Raast Hawala Monitoring: The Money Looks Local. The Hawala Network May Not Be

A Raast transfer can be domestic while the economic deal behind it starts abroad. Pakistan’s AML challenge is to detect that hidden relationship.

FATF’s Oman case shows why Pakistani banks must detect cross-border relationships hidden inside ordinary domestic payments.

A Pakistani bank can receive a perfectly ordinary Raast transfer at 10:17 in the morning. Imagine Rs85,000 entering a personal account in Karachi. The beneficiary is known, the account is active, and the payment arrives through Pakistan’s national instant-payment system. Nothing in the payment message says Oman, hawaladar or informal remittance.

Yet the economic story behind the transfer may have begun in Muscat.

Raast hawala monitoring therefore cannot stop at the domestic payment message. FATF’s September 2026 report on underground banking and hawala describes an Oman case in which suspected operators offered expatriates cheaper remittance services and used payment channels in destination countries, including fee-free Raast transfers in Pakistan. SBP correctly responded that Raast itself does not process cross-border transfers and that FATF did not identify Raast as a money-laundering mechanism.

Both statements can be true. A domestic payment rail can remain technically sound while an informal network uses it for the local payout leg of a wider cross-border arrangement.

Raast Hawala Monitoring Cannot Depend on One Transaction

The first mistake would be to treat every unusual Raast payment as evidence of hawala. Raast has become too large and too ordinary for that approach.

SBP’s Q2 FY26 Payment Systems Review shows how quickly the system has expanded:

MeasureQ2 FY25Q2 FY26Change
Total Raast transactions295.7 million645.7 million+118%
Total valuePKR 6.36 trillionPKR 18.47 trillion+190%
P2P transactions293.7 million603.0 million+105%
P2P valuePKR 6.14 trillionPKR 15.69 trillion+156%
Percent changes calculated from SBP quarterly payment-system data.

At that scale, a crude rule based on transaction value will create noise. A salary account may suddenly receive money for a wedding. A small trader may collect payments from many customers. A family may move funds between relatives. None of those facts proves an informal remittance arrangement.

Banks need to ask a different question: does the behaviour fit what they know about the customer?

SBP’s AML/CFT/CPF rules already point in that direction. Regulated entities are expected to use automated transaction-monitoring systems and compare activity with customer profiles. Transactions that depart from the history or normal operation of an account require closer examination.

Raast adds speed and volume to an old monitoring problem. The answer should not be to make Raast slower.

The Account Pattern Matters More Than the Payment

A single domestic transfer often tells very little. A sequence can tell much more.

Compliance teams should pay attention when a personal account receives funds from many unrelated senders and quickly disperses them to other beneficiaries. Analysts often describe those patterns as fan-in and fan-out. Rapid pass-through matters too: money arrives and leaves so quickly that the account behaves more like a conduit than an account used for normal personal or business activity.

FMU’s own hawala typologies have repeatedly highlighted accounts with activity inconsistent with the customer’s profile, unrelated counterparties and rapid movement of funds. Older payment instruments produced those patterns before Raast existed. Instant payments can now compress the same behaviour into minutes.

No single indicator should trigger an accusation. A marketplace seller can show high fan-in. A payroll account can show fan-out. A charity can receive money from people who have no obvious relationship with one another.

Context decides whether the pattern deserves escalation. Banks need combinations of signals followed by human review.

KYC Must Become Behavioural, Not Merely Documentary

Know Your Customer often receives most attention when an account is opened. The customer provides an identity document, occupation, expected income and purpose of account. The file can look complete on day one and become stale months later.

Digital hawala makes ongoing profiling more important.

A stronger model would continuously compare actual account behaviour with the customer’s expected activity. A salaried person who suddenly begins receiving dozens of transfers from unrelated people deserves a different review from a retailer whose business naturally produces the same pattern.

Centralised KYC could help, but the phrase needs care. Pakistan should not create a giant pool of customer data that every institution can browse. Privacy and data-security rules must govern legal access.

A more defensible goal is consistent customer-risk information and stronger ecosystem-level analytics under clear regulatory authority. Banks still need responsibility for their own customers. SBP and FMU need enough visibility to identify patterns that cross institutional boundaries.

