Anti-money laundering solutions rely on a simple guarantee to regulators. If something is not right, the institution will see it, investigate it, and report it if it has to. The AML alert investigation workflow is delivering on that promise. It's the trail of an alert from when it's flagged by a transaction monitoring system. It is subject to human assessment and escalation for a final decision whether to close it, keep monitoring, file a Suspicious Activity Report (SAR), or exit the customer relationship entirely.
The importance is a standard set internationally and enforced locally. Under FATF Recommendation 20, a financial institution must report promptly to its financial intelligence unit when it thinks or has reasonable grounds to suspect that monies are the proceeds of crime or are related to terrorist financing. The US Bank Secrecy Act hardens the principle. A SAR must be submitted within 30 days after the date of initial detection by the institution of facts that may constitute a basis for filing. If no suspect is discovered in that window, it can take up to 60 days in total.
None of these requirements is met by detection alone. A monitoring system can produce thousands of notifications. But an alert is a question, not an answer. That question is answered in the investigation when an analyst determines if the unexpected transfer of money is benign, a sanctions issue, or truly worrisome. There is a cost to getting the procedure wrong. TD Bank was fined more than $3 billion in total, in 2024. Partly because it did not flag questionable transactions and take action on them that it should have.
This routine is the core of financial crime defense. The article includes the creation and triaging of alerts and the contribution of each level of analyst. It discusses the documentation and decision criteria examiners expect to find when they review your file.
The following topics are going to be covered in this article;
- The Alert Lifecycle: From Generation to Disposition
- Alert Triage: Prioritization Frameworks
- Level 1 Review: What the First Analyst Does
- Level 2 Investigation: What the Senior Analyst Adds
- The Investigation Documentation Standard
- Common Investigation Pitfalls
- The Decision Tree: When to File a SAR
- Tipping Off: What You Cannot Do During Investigation
- Case Management Tooling
- Regulatory Expectations on Investigation Quality
1. The Alert Lifecycle: From Generation to Disposition
It is only appropriate to close an alert with a recorded explanation. There is a purpose for its raising. Every alert has a lifecycle. The details are as follows:
(a) Transaction monitoring system alerts: There is a set of behavioral models and rule-based limits. This system looks for suspicious activity by comparing it to these criteria. Any time a transaction doesn't conform to the expected client profile or violates a rule, an alert is thrown. Many banks do real-time monitoring for high-risk channels such as wires and crypto, where a flagged payment can still be intercepted. Lower velocity accounts are run as a daily batch. Notice that an alert is a signal and not a judgment.
(b) Triage and Prioritization: There are many alerts, and most of them are false positives. In one example, there were perhaps 20 real alerts buried in a single queue of 400 messages among fake alerts. Triage is the sorting step when alerts are categorized by risk so that critical alerts bubble to the top and obvious noise is quickly removed. The better programs have the triage logic built right into the workflow. They don’t let each and every reviewer decide everything.
(c) Level 1 review: The first analyst identifies the reason for the alert firing, obtains basic client context, tests it against known false positive trends, and documents their findings. Usually it’s a fast pass, like five to ten minutes. It concludes in one of two ways. Either it is cleared and the rationale is documented or it is escalated.
(d) Escalation to level 2: Anything that gets through L1 goes to a senior analyst. This stage can take two to eight hours. There is real digging with transaction history, client profiles, and counterparty research. After that, there is a documented decision on whether the activity is suspicious.
(e) The disposition decision: All alerts have a recorded outcome. The four common ones are:
- Close as a false positive
- Continue with enhanced monitoring of customer
- File a SAR
- Exit the relationship.
If the activity is judged suspicious, it goes to the MLRO or BSA officer. They review the narrative and make the filing decision under personal liability. The discipline of the process is not less important than the call. Every disposition should be reasoned and documented.
2. Alert Triage: Prioritization Frameworks
All alerts are not created equal. When treated equally, genuine risk becomes buried. Triage addresses that. Alerts are scored based on a number of weighted criteria and sent to the proper queue with the proper urgency.
Risk-based prioritizing: This is the key idea. Resources are finite, so you focus them on the signals that are most likely to be real. Risk signal prioritization means concentrating investigative attention on the most relevant situations. Each risk component has its own weight: Customer risk, product risk, location risk, and transaction risk. Then the score determines where the resources go. The most dangerous cases are at the top. The evident noise falls silent.
