Listen To Our Podcast🎧
Introduction
Transaction monitoring scenarios examples are the fastest way to see how an AML program turns raw payment data into alerts a human can act on. A scenario is a written detection rule: a pattern, a threshold, a time window and an owner. Get them right and your analysts spend the day on real risk. Get them wrong and they drown in noise.
This guide walks through seven scenarios we see working in banks, fintechs and insurers, then covers tuning, SAR filing, and the KYC controls that feed them.
- Seven concrete monitoring scenarios, with the trigger logic behind each
- How a small fintech team can run a BSA/AML program without a 40-person compliance floor
- What the 30-day SAR clock and the $10,000 CTR threshold mean for your alert queue
- When rule-based detection stops paying off and machine learning is worth adding
- How KYC, CDD and enhanced due diligence data make your scenarios sharper
Onboard Customers in Seconds
What Are Transaction Monitoring Scenarios?
A transaction monitoring scenario is a documented detection rule that flags account activity matching a known money laundering, fraud or sanctions-evasion pattern. Each scenario defines the customer segment, the behavior, the threshold, the lookback window and the alert priority.
Scenarios sit at the center of any AML compliance program. Examiners from the federal banking agencies expect them to map to your risk assessment, and the FFIEC BSA/AML examination manual describes what a defensible monitoring process looks like.
A useful scenario has five parts:
- Typology: the crime pattern it targets, such as structuring or rapid movement of funds
- Population: which customers and products it applies to
- Logic: the amounts, counts and time windows
- Tuning record: why the thresholds are set where they are
- Disposition path: who reviews it and when it becomes a SAR
Start with your AML risk assessment guide: list your products, geographies and customer types, then build scenarios only where real exposure exists. A scenario with no risk behind it is just an alert generator.
7 Transaction Monitoring Scenarios Examples That Work
These are the patterns that reliably earn their place in a monitoring library. Thresholds below are illustrative starting points. Tune them against your own data.
1. Structuring Below Reporting Thresholds
The trigger is multiple cash deposits or withdrawals just under $10,000 within a few days. This is a classic pattern because customers know about the CTR threshold and try to stay beneath it. Alert on aggregate cash across a rolling window, not on single transactions.
2. Rapid Movement of Funds
Funds arrive and leave within hours, leaving a near-zero balance. Mule accounts and layering schemes look like this. Compare inflow-to-outflow ratio and account age, since a new account with pass-through behavior is far riskier than a ten-year customer.
3. Activity Inconsistent With Customer Profile
A small bakery account suddenly receives international wires at ten times its stated monthly volume. This scenario depends on the expected-activity data you captured at onboarding, which is why KYC quality matters so much.
4. High-Risk Jurisdiction Payments
Flag payments to or from geographies your risk assessment rates as high risk, weighted by amount and customer type. Pair this with sanctions screening automation so a name hit and a corridor hit land in the same case.
5. Dormant Account Reactivation
An account silent for 12 months suddenly moves a large sum. Takeover fraud and sold accounts both show this shape. Add a check for recent contact-detail or device changes.
6. Round-Amount and Repetitive Transfers
Many identical round-dollar payments to the same set of counterparties can signal layering or a payment for illicit services. Look at repetition across counterparties, not just one pair.
7. Funnel and Many-to-One Accounts
Dozens of unrelated senders pay one account, which then sweeps funds out. Network-style scenarios catch this better than per-account rules. This is where graph analysis begins to beat static thresholds.
A scenario is only as good as its data. If onboarding never captured expected monthly volume, "activity inconsistent with profile" has nothing to compare against and will fire on everyone or no one.
How Do You Run AML Compliance for a Fintech With a Small Team?
A small team runs effective AML compliance by starting with a written risk assessment, limiting scenarios to real exposure, and automating triage before adding headcount. Ten well-tuned scenarios beat sixty untuned ones.
In our experience, the mistake small teams make is copying a large bank's scenario library. They inherit alert volume they cannot review.
A BSA/AML Compliance Checklist for Lean Teams
Use this BSA AML compliance checklist as a baseline:
- Appoint a BSA officer with documented authority
- Complete and date a risk assessment
- Write policies for CIP, CDD, monitoring and reporting
- Map each scenario to a risk in the assessment
- Document threshold tuning decisions
- Train staff and keep the records
- Schedule independent testing
For a fintech BSA AML small team, item 4 is where the time goes. It also pays back, because examiners ask for exactly that mapping.
BSA/AML Compliance for Community Banks
BSA AML compliance community banks face the same rules as large institutions with far fewer people. The practical answer is fewer, better scenarios, plus vendor tooling that documents tuning automatically. Our guide on AML screening and monitoring in digital lending shows how one payments risk team structures that.
SAR Filing Requirements and Best Practices
Monitoring only matters if it ends in a decision. SAR filing is where alerts become regulatory reports, and it has hard clocks.
SAR Filing Requirements 2026
Under FinCEN rules, a bank must generally file a SAR within 30 calendar days of detecting facts that may constitute a basis for filing, or 60 days if no suspect has been identified. The current SAR filing requirements 2026 still follow this structure, and FinCEN's filing information is the source to check for form and portal changes.
The CTR side is simpler. CTR filing rules require a report for cash transactions over $10,000 in a business day, aggregated across related transactions. Structuring scenarios exist precisely because customers try to game that line.
Suspicious Activity Report Guide: Best Practices
This suspicious activity report guide boils down to four habits that improve SAR filing efficiency:
- Write the narrative around who, what, when, where and why. Investigators reading it later need facts, not adjectives.
