Illicit finance quarterly

In this report:
Limits of trust, verification and compliance

When the victim authorizes the crime

Criminals are forcing victims to authenticate instant payments themselves. As PayShap expands, South African banks may face questions around fraud controls, liability and customer protection.

Nigeria’s stablecoin dilemma

Stablecoins are part of everyday life in Nigeria, complicating efforts to distinguish legitimate remittances from illicit financial flows. The experience offers lessons for South African banks assessing related risks.

When transparency standards diverge

As South Africa works to maintain the reforms that helped secure its FATF grey-list exit, the United States has moved in the opposite direction, creating new due diligence challenges.

Certified, but not verified

Cases from South Africa and the Western Balkans show how notarized documents, audit opinions and attorneys’ trust accounts can create confidence that extends beyond what was verified.

MARKET TYPOLOGY

Checked the box, missed the red flag

Gold laundering is a well-documented risk despite years of due diligence and industry guidance. For banks in the precious metals sector, familiar red flags are passing through established compliance controls.

When the victim authorizes the crime

Instant payment systems are designed to verify that the person making a transfer is the legitimate account holder. But what happens when a customer is forced to authenticate a payment at gunpoint? As South Africa’s PayShap expands, cases from Brazil, India and the US expose a growing blind spot.

One of the fundamental principles of digital banking is ensuring that a transaction is authorized by the account holder. Strong customer authentication – whether through a PIN, a biometric scan, or a one-time code – is designed to answer this question. Authentication confirms that the expected customer, using the expected credentials, approved the transaction. However, it does not in itself prove that the transaction is legitimate.

This vulnerability is now being exploited in remarkably similar ways in three different countries. Criminals in Brazil, India and the United States have found ways to manipulate situations so that customers authenticate transactions themselves.

The new express kidnapping

In Brazil, victims are grabbed off the street and forced to transfer money to their captors, usually through Pix, Brazil’s instant payment system. The practice, known as ‘sequestro relâmpago’, or ‘express kidnapping’, surged when Pix launched during the COVID-19 pandemic, and continues today. São Paulo state recorded 133 kidnapping cases in the first nine months of 2024, and police report that criminals now typically hold victims captive for over a day, waiting for daily transfer limits to reset before releasing them. In May 2025, São Paulo’s military police arrested three people in connection with a case in which a victim was forced to transfer BRL9 200 (US$1 770).

Brazil’s central bank has repeatedly revised its approach to combat the phenomenon. In 2021, it introduced caps on overnight transfers. Under the bank’s resolution BCB nº 147/2021, any transaction judged suspicious can be placed under a mandatory precautionary hold of up to 72 hours while the receiving institution investigates. Brazilian courts have confirmed the rule applies as written.

In 2023, São Paulo’s public prosecutors met formally with Febraban, Brazil’s bank federation, to discuss further measures, including geolocation data in banking apps, which would allow police to intercept a transaction in progress rather than investigating it afterwards.

In addition, a resolution published in 2025, mandatory nationwide since February 2026, requires banks to freeze and trace funds across a chain of accounts once a payer reports a transaction as fraudulent, rather than stopping at the first account that received the money, as the previous system did. The shift from transfer limits to active fund tracing reflects an approach that continues to adapt in response to the threat.

Traceable, but not preventable

Similar tactics are being used in India. In 2025, a woman in Bengaluru was forced to transfer INR5 100 (US$54) after intruders held her pet cat at knifepoint.

Here, however, transactions made using the country’s Unified Payments Interface (UPI), a real-time mobile payment system, leave a digital trail tied to the accounts involved. This has occasionally helped victims after the fact.

In 2025, police used a UPI transaction record to catch two suspects who had forced a victim to transfer INR3 500 (US$37) at knifepoint. In another case, near Gurugram, five men posing as cab drivers were convicted, fined and imprisoned for kidnapping two passengers and forcing them to transfer INR27 000 (US$283) through UPI.

The cases in India show that authentication can work exactly as intended and still be abused. Authentication confirms who initiated a payment. It does not explain the circumstances under which it was made.

Not confined to one type of rail

This type of criminal activity is not confined to sovereign instant payment infrastructure. In the United States, for example, where Zelle, Venmo and Cash App are consumer transfer services rather than part of a national system, similar crimes have emerged despite a very different landscape.

