Transaction monitoring is the process a regulated firm uses to watch its customers’ transactions for signs of money laundering, terrorist financing or fraud, so it can flag and report suspicious activity to the authorities. It runs continuously, screening payments as they happen and reviewing patterns over time.

It is also where the largest anti-money-laundering fines are won and lost. In December 2021 the FCA fined NatWest £264.8 million after around £365 million was paid into one customer’s accounts, most of it in cash. Part of the reason it went undetected: the bank’s automated monitoring system had misread some of those cash deposits as cheques, which carry a lower risk score. A single classification error, and hundreds of millions in cash walked through the controls.

What transaction monitoring is, in practice

Every regulated firm has to know not just who its customers are, but what they are doing with their accounts. AML transaction monitoring is the control that watches the activity: the payments in and out, their size, their frequency, their origin and destination, and whether any of it fits a pattern that looks like financial crime. It is a legal requirement under anti-money-laundering rules, and regulators expect to see it running across the whole customer base.

The output is an alert. When a transaction, or a run of them, breaks a rule or looks abnormal, the transaction monitoring system raises a flag for a human to investigate. The analyst reviews the flagged activity against the customer’s profile, gathers any missing context, and records a decision.

Most alerts close as false alarms. The ones that hold get escalated to the firm’s money-laundering reporting officer and, where the suspicion is real, filed as a Suspicious Activity Report with the national financial-intelligence unit. That investigation trail is what a regulator inspects after the fact, because it shows whether the firm acted on what its system found.

How transaction monitoring works 

Most monitoring runs on two engines that do different jobs. 

The first is rules-based. The firm sets thresholds and scenarios, such as cash deposits over a certain amount, rapid movement of funds in and out, or payments to a high-risk jurisdiction, and the system flags anything that matches. Rules are transparent and easy to explain to a regulator, which is why they remain the backbone of most programmes. Their weakness is that criminals who know the thresholds can structure activity to stay under them.

The second is behavioural, increasingly built on machine learning. Instead of fixed rules, it models what normal looks like for each customer and flags deviations, catching patterns a static rule would miss. It is better at novel typologies and at cutting noise, but harder to explain, which is the trade-off regulators weigh when a firm cannot show why the model flagged what it did.

The clearest example of what rules miss is structuring: breaking a large sum into a run of deposits, each kept just below the reporting threshold, so no single transaction trips a rule. A rules engine can catch the pattern, but only once someone has written the rule for it, which is part of why the behavioural layer earns its place.

Monitoring also runs on two clocks. Real-time transaction monitoring checks a payment as it happens and can hold or block it before it settles, which matters most for payments and fraud. Batch monitoring runs across the book after the fact, looking for patterns that only show up over days or weeks. A serious programme uses both. 

The false-positive problem

The hardest part of transaction monitoring isn’t missing the real thing. It is the sheer volume of alerts that turn out to be nothing.

The numbers are stark. Industry analysis from SAS puts the detection rate for cases that genuinely warrant investigation at 0.5 to 7 per cent, with more than 80 per cent of alerts turning out to be false positives. Every one of those false alerts still has to be reviewed by a person. A poorly tuned system can bury its analysts under millions of cases a year, most of them noise, while the real activity hides in the pile.

That is why tuning is the core craft of running a programme. Set the thresholds too tight and the alert volume becomes unmanageable and slows every payment. Set them too loose and a real case slips through. Getting that balance right is the hardest part of the job, and getting it wrong costs the firm either way. 

When monitoring fails: the fines

Regulators treat weak transaction monitoring as a serious failing in its own right, and the penalties have moved into the billions. Three cases show why compliance teams take it seriously.

The NatWest fine above came from a monitoring system that misclassified the risk of cash deposits. It was the first time the FCA brought criminal anti-money-laundering charges against a bank, and NatWest pleaded guilty.

In October 2024 the picture got larger. TD Bank pleaded guilty and agreed to pay more than $3 billion, including the largest penalty the US financial-crime regulator FinCEN has ever imposed on a bank, after admitting that roughly 92 per cent of its transactions, about $18.3 trillion, went unmonitored between 2018 and 2024. It became the first US bank to plead guilty to conspiracy to commit money laundering.

The Danske Bank case shows the same fault line. In December 2022 Danske pleaded guilty and forfeited about $2 billion after roughly €200 billion in suspicious payments moved through its small Estonian branch. Part of the fraud was that Danske had misrepresented the strength of its transaction-monitoring controls to the US banks it relied on. In each case the crime was detectable. The monitoring just didn’t catch what it should have.

