Skip to main content
Category: Suspicious Activity Reporting

Alert Disposition

Also known as: Transaction Monitoring Alert Disposition
Simply put

Alert disposition is the step in anti-money laundering monitoring where an analyst reviews an alert produced by a transaction monitoring system and records a decision about what to do with it, such as closing it or passing it on for further investigation. Because monitoring systems generate many alerts that turn out to be harmless, not every alert leads to further action or to a suspicious activity report. The recorded outcome documents the analyst's assessment of the alert.

Formal definition

Alert disposition is the documented decision made by an analyst after reviewing an alert generated by a transaction monitoring system, in which a defined outcome is assigned to the alert (for example, closing it as a false positive or escalating it for further investigation or reporting). It represents the final analytical assessment of an alert; in some systems the disposition value may be revised more than once as the review develops. Dispositioning an alert is an operational compliance activity and does not itself establish that any underlying transaction is suspicious or unlawful, and not every alert results in a suspicious activity report, false positives are an expected outcome of monitoring designed to capture all potentially suspicious activity. Specific disposition categories, workflows, and documentation standards vary by institution and by the applicable regulatory regime and should be confirmed against the institution's own procedures and applicable requirements.

Why it matters

Alert disposition is where the effectiveness of a transaction monitoring program is tested in practice. Monitoring systems are typically calibrated to capture a wide range of potentially suspicious activity, which means they generate large volumes of alerts, many of which turn out to be false positives. False positives are not a defect but an expected consequence of monitoring designed to detect all possible suspicious activity; the disposition step is where an analyst distinguishes alerts that warrant further investigation or reporting from those that can be closed. The quality and consistency of these decisions determine whether genuinely suspicious activity is escalated appropriately and whether resources are wasted or misdirected.

Because disposition decisions are documented, they also form part of the audit trail that examiners and internal auditors rely on to assess whether an institution is managing its financial crime risk in line with its own procedures and applicable requirements. Poorly reasoned or inconsistently recorded dispositions can expose weaknesses in an institution's monitoring framework, while well-documented rationale supports the defensibility of decisions to close alerts as well as decisions to escalate them.

It is important to note that dispositioning an alert, whether closing it or escalating it, is an operational compliance activity. It does not itself establish that any underlying transaction is suspicious or unlawful, and not every alert results in a suspicious activity report. Escalation reflects an analyst's assessment that further review is warranted, not a finding of wrongdoing.

Who it's relevant to

Transaction Monitoring Analysts
Analysts are the individuals who perform alert disposition day to day, reviewing alerts, forming an assessment, and recording the outcome together with supporting rationale. Consistent, well-documented decisions are central to their role, particularly given that many alerts are false positives that must be distinguished from those warranting escalation.
Financial Crime Investigators
Investigators receive alerts that analysts escalate for further review. The quality of the initial disposition and its documentation affects the information available to them, and their subsequent assessment determines whether an escalated alert leads to further action, including any potential reporting.
Compliance Officers and AML Program Managers
Those responsible for the monitoring program rely on disposition data to understand alert volumes, false positive rates, and escalation patterns, and to demonstrate that decisions are being made and recorded in line with the institution's procedures. This information can inform decisions about calibrating or tuning monitoring systems.
Internal Auditors and Examiners
Auditors and regulatory examiners review documented dispositions as part of assessing whether an institution's transaction monitoring framework operates as intended. The recorded rationale supports the defensibility of both decisions to close alerts and decisions to escalate them.

Inside Alert Disposition

Alert Rationale and Analysis
The documented reasoning that explains why an alert was reviewed and what conclusion was reached. This generally includes the analyst's assessment of the underlying activity, the customer or transaction context considered, and the basis for the decision, forming the core audit trail supporting the disposition.
Disposition Outcome
The categorized result assigned to the alert, typically distinguishing between closing an alert as a false positive (no further action), escalating it for additional review, or advancing it toward a suspicious activity report or suspicious transaction report filing. The available outcome categories vary by institution and by the applicable regime.
Supporting Evidence and Documentation
The records gathered and retained to substantiate the disposition, which may include transaction details, customer due diligence information, screening results, and any additional research. Retention expectations for this documentation are generally set by the applicable regulatory framework, such as FinCEN rules under the US Bank Secrecy Act or the relevant national money laundering regulations, and exact periods should be confirmed against the governing regulation.
Escalation and Referral Pathway
The defined route by which an alert warranting further scrutiny is moved to a more senior analyst, an investigations team, or a designated officer responsible for suspicious activity reporting decisions. This pathway is an operational control that helps ensure consistent handling rather than a determination of wrongdoing.
Quality Assurance and Review
The secondary checks applied to dispositions to test whether decisions were reasonable, adequately documented, and consistent with internal procedures. QA is typically a sample-based control used to detect and manage the risk of inconsistent or unsupported closures.

