What transaction monitoring is for
Customer due diligence tells you who a customer is and what they said they would do. Transaction monitoring checks what they actually do, and flags activity that does not fit.
It is a different control from screening. Screening asks whether a name matches a sanctions or politically exposed persons list. Monitoring asks whether a pattern of activity looks like money laundering, terrorist financing or fraud. A customer can pass every screening check and still use their account to launder money.
Monitoring happens in two ways:
- Before or as a payment happens, so that a transaction can be held for review before the money leaves.
- After the event, looking back over days or weeks of activity to find patterns no single transaction reveals.
In Kenya, section 44(1) of the Proceeds of Crime and Anti-Money Laundering Act, 2009 requires reporting institutions to monitor, on an ongoing basis, all complex, unusual, suspicious and large transactions, whether completed or not. They must also watch for unusual patterns, and for small but repeated patterns of transactions, that have no apparent economic or lawful purpose. The law allows an institution that forms a suspicion to complete the transaction while it reports (section 44(10)); separately, the Financial Reporting Centre can direct an institution not to proceed with a transaction for up to five working days (section 44A).
Most monitoring compares activity with a baseline: the customer's own history, what they declared at onboarding, and what is normal for similar customers. That is why good due diligence and good monitoring depend on each other. An alert is not proof of anything; it is a question that someone must answer.
The purpose is not to generate alerts. It is to find activity that should be reported to the authorities, and to leave a clear record of how each decision was made.
Red flags and typologies
A red flag is a sign that something may be wrong. A typology is a known method criminals use. Recognising both is the core skill of monitoring. Common examples:
- Structuring: splitting cash deposits or transfers into amounts just below a reporting threshold, such as Kenya's US$15,000 cash transaction reporting threshold, often across days, branches, agents or accounts.
- Pass-through activity: money arrives and leaves again quickly, with little left in the account and no business reason.
- Mule accounts: accounts, often in other people's names, that receive money from many unrelated senders and pass it on. Students and job seekers are sometimes recruited for this, knowingly or not.
- Activity that does not fit the profile: a salaried customer receiving large business payments, or a small shop moving far more than its size suggests.
- Sudden change: a dormant account that becomes very active, or a new pattern of cross-border transfers.
- Unusual links: many customers sharing one phone number, address or device, or transfers to parties with no apparent connection.
- Trade-based laundering: invoices priced far above or below market value, or goods described vaguely, used to move value across borders.
Kenya's financial system is heavily mobile, so the same patterns show up in mobile money as well as in banks: many small transfers from unrelated senders, rapid movement between wallets and bank accounts, and agent transactions that do not match the customer's profile.
Red flags are prompts, not conclusions. Many have innocent explanations. The job is to find out which.
How monitoring systems work
Most monitoring systems combine several approaches:
- Rules and scenarios: defined patterns with thresholds, such as "cash deposits totalling more than a set amount within seven days" or "more than a set number of incoming transfers from different senders in a day".
- Segmentation: grouping similar customers, such as individuals, small businesses and large companies, so each group gets thresholds that suit it. A pattern that is normal for a supermarket is unusual for a student.
- Behavioural and statistical models, including machine learning, that score how far activity departs from the customer's normal pattern or look for hidden links between accounts.
Every approach involves a trade-off. Set thresholds too low and analysts spend their time clearing harmless alerts, known as false positives; set them too high and real cases slip through. Most alerts, particularly those generated automatically, turn out not to be suspicious, so tuning matters.
Good practice for managing the system:
- Map each rule to a risk from your risk assessment, so you can show why it exists.
- Tune with evidence: test what would happen above and below the current threshold before changing it, and record why you changed it.
- Check data quality: a rule cannot see transactions that never reach it, or fields that are empty or wrong.
- Review coverage whenever a new product, channel or typology appears.
A supervisor will ask not only "what does your system do?" but "how do you know it works?"
Investigating an alert
An alert is the start of an investigation, not the end. A sound review follows the same steps each time:
- Understand the alert: which rule or model fired, and on what activity.
- Look at the customer: their due diligence file, risk rating, occupation or business, declared purpose and past alerts.
- Look at the wider activity: transactions before and after, the counterparties and whether they are linked to other alerts or accounts.
- Use available information: internal records, public sources and adverse media (negative news reports). If you need to ask the customer for an explanation or documents, do it as part of normal business, and never suggest that a report is being considered.
