effective Monitoring for Suspicious Activity of July 2024 argued that the value derived from ever-increasing STR volumes is not proportionate to outcomes, and that institutions should monitor activity – customer attributes, behaviour and transactions combined – rather than transactions alone14. Part II, published in August 2025, sets out a transition framework resting on validation, model risk governance proportional to financial crime risk, and explainability15. FATF reached compatible conclusions in 2021, noting machine learning’s capacity to reduce false positives and surface complex cases, and natural language processing’s value in screening and fuzzy matching16.
Tracing below-the-radar transactions
Below-radar activity is defined by what it avoids, not by what it does. Detection therefore has to be relative rather than absolute:
- Peer-group baselining. Compare the customer to the customer’s own history and to a genuine peer cohort, not to a fixed rupee limit.
- Cross-channel aggregation. Cash, UPI, IMPS, NEFT, card and wallet flows are treated as a single exposure.
- Counterparty concentration. Small values, repeated to the same beneficiaries, over sustained periods.
- Structural change detection. The change in behaviour is the signal, not the level of activity.
- Unsupervised methods. Anomaly detection and clustering surface what nobody thought to write a rule for; supervised models learn from confirmed cases. Both require explainability, because an alert you cannot explain is an alert you cannot defend to a supervisor or a court.
From case report to STR
This is where most programmes underperform. A defensible case report should carry:
- the customer and KYC baseline, including declared occupation, income and expected activity;
- the declared versus observed profile, with the variance quantified;
- a chronological transaction table with dates, values, channels and counterparties;
- the network map showing linked entities and the evidential basis of each linkage;
- the typology alleged, stage by stage – what was structured, how it was layered, where integration was attempted;
- the evidence relied on, with fact separated from inference;
- alternative innocent explanations considered, and the reasons for rejecting them; and
- the conclusion, the recommendation and the decision trail.
The reporting obligation is time-bound. Rule 8 of the same Rules requires suspicious transactions to be reported promptly and not later than seven working days from being satisfied that a transaction is suspicious, while threshold, NPO and cross-border reports go by the fifteenth day of the succeeding month417. Seven working days runs from conviction that a STR is necessary, not from alert generation – which is exactly why alert ageing must be governed and evidenced.
Quality matters more than volume. Wolfsberg’s central complaint is that rising STR volumes are not producing proportionate law enforcement value14. Perhaps the same woe in India by authorities. One STR that narrates all three stages, evidences each and names the counterparties is worth more than fifty that report a threshold breach without a hypothesis.
The governance point
Every item above is an operational task. None of it survives without board-level insistence. Monitoring calibration, alert ageing, model validation, analyst headcount, their training and the quality of the STR narrative are governance outputs, not technology outputs. Technology finds the pattern. Only people decide whether to act on it, and only boards decide whether those people have the time and the mandate to do so.
Conclusion
The three layers as discussed are the original pillars of money laundering. Many however, do not consider them to be so in the modern era given the sophistication of money laundering especially due to the adoption of technology by criminals themselves and globalization of trade and businesses. However, trends in each of these stages are detectable with the right mix of rules and risk-based approaches, especially on risk-based methods aided by artificial intelligence and machine learning. Leveraging these technologies, provides a reasonable platform for detection and discovery of typologies, which in the final analysis leads to value based STRs. That value is what law enforcement awaits from reporting entities – it is about quality and quantity. The intelligence that is developed by each reporting entity (and eventually at a national level) is the pivot on which money laundering can be dented to a significant level. They provide the deterrents that every stakeholder wishes for.
References
- UNODC (no date) Money Laundering – Overview. Vienna: United Nations Office on Drugs and Crime. Available at: https://www.unodc.org/unodc/en/money-laundering/overview.html (accessed 27 July 2026).
- FATF (no date) Frequently Asked Questions – How much money is laundered per year? Paris: Financial Action Task Force. Available at: https://www.fatf-gafi.org/en/pages/frequently-asked-questions.html (accessed 27 July 2026).
- Basel Institute on Governance (2025) Basel AML Index 2025: 14th Public Edition. Basel: Basel Institute on Governance. Available at: https://baselgovernance.org/publications/basel-aml-index-2025 (accessed 27 July 2026).
- Government of India (2005) Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, Rules 3 and 8. New Delhi: Department of Revenue, Ministry of Finance. Available at: https://fiuindia.gov.in/files/AML_Legislation/notification.html (accessed 27 July 2026).
