KibiPay
HomeBlog › AML

Model Risk and Tuning Transaction-Monitoring Rules

7 min read AML
AMLTransaction monitoringModel risk
Model Risk and Tuning Transaction-Monitoring Rules

A transaction-monitoring system generates alerts based on rules and models, and every one of those rules has parameters: thresholds, time windows, amounts, counts. Set them too tight and analysts drown in false positives; set them too loose and real financial crime slips through unnoticed. The discipline of choosing and validating those parameters is tuning, and the broader practice of managing the ways these models can be wrong is model risk management. This post explains both and why regulators care so much about them.

Why tuning matters so much

Monitoring rules are blunt instruments. A rule like "alert on aggregate cash deposits over a threshold in a rolling window" is only useful if the threshold and window reflect real risk. Most alerts that a typical system generates turn out to be false positives — legitimate activity that merely resembles a suspicious pattern. Each false positive costs analyst time, and a backlog of noise can bury the genuine alerts that matter. At the same time, a threshold set too high creates false negatives: real laundering that never triggers an alert. Tuning is the search for the parameter values that best separate the two.

Above-the-line and below-the-line testing

The core technique for tuning a threshold is testing on both sides of it. Suppose a rule fires when a value exceeds a threshold — the threshold is "the line."

Together, ATL and BTL testing bracket the threshold from both directions, giving evidence for whether it sits in the right place. Regulators expect this kind of empirical justification rather than thresholds pulled from thin air.

Segmentation

A single global threshold rarely fits everyone. A USD 10,000 aggregate that is unremarkable for a cash-intensive retailer is alarming for a salaried individual. Effective tuning uses segmentation: grouping customers by type, expected behaviour, product, and geography, then setting parameters per segment. Good segmentation sharpens detection and cuts false positives by comparing customers against relevant peers rather than one universal yardstick.

Model risk: the ways monitoring goes wrong

Regulators increasingly treat monitoring systems as models subject to formal model risk management, echoing frameworks originally written for capital and credit models. Model risk is the risk of adverse outcomes from a model that is flawed or misused. In transaction monitoring it shows up as:

Governance: keeping models honest

Managing model risk is a governance process, not a one-off. Mature programs include:

The goal is a system whose behaviour is understood, justified, and kept current — one that can be explained to a regulator with evidence, not assertion.

Key takeaways

See these rails in motion

KibiPay connects UK Faster Payments, Bacs, CHAPS, Mojaloop mobile money and Solana behind one API, with ISO 20022 messaging and real-time fraud & AML screening.

Open the live console How it works