What problem does it solve?
Transaction monitoring takes a large share of the effort in anti money laundering. Rule based scenarios (thresholds, rapid movement of funds, high risk geographies) are tuned to miss nothing, so they generate large volumes of alerts, and the great majority close as false positives after an analyst has pulled statements, looked up counterparties and written a note.
The cost is not only money. Investigators spend their time clearing noise, real laundering hides in the backlog, and the quality of the written rationale varies from analyst to analyst, which is exactly what supervisors test. Adding people does not scale with payment volumes on instant rails.
- The UN Office on Drugs and Crime reported in 2011 that criminals may have laundered around USD 1.6 trillion, or 2.7% of global GDP, in 2009, consistent with a 2 to 5% of global GDP range previously established by the International Monetary Fund.UNODC estimates that criminals may have laundered US$ 1.6 trillion in 2009 (2011)
- Google Cloud, citing industry reporting, stated in 2023 that more than 95% of system generated alerts turn out to be false positives in the first phase of review, and that about 98% never lead to a suspicious activity report.Google Cloud Launches AI-Powered Anti Money Laundering Product for Financial Institutions (2023)
- The Hong Kong Monetary Authority reported in November 2025 that 48 authorized institutions had assessed AI for transaction monitoring and that more than 30% of authorized institutions had already adopted it in their monitoring systems, with use cases concentrated in risk detection and alert prioritisation.Supporting Artificial Intelligence Adoption in AML/CFT (2025)
How does it work?
- Score the alert. A model trained on past alert outcomes, and increasingly on the full customer and transaction picture rather than the rule hit alone, scores each alert for the likelihood that it leads to a suspicious activity report.
- Enrich it. An agent gathers the evidence an analyst would: customer due diligence data, expected activity, the transactions behind the alert, counterparties, screening results and previous alerts or reports on the customer.
- Draft the rationale. For each alert the agent writes a structured narrative: what triggered it, what the evidence shows and a proposed disposition, with every fact linked to its source record.
- Close or escalate under policy. Alerts that meet approved low risk criteria are closed with the stored rationale; the rest go to investigators, ranked by risk, with the evidence pack attached.
- Learn and assure. Investigator decisions and quality assurance findings are fed back, and a random sample of closed alerts is reviewed independently.
- Audience
- Employee facing
- Autonomy
- Supervised agent
- Adoption
- Early adopters
- Channels
- Internal tools, Agent desktop
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
| KPI | Median | Reported range | Data points | Claimed by |
|---|---|---|---|---|
| False positive reduction | Too few to pool | 60% to 86% | 2 | 1 organization, 1 vendor |
| Alert volume reduction | Too few to pool | at least 60% | 1 | 1 vendor |
| Automation rate | Too few to pool | 57% | 1 | 1 vendor |
Value drivers: Compliance quality, Employee productivity, Lower cost to serve, Risk and loss reduction.
Indicative value
A mid sized bank working 100,000 transaction monitoring alerts a year
USD 400,000 to USD 2.8 million
Investigation capacity released per year
How this is calculated
Formula: alerts * hoursPerAlert * alertReduction * costPerHour. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Transaction monitoring alerts per year alerts, alerts per year | 100,000 | 100,000 | The reference bank. |
| Analyst hours per alert today hoursPerAlert, hours per alert | 0.5 | 1 | Editorial assumption for level one review including documentation. Replace with your own time study. |
| Share of alert workload removed by scoring and auto closure alertReduction, fraction of alerts | 0.2 | 0.4 | Conservative against HSBC's reported 60% fewer false positive cases, because most banks keep rules in place alongside the model at first. |
| Fully loaded analyst cost per hour costPerHour, USD per hour | 40 | 70 | Editorial assumption. Replace with your own. |
What it leaves out: Counts analyst time only. It leaves out the value of finding more genuine laundering, lower regulatory risk, the cost of model validation and data work, and the effort of running rules and models in parallel during the transition.
Who already uses it?
8 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Nexo
Europe · Payments and cards · 2026
Digital asset services company Nexo uses Unit21's transaction monitoring and case management with AI agents that automate alert narratives and dispositions. Analysts work in a supervisory role, verifying the AI generated output, investigating anomalies and applying judgment. The vendor reports that a majority of alert reviews are now automated, with further automation projected.
- Automation rate: 57%, share of alert reviews automated
"By automating alert narratives and dispositions, Unit21’s AI Agents have enabled Nexo to achieve 57% automation in alert reviews, with projections to reach up to 80% as the models continue to evolve."
