Above-the-Line Testing
Above-the-line testing is a technique used to check whether the rules and thresholds in an automated transaction monitoring system are set at the right level. It focuses on the transactions and alerts that currently fall above a monitoring threshold, helping an institution understand how many of those alerts are genuinely useful versus how many are false positives. It is typically used alongside below-the-line testing to fine-tune a monitoring program so it works more efficiently.
Above-the-line (ATL) testing is a model calibration and tuning method applied to rule-based AML transaction monitoring systems, in which the transactions and alerts generated above an existing detection threshold are examined, often by adjusting or elevating parameters above the current baseline, to assess alert quality and identify the threshold levels at which false positives arise. It is generally performed as one component of a broader calibration or optimization exercise and is paired with below-the-line (BTL) testing, which reviews activity falling below the threshold to detect potentially missed suspicious activity. ATL testing is an operational and analytical technique, frequently applying statistical methods, rather than a regulatory test defined by any single instrument, and its scope, sampling approach, and acceptance criteria vary by institution, system, and applicable supervisory expectations. The specific parameters, sampling volumes, and pass/fail standards should be confirmed against an institution's own model governance framework and any relevant regulatory guidance.
Why it matters
Rule-based transaction monitoring systems generate alerts whenever activity crosses a configured threshold, but a threshold set too low can flood investigators with false positives, while one set too high may leave genuinely suspicious activity undetected. Above-the-line testing gives an institution a structured way to examine the alerts already being produced above a threshold and assess how many represent useful, actionable output versus noise. This matters because alert quality directly affects the efficiency of an AML program: investigators have finite capacity, and time spent clearing false positives is time not spent on higher-risk activity.
ATL testing is one part of a broader model calibration and tuning exercise, and it is generally paired with below-the-line testing, which looks at activity falling below the threshold to check for potentially missed suspicious activity. Together, these techniques help an institution demonstrate that its thresholds are set deliberately and defensibly rather than left at vendor defaults or arbitrary levels. Because supervisory expectations increasingly emphasize documented model governance, being able to show evidence of periodic calibration can be an important element of a program's overall credibility.
It is important to frame ATL testing as an operational and analytical technique rather than a regulatory test defined by any single instrument. It does not guarantee that all suspicious activity is captured, nor does the presence or absence of alerts establish wrongdoing. Its value lies in helping an institution detect, deter, and manage financial crime risk more efficiently by informing where thresholds are placed, with the specific parameters, sampling approaches, and acceptance criteria varying by institution and system.
Who it's relevant to
Inside ATL
Common questions
Answers to the questions practitioners most commonly ask about ATL.