Playbook · 6 minute read
How to Build an AML Monitoring System
AI in AML monitoring works best as a triage and contextualisation layer over existing detection: ranking alerts by likelihood, assembling the customer and transaction context investigators gather manually, and supporting narrative drafting, with disposition decisions and any suspicious activity determination remaining with qualified investigators under documented model governance.
Transaction monitoring in most institutions produces far more alerts than investigators can clear, the overwhelming majority benign, and the genuine cases wait in the queue behind them. The instinct is to replace the detection engine with something smarter; the better first move is to fix what happens after an alert fires, because that is where investigator time goes and where supervisors have fewer objections. This guide covers building that, drawing on FISTA Solutions' AI agents delivery in financial crime operations. It complements the AI for compliance operations whitepaper and ai fraud detection. This article is general guidance, not legal advice.
Why not replace the detection engine first?
Because the rules-based layer is documented, explainable, and already assessed by the supervisor, and replacing it means re-establishing all of that. A machine learning detection model may find patterns rules miss, and firms do pursue that, but it requires validation, explainability work, and supervisory engagement on a scale that delays any benefit by a year or more.
Triage and enrichment above the existing engine deliver most of the operational gain, require far lighter governance because they do not change what is detected, and build the evidence and confidence that a later detection change would need.
| Layer | Change | Governance burden | Time to value |
|---|---|---|---|
| Alert enrichment | What investigators see | Light | Weeks |
| Alert ranking | Order of work | Moderate | Weeks |
| Narrative support | Drafting assistance | Light | Weeks |
| Automated closure | Which alerts a human sees | Heavy | Months, with supervisor |
| Detection model | What is alerted | Heaviest | A year or more |
What does enrichment assemble?
Everything the investigator would gather by hand: the customer's KYC profile and risk rating, the transaction in context with the account's normal pattern, counterparties and their profiles, related accounts and parties, prior alerts and their dispositions, screening results, and any adverse media. Presented as a structured file rather than as links to seven systems.
That is where most investigator time goes, and automating it returns that time without touching the decision. It also improves consistency, because every alert arrives with the same context rather than whatever the investigator had time to pull.
How does ranking help?
By putting the most probable and most severe alerts first. Investigators working a queue in arrival order spend the same time on an obvious false positive as on a genuine concern. Ranking by likelihood, informed by historical disposition patterns, and by severity, informed by amount, customer risk, and typology, changes what gets attention when the queue is long.
Ranking does not close anything. Every alert still requires disposition; the order changes.
What about automated closure?
The highest-value and highest-risk capability in the area, and it requires conditions. Validation against investigator decisions on a substantial and representative sample, with agreement measured. Documented reasoning recorded on every automated closure. Ongoing independent sampling of auto-closed alerts by investigators, with the sample rate and results tracked. Clear scope, so only alert categories with demonstrated performance are eligible. And discussion with the supervisor before implementation rather than disclosure afterwards.
Firms that deploy automated closure without these conditions create the examination finding that ends the programme and damages the firm's standing on everything else it wants to automate.
How is narrative drafting supported?
By assembling the facts into the firm's standard narrative structure, with the investigator writing the analysis and conclusion. A suspicious activity report's narrative has a required shape, and drafting the factual chronology from the enriched file saves substantial time while leaving the reasoning, which is the part that matters and the part the investigator is accountable for, with the person.
Generated conclusions are not acceptable. A narrative that asserts suspicion the investigator did not form is a compliance failure with personal consequences for whoever signed it.
What does typology detection add?
Pattern discovery across customers and time that per-transaction alerting misses: networks of related accounts moving funds in patterns that are individually unremarkable, structuring distributed across entities, and emerging typologies not yet encoded in rules.
This is analyst-driven exploration supported by the system rather than autonomous detection. The analyst forms a hypothesis, the system helps test it across the data, and confirmed findings feed back into detection tuning and, where warranted, into investigations. Graph analysis is particularly suited to the network cases. See how to build a neo4j ai agent.
What model governance applies?
The firm's model risk framework, in full. Documented purpose, scope, and limitations. Validation evidence demonstrating the component performs as described on representative data. Ongoing performance monitoring with thresholds. Change control covering model, prompt, and threshold changes with revalidation. Periodic independent review. And an owner accountable for it.
AI components in financial crime are models, they will be examined as such, and a firm that has not documented them will spend an examination explaining why. See ai model risk management.
How is it evaluated?
Enrichment completeness, judged by investigators against what they would have gathered. Ranking quality, measured by whether genuine cases appear earlier in the queue. Time per alert, before and after. Investigator agreement with any automated dispositions. Quality of dispositions, assessed by quality assurance review, which should improve rather than merely accelerate. And the outcome measures the firm reports to its supervisor.
What does the build sequence look like?
Two weeks establishing scope and governance requirements with compliance and model risk. Two weeks on alert enrichment across the source systems. Two weeks on ranking with investigators calibrating. One week on narrative factual drafting. Then, only if the evidence supports it and the supervisor has been engaged, scoped automated closure with sampling.
What goes wrong?
Detection replacement attempted first. Automated closure without validation or supervisory engagement. Generated conclusions in narratives. Model governance treated as documentation written afterwards. Ranking that buries a genuine case because the model never saw that typology. And efficiency reported without disposition quality, which is how a programme accelerates its way into a finding.
How FISTA Solutions helps
FISTA Solutions builds AML support as an enrichment and triage layer over existing detection, with model governance documentation from the first design, investigator workflow that returns context-gathering time, factual narrative drafting that leaves conclusions with people, and automated closure only where validation and supervisory engagement support it, through AI enablement, AI agents, and forward deployed engineers. The record behind the approach is 150+ projects for 50+ companies with 99.9% uptime.
To clear the alert queue without weakening the control, message FISTA on WhatsApp, or read the AI for compliance operations whitepaper.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01Should AI replace the transaction monitoring engine?
Rarely, and not first. The rules-based detection layer is documented, explainable, and accepted by supervisors. AI adds most value as a triage and enrichment layer above it, ranking and contextualising alerts, which improves outcomes without replacing a control the regulator has already assessed.
02Where does investigator time actually go?
Context gathering. For each alert an investigator pulls the customer profile, transaction history, related parties, prior alerts, KYC file, and screening results before forming a view. Automating that assembly returns most of the time without touching the decision.
03Can alerts be closed automatically?
Only with validation against investigator decisions on a substantial sample, documented reasoning on every closure, ongoing independent sampling of closed alerts, and discussion with the supervisor beforehand. Automated closure introduced without those conditions is the finding that ends the programme.
04What model governance applies?
The firm's model risk framework: documented purpose and limitations, validation evidence, ongoing performance monitoring, change control with revalidation, and periodic independent review. AI components in financial crime are models and will be examined as such. Confirm with compliance and counsel.
05How does typology detection differ from alerting?
Typology work looks for patterns across customers and time that individual alerts miss, such as networks of related accounts or structuring across entities. AI supports the analyst exploring hypotheses; it does not autonomously declare a typology, and findings feed detection tuning rather than direct action.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. Weâll map the fastest credible path from intent to verified production.