Preloader

Loading

100 Transaction Monitoring Interview Questions and Answers

100 Transaction Monitoring Interview Questions and Answers

Transaction monitoring is where most AML interviews are won or lost. Employers want to know whether you can read an alert, work out what the money is actually doing, and defend your decision in writing. These transaction monitoring interview questions cover the fundamentals, alert investigation, typologies, systems and thresholds, and escalation — with model answers you can adapt to your own experience.

How to use these answers

Do not memorise them word for word. Interviewers can tell. Use each answer as a structure, then substitute your own examples. Where you lack direct experience, say what you would do and why — reasoning scores higher than recall.

Fundamentals (Q1–10)

1What is transaction monitoring?

Transaction monitoring is the ongoing review of customer transactions to identify activity that may indicate money laundering, terrorist financing, fraud or sanctions evasion. It compares actual behaviour against what is expected for that customer, and generates alerts where activity is inconsistent or matches known risk patterns.

2Why do financial institutions carry out transaction monitoring?

It is a legal obligation under AML regulations, but the practical purpose is detection. KYC tells you who the customer says they are; monitoring tells you what they actually do. It is the control that catches risk that was not visible at onboarding.

3What is the difference between real-time and post-event monitoring?

Real-time monitoring screens a transaction before or as it is processed, allowing it to be blocked or held — typically used for sanctions and high-risk payments. Post-event monitoring reviews transactions after settlement, usually in batches overnight, and is used for behavioural and pattern-based detection.

4How does transaction monitoring relate to KYC?

They are two halves of the same control. KYC establishes the expected profile — income source, business type, anticipated activity. Monitoring tests actual behaviour against that expectation. Weak KYC makes monitoring far less effective, because there is no reliable baseline to compare against.

5What is a customer risk profile and why does it matter in monitoring?

It is the institution's assessment of the money laundering risk a customer presents, based on factors such as occupation, geography, product usage and ownership structure. It matters because monitoring should be risk-based — higher-risk customers warrant tighter thresholds and closer review.

6What is a scenario or rule in a monitoring system?

A scenario is a coded pattern the system looks for — for example, cash deposits exceeding a threshold within a rolling period, or rapid movement of funds in and out of an account. When transaction data satisfies the scenario logic, an alert is generated for human review.

7What is a threshold?

A threshold is the value or frequency at which a scenario triggers — for example, cash deposits over a set amount. Thresholds are calibrated to balance detection against alert volume: set too low, teams drown in false positives; set too high, genuine risk is missed.

8What is a false positive?

An alert generated by legitimate activity that superficially matches a risk pattern — for instance, a business with genuinely seasonal cash takings triggering a volume rule. False positives are unavoidable, but a high rate signals poorly calibrated rules or weak customer data.

9What is a false negative, and why is it more serious?

A false negative is genuinely suspicious activity that the system fails to flag. It is more serious than a false positive because the risk goes entirely undetected — no one reviews it. False positives cost time; false negatives cost enforcement action.

10What is the risk-based approach in monitoring?

It means allocating monitoring effort in proportion to risk rather than treating all customers identically. Higher-risk customers and products receive tighter scenarios and more frequent review; lower-risk relationships receive proportionate attention. Regulators expect the approach to be documented and defensible.

Alert handling and investigation (Q11–20)

11Walk me through how you investigate an alert.

I start by understanding why the alert triggered — which scenario, and on what data. Then I review the customer profile to establish what is expected. Next I examine the transactions themselves: amounts, counterparties, geographies, timing and patterns. I look for a legitimate explanation consistent with the customer's known activity, check for related alerts or history, and then reach a documented conclusion to close or escalate.

12What information do you review first?

The customer profile, because without knowing what is normal you cannot judge what is abnormal. Occupation or business type, expected turnover, geography and account purpose give the baseline against which the alerted activity is assessed.

13How do you decide whether to close an alert or escalate?

The test is whether the activity has a plausible, evidenced explanation consistent with the customer's profile. If it does and I can document it, I close. If it does not — or if the explanation cannot be verified — I escalate. The standard for escalation is reasonable suspicion, not proof.

14What makes a good alert narrative?

