Transaction monitoring in anti-money laundering

A transaction monitoring system produces alerts, and almost all of them are wrong. The work is in the part between the alert and the decision: which scenarios run, where their thresholds sit, who reviews the hit, and what makes a case a suspicious activity report. AML in Germany covers the reporting side; the subject here is the monitoring that comes before it.

A monitor shows a suspicious circular transaction flow highlighted in amber and red.

The duty behind the system

Two provisions carry it. Section 6 of the Geldwäschegesetz requires every obliged entity to have internal safeguards appropriate to its own risk situation, which is the general duty. For credit institutions section 25h of the Kreditwesengesetz is specific: an institution has to operate data processing systems to identify business relationships and individual transactions that appear doubtful or unusual in view of the risk, and it has to investigate what those systems flag.

The sequence matters for how a project is run. The system follows from the risk assessment, so the scenarios a bank operates have to be traceable to the risks it identified in its own analysis. A monitoring set bought as a vendor default and never mapped to the institution's risk assessment is the finding that comes up first in an audit of this area.

Rules, scenarios and anomaly detection

Rule-based scenarios test a condition: a cash deposit over a threshold, a series of transfers just under one, a payment to a jurisdiction on the institution's own high-risk list, a new account with immediate pass-through activity. They are explainable, which matters because the institution has to justify them, and they are easy for anyone who learns the threshold to avoid.

Statistical and machine learning detection works on deviation from a baseline instead: this customer, or customers like this one, do not behave this way. It finds patterns no rule was written for and it cannot explain itself as directly, so banks run both. BaFin's interpretation and application guidance on the GwG is the reference for what the supervisor expects of the monitoring and its documentation.

The typologies the scenarios are written against

Structuring, also called smurfing, splits an amount into pieces below a reporting or monitoring threshold, which is why a scenario looks at the series and not at the single transaction. Layering moves funds through several accounts and products to break the trail, so pass-through activity with no economic purpose for the account holder is its signature.

Other patterns a scenario set covers: money mule accounts, often newly opened, receiving from many senders and forwarding at once; round-figure transactions that repeat; activity inconsistent with the stated purpose of the account; rapid movement in and out of crypto, which AML in crypto covers; and trade payments without a plausible underlying transaction. Each pattern is a hypothesis about behavior, which is what a scenario encodes.

What happens to an alert

Alerts are triaged in two stages. Level one closes the obvious noise: the customer's salary arrived, the transfer matches a known pattern, the counterparty is the customer's own second account. The reviewer at this level works from a checklist and a time budget per alert, and documents the reason for closing and not only the outcome.

Level two investigates what survives. The analyst pulls the relationship history, the beneficial ownership, the other accounts and the earlier alerts, and writes the case. Escalation from there reaches the money laundering officer, the function German law requires an obliged entity to appoint, who decides on the report. A closing reason that reads only as unsuspicious, with no record of what was examined, is the gap a supervisor looks for.

Threshold tuning and the false positive problem

Most alerts are false positives, and the rate is a design choice, not a fact of nature. Lowering a threshold catches more and buries the team; raising it clears the queue and misses cases. The institution has to be able to show why its thresholds sit where they do, which means a documented tuning exercise: sampling below the threshold to show what is being missed, and above it to show what the alerts actually contain.

Where the detection is statistical, the tuning is model work and falls under the same controls as any other model, including independent validation and monitoring for drift. Model validation in banking sets out the method, and MaRisk supplies the governance.

From alert to suspicious activity report

Section 43 of the GwG requires an obliged entity to report without delay where facts indicate that an asset stems from a criminal offense, that a transaction relates to terrorist financing, or that the customer failed to disclose beneficial ownership. The threshold is lower than proof and lower than a criminal suspicion: facts that indicate are enough, and the institution does not have to establish which offense.

The report goes to the Financial Intelligence Unit, and a transaction may not be carried out until the FIU consents or three business days have passed. What this means for monitoring is that the system's output has to reach a decision-maker fast enough for that window to be usable. AML in Germany covers the FIU and the reporting route.

What the AMLR changes

From July 10, 2027 most of Regulation (EU) 2024/1624, the AMLR, applies directly, and it harmonizes the due diligence and internal policies rules that are currently national. For monitoring this means the duty itself stops being a German formulation and becomes an EU one, with technical standards from AMLA underneath it.

The practical preparation is not a system change but a mapping exercise: which of the institution's current controls exist because the GwG says so, which because BaFin's guidance says so, and which because the vendor shipped them. The first group is the one that has to be re-derived from the regulation. The EU AML package covers the three instruments and their dates.

Instant payments and the shrinking window

A credit transfer that settles in ten seconds leaves no room for a pre-execution review by a person. Regulation (EU) 2024/886 on instant credit transfers made euro instant payments mandatory for payment service providers in the euro area, which moves the real-time decision into the system.

Two consequences follow. Pre-execution checks have to be automatic and fast, which pushes sanctions screening and the hardest-stop AML rules into the payment path while the rest of the monitoring runs after settlement. And the same regulation introduced verification of payee, which changes the data available to a fraud and monitoring engine at the moment of the payment. Fraud prevention in Germany and financial crime in payments cover that side.

What is transaction monitoring in AML?

Transaction monitoring is the automated review of customer transactions against scenarios and behavioral baselines to find activity that may indicate money laundering or terrorist financing, followed by a documented human investigation of what the system flags. For German credit institutions the duty comes from section 25h KWG, and the general internal safeguards duty from section 6 GwG.

What is a good false positive rate?

There is no regulatory figure, and a low rate is not automatically better: a system producing few alerts may simply be set not to look. What the institution has to be able to show is that its thresholds come from an analysis of its own risk and its own data, that the tuning is documented and repeated, and that it tests below the threshold to see what it is not catching. The defensible answer is the method, not the number.

Who decides to file a suspicious activity report?

The money laundering officer, the function an obliged entity appoints under German law, decides and the institution files. The analyst prepares the case and recommends; the decision and the record of it sit with the officer. The duty under section 43 GwG does not permit a wait for certainty, so a case held open for more evidence while the facts already indicate is itself a compliance problem.

Does transaction monitoring have to run in real time?

German law does not prescribe real time. Section 25h KWG requires systems appropriate to the risk, and most monitoring runs after the fact on completed transactions. Two things do run in the payment path: sanctions screening, because executing a payment to a listed party is itself the breach, and the rules an institution is prepared to block on. Instant payments have widened that first group, because after-the-fact detection cannot stop a transfer that already settled.

Transaction monitoring and Finance Loop

Finance Loop is the meeting place for the analysts, money laundering officers and data scientists who run monitoring in German institutions. Finance Loop events bring the people tuning the scenarios together with the supervisors and investigators who see where the alerts end up.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.