top of page

The Noise That Hides the Signal: Why Transaction Monitoring Has Lost Its Way

  • Writer: Elizabeth Travis
    Elizabeth Travis
  • Jun 8
  • 11 min read
Silhouetted radio telescope dish against a cloudy sunset sky, with the sun glowing behind the metal lattice.

When TD Bank pleaded guilty in October 2024 to violations of the Bank Secrecy Act (BSA) and agreed to pay approximately US 3.09 billion in penalties to the United States Department of Justice and federal regulators, much of the post-mortem focused on culture.


Commentators dwelt on the internal "flat cost paradigm" that capped the bank's anti-money laundering (AML) budget regardless of business growth, and on the conduct of individual employees. Less attention was paid to a quieter operational truth at the centre of the Financial Crimes Enforcement Network (FinCEN) consent order.


From January 2018 to April 2024, approximately 92 per cent of TD Bank's transaction volume went entirely unmonitored. That figure represented around US 18.3 trillion in customer activity. The bank's transaction monitoring programme had remained, in the regulators' own description, effectively static from 2014 through 2022. No new scenarios. No material recalibration. The system was not blind. It had been left behind.


More than a decade after the HSBC settlement of 2012 first surfaced the question of whether large banks could be relied upon to make their own monitoring systems work, the same pattern recurs across the regulated sector with depressing regularity. Transaction monitoring, the most resource-intensive discipline in financial crime compliance, has reached a point at which the volume of information it generates routinely exceeds the capacity of the firms that operate it to convert that information into meaningful action.


This is not a technology problem. It is not a staffing problem. It is not a tuning problem. It is a structural mismatch between what the discipline generates and what it can absorb. And it has become one of the principal mechanisms by which serious financial crime continues to evade detection.


Transaction monitoring is being asked to do too many things at once


Modern transaction monitoring is no longer a single function. It is a composite of overlapping responsibilities accumulated incrementally over twenty years of regulatory evolution.


A typical UK bank now expects its monitoring framework to detect classical money laundering typologies, identify terrorist financing indicators, surface tax evasion patterns, support sanctions evasion detection, contribute to fraud prevention, generate the evidence base for suspicious activity reports (SARs), support law enforcement investigations, and identify authorised push payment fraud under the Payment Systems Regulator's mandatory reimbursement regime, which came into force on 7 October 2024.


Each objective has its own risk indicators, its own scenario logic and its own performance metrics. They are layered onto infrastructure that was, in most institutions, designed in the late 2000s for a much narrower purpose. The result is predictable: overlapping scenarios, conflicting thresholds and alert populations that no single function can rationally interpret.


The 2023 transaction monitoring best practice guide published by the Association of Certified Anti-Money Laundering Specialists (ACAMS), Effectiveness Matters, reported alert conversion rates among the financial institutions interviewed ranging from 3 per cent at the lower end to 20 per cent at the upper end. ACAMS itself observes that conversion rates are blunt instruments for measuring effectiveness. The more telling indicator is what happens to the alerts that close without action.


Across the institutions reviewed, the most common closure rationale was variance from expected behaviour deemed consistent with the customer profile. That phrase, repeated across hundreds of thousands of dispositions in the UK regulated sector each year, is doing more work than any single analyst can defend.


The distinction between filtering and investigation has collapsed


The legitimate function of high-volume monitoring is to operate as a wide-net first-stage filter. Scenarios are designed to err on the side of inclusion, generating alerts on the assumption that a triage process will subsequently narrow the population to the genuinely material.


This is sensible control design. A scenario that fires on every cash deposit above a threshold is not failing because most of those deposits are innocent. It is failing only if the indicators that distinguish the suspicious from the innocent cannot be reliably applied at the next stage.


The problem in current practice is that the next stage has collapsed. Where alert volume has outrun investigative capacity, triage is no longer a process of analytical narrowing. It is a process of clearing queues. The closure rationale becomes generic. The supporting evidence becomes formulaic. The decision to escalate or close is shaped by the time available to make it, not by the risk it discloses.


This is the operational mechanism by which monitoring failure most often occurs. It is not that alerts are missing. It is that alerts are being dispositioned through processes that no longer constitute investigation.


To a regulator reviewing a sample of closed alerts after a control breakdown, this is indistinguishable from the system working as intended. The records exist. The rationales are documented. The deficiency is visible only when the closed alerts are read alongside the activity they failed to escalate.


TD Bank, Monzo and Danske: three failures with a common shape


The TD Bank case is, on its facts, the most significant transaction monitoring failure in modern banking history. The settlement announced on 10 October 2024 imposed the largest BSA penalty ever assessed against a depository institution. FinCEN's share of the penalty, US 1.3 billion, was the largest the agency had ever imposed on a bank.


The regulators' findings are unusual in their specificity. TD Bank's transaction monitoring programme was not absent. It was not even broken in any conventional sense. It was simply not maintained. From 2014 to 2022 the bank added no new monitoring scenarios and made no material changes to existing ones, even as its product range expanded and its risk profile evolved.


