Financial Crime

Transaction Monitoring Effectiveness: Calibration, Tuning and Evidencing That It Works

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 13 min read

Key Takeaways

  • Monitoring rules must trace back to the risks identified in the business-wide risk assessment. Rules that exist because they came with the system are the first thing an assessor will challenge.
  • Tuning must be evidenced. Threshold changes without documented rationale and impact analysis are treated as weakening controls.
  • Above the line and below the line testing is the standard method of demonstrating that thresholds are set correctly.
  • Alert closure quality matters more than alert volume. Closures without recorded reasoning cannot be relied on.
  • Coverage gaps, typically new products, new channels or new corridors added without a corresponding rule review, are the most common serious finding.
Abstract network of connected light nodes on a dark background representing transaction monitoring across payment flows

Transaction monitoring is the control most often described as effective and least often evidenced as effective. Firms can usually show the system exists, the rules are configured and alerts are worked. What they struggle to show is that the rules detect the risks the firm actually faces, that the thresholds are set at the right level, and that alerts are closed for defensible reasons.

Start from the risk assessment

Every rule should be traceable to a risk in the business-wide risk assessment. Build a simple matrix.

BWRA riskTypologyRule or scenarioThresholdOwnerLast tuned
High-risk corridor exposureLayering through rapid movementVelocity across corridorConfigured valueMLRODate
Third-party fundingMoney mule activityInbound from unrelated payerConfigured valueMLRODate
Cash-intensive customersStructuringAggregation below reporting thresholdConfigured valueMLRODate

Two gaps become visible immediately: risks with no corresponding rule, and rules with no corresponding risk. Both need explanation, and the first is the serious one.

Calibration and tuning

Thresholds should be set from data about the firm's own population, not from vendor defaults. The evidence pack for each threshold should include the distribution of activity that the threshold sits within, the expected alert volume, the rationale for the level chosen, and the approval.

Above the line testing. Take alerts generated just above the threshold and assess whether they are productive. If almost none are, the threshold may be too low.

Below the line testing. Sample activity just below the threshold that generated no alert and assess whether any should have been escalated. Productive findings below the line mean the threshold is too high, and this is the test firms most often omit.

Any threshold change should record the reason, the testing performed, the expected effect on alert volume and the approval. A change made to reduce a backlog, without testing, is a control weakness that will be identified.

Alert handling quality

Volume metrics tell you about capacity. Quality metrics tell you about effectiveness.

  • Closure reasoning: does each closed alert record the facts reviewed, the analysis and the conclusion.
  • Consistency: do different analysts reach the same conclusion on similar patterns.
  • Escalation rate and outcome: what proportion of alerts escalate, and how many result in a suspicious activity report or a customer exit.
  • Ageing: how long alerts remain open, and whether backlog pressure correlates with lower escalation rates.
  • Quality assurance: independent sampling of closed alerts with feedback and re-training.

A falling escalation rate alongside rising volumes is one of the clearest indicators that the control is degrading.

Coverage and change control

The most common serious finding is a coverage gap created by change: a new product, a new payment channel, a new geographic corridor or a new customer segment introduced without a corresponding review of monitoring rules. The control is straightforward. Any material change to products, channels, geographies or customer types should trigger a documented monitoring impact assessment before launch.

Model or system changes should also be tested before deployment, with a record of pre-change and post-change alert behaviour.

Management information for the board and MLRO report

The board should see alert volumes and trends with the reason for material movements, escalation and reporting rates, quality assurance results, tuning activity and its rationale, backlog and ageing, and coverage assessment following any product or market change. The annual MLRO report should draw these together with an explicit conclusion on effectiveness.

Our guides to AML and CTF framework design and FCA financial crime compliance cover the wider control environment.

About Regulatory Counsel

Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.

Our financial crime work covers business-wide risk assessments, monitoring rule and typology mapping, threshold calibration and above and below the line testing, alert quality assurance frameworks, model change control, MLRO reporting and independent effectiveness reviews.

Contact our regulatory team at info@regulatorycounsel.co.uk.

This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.

Frequently Asked Questions

By mapping every rule to a risk in the business-wide risk assessment, documenting threshold rationale, performing above and below the line testing, running quality assurance on alert closures, and reporting escalation and outcome data to the board.

Sampling activity that fell just below an alerting threshold and did not generate an alert, to assess whether any of it should have been escalated. Productive findings indicate the threshold is set too high.

At least annually, and additionally whenever the customer base, product set, channels or geographies change materially, with each change supported by testing, expected volume impact and documented approval.

A coverage gap created by change: new products, channels, corridors or customer segments introduced without a documented review of whether monitoring rules detect the associated risks.

Alert volumes and trends with explanations, escalation and reporting rates, quality assurance results, tuning activity and rationale, alert ageing and backlog, and coverage assessments following product or market changes.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert