What is Rules-Based Monitoring?
Rules-based monitoring is a transaction monitoring approach that flags activity when it meets predefined criteria, such as a set amount, frequency, or pattern.
Rules-based monitoring turns known money laundering risks into clear if-then logic. A compliance team decides what suspicious activity looks like, writes it as a rule, and the monitoring system generates an alert whenever a transaction or group of transactions matches. Because every rule is written in plain terms, analysts and regulators can see exactly why an alert fired.
Rules-based monitoring is the traditional foundation of transaction monitoring. Most AML programs still rely on rules for core risks and add behavior-based models on top.
What are the main types of monitoring rules?
Rules-based monitoring typically uses three types of rules.
- Threshold rules, which flag transactions above a set amount, such as any cash deposit over $10,000
- Velocity rules, which flag rapid activity, such as more than five wire transfers in 24 hours
- Pattern rules, which flag known suspicious sequences, such as structured deposits just under a reporting limit or several accounts receiving funds from the same source within a short time
Rules-based monitoring can also be risk-weighted. The same rule can apply lower thresholds to high-risk customers and higher thresholds to low-risk customers. For example, a firm might flag cash deposits over $2,000 for high-risk customers, over $5,000 for standard customers, and only over $10,000 for low-risk customers.
How are monitoring rules built and tuned?
Monitoring rules are built through an iterative process. A team first identifies a red flag scenario and describes the rule logic in plain language, such as flagging customers whose individual cash deposits are under $10,000 but whose total exceeds $9,000 in 24 hours. The logic is then mapped to data fields, given threshold values, set up in the monitoring platform, and documented with a name, rationale, and owner.
Monitoring rules are tuned by testing them against real data. Teams back-test each new or revised rule on 6 to 12 months of historical transactions to see how many alerts it would generate and how many were genuinely suspicious. If the false positive rate is too high, they adjust thresholds, time windows, or filters, then review performance in regular calibration meetings.
What are the limits of rules-based monitoring?
Rules-based monitoring only catches what it is written to catch. Criminals who understand common thresholds can calibrate their activity to stay just under them, and new laundering methods can go unnoticed until someone writes a rule for them. Static rules also tend to generate large numbers of false positives, since they cannot tell the difference between unusual and suspicious behavior for each individual customer.
Most firms address these limits with a hybrid approach. They keep rules for known risks and add behavioral baselines, anomaly detection, and network analysis to catch what rules miss. Rotating thresholds and linking rules to dynamic risk scoring keeps rules-based monitoring aligned with each customer's current risk.