In Chicago and other cities, so-called ‘bank jackings’ have become increasingly common. In these incidents, criminals force victims to unlock their phones using passcodes, fingerprints or facial recognition, and then drain their accounts through commercial instant payment platforms.

In 2024, Manhattan District Attorney Alvin Bragg called for stronger safeguards to protect consumers against a rise in theft through payment apps, proposing measures including transaction limits and delays, secondary verification for large transfers, and stronger monitoring of unusual activity.

Despite their differences, these systems share one characteristic that criminals can exploit: money moves almost instantly once a customer approves a transfer.

South Africa’s open question

With PayShap, South Africa is still early in the growth curve that countries such as India and Brazil have already climbed. However, vulnerabilities are already emerging.

Like Pix and UPI, PayShap payments are final and irrevocable once authenticated. In a May 2026 BioCatch survey of fraud, anti-money laundering and compliance leaders at South African banks, 89% of respondents rated real-time payment platforms like PayShap as presenting a moderate to very high risk of fraud. Accompanying commentary points to the related rise in violent crime involving express kidnappings in the country.

The question, then, is whether fraud controls can correctly identify a transfer that has been authenticated by the real account holder under physical duress. This is a design problem that Brazil is still grappling with, even after several regulatory iterations following the launch of Pix.

Who bears the loss?

Although the examples from Brazil, India and the United States involve three different jurisdictions and payment products, the strategies employed by criminals are remarkably similar. Liability for the resulting losses is less straightforward.

In the United States, Regulation E explicitly recognizes some coerced transactions, including ATM transfers induced by force, as unauthorized. However, it does not provide explicit guidance on the scenario now appearing during payment app robberies, where the genuine customer is forced to authenticate and initiate the transfer themselves.

India’s customer protection framework, meanwhile, allocates liability based on whether the bank, a third party or the customer was at fault, but offers little guidance on how losses should be treated when a customer personally enters their credentials under physical duress.

In Brazil, courts have reached different conclusions about whether banks should reimburse victims of express kidnapping, with the circumstances and location of the robbery affecting liability. While the crime itself is similar, the courts have not always agreed on who should bear the loss.

When authentication is not consent

In 2026, the Financial Action Task Force (FATF) found that 90% of the 156 jurisdictions it assessed had identified fraud as a major money laundering risk. FATF ministers formally committed to tackling the growing ‘fraud epidemic’ as a strategic priority for the period 2026–2028. But coerced instant payments raise a more specific and challenging question: what happens when the bank correctly authenticates the customer, but cannot verify their consent?

South Africa must decide whether to wait for these ambiguities to arise through disputes or to learn from other jurisdictions that are already confronting them. As PayShap grows, it must consider not only how to detect coerced but authenticated payments, but also how to classify them, who should bear the loss and when victims should be reimbursed.

Nigeria’s stablecoin dilemma

Nigeria has become one of the world’s biggest stablecoin markets, driven by everything from remittances to dollar savings and cross-border business. As stablecoins move into mainstream finance, can banks distinguish legitimate economic activity from illicit flows when both travel on the same rails?

Sub-Saharan Africa is the most expensive region to send money to globally. A remittance of US$200 costs, on average, around 8.5% of the amount sent, well above the global average of roughly 6%. For Nigerians living abroad in cities such as London or Houston, trying to send money home, that fee is the difference between covering rent and falling short.

It was this problem with the financial system that drew Chris Maurice into the stablecoin business. In 2017, while waiting in line at a bank, he struck up a conversation with a Nigerian man who was trying to send a few hundred dollars to his mother. The bank was charging him $90 for the transaction. Two years later, Maurice launched Yellow Card in Nigeria; it has since grown into one of Africa’s largest licensed stablecoin infrastructure providers, moving billions of dollars across the continent each year.

Yellow Card’s growth is part of a much larger trend. Nigeria received roughly US$59 billion in crypto-asset inflows between July 2023 and June 2024, at a time when the naira lost significant value. The country ranks sixth globally on Chainalysis’s Global Crypto Adoption Index, and has accounted for close to 60% of all stablecoin inflows into Sub-Saharan Africa since 2019, according to the IMF. Much of this reflects legitimate activity, such as remittances, businesses paying overseas suppliers, and households buying stablecoins to preserve savings in US dollars. Yet because USDT (Tether), in particular, features so heavily in reports of cyber-enabled fraud, many in the financial sector continue to view heavy stablecoin activity as a red flag.

