AML Transaction Monitoring Pipeline

Postings to windowed features to typology rules to scored alerts to case and STR filing

AML Transaction Monitoring Pipeline Postings to windowed features to typology rules to scored alerts to case and STR filing 01 / Ingest 02 / Aggregate 03 / Detect 04 / Triage 05 / Dispose Txn Stream · postings · 01 / Ingest · event-time Txn Stream postings event-time Window Agg · sliding sums · 02 / Aggregate · keyed Window Agg sliding sums keyed Typology Rules · structuring, velocity · 03 / Detect · pure Typology Rules structuring, velocity pure Alert Scoring · score + dedup · 04 / Triage · grouped Alert Scoring score + dedup grouped Case Queue · analyst review · 05 / Dispose · auditable Case Queue analyst review auditable STR / SAR · FIU filing · 05 / Dispose · idempotent STR / SAR FIU filing idempotent Auto-clear · logged · 05 / Dispose · reversible Auto-clear logged reversible postings event stream features windowed rule hits with evidence alert above threshold escalation suspicious low score no case Legend primary data policy / PII async batch data store

Main Path

  • • Postings aggregate into entity-keyed sliding windows
  • • Pure typology rules read features and emit evidence-bearing hits
  • • Scoring groups hits per entity and deduplicates against open alerts

Disposition

  • • Alerts above threshold open an auditable case for an analyst
  • • Escalation files an idempotent STR/SAR with the financial intelligence unit
  • • Low scores auto-clear on a logged, reversible path

Why It Replays

  • • Features, hits, and alerts are stored immutable artifacts
  • • Deterministic event-time windows make reruns reproducible
  • • Thresholds live in versioned config, tuned without a deploy