Overview
Isaac, the Transaction Monitoring Investigator (TMI), automates transaction monitoring on the alert review level by investigating and evaluating unusual transactions generated from surveillance monitoring systems.
Current challenges in transaction monitoring
Transaction Monitoring (TM) is a critical tool for fighting global financial crime under anti-money laundering and countering the financing of terrorism (AML/CFT) programs. However, it can be a difficult compliance obligation since suspicious activity monitoring programs take a lot of time, require large teams of people, and cost a lot of money:
Monthly, banks are expected to review millions of transaction monitoring alerts manually, with most of them being non-suspicious.
Vast amounts of data and supporting documentation are aggregating in case management systems as a result of the monitoring activities.
Banks need to provide integrations for the investigation to be enriched with data from third-party sources and internal tools.
Transaction monitoring requires not only monitoring per se but also analyzing the links and relationships between multiple data points, anomaly detection to identify unusual patterns and outliers, and expectation analysis to compare actual versus expected activity.
Teaming up with Isaac to address challenges
As an AI Agent, Isaac helps with TM alert management by using machine learning capabilities to process first-level alerts and auto-escalate those of them that are likely to require investigation, while closing non-suspicious alerts.
The Transaction Monitoring Investigator helps with common Bank Secrecy Act (BSA) transaction monitoring scenarios generating high alert volumes. Examples include:
- Structuring
- Excessive fund transfers, movement of funds, and patterns of fund transfers
- Unexpected account usage or behavior
- High-risk factors
- Use of dormant accounts
To maintain transparency for examiners and auditors, each Isaac decision is supported by a human-readable justification, reporting documentation, and a confidence threshold. However, Isaac is not a transaction monitoring tool and does not generate alerts.
Isaac's capabilities
In terms of AI-based transaction monitoring, Isaac offers the following capabilities:
Sampling on transactions related to alerts
Gathering KYC information on focal entities, for instance, occupation, onboarding date, risk rating, source of funds, status of a politically exposed person (PEP), and previous suspicious activity reports (SARs)
Identifying all counterparties to transactions and the line of business using available data and analyzing red flags on counterparties, for example, lack of website, shell company address, high-risk geographies
Sourcing and reviewing negative news on counterparties and focal entities and conducting PEP or sanction alert reviews
Reviewing alerted transactions and historical transactions for counterparties or focal entities for consistency, value, volume, expected frequency, quick succession payments, and so on
Summarizing, justifying, explaining decisions, and clearing or escalating them accordingly
Business Process overview
A Business Process (BP) represents the core workflow and design of any automation use case in the WorkFusion platform. Out of the box, Isaac comes with the Transaction Monitoring Investigator BP.

The Isaac Transaction Monitoring Investigator Business Process does the following:
Updates the deferral list file stored in the configured S3 bucket.
Picks up alerts generated in surveillance monitoring systems from one or more input CSV files in the configured S3 storage.
Checks the deferral list and input data files against the investigation settings and, if needed, identifies the alerts that are eligible to be deferred to an open investigation.
Evaluates alerts, providing initial statuses and comments.
If the Human-in-the-loop step is enabled during configuration, routes deferral requests for manual review in Workspace according to the specified settings.
Collects the output from manual review (if any) and automatic evaluation results, generates a report, and sends it to the email specified during configuration (if any).

Download PDF
To download a PDF version of the documentation, right-click the document below, and choose Save As or Print > Save.