Alert queues rarely fail because analysts miss obvious fraud. They fail because hundreds of ordinary alerts get closed with notes like "reviewed, no concern", and when a regulator, auditor or partner bank samples them, nobody can say what was actually checked. This guide covers how to triage fraud and transaction-monitoring alerts and write a disposition that a second reviewer, or an examiner a year later, can follow.
The US rules quoted here are the ones for banks. Other institution types have parallel rules; check your own.
What the regulator expects of the process
The FFIEC BSA/AML Examination Manual describes the suspicious activity process in five parts: identifying or producing an alert of unusual activity, managing the alert, deciding whether to file, completing and filing the SAR, and monitoring and filing on continuing activity.
On alert management it says banks "should ensure that their suspicious activity monitoring program includes processes to evaluate any unusual activity identified, regardless of the method of identification," and that management "should establish a clear and defined escalation process from the point of initial detection to disposition of the investigation."
It also sets expectations for staffing. The bank "should assign adequate staff to the identification, evaluation, and reporting of potentially suspicious activities, taking into account the bank's overall risk profile and the volume of transactions," with staff who have the requisite experience, ongoing training and sufficient tools to "research activities and formulate conclusions." An alert queue that grows every weekend is a staffing question, not only a tuning question.
Step 1: Intake and first look
Before any research, confirm what the alert is.
- Source. A monitoring rule, a fraud model, an employee referral, a law enforcement request or a customer complaint. The manual lists all of these as ways unusual activity is identified.
- Scenario and threshold. Which rule fired, and on what values. A structuring rule and a dormant-account rule need different research.
- Subject and linked parties. The customer, related accounts, and any counterparties in the flagged activity.
- Duplicates and open cases. Check whether the same activity already sits in another alert or an open investigation. Merge rather than work it twice.
Step 2: Prioritise by risk, not by age
A first-in, first-out queue treats a possible account takeover like a slightly late rent payment. Set tiers in your procedures and apply them at intake. A workable scheme has three:
| Tier | Typical triggers | Handling |
|---|---|---|
| Urgent | Possible account takeover, funds still leaving, sanctions match, law enforcement request | Review now; consider holding funds under your procedures |
| Elevated | High-risk customer, large value against profile, repeat alerts on the same customer | Review ahead of the standard queue |
| Standard | Single rule hit, low value, customer with a clean history | Review in order |
Tiers are a policy decision. Write them down, and record the tier on each alert so a reviewer can see why it was worked when it was.
Step 3: Gather the context
An alert on its own says only that a transaction crossed a line. The disposition depends on what the customer was expected to do. Pull these before forming a view:
- The KYC or KYB profile. For a business: stated activity, industry, expected monthly volume, countries of operation, ownership and control persons. For an individual: occupation, stated source of funds, expected account use.
- Expected activity. The manual notes that banks set expected activity profiles and that the authority to establish or change them should be clearly defined.
- Account history. Twelve months of activity, prior alerts and how they were closed, prior SARs if your access permits.
- Counterparties. Who sent or received the money, whether they are known, whether they appear elsewhere in your book, and whether they screen clean.
- Customer contact history. Recent changes of address, phone, email or device, and any outreach already made.
Step 4: Test the alert against a hypothesis
Good triage is hypothesis testing. Write down the most likely innocent explanation and the most likely suspicious one, then look for the evidence that would separate them.
The FFIEC manual gives a useful reminder: "There are a variety of legitimate transactions that could raise a red flag simply because they are inconsistent with an accountholder's normal account activity," and it names a real estate purchase or sale, an inheritance and a gift as examples. A large credit that matches a property sale on public records is a different alert from a large credit followed within hours by outbound wires to new counterparties.
Common innocent patterns that trigger rules:
- Seasonal or one-off business events. A retailer's holiday volume, an annual insurance payout, a loan drawdown.
- Known life events. Property sales, inheritances, settlements.
- Profile drift. A business that grew and never had its expected volume updated.
- Internal transfers between accounts the same customer controls.
- Rule design. A threshold set so low that normal payroll trips it. Record these; they feed the tuning review.
Patterns that usually warrant escalation:
- Rapid in-and-out movement with little balance retained.
- Activity that contradicts the profile, such as a software consultancy receiving many small cash deposits.
- Counterparties with no apparent link to the stated business, or in unexpected jurisdictions.
- Amounts clustered just under reporting thresholds.
- Account changes followed by new payees, a common account-takeover sequence.
Step 5: Decide, and escalate when the facts call for it
Every alert ends in one of a few outcomes: close as explained, close with an action (a profile update, a customer outreach, a rule-tuning note), or escalate to investigation.
Escalation is not the same as a SAR decision. The manual describes research findings being "forwarded to a final decision maker (individual or committee)" who "should have the authority to make the final SAR filing decision." That decision stays with the institution. An analyst's job, in-house or outsourced, is to put the facts in front of that decision maker in a form they can act on.