Internal audits flagged the deficiencies repeatedly. Senior management was aware.


The result, as documented in the consent order, was that three money laundering networks moved over US 670 million through TD accounts. The networks did not have to defeat the bank's controls. They simply had to operate outside the narrow band of activity those controls were configured to see.


The Monzo case, announced by the Financial Conduct Authority (FCA) on 7 July 2025, is the contemporary UK illustration. The fine was £21,091,300. The FCA's Final Notice covered inadequate anti-financial crime systems and controls between October 2018 and August 2020, and a subsequent breach of a Voluntary Requirement that had been imposed to contain those failures.


The FCA found that Monzo had failed to design, implement and maintain adequate customer onboarding, customer risk assessment and transaction monitoring systems. The bank's customer base grew from around 600,000 to 5.8 million during the relevant period. Its compliance infrastructure did not grow with it.


Particularly relevant for the present argument is the FCA's published criticism of Monzo's over-reliance on post-event transaction monitoring to compensate for weaknesses in customer onboarding. Monitoring was being asked to do work that belonged upstream. Despite the regulatory restriction in place from August 2020, Monzo opened over 34,000 high-risk accounts that should have been refused.


The Danske Bank case in its Estonia branch remains the European reference point for scale. The internal investigation conducted by the Danish law firm Bruun & Hjejle, commissioned by Danske Bank and published in September 2018, found that approximately 200 billion euros in suspicious transactions had flowed through the branch between 2007 and 2015.


The Danske failure was structural, cultural and supervisory. Its operational expression was familiar. Alerts and concerns were generated, by both automated systems and human reporters, then absorbed into the existing control framework without disturbing it.


The 2021 NatWest case in the UK followed a related pattern at a much smaller scale, with the FCA's published facts identifying scenarios that fired on the wrong transaction types and concerns from branch staff that did not translate into appropriate escalation.


The four cases differ in scale, jurisdiction and the precise mechanism of failure. They share a common shape: information generated by the monitoring infrastructure faster than it could be interrogated, and a disposition layer that no longer functioned as a layer of investigation.


Defensive reporting has become the symptom no one names


The closest indicator of the system's strain is not the alert population. It is the SAR population. The UK Financial Intelligence Unit, within the National Crime Agency (NCA), received 872,048 SARs in the year to March 2024, according to the NCA's most recent published Annual Report. The previous year's figure was 859,905. The annual total has remained close to or above 900,000 for several years.


Successive NCA assessments have observed that a significant proportion of SARs contain limited intelligence value, often because the underlying alert was insufficiently investigated before the report was filed.


This is the corollary of monitoring under capacity pressure. Where alerts cannot be confidently dispositioned, the defensible option for the analyst is to file. A SAR insulates the institution and the individual from a charge of failing to report.


The cumulative effect is a regulatory reporting environment in which the volume of SARs has expanded faster than the capacity of the receiving agencies to process them. Genuinely material reports are obscured by the volume of marginal ones. The Law Commission's 2019 review of the SARs regime made this point explicitly. Successive reform programmes have improved aspects of the regime since. The structural pressure has not been resolved.


A monitoring framework that generates defensive filings rather than investigative outcomes is not merely inefficient. It is misaligned with the regulatory purpose the entire control was designed to serve.


The technological response has often made the problem worse


Vendors and consultants have responded to the volume problem largely by promising to reduce it through better technology. Some have delivered meaningful improvements. Others have compounded the problem.


The compounding operates in two ways. First, when machine learning is layered on top of existing rules-based monitoring without replacing it, the result is often a larger alert population, not a smaller one. The new system generates its own alerts, which are added to the existing queue rather than substituted for it. Firms find themselves running parallel systems whose outputs cannot easily be reconciled.


Second, the introduction of probabilistic scoring without corresponding investment in model governance creates a new failure mode. Analysts are presented with alerts ranked by risk score, but without the time or training to interrogate the scoring logic. They begin to defer to the score. Any bias or gap in the underlying model is inherited uncritically by the human review process.


The European Banking Authority (EBA) fifth Opinion on money laundering and terrorist financing risks, published on 28 July 2025, identified this dynamic in unusually direct terms. More than half of the serious compliance failures reported to the EBA's EuReCA database involved the improper use of regulatory technology tools. The Opinion warned of the careless use of innovative compliance products as a discrete source of money laundering and terrorist financing risk.


The position is further complicated by the widespread practice of outsourcing first-line alert review to managed service providers, often operating from lower-cost jurisdictions. These arrangements can be operationally effective when properly governed. But they introduce a structural distance between the analysts disposing of alerts and the contextual knowledge required to interpret them. A junior offshore reviewer applying a generic closure rationale to a sophisticated trade-based money laundering pattern is not a failure of the same character as one performed by an in-house analyst. The outcome is indistinguishable.


