Money transfers: analyzing sender, receiver, and their relationship
In money transfer operations, the sender, receiver, amount, frequency, country, transaction history, and the relationship between the parties must be evaluated together. Organizations providing money transfer services generally operate under a payment institution license and are subject to MASAK's guideline for payment and electronic money institutions.
Money transfer is the movement of funds from one person to another, and its laundering risk lies not in the amount, but in the relationship between the parties. Patterns that cannot be seen by looking at a single transfer emerge when the sender and receiver context, time window, and repetition are analyzed together.
Which indicators does the guideline list?
MASAK's payment guideline presents this as several distinct indicators. The guideline lists transfers from or to risky countries or offshore centers that reach significant amounts within a certain time frame without a reasonable explanation; funds transferred to a customer's name or account from many people in low and similar amounts within a short period, which are then sent to many other people; and the transfer of balances accumulated in the accounts of multiple customers to a shared bank account.
| Indicator | Required for detection |
|---|---|
| Risky country concentration | Country information and time window |
| Many-to-one, one-to-many transfer | Number of parties and proximity of amounts |
| Aggregation in a shared account | Extracting the network around the receiver |
| Structuring | Analyzing sub-threshold amounts together |
| Loading via shared IP | IP data collected at onboarding |
| Cash channel | Information on which channel the transaction passes through |
None of these can be seen by looking at a single transfer: they require analyzing the context, time window, and repetition together. Aggregation windows make this calculation possible; details are on the rule engine page.
Why are structuring and attempts mentioned together?
The guideline lists splitting money into multiple accounts, wire transfers, or cash to evade reporting procedures, and it also covers attempts. Rejected and incomplete transfers must also be stored.
TruvaLI ingests events using upsert logic: updating the same event does not generate a new record; it updates the existing record and re-evaluates it. Transactions that remain at the attempt stage are preserved in the records.
Are the sender and receiver screened separately?
Yes. The sender and receiver are recorded as separate parties, and both are screened against sanctions, PEP, and internal lists. The relationship network between the parties is extracted using shared IPs, devices, phone numbers, emails, and counterparties.
Structured transfers coming from different senders to the same receiver cannot be seen by looking at a single sender account; it requires extracting the network around the target. Details are on the fraud detection and sanctions compliance pages.
Why is the cash side separate?
Transferring funds deposited from ATMs in different provinces into a single account, and withdrawing loads made to an inactive account from ATMs at the maximum amount, are distinct types in the guideline. Neither can be analyzed without channel information.
Data collected at onboarding cannot be generated later
Email and IP scores collected during onboarding are inputs for subsequent rules. The guideline considers loading funds into accounts belonging to different unrelated individuals from the same IPs as a distinct indicator; if this data is not collected at onboarding, it cannot be generated later. Details are on the customer onboarding page.
The decision remains with the human
The decision is linked to the case with its justification and evidence; information on who decided, with what authority, and when is written to an immutable audit trail. The suspicious transaction report draft is prepared from the same case data, and the signature remains with the institution. Details are on the alert and case management and regulatory reporting pages.
The licensing framework is on the payment institutions page.
Source
MASAK sectoral suspicious transaction reporting guidelines and the Law No. 5549 on Prevention of Laundering Proceeds of Crime.
This page does not constitute legal interpretation. Rules, thresholds, and actions are configured according to the obliged party's own risk policy and obligations.
Common questions
- How is the risk of a transfer determined?
- Not by its amount, but by the relationship between the parties. The sender, receiver, frequency, country, transaction history, and time window are analyzed together.
- Which guideline applies to us?
- Organizations providing money transfer services generally operate under a payment institution license and are subject to MASAK's guideline for payment and electronic money institutions.
- Are incomplete transfers stored?
- Yes. The guideline also covers attempts in structuring; rejected and incomplete transfers remain in the records. Since events are ingested using upsert logic, updates do not generate new records but re-evaluate the existing record.
- Are the sender and receiver screened separately?
- Yes. Both are recorded as separate parties and screened against sanctions, PEP, and internal lists.
- Can transfers coming from different senders to the same receiver be detected?
- Yes, but not by looking at a single sender account. The relationship network around the target must be extracted using shared IPs, devices, phone numbers, emails, and counterparties.
- Why are cash transactions handled separately?
- Transferring funds deposited from ATMs in different provinces into a single account, and withdrawing loads made to an inactive account from ATMs at the maximum amount, are distinct types in the guideline; they cannot be analyzed without channel information.
- Which data should be collected at onboarding?
- Email and IP scores. The guideline considers loading funds into accounts belonging to different unrelated individuals from the same IPs as an indicator, and this data cannot be generated later.
- Where is the report draft prepared from?
- From the same case data. The decision is linked to the case with its justification and evidence, and the signature remains with the institution.