Skip to main content
Category: Anti-Corruption and AML

Ongoing Monitoring of Transactions

Also known as: Transaction Monitoring, Ongoing Monitoring, Ongoing Transaction Monitoring
Simply put

Ongoing monitoring of transactions is the practice of routinely reviewing customers' financial activity over time to spot behavior that could signal money laundering or other criminal activity. Rather than checking a customer only once, it involves continuously assessing their transactions to gauge risk and flag anything suspicious. Some tools carry out this review in or near real time. This entry is educational and not a substitute for professional or legal advice.

Formal definition

Ongoing monitoring of transactions is a component of an AML compliance program consisting of the continuous or routine assessment of customer transactions and activity to determine risk and detect suspicious activity potentially indicative of money laundering or other financial crime. It functions as a detective and risk-assessment control within a broader AML framework and does not by itself constitute a complete compliance program. According to the evidence, ongoing transaction monitoring is described as a regulatory requirement for business sectors falling under money laundering regulations; the specific obligations, thresholds, and covered sectors are jurisdiction-dependent and should be confirmed against the applicable primary regulations and qualified legal counsel. Certain implementations perform detection in real time, though monitoring approach and effectiveness depend on system design, data quality, and implementation context.

Why it matters

Money laundering and other financial crimes rarely reveal themselves in a single transaction. Criminal activity typically unfolds over time through patterns of behavior that only become visible when a customer's activity is assessed continuously rather than at a single point of onboarding. Ongoing monitoring of transactions serves as a detective control that helps organizations identify suspicious activity that a one-time check at account opening would miss, allowing risk to be reassessed as a customer's behavior evolves.

For sectors that fall under money laundering regulations, ongoing transaction monitoring is described in industry guidance as a regulatory requirement, though the specific obligations, thresholds, and covered sectors vary by jurisdiction and should be confirmed against the applicable primary regulations and qualified legal counsel. Failing to maintain adequate monitoring can leave an organization unable to detect illicit activity flowing through its systems and may expose it to regulatory scrutiny. It is important to understand, however, that monitoring is one component of a broader AML program and does not by itself guarantee detection or constitute a complete compliance framework.

Because monitoring operates at the intersection of technology, data, and human judgment, its usefulness depends heavily on implementation. Approach and effectiveness are shaped by system design, data quality, and how alerts are investigated and escalated. Organizations should treat monitoring as a control to be tested and tuned over time rather than a set-and-forget safeguard, and should confirm exact regulatory obligations against primary sources.

Who it's relevant to

Compliance and AML officers
Those responsible for AML programs rely on ongoing transaction monitoring as a core detective control for identifying suspicious activity. They oversee how monitoring is designed, how alerts are triaged and escalated, and how the function integrates with the broader compliance framework. They should confirm the specific monitoring obligations that apply to their sector and jurisdiction against primary regulations and qualified legal counsel.
Legal and audit teams
Legal and audit staff assess whether monitoring practices meet applicable regulatory requirements and internal policies. Because obligations, thresholds, and covered sectors are jurisdiction-dependent, these teams help interpret which rules apply and verify that monitoring controls are documented, tested, and functioning as intended. Matters touching specific legal obligations warrant qualified legal counsel.
Technology and data teams
Because some monitoring is carried out in or near real time, technology and data teams are central to implementation. The monitoring approach and its effectiveness depend on system design and data quality, making these teams responsible for building, tuning, and maintaining the tools that detect and flag suspicious activity.
Learning and development staff
L&D teams design training that helps relevant staff understand the role of ongoing monitoring within an AML program, how to recognize and respond to flagged activity, and how monitoring differs from a one-time customer check. Training is one part of a larger program and supports, but does not replace, the monitoring control itself.

Inside Ongoing Monitoring of Transactions

Automated Transaction Screening
System-driven review of transactions against defined rules, thresholds, and watchlists to flag activity that may warrant further examination. This is one component of a monitoring and auditing function and does not by itself constitute a full compliance program.
Risk-Based Thresholds and Rules
Parameters calibrated to the organization's assessed risk profile that determine when a transaction is flagged for review. These should be derived from a documented risk assessment and are intended to prioritize higher-risk activity.
Alert Triage and Investigation Workflow
The process by which flagged transactions are reviewed, escalated, cleared, or referred for deeper investigation. This separates automated detection from the human judgment required to interpret and act on alerts.
Documentation and Audit Trail
Records of monitoring activity, alert dispositions, and decisions that support internal review and demonstrate that monitoring is operating. Adequate documentation is generally regarded as important when a program's effectiveness is evaluated.
Periodic Tuning and Testing
Ongoing adjustment of rules and thresholds and validation that the monitoring system detects intended activity. Monitoring is a continuous function rather than a one-time control, and its outputs depend on how it is configured and maintained.
Escalation and Reporting
Defined pathways for reporting confirmed concerns to appropriate internal functions and, where required by applicable law, to external authorities. Specific reporting obligations are jurisdiction-specific and should be confirmed with qualified legal counsel.