If Nigeria shows that stablecoins are already mainstream, Western Union shows where the industry is heading. In May 2026, the company launched its own dollar-backed stablecoin, USDPT, with the aim of settling transfers more quickly and at lower cost than its existing payment infrastructure. When a major remittance provider begins issuing its own stablecoin, the technology has clearly moved from the margins of financial services towards the centre. The associated risks, therefore, now sit within the mainstream banking system, rather than outside it.

Nigeria has been here before. In February 2021, the Central Bank of Nigeria barred banks from facilitating crypto transactions to contain what it saw as a risk. Demand for these services did not fall, however, it moved underground, into peer-to-peer trading. By December 2023, the monetary authority had reversed course, and Nigeria’s regulators are now moving to bring that activity back onshore. In 2025, a law was introduced placing digital assets under formal securities oversight. The country has also taken steps against unlicensed peer-to-peer platforms. The lesson for banks watching this space is that shutting the door does not eliminate the activity, it simply pushes it out of view.

The question is no longer whether customers use stablecoins for cross-border activity. They already do so, at scale, and regulated global players are now building products on that assumption. The challenge for banks will be distinguishing between a Lagos family receiving a legitimate remittance and a money mule cycling fraud proceeds through the same token, the same rails, and often the same peer-to-peer platform.

Banks face two risks here. Treat all peer-to-peer stablecoin activity as suspicious, and legitimate customers get flagged, debanked and pushed further away from formal services. This has reputational and regulatory consequences. Treat the threat as background noise, and illicit activity gets lost in a flood of ordinary remittances, making it much more difficult to identify.

So what would a better model look like? Rather than treating stablecoin use itself as a risk indicator, banks may need to place greater weight on customer behaviour, transaction patterns, counterparties and the underlying purpose of a transfer. In other words, the context should matter more than the payment rail itself.

As stablecoins have become more widely used, the assumption that their use is itself a red flag has become harder to sustain. The signal has shifted from the asset to the behaviour surrounding it. The Nigerian model suggests that the most important question currently is whether existing risk models can distinguish between criminal activity and legitimate economic behaviour.

This cannot be determined from transaction data alone. Field research and on-the-ground analysis will be vital to understand why people are using stablecoins, and to ensure that legitimate economic activity is not mistaken for criminal behaviour.

When transparency standards diverge

South Africa spent years strengthening beneficial ownership transparency to secure its exit from the FATF grey list. Ten months later, the US has moved in the opposite direction. What does that divergence mean for South African banks dealing with US-linked companies?

From February 2023 to October 2025, South Africa lived under the scrutiny of the Financial Action Task Force’s (FATF) ‘increased monitoring’ list. Getting off it meant completing a 22-item FATF action plan, covering legislative amendments, improved access to beneficial ownership information, and demonstrated effectiveness in investigations, prosecutions and related measures.

When FATF confirmed the plan complete and delisted South Africa on 24 October 2025, the Financial Intelligence Centre (FIC) called it the end of ‘a difficult but critical chapter’. South African Revenue Service (SARS) Commissioner Edward Kieswetter was even more cautious, describing it as ‘not a finish line but a milestone on a long-term journey’. The country entered a new FATF review cycle in the second half of 2026.

For South Africa, one of those hard-won gains was greater transparency over who ultimately owns and controls companies, an area FATF specifically identified as a strategic deficiency and required the country to address.

Ten months later, the United States – the world’s largest economy and an FATF member – has moved in the opposite direction.

The reversal

On 11 August 2026, the US Treasury’s Financial Crimes Enforcement Network (FinCEN) finalized a rule that permanently exempts American companies and individuals from reporting beneficial ownership under the Corporate Transparency Act (CTA). This makes permanent an interim exemption that FinCEN had issued in March 2025. FinCEN will also delete any beneficial ownership data that US persons have already submitted. Foreign entities registering to do business in the US still have to report, but millions of US-created entities no longer do.