Claimed by: vendor
Uphold
United States · Payments and cards · 2026
Crypto platform Uphold unified alerts, cases and regulatory filings with FinCEN and FINTRAC in Unit21, and piloted Unit21's AI agent to help analysts review alerts faster and more consistently. The vendor reports a drop in median alert review time from the pilot and predicts much faster suspicious transaction report preparation, which has not yet been measured.
- Handling time reduction: 44%, median alert review time during the pilot
"Median alert review time has dropped by 44% thanks to a pilot of Unit21’s AI Agent, which helps analysts process alerts faster and more consistently."
Claimed by: vendor
HSBC
United Kingdom · Banking · 2024
HSBC replaced rule based transaction monitoring with Dynamic Risk Assessment in its key markets, a machine learning system co developed with Google Cloud that scores customers for money laundering risk from their full transaction and customer data, and routes the highest risk to investigators. HSBC piloted it in 2021 and says it checks about 980 million transactions a month for signs of financial crime. HSBC reports finding two to four times more financial crime with much greater accuracy, and cutting the processing time to analyse billions of transactions from several weeks to a few days.
- False positive reduction: 60%, compared with before, per HSBC
"Now, we have 60% fewer false positive cases."
Claimed by: organization - Alert volume reduction: at least 60%, compared with rules based transaction monitoring
"In fact, HSBC saw alert volumes decrease by more than 60%."
Claimed by: vendor
United Overseas Bank (UOB)
Singapore · Banking · 2020
UOB co developed a machine learning anti money laundering solution with Tookitaki that sorts transaction monitoring alerts into three priority tiers and identifies connected parties, so investigators focus on the cases most likely to be suspicious. UOB said in December 2020 that it was the first Singapore bank to apply AI to transaction monitoring and name screening at the same time, working through more than 5,700 alerts a month, and that the model complements its rules rather than replacing them.
- Accuracy: 96%, true positive prediction rate of the high priority tier
"Since its implementation, UOB’s new AI solution has proven an overall true positive prediction rate of 96 per cent in the ‘high priority’ category"
Claimed by: organization - Interactions handled: at least 5700, transaction alerts per month
"UOB’s AI solution sieves through an average of more than 5,700 transaction alerts each month to flag cases that are more likely to be suspicious with an overall true positive prediction rate of 96 per cent"
Claimed by: organization
BMO and Amalgamated Bank
North America · Banking · 2026
FIS announced in May 2026 that it is building a Financial Crimes AI Agent with Anthropic that assembles evidence across a bank's core systems for anti money laundering alert and case investigations and supports suspicious activity report narratives. BMO and Amalgamated Bank are developing with the agent, and FIS plans general availability in the second half of 2026. The release states aims for investigation time and narrative quality but no measured results.
No outcome disclosed.
Australia Post
Australia · Logistics and transportation · 2025
As Australia Post grew its financial services alongside postal services, it deployed Napier AI's platform on Microsoft Azure for transaction monitoring, client screening and behavioural analytics. The vendor reports large gains in false positive reduction and unusual activity detection, and suspicious activity information that helped dismantle a money laundering syndicate, but its case study credits these gains to rule configuration, the no code sandbox and rule calibration rather than to AI or ML alert scoring.
No outcome disclosed.
Ratepay
Germany · Payments and cards · 2025
Ratepay, a German provider of white label buy now pay later solutions and part of the Nexi Group, replaced its previous solution with Hawk's Payment Screening, which screens transactions in real time against global sanctions lists, and Hawk's AML Transaction Monitoring, with centralised case management for investigators and auditors. The vendor's story says Ratepay is now planning to add Hawk's AI technology for anomaly detection and false positive reduction, so the AI adjudication step this record is filed under is announced rather than live.
No outcome disclosed.
Shift4
United States · Payments and cards · 2024
Payments company Shift4 selected ThetaRay's AI transaction monitoring platform in late 2023 to replace static threshold rules, and completed its European deployment in the first quarter of 2024. The vendor reports a much lower false positive rate and more productive alerts that lead to investigations, with explainable risk scores for the compliance team.
- False positive reduction: 86%
"How Shift4 slashed false positives by 86% and reclaimed analyst bandwidth across $200B+ in annual volume"
Claimed by: vendor
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Several years of alerts with final dispositions, and which ones led to a report
- Customer due diligence data, expected activity and risk rating
- Transaction and counterparty data at the level of detail the investigator uses
- Written investigation procedures and quality assurance standards
Systems to integrate
- Transaction monitoring system
- AML case management
- Customer due diligence and KYC records
- Core banking and payment data
- Screening results (sanctions, PEP, adverse media)
Complexity: High
Scoring and drafting are proven, but auto closing an AML alert is a regulated decision. Expect model validation, a parallel run against the existing process and a conversation with the supervisor before any alert is closed without a human.
