Articles

How do you calculate the false positive rate of AML alerts?

The ratio compliance teams report, the one statisticians mean, and the staffing that follows from both.

In AML transaction monitoring, the false positive rate is normally the share of alerts that do not lead to a suspicion report to the financial intelligence unit: alerts minus reports, divided by alerts. On an illustrative 12,000 alerts a month producing 240 reports, it is 98.0 per cent, and clearing those alerts takes 53.4 analysts. A statistician would compute the same system's false positive rate as 2.94 per cent, so always say which one you mean.

Worked in full in The EU AML Handbook by Julian R. Sterling, with every figure reproduced in a free workbook.See the book on Amazon →

The monitoring operation and the assumptions

The case is an illustrative retail and business bank running rule-based transaction monitoring with a two-level review. Level one closes or escalates each alert; level two investigates escalated cases and decides whether to report. All volumes and handling times are illustrative, per month.

Illustrative monitoring volumes and handling times.
InputValue
Customers monitored400,000
Alerts generated a month12,000
Level one review, minutes per alert20
Alerts escalated to investigation8.0%
Investigation, hours per case2.5
Cases leading to a suspicion report25%
Report drafting and approval, hours3.0
Productive hours per analyst a year1,600

The calculation step by step

Cases = 12,000 x 8.0% = 960; reports = 960 x 25% = 240

Operational false positive rate = (alerts - reports) / alerts = 11,760 / 12,000 = 98.0%

Alert conversion (precision) = 240 / 12,000 = 2.0%, or one report per 50 alerts

Statistical false positive rate = false alerts / customers not reported = 11,760 / (400,000 - 240) = 2.94%

Hours = 12,000 x 20 / 60 + 960 x 2.5 + 240 x 3.0 = 4,000 + 2,400 + 720 = 7,120

Analysts = 7,120 / (1,600 / 12) = 7,120 / 133.3 = 53.4

In Excel: =(B2-B4)/B2 for the operational rate and =(B2*B5/60+B3*B6+B4*B7)/(B8/12) for the team.

The two false positive rates answer different questions. The operational rate, 98.0 per cent, measures how much analyst work produces nothing reportable, and it drives cost. The statistical rate, 2.94 per cent, approximates how often an innocent customer is flagged, and it drives customer friction; it treats each alert as a separate customer, so where customers trigger several alerts a month the true customer-level rate is lower. Both treat a filed report as the proxy for a true positive, which is a convention: a report is a suspicion, not a proven case, and genuinely suspicious activity the rules never flagged does not appear anywhere in either ratio.

Where the hours go

Monthly workload by stage.
StageVolumeHoursShare
Level one alert review12,0004,00056.2%
Level two investigation9602,40033.7%
Suspicion report24072010.1%
Total7,120100%

More than half the effort is spent closing alerts at level one, and each report costs 29.7 analyst hours of monitoring work in total. At an illustrative fully loaded cost of €85,000 a year per analyst, the team costs €4,539,000 a year.

The productive hours figure matters as much as any handling time. An analyst contracted for around 1,800 hours a year spends part of them on leave, training, quality assurance, team meetings and rework; 1,600 productive hours is an illustrative planning figure, not a standard. Overstate it and the team is undersized from the first month, which shows up as an alert backlog. Backlogs are themselves a supervisory finding, because an alert that waits weeks for review delays any report that should follow it.

What if the rules are tuned?

Suppose a threshold review removes 30 per cent of alerts. The alerts removed are mostly low quality, so investigations fall only 15 per cent, and reports fall 5 per cent.

Before and after tuning, per month.
MeasureBeforeAfter
Alerts12,0008,400
Investigations960816
Suspicion reports240228
Operational false positive rate98.0%97.3%
Alert conversion2.0%2.7%
Hours7,1205,524
Analysts53.441.4

The team shrinks by 12.0 analysts, 22.4 per cent, and the cost by €1,017,450 a year. The false positive rate barely moves, from 98.0 to 97.3 per cent, because it is a ratio close to its ceiling. Conversion is the more sensitive measure of the same improvement. Even halving alerts while keeping every report would only take the false positive rate to 96.0 per cent, while saving 15.0 analysts.

Report alert conversion alongside the false positive rate. Near 100 per cent the false positive rate hides large gains in efficiency; conversion rising from 2.0 to 2.7 per cent shows them.

The common mistake

The expensive error is treating a falling false positive rate as proof that tuning worked. Here the tuning also lost 12 suspicion reports a month. Whether that is acceptable depends on what those cases were, which is why supervisors expect below-the-line testing: sampling the alerts that would no longer fire and showing that what is lost is tolerable and documented. A rate that improves because good alerts disappeared is a control failure presented as an efficiency gain.

The second error is mixing the two definitions across reports: quoting a 2.94 per cent statistical rate to management and a 98.0 per cent operational rate to the operations team, so that nobody can tell whether monitoring is working.

Takeaway

Divide non-productive alerts by total alerts for the operational rate, 98.0 per cent here, and convert the volumes into hours to size the team, 53.4 analysts. Then judge any tuning on reports kept, not on the ratio. The same volume-times-throughput method sizes the back book in the free workbook for this book, and the periodic review load that sits beside monitoring is in how many KYC periodic reviews a year the AMLR implies.

Questions readers ask

What is a normal false positive rate for AML transaction monitoring?

Rule-based monitoring commonly produces very high operational false positive rates, but there is no regulatory target and the figure depends heavily on how a true positive is defined. In the illustrative case, 240 suspicion reports from 12,000 alerts is 98.0 per cent, or one report for every 50 alerts.

How many analysts are needed to work AML alerts?

Multiply each stage's volume by its handling time and divide by productive hours per analyst. 12,000 level one reviews at 20 minutes, 960 investigations at 2.5 hours and 240 reports at 3.0 hours make 7,120 hours a month; at 133.3 productive hours each that is 53.4 analysts.

Is a lower AML false positive rate always better?

No. A rate can fall because good alerts were removed along with bad ones. Tuning that cuts the illustrative alerts by 30 per cent saves 12.0 analysts but loses 12 suspicion reports a month; the false positive rate improves only from 98.0 to 97.3 per cent. Below-the-line testing must show the lost cases are acceptable.

Read the whole case

This article is one calculation from The EU AML Handbook. The book takes the same case from first principles to the decision, chapter by chapter, and every figure it prints is a live formula in the free companion workbooks.

Get the book on Amazon →Free companion files

Also on Amazon UK · Amazon Germany · Amazon France · Amazon Canada

Also on this site

Reading guide: regulation, compliance and banking → · All 453 articles →

If this book helped, or didn’t, a few lines on Amazon are worth more than they look: they are what the next reader goes on. Write a review. The workbook stays free either way.