Treasury Secretary Scott Bessent described it as ‘a victory for common sense and American small businesses’. However, transparency advocates took the opposite view. Erica Hanichak, co-director of the Financial Accountability and Corporate Transparency (FACT) Coalition, said the rule ‘keeps the floodgates open for criminals to launder money through US shell and front companies’.

It would be easy to frame this as hypocrisy, with Washington supporting stronger ownership transparency internationally while stepping back from it at home. That criticism has some merit. But for banks, the more important question is what the decision means in practice. The US has long had well-documented deficiencies in beneficial ownership transparency, even while supporting FATF standards internationally. The CTA was a relatively recent and contested attempt to address that gap, rather than a long-established part of the US anti-money laundering framework.

The FATF’s own standard (Recommendation 24) does not require all countries to operate the same type of beneficial ownership register. Instead, it requires companies to hold information on their beneficial owners, and the relevant authorities to have efficient access to adequate, accurate and up-to-date ownership information, whether through a registry or another mechanism. Whether the US retreat constitutes a technical breach is therefore a narrower and more contentious issue, which this article does not seek to resolve.

The sharper question

Whether the US remains technically compliant with FATF standards is only part of the story. A more immediate concern is what happens to the information available to banks when a major FATF member scales back its domestic transparency obligations at precisely the same time that jurisdictions such as South Africa have invested heavily in legislative, institutional and political reforms to build the opposite – largely in response to FATF requirements.

Regulatory retreat is not the same as risk retreat. FinCEN’s decision means that most US companies will no longer be required to report the details of their beneficial owners. This does not make it any easier to determine who owns or controls a company. Nor does it make such structures any less appealing to criminals seeking to conceal their identities. US authorities will simply have less ownership information available than they would have had under the Corporate Transparency Act.

This also does not mean banks have lost access to a database they previously relied on. The FinCEN database was never publicly accessible, and financial institutions’ access to it was limited and subject to customer consent. Foreign banks did not routinely consult it directly.

What has diminished is one potential layer of information available to US authorities. As a result, customer-supplied information, corporate records, commercial databases and institutions’ own due diligence have become more important.

Obligations here arise domestically, not internationally. The customer due diligence (CDD) and enhanced due diligence duties of South African institutions stem from local law and FIC requirements, rather than from the FATF, which sets the standard that domestic law implements. These obligations have not changed. What has changed is the amount of information available for US-linked counterparties.

Furthermore, the compliance burden does not disappear when a foreign jurisdiction collects less information. Rather, it shifts back to the institution conducting the due diligence. More than 600 US companies operate in South Africa, directly employing well over 250 000 people, while US Embassy figures from March 2026 put US direct investment in South Africa at over US$7 billion, with bilateral trade reaching nearly US$23 billion in 2025 alone.

Given the scale of these commercial ties, US-linked companies are significant counterparties in cross-border relationships where South African institutions may need to establish beneficial ownership. When a foreign jurisdiction collects less information, banks must rely more heavily on their own due diligence processes.

Why this matters now

For South Africa, the timing is significant. The country entered a new FATF review cycle in late 2026, and will need to show that the reforms that secured its exit from the grey list are being implemented and maintained in practice. The US decision does not change these obligations. It does, however, highlight an increasingly uneven landscape. South Africa is expected to ensure greater transparency regarding beneficial ownership at a time when the US government is stepping back from collecting the same information from most of its own companies.

For banks, the consequence is more practical. South African institutions still have to identify and verify the beneficial owners of their customers and counterparties. These requirements are not weakened simply because another jurisdiction has chosen to collect less information.

Who fills the gap?

As the US steps back from collecting beneficial ownership information on domestic companies, its corporate structures could become more attractive to those seeking to conceal ownership. Where the state collects less of this information, institutions may have to rely more heavily on information obtained directly from customers, corporate records, commercial databases and their own due diligence.

For South African banks, the key question is whether their verification processes are robust enough to determine who ultimately owns a US-linked client or counterparty when less official information is available to support that assessment.

Certified, but not verified

A notarized contract, an audit opinion or an attorney’s trust account can lend credibility to a transaction. But how much should banks infer from a professional’s involvement, and what happens when the assurance attached to that credential goes beyond what was actually verified?