- Reserve Bank of India (2025) Reserve Bank of India (Commercial Banks – Know Your Customer) Directions, 2025, RBI/DOR/2025-26/169, DOR.AML.REC.No.88/14.01.002/2025-26, dated 28 November 2025 (updated as on 29 December 2025). Mumbai: RBI. Available at: https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13141 (accessed 27 July 2026).
- Reserve Bank of India (2025) Reserve Bank of India (Non-Banking Financial Company – Know Your Customer) Directions, 2025, RBI/DOR/2025-26/361, dated 28 November 2025 (updated as on 29 December 2025). Mumbai: RBI. Available at: https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12943 (accessed 27 July 2026).
- Ministry of Finance, Government of India (2026) UPI user base and transaction data, FY2025-26, written reply of the Minister of State for Finance in the Lok Sabha, 20 July 2026, citing NPCI. Reported by ANI, 20 July 2026. Available at: https://aninews.in/news/business/upi-user-base-reaches-5549-crore-fy26-transactions-rise-to-24162-crore-worth-rs-314-lakh-crore20260720191431/ (accessed 27 July 2026).
- Press Information Bureau (2026) RBI Strengthens Framework on Unauthorised Electronic Banking Transactions, Ministry of Finance, written reply in the Rajya Sabha, 24 March 2026, Release ID 2244478. New Delhi: PIB. Available at: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2244478 (accessed 27 July 2026).
- Press Information Bureau (2026) I4C and RBIH Sign MoU to Strengthen AI-Driven Detection of Mule Accounts and Cyber Financial Frauds, Ministry of Home Affairs, Release ID 2260277. New Delhi: PIB. Available at: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2260277 (accessed 27 July 2026).
- ANI (2026) Fraudsters increasingly using India-based mule accounts to move stolen money: Report, 26 July 2026, citing a Ministry of Home Affairs reply in the Lok Sabha (position as at 31 January 2026). Available at: https://aninews.in/news/business/fraudsters-increasingly-using-india-based-mule-accounts-to-move-stolen-money-report20260726171122/ (accessed 27 July 2026). Secondary source; primary parliamentary answer not independently verified.
- Securities and Exchange Board of India (2024) Master Circular on Guidelines on Anti-Money Laundering (AML) Standards and Combating the Financing of Terrorism (CFT) / Obligations of Securities Market Intermediaries under the Prevention of Money Laundering Act, 2002 and Rules framed thereunder, 6 June 2024. Mumbai: SEBI.
- FATF, APG and EAG (2024) Anti-money laundering and counter-terrorist financing measures – India: Mutual Evaluation Report, September 2024. Paris: Financial Action Task Force. Available at: https://www.fatf-gafi.org/en/publications/Mutualevaluations/India-MER-2024.html (accessed 27 July 2026).
- Reserve Bank of India (2024) Internal Risk Assessment Guidance for Money Laundering / Terrorist Financing Risks, 10 October 2024. Mumbai: RBI.
- Wolfsberg Group (2024) Statement on Effective Monitoring for Suspicious Activity, Part I: Moving Beyond Automated Transaction Monitoring, July 2024. Available at: https://wolfsberg-group.org/resources/202/168 (accessed 27 July 2026).
- Wolfsberg Group (2025) Statement on Effective Monitoring for Suspicious Activity, Part II: Transitioning to Innovation, August 2025. Available at: https://wolfsberg-group.org/resources/202/ (accessed 27 July 2026).
- FATF (2021) Opportunities and Challenges of New Technologies for AML/CFT, July 2021. Paris: Financial Action Task Force. Available at: https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/Opportunities-Challenges-of-New-Technologies-for-AML-CFT.pdf (accessed 27 July 2026).
- FIU-IND (no date) Frequently Asked Questions – time limits for furnishing information to the Director, FIU-IND. New Delhi: Financial Intelligence Unit – India. Available at: https://fiuindia.gov.in/files/FAQs/faqs.html (accessed 27 July 2026).
A note on sources: every figure above is tied to the source listed. Reference 10 rests on media reporting of a parliamentary answer rather than the answer itself, and is flagged accordingly. The UNODC 2-5 per cent range derives from a 1998 IMF consensus estimate and is an order-of-magnitude indicator, not a measurement.