Weighting of customer risk score: The customer risk score (CRS) is one of the heaviest inputs. The identical transaction reads quite differently depending on who is behind it. Set the alert thresholds lower for clients that are deemed high risk and higher for those that are deemed low risk. This keeps the volume and quality of alerts in check. The Customer Risk Assessment module of Sanction Scanner generates this score from factors such as occupation, country, transaction patterns, source of funds, and PEP affiliation. The module then calculates it dynamically and updates it when the client information changes. Feed that CRS into triage, and high-risk consumers get tighter thresholds and faster reviews.
Transaction value weighting: Amount matters too but is a poor indication on its own. A surge in either total spend or payment volume well over a customer’s own standard is a stronger flag than a single large number. Round number transfers and just-below-reporting-threshold quantities are also factors that push an alert up the queue. Value only means something when set against what is typical for that customer, not in isolation.
Pattern severity: Some patterns just tell you more than a one-off large payment. Structuring, fast in-and-out movement, layering across accounts, and linkages to established typologies increase severity. The closer a warning matches a known laundering method, the more urgent it is.
SLAs by priority tier: Each tier has a service level agreement, an internal deadline for execution. Companies set SLA goals for alert handling and measure compliance. They will check all new notifications within a specific number of days. Critical alerts might need to be dealt with the same day, but lower priority alerts have a longer window. SLAs also protect against backlogs, which examiners consider a finding in their own right.

3. Level 1 Review: What the First Analyst Does
Level 1 is the front door of the inquiry. The first analyst's role is not to solve the case. The duty is more limited to evaluating if this alert is a pass or needs a second check. Even if it takes five to ten minutes usually, it sets the course for anything next.
Verify the cause of the notification: Start with the reason behind it. The analyst confirms which rule or threshold prompted the alert and what activity caused it. Without it, everything downstream is a guess.
Pull Customer Context: The next step is to review the background section. The analyst opens the Know Your Customer (KYC) file. The client's risk score ,background and source of wealth are examined. The past transactions from six to twelve months are checked. The goal is to find a starting point and see if the behavior has happened in the past. If you can't figure out what's average for that person, the alert doesn't mean anything.
Check for known false positive patterns: There is a lot of noise in alerts, and most of them can be predicted. This happens even if the account has never done anything fishy before and the transactions are valid. When the action fits a known pattern of harmless behavior, the analyst can safely clear it.
Report preliminary results: The analyst writes down everything learned. Why the alert was raised, the steps that were taken, the data that was looked at, red flags found, and the conclusion are all included. This is not busywork. That is what allows a supervisor or examiner to track the rationale afterward.
Decision: Close or escalate. L1 can finish in two ways. The analyst either closes the alert as a false positive with an explanation stated or escalates it to a senior analyst for further work. Where there is clear evidence of money laundering, the matter does not remain at L1 but moves straight up the chain. The trick is to tell them apart correctly and quickly.
4. Level 2 Investigation: What the Senior Analyst Adds
L1 chooses if an alert is worth looking at; L2 decides what it really implies. A senior analyst spends actual time putting together a whole picture. It is not a short read, as depth is the whole concept.
Deeper analysis of transaction history: The senior analyst goes way beyond the highlighted transaction. They will then apply filters and search queries to extract all transactions above a given amount or activity with specific counterparties or within a particular time. The results will be matched against the declared customer profile. A salary account with significant, unexplained inflows conveys a tale that a single alert could not.
Counterparty analysis: It concerns who is on the opposite side of the money. They look at who owns the counterparties involved, check the jurisdictions, look for layers, and quickly escalate if there is suspicion of shell-company misuse. It tells a different story if a clean client is directing money to opaque entities in high-risk regions.
Adverse media checks: The analyst then examines the customer and related parties against adverse media, court records, and regulatory alerts. The result must actually be referring to the correct individual or entity. A credible hit on fraud or corruption tips the scales for all.
Source of funds verification: The analyst follows the origin of the funds and analyzes whether the source is legitimate. The risk goes up if the customer cannot justify the source of their wealth, or it links to sanctioned nations.
Pattern analysis across multiple alerts: This is what L1 seldom catches. The analyst can link activities across time to see the quick cycling of funds and layering that no single warning would show. Often the pattern is the true proof.
The decision: L2 concludes in one of four ways. When the activity fits the profile, close it. Request further information if any crucial details are lacking. When the behavior is significantly at odds with the profile and cannot be adequately explained following proportional checks, escalate the situation. This means sending it to the MLRO or recommending a SAR when the evidence supports it. Either way, the rationale is documented.