Technology and outsourcing can ease the volume problem. They cannot, on their own, resolve the disposition problem. The decisions about what to monitor, at what threshold, with what investigative response and under what governance are control design decisions. They cannot be outsourced to a vendor or to a service provider.


The standard has moved beyond system existence


Recent enforcement and supervisory commentary make the position clear. The standard expected of transaction monitoring is no longer the existence of a system. It is the demonstrable effectiveness of the framework that surrounds it.


The FCA's 2024-2025 Annual Report identified financial crime as the leading source of enforcement activity, with the regulator's published case data indicating that the majority of open enforcement cases concern this area. The wider European picture is consistent.


The Bank of Lithuania fined Revolut Bank UAB 3.5 million euros in April 2025 for inadequate monitoring of business relationships and transactions. The Central Bank of Ireland imposed a 21.5 million euro fine on Coinbase Europe in 2025 for transaction monitoring deficiencies. The FCA's October 2024 enforcement against Starling Bank, which produced a £29 million penalty, included failures of sanctions screening that had remained undetected for years.


The pattern is not confined to one jurisdiction, one sector, or one type of institution. Several principles now separate the defensible from the indefensible.


First, scenario design must be defensible. Tuning methodology must be formal, including above-the-line and below-the-line testing, with documented rationale for threshold settings and periodic revalidation against the firm's evolving risk profile. The expectation expressed in FCA and Prudential Regulation Authority (PRA) supervisory dialogue, and in Office of the Comptroller of the Currency (OCC) and FinCEN findings in the US, is that firms can articulate why each scenario operates at the threshold it does. The TD Bank case is, in part, an enforcement demonstration of what happens when a firm cannot.


Second, the boundary between automated disposition and human investigation must be drawn deliberately. Where alerts are closed automatically, the basis must be capable of explanation to a regulator, including the model validation evidence that supports the auto-closure logic. Where alerts are closed after human review, the depth of that review must be calibrated to the risk indicators the alert was designed to surface. The closure rationale must engage with those indicators rather than recite generic language.


Third, governance must be informed by capacity, not just volume. Senior management cannot make informed decisions about risk appetite if the management information they receive reports only the number of alerts processed. The relevant indicators are scenario coverage against the inherent risk assessment, conversion rates by scenario, SAR conversion rates by scenario, average investigation time, sample quality assurance findings, and capacity utilisation trends. The absence of these indicators in board reporting is itself a deficiency.


Fourth, monitoring cannot be assessed in isolation. Effectiveness depends on the quality of the customer due diligence that informs it. The Monzo case turned in significant part on the FCA's finding that the bank had relied on monitoring to compensate for weaknesses in onboarding.


The shift in many institutions towards perpetual customer due diligence, in which customer risk profiles are updated continuously rather than at periodic intervals, is one of the more significant developments in financial crime compliance over the last five years. Firms that have implemented it effectively report scenarios that fire less often and more accurately, because the customer profile against which behaviour is assessed is itself current. Firms that have not implemented it are increasingly being asked by supervisors why not.


The cultural shift that has to accompany the technical fix


The structural pattern endures because the incentives that produce it remain intact. Monitoring teams are measured on queue clearance rates more often than on investigation quality. Senior management is reassured by the existence of infrastructure rather than by evidence of its effectiveness. Boards are presented with dashboards that show alerts processed rather than alerts whose disposition would not withstand scrutiny.


The cultural frame is one of throughput, when it should be one of efficacy. TD Bank's "flat cost paradigm" is an extreme expression of this incentive structure, but it is recognisable in a milder form across the sector.


Changing this requires more than technical adjustment. It requires the compliance function to assert, internally and visibly, that the purpose of transaction monitoring is the detection of financial crime, not the generation of regulatory artefacts. That assertion has implications for resourcing, for governance and for the relationship between compliance and the business. It is not always a comfortable conversation. It is the conversation the enforcement record now demands.


The signal beneath the noise


The defining failure of compliance in the current era has not been an absence of controls. It has been the proliferation of controls without the operational capacity to make them effective. Transaction monitoring is the most visible expression of this gap.


The firms that will be best placed for the next decade of enforcement are not those with the largest monitoring systems. They are those that have aligned their alerting architecture with their investigative capacity, invested in the customer due diligence that makes monitoring more accurate, and built the governance that makes effectiveness visible to those accountable for it.


The noise will not disappear. The signal can still be recovered. The discipline is to listen for it.


Is your firm confident that the alerts it generates are the alerts it actually investigates?


OpusDatum works with regulated firms to review transaction monitoring effectiveness, calibrate alert thresholds to investigative capacity, and design governance structures that give senior management genuine visibility of control performance. The objective is not to reduce alerts for its own sake. It is to ensure that the alerts a firm generates are the alerts it can defensibly investigate.


If you would like to discuss how OpusDatum can help you assess the operational effectiveness of your transaction monitoring framework, please contact us.

bottom of page