Transaction monitoring is the ongoing review of a customer’s transactions against their known profile and expected behaviour. The purpose is to identify activity that requires a more thorough assessment and, if a suspicion arises, filing a report to the authorities. It is a legal duty for regulated firms in every major jurisdiction, set as a global standard in Recommendation 10 and 22 of the FATF and written into national law across the EU, the UK, the US, and Asia-Pacific.
Transaction monitoring definition
The definition is derived from the obligation given in different regulations. Under Regulation (EU) 2024/1624, you must conduct ongoing monitoring of the business relationship, including the transactions a customer makes across its life, to ensure those transactions remain consistent with your knowledge of the customer, their business activity and risk profile, and to detect the transactions that must be made subject to a more thorough assessment.
It is not just an obligation statement; this definition can be broken down into three elements of a workable process:
- A subject: The transactions of a customer with whom you hold a business relationship.
- A benchmark: That customer’s own expected behaviour, established at onboarding and updated as the relationship changes.
- An action: Detection of the transactions that deviate, and escalation of them for assessment.
If your transaction monitoring solution skips even one of these elements, you can’t call it monitoring. For example, checking transactions against a fixed threshold with no reference to the individual customers will flood the queue with falsely flagged routine transactions because suspicious behaviour linked to one customer can be normal business for the second. Similarly, building an expected behaviour profile at onboarding and never testing it against real transactions is just paperwork sitting in a file for an auditor.
Where the obligation for transaction monitoring comes from
The major regimes have more or less same wording for monitoring obligation, because they all implement the same FATF standard.
| Jurisdiction | Instrument | What it requires |
| Global standard | FATF Recommendation 10 (Financial Institutions) Recommendation 22 (Designated non-financial businesses and professions) |
Ongoing due diligence on the business relationship and scrutiny of transactions throughout its course |
| European Union | Regulation (EU) 2024/1624 | Ongoing monitoring of the business relationship to detect transactions requiring a more thorough assessment |
| United Kingdom | Money Laundering Regulations 2017, regulation 28 | Ongoing monitoring including scrutiny of transactions and, where necessary, the source of funds |
| United States | 31 CFR 1020.320 for bank (Parallel Rules cover other classes) | Filing of suspicious activity reports, which in practice requires monitoring capable of detecting them |
| Singapore | MAS Notice 626 for Banks (Parallel notices for other classes of financial institution also issued) | Ongoing monitoring of all business relations, with depth adjusted to the customer’s risk profile |
The language and emphasis may differ but the resulting obligation for business is the same. The US frames the duty around the reporting outcome while the EU, UK, and Singapore frame it around the monitoring activity itself, but a firm that cannot detect unusual activity fails all four.
What falls in scope of transaction monitoring
Monitoring examines the movement of value through an account, not the identity evidence behind it. That covers deposits and withdrawals, inbound and outbound transfers, card and payment activity, cash handling, and currency exchange.
Why transaction monitoring is relative, not absolute
A EUR 40,000 transfer is unremarkable for a commercial importer and a red flag for a salaried retail customer. There is no universal suspicious amount. The benchmark is always the individual customer’s profile, which is why monitoring depends entirely on the due diligence performed before it.
How transaction monitoring works in an AML programme
Monitoring is the third control in a four-part chain, and it inherits its quality from the earlier two steps.
- KYC and customer due diligence: In KYC and Customer due diligence, you establish who the customer is and what they say they will do.
- Risk rating: You translate that into an expected pattern and a risk tier.
- Transaction monitoring: You test real activity against that expectation, continuously.
- Investigation and reporting: You assess the alerts that survive triage and file where a suspicion is formed.
Many transaction monitoring systems fail because monitoring at step 3 doesn’t link to the risk rating at step 2. Onboarding captures expected turnover and purpose of relationship, then the detection logic never reads those fields, so every customer is measured against a generic threshold. Alert volume climbs, precision falls, and analysts spend their days on customers who were always going to look like that.
How does the transaction monitoring cycle work?
Regardless of the technology being used, the AML transaction monitoring cycle has four stages.
| Stage | What happens | What good looks like |
| Ingest | Transactions arrive from core banking, payment rails, or card processors and are normalised into a common record | Complete counterparty, amount, currency, channel, and timestamp on every record |
| Detect | Each transaction, and the account’s recent history, is tested against detection logic tuned to the customer’s risk tier | Logic reads the onboarding profile rather than a single global threshold |
| Triage | Matches raise alerts, which are deduplicated and prioritised for analyst review | Every closure carries a recorded rationale, including the false positives |
| Report | Alerts that survive triage go to investigation, and a suspicious transaction report is filed where suspicion is formed | Full decision trail retained, including decisions not to escalate |
Many alerts are closed as false positives. That is expected and is not itself a control failure. Closing them without a written rationale is, because the audit trail is what a supervisor examines.
How Shufti’s Transaction Monitoring Helps Businesses
Shufti’s AML transaction monitoring software applies continuous, risk-tiered analysis to customer activity and reads the risk profile built during onboarding, so alerts are measured against what you actually expected that customer would do in the future. The full decision trail, including closures, is retained for supervisory review.
Frequently Asked Questions
Q: What is transaction monitoring?
Transaction monitoring is the ongoing review of a customer's transactions against their expected behaviour, to detect activity that needs a more thorough assessment and, where warranted, a suspicious transaction report.
Q: What does transaction monitoring mean in AML?
It means testing real customer activity against the profile established at onboarding, continuously, for as long as the business relationship lasts.
Q: Is transaction monitoring a legal requirement?
Yes, for regulated firms. It is required under Regulation (EU) 2024/1624 in the EU, Regulation 28 of the UK Money Laundering Regulations 2017, MAS Notice 626 in Singapore, and FATF Recommendation 10 globally.
Q: Does the US require transaction monitoring?
Yes, in effect. 31 CFR 1020.320 requires banks to file suspicious activity reports, which cannot be done without monitoring capable of identifying the activity to report.
Q: Who has to perform transaction monitoring?
Obliged entities that maintain business relationships, including banks, payment and e-money institutions, crypto-asset service providers, and regulated non-financial businesses such as casinos and high-value dealers.
Q: What happens when a transaction is flagged?
It becomes an alert, is triaged, and is either closed with a recorded rationale or escalated to investigation. Where suspicion is formed, a suspicious transaction report is made to the relevant financial intelligence unit or competent authority.
Q: Is transaction monitoring the same as a periodic review?
No. Periodic review refreshes the customer profile at set intervals. Monitoring tests transactions continuously against that profile, and a control that fires only at review does not meet the requirement.
































