Skip to content
Bankautomation

BSA AML monitoring software for the alert queue, not the detection model

Be clear about what this page is. Bankautomation does not score transactions and does not decide what is suspicious. It runs the queue that forms after your monitoring system has raised an alert, which is where most of the hours and most of the exam findings actually are.

Run the demo

camt.053 · NOSTRO USD · value date 03 sep 2026

Nostro cash break, sample data

Match rate

75.0%

Breaks

4

At risk

$533.9k

Oldest

4d

Date ±1d
Amount

This console matches the first rows a side. It left out statement and ledger , so anything in them is not counted below. To run a full file, .

BRK-001

Aged 0d

$219,105.40

2026-09-03 · both sides

REF//FX/SPOT/7741 · INTERBANK FX DESK

Amount differs by 164.80 USD (0.075%)

Re-price the ledger leg on the correspondent rate source for the value date and post 164.80 USD to FX variance.

FX RATE SOURCE

→ Treasury Ops

BRK-002

Aged 4d

$187,650.00

2026-08-30 · ledger

PAY/90012/R · KESTREL LOGISTICS

Second ledger entry for 187,650.00 USD against REF//PAY/90012

Confirm the original entry REF//PAY/90012 cleared, then reverse this posting under maker-checker and note the reversal on the original item.

DUPLICATE POSTING

→ Finance

BRK-003

Aged 0d

$123,760.00

2026-09-03 · both sides

REF//TRF/554121 · HALCYON TRADING

Statement 61,880.00 vs ledger 123,760.00 (50% short)

Split the ledger posting and match the settled leg; leave the residual 61,880.00 USD open against the same reference.

PARTIAL SETTLEMENT

→ Payments Ops

BRK-004

Aged 0d

$3,410.00

2026-09-03 · statement

REF//CHG/Q3FEES · CORRESPONDENT CHARGES

On the statement, nothing in the ledger

Post 3,410.00 USD to the charges account for the period and add it to the standing accrual so it stops surfacing as a break.

FEE NOT ACCRUED

→ Finance

Everything matched under these tolerances.

Tighten the date or amount tolerance to see the breaks it was absorbing.

Correspondent statement

camt.053 · NOSTRO USD

Value date Reference Amount
2026-09-02 REF//NONREF/2026090301 1,284,500.00
2026-09-02 REF//INV/88231 96,400.00
2026-09-03 REF//TRF/554120 452,180.25
2026-09-03 REF//FX/SPOT/7741 218,940.60
2026-09-01 REF//SEPA/33421 74,220.00
2026-09-03 REF//CHG/Q3FEES 3,410.00
2026-09-03 REF//TRF/554121 61,880.00
2026-09-02 REF//PAY/90012 187,650.00
2026-09-02 REF//INV/88245 242,015.00
2026-09-03 REF//TRF/554133 18,905.50
2026-09-01 REF//PAY/90044 505,300.00
2026-09-03 REF//INV/88260 132,640.75

Internal nostro ledger

Core banking export

Value date Reference Amount
2026-09-02 NONREF/2026090301 1,284,500.00
2026-09-02 INV/88231 96,400.00
2026-09-03 TRF/554120 452,180.25
2026-09-03 FX/SPOT/7741 219,105.40
2026-08-31 SEPA/33421 74,220.00
2026-09-02 PAY/90012 187,650.00
2026-09-03 TRF/554121 123,760.00
2026-08-30 PAY/90012/R 187,650.00
2026-09-02 INV/88245 242,015.00
2026-09-03 TRF/554133 18,905.50
2026-09-01 PAY/90044 505,300.00
2026-09-03 INV/88260 132,640.75
Matched pairs are tinted on both sides. Breaks carry the brass left rule and appear in the worklist.

Sample data only. Matching runs in your browser; classification is written by the model when you press Run. Matching done in your browser. Writing classifications… Classifications written by the model on this run. Decision support, not a compliance determination. The classification model was unavailable, so the built-in rule classifier wrote these. Same matching, same numbers. This console classifies up to 12 runs a minute and this run went over, so the built-in rule classifier wrote these. Same matching, same numbers. Wait a minute for the model, or . The model wrote the first 8 classifications; the rule classifier wrote the remaining .

