AML Typology Detection: Recognise Money Laundering Patterns in Your Data
Threshold-only monitoring misses patterned laundering. Structuring, layering, and trade-based money laundering stay invisible when every rule only asks "did this amount breach a limit?" FIC typology reports and FATF guidance expect you to detect those patterns before examiners ask why you missed them.
We implement typology-aware detection scenarios in your monitoring stack.

Sound Familiar?
These are the exact gaps MLROs face when monitoring stops at thresholds:
- Threshold rules fire on single amounts, while structuring stays just under the FIC R49,999.99 cash threshold
- Layering across accounts, branches, and payment rails never surfaces as a single coherent pattern
- Trade finance desks lack automated detectors for over-invoicing, under-invoicing, and phantom shipments
- Analysts spend most of their week clearing noisy threshold alerts instead of investigating known typologies
- Examiners and the FIC ask which typology library you run, and the answer is still "amount rules only"
South Africa exited the FATF grey list in October 2025, and the next mutual evaluation is expected in 2026–2027. Supervisors and the FIC will test whether institutions detect known typologies, not only whether cash thresholds fire. Static amount rules will not carry that conversation.
What Typology Detection Actually Does
Known money laundering patterns become automated detectors over your transaction data, with alerts your investigators can action.
Transactions Stream In
Payments, cash, wires, and trade events land in your monitoring or data layer as usual
Typology Scenarios Fire
Structuring, layering, TBML, and mule patterns evaluate across accounts, time, and counterparties
Case Pack Assembled
Matched events, indicators, and customer context land in the investigation queue with a typology label
STR Ready for goAML
Investigators file with pattern evidence examiners and the FIC recognise, not a lone threshold hit
Everything You Need to Detect Known AML Typologies
Structuring & Smurfing Scenarios
Detect sub-threshold cash and payment sequences designed to avoid CTR reporting, including multi-branch and multi-party smurfing patterns.
Layering Pattern Detection
Flag rapid movement through multiple accounts, round-tripping, and complex pass-through chains that threshold rules never see as one story.
Trade-Based Laundering Detectors
Encode FATF and FIC TBML red flags: price/quantity mismatches, shipments inconsistent with the client profile, and circular trade flows.
Mule Network Recognition
Surface funnel accounts, shared device or address clusters, and many-to-one aggregation patterns typical of mule networks.
FIC Typology Library Sync
Map your scenarios to published FIC typology indicators and case studies so your library stays current as guidance evolves.
Case Queue & goAML Handoff
Typology-matched alerts land in structured investigation queues with evidence packs ready for STR drafting and goAML filing.
Monitoring Stacks We've Extended with Typology Scenarios
From Threshold Noise to Typology-Matched STRs
How a mid-tier South African payment processor cut false positives 58% and raised typology-matched STRs 3.2× after encoding FIC structuring, layering, and TBML detectors.
Threshold-Only Monitoring
- Rules fired on single amounts near cash and velocity limits
- Structuring just under R50,000 across branches never assembled into one alert
- Trade desk relied on manual invoice review for TBML red flags
- Analysts cleared hundreds of weekly alerts with almost no typology label
- Internal audit flagged "no documented typology coverage" ahead of FIC inspection
Typology-Aware Detection
- Structuring, layering, mule, and TBML scenarios ran over the full transaction book
- Multi-event pattern packs landed in the case queue with FIC indicator references
- Trade finance TBML detectors flagged price and shipment inconsistencies automatically
- Analysts investigated coherent patterns instead of isolated amount spikes
- Inspection pack showed a living typology library mapped to FIC publications
Before vs After Typology Detection
How It Works
From first conversation to live typology scenarios in 4–8 weeks.
Map Your Typology Gaps
Which FIC and FATF typologies you must cover, what your stack already detects, and where threshold-only rules leave blind spots.
Free Scoping Call
30-minute call with your MLRO or financial crime lead to prioritise structuring, layering, TBML, and mule scenarios.
Build & Back-Test
We encode the typology scenarios, back-test against historical books, and tune so true positives rise without drowning analysts.
Go Live & Refresh
Scenarios go live in your monitoring stack. We leave you a refresh cadence so the library tracks new FIC typology guidance.
Frequently Asked Questions
How is typology detection different from threshold monitoring or a rule engine?
Threshold monitoring asks whether a single amount crossed a line. A generic rule engine lets you write any condition. Typology detection encodes known money laundering patterns (structuring, layering, trade-based laundering, mule networks) as multi-event scenarios over your transaction data, so patterned crime surfaces even when no individual payment breaches a threshold.
Which AML typologies do you typically implement first?
Most South African banks, payment processors, and trade finance desks start with structuring and smurfing against the FIC cash threshold, then layering across accounts and rails, then TBML red flags for trade desks, and mule or funnel-account networks. We prioritise from your RMCP risk assessment and recent FIC typology publications.
Will this replace our existing transaction monitoring system?
No. We implement typology-aware detection scenarios inside or alongside your current monitoring stack (vendor TMS or custom). Your analysts keep their case tools; the change is that patterned laundering finally appears as coherent alerts instead of fragmented noise.
How often should we refresh our typology library?
FIC publishes typology and indicator updates drawn from case studies, and FATF refreshes methods and trends guidance periodically. After South Africa exited the FATF grey list in October 2025, supervisors expect institutions to keep detection current ahead of the next mutual evaluation (expected 2026–2027). We typically set a quarterly review cadence with ad-hoc updates when material new guidance lands.
How do you reduce false positives while adding typology scenarios?
Traditional threshold-led systems generate 85–95% false positives. Typology scenarios use multi-event logic, customer-segment context, and back-testing so alerts match a known pattern, not a single amount spike. Clients usually see a sharp drop in noise alongside a rise in typology-matched STRs worth filing.
How much does AML typology detection implementation cost?
Scoped typology libraries typically range from R45,000 to R120,000 depending on how many scenarios you need, data sources, and whether we integrate with a vendor TMS or a custom stack. Most clients recover the investment within a few months through lower alert noise and stronger examiner-ready coverage.
Stop Relying on Thresholds Alone
If your monitoring still only asks whether an amount crossed a line, patterned money laundering is already walking past your controls.
Tell us which typologies your RMCP prioritises, what your monitoring stack looks like today, and where examiners have already pressed you. We'll show you how structuring, layering, and trade-based laundering detectors would run on your data.