Regulatory expectations on financial crime in the region have risen sharply in recent years, and banks have responded in the most visible way available: more rules, more scenarios, lower thresholds and larger investigation teams. The result in many institutions is a monitoring system that generates far more alerts than it can handle, the large majority of which turn out to be nothing.
It feels safe. It is not. When analysts are measured on how many alerts they close, they close alerts. The genuinely suspicious case sits in the same queue as hundreds of false positives, and receives the same few minutes of attention.
An alert that nobody has time to investigate properly is not a control. It is a liability with a timestamp.
Why alert volumes keep growing
Rules are added and never removed. Each finding from an audit or regulator adds a scenario. Nobody tests whether older scenarios still produce anything useful, so the rule set only ever grows.
Thresholds ignore the customer. A single threshold applied to a salaried retail customer and a trading company will be wrong for both. Without customer segmentation, the system cannot tell unusual behaviour from normal behaviour.
Data quality undermines everything. Incomplete KYC records, inconsistent customer identifiers and missing transaction detail generate alerts that exist only because the data is poor.
Tune with evidence
Effective tuning is a controlled, documented exercise, not a quiet raising of thresholds. It tests scenarios against historic outcomes, samples below the threshold to confirm nothing material is being missed, and records the rationale for every change. Done well, it reduces noise and improves detection at the same time, and it gives the bank a defensible story for the regulator.
Redesign the investigation
Much of an analyst's time goes on gathering information rather than judging it: pulling statements, checking screening results, assembling the customer's history. That assembly work is well suited to automation and, increasingly, to AI agents working under human supervision. The analyst's time moves to the decision, which is where it should have been all along.
Govern it like a model
Transaction monitoring is a model and should be governed as one: an inventory of scenarios, periodic validation, clear ownership and an audit trail for every change. SAMA, the CBUAE and the QCB will ask how the system was calibrated. The answer should be a document, not a recollection.
Three questions for the MLRO
What proportion of alerts led to a suspicious activity report last year? When was each scenario last validated against outcomes? And how much of an analyst's day is spent gathering information rather than making a judgement? The answers show whether the function is controlling risk or processing volume.