Common questions

Answers to the questions practitioners most commonly ask about Alert Disposition.

Does closing an alert as a false positive mean no money laundering occurred?
No. Disposing of an alert as a false positive means the alert did not correspond to activity warranting escalation or a suspicious activity report based on the information reviewed at that time. It is an operational and analytical conclusion about the alert, not a determination that no crime occurred. Alert disposition addresses whether the flagged activity meets internal escalation or reporting thresholds; it does not, and cannot, establish innocence or guilt as a matter of criminal law.
Is escalating an alert the same as filing a suspicious activity report?
No. Escalation and filing are distinct steps. Escalation typically moves an alert to a more senior analyst, an investigations team, or a designated compliance function for further review. A regulatory filing, such as a SAR under the US Bank Secrecy Act and FinCEN rules, or an STR in many other jurisdictions, is a separate decision made where a suspicion threshold is met. An alert may be escalated and still not result in a filing, and terminology and reporting triggers differ by jurisdiction.
What should be documented when disposing of an alert?
Disposition records generally capture the rationale for the outcome, the information reviewed, the analyst responsible, and the date, so that the decision is auditable and can be reconstructed later. Many programs require sufficient narrative detail to explain why an alert was closed, escalated, or referred for filing. Exact documentation standards depend on internal policy and the expectations of the applicable regulator, which should be confirmed against the governing regime.
Who is responsible for making alert disposition decisions?
Responsibility is typically assigned within the AML program according to a defined workflow, with initial review often performed by analysts and higher-risk or contested alerts escalated to senior investigators or the compliance function. Segregation of duties and appropriate approval levels are commonly used so that dispositions, particularly decisions not to file, are made and reviewed by suitably authorized staff. Specific role assignments vary by obliged entity and internal governance arrangements.
How are alert dispositions typically reviewed for quality?
Many programs apply quality assurance or quality control processes, such as sampling closed alerts to check that dispositions were consistent, adequately documented, and aligned with policy. These reviews are intended to detect and mitigate inconsistent decision-making and to support tuning of detection rules. They are risk-management measures and do not guarantee that every disposition is correct or that all suspicious activity is captured.
How does alert disposition feed back into detection systems?
Disposition outcomes, particularly patterns of false positives or confirmed escalations, can inform the calibration or tuning of monitoring scenarios and thresholds to improve the relevance of future alerts. This feedback loop is generally treated as part of ongoing model or rule governance. Any tuning should be documented and validated so that changes are defensible to auditors and regulators, and it should be understood as managing alert volume and focus rather than eliminating financial crime risk.

Common misconceptions

Closing an alert as a false positive means the system made an error or the underlying rule is flawed.
A false positive disposition generally indicates that, after review, the flagged activity did not warrant further action or reporting in the analyst's judgment. It does not necessarily mean the detection scenario malfunctioned; alerts are designed to surface activity for human assessment, and a benign outcome is an expected part of a risk-based monitoring process rather than proof of a defective control.
Escalating an alert or filing a report establishes that the customer committed a crime.
Alert disposition is a compliance process, not a criminal-law determination. Escalating an alert, recording a match, or advancing toward a SAR or STR reflects a suspicion or a decision to report under the applicable regime; it does not by itself establish that any wrongdoing occurred. The criminal-law question of whether an offense took place is separate and rests with competent authorities.
There is a single, universal standard governing how alerts must be dispositioned and documented.
Disposition practices are shaped by the obliged entity's own risk-based procedures and by the requirements of the governing regime, which may differ across the FATF Recommendations (standards rather than binding law), EU instruments, the US Bank Secrecy Act and FinCEN rules, and national money laundering regulations. Terminology, categories, and retention expectations can diverge, so requirements should be confirmed against the applicable regulation.

Best practices

Document the rationale for every disposition in sufficient detail that an independent reviewer can reconstruct the reasoning without consulting the original analyst, and record the specific evidence considered.
Apply consistent, clearly defined disposition categories so that closures, escalations, and referrals are handled uniformly, and confirm that the categories align with the institution's procedures and the applicable regime.
Route alerts warranting further scrutiny through a defined escalation pathway to appropriately trained personnel or the designated reporting officer, keeping the compliance decision distinct from any criminal-law conclusion.
Retain supporting documentation for the period required under the governing framework, and confirm exact retention periods against the applicable regulation rather than assuming a single global standard.
Use sample-based quality assurance reviews to test whether dispositions are reasonable, adequately supported, and consistent, treating QA as a measure to detect and manage the risk of unsupported closures rather than a guarantee of accuracy.
Periodically review disposition outcomes and patterns to inform tuning of detection scenarios and to identify training needs, while avoiding treating any single alert, match, or filing as proof of wrongdoing.