Transaction Monitoring [Key AML Challenges]

Find out where regulated platforms struggle most when it comes to transaction monitoring and follow some useful tips on how to solve common challenges, such as false positives. Discover why rule-based, automated AML systems are the most sustainable approach in the market right now.

Reviewed by

Compliance Team Lead

10 min read
Add iDenfy as a Preferred Source
Transaction monitoring system guide

Analyzing transaction patterns and anomalies to prevent financial crime is only one part of the transaction monitoring process. In Anti-Money Laundering (AML) compliance, this is a mandatory measure that helps identify suspicious AML red flags and report this activity. For example, a sudden increase in cross-border transfers between unrelated user accounts can trigger an alert.  At the same time, transaction monitoring simply ensures that the financial institution and its customers are protected from money laundering, terrorism financing, and other related crimes. 

Both traditional financial institutions and virtual asset service providers (VASPs) use monitoring to track their clients’ financial behavior. All modern transaction monitoring systems are automated because they need to be capable of working non-stop and dealing with a large number of transactions simultaneously, especially if it’s a big corporation. A risk-based approach is used, and the company’s analysts review whether the flags that were identified by the system are legitimate and not a false positive, providing an explanation and keeping results for a compliant audit log. 

TL;DR: Non-compliance and poor transaction monitoring practices, like not reporting certain activity, can result in suspension or even possibly jail time for the people involved. Not to mention, monitoring is an ongoing due diligence process, which makes it a more complex task. 

That’s why I review the main factors that you should consider when building your own system or implementing a third-party service provider. 

What is Transaction Monitoring?

Transaction monitoring is the process of continuously tracking customer transactions (transfers, deposits and withdrawals) with the goal of detecting suspicious patterns that might indicate unlawful activity. This process runs automatically, as all modern transaction monitoring systems are AI-powered simply because of the scope that financial companies deal with. 

Modern transaction monitoring systems are AI-powered and help analysts focus on high-risk cases, reducing manual effort.

High-risk businesses, such as banks, fintech platforms, iGaming and casino establishments, real estate firms, and other companies, even those that aren’t regulated but have money flowing, use transaction monitoring to prevent financial crime. Manual processes oftentimes aren’t sustainable and aren’t possible due to the large transaction volumes institutions are required to monitor. 

AML Screening

Automate your AML checks

Screen customers against global sanctions, PEPs, and watchlists in real time with iDenfy AML Screening.

AML Screening Software

The History of the Transaction Monitoring Process

The Bank Secrecy Act (BSA) was the first regulatory landmark for the official transaction monitoring process. It was introduced in the USA in 1970, but prior to that, banks relied on manual monitoring procedures and less formal regulatory guidance, for example, reporting suspicious activity. 

Then, stricter AML rules were introduced by the Financial Action Task Force (FATF) and its establishment in 1989. Fast forward to the 2000s and what we have today: transaction monitoring became an established procedure, which is by standard known to be AI-powered. This meant moving from a manual-only approach to a hybrid, rule-based system that’s able to flag transactions in real-time. 

Related: 40 Recommendations of the FATF — Overview

Which Entities are Required to Conduct Transaction Monitoring?

Exact requirements vary. However, the key entities include AML-obliged institutions, such as:

  • Banks and neobanks
  • Money services businesses (MSBs)
  • Foreign exchanges
  • Crypto exchanges and other VASPs
  • Lending and financing firms
  • Investment platforms
  • iGaming, gambling and sports betting sites
  • Dealers in precious metals and precious stones
  • Luxury item sellers, such as art dealers
  • Securities and brokerage firms
  • Insurance companies

Other examples include real estate agents, lawyers and notaries, as well as accountants and auditors. The main thing to remember is that their transaction monitoring obligations differ from those that financial institutions like banks need to follow. 

Does Transaction Monitoring Detect Money Laundering?

The short answer is no. Monitoring detects suspicious transactions based on alerts and reasons that explain why the particular transaction might indicate suspicious activity. It doesn’t automatically determine that it’s money laundering. 

The workflow for transaction monitoring often involves these components:

  • The transaction
  • The system or its rule that detects the red flag
  • The alert that’s sent out due to the anomaly
  • The investigation and decision
  • Possible suspicious activity or transaction report 

The analyst is still the final point and the decision-maker in the chain. 