Clear reasoning that another reviewer, or a regulator, can follow without re-doing the work. It should state what triggered the alert, what was reviewed, what was found, how the conclusion was reached, and why. Facts first, conclusion supported by those facts.

15How much time should an alert take?

It depends on complexity. Simple false positives may take minutes; a complex corporate case with multiple counterparties can take hours or days. I would rather flag that a case needs more time than close it prematurely — a rushed close is the decision that gets criticised later.

16What do you do if the customer's explanation seems plausible but you cannot verify it?

Unverified is not the same as verified. I document the explanation, note that supporting evidence was unavailable, and weigh that gap against the rest of the risk picture. If the activity remains unexplained in substance, that supports escalation rather than closure.

17How do you handle an alert on a long-standing customer with no prior issues?

History is context, not a clearance. A clean record makes a legitimate explanation more likely, but it does not remove the need to test the activity. Criminals also use established accounts precisely because they attract less scrutiny.

18What is alert aggregation?

Grouping related alerts on the same customer or network so they are reviewed together rather than in isolation. It matters because individually unremarkable alerts can form a clear pattern when viewed collectively.

19How do you prioritise a queue of alerts?

By risk, not by age alone. Higher-risk customers, larger values, sanctions-adjacent indicators and cases with regulatory deadlines come first. I also watch for ageing alerts, because unmanaged backlogs are themselves a compliance failure.

20What would you do if you disagreed with your team lead's decision to close an alert?

I would set out my reasoning and the evidence supporting it, and ask them to reconsider. If they still disagreed, I would accept the decision but ensure my view was documented. Escalation routes exist for genuine concerns, and a documented dissent protects both the analyst and the institution.

Red flags and typologies (Q21–30)

21What is structuring?

Breaking a large sum into multiple smaller transactions to stay below reporting or detection thresholds. Indicators include repeated deposits just under a threshold, activity split across branches or accounts, or several individuals depositing into one account.

22What are the three stages of money laundering?

Placement, where illicit funds enter the financial system; layering, where transactions obscure the origin; and integration, where the funds return as apparently legitimate wealth. Monitoring is most effective at placement and layering.

23What is a pass-through or funnel account?

An account where funds arrive and are moved out almost immediately, leaving little balance. It suggests the account is being used to move value rather than to hold it, which is a classic layering indicator.

24What red flags would concern you in a cash-intensive business?

Deposits inconsistent with the business size or sector, cash volumes that do not track normal trading patterns, deposits at unusual times or locations, and takings that show none of the seasonality you would expect for that trade.

25What is trade-based money laundering?

Moving value through trade transactions by misrepresenting price, quantity or quality — over- or under-invoicing, phantom shipments, or multiple invoicing of the same goods. It is difficult to detect because the transactions look commercial.

26What are money mules and how would you spot one?

Individuals who receive and forward funds on behalf of others, often recruited online. Indicators include a young or low-income profile receiving unexplained credits from multiple senders, followed by rapid withdrawal or onward transfer.

27What geographic factors raise risk?

Jurisdictions with weak AML controls, those on FATF's grey or black lists, sanctioned countries, known secrecy havens, and conflict zones. Context matters — a transfer to a higher-risk country is not suspicious on its own if it fits the customer's genuine business.

28What red flags apply to terrorist financing?

Terrorist financing often involves small amounts, which makes value-based rules less effective. Indicators include frequent low-value transfers to higher-risk regions, links to charitable or non-profit entities, and activity inconsistent with a customer's stated income.

29How does money laundering differ from terrorist financing?

Money laundering disguises the illicit origin of funds; terrorist financing conceals their intended use, and the money itself may be legitimately earned. The direction of concern is reversed, which is why detection relies more on context and connections than on transaction size.

30What crypto-related red flags would you watch for?

Transfers to or from unregulated exchanges, use of mixers or tumblers, rapid conversion between assets with no economic purpose, exposure to darknet or sanctioned wallet clusters, and fiat activity that does not match the customer's declared crypto involvement.

Systems, rules and thresholds (Q31–40)

31Which transaction monitoring systems have you used?

Name the platforms you have genuinely worked with and what you did in them — reviewing alerts, adding case notes, running searches, pulling reports. If your experience is training-based, say so and describe the workflow you learned. Overstating tool experience is easily exposed.

32What is rule tuning?

