What actually happens at each stage of money laundering, with concrete examples and the control that should catch it.
Money laundering usually moves through three stages. Placement puts dirty cash into the financial system. Layering moves it through complex transactions to break the audit trail. Integration returns it to the criminal as apparently legitimate wealth. The stages are an analytical lens, not a fixed sequence, and modern schemes often overlap or compress them.
Money laundering is the process of taking the proceeds of crime and passing them through a sequence of transactions until they look like legitimate wealth. Crime generates value that a criminal cannot spend safely: cash from drug sales, fraud, trafficking, corruption, or tax evasion is dirty, because spending or banking it directly exposes the criminal to detection. Laundering converts that value into money that appears clean.
Analysts break the process into three classic stages: placement (getting dirty cash into the financial system), layering (moving it through complex transactions to break the audit trail), and integration (bringing the now clean-looking money back into the legitimate economy). The Financial Action Task Force (FATF), the intergovernmental AML standard-setter, and the UN Office on Drugs and Crime (UNODC) both describe the process this way. The model originated in United States law enforcement analysis of cash-intensive drug proceeds.
The scale is enormous. UNODC estimates that between 2 and 5 per cent of global GDP, roughly 800 billion to 2 trillion US dollars, is laundered every year, and that less than 1 per cent of illicit flows is ever seized or frozen. FATF effectiveness data reflects the same gap: across roughly 120 assessed jurisdictions, only about 9 per cent scored high or substantial on money-laundering investigations and prosecutions, and about 19 per cent on confiscation.
The three-stage model is the single most-taught framework in anti-money laundering. It is the mental map that compliance officers, bankers, journalists, students, and regulators all use to reason about where controls belong. Each stage describes a different job the money is doing: entering the system, hiding its origin, or re-entering the economy as apparent wealth.
The most important correction to make early is about the order of the stages.
Placement is the entry point: getting bulk criminal proceeds, usually physical cash, into the financial system or into assets. It is the riskiest stage for the launderer, because it is the moment dirty money first touches a regulated institution that has reporting duties. If a control is going to trip, this is the most likely place.
Placement is a control problem at the front door. The defences that matter here sit at onboarding and at the point of deposit.
Layering is the concealment engine. Once money is in the system, the launderer moves it through many transactions to sever the link to its criminal origin, so an investigator following the trail loses it. It is widely described as the most complex stage, and the hardest to detect, because obscuring the origin is its entire purpose.
Layering is designed to defeat the audit trail. A single flow can pass through dozens of accounts, several companies, and multiple countries before it settles, and each hop is intended to look mundane on its own. Rules that fire on simple thresholds miss patterns that only become suspicious across many transactions.
This is where the industry is shifting from static threshold rules to network analytics, behavioural profiling, and machine learning. The aim is to reveal the hidden connections between accounts, shells, and jurisdictions that layering exists to hide, and to spot rapid, circular, or cross-border flows that a rule reading one transaction at a time cannot see. Ongoing screening and transaction monitoring are the primary defences at this stage.
Integration returns the laundered money to the criminal as apparently legitimate wealth, ready to spend or invest without suspicion. By this point the funds look clean, so the defence shifts from tracing transactions to questioning wealth that does not match the customer's known profile.
Because the money now looks legitimate, integration is caught by testing whether a customer's wealth is explained. The controls are less about individual transactions and more about the whole picture.
It is worth restating the point directly, because it changes how you use the model in practice. Sophisticated operations blend or skip stages, and digital-native laundering can compress the entire cycle. Instant payments, crypto rails, and mule networks let placement, layering, and integration happen in hours rather than weeks.
Two further misconceptions are worth clearing up. First, laundering is not only a bank problem. Real estate, gambling, gaming, professional sport, digital assets, and luxury goods are all exploited; Sumsub, for example, estimates football alone at around 30 billion US dollars a year in laundering exposure. Second, crypto did not replace the three-stage model. It stretched layering and integration, adding chain-hopping and mixers, but it did not remove the underlying jobs the money has to do.
The stakes, and the enforcement response, have sharpened over 2024 to 2026. These figures come from named primary and vendor sources; treat single-vendor figures as attributed estimates, not settled consensus.
The supervisory landscape is consolidating and tightening at the same time as the threat evolves.
