AI use case

AI for AML transaction monitoring alert triage

Machine learning and AI agents that score anti money laundering alerts for genuine risk, close clear false positives with a written and stored rationale, and hand investigators the remaining alerts already enriched with the customer, counterparty and transaction context.

By Len Debets · Last verified 27 September 2026 · 8 public deployments

86%
Reported false positive reduction
Shift4, vendor claim.
At least 60%
Reported alert volume reduction
HSBC, vendor claim.
USD 400,000 to USD 2.8 million
Indicative value per year
A mid sized bank working 100,000 transaction monitoring alerts a year. Worked example, see how it is calculated.

What problem does it solve?

Transaction monitoring takes a large share of the effort in anti money laundering. Rule based scenarios (thresholds, rapid movement of funds, high risk geographies) are tuned to miss nothing, so they generate large volumes of alerts, and the great majority close as false positives after an analyst has pulled statements, looked up counterparties and written a note.

The cost is not only money. Investigators spend their time clearing noise, real laundering hides in the backlog, and the quality of the written rationale varies from analyst to analyst, which is exactly what supervisors test. Adding people does not scale with payment volumes on instant rails.

How does it work?

  1. Score the alert. A model trained on past alert outcomes, and increasingly on the full customer and transaction picture rather than the rule hit alone, scores each alert for the likelihood that it leads to a suspicious activity report.
  2. Enrich it. An agent gathers the evidence an analyst would: customer due diligence data, expected activity, the transactions behind the alert, counterparties, screening results and previous alerts or reports on the customer.
  3. Draft the rationale. For each alert the agent writes a structured narrative: what triggered it, what the evidence shows and a proposed disposition, with every fact linked to its source record.
  4. Close or escalate under policy. Alerts that meet approved low risk criteria are closed with the stored rationale; the rest go to investigators, ranked by risk, with the evidence pack attached.
  5. Learn and assure. Investigator decisions and quality assurance findings are fed back, and a random sample of closed alerts is reviewed independently.
Audience
Employee facing
Autonomy
Supervised agent
Adoption
Early adopters
Channels
Internal tools, Agent desktop

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

Value benchmarks for AI for AML transaction monitoring alert triage
KPIMedianReported rangeData pointsClaimed by
False positive reductionToo few to pool
60% to 86%
21 organization, 1 vendor
Alert volume reductionToo few to pool
at least 60%
11 vendor
Automation rateToo few to pool
57%
11 vendor

Value drivers: Compliance quality, Employee productivity, Lower cost to serve, Risk and loss reduction.

Indicative value

A mid sized bank working 100,000 transaction monitoring alerts a year

USD 400,000 to USD 2.8 million

Investigation capacity released per year

How this is calculated

Formula: alerts * hoursPerAlert * alertReduction * costPerHour. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Transaction monitoring alerts per year alerts, alerts per year100,000100,000The reference bank.
Analyst hours per alert today hoursPerAlert, hours per alert0.51Editorial assumption for level one review including documentation. Replace with your own time study.
Share of alert workload removed by scoring and auto closure alertReduction, fraction of alerts0.20.4Conservative against HSBC's reported 60% fewer false positive cases, because most banks keep rules in place alongside the model at first.
Fully loaded analyst cost per hour costPerHour, USD per hour4070Editorial assumption. Replace with your own.

What it leaves out: Counts analyst time only. It leaves out the value of finding more genuine laundering, lower regulatory risk, the cost of model validation and data work, and the effort of running rules and models in parallel during the transition.

Who already uses it?

8 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Nexo

Europe · Payments and cards · 2026

ProductionGrade B

Digital asset services company Nexo uses Unit21's transaction monitoring and case management with AI agents that automate alert narratives and dispositions. Analysts work in a supervisory role, verifying the AI generated output, investigating anomalies and applying judgment. The vendor reports that a majority of alert reviews are now automated, with further automation projected.

  • Automation rate: 57%, share of alert reviews automated
    "By automating alert narratives and dispositions, Unit21’s AI Agents have enabled Nexo to achieve 57% automation in alert reviews, with projections to reach up to 80% as the models continue to evolve."
    Claimed by: vendor

Uphold

United States · Payments and cards · 2026

PilotGrade B

Crypto platform Uphold unified alerts, cases and regulatory filings with FinCEN and FINTRAC in Unit21, and piloted Unit21's AI agent to help analysts review alerts faster and more consistently. The vendor reports a drop in median alert review time from the pilot and predicts much faster suspicious transaction report preparation, which has not yet been measured.

  • Handling time reduction: 44%, median alert review time during the pilot
    "Median alert review time has dropped by 44% thanks to a pilot of Unit21’s AI Agent, which helps analysts process alerts faster and more consistently."
    Claimed by: vendor

HSBC

United Kingdom · Banking · 2024

ScaledGrade B

HSBC replaced rule based transaction monitoring with Dynamic Risk Assessment in its key markets, a machine learning system co developed with Google Cloud that scores customers for money laundering risk from their full transaction and customer data, and routes the highest risk to investigators. HSBC piloted it in 2021 and says it checks about 980 million transactions a month for signs of financial crime. HSBC reports finding two to four times more financial crime with much greater accuracy, and cutting the processing time to analyse billions of transactions from several weeks to a few days.