Adjusting scenario logic and thresholds so detection stays effective without generating unmanageable alert volumes. It is driven by outcome data — which rules produce escalations, and which produce almost entirely false positives.

33How would you reduce false positives without weakening detection?

Improve customer data quality first, since most false positives stem from poor segmentation. Then segment thresholds by customer type rather than applying one figure to everyone, and refine rule logic. Simply raising thresholds across the board reduces noise and detection together.

34What is customer segmentation in monitoring?

Grouping customers with similar expected behaviour — for example retail versus corporate, or by industry — so thresholds reflect what is normal for that group. Without segmentation, a rule appropriate for a salaried individual will constantly misfire on a trading business.

35What is model validation?

Independent testing that a monitoring system works as intended — that rules fire correctly, data feeds are complete, and coverage matches the institution's risk assessment. Regulators expect it to be periodic and documented.

36What happens if transaction data feeding the system is incomplete?

Detection fails silently. Missing counterparty details, absent transaction types or broken feeds mean scenarios never trigger, producing false negatives no one sees. Data completeness is a control issue in its own right and should be escalated.

37How is AI or machine learning used in transaction monitoring?

Mainly to score and prioritise alerts, detect anomalies that fixed rules miss, and reduce false positives. Most institutions run it alongside rule-based detection rather than replacing it, because rules are explainable to regulators and models must still be validated and governed.

38What are the limits of automated monitoring?

Systems detect patterns, not intent. They cannot assess whether an explanation is credible, interpret unusual but legitimate business context, or exercise judgement. Human review is what converts an alert into a decision.

39What is a below-the-line test?

Sampling transactions that fell just below a threshold and did not alert, to check whether genuine risk is being missed. It is the standard method for testing whether thresholds are set too high.

40Who is responsible if the monitoring system fails to detect suspicious activity?

The institution. Regulators do not accept system limitations as a defence — they expect firms to know their coverage, test it, and remediate gaps. Accountability sits with senior management and ultimately the MLRO.

Escalation and reporting (Q41–50)

41What is a SAR or STR?

A Suspicious Activity Report — or Suspicious Transaction Report in many jurisdictions — is the confidential report filed with the national financial intelligence unit when an institution has reasonable suspicion of financial crime. It reports suspicion, not proof.

42What is the threshold for filing?

Reasonable suspicion. You do not need evidence of a crime or certainty about what occurred — only a reasonable basis to suspect the activity may involve illicit funds or purposes.

43Who makes the final decision to file?

The Money Laundering Reporting Officer, or nominated officer. Analysts escalate with documented reasoning; the MLRO decides and files. Concentrating that decision keeps reporting consistent and accountable.

44What is tipping off?

Informing the subject, directly or indirectly, that a report has been made or is being considered. It is a criminal offence in most jurisdictions because it allows suspects to move funds or destroy evidence.

45How would you handle a customer asking why their payment is delayed during an investigation?

I would follow the institution's approved script and give no indication that a report exists or is contemplated. Typically that means referring to standard internal checks. Improvising here risks tipping off.

46What goes into a good escalation or SAR narrative?

Who is involved, what happened, why it is suspicious, and the supporting detail — dates, amounts, counterparties, jurisdictions. The reasoning matters most: investigators need to understand why the activity concerned you, not just see a transaction list.

47What happens after a report is filed?

It goes to the financial intelligence unit, which analyses it alongside other intelligence and decides whether to escalate to law enforcement. The filing institution usually receives no feedback, and must maintain confidentiality regardless.

48Should the relationship be exited after filing?

Not automatically. Exit is a separate commercial and risk decision, and in some cases authorities prefer the relationship to continue so activity can be observed. It is decided at the appropriate level, not by the analyst.

49What if you suspect a colleague is ignoring suspicious activity?

I would raise it through the proper internal channel — my manager, compliance, or whistleblowing procedures if needed. The obligation to report sits with the institution, and staying silent could expose both the firm and me personally.

50How do you keep your knowledge of typologies current?

FATF reports and typology papers, national FIU publications, regulator enforcement notices, and industry alerts. Enforcement actions are especially useful because they show exactly which control failures regulators are penalising.

Risk-based approach in practice (Q51–60)

51How does customer risk rating affect monitoring?

