Rules + models in one engine
80+ FATF-typology rule templates plus supervised anomaly models. Author, backtest and deploy without redeploying code.
AML transaction monitoring
Catch structuring, layering, mule networks and sanctions evasion without drowning analysts in false positives. ComplianceSuite pairs 80+ FATF-typology rules with behavioural models, unifies alerts with sanctions and PEP context, and files SARs to FinCEN, NCA, FIU-NET, MAS STRO and FINTRAC in the format each regulator expects.
Definition
AML transaction monitoring is the automated, ongoing review of customer transactions against risk-based rules and behavioural models to detect money laundering, terrorist financing, sanctions evasion and fraud. It is a legal requirement under FATF Recommendation 20, the EU AMLR, the US Bank Secrecy Act, and equivalent regimes in the UK, Singapore, Canada and 90+ other jurisdictions.
Effective monitoring combines rules (deterministic thresholds and typologies) with models (peer-group anomaly detection and behavioural baselines), enriched by the customer's EDD profile and adverse media. Suspicious activity triggers a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) to the national Financial Intelligence Unit — mandatory, protected by safe-harbour, and typically due within 30 days.
See our guides to AML and the AML glossary.
Capabilities
80+ FATF-typology rule templates plus supervised anomaly models. Author, backtest and deploy without redeploying code.
Sub-300 ms inline screening for sanctions and high-risk corridors; rolling-window behavioural detection for structuring and layering.
Every alert shows the triggered rule, the transaction graph, and the customer context — no black box.
Alerts inherit PEP, sanctions and adverse-media status. No context-switching between systems.
Structured filing to FinCEN, NCA, FIU-NET, MAS STRO, FINTRAC and 20+ FIUs with pre-populated narratives.
Analyst dispositions retrain the model weekly; auto-suppress repeat false positives with documented rationale.
How it works
Real-time stream via API/Kafka or batch file. Enriched with customer risk profile, PEP/sanctions status, historical baseline and peer-group segment.
80+ typology rules (structuring, layering, mule) plus behavioural models score every transaction. High-risk-corridor and sanctions checks run inline in real time.
Case opens with transaction graph, customer 360, prior alerts and rule rationale. Analyst dispositions in a structured form; escalations routed to L2 / MLRO.
Pre-populated FIU-specific templates (FinCEN 111, NCA SAR, FIU-NET STR, MAS STRO). Digital signature, submission tracking and audit trail.
Example alerts
| Rule | Scenario | Action |
|---|---|---|
| Structuring — cash deposits | Retail customer makes 9 cash deposits of $9,500 over 12 days across 3 branches | Alert routed to L2. Analyst confirms structuring pattern. SAR filed with FinCEN within 30 days. Customer risk score upgraded to high; EDD refresh triggered. |
| High-risk corridor + velocity | SME customer sends 14 wires totalling €3.2M to a new counterparty in a FATF grey-listed jurisdiction over 5 days | Real-time hold on wire #15. Case opens with source-of-funds request, sanctions re-screen of counterparty, STR filing to national FIU. |
| Peer-group anomaly | Freelance-designer customer receives €180K inbound from a shell company — 24× their monthly baseline | Behavioural model flags outlier. Analyst reviews; documented rationale required. If cleared → auto-suppress rule for 90 days with review reminder. |
Regulatory coverage
| Regime | Scope | Requirement |
|---|---|---|
| FATF Recommendation 20 | Global standard | Obliged entities must promptly report suspicious transactions to the national FIU. Requires ongoing monitoring capable of detecting complex, unusual and structured patterns. |
| EU AMLR (Reg. 2024/1624) | EU 27 | Art. 20–23 require risk-based ongoing monitoring, scrutiny of all complex/unusual transactions, and STR filing to the national FIU without delay. |
| US Bank Secrecy Act / FinCEN | United States | 31 CFR 1020.320 requires SAR filing within 30 days of detection for transactions aggregating ≥$5,000 that are suspicious. |
| UK MLR 2017 Reg. 28 | United Kingdom | Ongoing monitoring of transactions and source of funds. SARs to NCA under POCA 2002 s.330; DAML/DATF requests where required. |
| MAS Notice 626 §7 | Singapore | Continuous monitoring against customer's risk profile; STR to STRO under CDSA within 15 business days. |
| FINTRAC (PCMLTFA) | Canada | STRs on reasonable grounds to suspect; LCTRs on all cash transactions ≥CAD 10,000; EFTRs on cross-border transfers ≥CAD 10,000. |
AML transaction monitoring is the ongoing, automated review of customer transactions against risk-based rules and behavioural models to detect money laundering, terrorist financing, sanctions evasion and fraud. It is a legal requirement under FATF Recommendation 20, EU AMLD/AMLR, US Bank Secrecy Act, UK MLR 2017 and equivalent regimes.
Threshold rules (single or aggregated transactions above a value), velocity rules (frequency in a rolling window), structuring / smurfing (multiple transactions just below a reporting threshold), high-risk corridors (transactions to/from FATF grey or black-listed jurisdictions), round-tripping, dormant-then-active accounts, and peer-group anomaly detection.
Sanctions screening runs at the payment level against sanctions lists (OFAC, UN, EU, UK) to block or hold payments to designated parties. Transaction monitoring runs across the customer's full behaviour — patterns, frequencies, amounts, counterparties — to identify suspicious activity that may not touch a sanctioned party. Both are legally required, and ComplianceSuite unifies them.
A Suspicious Activity Report (SAR in the US and UK) or Suspicious Transaction Report (STR in EU / most jurisdictions) is the regulatory filing an obliged entity submits to its FIU (FinCEN, NCA, FIU-NET, MAS STRO, FINTRAC) when a transaction or pattern gives rise to suspicion of ML/TF. Filing is mandatory, protected by safe-harbour, and typically due within 30 days of the analyst decision.
Legacy rule-based systems commonly produce 90–98% false positives. A well-tuned modern platform combining rules, peer-group segmentation and behavioural models targets under 60% false positives on retail books. ComplianceSuite averages 42% across live tier-1 customers, measured on 1.4M alerts (2025).
Both. Sanctions and high-risk-corridor checks run in real time (<300 ms) inline with the payment. Behavioural monitoring, structuring detection and peer-group anomalies run on rolling windows post-transaction, with same-day alerts.
Yes. The rules engine ships with 80+ FATF-typology templates (structuring, layering, round-tripping, mule accounts) and lets you author custom rules in a visual editor with backtest-on-historical-data before deployment.
Every alert opens a case with the full customer profile, PEP/sanctions/adverse-media status, transaction graph, historical alerts and rule rationale. Analyst dispositions (true positive, false positive, escalate, file SAR) feed back into the model to auto-clear repeat false positives.
Replay 30 days of your own transaction data through ComplianceSuite. We'll show you the alerts your current system missed — and the false positives it created.
Learn more
We use essential cookies to make ComplianceSuite work. With your consent, we'll also use analytics and marketing cookies to improve the site and measure campaign performance. You can change your choice at any time. Read our Privacy Policy and Cookie Notice.