29 July 2026 · 6 min read

Monitoring is where most small and medium-sized firms lose control of their AML programme. Rules are switched on at go-live, never tuned, and the alert queue quietly becomes a backlog that nobody can defend to an auditor.
Start from your risk assessment, not the vendor defaults
Every rule should map to a typology you identified in your business-wide risk assessment. If you cannot point to the risk a rule is mitigating, it is noise. If you identified a risk with no rule behind it, that is a gap an auditor will find.
Tune deliberately and write it down
Thresholds will be wrong on day one. What matters is that changes are proposed, reviewed, approved and recorded, with before-and-after alert volumes attached. A short tuning log is often the single most persuasive document in an AML audit.
Quality over quantity in alert handling
A closed alert should tell a story: what triggered it, what was checked, what the customer said, and why the analyst concluded what they did. Two-line dispositions are the most common finding we raise in independent audits.
- Set a target time to disposition and monitor it weekly
- Sample-check closed alerts through a second line review
- Escalate to SAR promptly — delays are themselves a finding



