A large bank might process millions of transactions a day. Somewhere in that flood, a small number are moving criminal money. Transaction monitoring is how firms find them.
This guide explains how it works, in plain language, with no assumed background.
The basic idea
Transaction monitoring is the process of reviewing customer transactions to spot activity that does not fit what you would expect from that particular customer.
Notice the phrase from that particular customer. There is no universal definition of a suspicious transaction. A ₹20 lakh deposit is unremarkable for an established jewellery business and highly unusual for a salaried graduate. Monitoring is always relative to what normal looks like for that person.
That is why KYC matters so much. Without knowing who your customer is and what they do, you have nothing to compare their behaviour against.
How the system actually works
Software reviews transaction data against a set of defined rules, often called scenarios. Each scenario looks for a specific pattern — cash deposits above a threshold within a set period, funds moving in and out rapidly, transfers to high-risk countries, and so on.
When a transaction or pattern meets the conditions of a scenario, the system generates an alert.
An alert is not an accusation. It is simply a prompt for a human to look more closely.
Real-time versus post-transaction monitoring
Real-time monitoring happens before a transaction completes and can block it. Sanctions screening on outgoing payments is the classic example, because you cannot undo sending money to a sanctioned party.
Post-transaction monitoring reviews activity after it has settled, usually overnight in batches. This is what most AML monitoring is, because detecting a pattern requires seeing behaviour over time.
What triggers an alert
Scenarios are built around known criminal behaviour. Some of the most common:
Threshold rules trigger when an amount crosses a set limit — for example, cash deposits above a defined value in a single day.
Velocity rules look at how quickly money moves. Funds arriving and leaving almost immediately, leaving little balance behind, is a classic pattern.
Structuring detection looks for several transactions deliberately kept just below a reporting threshold.
Geographic rules flag transfers to or from high-risk jurisdictions where there is no obvious business reason.
Behavioural rules compare current activity against the customer's own history, flagging sudden departures from their normal pattern.
Common red flags
A red flag is an indicator that something might be suspicious. It is a reason to look closer — not a conclusion. A single red flag often has a perfectly innocent explanation. Several together, or one the customer cannot explain, is what builds genuine suspicion.
Frequently seen examples include:
- Deposits or transfers inconsistent with the customer's stated income or business
- Funds arriving and leaving almost immediately
- Multiple transactions just below a reporting threshold
- Sudden activity on a long-dormant account
- Round-figure amounts repeated frequently
- Transfers to high-risk jurisdictions with no business rationale
- A customer who is evasive when asked the purpose of a payment
The false positive problem
Here is the reality of the job: most alerts turn out to be nothing.
An alert that proves harmless after review is called a false positive. In many firms, well over 90% of alerts fall into this category.
That matters for two reasons. Analysts spend most of their time on activity that is entirely legitimate, and genuinely suspicious cases risk being buried in the noise.
The opposite problem is worse. A false negative is genuinely suspicious activity that the system never flagged at all. Nobody ever looks at it, so the risk passes through undetected.
Firms manage this balance through threshold tuning — adjusting the amounts, counts and time windows in each scenario so they catch real risk without drowning the team. Set thresholds too loose and you get a flood of alerts. Set them too tight and things slip through. Tuning is a documented risk decision, not a technical tweak.
What an analyst actually does
When an alert lands, the analyst works through it in a consistent order:
- Understand the trigger. Which scenario fired, and on which transactions?
- Review the customer. What is their occupation or business, expected activity and risk rating?
- Put it in context. Look at account history, counterparties, and whether funds stayed or moved on.
- Gather more information if needed — internal records, public sources, or a question to the relationship manager.
- Decide and document. Either close the alert with clear reasoning, or escalate it.
That last step is more important than beginners expect. Your case notes are the record that the decision was made properly. Regulators, auditors and quality reviewers judge the work by what is written, not by what you remember. A well-reasoned closure that is fully documented is defensible. A correct decision with no explanation is not.
When something is genuinely suspicious
If the activity cannot be explained, it is escalated — usually to a senior analyst, then to the Money Laundering Reporting Officer, who decides whether to file a Suspicious Activity Report with the national Financial Intelligence Unit.
The standard for filing is reasonable suspicion, not proof. You do not need to identify the underlying crime.
One rule matters absolutely here: you must never tell the customer. Warning someone that they have been reported is called tipping off, and it is a criminal offence in most jurisdictions.
Is transaction monitoring a good career?
It is one of the most common entry points into financial crime compliance, and it teaches you skills that transfer well — investigation, structured reasoning, and clear written English.
The work is genuinely analytical, but be realistic: there is volume, there is repetition, and a large share of what you review will be perfectly ordinary. Analysts who do well are the ones who stay consistent on their hundredth alert of the week, not just their first.
Where to start
Learn the typologies — the patterns criminals actually use — because scenarios are built around them. Get comfortable explaining your reasoning in writing, since that is most of the job. And practise the investigation sequence above until you can say it without thinking, because it is the question you will be asked in every interview.
