RecordArc public release R21
Skip to main content

Financial Crime & Compliance

Reconstructing an AML alert closure

A worked AML alert-review model focused on retained evidence and review authority, not a generic AML process summary.

Synthetic alert-review chronology
  1. 01Alert and signal
  2. 02Evidence review
  3. 03Human rationale
  4. 04Recorded outcome
RecordArc Editorial

In plain English

An AML alert closure is reconstructable when a later reviewer can connect the alert and monitoring signal to transaction and customer evidence, the applicable rule or scenario version, investigation activity, analyst rationale, approval or escalation, the recorded source outcome, chronology, and explicit proof gaps. RecordArc reconstructs that retained context; it does not monitor, investigate, close, or validate the alert.

A simple example

An AML alert was closed months ago. A reviewer now needs the retained monitoring signal, scenario version, analyst rationale, approval and outcome evidence to understand why.

The AML closure review problem

A closed status answers what the investigation workflow recorded. It does not by itself reveal which activity was reviewed, which monitoring logic applied, which rationale was retained, who approved the outcome, or which evidence was unavailable.

The source AML and investigation systems remain authoritative for alert creation, review actions, and the outcome. A proof layer connects those retained records for later assurance without operating the workflow.

A ten-part AML closure proof model

The model starts with identity and authority before assessing whether the record can support later review.

AML alert-review evidence model

1. Alert identity
2. Monitoring signal identity
3. Transaction and customer or account evidence
4. AML rule or scenario version
5. Investigation activity
6. Analyst rationale
7. Approval or escalation authority
8. Recorded source outcome
9. Event, decision, capture, and later-acquired chronology
10. Proof gaps and evidence classifications

Worked synthetic use case: retained alert-review evidence

The approved public synthetic AML context includes a transaction record, monitoring signal, alert, investigation activity, analyst rationale, supervisor approval, and recorded closure. It also retains AML rule or scenario context and the source identities behind each record.

The governing policy version was recorded after the alert event. The record therefore cannot establish which policy version applied at decision time, even though the alert, human actions, and outcome chronology are retained.

Synthetic example

A reviewable chronology with a policy-time gap

The closure record remains inspectable, but governing-context linkage is Ambiguous and the decision-time policy evidence is Missing/unverifiable.

  • Source facts: transaction, signal, alert, investigation events, and role identifiers.
  • Human-certified interpretation: analyst rationale and approved source meaning.
  • Source-system outcome: closure retained from the investigation workflow.
  • RecordArc derived: lineage and approved AML relationship presentation.

What a later reviewer asks

A later reviewer asks whether the alert and signal share the expected source identity, whether the transaction and customer evidence covers the analyst's rationale, whether the approver was identified, and whether the policy-time ambiguity is visible rather than silently resolved.

The reviewer may also ask whether evidence was acquired after closure and whether missing detailed notes limit the reconstruction. Those are proof questions, not a request for RecordArc to reopen or redispose the alert.

What RecordArc reconstructs and does not do

Regulatory obligations vary by jurisdiction, institution type, and facts. Primary sources support the importance of retained reporting and supporting documentation, but the synthetic record does not establish legal or operating sufficiency.

RecordArc does not detect suspicious activity, generate alerts, investigate, close, escalate, approve, file, or transmit a report. It reconstructs retained evidence and disclosed limitations for authorized review.

Source references

  • FinCEN Suspicious Activity Report Supporting Documentation - Primary US guidance describing supporting documentation for a filed SAR. Jurisdiction: United States. Publication/update: June 13, 2007. RecordArc source review: August 3, 2026.
  • FFIEC BSA/AML Manual: Suspicious Activity Reporting - US supervisory reference; institution-specific obligations still require qualified review. Jurisdiction: United States. Publication/update: Current online manual. RecordArc source review: August 3, 2026.
  • FATF Recommendations - International standards context; implementation and obligations vary by jurisdiction. Jurisdiction: International standard. Publication/update: Current consolidated recommendations. RecordArc source review: August 3, 2026.