Transaction Monitoring

Transaction Monitoring Calibration: A Practical Guide for MLROs

Transaction Monitoring Calibration: A Practical Guide for MLROs

Transaction monitoring calibration is one of the most technically demanding and least documented activities in a payment firm's AML programme. Most MLROs understand that their monitoring system needs to be calibrated — the FCA has made that clear in its thematic reviews and enforcement communications — but the practical mechanics of calibration: how often, what to measure, what to change, and how to document it, are poorly covered in the regulatory literature.

This guide sets out a practical quarterly calibration cycle for MLROs and the compliance engineering teams that support them. It does not assume a particular technology platform, but it does assume that you have access to alert-level data, false positive rate metrics, and SAR filing records.

What Calibration Means and What It Does Not Mean

Transaction monitoring calibration is the process of adjusting rule thresholds, peer group definitions, look-back periods, and suppression rules so that the system's alert output reflects the genuine risk distribution of your transaction population — rather than the generic risk distribution assumed by the vendor's default configuration or an earlier version of your own configuration that no longer reflects your current business.

Calibration does not mean reducing alert volumes as an objective. It means improving the ratio of meaningful alerts to total alerts. If your SAR filing rate from investigated alerts is 3% — meaning 97 out of every 100 investigated alerts produce no SAR — the objective of calibration is to improve that ratio, not simply to reduce the 100 to something smaller. A system that generates 50 alerts with a 6% SAR filing rate is better calibrated than one that generates 2,000 alerts with a 0.5% filing rate, because compliance analyst time is concentrated on higher-quality signals.

The MLR 2017 Regulation 19 requires systems and controls that are appropriate to the nature, scale and complexity of the firm. The FCA has interpreted this — in thematic reviews and skilled person reports — as requiring that monitoring systems are periodically reviewed and adjusted to remain appropriate as the firm's transaction profile changes. A calibration record is therefore both an operational document and a regulatory compliance document.

Phase 1: Data Collection (Weeks 1–2)

Before any rule changes are made, the calibration cycle begins with data collection. The data you need for a meaningful calibration review is:

Alert volume by rule. For each rule in your rule set, how many alerts did it generate in the review period (typically the previous quarter)? This identifies your highest-volume rules — the ones most likely to be generating disproportionate false positives.

Alert disposition by rule. For each rule, what proportion of the alerts generated were cleared at triage, escalated for investigation, and resulted in a SAR? A rule with a 0% SAR rate over 90 days is a strong candidate for threshold review. A rule with an unusually high SAR rate may be set too conservatively, meaning it is only firing on cases that are clearly suspicious rather than catching the full range of concerning activity.

False positive rate by customer segment. If you have peer group segmentation (and if you do not, implementing it should be your first calibration priority), break down the alert volume and disposition data by customer segment. High false positive rates within a specific segment indicate that the rule parameters for that segment need adjustment.

SAR timeline data. The elapsed time from alert generation to SAR filing for all SARs filed in the review period. If median filing time has increased quarter-on-quarter, it is likely that alert volumes are outpacing investigative capacity — a calibration problem that needs to be addressed by reducing noise, not by hiring more analysts.

Phase 2: Rule Performance Analysis (Weeks 2–3)

With the data assembled, the analysis phase ranks rules by their calibration need and identifies specific parameters for adjustment.

High-volume, Low-SAR Rules

Rules that generated a high volume of alerts but a very low SAR rate are the starting point. Before adjusting the rule, investigate why the alerts are being cleared. Are they being cleared at triage (suggesting the alert itself is low quality) or after investigation (suggesting the alert reaches investigation but the activity has a legitimate explanation)? The answer determines the appropriate calibration response.

If alerts are cleared at triage because they match a recognised pattern of legitimate activity — regular payroll runs, known supplier payments, recurring subscription collections — the appropriate response is to implement an exclusion or a triage filter. If alerts are reaching investigation but clearing because the transaction amount is within a wider legitimate range than the rule assumes, the appropriate response is to adjust the rule threshold itself.

