ATM Structuring

Published On: 07/20/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

Key Highlights: ATM Structuring

  • ATM structuring distributes potentially illicit cash across dispersed ATMs and cash deposit machines, by transaction, machine, account, depositor or time, exploiting around-the-clock availability and reduced direct staff observation.
  • Money-mule networks may accumulate substantial deposits without being identified by monitoring that assesses transactions only in isolation.
  • Financial institutions can strengthen detection by applying machine-location analysis and threshold-proximity rules, calibrated to their own risk assessment, to help mitigate ATM structuring.

What is ATM Structuring?

ATM structuring is the deliberate splitting or distribution of potentially illicit cash deposits across ATMs and cash deposit machines to reduce scrutiny or evade controls. It may spread deposits across transactions, machines, accounts, depositors or time; threshold-proximity amounts, multiple machines and multiple depositors are possible indicators, not required features of every case.

ATM structuring is an AML typology, not a separately defined offence under the cited UAE legislation. It is the deliberate splitting or distribution of cash deposits across transactions, times, machines, accounts, locations or depositors to reduce scrutiny or avoid detection, using automated teller machines and cash deposit machines (CDMs, also marketed by some providers as intelligent or interactive deposit machines, IDMs or ITMs).

The conduct may amount to money laundering where the relevant elements of Article 2 of Federal Decree by Law No. (10) of 2025 are satisfied; separately, a structured deposit pattern may trigger a suspicious transaction report where the institution suspects, or has reasonable grounds to suspect, that the funds or activity are connected with a crime.

Deposits close to an internal monitoring parameter may be an indicator, but are neither necessary nor sufficient to establish structuring. Unlike a branch counter, an ATM or CDM does not independently assess the customer’s explanation or observe behavioural indicators at the point of deposit; depending on the machine and product configuration, deposits may be available around the clock and generate access logs based on the depositor or authentication identifier and machine-location data available to the institution.

Cash-deposit functionality, authentication and recorded data vary by institution, product and machine.

Is ATM Structuring Illegal in the UAE?

ATM structuring is not automatically unlawful merely because a person makes several cash deposits. The relevant legal and compliance question is whether the deposits form part of money laundering or another criminal offence, or whether the pattern gives the institution reasonable grounds for suspicion. Red flags call for investigation; they do not, by themselves, establish criminal conduct.

UAE legal position: ATM structuring is not a separately named offence. Structured deposits may amount to money laundering where the elements of Article 2 of Federal Decree by Law No. (10) of 2025 are met.

An institution must submit a suspicious transaction report without delay where it suspects, or has reasonable grounds to suspect, that funds or activity are connected with a crime, regardless of the amount, and the duty extends to attempted transactions.

Regulatory Framework Related to ATM Structuring

Federal Decree by Law No. (10) of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing governs this typology.

Article 2 establishes money laundering as an independent crime from the predicate offence; ATM-based structuring may amount to money laundering where the acts and knowledge elements set out in Article 2 are met.

Separately, Article 18 imposes the reporting duty regardless of the value of the transaction or funds.

Article 19 requires regulated entities to identify, assess, document and continuously update their crime risks, apply customer due diligence, carry out ongoing monitoring, and maintain internal policies and controls. On a risk-based reading of these obligations, entities should design controls capable of detecting unusual ATM and CDM cash-deposit patterns, and location data from ATM access logs can support that monitoring where it is generated and available.

Cabinet Resolution No. (134) of 2025, Article 17, requires regulated entities to establish and update indicators capable of identifying suspicious transactions.

Deposits structured to stay below internal monitoring thresholds, and deposit volumes inconsistent with the customer’s declared profile, are examples of the kinds of patterns such indicators may be designed to catch.

The location dispersion of ATM deposits, where a customer’s deposits originate from ATMs in widely separated locations, inconsistent with their stated residence and work pattern, is another pattern an institution may choose to monitor.

Primary Authority or Supervisory Body

The Central Bank of the UAE (CBUAE) supervises banks, exchange houses and other financial institutions licensed by it, including commercial banks and their ATM networks.

Firms established or licensed in the DIFC or ADGM must also comply with the AML rules and supervisory requirements of the DFSA or FSRA, as applicable, alongside the applicable federal criminal and AML framework.

