New models in financial crime

How fraud and money laundering became one financial-crime problem

Until relatively recently, bank risk managers viewed fraud and money laundering differently. Fraud was about preventing the theft of the bank’s or bank customer’s money: that could be from stolen cards, from checks, account takeover, or false applications. Anti-money laundering (AML), meanwhile, was about identifying whether money passing through the bank was related to some underlying crime and identification of suspicious customers and transactions.

Core Insights

  • Fraud and AML are becoming increasingly interconnected as digital payments, scam networks, money mules, crypto, and AI blur the boundaries between the two.
  • Authorized push-payment scams show how a single criminal episode can move quickly from fraud into money laundering.
  • Money mules are central to this connection, helping criminal proceeds move through accounts and become harder to trace.
  • Faster payments and fragmented transaction chains make retrospective AML monitoring less effective on its own.
  • Crypto assets, including stablecoins and unhosted wallets, add another layer to financial-crime monitoring, but traditional bank and payment accounts remain critical entry points.
  • Banks increasingly need to connect fraud, AML, cyber, identity, and transaction intelligence rather than treat them as separate sources of risk.
  • The underlying principle of “FRAML” matters more than the term itself: financial-crime detection and intervention increasingly need to operate across functions and in real time.

In this article

 

This article is also available in podcast/video form. Watch the video below from our YouTube channel, or follow The Intuition Finance Digest on Spotify, Apple Podcasts, or Amazon Music.

The emergence of “FRAML”

There is a clear and growing convergence between fraud and money laundering, driven by digital payments, social engineering, organized scam networks, money-mule infrastructure, cryptocurrencies, and increasingly, Artificial Intelligence (AI). Indeed, the emerging model is sometimes referred to in the industry as “FRAML” — the convergence of fraud and AML.

What used to be treated as two reasonably distinct financial-crime problems is becoming an interconnected continuum.

Let’s take the example of an authorized push-payment (APP) scam where a criminal impersonates an investment adviser and persuades a customer to transfer €20,000.

In this case, for the sending bank, the customer is a fraud victim. For the receiving bank, the recipient is a money mule engaged in money laundering.

That €20,000 might then be divided between several accounts, with the funds moved through an e-money provider, converted into a stablecoin and transferred abroad. In this manner, a single criminal episode has moved almost seamlessly from fraud into laundering often without leaving the online environment.

This is increasingly the pattern in financial crime: the fraud creates the proceeds; the money-mule and laundering infrastructure monetize the fraud; both are organized as part of the same criminal business model. Indeed, INTERPOL’s 2026 threat assessment observes increasing collaboration between fraud networks and specialized professional money-laundering groups.

Bank fraud and AML: different but intertwined

Nonetheless, fraud and AML should remain legally distinct (their regulatory obligations, investigative objectives, and victim-protection responsibilities remain different). But from an operational standpoint, institutions increasingly need to see them as components of a single financial-crime ecosystem.

The most important evolution in financial crime is how criminals have shifted focus from attacking banking technology towards attacking the person using the technology.

Despite strong customer authentication, total payment fraud is on the rise, largely due to manipulation of the payer.  A transaction can be perfectly authenticated and still fraudulent.

Get the latest finance news delivered directly to your inbox

Subscribe to our Financial Newsletter

newsletter image

Role of the money mule

The money mule is the bridge between fraud and money laundering. The mule provides an account into which criminal proceeds can be received and from which they can be transferred onwards. The mule is often knowingly criminal, who may be recruited through offers of easy money, deceived through fake employment, or controlled by criminals. Sometimes they themselves may be victims.

Sophisticated mule networks don’t just receive money – they layer it, as in the example above. The lesson for banks is that in financial crime, equal attention needs to be paid to the paying and receiving account.

Another major development is the speed at which funds now move. By the time suspicious activity is identified through retrospective AML monitoring, the money may already have passed through several accounts or left the institution altogether. Additionally, criminal fund flows are becoming more fragmented with only the criminal network having full visibility of the entire transaction chain.