5. The Investigation Documentation Standard
An investigation that is not carefully documented may as well have not occurred. Law enforcement can't read an analyst's thinking, and neither can examiners. Thorough documentation leads to a well-founded judgment call.
The 5 W’s (who, what, when, where, why): This is the fundamental component, and it’s straight from FinCEN. A SAR narrative should include the basic five parts of the activity being reported: who, what, when, where, and why. The technique of operation, the "how," should be added as well. These are the questions the narrative must answer before it is considered complete. Rather than just a summary total, list out individual dates and amounts so the flow of monies may be traced.
Chain of proof: The story is in the narrative, but the proof is in the file behind it. FinCEN bans attaching supporting documents to the SAR. They need to be stated appropriately in the narrative instead. They should be retained for five years and produced on specific request. That kept file is your chain of proof.
Decisional rationale: Examiners want a clear recorded reason for the belief that the behavior is suspicious. It should be expressed explicitly with red flags identified and linked to the typology with which they have similarities. Structuring or layering is an example of typology. Weakest narratives only repeat data in the fixed fields of the form or alert language. No analysis raises questions about the program’s effectiveness.
Regulator-ready audit trail: The whole procedure works if you record the trail as you proceed. Case management provides a single place to record the alert, the review, and supporting paperwork. This makes the narrative based on evidence, not memory. Standardized templates, defined review workflows, and centralized case management keep that consistent across analysts. This is what holds up under examination.
6. Common Investigation Pitfalls
On paper, the majority of AML programs seem promising. When regulators start their reviews, the defects show up early. Issues are frequently the same few that are replicated in other institutions. The most problem-causing issues are as follows:
Closing due to insufficient proof: You are stressed by backlogs, which causes you to clear alerts more quickly than you should. If a legitimate case is closed as a false positive, the activity will simply go on. Until it is closed, the same vulnerability will be exploited. The notifications will continue to be handled insufficiently. Closing without enough to maintain the connection is the issue, not speed. Here, shortcuts are disliked by regulators. It is considered an aggressive strategy to automatically close low-risk warnings.
Failure to document decision reasoning: You can do a good inquiry and still fail the exam if you don't write down why you came to that conclusion. Regulators want documented proof of every decision, from the first screening to case closure. Not keeping it can be a penalty even if the screening was okay. The entire SAR process is silently undermined by weak case narratives and thin investigative documents.
Missing the link between multiple alerts on the same customer: This is a structural problem. Customer data is frequently siloed across disconnected systems. Context is lost and investigations are stalled. Each warning is thus regarded as an independent occurrence. But often the true proof is in a pattern that spans numerous alerts. Looking at them in isolation means the layering or structuring never comes into focus.
Failing to update the customer risk score after the investigation: An inquiry should inform the profile, rather than terminate in isolation. A SAR file or suspicious behavior or sanctions modification should automatically trigger a recalculation of the customer’s risk score. Too often, file refreshes that should be normal are deferred until a regulator demands them. If the score is static, the next alert on that client is being weighed against a stale image of their risk.
7. The Decision Tree: When to File a SAR
At the end of the investigation, the call boils down to two questions: Does the suspect meet the legal requirement, and does the behavior clear the amount barrier that makes reporting mandatory? Getting either wrong results in having an overfile or failing to file.
The threshold of materiality: The BSA has particular dollar triggers in the US. Any amount of insider abuse requires a SAR. Suspicious conduct of $5,000 or more requires a SAR when a known suspect is identified. For $25,000 or more, it does not need an identified suspect. These thresholds are institution-dependent, and that granularity is significant. Broker-dealers file at $5,000, and national banks file at $25,000, where there is no insider misuse and no strong cause to identify a suspect. Merrill Lynch applied the incorrect threshold for over a decade. The result was failing to file over 1,500 SARs and being fined $6 million. Any cash transaction of over $10,000 by or on behalf of one person in a single business day must be accompanied by a currency transaction report (CTR). But doing so below this figure is not inherently suspect. A SAR is required when you have a reason to suspect a customer intentionally divides monies to avoid the CTR filing limit.
