The Monitoring Alerts page is the working queue for transaction monitoring tickets — alerts automatically generated when EFI's risk engine detects suspicious patterns in your customers' transaction activity. Use it to triage new alerts, assign them to investigators, and progress them through the case management workflow.

To open it, go to Case Management in the top navigation and choose the Transaction Monitoring Tickets tab.

Monitoring Alerts overview

What's on this page

The page is split into three areas:

  • Severity summary cards at the top — a snapshot of how much open work exists, grouped by severity level. The numbers cover the last 90 days.
  • Alerts table — every open alert in the monitoring queue. Closed alerts are hidden by default. Each row links to the underlying ticket, where the full investigation happens.
  • Header links to the related Dashboard (trend and category analytics for monitoring) and Settings (where the rules that generate these alerts are configured).

Alerts here are read-only summaries — to add comments, change status, or close an alert, click into the ticket.

Triaging by severity

The severity cards double as filters. Click High Severity, Medium Severity, or Low Severity to narrow the table to just that band. The active card stays highlighted and the URL updates with a severity parameter, so you can share or bookmark a filtered view. Click the same card again, or click Total Open, to clear the filter.

High severity filter applied

Severity is set automatically by the rule that produced the alert. As a rough guide:

  • High — patterns with strong red flags such as sanctions circumvention, exposure to high-risk jurisdictions, invoice manipulation, or transactions to tax havens. Investigate these first.
  • Medium — patterns that warrant review but don't on their own indicate illicit activity, e.g. velocity breaches, structuring, party clustering, or repeated round-amount transfers.
  • Low — informational signals.

The severity bands and how each rule maps to them are configurable in Monitoring → Settings.

Reading an alert title

Alert titles are generated by the rule engine and follow a consistent format: [rule_code] Subject — short description with figures. The bracketed prefix tells you which monitoring rule fired:

  • round_amount — disproportionate share of round-number transactions
  • sanctions_circumvention — value flowing toward neighbours of sanctioned jurisdictions
  • velocity_abuse — too many transactions in too little time
  • high_risk_jurisdictions — transactions involving FATF-flagged or high-risk countries
  • tax_havens — concentration of payments to known tax havens
  • party_clustering — repeated transfers between the same parties or unusual networks
  • structuring — multiple transactions kept just below a reporting threshold
  • invoice_manipulation — trade values inconsistent with expected ranges

The same code is shown more readably in the Category column.

Narrowing the queue with filters

Click Show Filters to open the filter panel on the right. Filters apply on top of any active severity selection.

Filters panel

Filter When to use it
Institution Focus on alerts that belong to one of your counterparties. Start typing to search; only your portfolio is searchable here.
Title / Description Free-text search inside the alert title or its description. Useful for finding all alerts mentioning a specific party name or country code.
Status By default the queue hides closed alerts. Switch to All Statuses or pick a specific status to see closed or in-progress work.
Closure Reason Combine with a closed status to review why alerts were dismissed (e.g. false positive, justified, escalated).
Sequence Number Jump to a specific alert by its # ID.
Assigned To Show only alerts assigned to a particular investigator, or unassigned alerts.
Category Confirmed Filter to alerts where an investigator has confirmed (or rejected) the auto-assigned category.
Label Search by any label that has been added to alerts during investigation.
Category Limit the queue to one or more rule types — multi-select.

Use Reset filters to clear everything in one go. The button is disabled when no filters are active.

Working an alert

Click anywhere on a row, the magnifier icon, or the #<number> link to open the ticket. Investigation, comments, status changes, and closure all happen on the ticket page — see the Ticket guide for that workflow.

The Comments column shows the running discussion count on each ticket; an alert with several comments has typically already been picked up by someone.

Exporting

Export downloads the current view (with all active filters and severity selection applied) as a CSV. This is the standard way to hand a batch of alerts to an external auditor or to feed them into a separate reporting workflow.

Where the data comes from

Monitoring alerts are produced by EFI's transaction monitoring engine, which runs the rules configured in Monitoring → Settings against the transactions you submit. New alerts appear here as soon as the engine finishes a run — there is no manual creation flow on this page. If the queue looks unexpectedly empty or full, the Dashboard page shows volume trends over time and is a good starting point for diagnosing the upstream pipeline.