CBUAE transaction-monitoring expectations are risk-based across products, services and delivery channels; an institution offering cash-deposit ATM or CDM services should therefore ensure those transactions are covered by its monitoring framework.

The UAE FIU, established under Article 11 of Federal Decree by Law No. (10) of 2025 receives STRs through goAML, which is the FIU’s designated electronic reporting platform, or through any other means approved by the FIU.

The CBUAE also supervises licensed exchange houses. Where a CBUAE-licensed financial institution, including an exchange house where permitted, offers self-service cash-acceptance functionality, that product should be addressed within its risk assessment and monitoring framework on the same basis as any other cash-deposit channel.

The Ministry of Economy and Tourism (MoET) supervises specified DNFBP sectors within its regulatory remit; other DNFBPs may be supervised by the relevant competent authority or free-zone authority.

Reporting or Compliance Obligations and Channels

The STR obligation under Article 18 of Federal Decree by Law No. (10) of 2025 is triggered upon suspicion, without any minimum deposit value.

A compliance officer who identifies an ATM deposit pattern that is inconsistent with the customer’s profile, whether through threshold-proximity amounts, geographic dispersion, or multiple depositors to the same account, should prompt timely investigation; where the institution then suspects, or has reasonable grounds to suspect, that the funds or activity are connected with a crime, it must notify the FIU without delay and directly, regardless of the individual deposit values, through the electronic system designated by the Unit.

In the UAE, goAML is the FIU’s designated electronic reporting platform, subject to any other reporting method approved by the FIU.

Article 25 of Cabinet Resolution No. (134) of 2025 requires transaction records to be retained for at least five years from the completion of the transaction or the end of the business relationship.

Article 25(2) separately covers the results of any analysis, CCTV and related ATM recordings, and Suspicious Transaction Reports; for these categories the five-year period runs from the latest applicable statutory event, which may include account closure, completion of an occasional transaction, completion of a supervisory inspection or investigation, or issuance of a final court judgment.

Where the institution generates, receives or holds such data, machine identifiers, location data, authentication records, deposit amounts and timestamps should be mapped to the applicable Article 25 record category and retained for the relevant statutory period, so that the activity underlying an ATM structuring investigation can be reconstructed.

Article 37 also provides statutory protection for covered entities and their personnel when furnishing required information, unless reporting was undertaken in bad faith with an intention to harm another person.

Attempted Deposits and the Tipping-Off Prohibition

The reporting duty does not depend on a transaction completing. The definition of a suspicious transaction in Federal Decree by Law No. (10) of 2025 covers transactions that are executed or merely attempted, and Cabinet Resolution No. (134) of 2025 (Articles 17 to 19) sets out the suspicious-transaction reporting rules.

Where an ATM or CDM deposit is attempted, refused, or abandoned in circumstances that give rise to suspicion, the obligation still applies, regardless of value. Suspicion, not completion, is the trigger.

When investigating or reporting an ATM structuring pattern, staff must not disclose to the customer or any third party that a report has been or may be filed, or that an investigation is underway.

Under Article 29(1) of Federal Decree by Law No. (10) of 2025, tipping-off carries imprisonment and a fine of no less than AED 50,000, or either penalty. Article 29(3) imposes an aggravated penalty, imprisonment of not less than one year and a fine equal to the value of the proceeds, subject to a minimum of AED 100,000, where conduct under Article 29(1) or 29(2) results in the proceeds becoming unavailable for seizure, being destroyed, or losing value.

Any customer contact to clarify source of funds should be handled so that it does not reveal the existence of an alert or report.

Current Regulatory and Supervisory Relevance

Where cash deposit machines offer direct-note acceptance, extended operating hours and rapid account posting, they may increase the speed and frequency with which cash can be deposited.

The associated risk depends on the machine configuration, deposit limits, authentication process, customer segment and the data available to the institution.

Monitoring should therefore assess aggregate and linked activity rather than relying exclusively on individual transaction values.

Why Detecting ATM Structuring Matters

ATM structuring detecting matters because the ATM channel can be a high-volume, low-friction and geographically distributed cash-deposit channel operated by financial institutions.

A teller who handles the same customer’s third cash deposit of the day might pause and ask a question; a self-service machine does not independently assess an explanation at the point of deposit, which is why aggregate, pattern-level monitoring carries the load on this channel.

