Case Management: What It Is, What Regulators Expect, and What Gets You Cited
Case Management is the AML workflow control that governs how a financial institution receives, investigates, documents, and resolves suspicious activity alerts. It's required under FATF Recommendation 20, the US Bank Secrecy Act, and the EU Anti-Money Laundering Directives. Without it, suspicious activity reports don't get filed and investigations leave no audit trail.
What is Case Management?
Case Management is the compliance workflow control that covers the full lifecycle of an AML alert: from initial creation and triage, through investigation and documentation, to a final disposition decision. That decision is either a SAR (Suspicious Activity Report) filing, an escalation to the MLRO or senior compliance officer, or a closure with a documented rationale.
It sits between detection and reporting. Transaction monitoring systems, customer due diligence reviews, and screening hits all generate alerts. Most alerts are noise; the ones that survive initial triage become cases. A case is the investigation record: who is being investigated, what activity triggered the review, what evidence was collected, and what decision was made.
Without it, every other control in the AML program is undermined. Excellent transaction monitoring, rigorous KYC, and real-time screening all lose their value if the alerts they generate disappear into a queue with no documented investigation trail. Regulators will view the whole program as defective. That chain of documentation is what separates a defensible AML program from one that fails examination.
A single case often aggregates multiple alerts. A customer flagged for unusual cash deposits might generate 15 separate alerts over 90 days. Running 15 separate investigations wastes analyst time and produces fragmented findings. Merging them into one case gives investigators the full behavioral picture and, if filing becomes necessary, produces a coherent SAR narrative.
Case records typically contain the originating alert or referral, account and transaction data, customer due diligence (CDD) documents, adverse media results, internal notes, escalation history, and the final disposition with rationale. For cases that result in a SAR, the case record is the evidentiary foundation for the narrative attached to the filing.
Banks typically run case management through dedicated platforms. Actimize, Oracle FCCM, Quantexa, and FIS MANTAS are common choices, but the platform is secondary. What matters is the workflow: who receives the alert, what actions they're required to take, what evidence gets attached, and how escalation decisions are documented. The control applies to both individual and batch alert workflows, with high-volume automated triage handling lower-risk alerts and deeper manual investigation reserved for complex cases. In large institutions, case management can touch 50,000 to 200,000 alerts per month.
The OCC's BSA/AML Examination Manual lists case management documentation as a required component of sound internal controls. Banks that lack structured case records, or maintain records that are inconsistent and incomplete, receive supervisory findings. Regulators aren't looking for perfection. They're looking for evidence that the bank took suspicious activity seriously, investigated it, and documented the reasoning behind each decision. That's all case management is, at its core: a proof-of-work record for your compliance program.
Why is Case Management required?
Every major AML framework requires financial institutions to investigate suspicious activity and maintain records of those investigations. The specific phrase "case management" may not appear verbatim in every statute, but the operational requirement is consistent across jurisdictions.
FATF Recommendation 20 requires institutions to file suspicious transaction reports when they suspect money laundering or terrorist financing, an obligation impossible to meet without a structured workflow tracking what was reviewed, when, and by whom. Recommendation 11 requires records of all transactions and customer identification data for at least five years, and case files are how institutions prove they met it: without them, there's no evidence alerts were investigated rather than suppressed. Recommendation 10 on customer due diligence adds another dimension, since findings that reveal gaps in a customer's risk profile must feed back into the CDD process, and case management is that mechanism. Recommendation 11 requires records sufficient to reconstruct financial activity, and FATF's guidance on financial investigations, updated in 2023, treats case documentation as foundational to financial intelligence quality.
In the United States, the Bank Secrecy Act (31 U.S.C. § 5318(g)) mandates SAR filing within 30 calendar days of detecting suspicious activity, with a 60-day extension available when the subject hasn't been identified. FinCEN's SAR regulations under 31 CFR 1020.320 require banks to investigate transactions that may involve money laundering or BSA violations and to document those investigations, and its 2010 guidance (FIN-2010-A005) together with the OCC's BSA/AML Examination Procedures identify case management as a fundamental component of a sound program. The OCC manual, updated in 2021, describes it as part of the required internal controls structure, and examiners review case samples to assess whether the investigation process is consistent, thorough, and well documented.
