You've tuned your rules and adjusted your thresholds, yet you're still overwhelmed with alerts, and your team is missing actual suspicious activity. The problem isn't your monitoring system; it's your assumptions about how these systems should work.
I've reviewed many transaction monitoring programs where compliance officers think they're following effective practices, only to find they've built their approach on misconceptions about what monitoring can and should do. These myths persist because vendors oversell capabilities, regulators use vague language, and institutions copy each other's frameworks without questioning the underlying logic.
Let's dismantle the most damaging myths about AML/CTF monitoring and screening.
Myth 1: Real-Time Monitoring Catches Suspicious Activity as It Happens
Reality: Real-time monitoring generates alerts as transactions occur, but detection isn't the same as stopping suspicious activity.
Your monitoring software can assess customer transactions quickly, but you're getting faster alert generation, not faster decision-making. The alert still requires human review. Your analyst needs to pull historical data, review the customer profile, and determine whether the activity warrants further investigation or a Suspicious Activity Report.
Real-time monitoring's actual value is in building a complete picture faster. When you combine current transaction data with historical patterns and account profiles, you can see emerging risks before they become full-blown schemes. But you're not stopping transactions in progress; you're identifying patterns that deserve scrutiny.
This distinction matters when setting expectations with your board or allocating resources. You need analysts who can interpret alerts quickly, not just systems that generate them instantly.
Myth 2: More Alerts Mean Better Coverage
Reality: Alert volume is a measure of tuning quality, not monitoring effectiveness.
If your screening engine generates an alert every time a customer shares a name with someone on a sanctions list, you've built a false positive factory. Sanctions and watchlist screening produce frequent false positives because many people share similar or identical names.
The goal isn't maximum alerts. It's maximum relevant alerts. Your transaction monitoring program should recognize different forms of money laundering and flag the types of transactions customers might use to conceal it, like large cash deposits followed by electronic transfers to unrelated accounts. But it should also be calibrated to your institution's normal activity patterns.
What makes a transaction large or unusual depends on your institution's size, the services you offer, and the types of customers you serve. A $50,000 wire transfer is routine for a commercial banking client but highly unusual for a retail customer with a $2,000 average balance.
When optimizing your monitoring system, measure success by the percentage of alerts that survive initial review and trigger event-driven due diligence, not by total alert count.
Myth 3: Automated Systems Replace Human Judgment
Reality: Automation identifies patterns. Humans determine intent.
Your monitoring software can track transaction history and compare ongoing activity to risky patterns. It can alert you when customers make unusually large transactions, engage in complex transaction chains, or exhibit unexpected patterns that don't appear to serve a legitimate purpose. What it can't do is assess context.
Consider a scenario where your screening engine generates an alert because a customer appears in adverse media reporting related to a money laundering scandal. The system flags the match. Your analyst must then review the reporting, assess its credibility, determine whether your institution's products were involved, and decide whether the suspicion has legitimate grounds.
If the media reporting proves speculative and the sources aren't trustworthy, the alert is closed. But the review might reveal other relevant information, like a shift in the customer's geographical business focus to a higher-risk jurisdiction, triggering a risk score recalculation and adjusted due diligence frequency.
This is where human oversight becomes irreplaceable. The system surfaces the signal. The analyst interprets it within the full context of the customer relationship.
Myth 4: Transaction Monitoring Is Only Required Where Explicitly Mandated
Reality: Regulatory requirements establish a floor, not a ceiling.
Yes, certain regulators have made transaction monitoring a specific requirement, Part 504 in New York State and the 4th Money Laundering Directive in Europe for high-risk relationships, for example. But the FATF Recommendations call for effective systems to monitor customer activities as part of ongoing customer due diligence, and most jurisdictions have incorporated this expectation into their AML frameworks.
More importantly, monitoring isn't just about regulatory compliance. It's about knowing your customers' actual behavior. Without continuous monitoring, your initial due diligence becomes stale the moment onboarding completes. A customer initially assessed as low-risk might shift their business model, change beneficial ownership, or enter new markets. If you're only reviewing them on a fixed schedule, you're operating with outdated information.
Event-driven reviews, triggered by screening alerts or monitoring flags, let you reassess risk outside the regular cycle. A customer flagged for adverse media doesn't wait three years for their next scheduled review. They're reassessed immediately, and their due diligence frequency adjusts based on the new risk score.
Myth 5: Screening and Monitoring Are Separate Functions
Reality: They're complementary components of ongoing due diligence.
Your screening engine continuously checks your customer base against sanctions lists, watchlists, and adverse media. Your monitoring system tracks transaction patterns and flags unusual activity. Both generate alerts. Both trigger event-driven reviews. Both inform your risk scoring.
The distinction is in what they observe. Screening looks at who your customer is and whether their status has changed. Monitoring looks at what your customer does and whether their behavior has shifted.
When both systems feed into a unified case management process, you get the "whole picture" analysis that actually supports risk-based decision-making. An adverse media alert gains significance when paired with a sudden change in transaction patterns. A transaction monitoring alert becomes more urgent when the customer is also flagged as a Politically Exposed Person.
If your teams treat screening and monitoring as isolated workstreams, you're missing the connections that reveal actual risk.
What to Do Instead
Stop treating your monitoring program as a compliance checkbox. Start treating it as an intelligence system.
Tune your rules based on your institution's actual risk profile, not generic vendor defaults. Measure performance by how well alerts predict genuine risk, not by how many you generate. Invest in analysts who can interpret alerts within full customer context, not just operators who clear queues.
And most critically: recognize that monitoring and screening don't replace judgment. They inform it. Your system can tell you what happened. Your team determines what it means.