Under Federal Decree by Law No. (10) of 2025, a supervisory authority may impose administrative penalties for an AML reporting or control failure, including a fine of AED 10,000 to AED 5,000,000 for each violation (Article 17).

Where a suspicious transaction report is not filed through a deliberate act or gross negligence, Article 28 additionally provides criminal penalties of imprisonment and a fine of AED 100,000 to AED 1,000,000.

How an Organised ATM Structuring Operation Works

Fictional example for compliance training

More organised ATM structuring may involve coordinated distribution of cash deposits across transactions, machines, accounts, locations, depositors or time periods, of which deposits below or close to a monitoring parameter are only one possible feature; less complex activity may involve one person repeatedly splitting deposits across transactions, machines or days.

Cash is divided across transactions, machines, accounts, depositors or time periods so that no single deposit draws attention, and where more than one person is involved, deposits are spread across a network of depositors and machines in different locations.

Individually the deposits look unremarkable, but together they form an aggregate pattern, for example a run of same-account deposits across dispersed machines within a compressed window, visible only when the account’s full deposit history is reviewed.

The machine ID, location, timestamp, available depositor identifier and amount associated with each deposit provide the data that make the pattern detectable.

Once the account has accumulated the deposits, the balance can be moved, converted or transferred; because individual deposits may not trigger a value-based alert, early detection depends on aggregate, pattern-level monitoring.

Illustrative ATM Structuring Scenarios

The Geographic Dispersion Operation

These scenarios are hypothetical composites provided for illustration and do not describe specific real cases.

A commercial bank’s automated transaction monitoring flagged a customer account that had received twenty-six cash deposits over a three-day period, each between AED 4,200 and AED 4,800, totalling AED 121,000.

The individual deposits had not individually triggered a threshold alert.

A location review of the ATM access records showed that the deposits had been made at 26 different ATMs across 5 distinct areas of the city.

The customer’s stated occupation was a sole trader operating from a single commercial unit.

The geographic dispersion of the ATM deposits was materially inconsistent with the stated business profile.

Further investigation identified linked depositors and subsequent movement of funds consistent with an organised placement operation; the institution concluded that reasonable grounds for suspicion existed and filed an STR.

The operational lesson is that ATM location dispersion analysis, applied to the full set of deposits rather than to any individual transaction, can reveal a pattern consistent with coordinated ATM structuring and support further investigation.

The CDM Round-the-Clock Placement

A bank identified that one of its cash deposit machines had processed thirty-one deposits into the same account during a single overnight period, each between AED 3,500 and AED 3,800, with an aggregate of about AED 116,000.

The deposits were made by a sequence of depositors. Several distinct depositor or authentication identifiers appeared in the transaction data, and a data-quality review found incomplete depositor-identification records for part of the activity.

A compliance review found that the overnight deposit frequency and aggregate value had no credible legitimate explanation after reviewing the customer’s profile and available supporting information, and that the funds were moved on shortly afterwards. An STR was filed.

The lesson is that CDM round-the-clock monitoring with automated alerts for high-frequency deposit sequences within a single session or overnight window may help detect CDM-enabled ATM structuring where the institution’s risk assessment and data support it, since such activity can occur in time windows when direct oversight is lowest.

How Does ATM Structuring Facilitate Money Laundering?

ATM structuring is commonly associated with the placement stage because it introduces physical cash representing proceeds of crime into an account through deposits that individually appear unremarkable but collectively represent a structured pattern. Depending on the broader arrangement, however, placement, layering and integration may overlap.

Compared with branch-counter deposits, depending on the applicable machine limits, functionality and network availability, a self-service channel may allow deposits to be distributed more quickly or across more locations. It avoids the staff observation and opening-hours constraints of a branch, which is why aggregate, pattern-level monitoring of the channel matters.

Cash proceeds placed through ATM structuring may derive from a range of predicate offences, including tax evasion and drug trafficking.

Federal Decree by Law No. (10) of 2025, Article 2 criminalises money laundering and establishes it as an independent crime from the predicate offence. ATM-based structuring may constitute money laundering where the applicable proceeds, conduct and knowledge elements are satisfied.

