Field Notes

Sizing an AML alert sample without drowning the team

Defensible sample sizing for AML alert testing — enough depth for credibility, not so much that investigators stop clearing the live queue.

April 2, 2026

Charts and analytics printed for a compliance review meeting

Alert populations in electronic payment firms can run into tens of thousands of items a year. Pulling a flat percentage often produces a sample that looks rigorous on paper and impossible in the calendar. Harborline’s approach for Taiwan engagements starts with stratification, not volume theatre.

We typically separate true positives escalated to investigation, closed false positives with short notes, and aged items still open beyond the firm’s own service standard. Within each band we weight toward higher customer risk and higher transaction velocity. The goal is not statistical purity for its own sake; it is to place auditor time where residual risk concentrates.

A mid-size payment institution we reviewed in early 2026 had strong first-line clearing notes but thin second-line challenge. Expanding the sample in the closed-as-false-positive band revealed pattern copying across analysts — identical phrases reused without fresh evidence. That finding would have been invisible in a sample drawn only from escalated cases.

When you request AML control testing, bring last year’s alert counts by disposition and your written investigation timelines. Those two figures let us propose a sample that your team can support while fieldwork runs — so live monitoring does not stall while we re-perform historical cases.

Back to Field Notes