
Real-Time vs. Batch Transaction Monitoring
Transaction monitoring systems operate in two modes that serve different purposes and respond to different risk categories. Real-time monitoring evaluates each transaction as it occurs, applying instant rules that can block or hold a transaction before it completes — critical for catching obvious red flags like sanctions matches or transactions to blacklisted wallets that must be prevented rather than detected after the fact. Batch monitoring analyses completed transactions in aggregate over a time window (daily, weekly) to detect patterns that are not apparent from individual transactions — a sequence of structuring transactions that individually appear normal but collectively suggest deliberate threshold avoidance.
Most payment gateway compliance programs require both. Real-time monitoring for binary blocks (sanctions hits, confirmed blockchain analytics flags) and batch monitoring for pattern-based alerts (velocity changes, geographic clustering, structuring indicators). Systems that rely only on batch monitoring will miss transactions that should have been blocked in real time; systems that rely only on real-time rules will miss sophisticated patterns that emerge over time.
Alert Types and Their Escalation Paths
|
Alert Category |
Example Trigger |
Automated Response |
Manual Review |
|
Sanctions match |
Wallet address on OFAC SDN list |
Block transaction; freeze account |
Yes — confirm true positive; SAR consideration |
|
Blockchain analytics flag |
Wallet with >50% darknet exposure |
Hold transaction for review |
Yes — assess risk; approve or block |
|
Structuring indicator |
5 transactions just below €10,000 threshold in 3 days |
Alert compliance team |
Yes — review pattern; SAR if substantiated |
|
Volume spike |
Monthly volume 5x above established pattern |
Enhanced monitoring flag |
Yes — request business explanation |
|
Geographic anomaly |
Payments suddenly concentrated in high-risk jurisdiction |
Alert compliance team |
Yes — assess whether explained by business expansion |
|
Adverse media match |
Merchant linked to negative news in automated media scan |
Compliance team notification |
Yes — assess materiality; consider re-KYB |
Tuning Monitoring Systems to Reduce False Positives
An untuned transaction monitoring system generates alerts at a rate that overwhelms a compliance team's review capacity. If 40% of all transactions trigger alerts and 95% of those alerts are false positives (legitimate transactions flagged incorrectly), the compliance team spends most of its time clearing noise rather than investigating genuine risks. Effective monitoring requires continuous calibration.
Calibration involves measuring the true positive rate (alerts that result in confirmed suspicious activity) and false positive rate (alerts that are cleared as legitimate) for each rule and alert type, then adjusting thresholds, lookback windows, and risk weights accordingly. A structuring detection rule that triggers on three transactions over €5,000 within seven days may have a very high false positive rate for e-commerce merchants with regular high-value customers — adjusting the lookback window or adding a customer history filter can substantially reduce false positives without missing genuine structuring activity.
FATF Expectations for Transaction Monitoring in VASPs
FATF Guidance on Virtual Assets and Virtual Asset Service Providers specifies that VASPs must implement transaction monitoring systems that are risk-based, proportionate to the VASP's size and risk profile, and capable of generating SARs when suspicious activity is detected. FATF does not mandate specific technology solutions but expects VASPs to document their monitoring approach, demonstrate that alerts are reviewed in a timely manner, and show that SAR filing rates reflect genuine suspicious activity rather than systematic under-reporting.
National supervisors enforcing FATF standards increasingly conduct technology-specific assessments of transaction monitoring systems during VASP inspections — examining the rules in use, the alert volumes generated, the review workflow, the documentation of alert dispositions, and the SAR filing statistics. A VASP whose monitoring system generates no alerts and files no SARs will be viewed with scepticism: either the system is too weak to detect suspicious activity, or the VASP is operating in an implausibly low-risk environment.
Compliance Note: This glossary entry is provided for general educational purposes only and does not constitute financial, investment, legal, or tax advice. Industry terminology may vary across jurisdictions and providers; definitions herein may not directly reflect the specific features, terms, or specifications of Finassets' services. For details on Finassets' offerings, please refer to official product documentation or contact our team directly.