Money mules may act as operational participants in organised ATM-structuring schemes. They may transport or deposit cash on behalf of another person, sometimes knowingly and sometimes after deception or coercion. Their participation may create an evidential trail through machine, authentication, transaction and CCTV records, which the investigation can use to identify links among the depositors, accounts and organisers. Money mules may participate knowingly or may be recruited through fraudulent employment offers, deception, coercion or other forms of exploitation.

In more organised schemes, an organised crime group may coordinate the accounts, depositors, machines and onward movement of funds. Such a group typically receives the funds once the deposits have settled. The same group may run activity across several accounts or institutions, which is why monitoring that links accounts and depositors matters.

What Are the Red Flags That Identify ATM Structuring?

Category  Red Flag 
Transaction Pattern  Multiple ATM deposits consistently fall just below the institution’s internal alert threshold over short time intervals 
Transaction Pattern  Customer repeatedly deposits nearly identical sums at ATMs, each deposit below the threshold limit 
Transaction Pattern  Significant increase in the frequency of ATM deposits within a short time frame, inconsistent with the customer’s historical pattern 
Transaction Pattern  High aggregate volume of sub-threshold ATM deposits within a 24-hour, 7-day, or 30-day window inconsistent with the customer’s declared profile 
Geographic  Deposits occur at ATMs across multiple geographic locations inconsistent with the customer’s known residence and business pattern 
Geographic  ATM deposit locations are dispersed across distant areas of the city in a pattern inconsistent with any plausible daily routine 
Geographic  The observed volume and geographic dispersion of ATM deposits deviate significantly from the customer’s stated profile and historical behaviour 
Multi-Depositor  Multiple individuals deposit small cash amounts into the same account at different ATMs, each below internal alert thresholds 
Multi-Depositor  Multiple distinct depositor or authentication identifiers associated with deposits into the same account within a compressed period, where such identifiers are captured 
CDM-Specific  High-frequency deposits at cash deposit machines outside normal banking hours, particularly in overnight or early-morning windows 
CDM-Specific  Multiple sequential depositors using the same account at a CDM within a short period, accumulating a material aggregate without individual threshold breaches 

Red Flags and Possible Legitimate Explanations

Repeated or dispersed ATM deposits are indicators, not proof. Each has plausible legitimate explanations that an investigation should test before concluding that suspicion arises.

Indicator  Possible legitimate explanation  Evidence to review 
Deposits at several different machines  A mobile or geographically dispersed business, or cash-collection activity  Invoices, delivery or collection routes, business locations 
Several different depositors into one account  Authorised employees or cash-collection agents  Employment records, mandates, collection logs 
Repeated near-identical amounts  Standard till takings or fixed invoice values  Sales and accounting records 
Rapid outward payments after deposits  Routine supplier settlement cycle  Contracts and supplier invoices 
Deposit values sitting near an alert parameter  Normal product or operational cash limits  Historical account behaviour and product rules 

No single indicator is conclusive. The weight of any red flag depends on the customer’s profile, the surrounding context and the corroborating evidence; the review exists to test whether a legitimate explanation holds before deciding whether suspicion arises.

Which AML Controls Counter ATM Structuring?

Control What it supports Control function Limitation 
Threshold-proximity detection rules Flags deposits clustering just below a calibrated monitoring parameter Detects Legitimate amounts may cluster near product or operational limits; the band must be calibrated and validated 
ATM/CDM machine-location analysis Identifies geographic dispersion inconsistent with the customer’s KYC profile Detects Machine location does not establish the depositor’s identity or intent 
Cross-depositor account analysis Identifies multiple distinct depositors or authentication identifiers associated with deposits into the same account Detects A credential may not identify the person physically depositing cash 
CDM velocity monitoring Flags high-frequency overnight or weekend deposit sequences to one account Detects Legitimate businesses may deposit outside normal hours 
CDD and ongoing monitoring Establishes the expected-activity baseline the pattern is measured against Establishes baseline, detects and mitigates Depends on current KYC; stale data weakens detection 
Enterprise-wide risk assessment (EWRA) Documents ATM/CDM channel risk, the controls applied and any data limitations Risk assessment and governance Not a transaction-level control; depends on accurate channel and customer risk data 
Investigation-led STR filing Reporting suspicious activity to the FIU and supporting financial-intelligence analysis Reports and responds FDL 10/2025 Art. 18, suspicion threshold, no minimum value 
CCTV and related ATM-recording retention Identification of apparent depositors, reconstruction of events and support for investigation or evidential review Supports investigation and evidence Storage, indexing and retrieval can be operationally demanding; the retention framework must meet the Article 25 statutory retention period 

How Do Analytics, AI and RegTech Support Detection of ATM Structuring?