Better profiling should reduce false positives rather than multiply them.

From I. I. Chundrigar Road, the Gap Looks Familiar

Working around banking and SWIFT taught me to separate the message from the economic relationship behind it.

A SWIFT message can be technically valid while the underlying transaction still raises a compliance question. Nobody would conclude that SWIFT itself had failed simply because a suspicious payment used the network. Investigators would examine the parties and the economic purpose of the transaction.

Raast deserves the same distinction.

SBP’s September 4 clarification matters because some reporting blurred the line. Raast currently handles domestic payments. FATF did not say that Raast carried money from Oman into Pakistan.

The Oman case points to a different mechanism. A customer abroad can give value to a hawala operator. The network can create an obligation to pay a beneficiary in Pakistan. A counterpart in Pakistan can then use local funds to make the payout through Raast.

The Raast transaction remains domestic. The economic relationship does not.

Digitalisation therefore does not automatically eliminate hawala. It can give an informal network a cheaper domestic payout tool while the cross-border settlement happens somewhere else.

Banks Need Network Analysis, Not More Blanket Limits

Pakistan should resist the easiest response: lowering limits for everyone.

Blanket restrictions punish ordinary customers and weaken one of Raast’s main advantages. They can also push activity back toward cash, where monitoring becomes harder.

Banks should instead examine networks. An account that repeatedly receives funds from unrelated people may connect to another account showing the same behaviour. Several accounts may share devices or contact details where law and available data permit those links to be analysed. Recurring counterparties can reveal a pattern that no individual payment exposes.

FMU typologies already show the value of connected-account analysis. One published hawala case describes interlinked accounts with heavy turnover and unrelated counterparties. Another describes rapid movement of funds linked with people already suspected of illegal foreign-exchange activity.

Fraud monitoring and AML monitoring also need different questions. Fraud systems often ask whether the customer authorised a payment. AML systems ask whether an authorised payment makes economic sense in the customer’s broader activity. A transfer can pass authentication checks and still deserve AML review.

Graph analysis can help compliance teams find those relationships, but an algorithm should not become a verdict. Analysts still need evidence and customer context. Their reasoning should be documented before an STR is filed.

SBP Can See a Problem One Bank May Miss

One bank may see only one fragment.

Imagine an account at Bank A receiving money from several customers. Some funds move to Bank B. Another part reaches a wallet at a third institution. Each institution sees its own customer and its own transactions.

No bank necessarily sees the whole network.

SBP, Raast’s operator and FMU occupy different positions in the system. Their legal powers and responsibilities also differ. Pakistan should examine whether privacy-preserving, regulator-led analytics can identify cross-bank patterns without turning the payment system into an unrestricted customer-surveillance database.

The distinction matters. Central visibility should identify risk patterns and support lawful investigation. It should not erase institutional accountability or customer privacy.

A sensible model would allow regulators to identify suspicious network structures and then route intelligence to the institutions or authorities legally entitled to act on it.

Speed also matters. Instant payments can move through several accounts before a traditional case-review process begins. Monitoring has to become closer to the speed of the payment system without assuming that every fast transfer is suspicious.

The Missing Record May Sit Outside Pakistan

FATF’s Oman case exposes the hardest problem.

A Pakistani bank can see the domestic payout. It may know the account holder and counterparties in Pakistan. The bank may even detect rapid pass-through behaviour. Yet none of those records necessarily explains why someone in Oman handed money or value to an informal operator.

The missing information may sit with an Omani bank, an e-wallet provider or investigators who identified the suspected hawala network.

FMU already has a legal basis for cooperation with foreign financial-intelligence units. Its international-cooperation guidance explains that Section 6(4)(e) of the Anti-Money Laundering Act empowers FMU to exchange relevant information with counterpart financial-intelligence units through reciprocal arrangements.

That international connection is where Raast hawala monitoring becomes more than a software problem.

Pakistan can improve customer profiling while banks tune transaction-monitoring scenarios. Regulator-led analysis can also expose cross-bank patterns. Even together, those measures cannot reconstruct an offshore relationship that never appears in the domestic payment message.

