What is a False Positive?
A false positive is an alert that flags legitimate activity or a legitimate customer as potentially suspicious when no financial crime is taking place.
False positives are the most common outcome of AML monitoring and screening. In transaction monitoring, false positives often make up 95 to 99 percent of alerts across the industry. In sanctions screening, a false positive usually happens when a customer's name partially matches a sanctioned party but belongs to a different person.
False positives are not errors to be eliminated entirely. Some level of false positives is the price of catching real risk, since a system tuned to produce almost no false alerts would likely miss genuine suspicious activity. The goal is to keep false positives low enough that investigators can focus on cases that matter.
Why are false positives a problem?
False positives drain compliance resources and can hide real risk. Every false alert takes analyst time to review and document, and large volumes create backlogs that delay the investigation of genuine cases. False positives can also frustrate legitimate customers when payments are held or extra questions are asked without good reason.
What causes false positives?
False positives usually come from rules or matching logic that are too broad. Common causes include the following.
- Thresholds set too low for the customer's normal activity
- Rules that ignore customer risk levels
- Recurring legitimate payments, such as payroll, triggering alerts
- Common names that partially match sanctions lists
- Poor data quality, such as missing dates of birth or nationalities
How do firms reduce false positives?
Firms reduce false positives in transaction monitoring by tuning rules against real data and adding context. Back-testing rules on historical transactions shows how many alerts they would generate. Risk-weighted thresholds, contextual filters that exclude recurring payments, and comparisons against each customer's normal behavior all help separate unusual activity from suspicious activity.
Firms reduce false positives in sanctions screening by using layered matching logic. Exact matches on name plus date of birth or ID number come first, followed by fuzzy matching checked against additional details like nationality and location. Known legitimate customers can be whitelisted, with a documented reason and periodic review.
Every false positive should be documented with a clear rationale, such as a different date of birth. Over time, the reasons alerts are cleared become valuable feedback for refining rules and removing logic that adds work without catching risk.