AI is now a core AML defence, and it maps cleanly onto the three stages. At placement, machine-learning models flag structuring and smurfing by learning normal deposit behaviour and catching split-deposit patterns that rules miss, while document and identity AI at onboarding catches forged IDs before a mule account opens. At layering, network analytics and graph models reveal the hidden connections between accounts, shells, and jurisdictions, and behavioural profiling spots rapid, circular, or cross-border flows. At integration, monitoring shifts to unexplained-wealth and asset-purchase signals, with adverse-media and source-of-wealth AI supporting enhanced due diligence.
In a widely cited PwC survey, about 62 per cent of financial institutions already used AI or machine learning in AML, a figure expected to rise toward 90 per cent. HSBC reported that its Google Cloud AML AI deployment detected 2 to 4 times more confirmed suspicious activity while cutting false positives by more than 60 per cent. These are named-source figures, not industry consensus, but they show the direction of travel: from static rules to network and behavioural detection.
Criminals are using the same technology, and the FATF Horizon Scan maps the threat directly onto the laundering cycle. At placement, generative AI creates fake passports, IDs, and biometric data to pass onboarding and open mule accounts; synthetic identity was among the fastest-growing fraud types in 2025. At layering, FATF notes generative AI helps most, producing fake invoices and documents to disguise flows and patterning transactions in ways rules-based systems struggle to detect. FinCEN's own analysis confirms criminals already use AI to generate falsified documents, photos, and videos.
The landmark example is Arup (Hong Kong, 2024). A finance employee was deceived by a deepfake video call impersonating the chief financial officer and colleagues, and made 15 transfers totalling about 25.6 million US dollars in a single day; none was recovered as of early 2025. Deepfakes can pass liveness and biometric checks and only trigger alarms later, creating a window for fund diversion. Vendors including Sumsub report sharp rises in deepfake and synthetic-identity attempts and warn that a single agentic tool can now chain fake-ID generation, deepfake video, and human-like interaction. These figures are single-vendor estimates.
The practical value of the model is that it tells you which control belongs where. Use this as a starting checklist when reviewing your own onboarding and monitoring.
Three shifts are already visible. Regulation is centralising: AMLA and the EU single rulebook are harmonising standards, and supervisors have signalled they will scrutinise AI-specific AML controls, so firms will need governance defining ownership, risk appetite, and assurance for their AI models. Detection is going real-time and network-first: predictive analytics, graph analysis, and explainable AI are becoming standard, with continuous (perpetual) monitoring replacing periodic reviews. And the field is settling into an arms race: as criminals scale synthetic-identity and deepfake attacks, defensive AI and orchestrated, multi-vendor detection become the baseline rather than a differentiator.
Through all of it, the stage model persists, but as a lens rather than a sequence. Expect training and typologies to keep placement, layering, and integration while emphasising overlap, compression, and crypto-native variants.
Zenoo does not launder-proof a business on its own, and it does not replace verification, screening, or transaction-monitoring vendors. Zenoo is the orchestration and AI layer that sits over the vendors a firm already uses, routing checks, handling failover if a vendor is down, unifying the audit trail, and controlling cost. The framing is always your vendors plus Zenoo, never replace your vendors.
Mapped to the stages: at placement, Zenoo orchestrates the onboarding identity and document vendors that catch mule accounts and synthetic identities, and keeps one record of what was checked across 32 immutable audit event types in 8 categories. It does not itself verify a passport. At layering, Zenoo orchestrates screening and monitoring vendors and adds AI triage: its 10 specialised AI agents can pre-classify up to 80 per cent of screening alerts, cutting per-alert disposition from 20 to 45 minutes down to 2 to 3 minutes, and helping drive the benchmark of investigation time falling from 22 hours to 12 minutes, with most teams seeing a 95 per cent reduction in false positives within 90 days. A 209-country risk database with 16 indicators per country informs the geography risk that matters most here. At integration, Zenoo supports EDD workflows and ongoing monitoring so wealth-change review stays consistent and auditable.
Zenoo cannot detect laundering that the underlying vendors miss, and it cannot compensate for a firm with no monitoring vendor at all. It does not itself perform identity verification, provide sanctions data, or score transactions, and it does not guarantee regulatory outcomes. Its honest job is to make a multi-vendor programme faster, cheaper, more consistent, and fully auditable, with more than 240 check types and connectors available across the marketplace.
Zenoo orchestrates the vendors you already use to catch each stage, adds AI triage across 10 specialised agents, and keeps one audit trail. Your vendors plus Zenoo.