The next test is whether Pakistan can connect a suspicious-looking domestic pattern with foreign intelligence quickly enough to understand what it means.

A payment in Karachi may look entirely local.

The record that explains it may be sitting in Muscat.


Related Reading: Pakistan Built Raast to Fight Cash. Hawala Found a Way In

This analysis was drafted under editorial direction with AI technical assistance, then verified and edited by Munaeem Jamal.

Your Pakistani Card Can Be Charged Without an OTP. Who Protects You When It Happens?

Can a Pakistani card be charged without an OTP? Learn how 3-D Secure works, why some international payments need no OTP, and how to reduce fraud risk.

I was scrolling through LinkedIn when a UBL advertisement stopped me.

“Don’t Let a Search Lead to a Scam,” it warned. UBL was telling customers not to trust telephone numbers found casually through an internet search. A fraudster can publish a fake number, answer the call and pretend to represent the bank.

Sensible advice.

But I looked at the advertisement and thought about something banks discuss far less often.

What happens when I protect my OTP and nobody asks me for one?

I have used Pakistani cards on international websites where the payment process felt reassuring. I entered my card details, received an OTP and completed the transaction. But international online payments do not always work that way. Sometimes there is no OTP.

That raises a question every Pakistani debit and credit card user should understand: if my bank approves an international online transaction without asking me to confirm it, what exactly protected that decision? And if the protection fails, who bears the loss?

What an OTP Actually Protects

First, we need to clear up one common misunderstanding.

When you shop online, a legitimate merchant normally asks for your card number and expiry date, together with the CVV or CVC printed on the card. It should not ask for the PIN you use at an ATM.

Never enter your ATM PIN on an ordinary shopping website.

An online purchase is generally a card-not-present transaction, often called CNP. You are not physically presenting your card to the merchant. This creates a different fraud risk from paying at a shop.

Many Pakistani consumers have therefore learned a simple security rule: No OTP, no payment. Unfortunately, it is not that simple.

An OTP is one way of confirming the cardholder’s identity. It is not the entire security system. The more important technology is 3-D Secure, or 3DS.

Visa calls its EMV 3-D Secure programme Visa Secure. Under 3DS, information can pass between the merchant and the bank that issued your card before authorization. The issuer then assesses whether the person attempting the purchase is likely to be the genuine cardholder.

Sometimes the bank challenges the customer. You may receive an OTP. The bank could instead use another approved authentication method.

Modern 3DS can also operate through a frictionless flow. The issuing bank assesses transaction data and authenticates a low-risk transaction in the background without requiring the customer to do anything.

No OTP does not automatically mean no 3-D Secure.

But a customer should not assume that every transaction completed without an OTP received the same level of protection.

Pakistan Already Has Rules for Online Card Security

I initially wondered whether the State Bank of Pakistan should simply require Pakistani banks to introduce 3-D Secure for international transactions. Then I checked the regulations. SBP has already acted.

In its 2018 security instructions for digital payments, SBP told banks and microfinance banks to enable the EMVCo 3-D Secure protocol to prevent fraud in online transactions. It required them to prepare implementation plans for all applicable card payments.

By February 2021, SBP said 15 banks had adopted 3-D Secure. It also allowed banks that had implemented the technology to activate customers’ cards for online e-commerce without requiring customers to request activation first.

Pakistan therefore does have a regulatory foundation for safer e-commerce. The problem is not simply, “Why hasn’t SBP introduced 3-D Secure?” It has.

The more useful consumer question is: What protection applies when an international card-not-present transaction reaches my Pakistani bank and I am not actively asked to authenticate it?

Why Some International Payments Don’t Ask for an OTP

Suppose I buy software from an overseas company. I enter my card number and expiry date, followed by the CVV. I click Pay. The payment succeeds. My phone never receives an OTP.

Was the transaction insecure? Not necessarily.

Visa explains that modern 3DS uses risk-based authentication. The issuer can evaluate information associated with the transaction and decide that the risk is low enough to authenticate it without further customer involvement. Visa calls this the frictionless flow. If the transaction appears riskier, the issuer can require a challenge such as an OTP or another authentication method.