In June 2026, the Global Initiative Against Transnational Organized Crime (GI-TOC) published ‘Licence to Launder’, a report mapping how notaries, lawyers, accountants and auditors across the Western Balkans have become part of the infrastructure of illicit finance. The problem it documents is more specific than simply criminals using professionals to launder money. Rather, it is a mismatch of expectations. A notary certifies a signature, or an auditor signs off on a set of accounts. But banks may interpret these narrow certifications as broader assurance that the underlying transaction and the funds behind it are legitimate.

As the report notes, Montenegrin notaries filed 13 707 cash transaction reports in 2024 while handling 19 857 property sales worth approximately €1.6 billion, and precisely two suspicious transaction reports. This highlights the distinction at the heart of the problem: while procedural compliance is happening at scale, suspicious transaction judgement is not.

How the credential enters the laundering chain

The mechanism is simple: criminal proceeds are passed to a regulated professional, who produces documentation that appears, to everyone downstream, to be the output of ordinary legitimate business. A notary, for example, may certify a property sale without independently verifying the source of the funds involved. Where notarization is optional, as it has been for property sales in the Federation of Bosnia and Herzegovina since a 2015 Constitutional Court ruling, greater reliance may be placed on real estate professionals operating under an even weaker anti-money laundering regime to carry out the transaction. Financial statements prepared with the involvement of professional accountants can compound the effect, giving the receiving entity a documented business history.

A December 2025 indictment from Bosnia and Herzegovina’s prosecutor’s office illustrates the process. Twelve individuals and six legal entities were charged with laundering proceeds linked to international cocaine trafficking between 2017 and 2024. More than BAM6 million (€3.1 million) was smuggled across the border before being funnelled into legitimate businesses, real estate and cryptocurrency. The GI-TOC presents this case as part of a broader pattern in which property transactions and corporate arrangements are used to conceal and integrate criminal proceeds within Bosnia and Herzegovina’s formal economy.

In 2026, Serbian authorities discovered that at least €968 880 in cocaine proceeds had been concealed through cash holdings and property purchases in Serbia and Austria. As the GI-TOC notes: ‘Across the Western Balkans, illicit money rarely moves on its own. It travels through notarized contracts, property deeds, loan agreements, invoices and audited financial statements – paperwork that needs someone with a license to sign, certify or stamp it before it can pass as legitimate.’

The broader issue is not corruption among certain notaries and accountants. Rather, the problem lies in the financial system assigning evidentiary value to professional documents that exceeds what they actually establish. This discrepancy can cause criminal proceeds to appear as legitimate economic activity.

The same blind spot in South Africa

South African cases demonstrate a similar oversight in different institutional settings, relating to both audit opinions and attorneys’ trust accounts.

In 2018, a forensic report by Advocate Terry Motau for the Prudential Authority revealed that while approximately R2 billion was being stolen from VBS Mutual Bank, KPMG lead audit partner Sipho Malaba issued an unqualified audit opinion. Malaba had also, according to allegations in Motau’s report, received around R34 million in loans and benefits linked to the scheme. In April 2026, South Africa’s audit regulator, the Independent Regulatory Board for Auditors, found Malaba guilty of professional misconduct and referred the matter to the National Prosecuting Authority. The case demonstrates how an apparently valid professional opinion can continue to influence decision-making, even when questions are later raised about how it was reached.

A similar problem arises with attorneys’ trust accounts. In S v Price, an attorney arranged for a stolen cheque worth R1.62 million to be deposited into another attorney’s trust account, disguising it as an ordinary business transaction. The second attorney became suspicious and reported the scheme to the police. The court later treated Price’s attempt to launder the funds through another attorney’s trust account as an aggravating factor and upheld his 15-year sentence. In this case, a trust account provided what appeared to be a legitimate route for stolen funds.

In S v Hattingh, the connection was even more explicit. An attorney, who was retained by four banks, used his practice and trust account to commit fraud, theft and money laundering. The court found that he had ‘subverted all the controls’ that the banks had expected him to uphold, and that he had used his trust account to lend legitimacy to the payments passing through it.