  • False positive reduction: 60%, compared with before, per HSBC
    "Now, we have 60% fewer false positive cases."
    Claimed by: organization
  • Alert volume reduction: at least 60%, compared with rules based transaction monitoring
    "In fact, HSBC saw alert volumes decrease by more than 60%."
    Claimed by: vendor

United Overseas Bank (UOB)

Singapore · Banking · 2020

ProductionGrade B

UOB co developed a machine learning anti money laundering solution with Tookitaki that sorts transaction monitoring alerts into three priority tiers and identifies connected parties, so investigators focus on the cases most likely to be suspicious. UOB said in December 2020 that it was the first Singapore bank to apply AI to transaction monitoring and name screening at the same time, working through more than 5,700 alerts a month, and that the model complements its rules rather than replacing them.

  • Accuracy: 96%, true positive prediction rate of the high priority tier
    "Since its implementation, UOB’s new AI solution has proven an overall true positive prediction rate of 96 per cent in the ‘high priority’ category"
    Claimed by: organization
  • Interactions handled: at least 5700, transaction alerts per month
    "UOB’s AI solution sieves through an average of more than 5,700 transaction alerts each month to flag cases that are more likely to be suspicious with an overall true positive prediction rate of 96 per cent"
    Claimed by: organization

BMO and Amalgamated Bank

North America · Banking · 2026

AnnouncedGrade C

FIS announced in May 2026 that it is building a Financial Crimes AI Agent with Anthropic that assembles evidence across a bank's core systems for anti money laundering alert and case investigations and supports suspicious activity report narratives. BMO and Amalgamated Bank are developing with the agent, and FIS plans general availability in the second half of 2026. The release states aims for investigation time and narrative quality but no measured results.

No outcome disclosed.

Australia Post

Australia · Logistics and transportation · 2025

ProductionGrade C

As Australia Post grew its financial services alongside postal services, it deployed Napier AI's platform on Microsoft Azure for transaction monitoring, client screening and behavioural analytics. The vendor reports large gains in false positive reduction and unusual activity detection, and suspicious activity information that helped dismantle a money laundering syndicate, but its case study credits these gains to rule configuration, the no code sandbox and rule calibration rather than to AI or ML alert scoring.

No outcome disclosed.

Ratepay

Germany · Payments and cards · 2025

AnnouncedGrade C

Ratepay, a German provider of white label buy now pay later solutions and part of the Nexi Group, replaced its previous solution with Hawk's Payment Screening, which screens transactions in real time against global sanctions lists, and Hawk's AML Transaction Monitoring, with centralised case management for investigators and auditors. The vendor's story says Ratepay is now planning to add Hawk's AI technology for anomaly detection and false positive reduction, so the AI adjudication step this record is filed under is announced rather than live.

No outcome disclosed.

Shift4

United States · Payments and cards · 2024

ProductionGrade C

Payments company Shift4 selected ThetaRay's AI transaction monitoring platform in late 2023 to replace static threshold rules, and completed its European deployment in the first quarter of 2024. The vendor reports a much lower false positive rate and more productive alerts that lead to investigations, with explainable risk scores for the compliance team.

  • False positive reduction: 86%
    "How Shift4 slashed false positives by 86% and reclaimed analyst bandwidth across $200B+ in annual volume"
    Claimed by: vendor

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • Several years of alerts with final dispositions, and which ones led to a report
  • Customer due diligence data, expected activity and risk rating
  • Transaction and counterparty data at the level of detail the investigator uses
  • Written investigation procedures and quality assurance standards

Systems to integrate

  • Transaction monitoring system
  • AML case management
  • Customer due diligence and KYC records
  • Core banking and payment data
  • Screening results (sanctions, PEP, adverse media)

Complexity: High

Scoring and drafting are proven, but auto closing an AML alert is a regulated decision. Expect model validation, a parallel run against the existing process and a conversation with the supervisor before any alert is closed without a human.

  1. 1

    Measure the baseline

    Record alert volumes, conversion to reports, handling time and quality assurance findings per scenario. Without this baseline no one can show the model is better, including to the supervisor.

  2. 2

    Build the evidence pack before the score

    Start with an agent that enriches alerts and drafts rationales for investigators. It delivers time savings early, carries little regulatory risk and generates the labelled data for scoring.

  3. 3

    Validate the scoring model

    Train on historical dispositions, test against a hold out period, and have model risk validate it, including a check that alerts later reported as suspicious would not have been closed.

  4. 4

    Run in parallel

    Score and draft on live alerts while investigators still work everything, and compare decisions for at least one full quarter before closing anything automatically.

  5. 5

    Introduce governed auto closure

    Close only the lowest risk band, per scenario, with a stored rationale and independent sampling, and report the results to the money laundering reporting officer.

