TL;DR: Structuring in banking is the practice of breaking currency transactions into smaller amounts so a financial institution does not file a Currency Transaction Report, and it is a federal crime under 31 U.S.C. 5324 even when the underlying money is clean. FinCEN's Year in Review for FY2025 records 1.25 million SARs reporting structuring, out of 4.8 million SARs filed in total. In October 2025, FinCEN and the federal banking agencies clarified that activity near the $10,000 threshold does not by itself require a SAR — the test is whether the institution has reason to suspect the transactions were designed to evade reporting.
What Structuring Actually Is
Structuring is conducting currency transactions in a way calculated to keep a financial institution from filing a required report. FinCEN's regulatory definition at 31 CFR 1010.100(xx) is deliberately broad: a person structures a transaction when, acting alone or in conjunction with or on behalf of others, they conduct or attempt to conduct one or more transactions in currency, in any amount, at one or more financial institutions, on one or more days, in any manner, for the purpose of evading the CTR requirement.
Two features of that definition drive everything that follows. The offense turns on purpose rather than amount, and "in any manner" removes every obvious workaround — the activity does not have to exceed $10,000 at any single bank on any single day, as the FFIEC BSA/AML Examination Manual states in Appendix G. Splitting $24,000 into nine deposits of $2,700 across three institutions over two weeks is structuring if the purpose was evasion.
Structuring became a federal criminal offense in 1986 and is codified at 31 U.S.C. 5324. The statute prohibits causing an institution to fail to file a report, causing it to file a report containing a material omission, and structuring or assisting in structuring any transaction. No predicate offense is required. A contractor depositing legitimately earned cash in sub-threshold increments because they dislike federal paperwork has committed the same offense as a narcotics courier doing the same thing. Institutions carry a parallel exposure: an employee who tells a customer what amount to deposit to stay under the reporting line risks the "assist in structuring" prong of the statute.
Smurfing is the informal name for the same conduct, usually reserved for the version that uses multiple people. A coordinator hands cash to several individuals — the "smurfs" — who each deposit below the threshold at different branches. Structuring is the term that appears in the statute, in FinCEN guidance, and in SAR narratives.
Where Structuring Shows Up Now
Cash deposits remain the canonical form and still dominate structuring SARs: repeated deposits in the $8,000 to $9,900 range, same-day deposits split across branches or ATMs, cash routed through several accounts controlled by related parties, and business accounts whose cash volume does not match the stated line of business.
The rails have widened considerably. Prepaid card loads, money order purchases sequenced below the $3,000 identification threshold, P2P transfers between unrelated individuals, and virtual currency kiosks all now carry structuring behavior. FinCEN's August 2025 Notice on convertible virtual currency kiosks documents scammers instructing victims to separate cash deposits into multiple lower-value transactions to stay beneath the CTR threshold or a kiosk's daily limit, and describes splitting a payment across several machines as smurfing. The same notice records non-compliant kiosk operators structuring deposits into personal accounts and accounts held in the names of fake businesses.
Networked structuring is where detection tends to fail. When deposits are spread across a set of individually unremarkable accounts, no single customer profile looks abnormal, and the pattern surfaces only once the accounts are treated as one funding structure. This is the same problem that defines mule account detection — the account is normal, the network is not.
Red flags that consistently carry investigative weight:
Why Threshold Rules Produce Weak Alerts

Most structuring detection still runs on static thresholds: aggregate a customer's currency activity over a rolling window, then alert when two or more sub-$10,000 deposits sum above it. That logic satisfies the baseline obligation and catches unsophisticated cases. It also produces some of the noisiest queues in transaction monitoring.
Proximity to a number is not evidence of intent. A rule firing on deposits between $8,000 and $9,999 flags the restaurant owner banking Saturday receipts alongside the courier moving cartel proceeds, and contains nothing that separates them. The $10,000 threshold has not been adjusted since the Bank Secrecy Act established it, so the share of ordinary commercial cash activity sitting near that line grows every year while the underlying risk does not. Alert volume rises; yield falls.
Rules also key on the wrong entity. Monitoring configured around a single customer identifier cannot see three cousins depositing into one business account, or one individual layering across a bank, a credit union, and a prepaid program. The behavior is coordinated; the detection is atomized.
The result is familiar to anyone who has worked a structuring queue: high volumes of alerts that look identical, most closing as no further action, with the genuinely designed patterns sitting inside that volume carrying no distinguishing signal at the alert level. Threshold rules are among the worst contributors to false positive rates in AML programs.
FinCEN's October 2025 guidance sharpened the point. In FAQs issued jointly with the Federal Reserve, FDIC, NCUA, and OCC, the agencies confirmed that multiple transactions by the same person at or near the $10,000 CTR threshold are not, on their own, sufficient information to require a SAR. Filing is required when the institution knows, suspects, or has reason to suspect the transactions were designed to evade reporting. That shifts the analytical burden from measuring distance to a number toward evidencing design.
