FATF’s Oman case shows why Pakistani banks must detect cross-border relationships hidden inside ordinary domestic payments.
![]() |
| Pakistani banks need to look beyond individual Raast transfers and identify transaction patterns that may connect domestic payments with hidden cross-border hawala activity. |
Consider a simple monitoring scenario. At 10:17 a.m., a Pakistani account receives Rs85,000 through Raast. Nothing in the payment message says Oman. Nothing identifies a hawaladar. Raast Hawala Monitoring begins with that information gap because the transaction that gave the credit its economic meaning may have occurred hundreds of kilometres away.
FATF’s September 2026 report makes the problem concrete. In an Oman case, investigators uncovered a suspected unlicensed remittance operation serving Pakistan. The network used cheaper payment channels at the destination end, including fee-free transfers through Raast. FATF did not accuse Raast of a security failure.
SBP made the same distinction in its 4 September clarification. The central bank rejected claims that FATF had identified Raast as a money-laundering mechanism. SBP also acknowledged the wider FATF concern: underground banking networks can misuse legitimate formal payment channels.
For Pakistani banks, the argument should now move beyond whether Raast itself failed. It did not. The harder question is whether a bank can recognize a domestic payment that forms one leg of a hidden cross-border financial arrangement.
Raast Hawala Monitoring Cannot Depend on One Transaction
Pakistan built Raast for speed and low-cost digital payments. The system has succeeded on both measures. SBP recorded 645.7 million Raast transactions worth Rs18.469 trillion during Q2 FY26, compared with 295.7 million transactions worth Rs6.364 trillion a year earlier.
P2P activity drove most of that expansion.
Scale changes the compliance problem. A suspicious transfer now sits inside hundreds of millions of legitimate payments. A crude rule based mainly on transaction value will create noise while missing accounts that move smaller amounts through unusual patterns.
A Rs700,000 transfer from an established business may fit its normal activity. Repeated Rs40,000 credits from unrelated people into a low-turnover personal account may deserve much closer examination. Context matters more than an arbitrary number.
SBP already requires regulated institutions to monitor transactions against customer risk and expected behaviour. Banks therefore do not need an entirely new AML philosophy for Raast. They need better scenarios tuned to how informal settlement networks use instant payments.
The Account Pattern Matters More Than the Payment
A single Raast transaction rarely proves much.
Banks should instead examine how money behaves before and after the transfer. One useful pattern involves an account receiving credits from many unrelated customers before sending most of the funds onward within a short period. Another involves one account repeatedly distributing payments to beneficiaries who have no obvious relationship with the account holder.
Compliance teams often describe those behaviours as high fan-in or high fan-out activity. Neither pattern proves hawala. Combined with a customer-profile mismatch or rapid movement of funds, however, the pattern can justify investigation.
I would pay particular attention to accounts behaving like informal settlement businesses while claiming a completely different economic purpose. A salaried customer may suddenly process turnover far beyond normal income. A small shop account may begin receiving transfers from distant individuals who appear unrelated to its business.
The question becomes simple:
Does the account behave like the customer described during onboarding?
Banks can then examine the source of funds and the stated purpose of unusual activity. Historical behaviour provides another reference point. A quiet account that suddenly becomes a high-throughput payment node deserves more attention than a merchant whose established business already produces frequent Raast receipts.
False positives remain a serious risk.
A marketplace seller can legitimately receive payments from many people. Families may move funds quickly between accounts. Small businesses can show patterns that resemble collection activity during busy periods.
Better monitoring cannot mean treating high-volume digital activity as suspicious by default. The task is discrimination, not friction. A weak monitoring model misses illicit activity. An aggressive model can punish the digital customers Raast exists to serve.
From I. I. Chundrigar Road, I See a Familiar Limitation
At my desk on I. I. Chundrigar Road, payment messages often reduce complicated economic relationships to structured fields on a screen. A technically valid message tells the bank how value should move. It does not automatically explain the commercial relationship that caused someone to send the payment.
Years around SWIFT messaging have made that distinction familiar to me. A suspicious transaction can travel through a technically sound messaging network without showing that criminals compromised the network. Compliance staff still need to examine the customer relationship and the economic purpose.
Raast faces a similar boundary.
A Pakistani bank may see one account paying another through a domestic instant-payment rail. The bank may authenticate the customer correctly. Every technical control can work as intended.
A hawala arrangement can still sit behind the transfer.
