CasePilot

Third-party payments: when someone else's money moves through an account

Most accounts that receive money from other people are doing something entirely ordinary — supporting a relative, splitting a household bill, running a savings committee. A small number are acting as a collection point for someone else's proceeds. This note is about the features that actually separate the two, and how to work the file without deciding the answer in advance.

The pattern, stripped back

A third-party payment is money moving into or out of an account where the person on the other side is not the account holder and has no obvious documented connection to them. That is the whole definition. It is not a red flag on its own — it describes a very large share of retail banking, and a good deal of small business banking too.

What makes the pattern interesting to a monitoring system is that a laundering funnel looks superficially identical to a supported account. Both show credits from people whose names do not appear anywhere else in the customer file. Both show onward movement. The arithmetic of the alert cannot tell them apart, which is why the alert is a question and not a finding.

I have spent a lot of my career watching analysts get this wrong in both directions. Junior investigators close third-party activity too quickly because the customer gave a plausible one-line answer. More experienced ones sometimes escalate too readily because the shape of the pattern resembles something they saw six months ago. The discipline is in the middle: work the specific features, not the resemblance.

The ordinary explanations, which are most of them

Before I get to what distinguishes a funnel, it is worth being concrete about what the innocent population actually looks like, because if you do not have a clear picture of it you will over-escalate.

Family support is the single largest category I have seen in retail portfolios. An account receives regular or irregular credits from siblings, adult children, parents, cousins. Names differ from the customer's, sometimes entirely, because of marriage, naming conventions, or simply because families are not homogeneous. The sums tend to be modest, repeat from the same handful of people, and the money sits for a while before being spent on ordinary things.

Shared households and informal cost-splitting. Rent, utilities, a holiday, a car. One person pays the bill and the others repay them. In a flat share of five with high turnover, the customer's account can accumulate a surprising number of distinct senders across two or three years.

Informal lending between friends, which is common everywhere and especially visible in younger customer segments and in communities that have historically been underserved by mainstream credit. Money comes in, money goes out, the same names recur over time in both directions. That bidirectionality is diagnostic and I will come back to it.

Rotating savings and credit associations — committees, susu, tandas, hui, depending on where you are working. A group of people each contribute a fixed amount on a fixed schedule, and the pot goes to one member per cycle. On a statement this produces a striking pattern: numerous credits from the same defined set of people, then one large outbound payment, repeating. These arrangements are old, legitimate and widespread. The FATF work on financial inclusion has been clear for years that treating informal community finance as inherently suspicious pushes exactly the wrong people out of the regulated sector.

Small traders and casual work. A person doing hair, childcare, tutoring, repairs, delivery work. Their business receipts arrive as personal transfers from customers, because that is how their customers pay. This overlaps heavily with the question of whether the takings are plausible, which I have written about separately in the context of assessing a cash-intensive business.

What separates a supported account from a funnel

Three features do most of the work. None is conclusive alone. Together they are usually enough to reach a defensible view.

The number and diversity of senders

Family support has few senders and they repeat. A funnel has many senders and they largely do not repeat. The line is not a fixed number — it depends on the customer's profile, age, stated occupation and how long the account has been open — but the shape of the distribution is what you are reading. Fifteen credits from four people over a year is a support pattern. Fifteen credits from fifteen people over three weeks, with no name appearing twice, is something else and needs work.

Geographic dispersion matters too. Housemates and relatives tend to cluster. A set of unrelated senders spread across a dozen different banks and several regions, with no common thread, is harder to explain by any of the ordinary mechanisms above.

The speed and completeness of onward movement

This is the feature I weight most heavily. Money given to someone for their own use tends to stop. It sits. It gets spent on groceries and transport and a subscription. Money passing through an account for someone else's benefit tends to leave, and it tends to leave quickly and almost completely.

Look at the residual balance after each outbound sweep. If the account is consistently drained to within a few pounds of zero within hours of credits landing, and the outbound is concentrated on one or two beneficiaries, you are looking at a conduit — even before you ask whose conduit it is. The customer may be a controller. They may equally be someone whose credentials have been taken over, or who has been recruited under a false pretext. That distinction is the subject of a separate discussion about telling a victim from a mule, and it matters enormously to how you write the file up.

Whether the customer can name the counterparties

Ask. It sounds obvious and it is the step most often skipped. Someone receiving money from their aunt knows their aunt's name, knows roughly why the money arrived, and will tell you without hesitation. Someone whose account is collecting proceeds for a third party will usually be able to name one or two senders and then run out.