The standard of “reasonable suspicion": This is the heart of the decision. You file if you know, suspect, or have reason to suspect that funds: Are associated with unlawful activity; Are designed to hide such funds; Are structured to dodge BSA reporting requirements or have no obvious lawful purpose that you can determine. The bar is intentionally low. Not certainty, not probable cause, but a good faith assessment based on the evidence at hand. The threshold is low to promote proactive reporting. You don’t have to dig up or corroborate the underlying offense. One red flag might be explainable all by itself, but it's the sum of the facts, the pattern, and the customer history that adds up to indicate reasonable suspicion that tips you into filing.
8. Tipping Off: What You Cannot Do During Investigation
You cannot disclose to the client the material you are examining when determining whether to file. The regulation is in place and is stringent for a purpose. Notifying a suspect affords them the opportunity to transfer funds, obliterate evidence, or disappear.
Requirements for confidentiality: The principle is ubiquitous. FATF Recommendation 21 is entitled “Tipping-off and confidentiality”. It mandates that financial institutions and their directors, officers and employees are legally prohibited from revealing that a suspicious transaction report or associated information is being sent to the FIU. This legislation is rigorous in the United States. This pertains to all employees and officers, not alone compliance specialists. It is a federal criminal offense under 31 U.S.C. Section 5318(g)(2) to disclose the existence of a SAR or that one may be filed to the subject of the SAR. The ban is for current and former directors, officers, employees, agents, and contractors. You may disclose a SAR to applicable law enforcement, regulatory or supervisory bodies, the examining SRO, and to a parent or certain domestic affiliates. Except for these, there are no other exceptions.
Restrictions on customer communications: It guides you in how to work with the customer on an investigation. At no time during the inquiry is the subject informed that a report is pending. That doesn't freeze all contact, though. You can still ask typical due diligence questions like verification of source of funds, etc. You do not say that there is a SAR or that the questioning is about possible criminal behavior. It is an easy line to state and easy to cross: Get what you need, but never let on why you are really asking. The same principle applies outside the institution. Discussion of a SAR with the media or other unauthorized individuals is considered an unlawful disclosure.

9. Case Management Tooling
What we have learned thus far is all system-dependent. Good case management tooling converts a stream of alerts into a defendable procedure. The three most important capabilities are as follows:
Centralized dashboards: Analysts aren’t bouncing between disjointed systems; one dashboard displays alerts, customer data, and screening results in one view. Investigations would proceed more efficiently if they had a centralized approach. That system would handle warnings, keep track of findings, escalate correctly, and keep audit logs. When the tools don’t see each other, the team doesn’t see each other. Incomplete data means incomplete decisions. This is the exact reason at Sanction Scanner we've created an AI-native risk intelligence platform, FUSION, where all the customer data can be found in one single dashboard.
Audit trail: Every action has to be recorded, time-stamped, and retrievable. Every match, decision, and action is recorded in a proper audit trail in a format for regulatory scrutiny and internal tracking. An investigation can be reconstituted months later. An examiner will see exactly how you reached a result. Without this documentation, even sound work appears undocumented.
Workload distribution: Volume has to be carefully spread out between the team. Best solutions automate case assignment, route alerts to analysts based on their specialization, case value, and risk level, and let teams control how the queue functions. This avoids having high-priority cases become stuck and backlogs from accumulating. Examiners treat the issue as a finding if not resolved.
Where does Sanction Scanner fit in?: Fragmentation costs are a recurring topic. Headache-causing topics include inconsistent assessments, dispersed data, and missing connections between alerts. The Sanction Scanner Fusion platform aims to close that gap. Transaction monitoring, fraud monitoring, name screening, and client risk assessment are all combined into a single, smooth platform. Instead of putting data together across many suppliers, the team always has the complete picture with Fusion. Every alert is connected to a complete customer profile that includes entity resolution, cross-module analysis, a compliance dashboard, and a single risk score. To put it briefly, it consolidates the whole workflow into one central place.
10. Regulatory Expectations on Investigation Quality
The examiners check to see if the inquiry that led to each was done on time, well-recorded, and escalated in the right way. Examiners evaluate alert clearance protocols, escalation channels, and timeliness of SAR determinations. Weak alert dispositioning is a typical finding flagged in the FFIEC manual. So this becomes one of the highly examined topics of an exam.
