Transaction monitoring is the ongoing review of customer transactions to spot activity that doesn't fit what a bank knows about the customer. US banks rely on it to meet their Bank Secrecy Act (BSA) duty to identify suspicious activity and report it to FinCEN.
Most programs follow the same loop. Transactions flow from core banking, card, wire and ACH systems into a monitoring tool. Rules or models compare each transaction, or a pattern of them, against expected behavior for that customer and product. Anything unusual becomes an alert. An analyst investigates the alert, documents the reasoning, and either closes it or escalates it to a case. Cases that meet the reporting standard become Suspicious Activity Reports (SARs).
The FFIEC BSA/AML Examination Manual says monitoring can be manual (reports such as large currency activity, funds transfers, or monetary instrument logs) or automated surveillance, and that thresholds and scenarios should be risk-based and fit the bank's customers, products, services, and geographies. In an exam, the question is whether the monitoring fits the bank's risk profile.
Banks must file a Currency Transaction Report (CTR) for cash transactions over $10,000 in a business day (31 CFR 1010.311), and they aggregate multiple cash transactions by or for the same person that day. A customer who knows this might deposit $9,500 on Monday, $9,800 on Tuesday, and $9,700 at a different branch on Wednesday. No single deposit triggers a CTR.
A sub-threshold cash scenario flags the pattern. The analyst checks the customer's profile: a payroll-heavy small business with a history of large cash deposits looks different from a salaried individual who never handled cash before. If the activity totals at least $5,000 and the bank suspects it is designed to evade BSA reporting, 31 CFR 1020.320 requires a SAR, generally within 30 calendar days of initial detection (up to 60 days if no suspect has been identified). Structuring itself is a federal crime, so this is one of the most common reasons alerts escalate.
A deposit near $10,000 is not suspicious on its own, and a CTR doesn't automatically mean a SAR. Each decision depends on the facts of the case.
Rule-based systems are transparent and easy to explain to examiners, but they generate a lot of false positives, so analyst time goes to closing alerts that were never risky. Machine learning and behavioral models can rank alerts and find patterns rules miss, but they bring model risk management obligations: validation, documentation, and explainability. In practice many US banks run both, with rules as the baseline and models for prioritization. AI agents are increasingly used on the investigation side, gathering customer history, drafting the narrative, and leaving the decision with a human investigator.
The BSA and its regulations require banks to report suspicious activity and to maintain an AML program with internal controls. The FFIEC manual treats suspicious activity monitoring as a core part of those controls, so in practice every US bank needs some form of it, scaled to its risk.
Sanctions screening checks names and parties against lists such as OFAC's, usually before a payment goes through. Transaction monitoring looks at behavior over time, usually after the fact, to find patterns like structuring or rapid movement of funds.
Common triggers include cash activity just below the $10,000 CTR threshold, sudden spikes against a customer's normal volume, rapid in-and-out wires, transfers to high-risk geographies, and activity that doesn't match the stated business.
Generally 30 calendar days from initial detection of facts that may constitute a basis for filing, extendable to 60 days if no suspect has been identified. The clock starts at detection, not when the alert fired, which is why investigation backlogs are a real compliance risk.