Regulated firms are facing growing pressure to look beyond individual chargebacks and refunds and consider what these activities reveal about wider financial crime risk.
RegTech provider ZIGRAM, which provides AML and financial crime technology to banks, FinTechs and payment processors, says these patterns should form part of broader AML monitoring rather than being treated solely as operational fraud losses.
The challenge is that fraud and AML teams often examine different parts of the same activity. Fraud teams may investigate individual disputes or suspicious refunds, while AML teams focus on unusual movements of money. When those functions operate separately, connections between seemingly unrelated events can be missed. A customer could make purchases across several merchants, request refunds through different channels, dispute transactions with their bank and move funds between payment instruments, with no single event necessarily triggering an AML investigation.
This is where fraud and AML convergence, commonly known as FRAML, becomes relevant. ZIGRAM argues that regulated organisations need to combine fraud indicators with transaction monitoring to build a clearer picture of customer behaviour and identify patterns that would otherwise remain fragmented.
The potential exposure is substantial. Return fraud cost retailers more than $101bn in 2023, while around 14% of returns were estimated to be fraudulent. Businesses lost an average of $13.70 for every $100 of returned merchandise. Separately, 34% of merchants globally identified friendly fraud as one of their leading e-commerce fraud threats in 2023.
For compliance teams, the key issue is determining when repeated refund or chargeback activity moves beyond ordinary fraud and becomes a potential financial crime concern. Indicators highlighted by ZIGRAM include high-frequency refunds from multiple merchants being directed towards the same account or prepaid card, refunds being sent to a different payment instrument from the original transaction without a clear explanation, and cross-border refunds involving higher-risk jurisdictions.
Other warning signs include refunded funds being rapidly transferred to crypto exchanges or third-party accounts, multiple customer profiles sharing devices or delivery addresses, account takeover indicators and attempts to manipulate customer service employees into processing refunds. Merchants with chargeback ratios significantly above comparable businesses may also require additional scrutiny.
Taken together, these behaviours can resemble the three stages traditionally associated with money laundering: placement, layering and integration. Fraudulent purchases can introduce illicit value, repeated refunds and transfers can obscure its movement, while resale of goods or conversion into other assets can help bring the proceeds back into the legitimate economy.
ZIGRAM points to a US case involving more than $111m in transactions in which sham companies manipulated chargeback rates to keep acquiring accounts open while fraudulent activity continued. The example demonstrates how payment fraud can extend beyond individual transactions and involve wider networks of entities and accounts.
Traditional AML transaction monitoring systems were largely developed around signals such as cash thresholds, structuring and cross-border transfers. ZIGRAM argues that these systems now need to incorporate signals generated by refund and chargeback activity. Its proposed approach combines consolidated transaction and refund data with behavioural baselines, velocity analysis and entity resolution.
The framework also involves creating rules that account for refund frequency, transaction values, cross-border activity and changes to payment instruments. Alerts can then be routed between fraud and AML teams depending on the level of risk, while investigation outcomes can feed back into detection models and rules.
Customer-level risk factors can provide another layer of context. PEP status, sanctions exposure, adverse media and previous fraud activity can be assessed alongside refund and chargeback behaviour to help determine whether a pattern requires further investigation.
ZIGRAM has developed several products around this broader financial crime approach. Transact Comply incorporates refund and chargeback activity into transaction monitoring, while Entity Hero maps relationships between customers, merchants and payment instruments. Dragnet Alpha adds adverse media intelligence, while PreScreening.io and DueDiliger support screening and enhanced due diligence before onboarding.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





