Transaction monitoring
This is the engine that sets your alert volume, so demand more than a rule library out of the box. You want configurable scenarios you can map to your own risk profile, plus behavioral or risk-based detection that reads a customer against their own baseline rather than a fixed dollar line. A structuring rule that flags every transaction just under a threshold, as Unit21 describes, will bury analysts under legitimate activity if it can't account for who the customer is.
Monitoring output is only as good as two things feeding it: the data quality from the onboarding and screening stages above, and the tuning behind the rules. A pristine engine fed stale profiles produces confident nonsense. That's why transaction monitoring can't be evaluated in isolation from the pipeline that supplies it.
Ask how scenarios are built and whether threshold changes are version-controlled, including who can make those changes. The International Finance Corporation recommends a change control board that extends oversight to modifications of transaction-monitoring controls, from thresholds and rules to workflows, so every change is traceable and authorized. If a rule can be altered without a record, your transaction monitoring becomes indefensible the moment an examiner asks why.
Case management and reporting
When an alert fires, where does the analyst work it? A case management workflow that brings the alert and customer profile together with the transaction history and prior decisions into one investigation view is what separates a team that clears cases from one lost across a dozen browser tabs. Fragmentation here is expensive, because analysts rebuild context from scratch on every case instead of investigating.
The case management workflow also has to carry investigation context straight into regulatory filings. A Suspicious Activity Report (SAR) in the US, or a Suspicious Transaction Report (STR) elsewhere, should be populated from the case rather than retyped. FinCEN requires a SAR to be filed no later than 30 calendar days after initial detection, when that clock starts. AML software that forces manual re-entry burns days you don't have.
Every action inside the case management workflow should write to the audit trail you'll lean on during an examination. The strongest platforms treat these as one continuous record:
-
The alert that triggered the case and the data behind it
-
Each analyst action, documented with any note or escalation and a timestamp and user identity
-
The final disposition and its rationale, along with any resulting SAR or STR reference
That record is how you defend a decision two years after anyone remembers making it.
How to judge alert quality
Alert quality will define your team's daily workload more than any other single factor, so evaluate it harder than anything else. The industry baseline is brutal. PwC analysis cited across the sector since 2018 puts the share of alerts that are false positives at 90 to 95 percent in traditional rule-based systems. That means for every hundred alerts, as many as ninety-five lead nowhere while still consuming analyst time.
The number matters because it converts directly into headcount and cost. Manual review runs $25 to $50 per alert at mid-size institutions, and staffing eats 50 to 60 percent of a mid-size AML budget, per Fraxtional's analysis. Worse, a flood of noise hides genuine risk. Real suspicious activity sits buried under the false positives your team can't get through.
So push the vendor on how they reduce noise without raising false negatives. A false positive rate driven artificially low is its own red flag, as Unit21 warns, because it signals rules so tight that real activity escapes. They place a healthy rate around 15 percent.
Use these questions to separate a vendor who can fix the problem from one who only claims to:
-
How do you tune thresholds, and can we do it ourselves without a change request to you?
-
What does above-the-line and below-the-line testing look like in your AML software, and do you support it?
-
How does risk scoring prioritize alerts so analysts see the highest-risk ones first?
-
When customer data improves upstream, does alert quality improve downstream, or are the two disconnected?
That last question closes the loop back to the pipeline. Strong alert quality is a product of a well-fed, connected data flow. A vendor who talks about tuning but can't explain how clean onboarding and screening data reach the monitoring engine is selling you a patch, not a fix.