AML transaction monitoring is the process fintechs use to detect suspicious activity in customer transactions. Here is how it works, what types of monitoring rules exist, and how to build an effective monitoring program.
What Is AML Transaction Monitoring? Types, Rules, and Best Practices
Transaction monitoring is the systematic process of reviewing customer transactions to detect patterns and behaviors that may indicate money laundering, fraud, or other financial crimes. It is a required element of every BSA/AML compliance program for Money Services Businesses and other covered financial institutions.
This article explains how transaction monitoring works, what types of monitoring rules exist, how alerts are managed, and what a best-in-class monitoring program looks like for a fintech.
How Transaction Monitoring Works
Transaction monitoring involves applying rules or models to customer transaction data — reviewing individual transactions and patterns of transactions against predefined criteria — and generating alerts when those criteria are met. Alerts are then reviewed by compliance analysts who determine whether the flagged activity warrants further investigation or SAR filing.
Transaction monitoring is not an automated SAR filing system. An alert is an input to an investigation, not a filing trigger in its own right. The human review step — evaluating the alert in the context of the specific customer's profile, transaction history, and all available information — is essential and cannot be eliminated through automation.
Types of Transaction Monitoring Rules
Threshold-Based Rules
The simplest monitoring rules flag transactions that exceed specific dollar thresholds. Examples include flagging any single transaction above $10,000 (the CTR reporting threshold), or flagging any customer whose monthly transaction volume exceeds a defined amount.
Threshold rules are easy to implement but generate high volumes of alerts that require manual review. They catch obvious outliers but miss sophisticated layering patterns that stay below thresholds.
Velocity Rules
Velocity rules flag transaction patterns over a defined time period — for example, a customer who conducts more than 20 transactions in a 7-day period, or whose aggregate weekly transaction volume doubles compared to the prior 30-day average. Velocity rules are particularly effective at detecting structuring and layering patterns.
Peer Group Rules
Peer group rules compare a customer's behavior to other customers with similar risk profiles or business types. A customer whose transaction velocity significantly exceeds that of similar customers triggers an alert even if the absolute volume does not cross a threshold. These rules are more sophisticated and require sufficient customer data to build meaningful peer groups.
Behavioral Rules
Behavioral rules look for patterns that deviate from a customer's own historical baseline — a sudden change in transaction volume, a shift to different transaction types or counterparties, or activity that is inconsistent with the customer's stated profile. These rules are highly effective but require enough historical data to establish a meaningful baseline.
Network Rules
Network rules look for connections between customers — multiple accounts transacting with the same counterparty, funds flowing rapidly between multiple accounts in a network, or accounts that appear to function as pass-throughs in a larger pattern. These rules are more complex to implement but detect patterns that individual account-level rules miss.
Calibrating Your Monitoring Rules
Poorly calibrated monitoring rules generate either too many alerts — which overwhelms analysts and leads to important alerts being missed — or too few — which means suspicious activity goes undetected. Calibration means setting rule thresholds that produce a manageable alert volume with a high proportion of true positive results.
Rule calibration should be reviewed periodically and updated when your business changes — new products, new customer segments, changes in transaction volumes — and when you observe alert patterns that suggest over- or under-alerting.
Alert Management Best Practices
All alerts must be reviewed within a defined SLA — typically within 30 days for standard alerts. Alert review must be documented — including what was reviewed, what the analyst concluded, and why the conclusion was reached. Alerts cleared without a SAR must have documented rationale. High-risk alerts may require senior compliance officer review. Alert trends should be analyzed periodically to identify patterns and inform rule calibration.
Frequently Asked Questions
Is transaction monitoring software required by law?
The BSA requires MSBs to have a transaction monitoring program — but does not mandate the use of specific software. Manual monitoring may be feasible for very early-stage businesses with limited transaction volumes. As transaction volumes grow, automated monitoring becomes essential to conduct monitoring at scale while maintaining documented, consistent review processes.
How do I know if my monitoring rules are calibrated correctly?
Indicators of poor calibration include alert volumes that are impractical for your team to review in a timely manner, very low SAR filing rates relative to alert volume (suggesting poor true-positive rates), repeated findings of similar suspicious activity that was not flagged by monitoring, and examiner findings of inadequate monitoring coverage. Rule calibration should be reviewed at least annually and after any significant business change.
How ComplyOne Helps
ComplyOne helps fintechs design and implement transaction monitoring programs — from rule library development and calibration through alert management workflows and SAR filing integration — through advisory services, compliance technology, or both.
Talk to the ComplyOne team to get started.
The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.