Transaction Monitoring: Rules and Alerts
How do banks spot suspicious transactions automatically?
Banks run software that compares account activity with what they expect from each customer. Rules flag known patterns, such as clusters of deposits just under a reporting threshold, and newer models score unusual behaviour. Each alert goes to an analyst, and most are closed as innocent. The few that survive become suspicious activity reports.
As of September 2026: The US AML program reform is a proposal, not a final rule. FinCEN issued a notice of proposed rulemaking on April 7, 2026 that would replace its July 3, 2024 proposal, shift supervisory focus from technical compliance to effectiveness, and steer bank resources toward higher-risk customers and activities. Public comments were due June 9, 2026. This page did not confirm a final rule as of September 2026, so existing monitoring expectations still apply. The German FIU figures are for 2022, as cited by the Wolfsberg Group, and are one country's experience rather than a global rate.
What is transaction monitoring?
Every bank is expected to notice when an account behaves oddly. Transaction monitoring is the system that does the noticing. It is software plus people: the software compares payments, deposits and transfers against what the bank knows about the customer, and analysts review what it flags.
The Wolfsberg Group, a body of large international banks, prefers a wider term: monitoring for suspicious activity. Transaction monitoring is one part. The rest includes the customer’s attributes and behaviour and ongoing customer due diligence. That matters because the yardstick is the customer’s own profile. Ten transfers of the same size are normal for one business and alarming for another.
In the US, the customer due diligence rule requires banks to run ongoing monitoring “to identify and report suspicious transactions.” Other countries impose the same duty through FATF standards.
How do rules and models differ?
Rules are explicit tests written from known red flags and typologies. Examples include several cash deposits that add up to more than a reporting threshold across days, funds that enter an account and leave almost at once, or payments to and from places the bank rates as high risk. Rules map neatly onto the patterns described in the technique pages, such as structuring and money mules. Their strength is that an examiner can read them and see exactly why an alert fired.
Models use statistics or machine learning to produce a risk score from many signals at once. According to the Wolfsberg Group, models are harder to manage than rules, because they are built to make predictions across large data sets covering many risks. Banks need to document them clearly and test them against real outcomes. Banks also use machine learning as a “booster” on top of rules, for example to add a second layer of name screening.
Both approaches share a blind spot: they see only what one bank sees. Activity spread across several institutions is far harder to spot from inside any one of them, which is why national reporting databases matter.
What happens after an alert?
An analyst reviews the alert against the customer’s profile and history. Most alerts are closed with a note explaining why the activity is normal. A smaller number are escalated to a case, which may end in a written narrative and a confidential suspicious activity report to the national financial intelligence unit.
Why is the false-positive problem so large?
Because the incentives point toward alerting. A bank that misses real laundering faces enforcement. A bank that raises too many alerts faces only cost. So systems tend to be tuned wide.
Sources for a hard number are thin. The “90 percent or more of alerts are false” line that circulates in the industry is not one this page could trace to a regulator or standard setter, so it is not repeated here. What the primary sources do say is more specific.
The Wolfsberg Group’s 2024 statement says the value from ever-rising report volumes is not “contributing proportionately” to effective outcomes. It describes banks keeping monitoring scenarios that produce little or no escalation, trying to leave no historical report behind, and gradually lowering the bar for filing. Defensive filing removes regulatory risk for the bank but is unlikely to give law enforcement anything useful. It also says the usual scorecards, such as alert volumes and alert-to-report ratios, measure quantity, not usefulness.
One national example, cited in that statement: Germany’s FIU reported that of 337,186 suspicious transaction reports in 2022, about 15 percent went on to law enforcement, and feedback showed 95 percent of the resulting cases were closed without prosecution.
How is the system changing?
Wolfsberg also asks banks to feed lessons back in. Information from case investigations and filed reports, including the narratives analysts write, can be used to refine detection, raise the risk score of suspicious entities and reveal relationships nobody had linked before. It adds that banks should define success by high-value outcomes, not just by the number of reports filed. A monitoring system is meant to learn from its own cases.
The direction is toward fewer, better alerts. The Wolfsberg Group urges banks to stop monitoring routines that never produce useful reports and to spend effort on observed risks. In the US, FinCEN’s April 2026 proposal would push supervision the same way: toward effectiveness, and toward higher-risk customers and activities instead of lower-risk ones. It is a proposal only.
How monitoring catches launderers
Monitoring works less as a tripwire than as a memory with a pattern detector. It rarely proves a crime by itself. What it does is create a dated trail: this account, this behaviour, this mismatch with the stated business. When an investigator later queries a name, that trail is already there, which is why reporting and monitoring are described as banking evidence for future cases. It also raises the cost of crude methods. Simple patterns get caught, which pushes laundering toward slower, more complicated routes that are harder to run.
For the overall picture of where this succeeds and where it fails, see why detection still fails.
Frequently asked questions
What share of transaction monitoring alerts are false positives?
There is no official figure we could verify, and the often-quoted 90 percent or higher is not something regulators publish as a standard. What primary sources do show is the direction: the Wolfsberg Group says banks file more reports than ever without a matching rise in useful information for authorities, and it calls alert-to-SAR ratios a weak measure of effectiveness.
What is the difference between a rule and a model?
A rule is an explicit test, such as 'cash deposits above a set total in a set number of days.' A model, often machine learning, learns patterns from past data and produces a risk score. Rules are easy to explain to an examiner. Models can catch subtler patterns but are harder to document and validate.
Does an alert mean the bank thinks I did something wrong?
No. An alert is only a prompt for a person to look. Most alerts are closed once an analyst sees a normal explanation. Only a suspicion that survives review becomes a confidential report.
Can monitoring be gamed?
Regulators and banks assume some people try, which is why systems are tuned over time, combine several signals, and add human review. The Wolfsberg Group notes that publicly available red-flag lists mean known patterns lose value, so banks are pushed toward customer context and newer analytics. This site covers how detection works, not how to avoid it.
Techniques this catches
- Structuring (smurfing) · Splitting cash into deposits just below the reporting threshold so no single transaction triggers a currency report.
- Funnel accounts and money mules · Recruited or deceived account holders receive and forward criminal money, so the bank's customer checks land on a real person who isn't the criminal.
- Cuckoo smurfing · Cuckoo smurfing hijacks a legitimate international transfer: criminal cash is deposited into an unwitting recipient's account while the clean money stays offshore.
- Transaction laundering · Running card payments for a hidden business through another merchant's legitimate processing account so the payment system sees only the front.
Glossary
Sources
- Statement on Effective Monitoring for Suspicious Activity, Part I: Moving Beyond Automated Transaction Monitoring (The Wolfsberg Group, 2024).
- Fact Sheet: Proposed Rule to Fundamentally Reform Financial Institution AML/CFT Programs (FinCEN, April 7, 2026).
- Anti-Money Laundering and Countering the Financing of Terrorism Program Requirements: Notice of Proposed Rulemaking (OCC Bulletin 2026-11) (Office of the Comptroller of the Currency, April 2026).
- CDD Rule FAQs (ongoing monitoring requirement) (FinCEN, last updated May 6, 2026).
- FIN-2018-G001: Frequently Asked Questions Regarding Customer Due Diligence Requirements for Financial Institutions (FinCEN, April 3, 2018).
- Reports by banks of suspicious transactions (31 CFR 1020.320) (eCFR / FinCEN, accessed August 2026).