Accelerator · Documentation

UK Transaction Monitoring Alert Adjudication — Regulatory Cross-Reference

Every rule traced to the provision it implements, and every provision traced back to the rules that implement it.

This document demonstrates bidirectional traceability between the public regulatory corpus and the rules of the Rainbird knowledge graph:

  • Part A (regulation → rules) lists every provision the model relies on and the rules that implement it, so a reviewer can confirm each obligation is covered.
  • Part B (rules → regulation) lists every rule family in the graph and the provision(s) it traces to, so a reviewer can confirm no rule exists without a regulatory or documented-policy basis.

Rules are cited by their name attribute in the RBLang XML (graph.xml). Citations were verified against legislation.gov.uk, the FCA Handbook, JMLSG and FATF publications in August 2026. Operational thresholds (deposit bands, windows, ratios, score bands) are the firm's calibration choices made under these duties; they live as facts on the TM Policy instance so they can be recalibrated without touching rules.


Part A — Regulation and guidance → implementing rules

A1. Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692, as amended)

Provision Obligation Implementing rules
Reg 28(11) — ongoing monitoring: scrutiny of transactions for consistency with knowledge of the customer, the customer's business and risk profile The whole scrutiny pipeline: transactions must be assessed against the expected profile before any disposition All Layer-1 feature rules ("Classify inbound/outbound transactions", "Total inbound/outbound/cash deposit value", "Inflows as a multiple of expected monthly turnover", "Cash share of inflows as a percentage", "Share of total flow involving recognised counterparties", pass-through and payer-dispersion rules); "Mismatch - inflows far beyond the declared profile"; "Mismatch - inflows well beyond the declared profile"; both "Close - …" rules (which require an expected activity profile to exist, be positive, and be consistent before closing); "Rationale - close as false positive" (cites reg 28(11) verbatim)
Reg 28(11)(b) — keeping CDD documents and information up to date Closure is unavailable against stale customer records "Block - stale KYC profile" (closure barred when the KYC refresh exceeds the closure limit); "Factor - stale KYC refresh" (staleness raises the context score); both "Close - …" rules (KYC recency must be known)
Reg 33(1)(f) — EDD where a transaction is complex or unusually large, there is an unusual pattern, or no apparent economic or legal purpose Unusual-pattern detection and mandatory enhanced scrutiny instead of closure All strong/moderate typology rules ("Structuring - …", "Rapid movement - …", "Mule - …", "Mismatch - …", "Cash intensity - …", "Round amounts - …"); "Escalate - a single uncorroborated strong typology"; "Escalate - multiple moderate typologies"; "RFI - a single unexplained moderate anomaly"; "Rationale - escalate to investigation" (cites reg 33)
Reg 33(1)(b) with reg 33(3)(a) — mandatory EDD for FATF call-for-action country nexus (as narrowed by SI 2026/621) Any call-for-action exposure is a strong indicator, a closure block, and a defeater override "Transactions with call for action jurisdictions"; "Jurisdiction - any exposure to a call for action jurisdiction" (strong, cf 88); "Block - call for action jurisdiction exposure"; "Override - call for action nexus voids benign explanations"; jurisdiction risk table facts (maintained from the FATF Call for Action list)
Reg 33(6) — geographic and other risk factors in assessing ML/TF risk Increased-monitoring (grey-list) exposure treated as a graded risk factor rather than an automatic EDD trigger "Transactions with enhanced monitoring jurisdictions"; "Jurisdiction - repeated exposure to enhanced monitoring jurisdictions" (moderate, cf 68); "Defeater - flows dominated by recognised counterparties" (coverage defeater disabled when any jurisdiction exposure exists)
Reg 35(1), 35(5) — PEP identification, senior management approval and enhanced ongoing monitoring PEP status raises risk, escalates unusual activity, and forces four-eyes review "Factor - politically exposed person" (25 points); "Escalate - moderate typology on a politically exposed person"; "Review - politically exposed person disposition" (Second Reviewer Required); both "Close - …" rules (PEP screening must be known before closure)
Reg 18 — firm-wide ML/TF risk assessment (customers, geography, products, transactions, channels) The customer risk context layer operationalises the risk assessment per customer All ten "Factor - …" rules; "Points for each identified risk factor"; "Customer context risk score"; all four "Tier - …" band rules; "Evidence - customer risk context factor"; "Evidence - customer risk tier"
Reg 19(1), 19(3), 19(4)(a) — documented policies, controls and procedures for identification and scrutiny of unusual transactions The model itself is the documented procedure; its thresholds are recorded policy The 26 TM Policy parameter facts; the suppression-map, points-map, documented-explanation and directly-reportable data tables; every rule that binds a TM Policy fact instead of a hardcoded number
Reg 27(8) — CDD refresh on a risk-based approach and when circumstances change / doubts about veracity Stale or doubtful CDD prevents reliance on the profile "Block - stale KYC profile"; "Factor - stale KYC refresh"; "Close - …" knownness gates (expected turnover must exist and be positive, screening results must be known)

