AML case management is the process of taking a transaction monitoring alert or an internal referral, investigating it, deciding whether the activity is genuinely suspicious, and either closing it with a documented rationale or escalating it into a report to your financial intelligence unit. It covers alert triage, evidence gathering, decision making, filing and record keeping.
Detection gets the budget. Case management gets the blame.
Every institution that has been fined for anti-money laundering failures had a monitoring system. What regulators found was alerts nobody worked, cases closed without reasoning, and reports filed too late or not at all. The technology saw it. The process did not act on it.
This guide covers how the AML case management investigation process actually runs, what Nigerian law requires and by when, and how to tell whether your own case management is working.
What Is AML Case Management?
AML case management is the workflow that sits between detection and reporting. A monitoring system produces an alert. Case management decides what that alert means.
An AML case management function has five components, and most institutions have all five in some form even if nobody has written them down:
- Intake. Alerts from transaction monitoring, screening hits, internal referrals from front-line staff, and law enforcement requests.
-
- 1. Triage. Ranking what gets worked first, because everything cannot be first.
-
- 2. Investigation. Gathering customer records, transaction history, prior alerts and external information into one file.
-
- 3. Decision. Close, escalate, or file, with a stated reason.
-
- 4. Record. A durable account of what was reviewed, by whom, and on what basis.
The last one is the part people skip, and it is the only part a regulator can inspect years later.
Why AML Case Management Breaks Down at the Alert Queue
The failure mode is almost always the same, and it is arithmetic rather than incompetence.
A monitoring system generates alerts. Most are false positives, commonly 90% or more in rule-based systems. For how the detection side produces them, see our complete guide to transaction monitoring. Each alert still has to be looked at by a person. A system producing 400 alerts a week against a team that can properly close 300 does not leave you 100 alerts behind. It leaves you 100 alerts behind every week, compounding.
What happens next is predictable. Analysts start closing alerts faster to keep the number down. The quality of the rationale drops. Cases get closed as "no suspicious activity identified" with nothing supporting it. The backlog stabilises, management sees a healthy dashboard, and the control has quietly stopped working.
Then a regulator asks to see fifty closed alerts, and the file cannot explain why any of them were closed.
Three things cause this, and none of them are fixed by buying better detection.
1. Tuning nobody owns. Rules that generate volume without generating value stay switched on because switching them off feels like a risk decision nobody wants to sign.
2. No triage. If every alert enters the same undifferentiated queue, an analyst spends the same effort on a routine salary payment as on a structured cash pattern.
3. Investigation by screenshot. When an analyst has to open six systems to assemble one customer picture, most of the investigation time is spent gathering rather than thinking.
The AML Investigation Process: Five Stages From Alert to Decision
An alert moves through five stages before the case can close. Each one ends with something written down, because an investigation that leaves no record did not happen as far as an examiner is concerned.
1. Alert Triage: Deciding What Gets Worked First
Not every alert deserves the same response. Rank incoming alerts using the customer's risk rating, the alert type, the amount involved, and whether this customer has generated alerts before.
Prior alert history is the factor most often ignored. Three separate alerts on one customer, each closed individually as unremarkable, may be one pattern that nobody saw because nobody looked across them.
Set a target turnaround by priority band, and make the clock visible.
2. The Case File: Gathering Everything Before You Form a View
Pull everything into one place before forming a view. That means the customer's identity and verification records, their stated occupation and expected activity, the transaction history around the alerted activity, any related accounts, prior alerts and their outcomes, and screening results including politically exposed person, sanctions and adverse media hits.
The question the file has to answer is narrow: does the observed activity make sense for this customer, given what you know about them?
That comparison is only possible if somebody recorded expected activity at onboarding. Where customer due diligence never captured what normal looks like, every investigation starts blind. Our guide on how to build a customer risk rating model covers where that baseline comes from.
3. The Decision: Close, Escalate or Report
Three outcomes exist: close, escalate for further review, or report.
Whichever you choose, the reasoning goes in writing, and it has to be reasoning rather than a label. "Customer is a known trader, transaction volume consistent with declared business, invoices reviewed" is a rationale. "No suspicious activity identified" is a checkbox.
The test to apply: if you left the organisation tomorrow, could a colleague read this file and understand why you decided what you decided?
4. The Filing: Meeting the Statutory Reporting Deadline
If the conclusion is suspicion, the report goes to the financial intelligence unit within the statutory window. In Nigeria that window is tight, and the next section covers it in detail.
Suspicion is a lower bar than proof. The Financial Action Task Force Recommendation 20 requires a report where an institution suspects, or has reasonable grounds to suspect, that funds are the proceeds of criminal activity. You are not required to establish that a crime occurred. Waiting for certainty is how institutions miss deadlines.
5. The Relationship: Deciding Whether the Customer Stays
Filing a report is not the end of the relationship question. Someone still has to decide whether the customer stays, moves to enhanced monitoring, gets a rating change, or exits.
