Underground Banking Detection: AML Red Flags, Typologies and Strategies to Detect Hawala Networks

Table of Contents

Underground banking detection network connecting banks, PSPs, Hawala and financial crime signals

Underground banking detection begins with a practical reality: the activity you are looking for rarely announces itself. There is no “Hawala” label on a wire transfer, no flag on a structured cash deposit that identifies it as part of an informal value transfer network. The financial and behavioural footprint of underground banking is distributed across multiple accounts, entities, payment rails and jurisdictions – and it is designed to look ordinary.

Underground banking and informal value transfer systems have evolved far beyond cash-based Hawala into professionalised, digitally enabled networks that span banks, PSPs, fintechs, international trade, crypto platforms and money services businesses. FATF’s 2026 report on underground banking and Hawala confirms that more than 80% of surveyed jurisdictions now identify Hawala/HOSSPs among the principal channels used in professional money laundering. Some cases documented in that report involve over EUR 500 million laundered through underground banking networks in just months.

 

The 9/11 Commission reported terrorist funding via informal systems, and historical cases – including Osama Bin Laden’s documented use of hawala networks for fund transfers – cemented the link between these systems and terrorist financing. The central question for AML leaders today is not whether underground banking exists within their customer base, but whether their controls can detect it when it does.

This article provides a practical playbook for underground banking AML – aimed at MLROs, Heads of FCC and senior investigators – with concrete typologies, categorised red flags, a 7-step detection framework, and guidance on connecting detection to investigation and disruption.

What Is Underground Banking and Informal Value Transfer Systems? Clarifying Concepts Without Criminalising Hawala

Underground banking refers to informal value transfer systems – alternative remittance systems and non-bank transfer systems – that operate parallel to the formal financial sector while also sitting outside or within the formal financial system. Underground banking includes systems like hawala and hundi, as well as equivalents such as fei ch’ien. These systems operate outside formal banking channels and regulations, relying on trust networks, brokers and trade transactions rather than bank transfers. IVTS can facilitate rapid and anonymous money transfers, and hawala is a prominent example of an informal value transfer system used extensively across South Asia, the Middle East, North Africa and diaspora corridors globally.

Critically, many hawala transactions are legitimate remittances conducted where formal banking is expensive, slow or inaccessible. Legitimate informal value transfer can serve communities needing efficient remittance options, and treating every HOSSP transaction as suspicious would undermine financial inclusion without improving detection quality.

The distinction that matters for AML teams is between:

  • Legitimate remittance networks and cultural remittance practices where communities use informal channels for speed, cost or access reasons, and

  • Underground banking money laundering where professional money launderers and criminal organizations exploit IVTS and HOSSPs to move and disguise proceeds of crime, fund terrorist networks, or evade currency controls and sanctions.

Regulators treat many HOSSPs as money services businesses or MVTS. Unregistered money services businesses are vulnerable to terrorist financing, and unregistered providers are a core focus of financial crime and criminal justice responses. Underground banking is often exploited for money laundering activities, so anti-money laundering controls and supervision focus on how IVTS are misused for both money laundering and terrorist financing – but the system itself is not inherently criminal.

How Underground Banking Networks Operate?

Consider a cross-border settlement that never touches SWIFT: a worker in Dubai hands cash to a local broker. The broker messages a counterpart in Karachi, who pays the equivalent in local currency to the worker’s family. No conventional funds transfer crosses a border; the value is settled off-system. The brokers settle later – via netting, trade shipments, or reverse flows from other customers moving value in the opposite direction to transfer funds rather than using formal channels.

Modern underground banking networks, highlighted by recent FATF and FIU reports, combine multiple channels: cash collection in source countries; settlement through trade-based money laundering and invoice manipulation; use of bank accounts, PSPs, vIBANs and fintech wallets; virtual assets including OTC crypto brokers and P2P exchanges; and third-party and mule accounts across multiple jurisdictions. Approximately 70% of reporting jurisdictions now identify integration of new technologies – encrypted messaging apps, mobile wallets, stablecoins – in underground banking operations. These arrangements function as informal funds transfer systems that rely heavily on trust and verbal agreements without formal records, which makes simple origin-destination analysis insufficient.

The temporal and geographic decoupling is what makes detection so difficult. Value owed between underground bankers may be settled weeks later, in a different direction, and through an entirely different asset class than the customer’s original flow. A typical “mirror exchange” arrangement works like this: illicit cash from drug trafficking in one country is absorbed into a hawala network, while capital-flight demand in another country creates a matching obligation – both sides are satisfied without a single cross-border wire. Underground banking often blends with legitimate trade to disguise illicit financial flows through over- or under-invoicing.