These cases emerged in the broader context of weak supervision. South Africa’s 2023 FATF grey-listing identified the inadequate supervision of risk-based designated non-financial businesses and professions (DNFBPs) as one of the country’s strategic deficiencies. The FATF defines this category as including lawyers, notaries, other independent legal professionals, accountants, and trust and company service providers. Across both the Balkans and South Africa, therefore, professional status can create confidence downstream that exceeds what the professional's involvement actually establishes.

What banks should infer, and what they shouldn't

Two distinct risks emerge from these examples. In some cases, the professional knowingly uses a credential, account or position to facilitate illicit activity. In others, the professional performs a legitimate function, but the resulting sign-off is interpreted more broadly than its actual scope. Banks need to account for both scenarios.

A notarized document establishes the matters that fall within the notary’s legally defined certification role. It does not, by itself, establish the source of the funds involved. An audit opinion addresses financial statements under the applicable audit framework and does not constitute general anti-money laundering clearance of the audited entity or the transactions reflected in its accounts. Similarly, using an attorney’s trust account does not prove that the funds passing through it are of lawful origin or have an economic rationale.

Addressing the first risk requires strong professional integrity standards and supervision to deter licensed professionals from deliberately lending their credentials to illicit activity. The second calls for bank compliance controls and training that recognize the limits of professional certification. Even a legitimate sign-off cannot substitute for a bank’s own assessment of source of funds, beneficial ownership, transaction purpose or other relevant risks.

The usual triggers for enhanced scrutiny – transaction values inconsistent with a client’s known profile, unexplained use of professional or trust accounts, undisclosed financial ties between the certifying professional and the client, or seemingly routine domestic documentation alongside opaque or unexplained offshore ownership structures – remain relevant regardless of whether a licensed professional was involved.

Ultimately, professional sign-off should be treated as evidence of what has been certified, not as proof of everything that sits behind it.

MARKET TYPOLOGY

CHECKED THE BOX, MISSED THE RED FLAG

Gold’s money laundering vulnerabilities have been documented for more than a decade, and the industry already has extensive due-diligence standards. Yet illicit gold continues to enter legitimate supply chains. Why do familiar red flags keep passing through well-established compliance processes?

In 2018, Elemetal LLC, then one of the largest gold refiners in the United States, pleaded guilty to failing to maintain an adequate anti-money laundering programme. While operating as NTR Metals, Elemetal had bought billions of dollars’ worth of gold from South American sellers without adequately establishing the identities of certain suppliers or the origin of the gold. Some suppliers were identified only as ‘gold collectors’. The red flags were not difficult to detect, arising from basic questions about counterparties and provenance.

The case is notable precisely because there was little mystery involved. Gold-based money laundering is not an unknown typology. Since 2015, the FATF has documented the associated vulnerabilities and red flags. Gold is stable in value, easily transformed, cash-intensive to trade, and exchangeable almost anywhere in the world. These characteristics make it an efficient vehicle for converting criminal proceeds into apparently legitimate funds. These risks have therefore been apparent to buyers, refiners and financial institutions for more than a decade. Yet criminal proceeds continue to clear the same checkpoints.

The rules already exist

One reason is that the industry already has extensive due diligence requirements, on paper. The Organisation for Economic Co-operation and Development’s Due Diligence Guidance for mineral supply chains and the London Bullion Market Association’s Responsible Gold Guidance set expectations around identifying suppliers and beneficial owners, establishing the origin of gold and assessing risks across the supply chain. To achieve LBMA Good Delivery status, refiners must formally meet these standards and undergo third-party assurance reviews.

A June 2026 GI-TOC report examining illicit gold markets, however, makes the case that the persistence of gold laundering is not primarily a story about missing rules. From a compliance perspective, the report identifies three recurring weaknesses in how those controls operate.

The first blind spot is the confusion between documenting a process and establishing provenance. The GI-TOC’s research highlights one such weakness in gold-sector assurance: audits tend to focus on document checks rather than processes and outcomes, while information on grievances raised, non-compliances identified, or problems resolved routinely goes unpublished. A refiner can show that a check has taken place. However, whether the source of the gold was ever satisfactorily established is a separate matter, and one that often does not leave a visible record.