It drives how closely activity is watched. Higher-risk customers attract tighter thresholds, more scenarios and shorter review cycles; lower-risk customers receive proportionate coverage. The rating should also be revisited when monitoring reveals behaviour inconsistent with the original assessment.

52A customer's risk rating is low but their activity looks concerning. What do you do?

I treat the activity on its merits, not the rating. A low rating explains why fewer alerts fired; it does not make the behaviour acceptable. I would investigate fully, escalate if warranted, and flag that the risk rating itself may need review.

53What triggers a review of a customer's risk rating?

Material changes — new ownership or control, a move into a higher-risk jurisdiction or sector, adverse media, sanctions exposure, or a sustained shift in transaction behaviour. Periodic review cycles also force reassessment even where nothing obvious has changed.

54What is a trigger event?

Something that prompts due diligence outside the normal review cycle — a SAR filing, a sanctions hit, negative news, a change in beneficial ownership, or unusual activity. It moves the customer to the front of the queue rather than waiting for the scheduled review.

55How does product risk affect monitoring?

Products differ in how easily they move or obscure value. Cash-heavy services, international wires, correspondent relationships, prepaid instruments and crypto carry higher inherent risk, so they warrant more scenarios and tighter thresholds than a basic savings account.

56What is de-risking, and what is the problem with it?

Exiting or refusing whole categories of customers rather than managing their risk individually. Regulators discourage it because it pushes activity into less regulated channels and can exclude legitimate businesses. The expectation is to manage risk, not avoid it wholesale.

57How would you monitor a politically exposed person?

With enhanced scrutiny — tighter thresholds, closer attention to source of funds and wealth, and alertness to transactions involving state entities, contracts or unexplained third-party flows. PEP status raises inherent corruption risk; it is not an accusation.

58What is ongoing due diligence and how does it link to monitoring?

It is the continuous obligation to keep customer information current and ensure activity remains consistent with what is known. Monitoring is its practical engine — alerts often reveal that the customer file is out of date and needs refreshing.

59How do you monitor a customer whose business genuinely changes?

Update the profile first, then recalibrate expectations. Legitimate growth or a change in trading model will look anomalous against a stale baseline. The key is verifying the change is real and documented, rather than assuming either innocence or guilt.

60What documentation supports a risk-based monitoring programme?

An enterprise-wide risk assessment, documented scenario coverage mapped to those risks, threshold rationale, tuning and validation records, and clear procedures for alert handling and escalation. If it is not documented, regulators treat it as not done.

Sanctions and screening interplay (Q61–70)

61How does sanctions screening differ from transaction monitoring?

Sanctions screening is a name and identifier match against designated lists, usually in real time, and a true match requires blocking. Transaction monitoring is behavioural and pattern-based, usually post-event, and produces alerts for judgement rather than automatic blocks.

62What would you do with a potential sanctions match on a payment?

Hold the payment, do not release it, and escalate immediately to the sanctions team. Sanctions breaches carry strict liability in many regimes, so speed and escalation matter far more than trying to resolve it independently.

63What indicators suggest sanctions evasion?

Sudden routing changes through third countries, use of intermediaries with no clear commercial role, vague or altered payment references, dual-use goods, ownership structures obscuring a designated party, and counterparties in jurisdictions bordering sanctioned states.

64What is the 50 percent rule?

Under several regimes, an entity owned 50 percent or more by designated parties — directly or in aggregate — is itself treated as sanctioned even if not separately listed. It means screening must consider ownership, not just names on a list.

65What is fuzzy matching?

Matching logic that catches near-matches rather than exact strings — accounting for transliteration, spelling variants, name order and typos. It increases false positives but is essential, since exact matching alone misses obvious evasion.

66How do you resolve a screening hit?

Compare all available identifiers — full name, date of birth, nationality, address, entity registration — against the list entry. Sufficient distinguishing data supports a documented false-positive discount; insufficient data means escalation, not assumption.

67What is adverse media screening and how does it support monitoring?

Searching news and public sources for negative information about a customer — investigations, charges, regulatory action. It provides context monitoring cannot see on its own, and can convert an ambiguous alert into a clear escalation.

68How would you assess whether adverse media is credible?