Professional money launderers now run networked “underground banking as a service” operations, offered to fraud groups, cybercriminals and sanctions evaders, often embedded within ordinary-looking import-export, real-estate or foreign exchange dealing businesses.

Underground Banking and Money Laundering Typologies AML Teams Should Understand

Typologies are not crime stories – they are detection blueprints. Each typology below implies specific underground banking transaction monitoring scenarios that should be designed, tested and tuned.

  • Cash-intensive network: Cash collection points (travel agencies, convenience stores, phone shops) make structured cash deposits and immediate outgoing wires. Detection relies on identifying rapid cash-in/digital-out patterns, especially to diaspora corridors with known informal value transfer systems. Behavioural indicators can help identify underground banking activities such as unusual transaction patterns and cash deposits inconsistent with declared business.

  • Trade-based settlement: Underground bankers use over/under-invoicing, phantom shipments or mis-described goods to settle balances – for example, bulk used-car exports or electronics shipments with systematically manipulated values. Trade-based money laundering involves falsifying trade transactions to transfer value. Detection requires joining AML and trade-finance data to flag mismatches between payments, goods and counterparties.

  • Three-way/network settlement: Three or more brokers settle obligations in a circle (A–B, B–C, C–A), often across China, the Gulf and Europe. Detection relies on graph analytics to identify common counterparties and shared intermediaries across seemingly unrelated customers.

  • Money mule and third-party account networks: High-volume, low-value credits from many senders flow into mule accounts, followed by rapid aggregation and international transfers or crypto purchases. Cuckoo smurfing uses third-party accounts to disguise illicit funds – a technique where legitimate incoming remittances are co-opted so that illicit money substitutes for clean funds. Risk indicators include activity inconsistent with customer profile and frequent pass-through behaviour.

  • Virtual-asset-enabled settlement: OTC brokers, P2P platforms and small VASPs act as settlement rails between underground banking nodes, particularly involving China, Hong Kong SAR, UAE and Eastern Europe. Monitoring on/off-ramp behaviour, high-risk exchanges and privacy tools is critical for digital hawala detection.

  • Misuse of PSPs and vIBANs: Multiple payment institution accounts, virtual IBANs and e-money wallets in Europe, the UK and Singapore can mirror a hawala ledger. Detection strategies include profiling high-risk merchant categories and flagging unusual corridor-specific velocity patterns.

  • Front companies and professionalised HOSSPs: Some networks use licensed MSBs, remitters and FX houses as covers, complying superficially while providing underground banking on the side – an unregistered money services business hiding behind a registered one. Cross-checking reported business models against observed flows and peer benchmarks is essential.

  • Integration with formal financial institutions: Cases exist where insiders or complicit staff at banks, PSPs or FX brokers support underground banking by suppressing alerts or facilitating onboarding. Look for repeated linkage between specific employees, branches, and high-risk corridor flows.

Underground Banking Red Flags and Suspicious Transactions: From Customer to Network Level

No single underground banking red flag is determinative. Risk arises from patterns across multiple categories, assessed in context. A significant challenge for detecting underground banking is the lack of a formal paper trail, which means detection depends on connecting indirect signals rather than finding explicit documentation. Analysis of irregular financial flows is essential for detecting underground banking operations.

  • Customer-level indicators: Customers with modest declared income showing high-volume foreign exchange or cross-border money transfers for “friends” or “community,” inconsistent with their profile. Lack of plausible business rationale for frequent in-and-out flows. Reluctance to explain source of funds or the relationship to counterparties, with weak visibility into the parties involved in recurring transfers or remittance activity.

  • Transaction-level indicators: Frequent small-value transfers below reporting thresholds but cumulatively large, especially where originators and beneficiaries change constantly. Immediate onward transfers or cash withdrawals after receipt – “velocity laundering.” Circular flows where funds leave and re-enter the same accounts or a small cluster within days.

  • Entity/business-level indicators: Cash-intensive or FX-heavy businesses (import-export, used-car dealers, gold/jewellery, travel agencies, phone shops) with flows heavily skewed to high-risk corridors. Commingling of personal and business accounts, or obvious MSB-like behaviour in unregistered entities, which may indicate exposure to illegal activities when there is no clear business rationale. Inconsistent trade documentation, frequent invoice amendments and payments unrelated to stated business lines.

