Transaction monitoring process UK law requirements under MLR 2017 and POCA 2002

Transaction Monitoring Process UK: What the Law Requires 

Most guides to the transaction monitoring process begin with software. This one begins with the law, because every tool exists to meet a legal duty. When HMRC or the FCA asks your firm to “show me your monitoring”, you are the person who has to answer. This page explains what the rules actually say, before you speak to any vendor. 

Key takeaways

  • The transaction monitoring process is a legal requirement, not a best practice. MLR 2017 mandates ongoing monitoring of business relationships on a risk-based approach.
  • POCA 2002 creates the reporting duty: knowledge or suspicion of money laundering triggers a SAR, and failing to report is a criminal offence.
  • HMRC’s supervision principle is blunt: if it is not written down, it did not happen. Documentation is half the obligation.

What do the AML Transaction Monitoring Rules Actually Require?

Transaction monitoring process two legal duties - MLR 2017 monitoring and POCA 2002 reporting

The AML transaction monitoring rules sit in two main places, and they ask different things of you.

MLR 2017 makes monitoring mandatory and ongoing

POCA 2002 Makes Reporting Mandatory

What is Transaction Monitoring in AML, in Practice?

Transaction monitoring process loop showing detect review decide and report steps

Stripped of jargon, transaction monitoring in AML is a repeating loop with four steps.

StepWhat happens?What the AML transaction monitoring rules expect?
DetectTransactions are screened against rules and customer profilesA risk-based approach, tuned to your customer base
ReviewAlerts are investigated by a named personClear transaction monitoring roles and responsibilities
DecideClose as explained, or escalate as suspicious activityDocumented rationale either way
ReportSAR or DAML submitted to the NCA where requiredPrompt reporting once suspicion forms

Common transaction monitoring examples include a dormant account suddenly moving large sums, payments inconsistent with a customer’s stated business, rapid in-and-out transfers, and structuring: amounts kept just below reporting thresholds.

What are the Red Flags in Transaction Monitoring that Trigger a SAR?

The legal trigger is suspicion, which the courts set deliberately low: more than fanciful, less than proof.

Red Flags Are Indicators, Not Proof 

Typical red flags in transaction monitoring include transactions with no apparent economic purpose, unexplained third-party funding, activity just under thresholds, sudden changes in volume or geography, and reluctance to explain the source of funds. One flag prompts a closer look; a pattern usually prompts a report. The NCA’s November 2025 guidance stresses SAR quality: clear context, client details and a stated reason for suspicion.

The Volume is Real, and so is the Enforcement

The NCA’s UKFIU received more than 860,000 SARs in 2024-25, and the year recorded the highest amount of assets ever denied through DAML refusals. Suspicious activity reporting is not paperwork theatre; it feeds live enforcement.

What does HMRC Expect your Documentation to Show?

Transaction monitoring process documentation checklist for HMRC compliance inspections

HMRC’s supervisory mantra is simple: if it is not written down, it did not happen.

  • A written policy describing your transaction monitoring process, approved by senior management.
  • A transaction monitoring process flow chart or equivalent, showing how alerts move from detection to decision.
  • Named transaction monitoring roles and responsibilities, including who reviews alerts and who, as nominated officer, decides on SARs.
  • Records of every alert outcome, including the ones you closed, with reasons.
  • Evidence of staff training and of periodic reviews of your rules and thresholds.

A transaction monitoring process flow chart makes inspections easier by showing how alerts are reviewed and resolved. 

How often should the Transaction Monitoring Process Run?

real-time bank transaction data has made continuous monitoring practical for ordinary platforms, not just banks. Batch reviews create two problems the regulators notice: suspicious activity discovered weeks late, and false positives piling up between runs.

Where does Finexer fit in your Transaction Monitoring Process?

Finexer is not a monitoring engine. It solves the data problem underneath every transaction monitoring process UK compliance teams run: monitoring is only as good as the transaction data feeding it.

  • The Problem: Screen-scraped or manually uploaded statements arrive late, incomplete and unverified, so alerts fire on stale data and false positives multiply.
  • The Fix: Finexer delivers FCA-authorised (FRN 925695), read-only bank data in real time, with categorisation and balance enrichment included, across 99% of UK banks.
  • Finexer’s Verification product confirms account ownership at onboarding, closing the gap between customer due diligence and ongoing monitoring.
  • Usage-based pricing and 3- to 5-week onboarding, so compliance teams get verified data flowing within one review cycle.

The Bottom Line

The AML transaction monitoring rules come down to three core principles: monitor continuously, investigate carefully, and document your decisions. Technology can support each step, but effective monitoring starts with understanding your regulatory obligations and using reliable data to support them.

What does the law require, in one paragraph?

MLR 2017 requires ongoing monitoring of business relationships on a risk-based approach; POCA 2002 requires you to report knowledge or suspicion of money laundering to the NCA. Together, the AML transaction monitoring rules mean: watch transactions continuously, investigate anomalies, document decisions, and report suspicion promptly.

Is transaction monitoring mandatory for my firm?

If you are in the regulated sector (financial services, accountancy, legal, estate agency, high-value dealing and more), yes. The AML transaction monitoring rules apply regardless of size; only the depth of your controls scales with risk.

How often should monitoring happen?

Continuously, in proportion to risk. There is no fixed statutory interval, but a transaction monitoring in AML programme that only looks monthly will struggle to show it can detect suspicious activity promptly, which is the standard regulators’ test against.

What triggers a SAR?

Suspicion. Not proof. Typical transaction monitoring examples that cross the line: unexplained large movements, structuring below thresholds, and transactions that make no commercial sense for that customer. When suspicion arises, the nominated officer reports to the NCA, and a DAML request is used when consent is required to proceed.

See how verified, real-time bank data can strengthen customer due diligence and ongoing transaction monitoring.

About the Author

Clare Pearson
Clare Pearson

Clare Pearson is a senior payments professional with extensive experience across the global financial services and payments industry. She specialises in Open Banking, payment infrastructure, and financial technology transformation, with expertise spanning product delivery, operational strategy, regulatory compliance, and large-scale payments programmes. Clare currently serves as a Non-Executive Director at Finexer and a panel member for the Payment Systems Regulator (PSR), advising on the development of payment systems policy and innovation