What is Anomaly Detection?

Anomaly detection is a monitoring technique that flags activity that differs significantly from an established pattern of normal behavior.

Anomaly detection compares each transaction or customer against a baseline. That baseline can be the customer's own history or the typical behavior of similar customers. When activity breaks sharply from that norm, such as a customer suddenly sending ten times their usual wire volume, the system flags it for review.

Anomaly detection helps find risks that no one has written a rule for. Because it looks for anything unusual rather than a specific known pattern, it can surface new laundering methods and emerging typologies early. That makes it a useful complement to rules in transaction monitoring.

How does anomaly detection work?

Anomaly detection typically relies on unsupervised machine learning, which does not need labeled examples of past suspicious cases. The model learns what normal looks like from raw behavior and flags outliers. Common techniques include isolation forests, one-class support vector machines, and autoencoders.

Anomaly detection models usually look at signals such as the following.

  • Spikes in transaction frequency or amount compared with the customer's baseline
  • Sudden growth in the number of counterparties
  • First-time payees, corridors, or devices
  • Activity at unusual times of day

What is the difference between anomaly detection and rules-based monitoring?

Rules-based monitoring flags activity that matches predefined criteria, while anomaly detection flags activity that departs from normal behavior. A rule might flag every cash deposit over $10,000. Anomaly detection would instead flag a $4,000 deposit from a customer who normally deposits $200, because it is unusual for that customer.

Rules are easy to explain but can be gamed by criminals who calibrate activity just under known thresholds. Anomaly detection is harder to evade because there is no fixed line to stay under. Most firms combine the two, using rules for known risks and anomaly detection as a safety net.

What are the limits of anomaly detection?

Anomaly detection tends to produce more false positives than targeted rules. Unusual activity is not always suspicious, since a customer might be buying a house or receiving an inheritance. Models need human curation, clear guardrails, and regular tuning to stay useful.

Anomaly detection works best as a secondary trigger or exploration tool. Many firms use it to raise the priority of existing alerts or to seed queues that experienced analysts review, rather than sending every anomaly straight to investigation.