  • Network-level indicators: Multiple customers with no declared relationship sharing common counterparties, directors, phones, IPs or addresses. Clusters of accounts behaving like an informal clearing house, with high in/out ratios but low net balances. Repeated involvement of the same foreign MSBs, FX brokers or VASPs in unrelated customers’ payment chains.

  • Geographic indicators: Corridors known for informal value transfer (Gulf–South Asia, East Asia–North America, China–Latin America) where flows are inconsistent with normal migration, trade or investment patterns. Underground banking is prevalent in regions like Canada and Nepal, and transactions involving jurisdictions with currency controls, sanctions or weak AML regimes increase demand for underground banking channels.

  • Digital/virtual-asset indicators: Frequent transfers to/from small or unlicensed VASPs, P2P platforms or OTC brokers. Rapid conversion from fiat to privacy-enhancing coins or use of mixers and cross-chain bridges followed by re-entry into fiat corridors.

  • Trade-related indicators: Systematic over/under-invoicing, high-value goods shipped at implausible prices, or repeated shipments to the same counterparties with varying declared values. Large advance payments or open-account terms with no track record, where shipping or customs data is missing or clearly inconsistent.

How to Detect Underground Banking: A Practical 7-Step Framework

Conventional transaction monitoring – focused on single-account thresholds – will miss fragmented underground banking activity almost by design. Detection requires connecting signals across customers, entities, transactions, networks and external intelligence. Here is a practical, operational framework.

Step 1 – Know the customer. Robust CDD/EDD sets the baseline. Capture occupation, expected activity volume, links to higher-risk corridors, and – where relevant – explicit questions on remittance channels and money services use. A student account in Canada receiving frequent deposits from multiple unrelated senders, then transmitting funds internationally, should trigger deeper inquiry.

Step 2 – Know the entity. Map beneficial ownership, control and related parties – especially for FX dealers, import-export firms, freight forwarders, travel agencies and small MSBs. Use entity-resolution tools to unify multiple registrations, shell companies and nominee structures around the same principals.

Step 3 – Know the transaction. Profile normal behaviour by customer segment, then identify deviations: unexpected burst activity, anomalies in moving funds through accounts, corridor changes, or unexplained trade flows. Tune monitoring for structural patterns – fan-in/fan-out, pass-through behaviour, structured cash – rather than absolute amounts alone.

Step 4 – Know the network. Underground banking network detection requires graph analysis of accounts, devices, merchants, counterparties and intermediaries. Build internal “network views” where investigators see how a single suspicious account connects to others via shared owners, addresses, IPs or recurring counterparties. Research combining graph centrality with “blackhole” and hidden-link metrics has achieved approximately 94% recall in identifying hawala-linked accounts.

Step 5 – Know the external environment. Use FIU typology reports, FATF mutual evaluations, and sectoral advisories to adjust corridor and sector risk. Monitor changes in capital controls, sanctions and regulatory pressure that divert flows into informal value transfer systems.

Step 6 – Connect the signals. Combine customer-risk scores, entity intelligence, transaction-level alerts, adverse media and sanctions hits into composite risk indicators. Use case management that automatically groups alerts by network, not just by account, to form richer underground banking investigations.

Step 7 – Investigate and disrupt. Trace settlement mechanisms: trade, cash, and crypto. Map intermediaries. Assess links to known criminal organizations. File timely suspicious transaction reporting to FIUs with clear narratives referencing specific typologies and geographic risk, and in Canada align reporting for the Reports Analysis Centre context. Where risk is confirmed, apply enhanced due diligence, restrict or off-board relationships, and coordinate with law enforcement agencies.

Scenario: A PSP merchant in the Gulf receives many small digital wallet inflows from diaspora senders, immediately converts to stablecoins, then settles with a counterpart abroad via a virtual asset broker. No declared trade exists; the business model says “remittances and currency exchange.” Alerts arise from unusual corridor activity, rapid crypto conversions and common virtual IBANs. Steps 1–6 connect these signals to reveal a digital hawala operation moving illicit funds across borders.

The Role of Transaction Monitoring and Network Intelligence

Traditional rule-based transaction monitoring, focused on single accounts and value thresholds, often fails against fragmented underground banking activity. When suspicious transactions are split across dozens of accounts, entities and payment rails, no single alert captures the full picture.

Underground banking AML requires multi-channel transaction monitoring across cards, accounts, PSPs, trade and virtual assets; behavioural analytics that track velocity, directionality and lifecycle of funds; and customer and entity-risk layering where high-risk sectors or corridors dynamically adjust alert thresholds.