This distinction matters because consumers see only the checkout screen. The bank sees much more.

Payment systems must also handle stored credentials and subsequent payments. Other payment arrangements can affect how authentication occurs. A customer therefore cannot look at the absence of an OTP and determine exactly what happened behind the scenes.

That is part of the consumer-protection problem.

Imagine Someone Gets Your Card Details

Consider Ahmed, a Pakistani credit-card customer. Ahmed sometimes uses his card for international software subscriptions. One day, criminals obtain his card number and expiry date, along with the CVV.

They do not have his ATM PIN. They do not control his banking app.

Now they attempt a $150 purchase at an overseas merchant.

When Ahmed is challenged

The merchant sends the payment through its payment infrastructure. Authentication takes place through 3DS, and Ahmed’s issuing bank decides that additional verification is required.

Ahmed receives a challenge. He did not initiate the transaction, so he does not approve it. The criminal possesses the card information but cannot complete the required authentication.

The security control has intervened before authorization.

When Ahmed receives no challenge

Now imagine another transaction. Depending on how the transaction has been submitted and authenticated, Ahmed may not receive an OTP or app challenge.

The authorization request eventually reaches Ahmed’s Pakistani issuing bank. The issuer’s systems assess the transaction and decide whether to approve or decline it. The bank approves it.

Ahmed’s first visible sign may be an SMS or app notification: USD 150 charged to your card.

At this point, the notification has not prevented fraud. It has told Ahmed that a transaction has occurred.

I would much rather have my bank stop a questionable $150 payment than send me an excellent SMS two seconds after approving it.

3-D Secure Versus a Transaction Without an Active Challenge

What happens3DS with customer challengeFrictionless 3DSNo active customer challenge
Customer enters card detailsYesYesUsually
Customer must actively authenticateYes, when challengedNoNo active challenge
Issuer can assess transaction riskYesYesAuthorization and fraud controls may still apply
Customer actively confirms purchaseYesNoNo
Customer may first notice through an alertLess likelyPossiblePossible
Main protectionActive authentication plus issuer controlsRisk-based authenticationDepends on transaction type and issuer/network controls

The better question is not merely, “Did you receive an OTP?” It is: How was this particular transaction authenticated and authorized?

Why I Would Not Make SMS OTP Mandatory for Every Transaction

My first instinct was straightforward. Why doesn’t SBP simply require an OTP for every international online transaction?

After examining how modern card authentication works, I think the regulatory question needs to be framed differently. OTP itself has weaknesses.

A fraudster can telephone a customer while pretending to represent the bank and ask him to read out a verification code. The customer complies. The security control has now become part of the social-engineering attack.

A banking-app approval can communicate far more useful information. It can show the amount and merchant, then ask the customer to approve or decline the purchase.

Modern 3DS also deliberately supports frictionless authentication for transactions that an issuer assesses as low risk. So I would not ask SBP to mandate SMS OTP for every international transaction. I would ask for something more useful.

Give Pakistani Customers Control Over International Card Exposure

SBP cannot tell every American or European website how to design its checkout page. It can regulate Pakistani banks.

Pakistani issuers should give cardholders clear control over international card-not-present exposure. Customers should be able to disable international e-commerce when they do not need it.

They should also be able to impose a separate, deliberately low online limit without reducing the entire credit limit on the card.

Most importantly, banks should explain what happens to international transactions that proceed without active customer authentication.

One regulatory option deserves serious examination: international CNP transactions that do not meet a prescribed authentication standard could be disabled by default, while customers who need broader international acceptance could explicitly enable them within defined limits.

That proposal would require careful technical work. Recurring payments and other legitimate payment arrangements cannot simply be treated as fraud.

The customer should know how much international online exposure his card carries.

Digital Security Cannot Assume Every Customer Understands 3DS

The UBL advertisement that started this article illustrates another problem. It tells customers to verify branch telephone numbers through UBL’s official website. That is sound advice.

