Transaction monitoring is the control most often described as effective and least often evidenced as effective. Firms can usually show the system exists, the rules are configured and alerts are worked. What they struggle to show is that the rules detect the risks the firm actually faces, that the thresholds are set at the right level, and that alerts are closed for defensible reasons.
Start from the risk assessment
Every rule should be traceable to a risk in the business-wide risk assessment. Build a simple matrix.
| BWRA risk | Typology | Rule or scenario | Threshold | Owner | Last tuned |
|---|---|---|---|---|---|
| High-risk corridor exposure | Layering through rapid movement | Velocity across corridor | Configured value | MLRO | Date |
| Third-party funding | Money mule activity | Inbound from unrelated payer | Configured value | MLRO | Date |
| Cash-intensive customers | Structuring | Aggregation below reporting threshold | Configured value | MLRO | Date |
Two gaps become visible immediately: risks with no corresponding rule, and rules with no corresponding risk. Both need explanation, and the first is the serious one.
Calibration and tuning
Thresholds should be set from data about the firm's own population, not from vendor defaults. The evidence pack for each threshold should include the distribution of activity that the threshold sits within, the expected alert volume, the rationale for the level chosen, and the approval.
Above the line testing. Take alerts generated just above the threshold and assess whether they are productive. If almost none are, the threshold may be too low.
Below the line testing. Sample activity just below the threshold that generated no alert and assess whether any should have been escalated. Productive findings below the line mean the threshold is too high, and this is the test firms most often omit.
Any threshold change should record the reason, the testing performed, the expected effect on alert volume and the approval. A change made to reduce a backlog, without testing, is a control weakness that will be identified.
Alert handling quality
Volume metrics tell you about capacity. Quality metrics tell you about effectiveness.
- Closure reasoning: does each closed alert record the facts reviewed, the analysis and the conclusion.
- Consistency: do different analysts reach the same conclusion on similar patterns.
- Escalation rate and outcome: what proportion of alerts escalate, and how many result in a suspicious activity report or a customer exit.
- Ageing: how long alerts remain open, and whether backlog pressure correlates with lower escalation rates.
- Quality assurance: independent sampling of closed alerts with feedback and re-training.
A falling escalation rate alongside rising volumes is one of the clearest indicators that the control is degrading.
Coverage and change control
The most common serious finding is a coverage gap created by change: a new product, a new payment channel, a new geographic corridor or a new customer segment introduced without a corresponding review of monitoring rules. The control is straightforward. Any material change to products, channels, geographies or customer types should trigger a documented monitoring impact assessment before launch.
Model or system changes should also be tested before deployment, with a record of pre-change and post-change alert behaviour.
Management information for the board and MLRO report
The board should see alert volumes and trends with the reason for material movements, escalation and reporting rates, quality assurance results, tuning activity and its rationale, backlog and ageing, and coverage assessment following any product or market change. The annual MLRO report should draw these together with an explicit conclusion on effectiveness.
Our guides to AML and CTF framework design and FCA financial crime compliance cover the wider control environment.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our financial crime work covers business-wide risk assessments, monitoring rule and typology mapping, threshold calibration and above and below the line testing, alert quality assurance frameworks, model change control, MLRO reporting and independent effectiveness reviews.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.
Frequently Asked Questions
By mapping every rule to a risk in the business-wide risk assessment, documenting threshold rationale, performing above and below the line testing, running quality assurance on alert closures, and reporting escalation and outcome data to the board.
Sampling activity that fell just below an alerting threshold and did not generate an alert, to assess whether any of it should have been escalated. Productive findings indicate the threshold is set too high.
At least annually, and additionally whenever the customer base, product set, channels or geographies change materially, with each change supported by testing, expected volume impact and documented approval.
A coverage gap created by change: new products, channels, corridors or customer segments introduced without a documented review of whether monitoring rules detect the associated risks.
Alert volumes and trends with explanations, escalation and reporting rates, quality assurance results, tuning activity and rationale, alert ageing and backlog, and coverage assessments following product or market changes.