Guardrails

  • No alert on a high risk customer, a sanctions nexus or a prior report is closed without a human
  • Every closure stores the rationale, the evidence and the model version used
  • Independent sampling of auto closed alerts, with a threshold that stops auto closure
  • Facts in drafted narratives link to source records, and unsupported claims are rejected
  • Model inventory entry, validation and ongoing performance monitoring

KPIs to instrument

  • Alert volume and false positive rate per scenario, before and after
  • Conversion from alert to suspicious activity report
  • Investigator handling time per alert and per case
  • Error rate found in independent sampling of auto closed alerts
  • Share of reports that came from alerts the model ranked low

Human in the loop

Investigators decide every escalated alert and every filing. The money laundering reporting officer approves the auto closure policy and receives sampling results; model risk validates the scoring model and every material change.

Common failure modes

Training on yesterday's decisions
A model trained on past dispositions learns past blind spots. Include alerts later reported through other routes and review the lowest scored band regularly.
Defensive auto closure rates
Teams close too little automatically to show any benefit, or too much to satisfy a target. Set the band from validation results, not from a savings goal.
Rationales that read well but prove nothing
Fluent narratives without evidence links do not survive an audit. Require citations to source records in every draft.
Rules and models never reconciled
Running both forever doubles cost. Plan when rules are retired or retuned based on the parallel run.

What are the risks and rules?

EU AI Act

Minimal risk

AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.

Guidance

Controls to put in place

  • Auto closure policy approved by the money laundering reporting officer, per scenario
  • Stored rationale, evidence and model version for every closed alert
  • Independent sampling with an error threshold that suspends auto closure
  • Model validation, inventory entry and ongoing performance monitoring
  • Documented parallel run results available for supervisory review

Frequently asked questions

How much can AI reduce AML false positives?
Published results vary widely with the starting point. HSBC says it now has 60% fewer false positive cases and finds two to four times more financial crime after moving to a machine learning approach built with Google Cloud, and Shift4 reports an 86% reduction after adding ThetaRay's AI transaction monitoring. Measure against your own baseline per scenario, because rule sets differ so much between institutions.
Can an AML alert be closed without a human?
None of the regulators cited on this page prohibits it, but the bank remains accountable for every closure. The Wolfsberg principles ask institutions to validate AI regularly and hold them responsible for decisions that rely on it, whoever built the system. A cautious path starts with drafting and ranking, and closes only the lowest risk band automatically after a parallel run.
Does this replace transaction monitoring rules?
Not necessarily. UOB's model complements its rules, which remain its first line of defence, while HSBC made a machine learning risk score its primary transaction monitoring system in key markets. The HKMA sees both paths in Hong Kong: some institutions replace rules with a holistic approach, others add AI use cases step by step. Retire rules only once a parallel run shows the model finds at least as much.

How to cite this page

Blits.ai AI Use Case Library, "AI for AML transaction monitoring alert triage", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/aml-alert-triage. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

BankingPayments and cards

AI copilot for SAR and STR narrative drafting

Generative AI that drafts the narrative of a single suspicious activity or suspicious transaction report from the investigation file (who, what, when, where, why and how), with every fact linked to its source record, so the investigator verifies, edits and files instead of starting from a blank page. It works case by case, unlike the periodic data returns of regulatory reporting.

Deployments
4 public, best grade B
Autonomy
Copilot
BankingPayments and cards

AI for money mule account and network detection

Graph and behavioural machine learning that finds money mule accounts and the networks around them, such as circular flows, layering chains and clusters of newly linked accounts, and supports investigators in tracing scam proceeds and restricting accounts before the money is gone.

Deployments
3 public, best grade B
Autonomy
Copilot
BankingPayments and cards

Dynamic AML customer risk rating with machine learning

Explainable machine learning that produces the money laundering risk rating itself: it computes and continuously updates each customer's rating from due diligence data, products, geography, behaviour and screening results, and shows which factors drive the rating and when enhanced due diligence is warranted.

Deployments
1 public, best grade B
Autonomy
Supervised agent
BankingPayments and cards

AI for sanctions screening alert adjudication

AI that works the alerts raised when customer, counterparty or payment names match sanctions and watchlists: it resolves fuzzy matches across transliterations, aliases and naming conventions, clears clear non matches with a documented reason, and escalates true or uncertain hits with the evidence attached.

Deployments
7 public, best grade B
Reported false positive reduction
60%
United Overseas Bank (UOB), organization claim
BankingPayments and cards

AI agent for fraud alert triage

An AI agent that works the fraud alert queue behind the scenes as the analyst's first pass, without contacting the customer: it enriches each alert with customer, device and payment context, closes clear false positives under documented rules, merges duplicates, and routes genuine risk to an analyst with a drafted rationale.

Deployments
2 public, best grade C
Autonomy
Supervised agent
Banking

AI screening of trade finance transactions for trade based money laundering

AI that screens every trade finance transaction for financial crime risk: it checks parties, vessels and ports against sanctions and watchlists, tests goods descriptions against dual use and controlled goods lists, compares unit prices with benchmarks for over or under invoicing, and reads trade documents and messages for laundering red flags, then prepares a case narrative for a human investigator.

Deployments
3 public, best grade C
Autonomy
Supervised agent