But consider what the customer needs to know before he can follow it safely. He must distinguish an official bank website from an imitation. He may need to recognize a misleading search result. Then he must understand that the person answering a telephone number found online may not represent the bank.

Pakistan’s digital-payment system serves people with very different levels of digital literacy. A security model cannot assume that every cardholder understands the difference between an internet search result and an official bank page. Nor can it assume that everyone understands the difference between a CVV and an OTP.

The banking system therefore needs controls that protect people before education fails.

Warnings matter. System design matters more.

Before You Use Your Pakistani Card Online

  • Keep international e-commerce disabled when you do not need it, if your bank provides that control.
  • Set a deliberately low online or international transaction limit where your bank allows separate limits.
  • Prefer merchants using 3-D Secure or another recognized authentication mechanism.
  • Turn on immediate transaction notifications.
  • Never disclose an OTP or ATM PIN. Treat an unexpected authentication request as a warning.
  • Consider a virtual card with a controlled limit where your bank offers one.

Your total credit limit and the amount you expose to the internet do not need to be the same.

If You See a Transaction You Did Not Make

Speed matters.

Freeze or block the card immediately through your banking app if that facility exists. Otherwise, contact the bank using the telephone number printed on your card or published through the bank’s official channel.

Do not search casually for a customer-service number. That brings us straight back to UBL’s warning.

Report the transaction as unauthorized and obtain a complaint or dispute reference number.

Then ask a more specific question than “Why didn’t I receive an OTP?” Ask: “Was this transaction authenticated through 3-D Secure? If it was, what authentication method or transaction flow was recorded?”

Also ask whether the payment was processed as a recurring or merchant-initiated transaction, if relevant. Keep the transaction notification. Preserve your correspondence with the bank and record when you reported the fraud.

An Unauthorized Transaction Does Not Automatically Mean an Automatic Refund

An unauthorized transaction does not automatically produce a refund. The circumstances matter.

The bank will examine whether the customer authorized the transaction. Authentication records may matter, as can the circumstances surrounding the payment. Applicable card-network procedures and the bank’s dispute process can also affect what happens next.

Pakistani law nevertheless contains an important consumer safeguard.

Section 41 of the Payment Systems and Electronic Fund Transfers Act, 2007 places the burden of proof on the financial institution or authorized party in an action involving consumer liability for an unauthorized electronic fund transfer. The institution must show that the transfer was authorized or establish the statutory conditions relevant to liability.

That does not mean every disputed card transaction must automatically be refunded. It does mean consumers should not assume that a debit appearing on their statement ends the argument.

Dispute it. Ask how it was authenticated. Ask why it was approved. And keep the evidence.

Prevention, Detection and Reimbursement Are Not the Same Thing

Banks often present digital security as one package. From the consumer’s side, it looks very different.

Prevention tries to stop the fraudulent transaction before the money moves.

Detection identifies suspicious activity or tells the customer what has happened.

Then comes another question: who bears responsibility for the disputed transaction? Only after that do we reach reimbursement, when the customer discovers whether and when the money will actually return.

An SMS alert can provide excellent detection while providing no prevention at all. That distinction should appear in every serious consumer guide to digital banking.

The Question Pakistani Banks Need to Answer

The UBL advertisement is the starting point of this article, not its target. The underlying issue affects the wider banking and card-payment ecosystem.

UBL is right to tell customers to verify telephone numbers. Banks are right to tell us never to disclose our OTPs. Customers also have responsibilities. We need to protect our credentials and report suspicious transactions quickly.

But digital security cannot depend mainly on the assumption that every customer will recognize every scam.

SBP has already required important card-security measures. Pakistan’s banks use 3-D Secure, fraud-monitoring systems and other controls. Consumers now need greater visibility into what happens when those systems make decisions for us.

The next time my phone receives an OTP, I know what to do. I read it. I check the transaction. If it is not mine, I approve nothing.

The transaction that worries me is the one for which my phone never asks.

If my Pakistani bank can approve an international online payment without asking me to confirm it, I want to know what protected that decision. And if that protection fails, I want to know who bears the loss.

Those are questions a digital-payment system should answer before fraud occurs, not after the customer starts filling out a dispute form.