What is Transaction Monitoring?

Transaction monitoring is the process of reviewing customer transactions to detect activity that may indicate money laundering, terrorist financing, or other financial crime.

Transaction monitoring is the heart of daily AML operations. After a customer has passed onboarding checks, transaction monitoring watches how they actually use their account, including deposits, withdrawals, transfers, card payments, and crypto activity. When activity looks unusual or matches a known risk pattern, the system generates an alert for a compliance analyst to review.

Transaction monitoring has to balance coverage with efficiency. A strong program catches genuinely suspicious activity without burying analysts in false positives, which industry-wide often make up 95 to 99 percent of alerts.

How does transaction monitoring work?

Transaction monitoring uses two main approaches, and most programs combine them. Rule-based monitoring flags activity that crosses set criteria, such as the following.

  • Threshold rules, such as any cash deposit over $10,000
  • Velocity rules, such as more than five wire transfers in 24 hours
  • Pattern rules, such as repeated deposits just under a reporting limit

Behavior-based monitoring looks for activity that departs from what is normal for each customer. It builds a baseline of typical behavior, uses anomaly detection to spot sudden changes like a customer sending ten times their usual wire volume, and applies network analysis to find accounts moving funds in loops or layered structures.

Transaction monitoring can run in real time or in batches. Real-time monitoring flags high-risk transactions, such as large wires to high-risk jurisdictions, early enough to block them before settlement. Batch monitoring suits lower-risk, high-volume channels and makes it easier to test rules against historical data, but alerts can arrive hours or days after the transaction.

What happens after a transaction monitoring alert?

A transaction monitoring alert starts a structured review. Alerts are first scored and tiered by risk, based on factors such as the customer's risk rating, the amount, the geography, and recent alert history. High-risk alerts go straight to senior analysts, while medium- and low-risk alerts are worked within set deadlines.

An analyst then investigates the alert by gathering account details, reviewing the full transaction and counterparties, and checking the customer's past alerts and reports. The key question is whether the activity fits the customer's known profile. If suspicion remains, the case is escalated to the MLRO, who decides whether to file a suspicious activity report. Every step is documented for regulators and auditors.

How do firms reduce transaction monitoring false positives?

Firms reduce false positives by testing and tuning rules against real data. New or revised rules are back-tested on 6 to 12 months of past transactions to see how many alerts they would generate and how many would have been genuinely suspicious. Teams then adjust thresholds, time windows, and filters, and review rule performance regularly.

Risk-weighted rules make transaction monitoring more precise. Higher-risk customers face lower alert thresholds, while low-risk customers face higher thresholds or fewer active rules. Linking monitoring to dynamic risk scoring lets those thresholds update automatically as a customer's risk changes. Firms track results through metrics such as precision and alert-to-SAR conversion, with effective rules often converting around 3 to 5 percent of alerts into reports.

Flagright's transaction monitoring platform supports both real-time and batch monitoring.