Check the source's reliability, how recent it is, whether it is corroborated elsewhere, and whether it genuinely concerns your customer rather than a namesake. Allegation, charge and conviction carry different weight and should not be conflated.

69What is a dual-use goods concern?

Goods with both civilian and military application. Trade finance involving them warrants extra scrutiny because they are frequently used in sanctions and export-control evasion, particularly where the end user or destination is unclear.

70Why is correspondent banking considered higher risk?

Because you are relying on another institution's controls for customers you cannot see. Nested relationships compound this — the respondent's own clients may include institutions you have no visibility of at all, so monitoring depends on inference and the quality of the respondent's programme.

Crypto and emerging payments (Q71–78)

71How does crypto monitoring differ from traditional monitoring?

Blockchain transactions are publicly visible, so on-chain tracing is possible in ways bank data is not — but identity is pseudonymous. Monitoring therefore focuses on wallet clustering, exposure to risky services, and the fiat on- and off-ramps where identity attaches.

72What is the Travel Rule?

A FATF requirement that originator and beneficiary information accompanies virtual asset transfers above a threshold, mirroring the wire transfer rule. Missing or incomplete Travel Rule data is itself a monitoring red flag.

73What is a mixer or tumbler, and why does it matter?

A service that pools and redistributes crypto to break the transaction trail. Because its only real purpose is obfuscation, exposure to mixers is treated as a strong laundering indicator and, in some cases, sanctions exposure.

74What is blockchain analytics?

Tools that cluster addresses, attribute wallets to known entities, and score exposure to illicit sources such as darknet markets, ransomware or sanctioned wallets. They give crypto monitoring the counterparty context that raw blockchain data lacks.

75What red flags apply at a fiat off-ramp?

Large conversions inconsistent with declared income or activity, funds arriving from high-risk wallet clusters, rapid conversion with no economic rationale, and structuring of withdrawals below thresholds.

76How would you monitor a customer who trades crypto but banks with you?

Focus on the fiat side you can see — whether flows match their declared trading activity, which exchanges they interact with, whether counterparties are regulated, and whether volumes are consistent with stated income. Ask for evidence of source of funds where scale warrants it.

77What monitoring challenges do instant payments create?

Settlement is irrevocable and immediate, so post-event detection cannot recover funds. That shifts weight onto real-time controls and makes fraud and mule activity considerably harder to interrupt.

78What is a privacy coin and why is it a concern?

A cryptocurrency designed to conceal transaction details such as sender, receiver or amount. Because it defeats blockchain analytics, many regulated firms restrict or prohibit exposure entirely.

Quality, governance and regulation (Q79–88)

79What is quality assurance in monitoring?

Independent sampling of closed and escalated alerts to test whether decisions were correct, consistent and properly documented. It protects against both missed risk and inconsistent standards across analysts.

80How would you respond to QA feedback that you closed an alert incorrectly?

Understand the reasoning, accept it if the point is valid, and apply it going forward. QA exists to improve decisions, not to assign blame — defensiveness there is a bigger problem than the original error.

81What is the three lines of defence model?

The first line is the business and operational teams owning the risk day to day; the second is compliance and risk oversight setting policy and challenging; the third is internal audit providing independent assurance. Monitoring analysts typically sit in the first or second line depending on structure.

82What does FATF do?

It sets the international AML and counter-terrorist-financing standards through its Recommendations, evaluates countries against them, and maintains the grey and black lists. Most national regimes are built on its framework, which is why credentials and controls transfer across borders.

83What is the difference between the FATF grey list and black list?

The grey list covers jurisdictions under increased monitoring that have committed to fixing identified deficiencies. The black list — high-risk jurisdictions subject to a call for action — carries far stronger measures, including enhanced due diligence and, in some cases, countermeasures.

84Why do regulators fine banks for monitoring failures?

Usually not for missing a single case, but for systemic weakness — inadequate scenario coverage, untuned thresholds, alert backlogs, poor documentation, or failing to act on known deficiencies. Enforcement notices consistently target control effectiveness rather than isolated errors.

85What is an alert backlog and why does it matter?

Alerts left unreviewed beyond expected timeframes. It matters because unreviewed alerts mean undetected risk, and regulators treat sustained backlogs as evidence that the programme is under-resourced.