These techniques may use rules-based monitoring, statistical analytics, machine learning or a combination of methods. Their value depends more on appropriate data, calibration and governance than on whether the system is marketed as artificial intelligence.

Potential signals of ATM structuring include deposits close to monitoring parameters, unusual machine-location dispersion, high transaction velocity, several depositor or authentication identifiers, and subsequent movement inconsistent with the customer’s profile. No single signal or combination is required in every case.

Threshold-proximity detection may identify deposits falling within an institution-defined band below a relevant monitoring parameter. The band should be calibrated against the institution’s own products, customer segments and historical activity, and should operate alongside velocity, aggregation and behavioural indicators.

ATM/CDM machine-location analysis computes the geographic distribution of ATM deposits for each customer and compares it against the customer’s expected geographic range based on their KYC profile. A customer whose deposits are distributed across locations that are materially inconsistent with the customer’s stated profile, expected activity or historically observed behaviour, or that cluster in areas materially inconsistent with the customer’s stated address, business or historical activity, generates a geographic anomaly alert.

Cross-depositor network detection identifies accounts receiving deposits from multiple different depositor or authentication identifiers within compressed time windows, and, where those identifiers can be linked to customer records, supports review of common addresses, contact details, activation dates, devices or other connections that per-account monitoring would not surface.

CDM time-series analysis monitors the tempo and volume of CDM transactions, generating alerts when the per-session deposit count, the overnight deposit aggregate, or the inter-deposit interval falls outside the statistical distribution of legitimate usage patterns for that CDM and time period.

ATM Structuring: Model Calibration, Testing and Governance

Detection parameters are only as good as their calibration and oversight. Percentage bands, velocity limits and depositor-count triggers should be set from the institution’s own data, back-tested against known legitimate behaviour, and subject to testing and an appropriate degree of independent review or validation proportionate to the complexity and risk of the model or scenario, then reviewed periodically as typologies and customer behaviour change.

Data quality is a common failure point. Missing or inconsistent machine identifiers, cardless deposits, shared or border-location machines, stale KYC data and imprecise location all degrade detection and should be tracked as data-quality exceptions.

Scenario logic, parameter approvals, model changes and false-positive rates should be documented with a clear audit trail, and alerts should stay explainable to a human reviewer rather than accepted as a black-box score.

Location, device, identity and CCTV data used for this monitoring should be handled under a defined, lawful and proportionate purpose, with access restricted, retention mapped to the applicable record categories, and audit logging in place.

Ownership of the monitoring framework should be explicit. Delivery-channel risk assessment, scenario design, parameter approval, data-quality remediation, independent validation, alert-backlog management, investigation quality assurance, periodic typology review and senior-management reporting should have clearly assigned ownership.

Useful management information includes alert ageing, investigation turnaround, unresolved data exceptions, false-positive rates, overridden alerts, repeat-alert populations and last calibration and validation dates; case-conversion rates should not be treated as targets that encourage defensive or suppressed reporting.

Each detection feature has limitations that investigation must account for:

Detection feature  Key limitation 
Threshold proximity  Legitimate amounts may cluster around product or operational limits 
Location  Machine location does not establish the depositor’s identity or intent 
Multiple credentials or identifiers  A credential may not identify the person physically depositing cash 
Overnight activity  Legitimate businesses may operate outside normal hours 
Rapid onward movement  Supplier, treasury or cash-collection activity may explain it 
Network analysis  Shared addresses or activation dates may have innocent explanations 

Any expanded data collection to support ATM monitoring should be justified against the applicable data-protection framework, which is not uniform across the UAE: the mainland, the DIFC and the ADGM each apply their own privacy regime. An approach that is lawful in one should not be assumed lawful in another without jurisdiction-specific review.

What Data Should Compliance Teams Collect to Detect ATM Structuring?

