A Different Discipline

Fraud happens in minutes. Most AML training doesn't.

Most AML content, including much of this site, is built around ongoing relationships assessed over weeks or months. Fraud is a different discipline wearing similar clothes. It usually happens in minutes, sometimes seconds, and the analyst rarely gets a full case file before a decision has to be made.

This guide works through four genuine fraud typologies as decision scenarios, the same four cases live in Scenario Lab's Fraud Detection module, so you can read the reasoning here and then actually practise the call.

How to use this guide

Read the setup. Make your call. Then read why, both for the right answer and every wrong one. The knowledge check at the end pulls the same patterns from new angles. Do not skip ahead.

🔓
Scenario 01 · Account takeover
The Lagos Checkout
Account Takeover
Account Activity
👤
Customer login
Usual device, IP and location match every prior session
4 min later
🔑
Password changed
Then £2,400 gift voucher checkout, Android device, Lagos proxy IP
same session
⚠️
Under review
Impossible travel + device fingerprint changed
⚖️
What do you do? — Make the call

A customer logs in from their usual device. IP and location match every prior session. Six minutes later, the account password is changed. Four minutes after that, a £2,400 checkout attempt for digital gift vouchers comes from an Android device on a residential proxy IP geolocating to Lagos, Nigeria, with a device fingerprint that no longer matches the account's history.

💸
Scenario 02 · Authorised push payment scam
The £45,000 Transfer
APP Scam
Account Activity
👤
Customer
Usual device, session and biometrics genuine throughout
£45,000
🏦
New account
Recipient business account, opened 41 hours ago
support call
⚠️
Under review
Panicked call, "crypto bond opportunity"
⚖️
What do you do? — Make the call

A customer's account shows a large outbound transfer request. The session, device, and biometrics all match the customer's usual pattern with no sign of compromise. A £45,000 transfer is requested to a domestic business account that was opened 41 hours ago. Around the same time, a support call has the customer sounding panicked, referencing an urgent "crypto bond opportunity" someone told them about.

🏪
Scenario 03 · Transaction laundering
The Candle Shop
Merchant Fraud
Merchant Processing Activity
🕯️
Candle shop
Baseline: £15–£40 transactions, daytime hours, for months
1,200% surge
📈
Volume surge
Overnight, Saturday. £500, £1,000, £2,500 — nothing resembling candles
same window
⚠️
Under review
Card authorisation failure rate hits 65%
⚖️
What do you do? — Make the call

A small merchant account, registered as a handmade candle retailer, has processed a steady, low volume of £15 to £40 transactions during normal daytime hours for months. Overnight on a Saturday, processing volume surges roughly 1,200% above baseline. Transaction values shift to round figures, £500, £1,000, £2,500, nothing resembling candle retail. International card authorisation failure rate for this merchant hits 65% during the same window.

Screening a merchant applicant? Run a free sanctions, PEP, and adverse media check before onboarding, no account required.
Screen an entity →
💷
Scenario 04 · Structuring
The Five Deposits
Structuring
Deposit Activity
💤
Dormant account
No meaningful activity for 14 months
5 locations
💷
Five deposits
£2,290–£2,480 each, five separate ATM locations
£11,930 total
⚠️
Under review
All five inside roughly 36 hours
⚖️
What do you do? — Make the call

A personal current account, dormant for 14 months, receives a £2,400 cash deposit at a branch ATM. Roughly five hours later, a second deposit of £2,350 lands at a different ATM in the same area. The next morning, two more deposits, £2,480 and £2,290, land within the same window at two further locations. That afternoon, a fifth deposit of £2,410 completes the pattern, five deposits totalling £11,930 across five locations inside roughly 36 hours.

Unlike the US, where a fixed $10,000 threshold triggers automatic currency transaction reporting, the UK has no equivalent fixed pound threshold, suspicion is based on the pattern of behaviour, not a specific figure.

Knowledge Check
Five questions. How well do you read the patterns?
1. What makes impossible travel a reliable fraud signal, specifically?
2. In the UK, what triggers a Suspicious Activity Report for structuring?
3. Why does a card testing failure rate above 65% matter alongside a merchant's volume surge?
4. Why is a digital gift voucher purchase a notable detail in an account takeover case?
5. What's the actual argument this guide makes about reading fraud signals?
0/5
Quick Reference

At a glance

Four patterns, the trap that makes each one look routine, the tell that actually gives it away, and the response that fits.

PatternThe trapThe tellResponse
Account takeover Each fact looks routine alone Password change, then impossible travel Kill session, step-up verify
APP scam Customer authorises it themselves Urgency, new recipient, scripted language Freeze, reimbursement regime applies
Merchant fraud Baseline account looks unremarkable Volume surge, round amounts, card testing Suspend, investigate both typologies
Structuring No UK threshold to watch for Fragmented deposits, multiple locations Escalate, pattern over amount
Read the Pattern, Not the Fact

Reading about it is the starting point.

Reading about these patterns is a starting point. Scenario Lab's Fraud Detection module puts you through the same decisions under the same time pressure and partial visibility a real case presents, working an account timeline one fact at a time and watching the risk signal shift as new information arrives.

Ready to work a live case? Free. No account needed. Step through account activity one fact at a time.
Open Scenario Lab →