The second blind spot appears when assurance becomes a chain of reliance. The GI-TOC’s interviews with auditors and assurance providers in the gold sector revealed several recurring constraints, including limited time and budget, gaps in sector-specific expertise, and commercial pressure to maintain ongoing client relationships. The European Commission’s February 2025 assessment of the Responsible Gold Guidance, carried out as part of aligning it with the EU's conflict minerals regulation, came to a similar conclusion, identifying significant gaps in the work of auditors verifying refiners’ compliance, which were serious enough to materially affect how the standard was applied. The further the verification moves from the original supplier, the greater the risk that one layer is assessing the quality of another layer’s controls rather than establishing provenance independently.

The third blind spot is that the actors furthest downstream often encounter the cleanest-looking part of the transaction. The GI-TOC’s research challenges the idea that illicit gold is a marginal problem, as licit and illicit gold move through the same refineries, trading desks and financial institutions. In 2026, for instance, a New York Times investigation found that gold linked to a Colombian cartel had entered the United States Mint supply chain, as far from an unregulated gold shop as the market gets. This occurred after intermediaries and a domestic refiner failed to audit or question the origin of the product.

By the time gold reaches a bank or mint, the documentary trail may appear complete, even though visibility into its original source has diminished. The process of refining compounds this dependence on records: once gold from different sources has been melted and commingled, it is no longer possible to establish its physical provenance from the metal itself.

How the failure travels downstream

Viewed in this context, the Elemetal case looks less like an isolated failure. It was not a case of criminals engineering a novel evasion technique. Rather, it was a buyer who treated inadequate information about a seller and the provenance of its gold as sufficient. Several conditions that should have prompted closer investigation were present: insufficient information about suppliers, weak documentation of the gold’s origin, and transactions inconsistent with what was known about the counterparties. The failure was not necessarily due to the absence of a compliance mechanism, but rather the lack of action taken on information that the mechanism should have revealed.

This is where the typology becomes a banking issue rather than one for the refining industry. A bank that finances a precious metals trader or provides trade finance against a gold shipment may, several steps removed, be relying on the same supplier verification elements that failed in these cases. The vulnerability is cumulative: a weakness in supplier-level verification does not necessarily disappear as gold moves further down the supply chain. Instead, it can be inherited by each subsequent actor and wrapped in progressively more legitimate documentation.

At the banking layer, these underlying weaknesses can become harder to see. A financial institution may encounter an accredited counterparty, a documented shipment and an apparently coherent invoice, with no direct visibility of how the refiner or trader verified the supplier behind them.

The GI-TOC’s recommendations emphasize this point from a regulatory perspective. The report calls on banks, bullion banks and commodity traders to treat due diligence in the gold supply chain as a core compliance obligation, rather than relying on certification or third parties to determine the origin of the gold.

3 questions banks should be asking

The case evidence raises three questions that fall squarely within a bank’s existing client due diligence remit, rather than requiring new tools.

Does the client’s supplier verification process generate meaningful information, or simply create a paper trail? While a written sourcing policy shows that a process exists, escalation records reveal whether it works in practice. This includes investigating red flags and, where necessary, pausing or declining transactions.

How are supplier history and ownership assessed? Limited operating history, opaque ownership and unexplained changes in counterparties should inform the risk assessment of the client relationship itself, not just that of its suppliers.

Does accreditation replace scrutiny, or support it? Good Delivery status and the associated responsible-sourcing requirements provide important assurance. This assurance should inform a bank’s assessment of sourcing risk, rather than replace its own enquiry into how the client’s controls operate in practice.

Beyond the certificate

Gold-based money laundering survives not because the typology is obscure, but because verification and visibility are not the same thing. Each layer of the compliance chain can perform its own checks while still relying on someone further upstream to have established where the gold actually came from.

By the time a bank encounters a transaction, several layers of seemingly legitimate documentation may separate it from the point at which the question of provenance was inadequately answered. Furthermore, the gold itself may already have been melted and mixed in ways that make answering this question impossible.

For banks financing this sector, the practical implication is straightforward. They should treat a counterparty’s accreditation and third-party assurance as a starting point for further enquiries into how their due diligence actually functions, not as confirmation that it does.

Explore past issues

About the Global Initiative GI-TOC

The Global Initiative Against Transnational Organized Crime is a global network with over 700 Network Experts around the world. The Global Initiative provides a platform to promote greater debate and innovative approaches as the building blocks to an inclusive global strategy against organized crime. www.globalinitiative.net