Skip to content
Banca d'Italia · Italy

UIF anomaly indicators — the 2023 framework

Fintech Passport
July 13, 2026 · 8-min read
UIF anomaly indicators — the 2023 framework

Italy’s anomaly indicators are the operational vocabulary of suspicious-transaction detection — and since 1 January 2024 there is exactly one authoritative set. The UIF’s Provvedimento of 12 May 2023 consolidated everything that came before — the banking-era indicator lists, the sector lists and the standalone anomaly schemes — into a single framework: 34 indicators, articulated into roughly 400 sub-indices, organised in three sections. Every obliged entity operating in Italy is expected to select the indicators relevant to its business, wire them into its monitoring, and document why the rest were left out. This is the deep-dive: what each section contains, worked examples for a payments firm, and how to turn a legal list into a working monitoring programme.

The Unità di Informazione Finanziaria (UIF) — Italy’s financial intelligence unit, established at Banca d’Italia but operationally independent — issues anomaly indicators under Decreto Legislativo 231/2007, which empowers the UIF to develop and publish indicators to help obliged entities detect operations potentially connected to money laundering or terrorist financing.

The current set is the Provvedimento of 12 May 2023, published in the Gazzetta Ufficiale on 25 May 2023 and in force since 1 January 2024. It applies to all obliged entities under D.Lgs 231/2007 — banks, EMIs, payment institutions, CASPs, trust companies, professionals — each selecting the subset relevant to its activity.

2. The 2023 consolidation — what actually changed

Before 2024, an Italian compliance team juggled several generations of material: indicator decrees issued through Banca d’Italia and the ministries between roughly 2009 and 2013, sector-specific lists for professionals, and a long series of standalone UIF schemi di comportamento anomalo (behaviour schemes) covering individual typologies. The 2023 Provvedimento replaced that patchwork:

  • One document — 34 indicators with ~400 exemplifying sub-indices
  • One structure — three sections (subject, operations, terrorism/proliferation financing)
  • One rule of application — each entity selects by relevance to its concrete activity

3. The three sections, with concrete examples

Section A — the subject (indicators 1–8)

Red flags in who the customer is and how they behave in the relationship, independent of any single transaction:

  • Reluctance or inability to provide accounting or fiscal documentation, or current beneficial-ownership information
  • Documentation that appears altered, or paints an economic and patrimonial picture inconsistent with other evidence
  • Customers who are politically exposed persons, or hold senior positions in public bodies, where the operativity does not match the declared profile
  • Connections to high-risk jurisdictions or opaque offshore structures without a plausible economic rationale
  • Operativity that is simply incoherent with the customer’s declared activity and income — the classic profile-mismatch trigger

Section B — the operations (indicators 9–32)

The largest section, covering how transactions look. The sub-indices reach deep into modern payments territory:

  • Cash — structured deposits, cash inconsistent with the business, deposits to accounts of persons in insolvency procedures
  • Accounts and flows — rapid in-and-out patterns, accounts used as mere transit vehicles, disproportionate rent or service payments
  • Tax and public funds — anomalous tax reimbursements, misuse of public-support schemes, trafficking in tax credits (carrying forward the guidance developed during 2020–2022)
  • Fintech-native patterns — crowdfunding and peer-to-peer lending flows, e-commerce marketplaces, payment platforms and cashback systems used to disguise value transfer
  • Virtual assets — conversions between crypto-assets and fiat where the origin of funds is opaque, patterns typical of layering through exchanges
  • Trusts and fiduciary structures — sub-indices dedicated to trustee operativity
  • High-value goods — art, precious metals and similar value stores

Section C — terrorism and proliferation financing (indicators 33–34)

A dedicated section, including sub-indices on payment-card usage patterns, person-to-person transfers with doubtful elements, and commercial operations with counterparties whose economic substance is questionable — including the dual-use trade dimension relevant to proliferation financing.

4. The selection duty — and the documentation trap

The indicator set is deliberately broad; no entity applies all 400 sub-indices. The rule is select by concrete activity: a payments institution selects the account-flow, e-commerce, card and virtual-asset families; a trust company selects the fiduciary families; a professional selects the advisory families.

Two failure modes are equally dangerous:

  • Uncritical application of everything — floods the monitoring stack with false positives and buries genuine suspicion in noise.
  • Silent deselection — dropping indicator families without a documented rationale. In an inspection, an unexplained gap between the indicator set and your monitoring rules reads as a missed-SOS risk.

The clean pattern: a mapping document that lists every indicator, states applicable / not applicable with one line of reasoning, and links each applicable sub-index to the monitoring rule (or manual control) that implements it.

5. Three worked examples for a payments firm

Example 1 — the transit account (mule pattern)

Facts: a consumer account opened three months ago with declared employment income of ~€1,500/month receives four incoming SEPA transfers totalling €9,200 over two days from unrelated corporate counterparties, each followed within hours by outbound transfers to two foreign IBANs, leaving a near-zero balance.

