
AML Case Management: How Compliance Teams Track, Investigate and Resolve AML Alerts
Key Takeaways
AML case management is the process of turning an alert into a documented, defensible decision.
An alert is a risk signal, not proof of crime, and it is not automatically a suspicious transaction report (STR).
Alerts should be prioritised by risk, not by the order they arrive.
An unresolved alert should stay traceable until an authorised reviewer records the outcome and rationale.
In Nigeria, once a transaction is confirmed as suspicious, the STR must reach the Nigerian Financial Intelligence Unit (NFIU) within 24 hours.
What Is AML Case Management?
Anti-money laundering (AML) case management is the process of reviewing, investigating and resolving alerts raised by screening or transaction monitoring. It covers how an alert is assigned, investigated, escalated, decided and documented.
The goal is not to clear alerts quickly. The goal is a decision that holds up when a regulator asks why it was made, sometimes years later.
Snippet-ready answer: AML case management is the process compliance teams use to review, investigate and resolve alerts from sanctions screening and transaction monitoring. It covers alert assignment, investigation, escalation, decision and documentation. Each case ends either in a closure with a recorded reason or a suspicious transaction report to the financial intelligence unit.
Where AML Alerts Come From
AML alerts come from two main sources. The first is screening, when a customer matches or closely matches a sanctions list, politically exposed person (PEP) record or adverse media result.
The second source is transaction monitoring. Here, alerts fire when activity breaks a rule or departs from a customer's expected behaviour. Examples include sudden high-value transfers, rapid movement of funds or payments to high-risk jurisdictions.
An alert is a risk signal, not proof of criminal conduct. It may come from a false positive, such as a shared name, or from legitimate activity that needs explaining. Case management exists to tell the two apart and record why.
A Typical AML Case Management Workflow
The seven steps below describe a typical risk-based workflow. Institutions may combine, reorder or govern these steps separately, depending on their size, regulator and systems.
Step 1: The Alert Is Raised and a Case Opens
When a rule or screening check fires, the system creates an alert against the customer's record. In an integrated case management system, a case may open automatically and link to that same record.
Linking matters. If one customer triggers ten alerts in a week, an analyst should see one case with full history, not ten scattered tickets.
Step 2: The Team Is Notified
The relevant team must know an alert exists before it can act. Most platforms show new alerts on a central compliance dashboard, grouped into queues.
The dashboard should show who owns each case, how severe it is and how long it has been open. Without that view, alerts sit unread and internal deadlines pass unnoticed.
Step 3: The Alert Is Triaged and Prioritised
Not every alert carries the same risk. A possible sanctions match on a high-value corporate account needs attention before a low-value velocity alert on a dormant account.
Strong case management sorts queues by risk, not by arrival time. Analysts then open the case that matters most next, rather than the oldest one.
Step 4: The Analyst Investigates
Investigation means testing whether the alert reflects real risk. The analyst reviews the customer's profile, transaction history, previous alerts, screening results and any supporting documents.
The best systems attach this evidence before the analyst opens the case. Analysts then spend their time judging risk, not gathering data from separate tools.
Step 5: The Case Is Escalated or Closed
After investigation, the analyst either closes the case or escalates it. Every closure needs a written reason. "False positive, date of birth does not match listed individual" is a defensible reason. "Cleared" is not.
Where the institution's risk-based procedures require it, high-risk cases should go to a second reviewer or the money laundering reporting officer (MLRO). This "four-eyes" review means no single person makes a high-stakes decision alone.
Step 6: A Suspicious Transaction Report Is Filed if Needed
If the investigation confirms suspicion, the institution files an STR with its financial intelligence unit. FATF Recommendation 20 requires prompt reporting where there is suspicion, or reasonable grounds to suspect, that funds are criminal proceeds or linked to terrorist financing.
FATF Recommendation 21 addresses tipping-off and confidentiality. Staff must not tell the customer that a report has been or will be filed. National law, not FATF, sets the exact filing deadline.
Step 7: The Decision Is Recorded
The final step is the audit trail. It should show what triggered the alert, what the analyst reviewed, who decided, what they decided and when.
FATF Recommendation 11 requires institutions to keep transaction and due diligence records for at least five years, subject to any longer national retention rules. A case file without a clear audit trail is the first thing an examiner will question.
Snippet-ready answer: A typical AML case management workflow has seven steps. An alert is raised and a case opens. The team is notified, and the alert is triaged by risk. An analyst investigates, then closes or escalates the case. If suspicion is confirmed, a suspicious transaction report is filed. Finally, the decision is recorded in an audit trail.
How Is the Compliance Team Notified When an Alert Is Raised?
Notification usually happens through the compliance dashboard. New alerts appear in the relevant queue as soon as they fire, with severity and ownership visible.
The key test is whether the right person sees the right alert in time. Alerts should route to the team responsible for that risk type, such as sanctions, fraud or transaction monitoring. Each severity level should also carry an internal response deadline.
When choosing a platform, ask how alerts are routed, whether queues can be split by risk and whether overdue cases are flagged. Our guide to the best transaction monitoring software covers these evaluation points in more detail.
What Happens When an AML Alert Is Not Resolved?
