Effectiveness review of transaction monitoring and sanctions screening
Thousands of alerts a month and almost no reports? Or suspiciously few alerts? We measure what your system actually detects, what it misses and why — and deliver a substantiation of your thresholds that a supervisor will accept.
The problem behind the numbers
Almost every institution running automated monitoring sits in one of two states. In the first, the system generates too many alerts: analysts assess superficially because otherwise the queue never clears, and the rare genuine signal disappears into the noise. In the second, the system generates too few alerts: comfortable, until a supervisor asks why the thresholds sit where they do and the answer is "that is how the vendor delivered it".
The core issue: a monitoring system ages without anyone noticing. Your client base changes, your products change, criminal behaviour changes — the scenarios stay where they were.
What we measure
Scenario coverage
Which risks from your risk assessment are actually covered by a scenario, and which are not covered at all? This is where supervisors start.
Thresholds
Through below-the-line testing we measure whether transactions just under the threshold contained signals you would have wanted to see. That turns a threshold into a substantiated choice.
False positives
Per scenario: how many alerts, how many lead to a report. Scenarios yielding close to nothing consume attention that is needed elsewhere.
Screening match logic
We test with distorted names, transliterations from Arabic and Cyrillic, address variants and known false negatives — not just whether the list loaded.
List coverage
Are you screening the lists your sanctions risk assessment requires, or the lists your vendor ships as standard? Those are rarely the same.
Alert backlog
Is there a queue? We clear it under four-eyes review, so investigation does not stall while remediation runs.
How it runs
| Week | What happens | Your input |
|---|---|---|
| Week 1 | Inventory of scenarios, rules and thresholds, mapped to your risk assessment. Data request covering twelve months of alerts and reports. | Two-hour intake plus a data export |
| Week 2 | Analysis of alert yield per scenario and sampling for below-the-line testing. | One interview with the analyst team |
| Week 3 | Manual assessment of the sample and testing of screening logic with distorted names and variants. | Test environment or vendor contact |
| Week 4 | Report with findings per scenario and rule, proposed changes with expected impact, and the substantiation of the new thresholds. | Two-hour debrief |
What you are left with
- A substantiation for every threshold that you can put in front of DNB or the AFM — the document almost always requested during an examination.
- A smaller queue without losing detection, because scenarios that yield nothing are adjusted or switched off.
- Visibility of the risks currently covered by no scenario at all.
- A test set you can repeat annually, so the next review is your own work.
What it costs
- Review of transaction monitoring or sanctions screening: from € 6,500 excluding VAT, four weeks.
- Combined review: from € 9,500 excluding VAT.
- Alert backlog clearance: fixed price per alert after a baseline measurement.
We are not tied to any vendor and we do not sell software. That makes our verdict on your system usable towards a supervisor — and occasionally uncomfortable towards your vendor.
Frequently asked questions
What is transaction monitoring?
Transaction monitoring is the continuous automated assessment of client transactions against predefined scenarios and thresholds, in order to detect patterns that may indicate money laundering or terrorist financing. The signals the system produces — alerts — are assessed by analysts and, where warranted, lead to a report of an unusual transaction to FIU-the-Netherlands.
Why do monitoring scenarios need tuning?
Because a scenario that worked at go-live moves with your client base, your product range and the behaviour of criminals — and your system does not. Without periodic tuning you end up in one of two states: too many alerts, so analysts assess superficially and genuine signals are buried, or too few alerts, so you feel comfortable while in fact you have stopped seeing anything.
What is below-the-line testing?
Below-the-line testing means deliberately examining transactions that fell just below the configured threshold and therefore produced no alert. By manually assessing a sample from that group, you measure whether your thresholds are set too high. It is the only way to demonstrate that your thresholds are substantiated rather than merely convenient.
How often should sanctions screening be tested?
Supervisors expect you to demonstrate periodically — in practice at least annually, and after any change to the system, the lists or the client base — that your screening works. That means testing with deliberately distorted names, transliterations, address variants and known false negatives, not simply confirming that the list loaded.
Which sanctions lists must be screened?
For institutions in the Netherlands the EU sanctions lists, which incorporate UN listings, are binding; the Sanctions Act 1977 provides the national basis. Many institutions additionally screen US OFAC and UK lists because of dollar or sterling flows and correspondent banking relationships. Which lists you need follows from your sanctions risk assessment, not from what your vendor ships by default.
What does an effectiveness review actually deliver?
A report setting out, per scenario and per screening rule, what it currently detects, what it misses, how many false positives it generates and what change we propose. Plus a substantiation of the chosen thresholds that you can put in front of a supervisor. In most engagements false positives fall sharply while detection stays level or improves.
What does an effectiveness review cost?
A review of transaction monitoring or sanctions screening starts at € 6,500 excluding VAT with a four-week turnaround. The combined review of both starts at € 9,500 excluding VAT. With a large number of scenarios or multiple systems we quote in advance.
Sources
- Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft) — wetten.overheid.nl
- Sanctions Act 1977 — wetten.overheid.nl
- EU Sanctions Map
- EU restrictive measures — European Commission
- FIU-the-Netherlands
Related
Want a quick read first? Send us your alert and report volumes for the past twelve months. In a thirty-minute call we will tell you whether that ratio is normal for your type of institution — at no cost. Book a call.