The Monitoring Alerts page is the working queue for transaction monitoring tickets — alerts automatically generated when EFI's risk engine detects suspicious patterns in your customers' transaction activity. Use it to triage new alerts, assign them to investigators, and progress them through the case management workflow.
To open it, go to Case Management in the top navigation and choose the Transaction Monitoring Tickets tab.

What's on this page
The page is split into three areas:
- Severity summary cards at the top — a snapshot of how much open work exists, grouped by severity level. The numbers cover the last 90 days.
- Alerts table — every open alert in the monitoring queue. Closed alerts are hidden by default. Each row links to the underlying ticket, where the full investigation happens.
- Header links to the related Dashboard (trend and category analytics for monitoring) and Settings (where the rules that generate these alerts are configured).
Alerts here are read-only summaries — to add comments, change status, or close an alert, click into the ticket.
Triaging by severity
The severity cards double as filters. Click High Severity, Medium Severity, or Low Severity to narrow the table to just that band. The active card stays highlighted and the URL updates with a severity parameter, so you can share or bookmark a filtered view. Click the same card again, or click Total Open, to clear the filter.

Severity is set automatically by the rule that produced the alert. As a rough guide:
- High — patterns with strong red flags such as sanctions circumvention, exposure to high-risk jurisdictions, invoice manipulation, or transactions to tax havens. Investigate these first.
- Medium — patterns that warrant review but don't on their own indicate illicit activity, e.g. velocity breaches, structuring, party clustering, or repeated round-amount transfers.
- Low — informational signals.
The severity bands and how each rule maps to them are configurable in Monitoring → Settings.
Reading an alert title
Alert titles are generated by the rule engine and follow a consistent format: [rule_code] Subject — short description with figures. The bracketed prefix tells you which monitoring rule fired:
round_amount— disproportionate share of round-number transactionssanctions_circumvention— value flowing toward neighbours of sanctioned jurisdictionsvelocity_abuse— too many transactions in too little timehigh_risk_jurisdictions— transactions involving FATF-flagged or high-risk countriestax_havens— concentration of payments to known tax havensparty_clustering— repeated transfers between the same parties or unusual networksstructuring— multiple transactions kept just below a reporting thresholdinvoice_manipulation— trade values inconsistent with expected ranges
The same code is shown more readably in the Category column.
Narrowing the queue with filters
Click Show Filters to open the filter panel on the right. Filters apply on top of any active severity selection.

| Filter | When to use it |
|---|---|
| Institution | Focus on alerts that belong to one of your counterparties. Start typing to search; only your portfolio is searchable here. |
| Title / Description | Free-text search inside the alert title or its description. Useful for finding all alerts mentioning a specific party name or country code. |
| Status | By default the queue hides closed alerts. Switch to All Statuses or pick a specific status to see closed or in-progress work. |
| Closure Reason | Combine with a closed status to review why alerts were dismissed (e.g. false positive, justified, escalated). |
| Sequence Number | Jump to a specific alert by its # ID. |
| Assigned To | Show only alerts assigned to a particular investigator, or unassigned alerts. |
| Category Confirmed | Filter to alerts where an investigator has confirmed (or rejected) the auto-assigned category. |
| Label | Search by any label that has been added to alerts during investigation. |
| Category | Limit the queue to one or more rule types — multi-select. |
Use Reset filters to clear everything in one go. The button is disabled when no filters are active.
Working an alert
Click anywhere on a row, the magnifier icon, or the #<number> link to open the ticket. Investigation, comments, status changes, and closure all happen on the ticket page — see the Ticket guide for that workflow.
The Comments column shows the running discussion count on each ticket; an alert with several comments has typically already been picked up by someone.
Exporting
Export downloads the current view (with all active filters and severity selection applied) as a CSV. This is the standard way to hand a batch of alerts to an external auditor or to feed them into a separate reporting workflow.
Where the data comes from
Monitoring alerts are produced by EFI's transaction monitoring engine, which runs the rules configured in Monitoring → Settings against the transactions you submit. New alerts appear here as soon as the engine finishes a run — there is no manual creation flow on this page. If the queue looks unexpectedly empty or full, the Dashboard page shows volume trends over time and is a good starting point for diagnosing the upstream pipeline.