Rules Not Generating Alerts

Rules that generated no alerts in the review period require investigation of a different kind. Has the rule been tested against your transaction data to confirm it would fire on a genuinely suspicious transaction? Is it possible that the rule threshold is set so high that no transaction in your customer population would reach it? Zero-alert rules may indicate a gap in coverage — or they may indicate a well-calibrated rule operating in a low-risk segment. The distinction matters and requires documented analysis.

Peer Group Drift

Customer segments defined at system implementation change over time as the firm's customer base evolves. A peer group defined as "consumer remittance customers, average transaction £150-£300" may have drifted to include customers whose average transaction is now £600 as the product has been used by more affluent customers. Peer group definitions should be reviewed by comparing the current transaction value distribution within each group against the distribution at the time the group was defined.

Phase 3: Parameter Changes and Approval

Each proposed calibration change requires a documented rationale and a formal approval process. The approval documentation should include:

  • The specific rule or parameter being changed
  • The current value and the proposed value
  • The data analysis that supports the change (alert volume, false positive rate, SAR rate)
  • The predicted effect on alert volume (this should be quantified, not estimated vaguely)
  • The risk assessment: could the change reduce detection coverage for a genuine financial crime scenario? If so, what is the countervailing justification?
  • The approval by the MLRO (or nominated officer)
  • The implementation date
  • The scheduled review date for this change

The FCA expects that calibration changes are made by an authorised person, are documented with reasoning, and are subject to a review cycle. A change log maintained in a format that can be produced to the regulator on request is standard practice among payment firms that have been through FCA skilled person reviews.

Phase 4: Post-Change Monitoring (First 4 Weeks After Implementation)

After calibration changes are implemented, a post-change monitoring period of four weeks is recommended before the next calibration cycle begins. During this period, monitor the alert volume and SAR rate for the changed rules daily. The objective is to confirm that the change has had the expected effect — and to identify unexpected consequences quickly.

A calibration change that reduces alert volume but also reduces the SAR rate proportionally is potentially acceptable (if the change was targeting a low-risk segment). A calibration change that reduces alert volume but causes the SAR rate to drop to zero — where it was previously non-zero — may indicate that the change has suppressed genuine suspicious activity. That outcome requires immediate review and potentially reversal of the change.

The Documentation Standard

The FCA has been explicit in its supervisory guidance that a well-documented calibration programme is a prerequisite for demonstrating MLR 2017 Regulation 19 compliance. The question the regulator asks is not "how many alerts do you generate?" but "can you demonstrate that your monitoring system is calibrated to your specific risk profile and that calibration decisions are reviewed and documented?"

For MLROs preparing for a supervisory visit or a skilled person review, the calibration record should demonstrate: a regular review cycle (quarterly is standard); documented decisions for each parameter in your rule set; a record of who made each decision and when; and evidence that the decisions were based on analysis of your actual alert and SAR data rather than on vendor recommendations alone.

What Calibration Cannot Do

Calibration improves the quality of alerts that reach your compliance team. It does not improve the investigation quality — that depends on analyst training, investigation procedures, and the completeness of the customer information available to the investigator. A well-calibrated system that generates 200 high-quality alerts will not produce better SAR outcomes if those 200 alerts are investigated with inadequate customer risk context or if investigation notes are not documented to the standard the MLRO needs to make a well-evidenced filing decision.

Calibration also cannot substitute for CDD quality. A transaction monitoring rule may fire correctly on a suspicious transaction, but if the customer's CDD file does not include adequate source of funds information, the investigation that follows will be constrained. These are complementary elements of an AML programme, not alternatives.

This article is published for informational purposes. RegSynq Ltd is not authorised or regulated by the Financial Conduct Authority. Nothing in this article constitutes legal advice. Firms should consult qualified legal and compliance counsel for guidance specific to their regulatory obligations.