- 1
Measure the baseline
Record alert volumes, conversion to reports, handling time and quality assurance findings per scenario. Without this baseline no one can show the model is better, including to the supervisor.
- 2
Build the evidence pack before the score
Start with an agent that enriches alerts and drafts rationales for investigators. It delivers time savings early, carries little regulatory risk and generates the labelled data for scoring.
- 3
Validate the scoring model
Train on historical dispositions, test against a hold out period, and have model risk validate it, including a check that alerts later reported as suspicious would not have been closed.
- 4
Run in parallel
Score and draft on live alerts while investigators still work everything, and compare decisions for at least one full quarter before closing anything automatically.
- 5
Introduce governed auto closure
Close only the lowest risk band, per scenario, with a stored rationale and independent sampling, and report the results to the money laundering reporting officer.
Guardrails
- No alert on a high risk customer, a sanctions nexus or a prior report is closed without a human
- Every closure stores the rationale, the evidence and the model version used
- Independent sampling of auto closed alerts, with a threshold that stops auto closure
- Facts in drafted narratives link to source records, and unsupported claims are rejected
- Model inventory entry, validation and ongoing performance monitoring
KPIs to instrument
- Alert volume and false positive rate per scenario, before and after
- Conversion from alert to suspicious activity report
- Investigator handling time per alert and per case
- Error rate found in independent sampling of auto closed alerts
- Share of reports that came from alerts the model ranked low
Human in the loop
Investigators decide every escalated alert and every filing. The money laundering reporting officer approves the auto closure policy and receives sampling results; model risk validates the scoring model and every material change.
Common failure modes
- Training on yesterday's decisions
- A model trained on past dispositions learns past blind spots. Include alerts later reported through other routes and review the lowest scored band regularly.
- Defensive auto closure rates
- Teams close too little automatically to show any benefit, or too much to satisfy a target. Set the band from validation results, not from a savings goal.
- Rationales that read well but prove nothing
- Fluent narratives without evidence links do not survive an audit. Require citations to source records in every draft.
- Rules and models never reconciled
- Running both forever doubles cost. Plan when rules are retired or retuned based on the parallel run.
What are the risks and rules?
EU AI Act
Minimal risk
AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.
Rules that apply
Guidance
- Supporting Artificial Intelligence Adoption in AML/CFT (Hong Kong Monetary Authority, Asia Pacific). Reports adoption of AI in transaction monitoring by Hong Kong authorized institutions and announces workshops on risk detection, alert prioritisation and generative AI for compiling suspicious transaction reports.
- Joint Statement Encouraging Innovative Industry Approaches to AML Compliance (FinCEN and the US federal banking agencies, North America). Innovative pilot programs should not in themselves subject banks to supervisory criticism, even if they prove unsuccessful.
- Principles for Using Artificial Intelligence and Machine Learning in Financial Crime Compliance (Wolfsberg Group, Global). Industry principles from 2022 for AI in financial crime compliance: legitimate purpose, proportionate use, design and technical expertise, accountability and oversight, and openness and transparency.
- Notice 626 Prevention of Money Laundering and Countering the Financing of Terrorism, Banks (Monetary Authority of Singapore, Asia Pacific). Example of national AML requirements for ongoing monitoring that an AI triage process must still meet.
Controls to put in place
- Auto closure policy approved by the money laundering reporting officer, per scenario
- Stored rationale, evidence and model version for every closed alert
- Independent sampling with an error threshold that suspends auto closure
- Model validation, inventory entry and ongoing performance monitoring
- Documented parallel run results available for supervisory review
Frequently asked questions
- How much can AI reduce AML false positives?
- Published results vary widely with the starting point. HSBC says it now has 60% fewer false positive cases and finds two to four times more financial crime after moving to a machine learning approach built with Google Cloud, and Shift4 reports an 86% reduction after adding ThetaRay's AI transaction monitoring. Measure against your own baseline per scenario, because rule sets differ so much between institutions.
- Can an AML alert be closed without a human?
- None of the regulators cited on this page prohibits it, but the bank remains accountable for every closure. The Wolfsberg principles ask institutions to validate AI regularly and hold them responsible for decisions that rely on it, whoever built the system. A cautious path starts with drafting and ranking, and closes only the lowest risk band automatically after a parallel run.
- Does this replace transaction monitoring rules?
- Not necessarily. UOB's model complements its rules, which remain its first line of defence, while HSBC made a machine learning risk score its primary transaction monitoring system in key markets. The HKMA sees both paths in Hong Kong: some institutions replace rules with a holistic approach, others add AI use cases step by step. Retire rules only once a parallel run shows the model finds at least as much.
How to cite this page
Blits.ai AI Use Case Library, "AI for AML transaction monitoring alert triage", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/aml-alert-triage. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published