close
breadcrumb right arrowGlossary
breadcrumb right arrowTransaction Monitoring

Transaction monitoring is the ongoing review of customer transactions to spot activity that doesn't fit what a bank knows about the customer. US banks rely on it to meet their Bank Secrecy Act (BSA) duty to identify suspicious activity and report it to FinCEN.

How transaction monitoring works

Most programs follow the same loop. Transactions flow from core banking, card, wire and ACH systems into a monitoring tool. Rules or models compare each transaction, or a pattern of them, against expected behavior for that customer and product. Anything unusual becomes an alert. An analyst investigates the alert, documents the reasoning, and either closes it or escalates it to a case. Cases that meet the reporting standard become Suspicious Activity Reports (SARs).

  • Data intake: transactions, customer due diligence data, and KYC risk ratings
  • Detection: rules, thresholds, and scenarios (rule-based) or anomaly and behavioral models
  • Alert triage and investigation, with documented disposition
  • Case management and SAR decisioning
  • Tuning: adjusting thresholds and scenarios as the bank's risk profile changes

The FFIEC BSA/AML Examination Manual says monitoring can be manual (reports such as large currency activity, funds transfers, or monetary instrument logs) or automated surveillance, and that thresholds and scenarios should be risk-based and fit the bank's customers, products, services, and geographies. In an exam, the question is whether the monitoring fits the bank's risk profile.

A US example: structuring below the CTR line

Banks must file a Currency Transaction Report (CTR) for cash transactions over $10,000 in a business day (31 CFR 1010.311), and they aggregate multiple cash transactions by or for the same person that day. A customer who knows this might deposit $9,500 on Monday, $9,800 on Tuesday, and $9,700 at a different branch on Wednesday. No single deposit triggers a CTR.

A sub-threshold cash scenario flags the pattern. The analyst checks the customer's profile: a payroll-heavy small business with a history of large cash deposits looks different from a salaried individual who never handled cash before. If the activity totals at least $5,000 and the bank suspects it is designed to evade BSA reporting, 31 CFR 1020.320 requires a SAR, generally within 30 calendar days of initial detection (up to 60 days if no suspect has been identified). Structuring itself is a federal crime, so this is one of the most common reasons alerts escalate.

A deposit near $10,000 is not suspicious on its own, and a CTR doesn't automatically mean a SAR. Each decision depends on the facts of the case.

Rule-based vs. AI-assisted monitoring

Rule-based systems are transparent and easy to explain to examiners, but they generate a lot of false positives, so analyst time goes to closing alerts that were never risky. Machine learning and behavioral models can rank alerts and find patterns rules miss, but they bring model risk management obligations: validation, documentation, and explainability. In practice many US banks run both, with rules as the baseline and models for prioritization. AI agents are increasingly used on the investigation side, gathering customer history, drafting the narrative, and leaving the decision with a human investigator.

Frequently asked questions

Is transaction monitoring required by US law?

The BSA and its regulations require banks to report suspicious activity and to maintain an AML program with internal controls. The FFIEC manual treats suspicious activity monitoring as a core part of those controls, so in practice every US bank needs some form of it, scaled to its risk.

What's the difference between transaction monitoring and sanctions screening?

Sanctions screening checks names and parties against lists such as OFAC's, usually before a payment goes through. Transaction monitoring looks at behavior over time, usually after the fact, to find patterns like structuring or rapid movement of funds.

What triggers a transaction monitoring alert?

Common triggers include cash activity just below the $10,000 CTR threshold, sudden spikes against a customer's normal volume, rapid in-and-out wires, transfers to high-risk geographies, and activity that doesn't match the stated business.

How long does a bank have to file a SAR after an alert?

Generally 30 calendar days from initial detection of facts that may constitute a basis for filing, extendable to 60 days if no suspect has been identified. The clock starts at detection, not when the alert fired, which is why investigation backlogs are a real compliance risk.

Sources

  • 31 CFR 1020.320, Reports by banks of suspicious transactions (law.cornell.edu/cfr/text/31/1020.320)
  • 31 CFR 1010.311, Filing obligations for currency transaction reports
  • FFIEC BSA/AML Examination Manual, Suspicious Activity Reporting section (bsaaml.ffiec.gov)