Related: Transaction Monitoring Software in Fintech: How to Set it Up?

What Does the Risk-Based Approach Mean in Transaction Monitoring?

A risk-based approach in AML in general means that you apply different workflows and not the same process to all of the customers based on the risk the particular transaction or the customer poses. In transaction monitoring, the principle’s the same. You should put the most effort and extra manual review on high-risk transactions. Low-risk ones go through without generating alerts. 

Risk-based alert scoring helps determine how many alerts your analysts can realistically review and how quickly they can investigate them, setting the limit and clear guidelines on which alerts should receive priority. High-risk scenarios often require Enhanced Due Diligence (EDD), for example, a more frequent review of their profile/transactions. 

There are multiple steps that go into a compliant transaction monitoring system that ensures the financial institution is compliant and in line with AML laws.

Customer profiles also change, and low-risk customers that were once onboarded using a low-risk KYC verification flow can develop criminal tendencies and get flagged after months or years of being registered to a financial platform. That’s why monitoring is vital. You always adjust the process to the customer’s risk profile. For example, if it changes and it appears the client is now high-risk, you can then enable ongoing monitoring for them. 

Related: What is the Difference Between CDD and EDD?

Common Transaction Monitoring Challenges

Reliable information, good transaction monitoring software, and set up rules that would help collect enough context and still sustainably manage alert volumes are required to avoid these challenges:

False Positives

This is the most impactful challenge that comes with transaction monitoring. A false positive happens when a legit transaction is flagged, and an alert is triggered due to the rule that you use in your monitoring system. The rule detected the “suspicious” activity pattern, but it was a genuine customer who regularly makes a large payment. 

The key issue that’s most damaging is the fact that such fake alerts are costly. They drain analysts’ resources and the funds that the company uses on the software. 

Cross-Border Transactions

Cross-border payments automatically add complexity due to different countries, currencies, regulatory laws/AML regimes, and intermediaries that mix up and make it harder to assess the origin and the transaction’s destination. This can also mean that the multiple elements in the chain hide the real people behind the transaction. 

Criminals use cross-border payments and high-risk corridors that could potentially come from tax havens and shell companies. So, an instant red flag that should be flagged by a monitoring system is a large international transfer that doesn’t match their typical risk profile and behavior. 

Too Many Rules

Having a separate rule for every scenario won’t fix the issue and might even lead to even more false positives. So more rules don’t necessarily equal an effective system because they can overlap. If that happens, analysts are bombarded with excessive alerts that make it hard to piece all the puzzle pieces together. Specific risk profiles and rules should be created based on your internal risk appetite. 

Poor Data Quality

Missing or outdated information, such as incomplete customer profiles or inconsistent checks on high-risk customers, is dangerous and damaging to the whole transaction monitoring process. All AML screening elements, including checks like sanctions screening or occasional adverse media checks, need to be based on up-to-date details and official databases. 

How Do the Risk Rules Work in AML Transaction Monitoring?

Risk rules are designed to analyze historical data and customer behavior, checking if the current financial flows and patterns match the set rules and risk indicators. Rule-based AML transaction monitoring is one of the most popular approaches to modern monitoring systems because, due to the level of automation, such systems scan thousands of transactions without creating backlogs. 

Risk rules help detect transactions that do not align with the typical/expected customer behavior. The goal here is to:

  1. Detect suspicious transactions
  2. Assign a risk level to the flagged transactions
  3. Generate alerts for the analysts who then step in for further review

Risk rules are changed or “calibrated” over time. That’s because you want to avoid too many false positives and alerts that are irrelevant. This creates a hassle for analysts who need to work on meaningful, high-risk activity that actually reflects the company’s risk profile.

What Thresholds are Used in Transaction Monitoring?

Common types of rules are those based on thresholds (for example, extra-large and sudden transactions), velocity (the frequency, especially if it’s within a short period), and geography (funds that come from high-risk countries or sanctioned jurisdictions).  There is no single rule or AML threshold that defines your own internal monitoring rules. Regulatory standards are just guidelines and reference points. 

“Always flagging transactions over €10,000 might not work for you, and, in this case, you can set the rule below or above this threshold.” 