Timing matters here, and it is widely misread. Under 31 CFR 1020.320, a bank must file a SAR "no later than 30 calendar days after the date of the initial detection" of facts that may constitute a basis for filing. If no suspect is identified, filing may be delayed an additional 30 calendar days to identify one, but "in no case shall reporting be delayed more than 60 calendar days." The FFIEC manual adds that "initial detection" should not be read as the moment a transaction is highlighted for review; the period "does not begin until an appropriate review is conducted and a determination is made that the transaction under review is 'suspicious'."
That is not permission to let alerts sit. The manual expects expeditious review, and a stale queue is its own finding. It does mean that the date of the determination should be recorded clearly in the case.
For continuing activity, the manual describes a review after 90 days, with the SAR filing deadline 120 calendar days after the previous related SAR. It also notes that examiners should refer to interagency SAR FAQs issued January 19, 2021 and October 9, 2025, which address continuing activity and documentation of decisions not to file. Read those alongside your own procedures.
Two confidentiality points belong in every analyst's training. The regulation makes SARs and any information that would reveal their existence confidential, and it prohibits notifying anyone involved in the transaction that it has been reported. Customer outreach during triage must never hint at a filing.
Step 6: Write the disposition
The FFIEC manual says banks "should document SAR decisions, including the specific reason for filing or not filing a SAR," while noting that "no single form of documentation is required when a bank decides not to file." The manual also says examiners focus on whether the bank has an effective decision-making process rather than on second-guessing individual decisions. A consistent disposition format is how you show that process exists.
A defensible disposition has five parts:
- What was reviewed. The alert, the period, the accounts, the systems and sources checked.
- Facts. What the activity was, stated plainly, with amounts, dates and counterparties.
- Evidence references. Where each fact came from: statement lines, profile fields, public records, customer responses. Link or cite them so a reviewer can open the same source.
- Reasoning. How the facts compare to the customer's expected activity, which hypothesis they support, and what, if anything, remains unexplained.
- Conclusion and action. Close, close with action, or escalate, plus any follow-up such as a profile update.
A note that reads "customer is a known business, activity is normal" fails on every one of these. So does a long note that restates the alert without testing it.
Illustrative disposition
The case below is fictional and shows the format only.
Alert: Rule "Large incoming wire vs 90-day average", Kestrel Freight Ltd (business account). Illustrative. Reviewed: 90 days of account activity; KYB profile (freight forwarding, stated monthly inflows in a set range); counterparty screening; public company registry for the sender. Facts: Single incoming wire, well above the account's 90-day average, from Northgate Holdings Ltd. No outbound movement in the following 5 days. Sender screened with no sanctions or PEP match recorded; registry shows it as an active company. Evidence: Statement line reference; KYB profile field "major customers" lists Northgate Holdings Ltd; screening record with date and lists searched; registry extract with capture time. Reasoning: Sender is a customer named at onboarding. Funds remain in the account. Amount exceeds the stated monthly range, which suggests the expected-activity profile is out of date rather than the activity being unexplained. Conclusion: Close as explained. Action: request updated volume expectations from the customer and update the profile. Recommendation prepared for analyst lead sign-off.
Step 7: Four-eyes review and QA
A second reviewer should check a sample of closed alerts and every escalation before it reaches the decision maker. The second reviewer asks one question: could I reach the same conclusion from this note and the linked evidence alone? If not, the note goes back. Track the reasons notes are returned; they show where training or procedures need work. See four-eyes review and false positives in screening for the related terms.
Where Sweat AI fits
Sweat AI is an AI-native BPO for banks and fintechs, starting with back-office workflows like KYB, onboarding and fraud reviews. Our team works alerts overnight and at weekends using your procedures, gathers the context, and writes each disposition in the format above with its evidence attached. Escalations reach your team as a prepared case with a recommendation; the SAR decision and any customer action stay with you. Read more about our fraud alert review service and 24/7 onboarding review.
Questions
When does the 30-day SAR clock start for a bank?
Under 31 CFR 1020.320, a bank files within 30 calendar days after the date of initial detection of facts that may be a basis for filing. The FFIEC manual says initial detection is not the moment a system flags a transaction; the period begins once an appropriate review determines the activity is suspicious. If no suspect is identified, filing may be delayed up to a further 30 days, but never beyond 60 days.
Do we need to document alerts we close as not suspicious?
The FFIEC BSA/AML manual says banks should document SAR decisions, including the specific reason for filing or not filing, while noting that no single form of documentation is required for a decision not to file. A clear disposition note on each closed alert is the practical way to meet that expectation.
Can an outsourced team make the SAR filing decision?
The FFIEC manual describes a final decision maker, an individual or committee, with authority to make the SAR filing decision. That authority sits with the institution. An outside team can triage, research and recommend, but the filing decision stays with you.
What makes an alert disposition defensible?
It states what was reviewed, the relevant facts with references to the evidence, the reasoning that connects those facts to the customer's expected activity, and a clear conclusion. A reviewer who was not there should be able to reach the same answer from the note alone.