FATF warns underground banking is becoming a professional digital laundering network
FATF says underground banking is becoming more professional and digital, increasingly intersecting with fintech, payment platforms and virtual assets.

What happened
On 3 September, the Financial Action Task Force published a new global typologies report on professional money laundering, underground banking, hawala and other similar service providers. FATF says criminal misuse of these systems is widespread: more than 80% of reporting jurisdictions identified underground banking or HOSSPs among the principal channels or techniques used by professional money launderers.
The report describes an increasingly commercial model. Professional laundering networks can operate as business-like, scalable cross-border services that move value for criminal clients, sometimes at lower commission rates than traditional laundering arrangements. FATF cites cases in which more than EUR 500 million was laundered through underground-banking and hawala-based schemes within only a few months.
The infrastructure is also becoming more digital. Nearly 70% of respondents identified the integration of new technologies, including encrypted messaging, bank transfers, mobile wallets, fintech applications, instant payments, virtual IBANs, prepaid cards and virtual assets. FATF says stablecoins can be used to settle balances between operators, while purpose-built hawala applications and AI-based tools have also been identified.
This does not mean hawala or similar value-transfer systems are inherently illicit. FATF notes that they can serve legitimate remittance and financial-inclusion needs. The risk arises when unregistered or underground operators and professional money launderers exploit these networks to conceal the movement and settlement of criminal proceeds.
FATF also highlights deeper integration with the formal financial system. Professional money launderers increasingly use bank accounts, payment service providers, fintech platforms and virtual-asset wallets as entry and exit points. Lawyers, accountants, auditors, notaries, corporate-formation agents, financial consultants, real-estate professionals and other intermediaries can also feature in these structures.
The FATF report draws on evidence from more than 50 jurisdictions across the FATF Global Network and partners.
Why it matters for KYB teams
The KYB implication is not that every business connected to fintech, crypto or cross-border payments should be treated as suspicious. It is that a registered legal entity can still perform an important role inside a professional laundering network even when its incorporation record appears ordinary.
Static verification answers whether the entity exists, who owns it and whether direct sanctions or watchlist matches are present. Higher-risk relationships also require a view of how the business is expected to operate: the payment products it uses, the jurisdictions it serves, its counterparties and intermediaries, expected transaction corridors and whether those elements form a coherent economic picture.
That context becomes more important as informal value-transfer networks intersect with regulated infrastructure. A customer may use a legitimate bank account, fintech platform, payment service provider or virtual-asset wallet as one entry or exit point in a wider settlement chain. KYB teams therefore need risk logic that can combine legal-entity data with business-model and relationship evidence rather than treating each source as an isolated check.
The report also strengthens the case for continuous monitoring. New payment rails, counterparties, jurisdictions, virtual-asset exposure or changes in expected activity can materially alter the risk of an existing relationship even when the company name and ownership structure have not changed.
Where an alert leads to escalation, teams should preserve the evidence behind the decision: what changed, which source or rule identified it, how the reviewer assessed the business context and why the relationship was retained, restricted or exited. A connected audit trail makes that reasoning reconstructable later.
What teams should review
- Does onboarding capture how higher-risk customers move value, including relevant payment providers, fintech platforms, virtual assets and settlement routes?
- Can the risk assessment distinguish a legitimate remittance or payment business from activity that is inconsistent with the declared business model?
- Are key counterparties, intermediaries and operating jurisdictions connected to the legal-entity record rather than stored in separate case notes?
- Can monitoring detect material changes in payment rails, virtual-asset exposure, transaction corridors or associated service providers?
- Do repeated links across customers, such as common intermediaries, counterparties, accounts or addresses, become visible to reviewers?
- Can the workflow escalate network or business-model risk even when the customer itself has no direct sanctions or watchlist match?
- Are reviewer rationale, supporting evidence, policy version and final disposition retained together when a relationship is re-risked?