Network and graph analysis can surface underground banking clusters by mapping relationships between customers, entities, devices, IPs, merchants and counterparties. Specific analytic views – fan-in/fan-out graphs, hub-and-spoke merchants, broker-like nodes – can identify patterns resembling informal value transfer hubs. Integration with sanctions and PEP screening, adverse media, and internal fraud data is equally critical, since some underground banking networks also provide fraud cash-out services.

Fragmented AML and fraud systems create blind spots. When transaction monitoring, name screening, entity risk and adverse media operate in disconnected silos, underground banking detection suffers. An integrated risk intelligence architecture – bringing customer, transaction, entity and external intelligence into a single investigative environment – materially improves detection quality.

Underground banking transaction monitoring scenarios should be routinely tuned and back-tested using historical cases, typology updates from FIUs and findings from internal investigations.

Using FATF and FIU Intelligence to Sharpen Underground Banking AML Controls

FATF and national FIUs are primary sources of evidence-based underground banking typologies. FATF’s 2026 report on underground banking and Hawala highlights the professionalisation of HOSSPs and professional money launderers, documents increasing use of digital channels, PSPs and virtual assets in settlement, and shows stronger integration with legitimate trade and financial institutions.

Compliance teams should translate such findings into updated risk assessments for relevant products, sectors and corridors; new or refined monitoring rules and behavioural patterns; and training materials for frontline staff and investigators. The FATF addresses the requirement of licensing for underground banking service providers, and institutions should verify that their customers in the remittance and FX sectors hold valid registrations.

In Canada, unregistered money services businesses violate the PCMLTFA (Proceeds of Crime (Money Laundering and Terrorist Financing Act). National FIU advisories, such as FINTRAC’s sectoral advisory on underground banking in Metro Vancouver, GTA and Calgary–Edmonton, provide actionable intelligence on money mules, trade-based money laundering, co-mingling and structuring patterns that can be directly operationalised in monitoring scenarios. In 2003–04, AUSTRAC focused on the remittance sector for compliance, producing insights that remain relevant for risk-based supervision today.

Build an internal typology library where investigators document underground banking cases, map them back to FATF/FIU patterns, and use them to enhance future detection. Regulatory challenges arise because underground banking operates in jurisdictions with weak enforcement, and regulating it is complicated by its decentralized nature – making continuous intelligence gathering essential.

Investigating and Disrupting Underground Banking Networks

Once an institution suspects underground banking, the priority shifts from monitoring to mapping the network, identifying facilitators and assessing broader financial crime exposure.

Key investigative steps include: clustering customers, entities and bank accounts linked by shared identifiers, counterparties or transaction chains; identifying potential underground banking “hubs” – brokers, complicit MSBs, front companies – through degree and centrality analysis; and analysing settlement mechanisms including trade flows, cash withdrawal patterns and crypto on/off-ramp activity.

Leverage internal and external intelligence by cross-referencing internal alerts with law enforcement enquiries, subpoenas and previous SAR/STR filings. Review adverse media on key entities for links to professional money launderers, organized crime groups or other financial crime cases. Hawala networks facilitate money laundering by obscuring fund origins, so investigators must trace how value moves – not just where money moves.

Strong suspicious activity reports should clearly narrate the suspected underground banking arrangement, including value flows, counterparties and typology characteristics. Explicitly reference relevant indicators – TBML, money mules, informal value transfer systems – and geographic risk factors. A FinCEN case study documented a U.S. defendant running a hawala network using wire transfers into U.S. accounts, then disbursing local currency overseas via hawala to bypass OFAC sanctions – illustrating how illicit money flows through seemingly routine wires.

Disruption options range from enhanced due diligence and temporary restrictions to controlled exit of high-risk relationships and proactive engagement with FIUs for joint investigations. Post-case feedback loops – updating risk models, customer-risk scoring and training – ensure that underground banking detection improves over time.

How Technology and Connected Intelligence Strengthen Underground Banking Detection

Technology is an intelligence multiplier for experienced AML teams, not a replacement for investigator judgement. Using digital tools and blockchain analytics is crucial for authorities to trace underground banking transactions, but those tools must be embedded in workflows that investigators actually use.

Key capabilities for effective underground banking network detection include:

  • Advanced analytics and machine learning for behavioural and anomaly detection across products and channels

  • Robust entity resolution to unify fragmented records and expose front or shell companies

  • Network and graph analysis engines to discover hidden relationships between accounts, entities, devices and transactions

  • Continuous, cross-channel monitoring of payments, trade, FX, cards and crypto in a unified view

External data plays an equally important role: sanctions, PEP and watchlist screening integrated into name screening workflows; entity and ownership intelligence to understand real-world control and group structures; and adverse media monitoring to surface links to professional money laundering or criminal organizations.