Timeliness (60-day expectation): This is the clock that everyone operates on. A SAR must be filed within 30 days after the initial detection, which may provide a basis for filing a SAR. In the absence of a subject, this period is 60 days. If within the first 30 days no suspect can be identified, the time limit is extended, but in no case beyond a total period of 60 days. This criterion is found in the SAR regulations (31 CFR 1020.320 for banks) and is reiterated in the FFIEC BSA/AML Examination Manual. This guidebook is the reference that examiners work from. Failure to catch these in a manner that demonstrates a systemic failure, a pattern of noncompliance, or a significant case will be a problem. The authorities will take supervisory action after citing a violation.
Completeness of documentation: Examiners look for logic, not simply results. For the duration of the exam, they ask for SAR and CTR filing records. Additionally, they need authentic, independent test samples of SAR rulings pertaining to filed, unfiled, and escalated cases. One common issue is incomplete or inadequate documentation. The reasoning for this is that it prevents the disposition from being verified after the fact.
Appropriateness of escalation: The last topic is whether or not the alarms were escalated at the proper time. Dispositioning quality and escalation routes are examined at this point. The closed cases that require reexamination are checked. Quality is the factor to evaluate the process, not just the filing.
Sources:
[1] Financial Action Task Force. International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation: The FATF Recommendations. 2025.
[2] eCFR, U.S. Code of Federal Regulations. 31 CFR 1020.320: Reports by Banks of Suspicious Transactions. 2025.
[3] Financial Crimes Enforcement Network. Frequently Asked Questions Regarding the FinCEN Suspicious Activity Report. 2025.
[4] Financial Crimes Enforcement Network. FinCEN Assesses Record $1.3 Billion Penalty against TD Bank. 2024.
[5] FINRA. FINRA Fines Merrill Lynch $6 Million for Longstanding AML Program Failures. 2023.
[6] FFIEC. BSA/AML Examination Manual: Assessing Compliance with BSA Regulatory Requirements – Suspicious Activity Reporting. 2025.
FAQ's Blog Post
The customer risk score should be recalculated after any investigation that produces a SAR, confirms suspicious behavior, or reveals a sanctions change. If the score stays static, the next alert on that customer is weighed against a stale picture of their risk, which weakens both triage and every downstream decision.
Auto-closing low-risk alerts is considered an aggressive strategy and draws regulatory scrutiny. The risk is that a genuine case cleared as a false positive lets the activity continue undetected. Where institutions use it, the logic needs documentation, testing, and sampling that shows real cases are not being swept out with the noise.
Examiners look at three things: Timeliness against the 30 and 60-day SAR clocks, completeness of documentation so every disposition can be verified after the fact, and appropriateness of escalation. They sample filed, unfiled, and escalated cases, and they treat backlogs and weak alert dispositioning as findings in their own right.
AML investigation documentation should answer the five Ws plus how: Who, what, when, where, why, and the method of operation, with individual dates and amounts so the flow of funds can be traced. Supporting documents are never attached to the SAR; they are described in the narrative and retained for five years.
Tipping off is disclosing to a customer that a SAR has been or may be filed about them, and it is prohibited. Under 31 U.S.C. 5318(g)(2) it is a federal offense in the US, and FATF Recommendation 21 sets the same rule internationally. You can still ask normal due diligence questions; you never reveal why.
The large majority of AML alerts are false positives; queues where a few dozen genuine alerts sit among hundreds of noise alerts are common. That is why triage exists: Scoring alerts on customer risk, transaction value, and pattern severity so real risk surfaces first instead of being buried by volume.
A SAR is required for insider abuse in any amount, for suspicious activity of $5,000 or more with an identified suspect, and for $25,000 or more with no suspect, with thresholds varying by institution type. The standard is reasonable suspicion, deliberately set low: Not certainty, a good-faith assessment of the facts at hand.
A SAR must be filed within 30 calendar days of the initial detection of facts that may constitute a basis for filing. If no suspect is identified in that window, the deadline extends, but never beyond 60 days in total. The requirement sits in 31 CFR 1020.320 and is reiterated in the FFIEC BSA/AML Examination Manual.
Level 1 decides whether an alert deserves a second look: A fast pass of five to ten minutes confirming why the alert fired, pulling basic customer context, and clearing or escalating. Level 2 decides what the alert actually means, spending two to eight hours on transaction history, counterparty research, adverse media, and source of funds.
An AML alert investigation is the process that takes an alert from a transaction monitoring system through human assessment to a final decision: Close it as a false positive, keep monitoring, file a Suspicious Activity Report, or exit the customer relationship. An alert is a question, not an answer; the investigation answers it.