86How long should monitoring records be retained?

Retention periods are set by local law, commonly five years from the transaction or the end of the relationship, and sometimes longer where an investigation is open. I would follow the institution's stated policy rather than assume a figure.

87What is the MLRO's role?

The Money Laundering Reporting Officer owns the reporting decision, is the point of contact for the financial intelligence unit, and carries personal regulatory accountability for the firm's reporting obligations.

88How do data protection rules interact with monitoring?

Monitoring processes personal data under a legal obligation, which generally provides the lawful basis. In practice it means handling data proportionately, restricting access, and recognising that AML confidentiality can override normal subject access rights.

Scenario and situational questions (Q89–95)

89A student account receives 15 deposits from different individuals over two weeks, each just under the reporting threshold, then withdraws the total in cash. Your assessment?

This has clear structuring and money-mule characteristics — multiple unrelated senders, amounts kept below thresholds, and rapid cash extraction, none of which fits a student profile. I would review the account history and counterparties, check for related accounts showing the same pattern, and escalate. The pattern is strong enough that I would not expect an explanation to resolve it.

90A restaurant's cash deposits triple in three months. How do you approach it?

First I would test whether there is a legitimate explanation — a second site, a refurbishment, seasonal trade, a change in trading hours. I would compare deposits against card takings, since a genuine uplift usually moves both. Cash rising sharply while card revenue stays flat is the pattern that concerns me, and I would seek evidence before drawing a conclusion.

91A long-standing corporate client suddenly starts paying counterparties in a high-risk jurisdiction. What do you check?

Whether the customer's business genuinely expanded into that market, who the counterparties are and whether they have a plausible commercial role, whether payment references and invoices are consistent, and whether ownership or control of the client has changed. A genuine expansion is usually easy to evidence.

92You find your close colleague's relative is a customer whose alert you are reviewing. What do you do?

Declare the conflict immediately and hand the case to someone independent. Continuing to review it would compromise the decision regardless of my actual objectivity.

93A relationship manager pressures you to close an alert quickly because the client is important. How do you respond?

I would explain that the review has to be completed properly and that commercial importance cannot change the outcome, then escalate if the pressure continued. Documented pressure of that kind is itself a compliance concern.

94You notice the same red flag pattern across several unrelated customers. What does that suggest?

Possibly an organised network using multiple accounts, or a gap in a control that a group is exploiting. I would document the linkage, escalate it as a pattern rather than as separate alerts, and flag it for scenario review — connected cases are far more significant than individual ones.

95An alert involves activity you do not understand — an unfamiliar product or industry. What do you do?

Research it and ask. Guessing produces bad decisions in both directions. I would consult colleagues or subject-matter experts, and record what I learned so the reasoning is transparent to reviewers.

Behavioural and closing questions (Q96–100)

96Why do you want to work in transaction monitoring?

Give a real reason. Strong answers reference the investigative nature of the work, the value of the outcome, and the fact that decisions have consequences. Avoid saying it is a stepping stone or that compliance is stable — both read as low commitment.

97How do you handle repetitive work without losing accuracy?

Consistent process rather than reliance on concentration — working alerts in a set order, using checklists, and taking breaks between complex cases. The risk in this role is complacency, so treating each alert as a fresh case matters.

98Tell me about a time you found something others had missed.

Use a real example with a clear structure: what the situation was, what you noticed, what you did, and what resulted. If you lack direct experience, use a training case or transferable example and be honest that it was training — invented examples collapse under follow-up questions.

99What would you do if you made a mistake on a case that had already been closed?

Report it immediately so it can be reopened. Concealing an error turns a correctable mistake into a serious integrity issue, and compliance teams are judged on how they handle errors rather than on never making them.

100What questions do you have for us?

Always have some. Good ones: which monitoring system the team uses, how alerts are allocated and prioritised, how QA works, what the escalation path looks like, and how the team keeps up with new typologies. They show you are thinking about the actual work.

Prepare with practical training

Interviewers test whether you can actually work a case, not just define terms. eStraLux training covers real workflows with hands-on tool access, so you can talk through a live example rather than a textbook definition.

Explore eCADS Browse All Courses

Browse live AML/KYC jobs on eStraLux →

leave your comment


Uploading