- Keep the case file complete before you file, including the alert, the analysis and the decision to file or not.
- Track time-to-decision from alert creation so no case approaches the deadline.
- Review closed-no-file decisions monthly for consistency.
These are the core SAR filing best practices we recommend. Cutting alert noise upstream is the largest efficiency gain. See how agentic AI cut false positives for one approach.
The 30-day SAR clock starts at detection, not at the end of your investigation. A backlog does not pause the deadline.
Rule-Based vs AI: Which Anti-Money Laundering Technology Fits?
Rule-based scenarios are transparent and easy to explain to examiners, while machine learning finds patterns rules miss but needs stronger governance. Most mature programs run both.
Rules vs Machine Learning in Transaction Monitoring
| Rule-Based Scenarios | AI / ML Detection | |
|---|---|---|
| Explainability | High, logic is written down | Needs model documentation |
| False positives | Often high without tuning | Lower when trained well |
| New typologies | Manual rule updates | Can surface unseen patterns |
| Setup effort | Low to moderate | Moderate to high |
| Best for | Known, regulated thresholds | Networks and behavior shifts |
Our comparison of rule-based systems vs AI for false positives covers the trade-offs in depth. The honest limit of AI is governance: a model you cannot explain is a model an examiner will challenge.
Anti-Money Laundering Technology 2026 and the EU AI Act
For anti money laundering technology 2026, the regulatory question is no longer only "does it detect?" but "can we govern it?" The EU AI Act financial services obligations, set out in Regulation (EU) 2024/1689, place requirements on high-risk AI systems, such as credit scoring, and push firms toward documented oversight. Check with counsel whether your monitoring models fall into scope, since classification depends on the use case.
The practical move is to adopt AML compliance software that logs model versions, inputs and analyst overrides. Firms building this into regulatory compliance automation tend to find audit preparation faster because the evidence already exists.
How Do KYC, CDD and Enhanced Due Diligence Improve Monitoring?
KYC and customer due diligence data set the baseline that monitoring scenarios compare activity against. Weak onboarding data produces weak alerts.
KYC CDD Requirements for Banks
The KYC CDD requirements banks must meet include identifying customers, verifying identity, understanding the nature and purpose of the relationship, identifying beneficial owners of legal entities, and ongoing monitoring. Capture expected activity at onboarding, because scenarios like profile mismatch depend on it.
KYC automation 2026 tools reduce manual keying and speed up document checks. The limit is that automation reproduces bad inputs quickly, so audit sample records regularly.
Enhanced Due Diligence Guide for High-Risk Customers
This enhanced due diligence guide applies to politically exposed persons, high-risk jurisdictions and complex ownership. EDD means deeper source-of-funds review, senior approval and tighter monitoring thresholds for those accounts. Supply chain and trade firms face similar pressure, covered in our piece on high-risk supplier KYC/AML validation.
Treat risk rating as a living score. When a customer moves up a tier, the scenario thresholds for that customer should tighten automatically.
- A monitoring scenario is a documented rule with a typology, threshold, window and owner, and it must map to your risk assessment.
- Seven patterns cover most needs: structuring, rapid movement, profile mismatch, high-risk corridors, dormant reactivation, repetitive transfers and funnel accounts.
- Small teams should run fewer, tuned scenarios rather than copy a large bank's library.
- SAR clocks start at detection, so alert quality and case tracking drive filing efficiency.
- Rules give explainability and AI gives pattern discovery, so most programs need both with clear governance.
- KYC and EDD data are the baseline every scenario compares against.
Onboard Customers in Seconds
Conclusion
Transaction monitoring scenarios examples only help if they produce alerts your team can decide on within the 30-day SAR window. Seven scenarios, each tied to a documented risk, are enough to start, and untuned libraries are what bury analysts.
Three things fix most programs. Tuned, risk-mapped scenarios cut noise. Strong KYC baselines make profile-based rules meaningful. Auditable automation speeds triage while keeping examiners satisfied.
Realistically, a lean team can stand up a first ten-scenario library in a quarter, then tune monthly against disposition data. Pick your three highest-risk products today, map one scenario to each, and review the first 30 days of alerts.
Frequently Asked Questions
Common transaction monitoring scenarios examples include structuring below the $10,000 CTR threshold, rapid movement of funds through new accounts, activity inconsistent with customer profile, payments to high-risk jurisdictions, dormant account reactivation, repetitive round-amount transfers, and many-to-one funnel accounts. Each should map to a risk in your AML risk assessment.
A fintech BSA AML small team can usually start with about ten scenarios tied to its real products and geographies. Fewer, well-tuned scenarios create reviewable alert volumes, which matters more than coverage breadth for AML compliance fintech teams.
Under FinCEN rules, a bank generally must file a SAR within 30 calendar days of detecting facts that may constitute a basis for filing, extended to 60 days if no suspect is identified. Check FinCEN's current guidance for SAR filing requirements 2026 before finalizing procedures.
CTR filing rules require a report for cash transactions over $10,000 in one business day, aggregated across related transactions. Structuring scenarios monitor for customers splitting cash activity to stay under that amount.
Most programs use both. Rules give transparency for known thresholds, while AI detects network and behavior patterns rules miss. AML compliance software that logs model versions and analyst overrides makes AI easier to defend to examiners.
KYC and CDD data provide the baseline, such as expected monthly volume and beneficial owners, that scenarios compare activity against. Poor onboarding data leads to noisy or missed alerts, and higher-risk customers under enhanced due diligence should get tighter thresholds.
Share this article