Transaction monitoring is the process by which a financial institution reviews customer activity after it occurs to identify transactions that may be suspicious and reportable. A monitoring program consists of detection scenarios with thresholds, customer segmentation, an alert review and case management process, a documented decision on whether to file a suspicious activity report (SAR), and periodic tuning and testing. For banks, the SAR is due within 30 calendar days of initial detection of the facts that may support filing, under 31 CFR 1020.320.
Transaction monitoring is the process by which a financial institution reviews customer transactions, usually after they settle, to identify activity that may be unusual or suspicious and that may require a suspicious activity report (SAR). It is the detection component of the ongoing customer due diligence that the bank anti-money laundering program rule requires: 31 CFR 1020.210 calls for risk-based procedures that include "conducting ongoing monitoring to identify and report suspicious transactions." Monitoring can be manual, automated, or a combination, and the same program structure applies whichever method an institution uses.
This article covers the parts of a monitoring program, the path from alert to SAR, how programs are tuned and tested, and the supervisory expectations that govern them.
Legal basis
The duty to monitor is derived from the duty to report. Under 31 CFR 1020.320, a bank must file a SAR for a transaction conducted by, at, or through the bank that involves or aggregates at least $5,000 where the bank knows, suspects, or has reason to suspect that the transaction involves illicit funds, is designed to evade Bank Secrecy Act requirements, has no business or apparent lawful purpose, or uses the bank to facilitate criminal activity. Parallel reporting rules apply to money services businesses, broker-dealers, and other covered institutions, with their own thresholds. An institution cannot report what it does not detect, so the reporting rule presupposes a system that surfaces reportable activity.
The FFIEC BSA/AML Examination Manual describes the monitoring process in four stages in its Appendix S (Key Suspicious Activity Monitoring Components): identification of unusual activity, alert management, SAR decision making, and SAR completion and filing. Examiners assess each stage separately.
Components of a monitoring program
| Component | What it is |
|---|---|
| Scenarios and rules | The detection logic. A scenario describes a pattern associated with a money-laundering or fraud typology, such as structuring cash deposits below the currency transaction report threshold, rapid movement of funds in and out of an account, or wires to higher-risk jurisdictions. |
| Thresholds and parameters | The values that decide when a scenario fires: dollar amounts, transaction counts, time windows, and percentage changes against a customer's own history. |
| Segmentation | The grouping of customers with similar expected behavior (for example, retail consumers, small businesses, money services businesses) so that each group is measured against thresholds suited to it. Segments usually draw on the customer risk rating. |
| Data inputs | The transaction, account, and customer data the system reads. Monitoring is only as complete as the data feeding it; an unmapped product or payment channel is an unmonitored one. |
| Alert review and case management | The workflow in which analysts review alerts, gather context, close alerts with a documented rationale, or escalate them to an investigation case. |
| Governance | Written procedures, ownership of each scenario, change control over thresholds, management reporting, and periodic independent review. |
Rules-based systems remain common, and many institutions supplement them with statistical or machine-learning models that score activity or prioritize alerts. The choice affects which supervisory model-risk guidance applies, discussed below.
From alert to SAR
An alert is a signal that activity met a scenario's conditions. It is not a finding. The first-level review decides whether the activity is explained by what the institution knows about the customer: occupation or business type, expected activity recorded at onboarding, and prior history. Alerts that are explained are closed with a written rationale. Alerts that are not explained are escalated to a case, where an investigator reviews the broader relationship, related accounts, counterparties, and open-source information.
The FFIEC manual states that SAR decisions should consider all available customer due diligence and enhanced due diligence information, that decisions to file or not to file should be supported and reasonable, and that institutions should document decisions not to file. The manual also states that the volume of alerts and investigations should not be tailored solely to meet existing staffing levels.
Timing is fixed by regulation. Under 31 CFR 1020.320(b)(3), a bank must file a SAR no later than 30 calendar days after the date of initial detection of facts that may constitute a basis for filing. If no suspect is identified at that date, the bank may take an additional 30 days to identify one, but reporting may not be delayed more than 60 calendar days after initial detection. Where a violation requires immediate attention, such as an ongoing money-laundering scheme, the bank must also notify law enforcement by telephone. The bank must keep a copy of each SAR and its supporting documentation for five years from filing (31 CFR 1020.320(d)). The narrative written at the end of this process is covered in the SAR narrative guide.
Tuning and threshold testing
Tuning is the periodic adjustment of scenarios, thresholds, and segments so that the system detects the activity it is meant to detect without generating alerts that carry no information. A scenario set to a low threshold produces large alert volumes and slow review; a scenario set too high misses reportable activity. Tuning uses the institution's own alert outcomes as evidence.