Open the full resolver

Scope, stated plainly. This is workflow and evidence software. It is not a transaction monitoring engine, not a detection model and not a sanctions screening tool. It does not make compliance determinations, and it does not replace your BSA officer, your model validation or your institution's obligations under its own program.

The alert is raised in one system and worked in three others

A monitoring system produces alerts. What happens next, in most banks, is not a system at all. The alert is opened in the monitoring tool, the customer is researched in the core, the transactions are pulled into a spreadsheet, the narrative is written in a document, the approval is an email, and the case file is whatever the analyst remembered to save into a folder named after the alert.

Nothing in that sentence is a detection problem. It is a workflow problem, and it is the reason two banks running the same monitoring scenarios can have completely different exam outcomes. The detection was equivalent. The record of what was done about it was not.

What the triage layer has to do

Step 01

Take the alert as an item

Alerts arrive from the monitoring system as items with a type, a subject, a risk rating and the transactions that triggered them, rather than as a screen an analyst has to be logged into.

Step 02

Route on rules you set

By alert type, risk rating, entity, business line or language. A high risk correspondent alert does not sit in the same queue as a low value structuring alert, and neither waits for someone to notice it.

Step 03

Enforce the evidence set

Each alert type carries a required evidence list. The disposition action is not available until the list is satisfied, so an incomplete case cannot be closed and then discovered at exam time.

Step 04

Approve under segregation of duties

The analyst proposes a disposition and a different role approves it. The system refuses a self approval regardless of permissions, and logs the attempt.

Where the hours actually go

Alert volume is the number every vendor quotes and it is rarely the constraint. The constraint is the time between opening an alert and having enough in front of you to make a decision. When that assembly is manual, it dominates the day, and it is identical for every alert of the same type, which is what makes it automatable without touching a single detection threshold.

Stage of an alertWorked across four systemsWorked as one item
Assignment Analyst picks from a shared list, or a lead allocates by hand Routed on type, rating and business line at arrival
Context gathering Manual lookups in the core, the CRM and prior cases Subject, history and prior alerts attached to the item
Transaction review Exported to a spreadsheet and annotated locally Triggering transactions held on the item with the analyst notes
Narrative Free text in a document, quality varies by analyst Structured template per alert type, required fields enforced
Approval Email to a manager, decision recorded in the reply Maker-checker action, approver and timestamp on the record
The case file Assembled from folders and inboxes when asked One export, complete, with the policy version in force

Swipe the table sideways to read every column.

Detection is unchanged in both columns. Only the record of the work is different.

A worked example

Input

Alert as it arrives from monitoring

  • ALERT-2026-04417 · Scenario: rapid movement of funds
  • Subject: business account, opened 2024-11, MSB related
  • Risk rating: high · Raised: 03 Sep 2026 06:12
  • Triggering activity: 9 credits, 8 debits, 14 days
  • Aggregate: $486,300 · Prior alerts: 2 (both closed)

Output

Item in the triage queue

  • HIGH RISK routed to Enhanced review, not the general queue
  • AGE 0d clock starts at raise time, SLA target 5 business days
  • Prior alerts and dispositions attached automatically to the item
  • Required evidence: source of funds, expected activity, 2 prior dispositions, EDD note
  • Disposition blocked until the evidence list is complete, then maker-checker

Escalation to a SAR decision, and where we stop

When an alert escalates, the workflow escalates with it: a case that can hold several alerts, a longer evidence set, a different approval chain, and a deadline that is counted rather than remembered. What the software does is make sure the file is complete, the clock is visible and the approvals happened in the right order.

What it does not do is decide. Whether activity is suspicious, whether a filing is required, and what the narrative says are determinations made by your BSA officer under your program. Software that claims to make that call for you is describing a compliance risk as a feature. We package the decision, we do not make it.

Tuning, backlog and the two numbers that get confused

A false positive rate is a property of your scenarios and thresholds, and it is changed by tuning the monitoring system with model validation behind it. A backlog is a property of your throughput. They are different problems and they are constantly treated as one, usually by proposing a tuning exercise to fix a queue that is behind because triage takes forty minutes an alert.

