Building a transaction monitoring program from scratch requires the right technology, calibrated rules, and operational workflows. Here is a step-by-step guide for fintechs building their first monitoring program.
How to Build a Transaction Monitoring Program from Scratch
Transaction monitoring is a required element of every BSA/AML compliance program — and one of the most technically complex to build correctly. Many fintechs configure monitoring technology at launch using default settings and never revisit it, creating a program that generates too many false positives to manage or too few alerts to catch real suspicious activity.
Building a program correctly from the beginning is significantly more effective than retrofitting a poorly configured one. This guide covers the process step by step.
Step 1 — Start With Your AML Risk Assessment
Before configuring a single monitoring rule, complete your AML risk assessment. Your risk assessment defines what risks your specific business creates — based on your products, customers, geographies, and delivery channels. Your monitoring rules should be designed specifically to detect the suspicious patterns most relevant to those identified risks.
Building monitoring rules before completing a risk assessment is a common mistake that produces a program calibrated for a generic business rather than your specific one.
Step 2 — Select Your Technology
Evaluate transaction monitoring platforms based on rule customizability, audit trail completeness, alert management workflow, integration with your transaction infrastructure, and false positive management capability.
Most early-stage fintechs use purpose-built compliance platforms with transaction monitoring included rather than building proprietary monitoring systems. The key is ensuring the platform can be configured for your specific risk profile — not just that it provides monitoring capability. See our guide on BSA compliance software for evaluation criteria.
Step 3 — Design Your Rule Library
Based on your risk assessment, design the specific rules your program will use. Your rule library should address the key risk scenarios identified in your assessment.
For most fintechs, a baseline rule library includes threshold rules detecting structuring patterns near the $10,000 CTR threshold, velocity rules detecting unusually high transaction frequency, pattern rules detecting rapid round-trip fund movement, geographic rules flagging transactions involving high-risk jurisdictions, and behavioral rules detecting activity inconsistent with each customer's established profile.
Document the rationale for every rule you create — why this rule, why this threshold, and what specific risk scenario it is designed to detect. This documentation is what you produce when examiners ask about your monitoring program design.
Step 4 — Calibrate Rule Thresholds
The most important configuration decision for each rule is the threshold — the point at which the rule generates an alert. Thresholds set too low generate excessive false positives. Thresholds set too high miss genuine suspicious activity.
Calibration is an empirical process. Start with reasonable initial thresholds based on your expected transaction profile, run the rules for 30 to 60 days, and analyze the alert output. If false positive rates are very high — if most alerts are clearly explainable upon review — consider tightening thresholds. If alert volumes are very low relative to transaction volumes, consider whether thresholds may be missing legitimate red flags.
Step 5 — Build Your Alert Review Workflow
Define who reviews alerts, in what priority order, within what timeframe, with what documentation required for each disposition.
Alert review SLAs — the maximum time from alert generation to disposition — must be defined and enforced. Most compliance programs target 5 to 10 business days for standard alerts, faster for high-risk flagged alerts.
Document the disposition of every alert — whether cleared with specific reasoning, escalated to investigation, or filed as a SAR. Undocumented alert dispositions are an examination finding.
Step 6 — Connect to SAR Filing
The pathway from monitoring alert to SAR filing must be clear, documented, and followed consistently. When an investigation concludes that activity is suspicious and meets the filing threshold, the SAR must be filed within 30 days of initial detection. Document the connection between each SAR filing and the monitoring alert that triggered the investigation.
Step 7 — Establish a Tuning Process
Monitoring rules need ongoing maintenance. Schedule quarterly rule reviews to assess alert volumes, false positive rates, and whether rules are producing actionable alerts. Update rules when your customer base, products, or geographies change. Document all rule changes with the rationale for each change.
Frequently Asked Questions
How many monitoring rules does a new fintech need?
There is no minimum number. Start with rules that specifically address the key risks identified in your AML program — typically 5 to 10 well-designed rules for an early-stage fintech with a simple product. More rules are not better if they generate unmanageable false positive volumes.
How ComplyOne Helps
ComplyOne helps fintechs design, implement, calibrate, and maintain transaction monitoring programs — through compliance technology, advisory services, or both.
Talk to the ComplyOne team to get started.
The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.