Rules-based or AI: what regulators actually accept

Vendors selling behavioural monitoring often frame rules-based systems as obsolete. Regulators don’t see it that way. What supervisors want is a monitoring programme that is risk-based, properly tuned, and explainable, whichever engine sits underneath.

That is the practical constraint on machine learning in this space. A model that flags more accurately but cannot explain why it flagged a given transaction is hard to defend in an examination, because the firm has to show its work.

Most serious programmes now run a hybrid: rules for the clear-cut, transparent scenarios, and behavioural models layered on top to catch what the rules miss and to cut the false-positive load. In practice a rule still stops the obvious cash structuring, while the model surfaces the account whose behaviour has drifted in a way no single rule would catch. The direction of travel is towards more machine learning, as long as a firm can still explain what the model did and why. 

Transaction monitoring in the UAE and the Gulf 

For firms in the Gulf, transaction monitoring is a hard legal obligation, and the rules are specific. In the UAE, regulated entities must monitor customer activity on an ongoing basis and report suspicious transactions to the Financial Intelligence Unit through the mandatory goAML portal.

The framework is strict on the points that matter. Every entity supervised by the Central Bank of the UAE, from banks to exchange houses to designated non-financial businesses, has to register on goAML and keep the registration active. There is no minimum threshold, so any suspicious transaction, including an attempted one, has to be reported regardless of amount. 

The penalties for failing to file bite: fines run from AED 100,000 to AED 1 million, and can come with imprisonment. Firms licensed in the DIFC and ADGM free zones carry equivalent obligations under their own regulators. For a compliance team in the region, monitoring is part of the licence, and the regulator treats it that way. 

What transaction monitoring software has to do 

Because the volumes are enormous and the rules keep changing, firms of any size run dedicated transaction monitoring software rather than watch activity by hand. A buyer evaluating a system is really testing four things.

 It has to screen transactions against the firm’s rules and risk model, in real time where the payment type demands it. It has to tune to keep the false-positive rate workable without letting real cases through. It has to give analysts a clean case-management workflow, so an alert can be investigated, documented and escalated to a Suspicious Activity Report without leaving the system.

And it has to hold a full audit trail of what was flagged, cleared or reported, and why, because the regulator will ask to see it. A tool strong on detection but weak on the audit trail leaves the firm unable to prove it did the work.

Where monitoring programmes struggle

The pressures on a monitoring team are familiar ones. False positives dominate the workload, so most analyst time goes on alerts that come to nothing. The data underneath matters just as much, because a monitoring system is only as good as the customer and transaction data feeding it. And criminals keep changing method, so a scenario that caught last year’s laundering misses this year’s, which means the rules need constant review and retuning.

That is why supervisors treat monitoring as a running programme rather than a system a firm installs and leaves. The fines above all landed on firms that let the programme drift.

 

FAQs

What is transaction monitoring in simple terms?

It is the ongoing screening of customer transactions for signs of money laundering, terrorist financing or fraud, so a firm can flag suspicious activity and report it to the authorities. It runs in real time on payments and across the book over time.

What is the difference between rules-based and AI transaction monitoring?

Rules-based monitoring flags transactions that match set thresholds and scenarios, and is transparent and easy to explain. Behavioural or AI monitoring models normal behaviour and flags deviations, catching more but being harder to explain. Most firms now use both. 

Why does transaction monitoring produce so many false positives?

Because systems are tuned to catch anything that might be suspicious, they flag large numbers of legitimate transactions. Industry figures put false positives at more than 80 per cent of alerts, and every one has to be reviewed by a person. 

What happens when a transaction monitoring alert is confirmed?

The analyst escalates it to a Suspicious Activity Report, filed with the national financial-intelligence unit, often within a set window such as 30 days. In some cases the firm also freezes or blocks the funds.

What are the rules for transaction monitoring in the UAE?

UAE firms supervised by the Central Bank must monitor transactions on an ongoing basis, register on the goAML portal, and report suspicious transactions to the Financial Intelligence Unit with no minimum threshold. Failure to file can bring fines from AED 100,000 to AED 1 million.

Next read

Transaction monitoring is one control in a firm’s wider financial-crime programme. For the rest of our regtech and compliance coverage, see the Compliance hub.