Transaction monitoring audit and validation
Is your monitoring catching what it should? Find out before your examiner asks.
An independent audit of your monitoring program's documentation, and a validation snapshot over your own alerts. Start with the documents and no data at all, or run a parallel read of your live alerts and dispositions and see where the results differ.
Your problem
Rules set years ago, and nobody's checked them since
- Your monitoring rules and thresholds were set when the business looked different. You don't know whether they still fit your customers and products.
- The documentation says one thing, and the system may do another. Examiners look for that gap.
- Alerts get closed every day, but nobody outside the team has looked at whether those decisions hold up.
- An exam, a sponsor bank review or a prior finding is asking you to show the program works, and you need an answer you can put in writing.
What you get
Two ways in, one written answer
- A documentation audit that needs no data. We read your monitoring policy, rule descriptions, thresholds, tuning records and alert procedures against your risk assessment and the rules that apply to you, and report where they fall short or don't line up.
- A validation snapshot over your own alerts and dispositions. We run a parallel read over the same period and report the differences: activity your rules didn't alert on, alerts that were closed when the facts pointed another way, and rules that produce noise and little else.
- Findings tied to evidence. Each one names the rule or procedure involved and points to the records that show it.
- A written report you can hand to your board, your sponsor bank or your examiner.
How we do it
Read the documents, then read the alerts
- For the documentation audit, you send us your monitoring documents. We don't need access to any customer or transaction data.
- For the validation snapshot, we take an extract of your transactions, alerts and dispositions for an agreed period and run our own read alongside yours.
- A practitioner reviews every difference before it goes in the report, so you're not handed a list of raw exceptions.
- We have no role in running the program we review.
Where the boundary sits: the snapshot is an independent read of how your monitoring performs over a period. It doesn't replace a model validation by an independent validator, and if your regulator or your policy requires one, you'll still need it. The snapshot tells you what to bring to that validation.
How the work is done
The audit you already buy, performed by an engine.
- Every record testedControls are tested against the full population of accounts and transactions, not a sample of twenty-five.
- Every requirement citedEach requirement the work runs against is cited to the rule it comes from, with the facts behind it labelled.
- Findings pricedFindings arrive priced in dollars, so remediation is ordered by what each gap is worth.
- A signed reportThe report is signed, and any reader can check that nothing in it changed after signing.
Pricing
Scoped to your program
The documentation audit and the validation snapshot are priced separately. You can buy either one or both, and the price depends on your size and the volume in scope.
Priced at scoping. How pricing works
The published method
How this is normally done
The regulator's and the standard-setter's own method for this work, explained in plain English and cited to the source. We have nothing to hide about how we do it: check our process against it.
- ReferenceTransaction Monitoring: How AML Monitoring Programs WorkWhat transaction monitoring is, the parts of a monitoring program, the path from alert to SAR, tuning and threshold testing, model risk guidance, and NYDFS Part 504.
- ComparisonAML Audit vs. Independent TestingThe two terms get used interchangeably but are not identical. What each means, where they overlap, and which one satisfies the third pillar.
- Field GuideBSA/AML Exam Preparation: A Fintech's Field GuideWhat the exam tests, how it unfolds, the documents examiners request, where fintechs get caught, and a runbook to be ready before the entry letter arrives.
What happens next
Three steps from here.
- 01
A call with our founder
Tell us about your monitoring system, what's prompting the review and who'll read the result. We'll tell you plainly whether we're the right fit.
- 02
A written scope
Audit, snapshot or both, the period, what you'll receive and the price, in writing before you commit.
- 03
The review and the report
We read the documents, run the snapshot if it's in scope, and a practitioner reviews the findings before you receive the report.