FATF’s Oman case demonstrates why. Someone abroad can deal with an informal remitter while a Pakistani counterpart handles the domestic payout. The Raast message does not need to contain any reference to Oman because Raast never carried the cross-border leg.
Digital hawala therefore creates a visibility problem rather than necessarily a payment-security problem.
FATF reports that nearly 70 percent of responding jurisdictions see growing use of technology in hawala activity. Digital tools can make customer payments faster even when operators settle their own obligations outside the payment platform.
Pakistan should read the Raast case as part of that wider change, not as an isolated controversy.
Banks Need Network Analysis, Not More Blanket Limits
Traditional transaction monitoring often treats each customer as a separate risk object. Digital settlement networks can make that approach too narrow.
Suppose one account receives Raast payments from several people. It then pays another small cluster of accounts. Those accounts later make further distributions.
Individual alerts may look unrelated.
A relationship map can reveal something different.
Banks should therefore use network analytics to identify recurring counterparty clusters and unusual movement between connected accounts. The objective is not to label every network suspicious. Analysts need to determine whether the relationships fit the customer’s known economic activity.
Device and account information can add useful context when the law permits banks to use it. Several supposedly unrelated customers may share unusual operational links. A common contact detail can also support deeper review when transaction behaviour already raises concern.
Pakistan’s Financial Monitoring Unit has encountered related problems before.
In one published FMU case, four overseas remitters sent about 1,300 transactions to more than 500 beneficiaries in Pakistan. Analysts identified common beneficiaries and then sought information from a foreign financial intelligence unit. The case shows why domestic transaction data sometimes becomes meaningful only after investigators connect it with information from abroad.
Raast makes that problem faster.
SBP Can See a Problem That One Bank May Miss
A commercial bank sees the transactions booked through its own customer relationships. Another bank may hold the next account in the chain.
Consider a simplified sequence.
An HBL customer pays an MCB customer through Raast. The MCB account later sends money to a Bank Alfalah customer. Each institution can monitor its own customer relationship, but no single bank necessarily sees the full pattern.
Network-level oversight could reveal connections that participant-level monitoring misses.
SBP should therefore examine whether it can support ecosystem-level financial-crime analytics across Raast. Any model would need clear legal authority and strong privacy safeguards. Centralized surveillance without proper governance would create a different institutional risk.
The objective should remain narrow: identify unusual network structures and return actionable intelligence to regulated institutions for investigation.
FMU should form the second side of that architecture.
Banks file suspicious transaction reports when the evidence reaches the required threshold. FMU can then compare reports and seek information from foreign counterparts. The Oman case shows why that international connection matters.
A Karachi bank may hold the domestic payment. Investigators in Muscat may hold the conversation that explains it.
Neither side necessarily has enough information alone.
Do Not Confuse Fraud Detection With Hawala Detection
Raast already operates inside strong cyber and fraud controls. Banks authenticate customers and monitor abnormal activity. Security teams look for compromised credentials or unauthorized access.
AML teams ask a different question.
A fraud analyst wants to know whether the person making the payment had authority to make it. A financial-crime analyst asks whether the transaction itself makes economic sense.
A perfectly authenticated payment can still support hawala.
The difference matters because stronger passwords will not solve the FATF problem. Neither will another OTP if the genuine account holder knowingly participates in an informal settlement network.
Banks need to combine Raast activity with the wider customer relationship instead. Cash movements may change the interpretation of a digital pattern. Foreign-remittance history may provide another clue.
Raast monitoring should therefore feed into the bank’s broader transaction-monitoring system rather than operate as an isolated compliance silo.
The Missing Record May Sit Outside Pakistan
I would resist any response that simply makes Raast slower or more expensive.
Pakistan spent years trying to move transactions away from cash. Blanket limits could push legitimate users back toward informal channels while sophisticated hawala operators adapt again. FATF’s case argues for better intelligence, not less useful payment infrastructure.
The hardest control problem remains outside the domestic payment message.
A bank in Karachi may see a perfectly authenticated Raast payment. Investigators in Muscat may hold the WhatsApp conversation that explains why it happened. Neither institution necessarily sees enough when the money moves.
One record sits inside Pakistan’s formal financial system. Another may sit abroad, attached to an informal remittance relationship.
By the time investigators connect them, the next payout account may already look different.
Related Reading
I examined the FATF case behind this discussion in my earlier article, where I explained how a secure domestic payment rail can still become part of a wider hawala arrangement without Raast itself failing.
Read: Raast and Digital Hawala: How Hawala Uses Formal Rails


Comments
Post a Comment
Please keep discussions respectful and on-topic