This decision belongs to the compliance function with senior management involvement, and it needs its own record. Filing a report and then leaving the account to operate exactly as before is a position you may be asked to defend.
AML Case Management Deadlines Under Nigerian Law
Nigerian reporting entities work to some of the tightest reporting timeframes anywhere, and the deadlines are frequently misunderstood.
The 72-Hour Scrutiny Window and the 24-Hour Filing Deadline
Under the Money Laundering (Prevention and Prohibition) Act 2022 and the NFIU's Suspicious Transaction Reporting Guidelines, a reporting entity must complete its internal scrutiny of a suspicious transaction within a maximum of 72 hours.
The suspicious transaction report must then reach the Nigerian Financial Intelligence Unit within 24 hours of the point at which the entity deems the transaction suspicious.
Two practical consequences follow.
The clock starts when suspicion arises, not when the investigation finishes. An analyst who forms suspicion on Monday and completes their write-up on Thursday has a timing problem regardless of how good the write-up is.
And 72 hours is not enough time to chase a document from a customer, which means your case management has to be built around information you already hold rather than information you will request.
STR Content: What the NFIU Expects in the Narrative
The NFIU guidelines are specific, and this is where most rejected filings fall down. An acceptable STR gives a detailed, well-organised account of the suspicious activity that identifies:
- Who the subject of the report is
- What the subject is doing
- When the transaction was conducted
- Where it was performed, by channel or geography
- Why the activity is considered suspicious
- How the subject is doing it
It should also include the alerts that triggered the review, any previous alerts or STR history on the subject, records of earlier internal investigations or law enforcement requests, and any remedial action taken. Customer identification documents and transaction records are attached.
A narrative that says "multiple large cash deposits inconsistent with customer profile" and stops there does not meet that standard. Our guide to suspicious transaction reporting covers the filing mechanics in more detail.
Tipping Off: What Investigators Cannot Say to a Customer
Nigerian law makes it an offence to disclose to a customer or a third party that a suspicious transaction report has been made or that an investigation is under way. FATF Recommendation 21 sets the same prohibition internationally, alongside legal protection for staff who report suspicion in good faith.
This has an operational edge that catches teams out. Relationship managers frequently want to know why an account is under review, and customers ask why a payment is delayed. Your case management process needs a script for both, and a rule about who inside the institution can see that a report has been filed.
Restricting case visibility is not internal secrecy for its own sake. It is a legal requirement with a criminal penalty attached.
How to Measure AML Case Management Performance
1. Alert volume tells you almost nothing. A department closing 400 alerts a week may be doing excellent work or may be rubber-stamping. These four measures separate the two.
2. Age of the Oldest Open Case: The Number That Exposes a Backlog
The single most useful figure in the department, and the one averages hide. A queue with an average turnaround of four days can still contain a case nobody has touched in six weeks, and that case is the one an examiner will find.
Report it weekly as a single number with the case reference attached, so it belongs to someone.
3. Alerts Closed Per Analyst: Throughput Paired With a Quality Sample
Throughput on its own rewards fast closing, which is the behaviour that caused the problem in the first place. It only means something alongside quality.
Pair it with a monthly review of a random sample of closed cases, carried out by someone who did not close them. Ten cases is enough to tell you whether the rationales would survive inspection.
4. Escalation and Filing Rate by Rule: Which Rules Produce Intelligence
Break escalations and filings down by the monitoring rule that raised the alert. A rule generating 200 alerts a quarter that has never once escalated is producing work rather than intelligence, and that is a tuning decision waiting to be made.
A high escalation rate is not a bad sign. A zero escalation rate almost always is.
5. Time From Suspicion to Filing: Your Statutory Compliance Number
Measure from the moment an analyst forms suspicion to the moment the report reaches the NFIU, against the 24-hour requirement rather than against internal habit.
An institution that cannot produce this number cannot demonstrate compliance with the deadline, which is a finding in itself.
Clearing Your AML Case Management Alert Queue With Youverify
The alert backlog is not a staffing problem. It is a gathering problem. Analysts spend most of an investigation assembling a picture from six systems, and the 24-hour clock runs while they do it.
Youverify Case Management is where a flag becomes a case: queues, SLAs, the entity graph, evidence, and a decision trail you can hand to an examiner. The queue is prioritised rather than undifferentiated. The SLA makes the statutory clock visible on every open case instead of something you discover you missed. And the entity graph surfaces connections between accounts that stay invisible when a system evaluates one customer at a time, which is where the three-alerts-one-pattern problem gets solved.
When the conclusion is suspicion, Youverify Regulatory Reporting drafts STRs, CTRs and periodic returns from the case file itself, formatted per regulator and filed with the evidence attached. The narrative is built from what the investigation actually recorded rather than retyped from memory at hour twenty-three.
The result is the position every compliance team wants and few can demonstrate: regulator-ready before the regulator asks.
Book a free demo with our compliance experts to see what your alert queue and filing timelines would look like on Youverify.