Pay attention to the texture of the answer, not just its content. Vagueness in the aggregate with precision about the outbound side is a notable combination. So is an explanation that fits the total but not the pattern — "it's my savings from work" does not account for forty distinct payers.

Case note

A composite from two e-money portfolios I have worked on. Customer opened in October, stated occupation "student", declared expected monthly turnover of about £800. Between 3 February and 19 April the account received 62 inbound faster payments from 41 distinct sender names, ranging from £120 to £950, totalling £27,400. Fifty-one of the 62 credits were followed by an outbound transfer within four hours; nine outbound payments to two accounts held at an overseas institution accounted for £26,150. Peak balance held overnight across the whole period was £312. When contacted, the customer named six of the 41 senders, described the remainder as "people from a group chat paying for tickets", and could not explain the two overseas beneficiaries beyond "a friend's business". That file was escalated and reported to the relevant financial intelligence unit; the account was subsequently linked to reported purchase fraud.

The instructive comparison is the file I reviewed the same fortnight that alerted on almost identical rule logic. A customer in her fifties, 38 credits over five months from nine recurring senders, amounts fixed at £200, and one outbound payment of £1,800 on the last working day of each month to a different member of the same nine each time. She named all nine, explained the rotation without being prompted, and the pattern had been running for three years on her previous account. That was a savings committee. It took twenty minutes to establish and the file was closed with a clear rationale. Same rule, same trigger, opposite conclusion — and the only reason I could tell them apart was that someone had asked the question.

The outbound side

Third-party payments out attract less attention than payments in, which is a mistake. An account paying unrelated beneficiaries can be doing several different things: settling genuine obligations, making onward disbursements on behalf of a controller, or dispersing funds deliberately to break the chain.

What I look for on outbound is the relationship between the credit and the debit. Are individual credits matched almost one-to-one with individual debits? Does the sum of outbound payments to a given beneficiary track the sum of inbound from a given sender? Layering leaves arithmetic fingerprints, and they are often legible on a single statement page. The behaviours overlap with deposit patterning, and if you have not read it, the note on what structuring looks like on a statement covers the adjacent shape.

One thing to hold lightly: round-number payments out to unrelated parties are frequently just repayments of informal loans. People settle debts in round numbers. The presence of round sums is a weak signal on its own and I have seen it over-weighted badly.

Working the file

My sequence, more or less. Pull the full period rather than the alert window — twelve months if you have it, because seasonality and life events explain a great deal. Build a counterparty table with sender name, count, total, first and last date. Look for names appearing on both sides of the ledger; reciprocity is one of the strongest indicators of a genuine social relationship. Then reconcile the aggregate against the stated profile, and only then decide whether you need to contact the customer.

Document the negative findings as well as the positive ones. "No reciprocal payments observed" is evidence. So is "customer named seven of nine senders, consistent with account history since 2021". The JMLSG guidance in the UK is helpful on the principle that customer due diligence is proportionate and risk-based rather than uniform, and the same logic applies to how much work a third-party pattern warrants. A pensioner receiving two payments a month from her son does not need a full counterparty reconstruction.

If you are new to this and building your own working order, the alert triage checklist sets out the broader sequence this fits inside. And when the file does go forward, the counterparty table you built is very close to being the evidential spine of the narrative — the structure of a good SAR narrative with a worked example maps onto it almost directly.

A word on tone

Write these files as though the customer will one day read them. Not because they will, but because it disciplines the language. "The customer received funds from parties not identified in the file" is accurate. "The customer was collecting criminal proceeds" is a conclusion you are usually not entitled to draw, and in jurisdictions where reporting goes to a body like the National Crime Agency or FinCEN, the intelligence value lies in the observed facts rather than in your characterisation of them.

Most people with unexplained credits in their account are not laundering anything. They are being helped, or helping, or running a small business badly documented. Treat the pattern as a question about information you do not yet have, and you will close the ordinary files faster and escalate the genuine ones with a file that holds up.

What matters: The distinguishing feature is rarely the money coming in — it is how fast it leaves, and whether the customer can tell you who sent it.

Practise the work, not the theory

CasePilot puts you in the analyst's seat with a morning queue of alerts and authored case files — the same decisions this note describes, with a disposition to defend at the end of each one.

Open CasePilot

Or work cases offline — iOS and Android, free.