Structuring: what it actually looks like on a statement
Every training deck defines structuring in a sentence and then moves on, which leaves you no better equipped when a real statement lands in your queue. This note works through what the pattern looks like in the data — the clustering, the branch spread, the rounding — and why the threshold itself is the least useful thing on the page. It also covers the version of this case that turns out to be a shop owner following advice a branch clerk gave them years ago.
The definition is not the skill
Structuring gets defined for you on day one: breaking a large cash amount into smaller deposits to stay beneath a reporting or verification threshold. Fine. Every practitioner can recite it. Almost nobody can look at four months of account data and tell you whether they are seeing it.
The gap is that the definition describes an intention, and a statement only ever shows you arithmetic. You get dates, amounts, branch codes, channel, sometimes a depositor name. The intention has to be inferred, and the inference is where junior analysts either learn the job or start filing on shape alone. I have reviewed queues where thirty per cent of the structuring alerts were closed with a narrative that amounted to "amounts were below the threshold, therefore structuring" — which is not reasoning, it is restating the alert logic back to itself.
So let us look at what the data actually does.
What the pattern looks like on the page
Start with the distribution, not the individual amounts. Deliberate structuring produces a cluster with a hard ceiling and almost no tail above it. If you plot four months of cash credits and see forty deposits between, say, eighty and ninety-eight per cent of the relevant limit, and not a single one above it, that ceiling is doing work. Random business takings do not respect a ceiling. A busy Saturday spills over. A quiet January dips well under. The absence of variance is more informative than the amounts themselves.
Then look at the pence. This is the single most useful habit I teach new analysts on cash cases. Genuine till takings are messy — £7,412.68, £4,206.31 — because they include coin and because they are the residue of hundreds of small transactions. Cash that has been counted out to sit under a line tends to arrive in notes only, in round hundreds, sometimes the same amount repeatedly. When I see £9,500 four Tuesdays running from a business that claims to sell sandwiches, the pence are telling me the amount was chosen rather than earned.
Next, the geography and the calendar together. Multiple branches on the same day is the classic marker, but the more revealing question is whether the branch spread makes any operational sense. A supermarket chain banking at four branches is banking near its four shops. A single-site takeaway whose cash arrives at four branches spread across eleven miles is doing something that costs the depositor time and petrol, and people do not incur cost without a reason. Similarly, ask whether the deposit rhythm follows the trading week or the depositor's week. Hospitality cash lands on Mondays and Tuesdays because it accumulated over the weekend. Cash that lands on whatever days the person carrying it was free is following a different logic.
Finally, look at what happens after the cash arrives. Structured deposits that consolidate and leave within days — a single onward transfer that sweeps the accumulated balance to a third party, a related company, or overseas — tell a very different story from cash that sits in the account and gets drawn down on suppliers, wages and rent. In the teams I have run, the outbound leg resolved more of these cases than the inbound leg ever did. If you are building the file properly, that outbound analysis belongs in it; the same reasoning that shapes what an EDD file should contain applies here.
Why the threshold is the least interesting number
Analysts fixate on the limit because the alert rule fixates on it. Two reasons to hold it more loosely.
First, thresholds vary and they are not always statutory. In the United States, the currency transaction reporting regime administered by FinCEN creates a well-known reporting point that has been part of the structuring conversation for decades. In the United Kingdom there is no equivalent routine cash transaction report, so the line a customer appears to be avoiding is usually the firm's own — a counter policy requiring extra source-of-funds questions, an internal escalation trigger, or a branch's local practice. JMLSG guidance frames the expectation around risk-sensitive scrutiny rather than a fixed number. That matters, because a customer cannot be inferred to be evading a legal obligation they were never subject to.
Second, and more importantly: the threshold tells you where the ceiling sits, not why. FATF has documented structuring as a typology for a long time, and the typology has never rested on the arithmetic alone. Avoidance of paperwork is a motive shared by tax evaders, people hiding income from a spouse, people who find bank forms humiliating, people whose English is limited, people who were told to do it, and people laundering criminal proceeds. Only one of those is your predicate concern, and the ceiling in the data does not distinguish between them.
