INTERNATIONAL TRADE LAW

Transaction Monitoring: An AML Compliance Checklist

Transaction monitoring is the ongoing review of customer transactions to detect and report activity that may signal money laundering, terrorist financing, fraud, or sanctions evasion. It is the engine of a Bank Secrecy Act (BSA) / anti-money-laundering (AML) program: rules and analytics flag unusual activity, trained staff investigate the alerts, and the institution files the reports the law requires. A monitoring program that misses suspicious activity — or generates alerts no one works — exposes the institution to regulatory penalties and reputational harm. This checklist covers the components, thresholds, and reports an effective program needs.

Why Transaction Monitoring Matters

Under the BSA and the USA PATRIOT Act, covered financial institutions must monitor customer activity and report suspicious and large-cash transactions to FinCEN. Effective monitoring does more than satisfy examiners: it builds a real-time picture of customer behavior, surfaces the patterns criminals use to move illicit funds, and lets an institution act before it becomes a conduit for that money. For businesses engaged in international trade, monitoring also catches trade-based money laundering — schemes that disguise illicit value through over- or under-invoicing, phantom shipments, and mismatched goods.

The Transaction Monitoring Checklist

A defensible program is built from the same building blocks, documented and tested.

ComponentWhat it requires
Clear objectivesDefine the risks monitored, the products covered, and the program’s goals
Risk assessmentMap risk across customers, products, geographies, and channels to focus monitoring
Written policies and proceduresDocument how alerts are generated, investigated, escalated, and reported
Detection rules and scenariosSet thresholds and typologies tuned to the institution’s actual risk profile
Technology and data qualityEnsure monitoring systems receive complete, accurate transaction data
Alert investigation workflowAssign, document, and resolve every alert with a clear audit trail
Suspicious activity reportingFile SARs within required deadlines when criteria are met
Currency transaction reportingFile CTRs for reportable cash activity
Independent testingAudit the program periodically for gaps and effectiveness
TrainingKeep staff current on red flags, typologies, and regulatory expectations
RecordkeepingRetain reports and supporting documentation for the required period (generally five years)

The Reports the Law Requires

Two filings sit at the heart of monitoring, and their thresholds are well established:

ReportTriggerTiming
Currency Transaction Report (CTR)Cash transactions totaling more than $10,000 by or for one person in a business day (aggregated)File with FinCEN within 15 days
Suspicious Activity Report (SAR) — banksKnown or suspected suspicious activity of $5,000+ where a suspect is identified, or $25,000+ regardless of suspect (money services businesses file at $2,000)File within 30 calendar days of initial detection (up to 30 more, never exceeding 60 total, if no suspect is yet identified)

Two related points matter in practice. Structuring — breaking cash transactions into amounts at or below $10,000 to dodge the CTR requirement — is itself illegal, and monitoring should be calibrated to detect it across days and accounts. And a transaction occurring near the $10,000 threshold does not, by itself, require a SAR; a SAR is required when the institution knows, suspects, or has reason to suspect the activity is designed to evade reporting or otherwise meets SAR criteria.

Tuning, Testing, and Governance

A monitoring program is only as good as its calibration. Thresholds set too tight bury investigators in false positives; set too loose, they miss real activity. Effective programs document their rule logic, validate and re-tune scenarios against current typologies, and subject the whole system to independent testing. Sanctions screening should run alongside transaction monitoring — OFAC sanctions apply on a strict-liability basis, so screening counterparties against restricted-party lists is essential. See sanctions risk assessments and denied-party screening for the screening side, and the enhanced due diligence checklist for the onboarding controls that feed monitoring.

Frequently Asked Questions

What is transaction monitoring in AML?

It is the systematic review of customer transactions — in real time or after the fact — to detect patterns that may indicate money laundering, fraud, terrorist financing, or sanctions evasion, and to generate the alerts that lead to suspicious activity reports.

When must a SAR be filed?

A bank must file a SAR within 30 calendar days of initially detecting facts that may warrant one. If no suspect has been identified, it may take up to 30 additional days, but never more than 60 calendar days after initial detection.

What is the CTR threshold?

Financial institutions must file a Currency Transaction Report for cash transactions totaling more than $10,000 by or on behalf of one person in a single business day, aggregating multiple transactions that together exceed the threshold.

What is trade-based money laundering?

It is the use of trade transactions to move or disguise illicit funds — for example, over- or under-invoicing goods, shipping less than invoiced, or mislabeling products. It is a key reason transaction monitoring matters to importers and exporters, not just banks.

A monitoring program lives at the intersection of financial-crime compliance and international trade, where the same red flags can signal both laundering and sanctions exposure. Reidel Law Firm helps trade-facing businesses align their screening and compliance controls with their actual risk — talk to a trade compliance attorney about your program.