Domantas Ciulde, iDenfy’s CEO 

Why? Simple. Imagine that your workflow flags every client who makes a transfer of more than €10,000 within 24 hours. The company can be dealing with such transactions regularly. Then, analysts would be flooded with thousands of flagged transactions that are low-risk and come from legitimate customers who make legitimate €10,000 or €15,000 payments, only due to the rule being too broad. 

What Happens if the Monitoring System Detects Suspicious Activity?

When the system flags a transaction, your compliance team receives an alert. A reviewer takes the alert in for investigation to determine if there’s an explanation and a legit reason to believe it’s fraudulent. In practice, this requires looking for suspicion of financial crime using the client’s transaction history and other risk signals, like links to suspicious counterparties (sanctions, high-risk jurisdictions, etc.).

A standard workflow that explains why and how analysts should report suspicious transactions if they appear to be linked to real fraudulent activity.

Only if the analyst concludes that the suspicious transaction is reasonably flagged and possibly fraudulent (after investigation), a Suspicious Activity Report (SAR) (also referred to as the Suspicious Transaction Report in some jurisdictions (STR)) needs to be filed with the relevant regulator. Different countries have different systems and portals where you need to file this information. 

That’s why it’s important to either build or implement an automated transaction monitoring system that helps make all steps in the process, from detection to reporting, more efficient. 

Final Self-Assessment Checklist on Transaction Monitoring

To conclude this guide on transaction monitoring, I’ve made a short list that you can use to assess whether your own system has the right capabilities and whether they reflect the reality of your system’s performance:

-> The transaction monitoring system allows you to customize and set flexible rules.

Use a transaction monitoring solution to add and remove rules that need regular updates, based on new risks and changes in customer behavior. 

Tip: Choose a system that lets your compliance teams easily create, test, and adjust rules without lengthy development work. This helps reduce false positives and doesn’t require you to ask your engineering or development team to step in. All work can be done by the AML analysts. 

-> The transaction monitoring system combines rules based on risk scoring and AML screening.

Rules can identify specific risk patterns, but a single rule match does not always tell you the final risk score. It should consist of multiple data points. For example, iDenfy has both AML screening and monitoring tools + transaction monitoring under the same dashboard. That means it merges custom rules and velocity checks with risk assessment and screening against PEPs and sanctions, global watchlists and adverse media. 

Tip: Look for a system that lets you set your own risk thresholds and automatically prioritize alerts that are higher risk. This helps your team focus on EDD and cases where extra manual attention is needed. 

-> The transaction monitoring system connects transactions with the customer’s wider risk profile.

Your transaction monitoring software should connect transaction data with information about the customer (KYC-submitted information during onboarding, for example), their risk profile, previous activity, and AML screening results. This makes it easier to identify changes in behavior and understand why the transaction suddenly “became unusual”. It should also support cross-border transactions and crypto payments, if this is where your audience is at.

Tip: Choose a system that connects transaction monitoring with KYC, Know Your Business (KYB) and AML screening. This is simply because you’ll manage a single workflow and audit trail and one dashboard instead of multiple vendors and pop-ups with a broken auditing and logging system.  

Good news! iDenfy’s transaction monitoring solution checks all of these boxes and offers end-to-end compliance support (KYC/KYB/AML) for regulated businesses.

To find out more, book a free demo.

Frequently asked questions

1

How Does Transaction Monitoring Work?

Arrow

Transaction monitoring continuously analyzes customer transactions. Designed to identify unusual activity that might potentially indicate money laundering, fraud, or other financial crime, it’s automated and helps analysts review flagged cases instead of all transactions that run in the entity’s ecosystem. 

The system compares transactions against predefined rules, customer risk profiles, and behavioral patterns. When activity triggers a rule, it generates an alert for an AML analyst to investigate. The alert is then closed, escalated, or reported as suspicious.

2

What is a Transaction Monitoring System?

Arrow
3

Should Transaction Monitoring Run in Real-Time or After the Event?

Arrow
4

Why is Ongoing Monitoring Required After User Onboarding?

Arrow
5

Does Every Alert Lead to a Suspicious Activity Report?

Arrow

Save costs by onboarding more verified users

Join hundreds of businesses that successfully integrated iDenfy in their processes and saved money on failed verifications.

Image of salesmens