Money flows between fiat and crypto

In this new age of financial crime, cryptocurrency naturally gets major attention. Indeed, it becomes especially valuable further down the chain, with criminals using stablecoins, multiple wallets, decentralized exchanges, unhosted wallets among other crypto infrastructure.

While cryptocurrency is a major new consideration, traditional bank and payment accounts remain crucial, particularly at the point at which victims initially send money. Bank AML teams need to understand how funds move between fiat currency and crypto assets. Blockchain activity cannot be treated as a specialized area separate from traditional payment monitoring.

An integrated financial-crime risk model

In this new world of financial crime, financial institutions need to move towards an integrated financial-crime risk model.

While specialist fraud, sanctions, AML, cyber and investigations teams may remain distinct, the data, intelligence, risk assessments, and investigative processes increasingly need to be brought together.

As far as “FRAML” goes, the term itself matters less than the underlying principle. Fraud intelligence should inform AML monitoring; AML network analysis should inform fraud detection; cyber and identity intelligence should feed both; receiving-account behavior needs as much attention as sending-account behavior; and interventions increasingly need to occur in real time.

Intuition Know-How has a number of tutorials relevant to the content of this article:

  • Crypto Assets – Financial Crime Risks
  • AI Applications – Fraud Detection & Prevention
  • AI Applications – Regulatory Compliance
  • Crypto Assets – Regulation
  • Digital Banking – An Introduction
  • Model Risk – An Introduction
  • Model Risk – Management
  • Operational Risk Management – Developments and Emerging risks
  • AI Applications – Corporate Credit Risk
intuition - text logo_ black
Intuition Know-How is the complete learning library for financial services

Frequently Asked Questions

What is FRAML in financial crime?

FRAML refers to the growing convergence of fraud and anti-money laundering. Activities that were once treated as separate financial-crime problems are increasingly connected through digital payments, social engineering, organized scam networks, money-mule infrastructure, cryptocurrencies, and AI. The term matters less than the underlying principle: fraud and AML intelligence increasingly need to inform each other.

How can an authorized push-payment scam connect fraud and money laundering?

An authorized push-payment scam can begin as fraud when a criminal persuades a victim to transfer money. For the sending bank, the customer is a fraud victim. For the receiving bank, the recipient account may be used to move criminal proceeds. Those funds can then be divided across accounts, transferred through an e-money provider, converted into a stablecoin, and sent abroad.

Why are money mules important in financial crime?

Money mules provide accounts into which criminal proceeds can be received and from which they can be transferred onward. Some are knowingly involved, while others may be recruited through easy-money offers, deceived through fake employment, controlled by criminals, or themselves be victims. Mule networks can also layer funds across accounts, linking the original fraud with subsequent money-laundering activity.

Why is retrospective AML monitoring becoming less effective?

Funds can now move through several accounts or leave an institution before suspicious activity is identified through retrospective AML monitoring. Criminal fund flows are also becoming more fragmented, meaning that individual institutions may see only part of the transaction chain. This makes speed an increasingly important factor in financial-crime detection and helps explain why interventions may need to occur in real time.

How do fiat currency and crypto assets interact in financial crime?

Traditional bank and payment accounts remain important because they may be where victims initially send money. Further along the chain, criminals can use stablecoins, multiple wallets, decentralized exchanges, unhosted wallets, and other crypto infrastructure. AML teams therefore need to understand how funds move between fiat currency and crypto assets rather than treating blockchain activity as separate from traditional payment monitoring.

Why are banks moving toward integrated financial-crime risk models?

Banks are increasingly bringing together data, intelligence, risk assessments, and investigative processes across fraud, AML, cyber, identity, sanctions, and investigations. Fraud intelligence can inform AML monitoring, while AML network analysis can support fraud detection. The article argues that receiving-account behavior deserves as much attention as sending-account behavior and that financial-crime interventions increasingly need to happen in real time.