Skip to main content

Blog entry by FintEdu Admin

Is Transaction Monitoring Only a Technology Problem?

Transaction monitoring is often treated as a technical exercise.

A system is purchased, rules are configured, thresholds are set, alerts are generated, and investigators review the results.

But the real question is not whether an institution has a transaction monitoring system.

The real question is whether the system is capable of seeing the risks the institution actually faces.

A monitoring system can only detect what it has been designed, configured, and connected to detect. If relevant transaction types are excluded, scenarios are outdated, thresholds are poorly calibrated, or the data feeding the system is incomplete, the existence of the technology may create a false sense of security.

This is where transaction monitoring can become a blind spot instead of a control.

When the System Is Working, But the Control Is Not

In 2024, a major U.S. bank pleaded guilty to Bank Secrecy Act and money laundering-related violations following an investigation by the U.S. Department of Justice.

The case was not simply about a bank failing to purchase appropriate technology.

According to the DOJ, the bank had an automated transaction monitoring system but intentionally excluded domestic automated clearinghouse transactions, most check activity, and other transaction types from monitoring. From January 2018 to April 2024, approximately 92% of its total transaction volume went unmonitored, representing around $18.3 trillion in activity.

The DOJ also found that the bank's transaction monitoring program remained effectively static for years despite known deficiencies, emerging money laundering risks, and new products and services.

The bank's failures enabled three money laundering networks to collectively move more than $670 million through its accounts between 2019 and 2023.

The eventual resolution included $1.8 billion in penalties, AML remediation, and an independent monitor.

The important lesson is not simply that the technology was inadequate.

It is that transaction monitoring is a control framework, not a software purchase.

A Monitoring System Is Only as Good as Its Coverage

One of the first questions compliance teams should ask is:

What exactly are we monitoring?

A transaction monitoring system may cover certain payment channels while excluding others.

It may monitor account transfers but not certain forms of payment.

It may monitor transactions above a particular threshold while missing activity occurring just below it.

It may monitor individual accounts without effectively connecting related accounts, customers, beneficial owners, or counterparties.

These gaps matter because money laundering rarely presents itself as one isolated transaction.

It can appear as a sequence.

It can involve several accounts.

It can involve multiple customers who appear unrelated.

It can involve third parties.

It can involve transactions that only become suspicious when viewed together.

The CBUAE's guidance recognizes this by requiring monitoring of customer activity and the use of appropriate rules and parameters designed around relevant illicit-finance typologies. It also emphasizes that monitoring should consider information collected through CDD.

This means transaction monitoring cannot be designed independently from the rest of the AML program.

The Risk Assessment Should Drive the Rules

A common weakness is starting with the technology instead of the risk.

An institution may purchase a platform and then ask:

“Which rules should we turn on?”

A stronger approach is:

“What risks do our customers, products, services, channels and markets create, and how will we detect them?”

The difference is significant.

A bank offering trade finance may face very different risks from an exchange house.

A payment company may face different risks from a private bank.

A DNFBP dealing with high-value goods may need to consider different typologies from a retail financial institution.

The monitoring program should therefore reflect the institution's own risk profile.

The study material emphasizes that transaction monitoring rules should be risk-based and consider the size of the organization, products offered, and characteristics of those products. Rules and thresholds should also be reviewed and updated as risks change.

Technology should support this process.

It should not determine the risk strategy.

More Alerts Do Not Always Mean Better Monitoring

There is another problem that often appears when institutions try to strengthen transaction monitoring:

alert volume becomes the measure of effectiveness.

Thousands of alerts can make a monitoring program look active.

But a large alert volume does not necessarily mean that meaningful suspicious activity is being detected.

If investigators are spending most of their time closing low-quality alerts, important activity may receive less attention.

This creates two risks.

First, compliance resources are consumed by false positives.

Second, genuinely suspicious activity may be buried within the volume.

The answer is not simply to reduce alerts.

The answer is to improve the quality of the monitoring program.

That means reviewing:

  • Why is this scenario generating alerts?
  • Is the threshold appropriate?
  • Does the scenario reflect a real typology?
  • Are similar alerts repeatedly being closed for the same reason?
  • Are important suspicious patterns missing?
  • Does the alert contain enough information for an investigator to understand the activity?

The CBUAE specifically expects institutions using automated monitoring systems to periodically review and test their capabilities, thresholds, parameters and detection scenarios.

A system should not be considered effective simply because it produces output.

The output must be useful.

Customer Information Must Connect to Transaction Monitoring

Transaction monitoring becomes much stronger when it is connected to customer information.

Consider a company that tells a financial institution that it expects to receive approximately AED 200,000 a month from its normal business.

Six months later, it begins receiving several million dirhams from unrelated third parties and quickly transferring the money elsewhere.

The individual transactions may not all breach a simple numerical threshold.

But the overall activity may be inconsistent with the customer's known profile.

That is why CDD and transaction monitoring should not operate as separate worlds.

Customer type, expected activity, beneficial ownership, business purpose, source of funds and risk rating can all provide important context.

The CBUAE specifically requires financial institutions to continuously monitor transactions for consistency with customer information, type of activity and associated risks, including source of funds where necessary.

The question is therefore not only:

“Did the transaction trigger a rule?”

It should also be:

“Does this activity make sense for this customer?”

Beneficial Ownership Can Change the Meaning of a Transaction

Two companies may appear unrelated when viewed only at the transaction level.

But if both are controlled by the same beneficial owner, the relationship may become much more important.