Two standard techniques are used:
- Above-the-line testing examines alerts the system already produces, measuring how many led to cases or SARs. A threshold may be raised where alerts just above it rarely lead to anything, provided the analysis is documented.
- Below-the-line testing lowers a threshold in a test environment and samples the activity that would have alerted but did not. Analysts review the sample to determine whether reportable activity sits below the current setting. If it does, the threshold is too high.
Each tuning change is recorded with the data examined, the analysis performed, the approval obtained, and the date the change took effect. A threshold change without a supporting record is difficult to defend in an examination, because the examiner cannot tell whether it was made for risk reasons or to reduce workload.
Model risk management expectations
From 2011 to 2026, the federal banking agencies applied their model risk management guidance, SR 11-7 and OCC Bulletin 2011-12, to many monitoring systems. In April 2021 the agencies, with FinCEN and the NCUA, issued the Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance (SR 21-8, OCC Bulletin 2021-19), which stated that it did not alter existing BSA/AML legal or regulatory requirements or establish new supervisory expectations, and that no specific model risk management framework was required.
On April 17, 2026, the Federal Reserve, OCC, and FDIC issued revised Guidance on Model Risk Management (SR 26-2, OCC Bulletin 2026-13), which supersedes SR 11-7, OCC Bulletin 2011-12, and the 2021 BSA/AML statement. The revised guidance defines a model as a complex quantitative method that applies statistical, economic, or financial theories to produce quantitative estimates, and it excludes deterministic rule-based processes that have no such theory underpinning them. It is expected to be most relevant to banking organizations with more than $30 billion in total assets, and it places generative and agentic AI models outside its scope. Its core practices remain validation of conceptual soundness, outcomes analysis that compares model outputs with real-world results, ongoing monitoring, documentation, and specific attention to vendor models.
In practice, a purely rules-based monitoring system may fall outside the revised definition of a model, while a statistical risk score or machine-learning alert prioritizer is more likely to fall within it. Whether or not the guidance applies, examiners still assess whether the monitoring system is reasonably designed and tested for the institution's risk.
New York: 3 NYCRR Part 504
New York imposes a specific monitoring standard on institutions regulated by the Department of Financial Services, including banks, money transmitters, and check cashers. Under 3 NYCRR 504.3(a), the transaction monitoring program must be based on the institution's risk assessment; be reviewed and updated at risk-based intervals; include detection scenarios with threshold values designed to detect potential money laundering; undergo end-to-end, pre- and post-implementation testing; be supported by documentation of current scenarios and their assumptions, parameters, and thresholds; include protocols for investigating alerts; and be subject to ongoing analysis of whether the scenarios remain relevant. Section 504.3(c) adds data requirements, including identification of data sources and validation of data integrity. Under 504.4, each regulated institution submits an annual board resolution or senior officer compliance finding by April 15.
Who operates and reviews monitoring
Monitoring is normally operated by a financial intelligence or investigations team within the compliance function, under the BSA officer. Scenario design and tuning may involve compliance analysts and data specialists. Independent review of the program comes from internal audit or an outside tester as part of BSA/AML independent testing, which the FFIEC manual expects to evaluate the alert process, alert management, SAR decision making, and filing. Monitoring coverage should also trace back to the institution's risk assessment, so that each higher-risk product, channel, and customer segment has scenarios assigned to it.
Primary sources
- 31 CFR 1020.320: Suspicious activity reporting by banks: the $5,000 threshold, the 30- and 60-day filing deadlines, and five-year retention.
- 31 CFR 1020.210: Anti-money laundering program requirements for banks, including ongoing monitoring to identify and report suspicious transactions.
- FFIEC BSA/AML Examination Manual, Suspicious Activity Reporting: Examiner expectations for alert management, SAR decision making, and documentation of decisions not to file.
- FFIEC BSA/AML Examination Manual, Appendix S: Key suspicious activity monitoring components: identification, alert management, SAR decision making, and filing.
- SR 26-2, Revised Guidance on Model Risk Management (April 17, 2026): Interagency guidance that supersedes SR 11-7 and SR 21-8; defines a model and excludes deterministic rule-based processes.
- OCC Bulletin 2026-13, Model Risk Management: Revised Guidance: The OCC issuance of the revised guidance; rescinds OCC Bulletins 2011-12 and 2021-19.
- Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance (April 2021): The 2021 statement (SR 21-8, OCC Bulletin 2021-19), superseded in April 2026; retained here for history.
- 3 NYCRR Part 504: New York DFS transaction monitoring and filtering program requirements and annual certification.