What it means
The basic mechanism is pattern matching against expected behaviour. A monitoring system holds a picture of what normal looks like for each customer and raises an alert whenever activity departs from it, such as sudden large cash deposits or payments to unexpected countries.
Rules-based monitoring uses explicit thresholds, for example flagging any transfer above a set amount or several deposits just below a reporting limit. Model-based monitoring instead compares behaviour against statistical norms, which catches subtler patterns but is harder to explain to a regulator.
The output is alerts, and the volume of them is the central operational challenge. The overwhelming majority turn out to be innocent, so the real work lies in triaging efficiently while making sure genuinely suspicious activity is not lost in the noise.
Alerts that survive review are escalated into cases, and cases that remain suspicious result in a report to the relevant financial intelligence unit. In many jurisdictions the firm must file that report without telling the customer, a restriction usually described as a prohibition on tipping off.
The cost is substantial and falls mainly on people rather than software. A poorly tuned system that generates tens of thousands of false alerts a month will absorb an entire compliance team's capacity while adding very little genuine protection.
Regulators therefore expect firms to tune their rules, test them and document the reasoning. Periodic threshold reviews, above-the-line and below-the-line testing, and a clear record of why each parameter was chosen are now standard expectations rather than optional refinements.
In practice
Real-world examples.
Example
A payments company notices that one merchant account is receiving hundreds of small card payments from unrelated cards within minutes. The monitoring rule flags the velocity pattern, and the account is frozen before a card testing fraud escalates.
Example
A retail bank's system alerts on a customer whose salary account suddenly receives nine cash deposits of $9,500 in a fortnight. The pattern of amounts sitting just under a reporting threshold is a textbook structuring indicator, and the case is escalated the same day.
Example
A crypto exchange tunes its thresholds after finding that 99% of its alerts were closed with no action. Raising one threshold and adding a customer risk score cuts alert volume by 40% while increasing the proportion that lead to genuine reports.
Think of it
“Transaction monitoring is watching for suspicious patterns-automated surveillance.
Formula
Calculation
False positive rate = (total alerts - alerts resulting in a report) / total alerts. Review cost = number of alerts x average review time x analyst hourly cost.
A mid sized bank's system generates 5,000 alerts a month. Analysts escalate 250 of them into full cases, a 5% escalation rate, and 100 of those cases end in a suspicious activity report being filed.
The false positive rate is therefore (5,000 - 100) / 5,000 = 0.98, or 98%. If each alert takes 15 minutes to review, the monthly workload is 5,000 x 0.25 hours = 1,250 hours, and at a fully loaded analyst cost of $40 an hour that is 1,250 x $40 = $50,000 a month, or $600,000 a year, which works out at $500 of review effort for every report actually filed.Case study
Seen in the real world.
This is an illustrative and entirely fictional example. Larkfield Savings Bank, an invented regional lender, implemented a monitoring system quickly to satisfy a regulatory deadline and set every threshold conservatively low on the assumption that more alerts meant more safety.
The result was 12,000 alerts a month against a customer base of 90,000, reviewed by a team of six analysts who could realistically clear about half of them. A backlog built up, older alerts were closed in bulk to catch up, and the fictional regulator's inspection found that a genuinely suspicious account had sat unreviewed for eleven weeks.
Larkfield's remediation involved segmenting customers into risk bands, setting different thresholds for each band, and testing the changes against a year of historical data before going live. Alert volume fell to roughly 4,000 a month, the backlog cleared, and the number of reports actually filed rose rather than fell, which was the point the invented board had originally missed.
Watch out
Common mistakes.
- Assuming that lower thresholds and more alerts automatically mean stronger controls, when they usually mean an overwhelmed team and a growing backlog.
- Applying identical rules to every customer regardless of risk, so that a small retail saver is monitored the same way as a high risk corporate account.
- Treating monitoring as a technology project, when the quality of customer data and the skill of the review team matter far more than the software.
Questions
People also ask.
What counts as a good false positive rate?
Rates above 90% are entirely normal in this field, so the more useful measures are backlog size, review quality and the number of genuine reports produced.
Can a small non-bank business be required to do this?
Yes, obligations extend to many money service businesses, estate agents, accountants, casinos and dealers in high value goods depending on the jurisdiction.
What is tipping off?
It is warning a customer that they are being investigated or reported, which is a criminal offence in most jurisdictions and one of the strictest rules a compliance team works under.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%