For example:

Company A sends funds to Company B.

Individually, that may not look suspicious.

But if both companies are ultimately controlled by the same person, and the transactions are circular, unusually frequent, or lack an obvious economic purpose, the institution has more information to investigate.

The CBUAE provides a similar example in its transaction monitoring guidance, noting that transactions between apparently unconnected companies may require investigation when they are owned or controlled by the same individual or individuals.

This demonstrates why effective monitoring requires more than transaction data.

It requires relationships and context.

People Still Matter

Automation does not remove the need for trained employees.

Customer-facing employees may notice unusual behaviour before a system generates an alert.

Relationship managers may know that a customer's business has changed.

Operations staff may identify unusual documentation.

Compliance analysts may recognize a pattern across several cases.

Investigators may identify a typology that the existing rules do not capture.

The study material specifically recognizes employee referrals and other manual processes as potential sources for investigations in addition to automated transaction monitoring.

This creates an important principle:

The monitoring system should not be the only way suspicious activity enters the investigation process.

Employees should have a clear mechanism to escalate unusual activity.

And compliance teams should have the authority and resources to investigate it.

What Compliance Officers Should Check

For compliance officers, reviewing transaction monitoring should go beyond asking whether the software is operational.

A practical review can start with five questions.

1. What are we actually monitoring?

Map the products, services, payment channels and transaction types covered by the monitoring system.

Identify what is outside automated monitoring.

2. Do our scenarios reflect our actual risks?

Compare monitoring scenarios with the institution's AML/CFT risk assessment.

If a significant risk exists but there is no monitoring scenario or manual control addressing it, document why.

3. Are the thresholds still appropriate?

Review alert thresholds against actual customer behaviour.

Test activity above and below thresholds to determine whether suspicious patterns could remain undetected.

4. Can investigators see the full picture?

An investigator should be able to access relevant customer information, transaction history, risk information and relationships needed to assess an alert.

5. What happens when a gap is identified?

Monitoring weaknesses should be documented, escalated and tracked through remediation.

A known weakness that remains unresolved is a governance issue, not simply a technology issue.

What DNFBPs Can Learn From This

Although many transaction monitoring discussions focus on banks, the same principle applies to DNFBPs.

A real estate professional, precious metals dealer, accountant, auditor, lawyer, or other relevant business should not assume that transaction monitoring means purchasing a sophisticated automated platform.

For smaller or less complex businesses, monitoring may involve a combination of manual reviews, defined red flags, customer information, transaction records, employee escalation and periodic risk reviews.

The objective is the same:

identify activity that is inconsistent with what the business knows about the customer and the transaction.

DNFBPs should therefore:

  • Define what unusual activity looks like for their specific business.
  • Establish documented monitoring procedures.
  • Link monitoring to CDD and beneficial ownership information.
  • Review transactions against the customer's expected business activity.
  • Pay attention to third-party payments and unexplained funds.
  • Document investigations and decisions.
  • Escalate suspicious activity according to applicable reporting requirements.
  • Review their monitoring approach when products, customers, risks or typologies change.

The level of sophistication should be proportionate to the risk.

But “we are a smaller business” should not mean “we do not need an effective monitoring process.”

Management Has a Role Too

Transaction monitoring is often placed entirely on the compliance department.

That is a mistake.

Senior management should understand whether the monitoring framework is capable of addressing the organization's risks and whether significant gaps are being resolved.

Management should be asking questions such as:

Are there transaction types we cannot monitor?

Are new products being assessed before launch?

When were our monitoring scenarios last reviewed?

How many alerts are we generating, and how many result in meaningful investigations?

Are compliance resources sufficient for the current alert volume?

Have regulators, auditors, or internal reviews identified monitoring weaknesses?

How quickly are those weaknesses being remediated?

These questions help move transaction monitoring from a technical discussion into a governance discussion.

The Real Problem Is Not Always the Technology

The case demonstrates what can happen when monitoring weaknesses are allowed to become structural.

The lesson is not that automated monitoring is ineffective.

In fact, automated monitoring is essential for organizations dealing with large transaction volumes.

The lesson is that technology must be supported by:

Risk assessment.

Complete and reliable data.

Appropriate scenarios.

Effective thresholds.

Regular testing and tuning.

Trained investigators.

Clear escalation procedures.

Adequate resources.

Senior management oversight.

Without these elements, even sophisticated technology can provide a false sense of comfort.

The strongest AML programs do not ask only whether they have a transaction monitoring system.

They ask whether their entire monitoring framework is capable of adapting to the way risk actually changes.

Because criminals do not wait for an institution to update its rules.

They change their behaviour first.

And if the monitoring program changes only after the risk becomes obvious, the system may already be looking in the wrong direction.

Disclaimer: Content posted is for informational and knowledge sharing purposes only, and is not intended to be a substitute for professional advice related to tax, finance or accounting. The view/interpretation of the publisher is based on the available Law, guidelines and information. Each reader should take due professional care before you act after reading the contents of that article/post. No warranty whatsoever is made that any of the articles are accurate and is not intended to provide, and should not be relied on for tax or accounting advice.


Total Views : 22 | Share on

Contributor

Related Posts

An internal warning reaching the right person is not necessarily the same as an internal warning bei...

Read More

A customer category with a documented history of money laundering or financial crime exploitation do...

Read More

If you work in compliance, you already assign risk ratings to customers, countries, and relationship...

Read More

  
Job PortalWhatsAppRequest a Call