CTR and SAR Are Two Different Tests
Confusing the two obligations is a common source of both over-filing and under-filing. The CTR is a mechanical report: any currency transaction, or set of transactions by or on behalf of one person, exceeding $10,000 in a single business day requires one, with no suspicion element and no discretion. Institutions may exempt qualifying Phase I and Phase II customers by filing a Designation of Exempt Person, subject to annual eligibility review. The SAR is a judgment report, triggered at $5,000 in aggregate when the institution knows, suspects, or has reason to suspect the activity is designed to evade a BSA requirement, involves potential money laundering, or has no apparent lawful purpose.
The interaction matters operationally. Telling a customer a CTR will be filed is permitted, and it often produces the clearest structuring evidence, because the customer's response — reducing the deposit, splitting it, walking out — is itself the intent signal. Disclosing that a SAR has been filed is prohibited. A narrative documenting that conversation and what the customer did next is stronger than one reciting deposit amounts, which is why SAR narrative quality carries so much of the law enforcement value. FinCEN reports that 88.6% of IRS-CI cases opened in FY2025 had one or more BSA filings associated with the primary subject.
Building Defensible Structuring Detection
Defensible structuring detection is detection that produces intent evidence, not threshold proximity. Four capabilities separate programs that withstand examination from those that generate volume.
Aggregate on Behavior, Not Only on the Number
Threshold aggregation is the floor, not the model. Programs that perform well add behavioral context to the rule output: how current cash activity compares to the customer's own baseline, whether deposit sizes cluster with unnatural consistency, whether activity changed immediately after a CTR was filed or discussed, and whether the cash reconciles with the business model. That context turns an alert into a filing decision.
Resolve the Network, Not the Account
Structuring is frequently a group activity, and account-level monitoring is structurally blind to it. Effective detection links common attributes — shared addresses, phone numbers, devices, beneficiary relationships, funding sources — and evaluates the cluster as one pattern. Internally, activity across deposit accounts, prepaid programs, and money services should aggregate to one customer view.
Document the Intent Question Explicitly
Following the October 2025 FAQs, the file needs to answer one question: what indicates these transactions were designed to evade reporting? An examiner reviewing a closed alert should see the analyst's reasoning, the evidence considered, and the basis for filing or not filing. Programs recording only a disposition code and a threshold breach have documented an outcome without documenting a decision.
Measure Outcomes, Not Alert Counts
Falling alert volume is not by itself an improvement, and rising volume is not by itself diligence. The measures that indicate a healthy structuring program are the proportion of alerts converting to filings, the time between activity and disposition, and whether filings produce law enforcement follow-up. Lean BSA teams at community banks and credit unions feel this most acutely, because a queue calibrated for volume consumes the same staff responsible for CTR filing and examination preparation.
Where Sphinx Fits
Sphinx operates at the investigation layer beneath structuring alerts. When a monitoring system flags sub-threshold currency activity, Sphinx's agents assemble the transaction history, compare it against the customer's baseline and stated business profile, check for related-party and network signals, and produce a documented recommendation with the reasoning attached. Every decision is logged, explainable, and subject to analyst override. For BSA teams working queues where most alerts resolve as ordinary cash behavior, that moves analyst time toward the cases where design is in question.
Frequently Asked Questions
Is structuring illegal if the money is legitimate?
Yes. Under 31 U.S.C. 5324, breaking up transactions to evade a reporting requirement is a federal offense regardless of the source of funds. No predicate crime is required. The offense is the evasion, not the money.
What is the difference between structuring and smurfing?
They describe the same conduct. Structuring is the statutory term used in 31 U.S.C. 5324, FinCEN regulations, and SAR narratives. Smurfing is the informal term, usually applied to structuring carried out by multiple individuals acting for a coordinator.
Does a bank have to file a SAR whenever deposits fall just under $10,000?
No. FinCEN and the federal banking agencies clarified in October 2025 that transactions at or near the $10,000 CTR threshold are not by themselves sufficient to require a SAR. A filing is required when the institution knows, suspects, or has reason to suspect the transactions were designed to evade reporting.
What dollar amounts count as structuring?
No amount defines structuring. FinCEN's definition covers currency transactions in any amount, at one or more institutions, on one or more days, conducted to evade CTR requirements. A series of $2,000 deposits can be structuring; a single $9,900 deposit with an innocent explanation is not.
Can structuring occur without cash?
The CTR-related offense is specific to currency transactions, but 31 U.S.C. 5324 also covers evasion of other BSA reporting and recordkeeping requirements, including geographic targeting orders and monetary instrument recordkeeping. Splitting activity across P2P platforms, prepaid programs, or virtual currency kiosks to stay under internal limits is reportable as suspicious activity even where the currency-specific definition does not apply.

.png)