An unresolved alert should remain traceable in the case management system until an authorised reviewer records the outcome and rationale. It should not drop out of view because it is old or difficult.
What happens to the customer in the meantime depends on the risk and alert type. The institution may pause a transaction, restrict activity, request more information or apply enhanced monitoring. The right treatment is set by the institution's policies, its regulator and the product involved.
A potential sanctions match needs particular care. It should not be treated as a confirmed match until the relevant identifiers, such as date of birth and nationality, have been reviewed. It should be escalated and resolved under the institution's sanctions procedure.
Good practice keeps three things true. Unresolved cases stay visible to the team. Cases past their internal deadline are flagged. No case closes without a recorded reason.
AML Case Management Rules in Nigeria
Nigeria's reporting obligations shape how case management must work. Section 7 of the Money Laundering (Prevention and Prohibition) Act 2022 (MLPPA 2022) requires financial institutions and designated non-financial businesses and professions (DNFBPs) to report suspicious transactions to the NFIU.
The NFIU added detail through its Guidelines for the Identification, Verification and Reporting of Suspicious Transactions for Financial Institutions, issued on 13 December 2024. According to a Templars legal briefing, the guidelines set two separate periods.
The first is an examination window. A transaction that appears suspicious must be thoroughly reviewed within 72 hours. The second is the reporting deadline. Once suspicion is confirmed, the STR must be filed with the NFIU within 24 hours.
These periods should not be confused. The 72-hour window is for examination and does not extend the 24-hour reporting deadline. An alert is also not automatically an STR. The reporting duty arises when the institution has formed a suspicion, or has reasonable grounds to suspect, under Nigerian law.
The same briefing notes that non-compliance "may result in penalties, fines, or even licence withdrawal" for reporting entities. Institutions should also keep the evidence behind each alert, analysis, decision and report.
These timelines leave little room for alerts sitting unread. A process that takes a week to open an alert cannot meet a 72-hour examination window. This is why queue visibility and evidence attached to each case are compliance needs, not conveniences.
Sanctions follow their own rules. A confirmed match to a person or entity under applicable Nigerian or United Nations (UN) targeted financial sanctions may require immediate freezing or blocking action. A potential match should be escalated and resolved under the institution's sanctions procedure first.
A Real-World Compliance Scenario
Consider a Nigerian payment service provider that receives 400 transaction monitoring alerts on a Monday morning. Its team works the queue in order of arrival.
One alert flags a merchant receiving dozens of small transfers from new accounts, then moving the funds out within minutes. It sits 300th in the queue and is not opened until Thursday afternoon.
By then, the 72-hour examination window has passed and the funds are gone. The provider must now explain the delay to its regulator.
A team using risk-based queues sees the same alert near the top on Monday morning. The case already shows the merchant's profile, linked accounts and earlier alerts. The analyst escalates it within the hour. The MLRO confirms suspicion the same day, and the STR is filed well inside the 24-hour deadline.
Common AML Case Management Mistakes
The first mistake is working alerts in arrival order. This buries high-risk cases behind low-risk noise.
The second is closing cases without a clear reason. An examiner will ask why a match was cleared, and "reviewed" is not an answer.
The third is splitting evidence across tools. When analysts must search several systems for one customer, investigations slow down and gaps appear in the record.
The fourth is letting unresolved cases go stale. An open case with no owner and no deadline is a risk the institution has seen but not handled.
How Youverify Handles AML Alerts and Cases
On Youverify, alerts surface on the compliance dashboard. According to Youverify's transaction monitoring page, every agent that fires opens a case on the same entity record built at onboarding. As the page puts it, “one customer in one window raises one alert, not forty.”
The transactions, the customer's declared profile, earlier alerts and Vyra's reasoning are already attached when the analyst opens the case. Queues are organised by risk, not by arrival.
The platform applies four-eyes review on escalation and service-level deadlines on every severity, and no case is closed without a reason. STRs are drafted from the case file in the format the financial intelligence unit expects, with the evidence trail intact.
Vyra investigates. Your workflow decides. Every alert's audit trail records the agent version that fired, the conditions it evaluated, who worked the case, what they decided and when.
Conclusion
AML case management decides whether an alert becomes a defensible decision or an unexplained gap. A typical workflow runs from raise to notify, triage, investigate, decide, report and record.
Doing it well is harder. It needs alerts that reach the right team, queues sorted by risk, evidence attached before investigation and no case closed without a reason. For Nigerian institutions working to a 72-hour examination window and a 24-hour reporting deadline, those are not optional.
See How Youverify Turns Alerts Into Defensible Decisions
If your team is still working alerts in arrival order, book a free demo today to see risk-based case management in action.
Read Also
Banks Requirements for FICA Verification
NIN Slip in Nigeria: Types, How to Get It, and How to Verify If It's Genuine
AI and Frauds: How to Protect Yourself from Deep Fake Videos
Author the Author
Victoria Okere is a compliance content writer at Youverify, specializing in AML compliance, financial crime risk, regulatory technology, and emerging trends in financial services.
Related Articles

Why is Negative News Screening (NNS) Important?

What is a Sanctions List?
