Every mature transaction monitoring system eventually reaches the same place: alert volumes that grow faster than the team, conversion rates in the low single digits, and a rule library nobody fully understands. The instinct is to ask for more analysts. The better move is usually to ask harder questions of the rules.
Begin with the population, not the rule
Before touching thresholds, profile what is actually alerting. In most systems, a small number of rules generate the majority of alerts, and within those rules a small number of customer segments generate the majority of false positives. A week of analysis here typically reveals that the 'tuning problem' is really three or four specific rule-segment combinations.
The tuning sequence that holds up to scrutiny
Start with above-the-line analysis: of the alerts a rule produced, how many progressed to a report? Then do the harder below-the-line work: sample transactions just under the threshold and confirm you are not missing genuine activity. Document both. A threshold change supported by above- and below-the-line evidence is defensible; a change made because 'the volume was too high' is not.
Switching rules off is allowed
A rule that has produced thousands of alerts and zero reports over several years is not a control β it is a cost centre with a compliance costume. Retiring it is legitimate, provided you can show the risk it targeted is covered elsewhere or was never real for your business. Keep the analysis; regulators respond well to evidence-based decisions and poorly to drift.
Make tuning routine, not a project
The organisations that stay in control treat tuning as a quarterly cycle with standing governance, not a crisis project every three years. Small, evidenced, regular adjustments beat periodic overhauls on every dimension: risk, cost and regulator confidence.
PRAXANA