AML and fraud case scenarios are hard because the same transaction stream can carry several labels at once, and each label points to a different control, escalation path, and report narrative. This guide trains one skill in a deliberate order: classify first, then decide. You will separate money laundering from fraud and terrorist financing, map transaction patterns to laundering stages, anchor every judgment to a customer baseline, and practice writing the short rationales that case files demand. Work through both scenarios and the rubric below, then use the free practice bank to drill the same decision under time pressure.
Separating Money Laundering from Fraud and Terrorist Financing in Case Scenarios
Money laundering disguises criminal proceeds; fraud obtains assets through deception; terrorist financing moves funds toward violence regardless of their origin. Which label you assign determines which indicators, controls, and narrative language apply to the case.
The three crime types answer different questions. Money laundering is about the source of funds: proceeds are already criminal, and the goal is to make them appear legitimate. Fraud is about how assets were acquired: deception produced the transfer, so the origin may be an otherwise clean account. Terrorist financing is about purpose: funds can be entirely lawful in origin, which is why a laundering-stage analysis finds nothing, because there is no dirty money to place, layer, or integrate.
Hybrid cases appear throughout AML and fraud work, which is why single-label memorization breaks down. A business email compromise pays stolen money into a mule account that then wires it onward: the theft is fraud, the onward movement by the mule resembles laundering, and classification applies per account role. Train a three-question order for every stem: how did the funds originate, what is their intended use, and who controls each account in the chain. Then confirm your label against the comparison below before choosing any control.
| Dimension | Money laundering | Fraud | Terrorist financing |
|---|---|---|---|
| Core question | Is the source of funds criminal? | Was the transfer obtained by deception? | Is the purpose of funds violent activity? |
| Early indicator type | Cash intensity, layered movement, opaque ownership | Changed credentials, urgency, new payees, pressure tactics | Structuring with clean funds, front entities or charities |
| Matching control | Source inquiry, pattern review, diligence escalation | Credential review, payee verification, victim contact | Purpose-of-funds inquiry, network review |
| Narrative focus | How proceeds moved and were disguised | Who deceived whom and how access was gained | Intended use and the supporting network |
Matching Transaction Patterns to Placement, Layering, and Integration
Placement, layering, and integration describe where funds sit in a laundering cycle, and each stage produces different observable patterns. Attaching a stage label to the wrong pattern weakens both your analysis and any written rationale you produce from it.
Placement means criminal cash first enters the financial system: repeated cash deposits by multiple individuals, inflated receipts at a cash-intensive business, or deposits spread across branches and days. Layering is movement designed to obscure the trail: rapid transfers between related entities, round-amount wires across borders, or trade-based schemes using over- and under-invoiced shipments. Integration is re-entry as apparently legitimate wealth: a loan repaid by a shell company, an asset bought and resold, or invested funds returned as business income.
The confusion worth drilling is that fast movement is not automatically layering. Movement patterns describe a laundering cycle only when the origin is criminal proceeds; stolen funds leaving a compromised account quickly are simply theft proceeds exiting, and there may be no laundering cycle at all. When you practice, label each stage only after confirming the origin question from Section 1. A reliable drill: take five short transaction lists, write the stage you see, then force yourself to write one sentence explaining what makes it that stage rather than the adjacent one.
Deciding When Unusual Becomes Suspicious: Building a Customer Baseline
Unusual means inconsistent with the customer's expected profile; suspicious means you can articulate why that inconsistency, in context, suggests possible criminal activity. The baseline built during due diligence is the measuring stick for both judgments.
A usable baseline records the customer's stated occupation and income source, the products and channels they were opened for, and the expected volume, frequency, and geography of activity. A florist who deposits substantial cash is plausible; a florist who suddenly wires weekly to unfamiliar high-risk counterparties is not, but only because the baseline says so. Without the expectation on record, unusual and suspicious collapse into the same vague impression, and your justification rests on gut feel rather than stated facts.
This distinction is trainable through a four-part writing habit: state the expectation, state the deviation, state the context that makes the deviation meaningful, and state the next decision with its owner. If you cannot fill in the expectation line, you have not finished the analysis, whatever conclusion you reached. In scenario practice, apply the same structure to every option before selecting one, because a conclusion drawn without the baseline step rests on impression rather than stated facts.
Choosing the Right Level of Diligence: KYC, CDD, and EDD Triggers
KYC verifies identity at onboarding; customer due diligence builds ongoing understanding of activity and risk; enhanced due diligence applies deeper scrutiny when risk factors demand it. Practice choosing the proportionate level for each fact pattern rather than defaulting to the deepest one.
The risk-based approach means diligence scales with assessed risk rather than being uniform. Enhanced review is typically reserved for relationships carrying higher risk, such as politically exposed persons, complex or opaque ownership structures, and geographies elevated by your institution's own risk assessment. Applying enhanced measures everywhere looks thorough but fails a proportionality test, and applying only basic measures to a clearly elevated relationship fails a sufficiency test. Practice recognizing which side of that line a case sits on and stating why in one sentence.
