Compliance

Transaction monitoring in practice

Cover: transaktionsbevakning-i-praktiken

Noah Mannberg

The duty is clear enough on paper: follow up client relationships on an ongoing basis, and react when activity does not match what you know about the client. The harder question is what that looks like on a Tuesday afternoon in a firm with four hundred clients and no compliance department. This article describes a working setup — what to watch, when to watch it, and what to do when something does not add up.

Start from the risk classification, not the transactions

Monitoring every client with the same intensity is neither required nor possible. The client’s risk classification sets the cadence: low-risk clients are reviewed when you already have their material in hand — the monthly close, the VAT return, the year-end accounts — while high-risk clients get their own recurring check with tighter thresholds. If the classifications are stale, the whole scheme inherits the error, so the practical first step of “doing monitoring” is often to bring the risk assessments up to date.

What to actually look for

The signals that matter in bookkeeping are mundane and specific. Cash entries in a business that should not handle cash. Round amounts to counterparties that appear for the first time and lack an obvious business purpose. Revenue that grows out of proportion to staffing, premises or the owner’s explanation. Transfers to or from private accounts and related companies that are labelled as loans but never repaid. Invoices from suppliers whose line of business does not match what was delivered. None of these proves anything on its own — each is a question to put against the client file.

Handle every alert the same way

A signal needs an owner, a look at the customer-due-diligence file, a conclusion and a written note — in that order. Either the activity is explainable, and the note says why, or it is not, and the matter is escalated to the firm’s AML officer. If reasonable suspicion remains, it is reported to Finanspolisen through goAML without delay and without informing the client. The discipline of writing down the reasoning on every alert, including the dismissed ones, is what separates a routine that holds up at an inspection from one that exists only in good intentions.

The pitfalls to design away

Three failures recur. Monitoring that happens only at onboarding, because no review dates were ever set. Alerts noticed by an assistant but never handed to anyone with responsibility to conclude. And findings discussed at a partner meeting but written down nowhere. All three are process failures, not judgment failures — and all three disappear when follow-up dates, alert ownership and documentation are enforced by the system that holds the client files rather than by individual memory.