- Decide and explain: either the activity has a credible, documented explanation, or it remains suspicious. Record what you found, what you concluded and why, in words a supervisor or court could follow.
Two principles keep decisions sound:
- Suspicion is enough. You do not need to prove a crime or identify it. If the activity is suspicious and you cannot explain it away, it should be reported.
- Four eyes for the hard cases. A second reviewer, or a quality-assurance check on a sample of closed alerts, catches both missed cases and inconsistent decisions.
Kenyan law requires a reporting institution, as far as possible, to examine the background and purpose of unusual or suspicious transactions, set out its findings in writing and keep them for at least seven years (section 44(4) and (5) of the Act). Closing an alert as "no concern" with no explanation does not meet that standard, and supervisors look for it. The reasoning is part of the work.
Reporting a suspicion
When suspicion remains, it is reported to the country's financial intelligence unit. The FATF standard (Recommendation 20) is that institutions must report promptly when they suspect, or have reasonable grounds to suspect, that funds are the proceeds of a criminal activity or are related to terrorist financing.
Inside the institution, staff do not report to the authorities themselves. They report the suspicion to the Money Laundering Reporting Officer (MLRO), and the MLRO decides whether to file a report. Section 47 of the Act requires these internal reporting procedures. Regulation 12 of the Proceeds of Crime and Anti-Money Laundering Regulations, 2023 requires every reporting institution to appoint an MLRO at management level, with the authority and independence to do the job.
In Kenya, reports go to the Financial Reporting Centre (FRC). Section 44(2) of the Act requires a reporting institution to report a suspicious or unusual transaction or activity within two days after the suspicion arose (see also regulation 38). Attempted transactions must be reported too (section 44(3)). The duty covers money laundering, terrorist financing, proliferation financing and the proceeds of crime.
Reporting institutions must also report every cash transaction of US$15,000 or more, or the equivalent in another currency, whether or not it looks suspicious, normally by the end of the week in which it happened (section 44(6) and the Fourth Schedule of the Act; regulation 40). Reports are filed electronically through goAML, the FRC's online reporting system. Check the FRC's current guidance for the exact forms and channels.
A useful report answers five questions clearly and factually:
- Who: the customer and other parties, with identifiers.
- What: the transactions, amounts, dates and accounts.
- When and where: the period and the channels used.
- Why it is suspicious: the red flags, what does not fit the profile, and what explanation was sought. Attach the documents that support the suspicion (section 44(7)).
- What you did: any action taken on the account.
After reporting:
- Do not tip off. Disclosing to the customer, or to anyone not authorised to know, that a report is being prepared, is about to be sent or has been sent to the FRC is an offence under section 8 of the Act.
- Decide on the relationship under your procedures: continue with closer monitoring, restrict or exit. Record the decision.
- Keep the records of the alert, the investigation and the report for at least seven years (sections 44(5) and 46(4) of the Act; regulation 42), or longer if the FRC requires.
Reporting in good faith is protected. Under section 19 of the Act, no suit, prosecution or other legal proceedings lie against a reporting institution or its staff for anything done with due diligence and in good faith under the Act, and section 20 keeps the identity of the person who gave information confidential. This reflects FATF Recommendation 21.
Ten questions
Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.
Your answers
Your certificate of completion
Enter your name as you want it to appear, then save the certificate as a PDF. In the print window, choose Save as PDF. A certificate is issued once per completion of the course.
Saolix does not record who takes this course, so it cannot verify these certificates. The certificate confirms completion of a free self-paced course and is not an accredited qualification.
Sources
The official documents this course relies on. Laws and guidance change, so check the current version.
- The FATF Recommendations (Recommendations 20 and 21) · Financial Action Task Force
- Proceeds of Crime and Anti-Money Laundering Act, 2009 (No. 9 of 2009) · Kenya Law
- Proceeds of Crime and Anti-Money Laundering Regulations, 2023 (L.N. 153 of 2023) · Kenya Law
- Financial Reporting Centre, Kenya · Financial Reporting Centre
- Guidance to Reporting Institutions on Suspicious Transaction and Activity Reporting (2025) · Financial Reporting Centre
- Money Laundering and Terrorist Financing Trends and Typologies Report (2025) · Financial Reporting Centre
- goAML Registration Guide · Financial Reporting Centre
- Mobile payments statistics · Central Bank of Kenya