Transaction monitoring is the continuous screening of every transaction an institution processes against rules, watchlists, and behavioral baselines, before or after execution, to detect money laundering, fraud, and terrorism financing. It is a legal obligation for banks, microfinance banks (MFBs), fintechs, and payment service providers under FATF standards and local law. In Nigeria, that law is the Money Laundering (Prevention and Prohibition) Act 2022 (MLPPA) and the CBN AML/CFT Regulations.

That definition raises three practical questions. Why does the law demand it, how does a monitoring system actually process a transaction, and what should you look for if you are buying one. This post answers all three, in order.

What is transaction monitoring?

Transaction monitoring in banking is the systematic review of account activity to spot behavior that should not be there. Every deposit, transfer, withdrawal, and payment is checked, and anything that breaks a rule, touches a watchlist, or departs from the customer's normal pattern is flagged for a human to review.

Two terms get used interchangeably and should not be:

  • Screening is a point-in-time check. You screen a name against a sanctions list at onboarding, or a counterparty against a watchlist before a payment leaves.
  • Monitoring is the ongoing process. It watches the full transaction stream over time, builds a picture of what normal looks like for each customer, and raises alerts when reality diverges from that picture.

A complete AML program does both. Screening tells you who the customer is dealing with. Monitoring tells you what they are actually doing. A customer can pass every list check and still be laundering money through pattern, volume, and velocity, which is why regulators treat monitoring as a distinct obligation rather than an extension of KYC.

Monitoring also happens at two points. Pre-transaction monitoring holds or blocks a payment before it executes. Post-transaction monitoring reviews settled activity and generates alerts for investigation. Most mature setups run both: real-time checks on the wire, deeper analysis after the fact.

Why regulators require it

The global basis is the FATF Recommendations, the standards that national AML laws are built on. FATF Recommendation 20 requires financial institutions to report transactions they suspect are linked to money laundering or terrorism financing to their financial intelligence unit. You cannot report what you cannot see. Transaction monitoring is the mechanism that makes reporting possible, and regulators treat a weak monitoring system as a broken reporting obligation.

In Nigeria, the chain of obligation looks like this:

  • The MLPPA 2022 sets the statutory duty for reporting entities (banks, MFBs, fintechs, PSPs, and others) to monitor activity and report suspicion.
  • The CBN AML/CFT Regulations operationalize that duty for licensed institutions: risk-based programs, monitoring systems proportionate to the business, and board-level accountability.
  • The NFIU is the financial intelligence unit that receives the reports. Filings go through goAML, its reporting platform. A Suspicious Transaction Report is due within 24 hours of suspicion. Currency Transaction Reports above ₦5 million (individual) or ₦10 million (corporate) are due within 7 days. Records are kept for at least five years.

The 24-hour STR clock starts when suspicion is formed, and for most institutions suspicion is formed by the monitoring system, not by a person. That makes the monitoring layer the front end of your entire reporting compliance. We covered the filing process in detail in how to file an STR with the NFIU.

How transaction monitoring works, step by step

Vendor demos make this look like magic. It is not. A monitoring system is a pipeline, and each stage is understandable on its own:

  1. Data intake. Every transaction arrives with its context: amount, channel, counterparties, timestamp, plus the customer's KYC profile and, where available, device and session data. Garbage in, garbage alerts. This stage decides the ceiling of everything after it.
  2. Rules and scenarios. The transaction is tested against explicit logic: amounts above a threshold, velocity over a window, geographic patterns, structuring just under reporting limits. Good rules are specific, versioned, and tunable without a code deploy.
  3. Watchlist screening. Sender, receiver, and related parties are checked against sanctions and watchlists. This runs on the transaction, not just at onboarding, because a clean customer can receive funds from a listed party.
  4. Behavioral baselines and scoring. The system compares the transaction against what this customer, and customers like them, normally do. A ₦2 million transfer is routine for one account and an alarm for another. Baselines are what separate monitoring from a threshold filter.
  5. Alert generation. Rules and scores combine into a verdict: clear, review, or hold. Alerts carry the reasons with them, not just a score, so the analyst starts with evidence instead of a mystery.
  6. Analyst review and case management. A human investigates the alert: pulls the KYC file, reviews the surrounding transactions, traces counterparties, and decides to clear or escalate. Every action is logged.
  7. Reporting and audit trail. Escalated cases become STRs or CTRs in the regulator's format. Every step, from the original verdict to the final decision, sits in an audit trail that an examiner can replay.