In the European Union, the Fourth and Fifth Anti-Money Laundering Directives mandate that obliged entities maintain records of suspicious transaction reports and the supporting analysis for at least five years. The Sixth Directive and Regulation 2024/1624, part of the 2024 EU AML Package, both require documented investigation procedures and internal controls that produce auditable records.
In the UK, the Proceeds of Crime Act 2002, the Terrorism Act 2000, and the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 all impose SAR obligations, requiring a report to the National Crime Agency before any action that could constitute tipping off. The FCA's Financial Crime Guide expects firms to maintain investigation processes proportionate to their risk profile.
Case management records are the primary evidence a bank presents during regulatory examination. Published FinCEN enforcement actions consistently cite inadequate case documentation as a contributing factor in AML program failures. Incomplete records signal more than a paperwork gap: they give regulators reason to question whether the underlying investigation was adequate in the first place.
How is Case Management used in practice?
A typical case management workflow moves through four stages: intake, investigation, decision, and closure.
Intake is when a signal, whether an alert, a branch referral, or a tip from a correspondent bank, gets promoted to a case. The analyst assigns a priority level, links the subject entities, and pulls the initial data package: account history, KYC documents, prior case history, and any relevant sanctions screening results.
Investigation is where most of the work happens. The analyst reviews transaction patterns, checks politically exposed person (PEP) lists, runs adverse media screening, and gathers external data where needed. For complex cases involving multiple related entities, network analysis tools map the connections between accounts. An analyst investigating a suspected mule network might link a single case to 30 accounts across four institutions.
Decision is the escalation or closure point. Analysts below a set authority threshold must escalate to the Money Laundering Reporting Officer (MLRO) or BSA Officer for SAR authorization. The decision record must document the reasoning, not just the outcome. "No suspicious activity identified" with no supporting rationale is a compliance gap.
Closure locks the case and archives it. Under 31 CFR 1020.320, SAR records and supporting documentation must be retained for five years. For closed-no-action cases, retention policies typically match that period, though requirements vary by jurisdiction.
One US regional bank cut average case resolution time from 22 days to 8 days by restructuring its intake workflow to auto-populate CDD data from its core banking system. Investigators spent less time pulling documents and more time analyzing behavior. That's the practical dividend of well-designed case management.
What do regulators expect to see?
On exam day, regulators look for documented procedures first. They want a written case management policy that defines the alert triage process, escalation thresholds, SAR decision-making authority, and timelines for each case type.
Then they test the records. Examiners will pull a sample of cases across risk tiers and check for:
- A clear audit trail showing every action taken on the case, timestamped and attributed to a named user
- Supporting evidence attached: transaction data, account history, adverse media results, and prior case history for the same customer
- A written rationale for the disposition decision (file SAR, escalate, or close with documented reasoning)
- For SAR filings: proof that the form was submitted within the statutory deadline (30 days in the US, 7 days for consent SARs in the UK)
- Evidence that senior compliance officers or the MLRO reviewed cases above defined risk thresholds
- Exit documentation when a case is closed without a SAR: what was reviewed, why it wasn't suspicious, and who approved the closure
They also look at management information. A well-run program produces regular MI reports showing alert volumes, average case age, SAR filing rates by business line, and backlog trends. If those reports don't exist, or if they show deteriorating backlogs without a documented response plan, examiners will view that as a governance failure.
Quality assurance matters too. Regulators expect periodic second-line reviews of case samples, with documented findings and corrective actions. The FCA's Financial Crime Guide specifically calls out QA programs that test the quality of investigation decisions, not just whether cases were closed.
Training records round out the evidence set. Analysts who investigate cases must be trained, and that training must be documented and refreshed at least annually.
What does good Case Management look like?
Good case management is fast, documented, and connected to the rest of the AML program. Speed matters because SAR filing deadlines are statutory, and backlogs create regulatory exposure at scale.
The Wolfsberg Group's 2019 Guidance on SAR Filing recommends that institutions set and track internal SLAs for each case tier. A high-risk alert should be opened, assigned, and triaged within 24 hours. A complex multi-jurisdictional case may take 30 days or more, but documented checkpoints throughout are expected at every stage.
On documentation, the standard is simple: anyone with access to the case file should be able to reconstruct what happened without asking the analyst. Every action is timestamped. Every source is attached. Every decision references specific facts rather than generic conclusions.