Keep the outputs of each level distinct in your head, because the outputs are easy to mix up when you are deciding quickly. Identity verification produces verified identity documents and a customer record; standard due diligence produces a risk rating and an expected activity profile; enhanced diligence produces additional source-of-funds and source-of-wealth evidence plus senior approval where your framework requires it. Use the table to check yourself, then drill trigger-recognition: given a short customer fact pattern, name the level you would apply and the single risk factor that justifies it.
| Level | Core question | Typical triggers | Typical outputs |
|---|---|---|---|
| KYC | Who is this customer, verified? | New account or relationship | Verified identity and customer record |
| CDD | What activity is this customer expected to have? | Ongoing relationship monitoring | Risk rating and expected activity profile |
| EDD | Does elevated risk require deeper evidence? | PEP status, complex ownership, higher-risk geographies, unexplained profile changes | Source-of-funds and source-of-wealth evidence, senior review, tighter monitoring |
Worked Scenario One: Sub-Threshold Cash Deposits That Look Innocent Alone
When deposits are individually small but patterned to stay under a reporting threshold, the decision rests on aggregation and pattern analysis rather than any single transaction. The predictable error is closing the alert because no one deposit appears to qualify.
The case: a retail customer whose baseline shows a salaried income deposits between roughly eight and nine and a half thousand in cash on six consecutive days, spread across four different branches, with no business rationale on file to explain cash volume. The weaker decision reviews each deposit in isolation, notes that none crosses the reporting threshold, and marks the alert as no reportable activity. The stronger decision aggregates across days and branches, compares the total to the documented baseline, inquires about the source of the cash, records the answers, and escalates per policy if the explanation does not resolve the pattern.
Why it matters: structuring is defined by the pattern and by apparent intent to evade a reporting or recordkeeping duty, so threshold rules exist to create records in the first place, and evading them is itself the signal. A caution on numbers: specific thresholds, aggregation windows, and filing deadlines are jurisdiction-specific and change over time, so learn the aggregation principle and the pattern-recognition reasoning, and confirm current figures through the regulator and issuer rather than memorized amounts. Administrative details for this credential live with the issuer at aba.com.
Worked Scenario Two: A Rapid Withdrawal Case That Is Fraud, Not Laundering
An account emptied within hours of a credential change is most plausibly account takeover fraud rather than laundering. Treating it as laundering sends the case down a stages-and-typologies path that delays the victim-focused actions the situation calls for.
The case: a long-standing customer's email and phone contact details were changed two days ago, a new device then logs in, a new payee is added, and the balance is moved out the same day. The weaker response writes a laundering narrative using layering language, which misframes the case because the funds originated from the customer's own legitimate balance and no laundering cycle exists. The stronger response classifies attempted or completed unauthorized transactions, preserves login and device evidence, initiates contact attempts through previously verified channels, reviews and holds the new payee where the framework allows, and files an internal fraud record stating who, what, when, and how access was gained.
Why the classification matters: it determines the downstream playbook. A fraud case triggers victim contact, credential resets, and possible recall of transfers; a laundering case triggers source inquiries and pattern review of the wrong party. Real cases do combine the crimes, since mule accounts receiving fraud proceeds connect both, but the classification applies per account role: the victim's account is a fraud case, the receiving mule account may be a laundering case. Practice stating that split explicitly whenever a single fact pattern touches multiple accounts.
A Practice Routine and Self-Check Rubric for Scenario Readiness
Build readiness with a four-step cycle: concept mapping, timed scenario drills, written rationales, and an error log reviewed weekly. Score every practice case against the rubric below, and treat the scores as learning milestones rather than predictions of any exam outcome.
An adaptable sequence over roughly two weeks: days one to three, draw concept maps covering the three crime types, the three laundering stages, and the three diligence levels, connecting each concept to one indicator and one control. Days four to ten, drill scenarios from the practice bank, untimed first and then timed, recording your classification and decision for each. Days eleven to fourteen, write five-sentence rationales for the same cases using the expectation-deviation-context-decision structure, then redo every case you scored below standard before moving on.
The core exercise: pick five transaction lists of increasing complexity. For each, record the stage or crime type, two indicators tied to a stated baseline, your decision with an escalation path, and one material fact the scenario does not tell you. This mirrors real analytical work, where the deliverable is a defensible rationale, not just a label. Your error log should have one line per miss: what you classified, what the classification should have been, and which question you failed to ask first, then review the log before every subsequent session.
- Classification correct and reasoned: 2 points
- Two indicators, each tied to a stated baseline expectation: 2 points
- Decision stated with a specific escalation path and owner: 2 points
- One material missing fact identified: 1 point
- Milestone: 7 out of 7 across five consecutive cases before timed drills
- Final readiness checks: classify a ten-case mixed set within your target time; write one rationale from memory; name the EDD trigger you would cite for three different fact patterns
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
