How an AML case is scored
Summary
Read a case's score, matched pattern and evidence so you can tell how strong the flag really is.
About 2 minutes · 3 steps. Also called: risk score, why was this flagged, alert evidence.
Sign in with your email to read the rest of this article, track what you have finished, and earn your certificate.
Sign inPrerequisites
- A sign-in for Wakandi AML Risk Monitoring.
- A case open in front of you. See How to work an AML case.
Step-by-step
Open Wakandi AML Risk Monitoring and sign in.
In the top menu, click Cases, then click a row to open it.
Read the record from the top down. Each block answers a different question.

Figure 1: A case showing the details block, matched patterns, scoring breakdown and payload evidence
Then, the parts that explain the flag:
Matched patterns. The rule that fired, by name. STRUCTURING means a larger sum appears split into smaller transactions. LCT_CUMULATIVE_DAILY means cash added up past your daily reporting threshold in one day.
Score. A single number from 0 to 100 at the top of the record. It combines the parts below into one figure, so a queue can be sorted by seriousness.
Scoring breakdown. The four inputs behind the score:
- Amount — how large the money involved is against your thresholds.
- Pattern — how strongly the activity matches the rule's shape.
- Profile — how the member's own history and risk classification affect it.
- Frequency — how much busier this is than the member's normal.
Payload. The evidence the rule collected: how many transactions it counted, their total, the time window, and every transaction number involved. Check this first — it shows the actual activity rather than a conclusion about it.
Severity. Set by the rule, not calculated per case. Two cases can share a score of 78 and still be critical and high, because they came from different rules.
Activity. A tab under Notes & history holding the untouched record of the case as it was created, for audit.
Tip: A high Pattern score with a low Profile score often means a new member with no history yet, rather than someone behaving oddly. Check how long the member has been with you.
Common pitfalls & FAQ
- Two cases have the same score but different severity. Severity comes from the rule. Score comes from the activity. They are independent.
- The payload lists ten transactions but the case names one. The case is attached to the transaction that completed the pattern. The payload lists everything that made it up.
- Profile scores 25 on almost every case. That is the value used when a member has little history. It rises as the member builds a baseline.
- Can I change the score? No. Change the rule that produced it, under Settings, Rules.