Data Point Source System What It Reveals 
ATM/CDM machine ID and mapped location, where available and geographic coordinates per deposit ATM usage and location data Whether the geographic distribution of deposits is consistent with the customer’s stated profile and expected and historically observed activity 
Deposit amount distribution relative to monitoring threshold Transaction logs Whether amounts cluster just below threshold in a pattern inconsistent with the natural variation of genuine deposit amounts 
Depositor or authentication identifier per ATM deposit for same account ATM usage data / transaction logs Whether multiple distinct depositor or authentication identifiers are associated with deposits into the same account, which may indicate coordinated third-party activity 
Deposit frequency and inter-deposit timing per account Transaction logs Whether deposits are occurring in sequences inconsistent with a genuine individual customer’s cash flow pattern 
CDM deposit session data including machine ID, time, and depositor sequence ATM usage data / CDM transaction logs Whether the CDM is being used in a high-frequency sequential pattern potentially consistent with coordinated third-party deposit activity 
Rolling aggregate ATM and CDM deposits over institution-defined periods, such as 24-hour, seven-day and 30-day windows, calibrated to customer behaviour, product characteristics and the institution’s risk assessment Transaction logs Whether cumulative ATM deposits exceed amounts consistent with the customer’s stated income and profile 

Why ATM and CDM Deposit Channels Present Elevated Risk

ATM and CDM deposit channels may present elevated channel risk because they permit self-service cash deposits with reduced direct human observation. The level of risk depends on machine functionality, authentication, deposit limits, customer base, transaction volumes, data availability and the controls applied.

An institution whose risk framework treats ATM deposits as a low-risk channel because they are processed by the bank’s own infrastructure, rather than recognising their structural vulnerability to structuring exploitation, may have under-assessed the channel risk.

Third-Party Deposits and Linked-Activity Monitoring

The identity and device data available for a deposit depend on how it was made. A deposit may use the account holder’s own card, an account number, a cardless code, Emirates ID authentication, an authorised employee or cash collector, or it may be paid into another person’s account.

Each method exposes a different authentication and depositor record, so monitoring should use whichever depositor or authentication identifier the institution actually holds rather than assuming a single account card.

CBUAE guidance for licensed financial institutions providing services to cash-intensive businesses states that institutions should obtain appropriate information concerning the source of deposited cash and mandate the use of Emirates ID for cash deposits through ATMs.

This is a supervisory-guidance expectation within the guidance’s stated scope, and should not be described as an express provision of Federal Decree by Law No. (10) of 2025.

The CBUAE guidance was issued under the predecessor federal AML framework and remains published in the CBUAE Rulebook. It should be read together with Federal Decree by Law No. (10) of 2025, Cabinet Resolution No. (134) of 2025 and any later applicable supervisory directions.

Deposit patterns rarely sit in isolation. Detection should also weigh activity linked to the deposits, including:

  • rapid cash withdrawal shortly after deposits;
  • transfers to newly added beneficiaries;
  • transfers to unrelated personal or business accounts;
  • deposits followed by foreign exchange or remittance;
  • activity across linked customers or commonly controlled accounts;
  • repeated use of the same machine by apparently unrelated customers;
  • account turnover inconsistent with known income or business activity;
  • unexplained pass-through activity; and
  • changes in cash behaviour following previous alerts or customer contact.

CBUAE identifies frequent cash activity involving multiple individuals using cash deposit machines as a potentially suspicious pattern.

Not every structured cash pattern reflects the placement of organised-crime proceeds: small-value cash activity may also relate to terrorist financing, fraud or other offences, and may not follow a conventional placement, layering and integration sequence.

The reporting question is whether the institution has reasonable grounds to suspect a link to crime, not which laundering model applies.

Separately, Article 35(2) may be relevant where a person unlawfully enables another person to benefit from their account while knowing, or having sufficient grounds to believe, that the account is intended to be misused. This provision should not be interpreted as making legitimate authorised third-party deposits unlawful.

How Should Compliance Teams Investigate an ATM Structuring Alert?

An alert is a starting point, not a conclusion. Compliance teams typically reach a defensible decision on an ATM structuring alert by working through the following steps:

  • Validate the underlying machine and transaction data: machine IDs, timestamps, amounts and depositor or authentication identifiers.
  • Aggregate the activity across the account, its depositors, cards, machines and time windows.
  • Compare it against KYC information and the customer’s expected account use.
  • Identify the apparent depositors and any linked accounts where the data allows.
  • Review source-of-funds information and supporting documents.
  • Examine what happens after the deposits: rapid withdrawals, transfers or currency conversion.
  • Review prior alerts, KYC changes and connected parties.
  • Weigh credible legitimate explanations before reaching a conclusion.
  • Document supporting and exculpatory evidence, record the decision and its rationale, and where suspicion or reasonable grounds exist file the STR without delay; consider enhanced monitoring or account-risk measures separately.

Filing an STR does not establish that the customer committed an offence, and does not by itself require rejecting a transaction, restricting an account or terminating a relationship. Subsequent action should reflect applicable law, FIU or authority instructions, contractual rights and the institution’s documented risk assessment. Confidentiality and tipping-off restrictions continue to apply.

Sectors at Highest Exposure

Sector  Potential exposure  Specific Reasoning 
Commercial Banks with ATM Networks  Potentially elevated  Banks offering cash-deposit-enabled ATMs or CDMs are directly exposed to this typology because they provide the account and machine infrastructure through which the deposits may be made 
Licensed Exchange Houses  Product-dependent  Exposure depends on the cash-acceptance and self-service products actually offered; CBUAE supervision applies, and machine functionality should be assessed institution by institution. 
Banks Serving High Cash-Turnover Segments  Potentially elevated  Dense ATM networks serving high cash-turnover customer segments can be targeted for mule deposits; risk should be assessed against the customer profile rather than location demographics 

How ATM Structuring and Structuring Are Related

ATM structuring is a sub-technique of the structuring typology, applying structuring mechanics specifically within the ATM and CDM cash deposit channel. Where the parent typology addresses all structuring methods, ATM structuring focuses on the specific operational advantages of the ATM channel: 24-hour availability, reduced direct staff interaction, geographic distribution, and the potential for higher-volume deposits, depending on machine configuration.

Related Terms and Concepts

Term  Connection 
Structuring   Parent typology: ATM structuring applies structuring mechanics specifically to the ATM cash deposit channel 
Micro-Structuring   Sibling sub-technique: micro-structuring operates at very small amounts across all channels; ATM structuring distributes cash deposits across ATM and CDM channels, of which threshold-proximity amounts are only one possible indicator 
Remittance Splitting   Sibling sub-technique: remittance splitting targets MSB remittance channels; ATM structuring targets bank ATM cash deposit channels 
Money Mule  Possible participant in coordinated or organised schemes 
Placement  Commonly associated with placement, although laundering stages may overlap 

Variants and Synonyms

Term  Context or Jurisdiction  Distinction from Primary Term 
ATM smurfing  Informal usage  Emphasises the multi-person mule network dimension of ATM structuring 
ATM layering  Incorrect usage in media  Potentially imprecise. An ATM cash deposit commonly represents placement, but the relevant laundering stage depends on the wider scheme and the prior movement of the funds. 
CDM structuring  Technical and compliance contexts  Specifically refers to structuring through cash-deposit-machine functionality; a sub-variant of ATM structuring 
Cash deposit structuring  Broader regulatory contexts  General term for cash-based structuring; ATM structuring is the ATM-channel-specific variant 

What Products and Services Do Criminals Abuse in ATM Structuring Schemes?

ATM services are the primary channel abused in this typology. Standard ATMs with cash deposit capability, which accept physical banknotes through deposit envelopes or direct note acceptance, are used for the individual deposits.

Depending on the machine and product configuration, a deposit generates a card or account credential and, where available, authentication, transaction, device and CCTV records; the receiving account may have been fraudulently opened or be controlled by a money mule, or the account holder may have been deceived or coerced into permitting its use.

Cash deposit machines (CDMs) can support higher-volume deposits: depending on configuration they count banknotes directly, may credit accounts quickly and are often available outside branch hours, including overnight and at weekends. Posting times, deposit limits and authentication vary by institution and product.

The instruments involved are straightforward: physical cash is the input the typology is designed to place, and a bank account capable of accepting cash deposits is the receiving instrument, which then serves as the source for any onward movement.

