How money laundering is detected in 2026: placement, layering and integration, plus examples, penalties, and AML controls that skip a central data store.
Table of contents
- Laundering is the process of disguising the origins of illegally obtained funds so they appear to come from a legitimate source, breaking the link between the cash and the underlying crime.
- It moves through three canonical stages, placement, layering and integration, a model used by the Financial Action Task Force (FATF) and the United Nations Office on Drugs and Crime (UNODC).
- UNODC's standing estimate is that 2 to 5 percent of global GDP, roughly 800 billion to 2 trillion US dollars, is laundered each year.
- On 10 October 2024, TD Bank pleaded guilty and agreed to pay over 1.8 billion US dollars to the Department of Justice after leaving about 92 percent of its transaction volume unmonitored, the largest US bank ever to plead guilty to Bank Secrecy Act failures.
- Detection runs on a stack of controls (identity checks, transaction monitoring, sanctions screening and reporting), and the open 2026 question is whether that stack has to pool every customer record into one central store.
Money laundering is the process of disguising the origins of illegally obtained money so it appears to come from a legitimate source. It typically moves through three stages, placement, layering and integration, turning proceeds from crimes like fraud, drug trafficking or corruption into seemingly clean, usable funds inside the financial system.
TL;DR
Laundering is how criminals make dirty money look clean: they break the link between funds and the crime that produced them, then move the proceeds back into the legitimate economy. The classic model has three stages, placement, layering and integration, and regulators including FATF and UNODC treat it as the standard. UNODC estimates 2 to 5 percent of global GDP is laundered each year. Anti-money laundering (AML) controls detect it through identity verification, transaction monitoring, sanctions screening and suspicious activity reporting. The 2024 TD Bank guilty plea shows the cost of weak detection. The harder 2026 question is architectural: you can run those controls without building one central store of customer data that becomes its own liability.
What is money laundering?
Laundering is the process of disguising the origins of illegally obtained money so it appears to come from a legitimate source. The phrase captures the goal exactly: take "dirty" proceeds from an underlying crime, the predicate offence, and put them through enough steps that they emerge looking "clean" and spendable. The point is not to hide the money but to break the evidentiary link between the funds and the crime, so the cash can be banked, invested or spent without raising questions.
The scale is large and, by its nature, hard to measure. UNODC's standing estimate is that 2 to 5 percent of global GDP, roughly 800 billion to 2 trillion US dollars, is laundered each year, a range UNODC itself flags as imprecise given how clandestine the activity is. It is a criminal offence in nearly every jurisdiction, and the controls built to stop it sit at the centre of modern financial regulation. The rest of this guide walks through how it works, what detection looks like in 2026, and the architecture question most explainers skip.
How does money laundering work? The three stages
Laundering is usually described as a three-stage process: placement, layering and integration. Placement is where illicit cash first enters the financial system. Layering moves those funds through a chain of transactions designed to obscure the trail. Integration is the payoff, where the now-disguised money re-enters the legitimate economy looking like ordinary wealth. The FFIEC BSA/AML Examination Manual, the reference US examiners use, describes layering as moving funds through complex transactions to complicate the paper trail and integration as the ultimate goal of creating the appearance of legality.
In practice the stages blur. A single scheme can run all three at once, skip a clean break between them, or recycle funds through several rounds. Digital and crypto rails compress the timeline: a chain of wallet hops can do in minutes what once took a network of shell accounts weeks. The three-stage model is a map, not a rulebook, and the criminals are not obliged to follow it in order. What stays constant is the objective, distance between the money and its source.
What happens at placement, layering and integration?
Placement is the riskiest and most detectable stage, because raw cash has to touch a regulated institution somewhere. Classic techniques include structuring, also called smurfing, where a launderer breaks a large sum into many sub-10,000-dollar deposits to stay under the US Currency Transaction Report threshold. Deliberately structuring transactions to evade that report is itself a federal crime under 31 U.S.C. 5324, so the evasion creates its own offence. Cash-intensive businesses and casino chips are other common placement routes.
Layering is the obscuring stage. Funds move through wire chains, shell companies, offshore accounts, crypto mixers and trade-based mispricing, each hop adding a layer of paperwork between the money and its origin. The aim is to make the trail expensive to follow. Integration is the re-entry: clean-looking funds are parked in real estate, securities, luxury goods, business investments or loans-back arrangements, so the launderer can finally enjoy the proceeds as apparently legitimate wealth. Each stage leaves different fingerprints, which is exactly why detection has to work stage by stage rather than at a single choke point.
Are there four stages of money laundering?
A common search asks whether there are four stages, and the honest answer is that the standard regulatory model has three. FATF and UNODC both use placement, layering and integration. Some training materials and frameworks add a fourth step, usually framed as the predicate or proceeds-generation stage that comes before placement, or a recycling and repatriation phase that follows integration. These are useful teaching variants, not an established standard.
If you are mapping a compliance programme, build it against the three-stage model, because that is what examiners and the FFIEC manual reference. Treat any "fourth stage" as a non-canonical add-on that can help you reason about where the dirty money originated or where it ultimately lands, rather than a separate regulatory category you are obliged to control for. The distinction matters mostly so readers are not confused when one source says three and another says four.
What are real-world examples of money laundering?
The clearest way to understand the typologies is through concrete examples, kept educational rather than instructional:
- Structuring and smurfing: an individual or network splits illicit cash into dozens of small deposits across multiple accounts to dodge the 10,000-dollar reporting threshold.
- Casino chip-washing: dirty cash buys chips, a token amount is gambled, and the rest is cashed out as apparently legitimate winnings, a pattern that recurs in iGaming.
- Trade-based laundering: shell companies over- or under-invoice goods so value moves across borders disguised as ordinary trade payments.
- Real-estate purchases: proceeds buy property, often through opaque ownership structures, integrating the funds into a high-value, stable asset.
- Crypto mixers and chain-hopping: funds are pooled and swapped across tokens and chains to break the on-chain trail during layering.
- Money-mule networks: recruited individuals move funds through their personal accounts, fragmenting the flow so no single transaction looks unusual.
The named case that anchors all of this is TD Bank. On 10 October 2024, TD Bank and its US holding company pleaded guilty and agreed to pay over 1.8 billion US dollars to resolve the Department of Justice's Bank Secrecy Act and laundering investigation, becoming the largest US bank ever to plead guilty to Bank Secrecy Act programme failures and the first to plead guilty to conspiracy to commit money laundering. Monitoring gaps left roughly 92 percent of transaction volume, about 18.3 trillion US dollars, unmonitored from January 2018 to April 2024, and three networks moved more than 670 million US dollars through TD accounts between 2019 and 2023. The widely cited figure of about 3.09 billion US dollars is the aggregate across the DOJ resolution, the Financial Crimes Enforcement Network (FinCEN), the Office of the Comptroller of the Currency and the Federal Reserve, not the DOJ component alone.
How is money laundering detected?
Detection runs on a stack of overlapping controls, each tuned to a different stage. At onboarding, Know Your Customer (KYC) and Know Your Business (KYB) checks verify who is opening the account, catching the false identities that placement relies on. Once accounts are live, transaction monitoring watches for the patterns of layering: rapid in-and-out movement, transfers structured just under reporting thresholds, sudden activity spikes and links to high-risk jurisdictions. Sanctions and politically exposed person screening filters out prohibited counterparties, and adverse-media screening surfaces reputational red flags. When something crosses the line, the institution files a Suspicious Activity Report.

The field is shifting from static rules toward behavioural analytics and machine-learning anomaly detection, and the regulatory frame is moving with it. FinCEN published a Notice of Proposed Rulemaking to reform AML programme requirements in the Federal Register on 10 April 2026, with the comment window closing on 9 June 2026, pushing away from process-driven, "check-the-box" compliance toward a risk-based, effectiveness-focused regime with mandatory risk assessments. The signal to compliance teams is that outcomes, not paperwork, will be measured. Worth noting up front: effective detection across the whole stack does not require pooling every customer's data into one central database, a point this guide returns to next. Our AML transaction monitoring guide covers the monitoring layer in depth.
Can you detect laundering without warehousing PII?
Here is the contrarian thesis worth weighing. Most AML platforms detect laundering by centralising customer personal data and transaction records into one system, and that system becomes a breach honeypot and a privacy liability. The incumbent pillars define the stages identically and quietly assume detection means warehousing everything in one place. The steelman for that approach is real: a single store is operationally simpler, examiners get one place to look, and plenty of well-run institutions pass their exams running exactly that model. So why argue with it?
