transaction-monitoring

Monitors CSV transaction data to detect AML threat patterns and draft SAR narratives for MLRO escalation.

53|10|Updated Feb 15, 2026
One-click install
npx skills add https://github.com/vyayasan/kyc-analyst --skill transaction-monitoring
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: transaction-monitoring
Source: https://github.com/vyayasan/kyc-analyst/tree/main/skills/transaction-monitoring
Command: npx skills add https://github.com/vyayasan/kyc-analyst --skill transaction-monitoring

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps AML teams spot suspicious transaction patterns in ongoing customer activity and prepares SAR-ready investigation outputs to reduce repetitive manual review.

Core Features & Use Cases

  • Suspicious Pattern Detection: Identifies structuring (smurfing), layering, circular flows, velocity anomalies, and geographic risk patterns using defined monitoring heuristics and thresholds.
  • Analyst HITL Investigation Gates: Provides a structured review workflow where an analyst assesses legitimacy, documents findings, and selects the appropriate disposition.
  • SAR Drafting & Escalation Support: Produces a draft SAR narrative and an escalation brief for MLRO review when activity is determined suspicious or critical.

Quick Start

Use the transaction-monitoring skill on your exported transactions CSV for an ongoing customer to detect alert-worthy patterns and generate a SAR draft with HITL decision options.

Frequently Asked Questions about transaction-monitoring

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect structuring and layering patterns in customer transaction data?

To draft a Suspicious Activity Report, the investigation workflow produces a SAR-ready narrative and an MLRO escalation brief after an analyst completes HITL review checkpoints and selects a disposition for the flagged activity.

Can I score transaction alert severity for cross-border activity before analyst review?

Yes, transaction risk scoring evaluates velocity anomalies and geographic risk triggers across domestic and cross-border activity, applying configurable threshold assessments to generate severity scores before HITL analyst review.

What is the process for escalating suspicious transaction alerts to an MLRO?

Escalating suspicious transaction alerts involves the analyst reviewing the alert severity score at a HITL checkpoint, determining the activity is suspicious, and generating an MLRO escalation brief with a draft SAR narrative attached.

Does AML transaction monitoring work with exported transactions CSV files for ongoing customers?

Yes, AML transaction monitoring processes exported transactions CSV files for ongoing customer relationships, applying detection heuristics for circular flows and velocity anomalies to identify alert-worthy patterns.