What is AML typology recognition?
AML Typology recognition is the process of matching a customer’s behaviour to a known method of money laundering, such as mule account activity, structuring, or trade-based laundering, so an investigator understands what kind of crime an alert might represent and what to look for next. A typology library records how laundering was done before; it is not, by definition, a map of how it is being done now.
That gap between known patterns and current behaviour is the structural limitation of rules-based typology recognition, and it matters more at the investigation layer than most AML system designs acknowledge. Detection systems are designed to trigger on known patterns, and they do it better than they did five years ago. But triggering an alert and giving an investigator typology context are different things. Most AML platforms do the first. Very few do the second consistently, leaving an analyst with a flagged transaction and no framing for what kind of crime it might represent.
What’s the difference between typology recognition in detection and in investigation?
In detection, it’s pattern matching: does this transaction sequence resemble a known laundering method closely enough to cross the alert threshold? In investigation, it’s context: what does this alert most likely represent, how does that pattern typically develop, and what should the investigator check next? A rule can do the first in real time. Only a system that reads the alert alongside the customer’s full history can do the second.
Three Typologies That Look Different in Detection Than in Investigation
Mule account activation typically triggers in detection on inflow-outflow velocity: money arrives and leaves quickly, often to multiple beneficiaries, in a pattern inconsistent with the account’s stated purpose. In investigation, the same alert sits alongside a KYC profile that doesn’t explain the payment behaviour, an onboarding note mentioning a particular referral channel, and connections to other accounts showing correlated activation timing, none of which is visible in the transaction alert alone.
Structuring triggers in detection when transactions below a reporting threshold aggregate into a material value. In investigation, structuring as a customer’s primary evasion method looks different from structuring used to layer funds already in the system via a separate technique like trade-based laundering, and an investigator who knows which pattern they’re looking at writes a materially better SAR narrative.
Trade-based money laundering (TBML) is among the most consistently under-detected typologies, since FATF’s guidance on TBML identifies over- and under-invoicing, multiple invoicing, and falsely described goods as core methods, none of which present cleanly in transaction monitoring systems built around domestic payment behaviour. At the investigation layer, TBML typically surfaces through counterparty risk indicators, unusual payment terms, and cross-border patterns inconsistent with the customer’s declared trade activity, signals that require investigative analysis spanning the full relationship, not a single alert.
What Each Typology Looks Like in Detection vs. Investigation
| Typology | What detection sees | What investigation needs |
|---|---|---|
| Mule account activation | Velocity and beneficiary-count rules fire | Connected-account timing, prior SAR mentions, risk trajectory change |
| Structuring | Threshold-aggregation rule fires | Whether this is the primary method or layering for another typology |
| Trade-based laundering | Rarely fires cleanly at all | Counterparty risk, payment terms, cross-border pattern vs. declared trade |
Can AI keep up with evolving typologies faster than a static rule set?
Better than a quarterly-updated rule list can, though it still depends on continuously incorporating new case dispositions and typology intelligence. FATF’s typology reports document how methods evolve week to week: trade-based techniques adapt to controls, mule structures change as detection improves, and structuring thresholds shift. A rule set updated quarterly cannot track that. It is a property of static rules in a dynamic threat environment, not a failure of the people who write them.
Why Typology Context Needs to Reach the Investigator
The JMLSG Part I and Part II guidance frames typology awareness as an expectation within the investigation function, not just within detection: firms are expected to understand the typologies relevant to their customer population and apply that understanding in their investigation decisions. FATF’s typology guidance sits above any single jurisdiction, and US, EU and Middle East AML frameworks each build the same expectation into their own supervisory guidance: understand the typologies relevant to your customer base, not just the ones a rule set was originally built to catch.
In practice, most investigators lack fast access to typology context at the point of alert review. The knowledge may exist in training materials, in a typology library the financial crime intelligence team maintains, or in external sources like FATF reports, but it is not assembled and surfaced at the moment the analyst opens the case. That is a context friction problem: an investigator who would benefit from knowing “this pattern is consistent with the first phase of mule network activation, here is what to look for next” cannot access that framing in real time. They build it from experience, which means new investigators work without it and experienced investigators apply it inconsistently.
Does typology-aware AI decide whether an alert is genuinely suspicious?
No. It surfaces the typological framework, entity connections and prior case history relevant to the alert; the investigator still decides what the behaviour represents. The judgement doesn’t move. What changes is how quickly and accurately the investigator can apply it.
Detection AI has improved considerably, with documented gains in transaction-level pattern recognition at leading institutions, but that improvement hasn’t been matched by better investigation intelligence: the typological context, entity connections and behavioural framing investigators need to do something useful with the alerts they receive. A better detection engine producing alerts that investigators cannot contextualise quickly does not produce better outcomes. It produces more alerts entering an investigation process still operating without the typological intelligence to resolve them well, and the SAR that comes out the other end reflects the limits of the investigation, not the capability of the detection.
At TechnoXander, our AML Investigation Intelligence Platform surfaces typology context at the point of alert review, connecting the flagged behaviour to relevant pattern intelligence, entity relationships and prior case history before the analyst makes their first decision. Speak to our team to see what typology-aware AML investigation looks like in practice.
