What is a False Negative?
A false negative is suspicious activity that a monitoring or screening system fails to flag.
A false negative is the opposite of a false positive. Instead of raising an unnecessary alert, the system stays silent when it should have spoken up. The transaction goes through, the customer remains unreviewed, and the risk is only discovered later, if at all.
False negatives are harder to see than false positives. A false positive shows up in the alert queue, but a false negative leaves no trace in the system that missed it. Firms usually learn about false negatives through later investigations, law enforcement requests, audits, or regulatory exams.
Why are false negatives dangerous?
False negatives let real financial crime pass through undetected. Missed suspicious activity means missed suspicious activity reports, which can expose a firm to regulatory penalties and reputational damage. They also allow criminals to keep using the firm's services, often at larger scale.
False negatives and false positives pull in opposite directions. Raising thresholds or narrowing rules cuts false positives but can increase false negatives. Many firms handle this trade-off by weighing the cost of a missed suspicious case against the cost of reviewing an extra alert, then setting thresholds that minimize total cost within their team's capacity.
What causes false negatives?
False negatives usually come from gaps in detection logic or data. Common causes include the following.
- Criminals calibrating activity to stay just under known thresholds
- New laundering methods that no rule has been written for
- Models trained only on past cases, which can miss new typologies
- Poor data quality or outdated sanctions lists
- Name variations and transliterations that matching logic does not recognize
How do firms measure and reduce false negatives?
Firms measure false negatives by testing whether their systems would have caught known cases. Back-testing checks what percentage of past suspicious activity reports a rule or model would have flagged. After deployment, many firms track missed suspicious activity reports as a key risk indicator.
Firms reduce false negatives by layering detection methods. Behavioral baselines, anomaly detection, and network analysis catch activity that fixed rules miss, while regular threshold reviews and alias tables for common name variations close known gaps. Stress tests for events like product launches, seasonal spikes, and sanctions changes help reveal weak spots before criminals find them.