Suspicious Activity Monitoring
Abbreviation: SAM
Pronunciation: sus-PISH-us ak-TIV-uh-tee MON-uh-ter-ing
Also known as: Suspicious Transaction Monitoring, SAM
Definition
Suspicious Activity Monitoring is the ongoing use of rules, analytics, customer context, and investigation to identify activity that may indicate money laundering, fraud, sanctions evasion, terrorist financing, or other financial crime. It is used to surface unusual behavior for review and support timely escalation, restriction, or regulatory reporting where required. It differs from simple anomaly detection, because unusual activity is not automatically suspicious and must be assessed against expected behavior, known typologies, and available customer information.
Overview
Suspicious Activity Monitoring is the ongoing use of rules, analytics, customer context, and investigation to identify activity that may indicate money laundering, fraud, sanctions evasion, terrorist financing, or other financial crime. Its operational purpose is to surface unusual behavior for review and support timely escalation, restriction, or regulatory reporting where required. It should be considered alongside Case Management. The relevant distinction is simple anomaly detection, because unusual activity is not automatically suspicious and must be assessed against expected behavior, known typologies, and available customer information.
A typical workflow is as follows: Transactions and account events are normalized, enriched, and evaluated against scenarios or models. Alerts are prioritized, investigated, linked to related activity, dispositioned, and escalated into cases or reports.
Core controls include documented scenarios, threshold governance, data-quality testing, segmentation, alert sampling, model validation, investigator training, quality assurance, backlog monitoring, and independent testing.
In payment and crypto operations, Monitoring should cover deposits, withdrawals, payouts, refunds, payment links, rapid movement, cross-chain activity, structuring, account takeover, and changes from the customer’s expected profile.
Evidence should include scenario and version, triggering events, customer profile, linked accounts, blockchain or bank data, investigator steps, decision, escalation, filing reference, and review time. Poor data, excessive false positives, or unreviewed backlogs can make a formally present monitoring program ineffective.
It is used to surface unusual behavior for review and support timely escalation, restriction, or regulatory reporting where required. It differs from simple anomaly detection, because unusual activity is not automatically suspicious and must be assessed against expected behavior, known typologies, and available customer information.
A production treatment of Suspicious Activity Monitoring should test the use of of rules, analytics, customer context, and investigation to identify activity that may indicate money laundering, fraud, sanctions evasion, terrorist financing, or other financial crime within the relevant asset, decision, or service state. The Suspicious Activity monitoring process record for of rules, analytics, and customer context should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Suspicious Activity Monitoring should determine whether safeguards addressing of rules, analytics, and customer context changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
Suspicious Activity Monitoring must convert reliable transaction data into explainable alerts, consistent investigations, documented decisions, and timely reporting.
Sources
- Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing — FATF (2026-08-03)
- Guidance for a Risk-Based Approach to Virtual Assets and VASPs — FATF (2026-08-03)
- Suspicious Activity Reports — FinCEN (2026-08-03)