In short: Transaction monitoring alert triage is the work of deciding which rule-triggered alerts reflect genuine suspicion and which are ordinary account behaviour. Zyphe runs it as an operated desk: agents reconstruct the transaction history behind each alert, test it against that customer's own established pattern and against your typology library, and produce a written disposition, with a draft narrative where escalation is warranted. Your investigators approve. The decision to report to the FIU never leaves your firm, because AMLR Article 18(3)(e) does not allow it to.
Desk description last reviewed 2026-08-20.
What arrives at this desk?
The work this desk takes off your team, stated as the queue it actually receives.
Rule-triggered alerts
Threshold breaches, velocity rules, structuring patterns and jurisdiction rules firing out of your existing monitoring platform.
Aged backlog
Alerts that have been open past your internal service level, where the cost of the backlog is now itself a supervisory finding waiting to happen.
Repeat alerts on the same customer
The same rule firing monthly on a customer whose behaviour was explained and documented the first three times.
Escalations needing a narrative
Cases where the conclusion is already reached and the remaining work is assembling the facts into something a reviewer can sign and a regulator can read.
How does the transaction monitoring alert triage desk work?
Five steps, the same way every time, because consistency is what an audit is actually testing for.
- 1
Reconstruct the account picture
The agent pulls the transaction history around the alert, every prior alert on the same customer, how each was dispositioned, and what the customer declared about expected activity at onboarding.
- 2
Test against that customer's baseline
An alert only means something relative to what is normal for this customer. Seasonal trade, a funding round, a payroll cycle and a genuine structuring pattern all breach the same threshold and read completely differently against the customer's own history.
- 3
Apply your typologies
Your rules, your thresholds, your typology library. The desk applies the detection criteria you approved rather than importing a generic pattern set and calling it best practice.
- 4
Draft the disposition or the narrative
Alerts that resolve get a reasoned close. Alerts that do not get a narrative drafted in your house format, with the supporting facts assembled, for your investigator to amend, approve and file.
- 5
Write it back where you work
The disposition and its evidence return to your monitoring or case management platform, in the structure your audit trail already expects.
What we prepare, and what you approve.
Agent-prepared, human-approved is not a hedge in the marketing copy. It is the shape EU law requires, and it is the reason this desk can be bought by a regulated firm at all.
| Stage | The agent prepares | Your team approves |
|---|---|---|
| Alert disposition | Rebuilds the account picture and drafts the close with its reasoning | Approves the close, or sends it back |
| Detection criteria | Applies the rules and typologies you approved | Owns and approves the criteria for detecting suspicious or unusual activity AMLR Art. 18(3)(f) |
| Customer risk profile | Assembles the behavioural evidence | Sets or revises the risk profile AMLR Art. 18(3)(c) |
| The relationship | Prepares the file for a decision | Decides whether to continue, restrict or exit AMLR Art. 18(3)(d) |
| Reporting | Drafts the narrative and gathers the supporting facts | Decides whether to report, and files with the FIU AMLR Art. 18(3)(e) |
Why the split is drawn there
Article 18 of Regulation (EU) 2024/1624, the EU anti-money laundering regulation that applies from 10 July 2027, permits obliged entities to outsource tasks to service providers, and requires the supervisor to be notified before the provider starts. Article 18(2) then treats the service provider as part of the obliged entity, leaves the entity fully liable, and requires it to be able to demonstrate to its supervisor that it understands the rationale behind the activities the provider carries out. Article 18(3) lists tasks that cannot be outsourced under any circumstances. Every one of them sits on your side of this table.
That demonstrability requirement is the reason each case leaves this desk with its reasoning written out rather than with a score. A confidence number cannot be explained to a supervisor. A rationale can.
What this desk will not do
- Write or tune your detection rules and thresholds
- Close an alert without your approval
- Decide a customer's risk rating
- File a suspicious activity report on your behalf
- Decide whether to exit a relationship
What do you actually receive?
A decision-ready file, in the systems you already run.
- A disposition for every alert, with the account reasoning written out
- A draft narrative in your house format wherever escalation is warranted
- A backlog worked down to an agreed level, then held there
- Everything written back into your monitoring or case management platform
The software behind this desk
If you would rather run the work yourself than have it operated, these are the same capabilities as a product surface.
Frequently asked questions about transaction monitoring alert triage.
What is transaction monitoring alert triage?
Transaction monitoring alert triage is the first-line review of alerts a monitoring system generates: establishing what the customer actually did, whether it fits their known profile and declared activity, and whether the alert should be closed with a reason or escalated for investigation. It is high volume, mostly resolves to ordinary behaviour, and is where most compliance operations backlogs accumulate.
Can an AI agent close an AML alert on its own?
Not at this desk. The agent drafts the close and the reasoning behind it; a human approves. Two constraints make that the right design rather than a courtesy: AMLR Article 18(3) reserves the customer risk profile, the relationship decision and FIU reporting to the obliged entity, and GDPR Article 22 constrains decisions based solely on automated processing that have legal or similarly significant effects on a person.
Can the agents draft SARs or STRs?
They draft the narrative and assemble the facts behind it. They do not decide that a report is warranted and they do not file it. AMLR Article 18(3)(e) names reporting to the FIU as a task that cannot be outsourced under any circumstances, with a narrow carve-out only for another obliged entity in the same group and Member State. Drafting is the part that takes the hours; deciding is the part that has to stay with your MLRO.
Do you replace our transaction monitoring system?
No. The desk works the alerts your existing platform produces and writes back into it. Rule design, tuning and the platform itself stay where they are. What changes is who works the queue those rules generate.
How do you handle an existing alert backlog?
As a defined slice with an agreed service level, run alongside your live queue rather than instead of it, so current alerts do not age while the backlog is cleared. Aged alerts are worked with the same written reasoning as new ones, because a backlog cleared without documented rationale simply converts one supervisory finding into another.
The other desks
Most teams start with one queue and add the next once the first is clearing.
Sanctions and PEP alert review
Works the screening queue your engine produces: compares each hit against your matching policy, writes the disposition and its reasoning, and escalates the ones that are genuinely unclear.
See the deskAdverse media review
Reads the underlying coverage rather than the headline, resolves whether the story is actually about your customer, classifies it against your risk taxonomy, and summarises with citations.
See the deskUBO and EDD review
Walks the ownership chain through corporate registries to the natural persons behind it, screens them, and assembles the enhanced due diligence file including what could not be resolved.
See the deskKYC periodic review and refresh
Re-runs the checks on customers falling due, compares what it finds against the file you already hold, and reports what actually changed rather than rebuilding a dossier nobody reads.
See the deskBook a demo
Put the transaction monitoring alert triage queue on a desk.
Book a demo and bring a real slice of your queue. We will work it, show you the files, and you will see exactly what your team still has to approve.