  • If alerts are mostly noise, that is a tuning and validation exercise in your monitoring system. Nothing on this page fixes it, and no vendor should promise a reduction without your data.
  • If alerts are reasonable but the queue is behind, that is triage time and it is very fixable, because most of it is assembly rather than judgement.
  • If dispositions are inconsistent between analysts, that is a required evidence and template problem, not a training problem.
  • If exams find gaps in closed cases, that is an enforcement problem: the system allowed an incomplete case to close.
  • If nobody can say how old the oldest open alert is, that is the first thing to fix, and it is a reporting change rather than a project.

What an examiner asks for, and how long it takes

The exam question is rarely about the model. It is a sample: pull these fifteen alerts from this period and show us what was done. The honest measure of a triage layer is how long that takes and whether the answer is the same for every one of the fifteen.

  1. 01Every alert raised in the period, with its disposition and the date it was reached.
  2. 02For a sampled alert, the complete file: evidence, notes, transactions, approvals, timestamps.
  3. 03The policy and rule versions in force at the time of the decision, not the versions in force today.
  4. 04The aging profile of open alerts, and the escalation record for anything past its target.
  5. 05Evidence that the person who approved was not the person who prepared.

Each of those is a filtered export when alerts are items in a system with an audit trail, and a multi day reconstruction when they are folders and inboxes. That difference is the entire argument for this layer.

How this sits with the rest of the program

Monitoring is one queue among several that a compliance function runs. The onboarding and periodic refresh queues are covered in KYC automation software, the program level framing is in AML compliance software, and the generic mechanics of queues, SLAs and maker-checker are in compliance workflow automation. If you are selecting a vendor, AML software for banks is the buyer guide, and the anti money laundering program post is the background reading.

Questions about bsa aml monitoring software

Is this a transaction monitoring system?

No, and it is important that it is not sold as one. It does not score transactions, does not raise alerts and contains no detection scenarios. It takes the alerts your monitoring system produces and runs the queue, the evidence and the audit trail around them.

Will it reduce our false positives?

It cannot, and any vendor promising that without your data is guessing. False positives come from scenarios and thresholds in the detection layer. What this reduces is the time each alert takes to work and the inconsistency between analysts.

Does it decide whether to file a SAR?

No. Determinations are made by your BSA officer under your program. The system makes sure the file is complete, the deadline is visible and the approvals happened in the right order.

How do alerts get in?

The day one path is a scheduled export from your monitoring system, ingested as items with type, subject, rating and triggering transactions. Where an API exists it can be configured as a source, but nothing waits on that.

Can we keep our existing disposition codes?

Yes. Alert types, disposition codes, required evidence sets, SLA targets and approval chains are all configuration. The one thing that is not configurable is the ability to switch off the audit trail.

More banking automation pages

Every process line we cover, in one place.

Account reconciliation software Where the differences start, account by account. Bank reconciliation software Statement against ledger, MT940 and camt.053 native. Automated reconciliation software Match rates, tolerances, and what auto-match must never mean. Payment reconciliation software Instructed, settled and posted, reconciled three ways. Financial reconciliation software The same engine, framed for the finance team. ATM reconciliation software Cash, switch and network settlement, balanced daily. Credit union reconciliation software Corporate, share draft, card, ATM and shared branching. ACH reconciliation software Origination, receipt, returns and FedACH settlement. Federal Reserve account reconciliation Master account, FIRD, Fedwire and FedNow against the GL. Correspondent bank reconciliation Due from, due to and respondent settlement against the GL. AML compliance software Program workflow, evidence and cadence. Not a detection model. KYC automation software Onboarding and periodic refresh, queued and evidenced. AML software for banks What to ask, and what to refuse to buy. Compliance workflow automation Maker-checker, SLAs and evidence as a system property. RPA for banks Why screen-scraping bots break, and what replaces them. General ledger reconciliation software Sub-ledger to GL, and the suspense account nobody owns. Balance sheet reconciliation software Certification, sign-off and the quarter-end pack. ISO 20022 payment automation Structured data, repair rates and CBPR+ deadlines. Nostro reconciliation automation The most bank-specific reconciliation there is.

Get started

Put your first reconciliation on rails

Create an account, and we will email you how onboarding works and what a first source connection looks like. The Reconciliation Break Resolver is open to try right now, on sample data, without an account.

Run the demo

No card required to create an account. Sample data only in the demo. Bankautomation is operations software, not a regulated service.