A well-designed workflow runs like this:
- Alert is generated by a transaction monitoring or screening system
- Automatic triage assigns a risk score and routes the alert to the appropriate analyst queue
- Analyst reviews the alert and pulls supporting data: account history, prior cases, KYC profile
- Level-1 decision: escalate to a full case, or dismiss with documented rationale
- For open cases: investigation, evidence collection, and customer risk-profile review
- Level-2 decision by a senior compliance officer or MLRO: file SAR or close the case
- For SAR filings: form completed, submitted, and confirmation retained in the case file
- Post-SAR monitoring flag set on the customer for heightened surveillance
The Basel Committee's 2017 guidelines on AML risk management recommend that institutions build feedback loops between case management and their customer risk profiling systems. When a case reveals new risk indicators, the customer's risk rating should be updated. That loop is absent at most institutions.
Wolfsberg also recommends regular cross-functional case reviews where compliance, legal, and business line representatives review a sample of complex cases together. This catches interpretation drift before it becomes a regulatory finding.
Common challenges and how to address them
Case backlogs are the most visible symptom of a struggling case management process. One large US bank reported a SAR backlog of over 6,000 open cases in a 2020 OCC examination finding. The root causes were consistent: too many low-quality alerts promoted to cases, insufficient analyst staffing, and no prioritization logic to route high-risk cases faster.
Three challenges dominate case management operations in practice.
Alert-to-case conversion rate is too high. If 60% of alerts become cases, the investigation queue will always overflow. Effective alert disposition practices, including tiered triage rules and pre-disposition automation for clear low-risk signals, can bring conversion rates down to 10–20% without increasing false negative risk. The triage logic must be documented so examiners can confirm it's defensible.
Case records are incomplete or inconsistent. This is a training and tooling problem. Analysts under time pressure take shortcuts: copying boilerplate narrative, skipping adverse media checks, not linking related cases. Standardized templates with mandatory fields reduce the variance. So does periodic quality review of a random sample of closed cases. The audit trail on every action in the case record also gives compliance leadership visibility into where process breaks down.
Cross-entity cases are fragmented. A customer with multiple accounts, a business with multiple beneficial owners, or a network involving a shell company and related individuals often generates separate cases across different investigation teams. Without explicit case linking and entity resolution capabilities, the full picture never assembles. We've seen institutions file five separate SARs on what was clearly one connected scheme, because no one linked the cases.
Fixing these problems rarely requires replacing the case management platform. It usually requires cleaner alert-feeding logic, better analyst workflows, and consistent quality controls on case closure documentation.
Common audit findings and exam citations
Case management failures tend to fall into five categories, and regulators have been consistent about this for more than a decade.
SAR backlogs. The most common finding is a queue of alerts that have been sitting uninvestigated for months. When the US Senate Permanent Subcommittee on Investigations reviewed HSBC in 2012, the bank had cleared a backlog of approximately 17,000 unreviewed alerts in a single week, right before the hearing. The HSBC 2012 enforcement action resulted in a $1.9 billion settlement, with deficient case management identified as a central failure.
Missing documentation. Examiners regularly find cases closed with no rationale, or SAR decisions that record "investigation completed" without specifying what was reviewed. That's not a documentation format problem. It's evidence that the investigation didn't happen.
Broken escalation paths. Cases flagged for MLRO review should have a documented trail showing when the referral was made, what the MLRO decided, and when that decision was communicated back. In the Danske Bank 2018 case, the Estonian branch processed approximately €200 billion in non-resident payments over nearly a decade. Internal escalations about suspicious activity were not acted on by group-level compliance. Case management governance was identified as a core failure in the subsequent regulatory proceedings.
Disconnected systems. Case files that don't reference KYC data, prior SAR history, or related-party accounts leave analysts investigating in isolation without the full customer picture.
SLA breaches on SAR filing. FinCEN has cited multiple US institutions for systematic late SAR filings where backlogs pushed submissions beyond the 30-day statutory window. The OCC's BSA/AML Handbook explicitly lists SLA monitoring as a required element of a sound case management program.
Metrics and KPIs
Measuring case management health requires a mix of volume, quality, and timeliness metrics. Here are the ones that matter.