At Finhaq, stages 2 through 5 run as six screening engines per transaction, returning a verdict in 142ms inside a 200ms latency budget, fast enough to sit in the payment path. The full breakdown is in anatomy of a 142ms verdict.

The red flags every monitoring system must catch

Patterns vary, but a core set shows up in examinations and enforcement cases again and again. If your monitoring does not catch these, it is furniture, not a control:

PatternWhat it looks likeExample
Structuring Deposits or transfers kept deliberately below reporting thresholds, often split across days, branches, or accounts. Eleven cash deposits of ₦4.8m over two weeks, each just under the ₦5m CTR threshold.
Rapid pass-through Funds arrive and leave within hours. The account is a pipe, not a store of value. ₦30m lands at 09:15, moves out in four transfers by 14:00, balance returns to near zero.
Profile mismatch Activity inconsistent with the customer's declared occupation, income, or history. A student account that averaged ₦80k monthly starts receiving ₦6m weekly from unrelated senders.
Dormant account reactivation A long-inactive account wakes up into immediate high-value activity. An account idle for 14 months receives ₦12m and empties it within 48 hours.
Round-amount velocity Unnatural volumes of round figures at machine-like frequency. Forty transfers of exactly ₦500,000 in one day from a retail account.
Mule fan-in / fan-out Many senders converging on one account, which then disperses to many, the signature of a mule network. ₦200k payments from 60 unrelated accounts collect in one wallet, then fan out to 15 destinations.

None of these prove a crime on their own. Each is a reason to look closer, which is exactly what an alert is for.

Rules, machine learning, or both?

Rules are transparent and auditable, but rigid. Pure machine learning adapts to new patterns, but produces scores that cannot explain themselves. The practical answer for a regulated institution is rules first, behavior second, and explainability always.

The reason is regulatory, not philosophical. When an examiner asks why a transaction was blocked or why an alert fired, "the model said so" is not an answer. CBN AI/ML governance expectations point the same way: automated decisions that affect customers need to be decomposable into reasons a human can review. Every verdict should decompose rule by rule, so the analyst and the examiner see the same logic the system used.

Behavioral intelligence still earns its place. Baselines and trust scores catch what static rules miss, but they work as scored, reviewable signals, not as an opaque oracle. We made the full argument in behavioral intelligence without black-box ML.

Real-time vs batch monitoring

Batch monitoring processes the day's transactions after the fact, usually overnight. It is cheaper to run and fine for deep analysis, but it means a fraudulent transfer settles before anyone looks at it, and you spend your effort on recovery instead of prevention.

Real-time monitoring sits in the transaction path and returns a verdict before execution, which is the only way to stop value rather than document its loss. The honest caveat: real-time has to be genuinely fast. A "real-time" system that adds seconds of latency gets bypassed by product teams within a quarter. The full comparison, including what vendors mean when they say "real-time", is in real-time vs batch monitoring.

What to look for in transaction monitoring software

If you are evaluating tools, the demo will be polished. The checklist is what protects you:

  • Real-time verdicts with a stated latency budget, not a marketing adjective. Ask for the number.
  • Explainable rules. Every verdict should decompose into the specific rules and signals behind it.
  • Local list coverage. Nigerian and regional watchlists, PEP data, and sanctions sources relevant to where you operate, not just global lists.
  • Case management with an immutable audit trail of every alert and decision.
  • Retroactive screening. The ability to screen your full transaction history on day one, so past exposure surfaces before an examiner finds it.
  • Regulator-ready output. goAML-ready report formats and the five-year record retention the MLPPA requires.

For the full evaluation framework, including the questions that make weak vendors uncomfortable, read how to choose an AML solution: 14 questions that expose weak vendors.

Where Finhaq fits

Finhaq is the pipeline described above, built for Nigerian and African institutions. Six screening engines per transaction return explainable verdicts in 142ms, every alert lands in case management with an immutable audit trail, and reports come out in goAML-ready formats for NFIU filings. Bulk CSV import screens your full transaction history on day one, no code required. At Buildbank MFB, that setup blocked over ₦97 million in suspicious value with zero false negatives.

If you want to know how your current monitoring would hold up under examination, the free AML readiness assessment scores it in three minutes.


This article is general guidance for compliance professionals, not legal advice. Monitoring and reporting obligations are set by the Money Laundering (Prevention and Prohibition) Act 2022, CBN AML/CFT regulations, and NFIU directives. Always check the current instruments and your regulator's circulars.

See live monitoring on your own transactions

A 30-minute demo on your scenarios: six engines per transaction, explainable verdicts in 142ms, and goAML-ready reporting.