Indicator reading: Section A profile-mismatch (operativity incoherent with declared income) plus Section B transit-account sub-indices (rapid in-and-out, no economic rationale for the flows). Two independent families firing on one account is a strong composite signal.

Analyst path: check onboarding data freshness, request purpose evidence if the relationship justifies contact without tipping off, review linked devices/IPs against other accounts. Outcome here is typically an SOS — and where third-party use of the account is confirmed, the mule-specific handling applies alongside.

Example 2 — the cashback merchant

Facts: a small e-commerce merchant runs a cashback programme; monitoring shows a cluster of customer accounts making frequent purchases that are refunded at 90–100% within days, with the cashback flows concentrating into three beneficiary accounts.

Indicator reading: Section B e-commerce and payment-platform sub-indices — marketplaces, platforms and cashback systems used to move value rather than to buy goods. The purchase-refund-cashback loop is a value-transfer disguise pattern named in the indicator families.

Analyst path: establish whether goods actually ship (delivery data), whether the “customers” are connected (shared attributes), and whether the merchant’s turnover profile matches its declared business. A confirmed loop with concentration of benefit is SOS territory; the merchant relationship also gets a due-diligence refresh.

Example 3 — the opaque crypto off-ramp

Facts: a customer receives recurring crypto-to-fiat conversion proceeds from an exchange into their payment account — amounts stepping up monthly, now materially above declared income, with the customer unable to evidence the origin of the crypto when asked in a periodic review.

Indicator reading: Section B virtual-asset sub-indices — fiat conversions where the origin of the underlying crypto is opaque — combined with the Section A documentation-reluctance indicator.

Analyst path: request source-of-funds evidence (acquisition records, wallet history where the customer can provide it), check whether the counterparty exchange applies the Travel Rule data on transfers, and assess coherence with the profile. Undocumented, escalating conversion income is a recurring SOS fact-pattern.

6. Wiring indicators into a monitoring programme

  1. Map — every applicable sub-index to a detection rule, a periodic review control, or an onboarding control. One line each; keep the not-applicable rationale in the same document.
  2. Calibrate — thresholds tuned to your customer base, reviewed on a defined cycle. Uncalibrated indicator rules are the main source of alert fatigue.
  3. Compose — the strongest signals are composites (profile mismatch + flow pattern), as in the worked examples. Build rule logic that scores across families rather than firing on single hits.
  4. Document the judgement — the indicator framework is explicitly non-exhaustive and non-binding: a hit does not force an SOS and the absence of hits does not excuse one. The analyst’s holistic assessment, recorded, is the defensible artefact.
  5. Close the loop — SOS outcomes and UIF feedback flow back into rule calibration; the AUA archive gives you the structured history to do it.

The indicators feed the suspicion assessment; the filing itself runs through the Infostat-UIF portal — see our step-by-step SOS filing guide. The two documents to keep aligned: your indicator-mapping document (what you look for) and your SOS procedure (what happens when you find it). Inspections read them together.

8. FAQ

Are the old UIF anomaly schemes still valid?

No. From 1 January 2024 the previous indicator sets and the standalone anomaly schemes ceased to apply. The Provvedimento of 12 May 2023 is the single authoritative framework; monitoring documentation should cite it, not the repealed schemes.

Do I have to implement all 400 sub-indices?

No. You select the indicators relevant to your concrete activity and document the rationale for the rest. Both indiscriminate application and silent deselection are inspection findings.

Does one indicator hit oblige an SOS?

No. The lists are explicitly neither exhaustive nor binding — a hit informs the holistic assessment, it does not replace it. Conversely, genuine suspicion must be reported even when no codified indicator matches.

Where do the indicators come from legally?

D.Lgs 231/2007 empowers the UIF to issue them; the current set is the UIF Provvedimento of 12 May 2023, published in the Gazzetta Ufficiale on 25 May 2023, in force since 1 January 2024.

Do the indicators apply to foreign PSPs passporting into Italy?

Yes, for Italian-attributable activity — the indicator framework travels with the D.Lgs 231/2007 obligations. See our Italian AML framework overview.

How do the indicators relate to transaction-monitoring software rules?

The indicators are the regulatory taxonomy; your rules are the implementation. The mapping document connecting each applicable sub-index to a rule or control is what demonstrates coverage — to yourself and to the inspector.

9. What to do, today

  • Check what your monitoring documentation cites: anything anchored to pre-2024 schemes needs re-anchoring to the 2023 Provvedimento.
  • Build (or refresh) the indicator-mapping document: applicable / not-applicable per indicator, one-line rationale, rule linkage.
  • Prioritise the composite patterns from the worked examples — profile-mismatch plus flow anomaly catches more real cases than any single rule.
  • Align the mapping document with your SOS procedure and your AUA data so the three tell one story at inspection.

Related: How to file an SOS in Italy · UIF and the Archivio Unico Antiriciclaggio · The Italian AML framework beyond UIF · Money muling & tech-enabled fraud (UIF 2026) · Money mule typologies · The supervisory fraud taxonomy

Related reads.