Volume and throughput:
- Alerts generated per month, by business line and detection rule
- Alert-to-case conversion rate: what percentage of alerts are escalated to full investigation
- Cases closed per analyst per day (a typical benchmark for standard-complexity cases is 8 to 15)
Timeliness:
- Average days to alert disposition
- Average days to case closure
- SAR filing timeliness rate: percentage of SARs filed within the statutory window (target: 100%)
- Backlog by age tier: 0-15 days, 16-30 days, 31-60 days, over 60 days open
Quality:
- False positive rate: cases escalated to full investigation that close without a SAR (industry averages run 90-95% for most transaction monitoring programs; rates above 97% often indicate poorly tuned detection rules)
- SAR quality score based on QA sampling of narrative completeness, accuracy, and readability
- QA reviewer override rate: how often second-line reviewers overturn an analyst's disposition
Governance:
- Percentage of cases reviewed by the MLRO or second line within SLA
- Training completion rate for case management staff
- Time to correct QA deficiencies after they're identified
The FCA's Financial Crime Guide recommends producing MI dashboards at least monthly and presenting quarterly summaries to a senior risk committee. FinCEN's 2016 guidance on SARs reiterates that institutions should track filing trends and investigate unexplained drops in SAR volume. A drop that doesn't correspond to a genuine reduction in customer risk is often a detection failure, not a compliance success.
How Case Management connects to other controls
Case management is the integration point for the AML control stack. Alerts flow in from transaction monitoring, sanctions screening, PEP screening, and adverse media screening, and case management is where those signals are combined, investigated, and converted into a decision.
Transaction monitoring is the primary alert source. When a rule fires on an unusual pattern, say a series of cash deposits near the Currency Transaction Report threshold, a pattern associated with structuring, that alert is what initiates a case. The quality of transaction monitoring directly determines the quality of the case queue.
The connection to customer due diligence runs both ways. CDD and enhanced due diligence provide the customer context investigators rely on: a case about unusual wire transfers looks completely different when reviewed against a customer who passed standard CDD versus one flagged for high-risk activity and enrolled in periodic EDD. In the other direction, when a case reveals that actual behavior doesn't match the declared risk profile, that finding should trigger a CDD review or EDD escalation, and CDD updates surfacing new indicators (change of beneficial ownership, adverse media hits, sanctions list addition) should generate case flags in the management system.
For sanctions screening, case management handles the post-match workflow: confirming a true positive, escalating to legal, and generating the required regulatory notification with a full evidence record.
Typology coverage is where case management earns its keep. Complex schemes like money mule networks typically span multiple accounts and time periods, and a single monitoring alert won't surface the full pattern. Systems that support related-case linking, customer history views, and network visualization catch these where isolated alert review fails. Layering requires the same cross-case analysis: the scheme is designed to look legitimate transaction by transaction, and the pattern only becomes visible when an analyst can assemble the sequence from placement through movement to integration.
The Suspicious Activity Report, or its international equivalent the Suspicious Transaction Report, is the primary output of a case that crosses the filing threshold. The narrative is written from the case record. A well-documented case produces a SAR that gives the Financial Intelligence Unit actionable intelligence. A poorly documented one produces a SAR that tells the FIU almost nothing useful.
Audit trail and chain of custody requirements govern how the case record itself is maintained. Any system that allows retroactive edits to case notes without logging the change creates a regulatory liability. Investigators need to know their work is preserved as written, and examiners need to verify that documentation wasn't altered after the fact.
For institutions deploying AI in case management, explainability is increasingly a regulatory expectation. When an AI system recommends closing a case or escalating for SAR review, the reasoning must be available to the analyst and, on request, to examiners. Black-box decisions in case management are an audit finding waiting to happen.
How FluxForce supports Case Management
FluxForce's AI agents work across the full case lifecycle. Nova Sentinel generates real-time alerts with behavioral context pre-attached, so analysts open a case with the relevant evidence already assembled. Aiden Flux conducts structured investigations, links related accounts and prior case history, and produces a decision memo with a complete audit trail. Every action is timestamped and attributed to a named user. For teams managing high alert volumes, this cuts average case resolution time and produces case files that are audit-ready from the moment they're closed. Request a demo to see how this works in practice.
How FluxForce strengthens Case Management
FluxForce AI agents operate Case Management in real time, capture audit-ready evidence automatically, and surface the gaps examiners cite before they become findings.