The version that is just a shop banking its takings
Here is the case I have seen more often than any genuine structuring scheme, and it is the one juniors get wrong.
Case note
A wholesale-supplied fast food business, two sites, banking with a UK high street institution since 2014. Between 11 May and 26 September the account received forty-seven cash deposits totalling about £431,000. Mean deposit £9,170. Highest deposit £9,880. Not one credit above the bank's internal £10,000 counter-verification point in the entire period. Deposits landed at four branches, all within about eleven miles, frequently two on the same day.
The alert looked textbook. It was not. Till reports and card-to-cash ratios for both sites reconciled to the banked cash within about four per cent across the period. When the relationship manager asked the owner directly, he explained that in 2016 a counter clerk had told him that deposits of ten thousand or more meant filling in a form and waiting, and that he had instructed his manager to keep every bag under that ever since. Nine years of habit, formed at a counter, by a member of staff who was probably trying to be helpful. The four branches were a queue-avoidance strategy; two of them are next to his suppliers.
What did not reconcile was a second strand: eight deposits between 3 July and 12 September totalling about £38,000, made by a named individual with no employment relationship to the business, on days when neither site traded. That strand went to the MLRO and was reported. The other thirty-nine deposits did not.
The lesson I draw from that composite, and from the dozen or so real files it is stitched from, is that a structuring alert on a cash-intensive business is a question about reconciliation, not about intent. If the banked cash matches an independent measure of trade, the ceiling has a mundane explanation available and you are obliged to test it. If it does not match, the gap is your case — and it is usually smaller and sharper than the alert made it look.
The three questions that resolve most of these
- Does the volume fit the trade? Reconcile the cash against something you did not get from the customer's mouth — card receipts, VAT filings, supplier invoices, seasonality, the number of covers a forty-seat restaurant can physically turn. This resolves the majority of cases by itself.
- Who is physically carrying the cash, and does that make sense? Deposits by unconnected third parties, by several different individuals, or by people who cannot plausibly have been at the business that day are worth more than any amount pattern.
- Where does it go? Cash that stays and funds operations behaves differently from cash that consolidates and exits. Look at the seven to fourteen days after each cluster.
Work them in that order. And when you write the case up — whether it closes or escalates — say which question you answered and with what evidence. A closure that records "reconciled banked cash to card takings for the period 11 May to 26 September, variance under five per cent" is defensible in two years' time. "No adverse findings" is not. If narrative construction is where you feel least confident, the fuller treatment in how to write a SAR narrative walks through exactly how much of your reasoning belongs on the page.
How to handle the customer contact
Two practical points, because these cases usually involve asking someone a question.
Frame the enquiry around your own process, not around their conduct. "We periodically review cash deposit arrangements and I want to make sure our records reflect how your business banks" gets you a better answer than anything that implies suspicion — and it keeps you well clear of the tipping-off problem, which is a real constraint in the UK and in most regimes that follow the National Crime Agency reporting model. If a report has been made or is contemplated, the questions you may ask narrow considerably, and that judgement sits with your MLRO, not with you.
And watch for the outcome where the customer's explanation is true and the arrangement still needs fixing. The shop owner in that composite was not doing anything wrong, but nine years of sub-limit deposits had made his account permanently noisy, generating alerts that consumed analyst time every quarter. The right ending was a conversation about depositing his actual takings, and a note on the file explaining the history. Alert volume is a resource problem as much as a risk one, and the discipline for managing that is much the same as the discipline in a good transaction monitoring alert triage routine.
Structuring is real, it is common, and I have worked cases where the pattern was unambiguous and the money was very dirty indeed. But the pattern alone never carried the case. The arithmetic opens the question. Reconciliation, the depositor identity and the outbound leg answer it.
What matters: The ceiling in the data tells you where to look, never what you have found — reconcile the cash against something the customer did not tell you, and the case usually answers itself.