“The ATM channel’s defining feature for structuring is the reduced level of direct human observation. A teller who processes ten identical cash deposits in an hour may pause and ask a question; a network of machines can accept thirty deposits across thirty locations without weighing the explanation or observing the depositor’s behaviour in the way a teller might. The detection infrastructure that handles branch counter structuring does not automatically transfer to ATMs because the channel is fundamentally different. Location data provide an additional detection dimension for ATM structuring. Without them, an institution is monitoring a channel while overlooking one of its defining features.”

Jyoti Maheshwari

Jyoti Maheshwari - CAMS, ACA

How AML UAE Helps Mitigate ATM Structuring Risk

Where ATM or CDM exposure is material, a financial institution may need to enhance value-based transaction monitoring with aggregate, velocity, machine-location or cross-depositor analysis, depending on its products, available data and documented risk assessment. Financial institutions should assess whether specific monitoring enhancements are appropriate for their ATM and CDM exposure.

AML UAE provides compliance guidance for ATM and CDM channel risk management, including the configuration of machine-location analysis, threshold-proximity rules, and cross-depositor monitoring for ATM networks. Institutions receive practical guidance on the EWRA entry for ATM structuring and STR reporting obligations.

Frequently Asked Questions

Micro-structuring operates in very small amounts across all channels, exploiting monitoring systems calibrated to larger thresholds. ATM structuring distributes cash deposits across ATM and cash deposit machine channels, with threshold-proximity amounts as only one possible indicator, exploiting the channel’s reduced direct human oversight and geographic distribution. The detection emphasis in ATM structuring includes location analysis, which is ATM-channel-specific.

A CDM is an ATM variant that counts and accepts banknotes directly. Its authentication, deposit limits, posting time and operating hours vary by institution and product. Depending on their configuration, CDMs may support faster or higher-volume cash deposits than machines with more restrictive deposit functionality. They are a compliance concern because their combination of speed, capacity and extended-hours access, where offered, can create a higher-volume placement channel that requires specific monitoring controls beyond standard ATM transaction rules.

Financial institutions may detect ATM structuring through a combination of aggregate and velocity monitoring, threshold-proximity indicators, machine-location analysis, cross-depositor analysis, customer-profile comparison and review of subsequent fund movements. The appropriate controls depend on the institution’s products, data and risk assessment.

FDL 10/2025 Art. 2 establishes money laundering as an independent crime from the predicate offence; ATM structuring is a channel-specific form of structuring that may amount to money laundering where Article 2’s elements are met. Art. 18 triggers STR filing on aggregate pattern suspicion without a minimum value. CR 134/2025 Arts. 6–15 require CDD. Art. 25 requires records to be retained for at least five years, subject to the applicable statutory trigger.

Yes. Genuine deposits by several authorised persons into one account are not inherently unlawful. The pattern may warrant review where it is inconsistent with the customer’s profile, lacks a credible economic purpose or is accompanied by other indicators such as rapid onward movement or unusual location dispersion. It does not need to point specifically to mule activity. An STR is required where the institution suspects, or has reasonable grounds to suspect, a connection with crime.

Both are sub-techniques of structuring applied to specific channels. ATM structuring uses cash-deposit-enabled ATMs or CDMs to distribute cash deposits into one or more accounts. Remittance splitting divides transfers through money-transfer or remittance services, often across senders, transactions or beneficiaries. The detection methodologies differ: detection of ATM structuring may use machine-location, aggregate, velocity and threshold-proximity analysis, while remittance-splitting detection commonly focuses on aggregation across senders, beneficiaries, corridors and time periods.

Closing Summary

ATM structuring exploits the structural features that make ATMs valuable: 24-hour availability, reduced direct staff interaction, and geographic distribution. Each of these features is a legitimate benefit for customers and a specific vulnerability for compliance frameworks that do not account for the ATM channel’s distinctive risk profile.

The regulatory framework under Federal Decree by Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 requires regulated entities to assess relevant delivery-channel risks, conduct ongoing monitoring, maintain and update suspicious-transaction indicators, file an STR without delay where suspicion arises, and retain the relevant records for at least five years under Article 25. Where ATM or CDM exposure is material, these obligations support risk-based controls capable of identifying aggregate and channel-specific patterns.

Strengthen Your ATM Structuring Detection Framework

Enhance your AML controls with advanced transaction monitoring, machine-location analysis, and cross-depositor detection to identify suspicious ATM structuring activities.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik