How an AML case is scored

Summary

Read a case's score, matched pattern and evidence so you can tell how strong the flag really is.

About 2 minutes · 3 steps. Also called: risk score, why was this flagged, alert evidence.

Prerequisites

  • A sign-in for Wakandi AML Risk Monitoring.
  • A case open in front of you. See How to work an AML case.

Step-by-step

  1. Open Wakandi AML Risk Monitoring and sign in.

  2. In the top menu, click Cases, then click a row to open it.

  3. Read the record from the top down. Each block answers a different question.

    A case showing the details block, matched patterns, scoring breakdown and payload evidence
    Figure 1: A case showing the details block, matched patterns, scoring breakdown and payload evidence

Then, the parts that explain the flag:

Matched patterns. The rule that fired, by name. STRUCTURING means a larger sum appears split into smaller transactions. LCT_CUMULATIVE_DAILY means cash added up past your daily reporting threshold in one day.

Score. A single number from 0 to 100 at the top of the record. It combines the parts below into one figure, so a queue can be sorted by seriousness.

Scoring breakdown. The four inputs behind the score:

  • Amount — how large the money involved is against your thresholds.
  • Pattern — how strongly the activity matches the rule's shape.
  • Profile — how the member's own history and risk classification affect it.
  • Frequency — how much busier this is than the member's normal.

Payload. The evidence the rule collected: how many transactions it counted, their total, the time window, and every transaction number involved. Check this first — it shows the actual activity rather than a conclusion about it.

Severity. Set by the rule, not calculated per case. Two cases can share a score of 78 and still be critical and high, because they came from different rules.

Activity. A tab under Notes & history holding the untouched record of the case as it was created, for audit.

Tip: A high Pattern score with a low Profile score often means a new member with no history yet, rather than someone behaving oddly. Check how long the member has been with you.

Common pitfalls & FAQ

  • Two cases have the same score but different severity. Severity comes from the rule. Score comes from the activity. They are independent.
  • The payload lists ten transactions but the case names one. The case is attached to the transaction that completed the pattern. The payload lists everything that made it up.
  • Profile scores 25 on almost every case. That is the value used when a member has little history. It rises as the member builds a baseline.
  • Can I change the score? No. Change the rule that produced it, under Settings, Rules.

Back to course: Anti-Money Laundering for SACCOs