How an AML case is scored
Summary
Read a case's score, matched pattern and evidence so you can tell how strong the flag really is.
About 2 minutes · 3 steps. Also called: risk score, why was this flagged, alert evidence.
Prerequisites
- A sign-in for Wakandi AML Risk Monitoring.
- A case open in front of you. See How to work an AML case.
Step-by-step
Open Wakandi AML Risk Monitoring and sign in.
In the top menu, click Cases, then click a row to open it.
Read the record from the top down. Each block answers a different question.

Figure 1: A case showing the details block, matched patterns, scoring breakdown and payload evidence
Then, the parts that explain the flag:
Matched patterns. The rule that fired, by name. STRUCTURING means a larger sum appears split into smaller transactions. LCT_CUMULATIVE_DAILY means cash added up past your daily reporting threshold in one day.
Score. A single number from 0 to 100 at the top of the record. It combines the parts below into one figure, so a queue can be sorted by seriousness.
Scoring breakdown. The four inputs behind the score:
- Amount — how large the money involved is against your thresholds.
- Pattern — how strongly the activity matches the rule's shape.
- Profile — how the member's own history and risk classification affect it.
- Frequency — how much busier this is than the member's normal.
Payload. The evidence the rule collected: how many transactions it counted, their total, the time window, and every transaction number involved. Check this first — it shows the actual activity rather than a conclusion about it.
Severity. Set by the rule, not calculated per case. Two cases can share a score of 78 and still be critical and high, because they came from different rules.
Activity. A tab under Notes & history holding the untouched record of the case as it was created, for audit.
Tip: A high Pattern score with a low Profile score often means a new member with no history yet, rather than someone behaving oddly. Check how long the member has been with you.
Common pitfalls & FAQ
- Two cases have the same score but different severity. Severity comes from the rule. Score comes from the activity. They are independent.
- The payload lists ten transactions but the case names one. The case is attached to the transaction that completed the pattern. The payload lists everything that made it up.
- Profile scores 25 on almost every case. That is the value used when a member has little history. It rises as the member builds a baseline.
- Can I change the score? No. Change the rule that produced it, under Settings, Rules.