TransÂaction monitoring does not prove money laundering. It identifies activity that is inconÂsistent with a customer, account or business model and therefore needs documented review. A sound analysis combines transÂaction data with current customer due diligence, counterÂparties, geography and the stated purpose of the relationship.
Start with the customer and the expected activity
Before searching for anomalies, record the customer’s products, expected volumes, source of funds, counterÂparties, jurisÂdicÂtions and normal transÂaction frequency. The FCA’s financial-crime guidance describes ongoing monitoring as checking whether transÂacÂtions remain consistent with what the firm knows about the customer and keeping due-diligence inforÂmation current.
A static threshold is rarely enough. A £50,000 transfer may be normal for one wholesale client and excepÂtional for another. Segment customers by compaÂrable risk and activity so that alerts reflect genuine deviation rather than arbitrary amounts.
Build a complete transaction view
Bring together account entries, payment instrucÂtions, benefiÂciary and origiÂnator data, device or access inforÂmation where lawful, currency converÂsions, chargeÂbacks, linked accounts and relevant customer-contact records. Normalise names, dates, currencies and identiÂfiers before analysis. For cryptoasset activity, the same principle applies, although blockchain analytics must be connected to verified identities and off-chain evidence.
Test patterns, not isolated red flags
Useful tests include rapid movement of recently received funds, repeated payments just below review thresholds, circular flows, unexplained pass-through activity, dormant accounts becoming active, payments involving unrelated third parties, abrupt geographic changes and activity inconÂsistent with the customer’s business. None is proof by itself.
| Pattern | Questions for the analyst |
|---|---|
| Rapid in-and-out movement | What is the commercial purpose, who controls both ends, and is value retained? |
| Many small linked transfers | Are the parties, devices, addresses or benefiÂciaries connected? |
| Unexpected jurisÂdiction | Does the customer have a documented reason and supporting records? |
| Profile change | Has the business, ownership, income or source of funds changed? |
Network analysis can reveal shared benefiÂciaries or coordiÂnated accounts that transÂaction-by-transÂaction rules miss. This is especially relevant when reviewing higher-risk financial and gambling relationÂships.
Investigate and document every material alert
For each alert, preserve the triggering data and rule version, reconÂstruct the flow of funds, review relevant due diligence, request proporÂtionate supporting documents and record both supporting and contraÂdictory evidence. The decision should explain why the activity is reasonable, why monitoring should change, or why escalation is necessary.
The FCA’s transÂaction-monitoring review stresses profiling, timely alert handling, calibrated rules and management oversight. A Malta Media discussion of compliance controls in iGaming provides sector context, but any real decision should rest on primary law, regulator guidance and the instiÂtuÂtion’s evidence.
Measure whether the system works
Track alert age, invesÂtiÂgation quality, rule coverage, repeat false positives, escalation outcomes and unresolved backlogs. Test rules against known cases and emerging typologies, document changes and retain independent challenge. Manual monitoring may be credible for a small, simple business; larger or more complex firms will generally need approÂpriÂately governed automation.
Finally, separate detection from reporting. Analysts identify and invesÂtigate unusual activity; the legally responÂsible function decides whether the applicable threshold for a suspiÂcious activity report has been met. Local law, confiÂdenÂtiality and anti-tipping-off obligÂaÂtions must govern that step. A review of compliance-audit evidence and goverÂnance shows why documenÂtation and oversight matter as much as the monitoring rule itself.