Because the TD Bank case shows the failure mode was architectural, not definitional. TD did not misunderstand what laundering is; its monitoring and controls did not cover the volume flowing through it. Concentrating data does not, on its own, make detection better, and it adds a standing target. A privacy-first design verifies and screens without building that central store. Zyphe shards verified data across a decentralised network under a 29-of-100 threshold scheme, so no single node holds a complete record and there is no central honeypot, while authorised parties can still reconstruct a full record and export an audit-ready trail on demand. The customer keeps a reusable KYC passport they can re-present elsewhere. Detection of placement, layering and integration still happens; the difference is what you put at risk to do it. See how Zyphe works and the AML software page for the mechanics, and our analysis of why your KYC vendor is your biggest data breach risk.
What are the penalties for money laundering?
In the United States, criminal laundering under 18 U.S.C. 1956 carries a fine of not more than 500,000 US dollars or twice the value of the property involved, whichever is greater, and imprisonment of up to 20 years. The same statute provides a separate civil penalty of up to the greater of 10,000 US dollars or the value of the property. These are individual-conduct penalties; institutional failures are punished separately under the Bank Secrecy Act.
Bank Secrecy Act civil money penalties under 31 U.S.C. 5321 need careful phrasing. The headline figure of the greater of 1 million US dollars or twice the transaction amount is narrow: under section 5321(a)(7) it attaches only to violations of the correspondent-account and private-banking due-diligence duties in section 5318(i) and (j), and to special measures imposed under section 5318A. A general willful violation of the AML-programme requirement in section 5318(h), the bucket that covered the TD Bank failure, falls under section 5321(a)(1) and carries a far lower cap: the greater of 25,000 US dollars or the transaction amount, up to 100,000 US dollars. So the 1 million figure is a correspondent and private-banking number, not a general AML-programme number. Beyond fines, institutions face licence loss, consent orders, monitorships and lasting reputational damage. Internationally, the UK Proceeds of Crime Act 2002 and the EU's AML rules impose parallel duties for cross-border readers. Our AML compliance software guide maps the controls these regimes expect.
Why does money laundering matter for regulated businesses?
For fintechs, banks, neobanks, crypto and web3 firms, iGaming operators and marketplaces, laundering is not an abstract crime, it is direct regulatory exposure. FATF's 40 Recommendations are the recognised global AML and counter-financing-of-terrorism standard, and more than 200 jurisdictions have committed at the political level to implement them through FATF and its network of regional bodies. That means the duty to detect and report follows the activity, not the postcode, and the cost of weak detection now lands as guilty pleas and nine-figure settlements, as TD Bank learned.
The 2026 direction of travel makes detection quality the thing regulators grade. FinCEN's proposed effectiveness-based standard rewards programmes that actually catch illicit flows, not ones that merely document a process. For a regulated business, that raises a practical design question alongside the compliance one: how do you run high-quality detection without turning your own customer database into the next breach headline? Our KYC for fintech startups guide and KYB software page cover the onboarding controls that feed the answer.
The bottom line
Laundering is, at heart, a distance problem: criminals put steps between their money and the crime that produced it, and AML controls exist to close that distance back up. The definition and the three stages are table stakes, identical on every pillar page. The decision that actually shapes a 2026 compliance build is architectural. The TD Bank guilty plea was a monitoring and architecture failure, not a failure to understand what laundering is, and FinCEN's move toward effectiveness-based rules will keep grading detection quality over documentation. The teams that come out ahead will run placement, layering and integration detection at full strength without warehousing every customer record into a single store that becomes its own liability.
Related resources
- AML transaction monitoring guide
- AML compliance software in 2026
- Why your KYC vendor is your biggest data breach risk
- KYC for fintech startups: compliance from day one
- How Zyphe works
- Zyphe AML software
Cited sources
- UNODC, Money-Laundering Overview and the 2 to 5 percent of global GDP estimate
- 18 U.S.C. 1956, federal money laundering statute and penalties (Cornell LII)
- 31 U.S.C. 5321, Bank Secrecy Act civil money penalties (Cornell LII)
- FFIEC BSA/AML Examination Manual, stages and monitoring expectations
- FATF, The FATF Recommendations (global AML/CFT standard)
- Department of Justice, TD Bank pleads guilty to Bank Secrecy Act and money laundering conspiracy (October 2024)
- FinCEN, 2026 Notice of Proposed Rulemaking on effectiveness-based AML programmes (Federal Register)
- FinCEN, Currency Transaction Reporting requirement explainer
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.