ZIGRAM’s connected AML/FRAML ecosystem, including Transact Comply for transaction and payment-risk monitoring, Entity Hero for entity risk assessment, PreScreening.io for name screening & adverse media intelligence, and Fraud Fighter for fraud monitoring, can help institutions bring these capabilities together in a single investigative environment, connecting everything to fulfill specific obligations across underground banking detection workflows.

Prioritise explainable analytics, investigator-friendly workflows and clear governance over purely black-box models.

Designing an Underground Banking Risk Assessment for Your Institution

An explicit underground banking and informal value transfer system AML risk assessment is necessary beyond generic money laundering risk assessments. Underground banking systems are difficult to regulate globally, and institutions must proactively assess their own exposure rather than relying solely on regulatory prompts.

Key components include:

  • Product and channel risk: Evaluate remittances, FX services, PSP and vIBAN offerings, trade finance and virtual-asset exposure.

  • Customer and sector risk: Assess exposure to high-risk sectors (FX dealers, import-export, used cars, gold, the gambling industry) and diaspora communities with strong informal value transfer traditions, balancing financial inclusion with risk management.

  • Jurisdictional and corridor analysis: Map corridors where capital controls, sanctions or large informal economies create demand for underground banking. Align corridor risk ratings with FATF evaluations, FIU advisories and central bank reports. Underground banking systems operate outside formal regulatory oversight, requiring proactive controls.

  • Control effectiveness testing: Periodically sample alerts and closed cases to evaluate whether underground banking typologies would be caught. Run thematic reviews – for example, review all high-risk import-export customers or entities exhibiting unregistered MSB-like behaviour.

  • Governance: Ensure underground banking risk is explicitly covered in AML policies, procedures and training. Present typology updates and case studies to board-level risk or compliance committees annually. Institutions that lack internal data-science or network-intelligence capabilities should consider collaboration with RegTech providers where appropriate, while maintaining independent oversight.

Terrorist financing and money laundering exploit underground banking, and controls must address both dimensions. Organised crime, drug trafficking and tax evasion all exploit underground banking channels, and institutions handling foreign currency, redeeming money orders, or transmitting money across high-risk corridors should calibrate their risk assessments accordingly.

Conclusion: From Isolated Alerts to Network-Level Underground Banking Intelligence

Underground banking detection requires shifting from single-transaction alerts to joined-up customer, entity, transaction and network intelligence. When underground banking activity is fragmented across dozens of accounts and multiple rails, no isolated alert will capture the full picture. The institutions that detect and disrupt these networks are the ones that connect signals across every layer, from CDD to graph analytics to external intelligence.

Informal value transfer systems like Hawala and HOSSPs are not inherently criminal. But their exploitation by professional money launderers, organized crime and those seeking to fund terrorist networks demands sophisticated AML responses that go far beyond threshold-based rules. IVTS operate in corridors where the formal banking system may be inaccessible, and AML controls must distinguish legitimate purposes from illicit financial flows without pushing vulnerable communities further underground.

The operational takeaways are clear: use structured typologies and risk indicators rather than generic lists. Adopt the 7-step detection framework to connect customer, entity, transaction, network and external signals. Invest in integrated monitoring, network analytics and robust investigations to move from identification to effective disruption. As underground banking networks continue to professionalise and digitise, the institutions that combine strong human expertise with advanced RegTech and high-quality data will be best positioned to combat money laundering and protect the global financial system.

Enhance Your AML Compliance Efforts

Empower your organization with ZIGRAM's integrated RegTech solutions

Financial Crime Prevention Image

Articles

Explore insightful articles on cutting-edge topics like regulations, technological advancements, and critical insights into AML and financial crime risks
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Underground-Banking-Detection-scaled.webp

Underground Banking Detection: AML Red Flags, Typologies...

15 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Article-Banner-39-scaled.png

Fraud Detection in Banking: A Cross-Channel Approach...

12 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Article-Banner-37-scaled.png

Account Takeover Fraud: Detection, Red Flags and...

15 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Money-Laundering-In-Film-Industry-scaled.webp

Money Laundering in Film Industry: Risks, Cases...

13 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Article-Banner-33-scaled.png

Adverse Media Screening: How It Strengthens AML...

10 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Fraud-Monitoring-Regulatory-Requirements-2-scaled.webp

Fraud Monitoring Regulatory Requirements: What Financial Institutions...

15 Min