Common questions

Answers to the questions practitioners most commonly ask about Ongoing Monitoring of Transactions.

Does ongoing monitoring of transactions mean the same thing as auditing?
No. Ongoing monitoring of transactions is a continuous or near-continuous activity, typically embedded in operational processes and often automated, that reviews transactions as they occur or shortly after. Auditing is generally a periodic, independent review conducted at defined intervals. The two are related but distinct components of a broader compliance program: monitoring is generally regarded as an ongoing, management-owned control, while auditing provides periodic independent assurance. Neither substitutes for the other, and neither alone constitutes a complete compliance program.
If we have transaction monitoring in place, does that satisfy our compliance program obligations?
No. Ongoing monitoring of transactions is one element within a larger compliance and ethics program. It does not replace other components such as a code of conduct, risk assessment, training, whistleblower channels, or the broader monitoring and auditing function. Frameworks such as the DOJ Evaluation of Corporate Compliance Programs generally look at whether a program is well designed, adequately resourced, and working in practice across multiple components, not at any single control in isolation. Treating transaction monitoring as sufficient on its own would misrepresent how these frameworks assess program effectiveness.
How should we determine which transactions to monitor and at what thresholds?
Monitoring scope and thresholds are typically driven by the organization's risk assessment, which identifies where the greatest exposure lies given the business, geography, counterparties, and applicable requirements. Because thresholds and monitoring parameters that touch regulated areas (for example, anti-money-laundering or sanctions screening) may be jurisdiction-specific and governed by binding obligations, specific parameters should be set with qualified legal and subject-matter input. This entry is educational and not a substitute for professional advice on requirements applicable to your organization.
What is the difference between automated and manual transaction monitoring, and when is each appropriate?
Automated monitoring applies predefined rules, patterns, or analytics to transaction data at scale and can flag items for review continuously. Manual monitoring relies on human review of selected transactions and is often used where judgment, context, or lower volumes make automation less practical. Many programs use a combination, with automation handling volume and consistency and human reviewers assessing flagged items. The appropriate mix depends on transaction volume, data quality, resources, and the nature of the risks being addressed; there is no single configuration that fits all organizations.
How do we handle and document alerts generated by transaction monitoring?
A defined process for triaging, investigating, escalating, and resolving alerts is generally regarded as important so that flagged items receive consistent treatment and outcomes are traceable. Documentation of how alerts are dispositioned can help demonstrate that the control is working in practice, which is the kind of evidence program-evaluation frameworks tend to look for. Because handling of certain alerts may trigger reporting obligations that vary by jurisdiction, escalation and reporting procedures should be developed with qualified legal counsel.
How can we assess whether our transaction monitoring is actually working?
Effectiveness is generally evaluated by looking at whether the monitoring detects the issues it is designed to detect, whether alerts are resolved on a timely basis, and whether the rules and thresholds remain aligned with the current risk profile. Periodic testing, tuning of rules to manage false positives and negatives, and independent review through the auditing function can support this assessment. No monitoring approach guarantees detection or prevention of misconduct; outcomes depend on implementation, data quality, resourcing, and context, and results should be confirmed through the organization's own testing and review.

Common misconceptions

Ongoing transaction monitoring is primarily a compliance obligation with no ethical dimension.
Monitoring supports adherence to external laws and internal policies, placing it largely on the compliance side of the spectrum, but the handling of alerts and the judgment applied to ambiguous activity can also involve values-based ethical decisions that exceed strict legal minimums.
Deploying an automated monitoring system satisfies an organization's compliance program.
Transaction monitoring is only one part of a broader system that also includes a code of conduct, risk assessment, training, whistleblower channels, and other auditing functions. Automated screening alone does not constitute a complete program and requires human triage, investigation, and oversight.
A well-configured monitoring system guarantees that misconduct will be detected and prevented, and provides legal protection.
No monitoring method guarantees prevention of misconduct or legal protection. Monitoring is intended to help detect and prioritize suspicious activity, but outcomes depend on implementation, tuning, staffing, and context.

Best practices

Derive monitoring rules and thresholds from a documented risk assessment so that higher-risk activity is prioritized rather than applying uniform parameters across all transactions.
Maintain a clear alert triage and investigation workflow that assigns responsibility for reviewing, escalating, clearing, and documenting each flagged transaction.
Periodically tune and test rules and thresholds, and validate that the system detects the activity it is intended to catch, treating monitoring as a continuous function rather than a one-time control.
Keep a complete audit trail of alerts, dispositions, and decisions to support internal review and to demonstrate that monitoring is operating as designed.
Confirm any external reporting obligations with qualified legal counsel, since specific requirements are jurisdiction-specific and vary by local law.
Use qualified language when describing the system's capabilities to internal stakeholders, making clear that monitoring supports detection but does not guarantee prevention of misconduct.