A2. Proceeds of Crime Act 2002

Provision Obligation Implementing rules
s.330 — failure to disclose (regulated sector): "knows or suspects, or has reasonable grounds for knowing or suspecting" The SAR recommendation standard: reasonable grounds are constituted by corroborated or directly reportable typology evidence "SAR - multiple strong typologies corroborate"; "SAR - strong typology corroborated by a moderate typology"; "SAR - strong typology on a high risk context customer"; "SAR - strong typology recurs after a prior SAR"; "SAR - moderate typology recurs after a prior SAR"; "SAR - directly reportable typology with strong evidence" (with the is directly reportable typology registry for Structuring and Money Mule Pattern); "Rationale - recommend SAR" (cites s.330); "Next step - SAR" (File SAR With Nominated Officer)
s.331 — nominated officer evaluation The model recommends; the nominated officer decides. Every SAR recommendation routes to the nominated officer with a second reviewer "Next step - SAR"; "Review - SAR recommendation" (Second Reviewer Required); "Evidence - second reviewer routing"
s.333A — tipping off Customer enquiries must be neutral and never disclose that an alert or report exists "Rationale - request information" (mandates neutral enquiry, cites s.333A); "Rationale - recommend SAR" ("do not alert the customer", cites s.333A); "Next step - request information" (Issue Neutral Customer Enquiry)
s.335 / s.336 — appropriate consent (DAML) mechanics Out of model scope by design: consent and moratorium mechanics run in the SAR process after referral Covered by the handover embodied in "Next step - SAR" — the model stops at Recommend SAR and never authorises the transaction itself
R v Da Silva [2006] EWCA Crim 1654 — suspicion is "a possibility, which is more than fanciful" The strong/moderate grading calibrates "more than fanciful" against "merely unusual" All graded typology certainties (strong signals approach the suspicion standard, moderate signals mark unusual activity); "Rationale - recommend SAR" (cites Da Silva verbatim)
K Ltd v National Westminster Bank plc [2006] EWCA Civ 1039 — a staff member's genuine suspicion binds the firm A staff-raised alert can never be closed by the model and always at least escalates "Block - staff raised concern"; "Override - staff raised concern voids benign explanations"; "Escalate - staff raised concern binds per K Ltd" (cf 90)

A3. JMLSG Guidance Part I (June 2023 edition, updated August 2025)

Provision Obligation Implementing rules
Section 5.7 — monitoring customer activity: risk-based monitoring to identify unusual activity; unexplained unusual activity may give grounds for suspicion The alert intake layer and the typology sub-models grade unusual activity; monitoring outcomes feed the risk profile "has alert type"/"has alert source" intake facts and "Evidence - generating monitoring rule"; all typology rules; "Factor - three or more prior alerts" (outcomes feed back into customer risk context)
Chapter 6 (unusual vs suspicious, ~para 6.11) — unusual is not necessarily suspicious; examine and enquire before reporting The four-outcome ladder embodies the distinction: RFI for unexplained-but-unusual, Escalate for beyond-unusual, SAR only at the suspicion standard "RFI - a single unexplained moderate anomaly"; "Escalate - …" family; "Final - default to request information when nothing resolves" (never closes and never reports on insufficient data); "Rationale - request information" (cites the distinction verbatim); the defeater layer ("Defeater - …" rules) which formalises "rationally explained" activity
Chapter 6 (internal reporting / MLRO evaluation) — staff report internally; the nominated officer evaluates and documents Staff-raised handling and the documented rationale on every outcome "Escalate - staff raised concern binds per K Ltd"; all four "Rationale - …" rules; "Evidence - …" family (every disposition carries its evidence set)

A4. FCA Handbook and guidance

Provision Obligation Implementing rules
SYSC 6.3.1R — systems and controls to identify, assess, monitor and manage ML risk The layered pipeline as a whole: features → context → typologies → defeaters → controls → outcomes Architecture-level: every layer; specifically the control layer ("Block - …", "Override - …") that prevents unsafe closure
SYSC 6.3.9R — MLRO oversight Escalation and SAR routing into the MLRO function; four-eyes review on the highest-risk dispositions "Next step - SAR"; "Next step - investigation"; all three "Review - …" rules
FCG 2.2 — governance, MI and systematic recording of risk decisions Every adjudication emits its outcome, evidence set, rationale, next step and review requirement as queryable facts for MI "has adjudication outcome" ladder rules; all "Evidence - …" rules; all "Rationale - …" rules; "has review requirement" rules
FCG 3.2.5 / 3.2.5A — how the firm decides whether activity is genuinely suspicious; automated alert triage must be justified and documented with accessible rationales The written rationale and full evidence trail on every outcome, including set-aside notes for suppressed indicators and disregard notes for voided explanations All four "Rationale - …" rules; "Evidence - indicator set aside by explanation"; "Evidence - benign explanations disregarded"; "Evidence - closure precluded"; "Evidence - no indicators found"; "Evidence - insufficient data note"
FG17/6 as updated by FG25/3 — proportionate, risk-based PEP treatment PEP status is a graded risk factor and review trigger, not an automatic escalation on its own "Factor - politically exposed person" (points, not an outcome); "Escalate - moderate typology on a politically exposed person" (escalates only when combined with an indicator); "Review - politically exposed person disposition"

A5. FATF standards and typologies

Provision Obligation Implementing rules
Recommendation 10 — ongoing due diligence and transaction scrutiny International parent of reg 28(11): same rules as A1 row 1 Layer-1 feature rules; mismatch typology; closure consistency gates
Recommendation 20 — report on suspicion or reasonable grounds Same rules as POCA s.330 (A2 row 1) "SAR - …" candidate family; "Rationale - recommend SAR"
FATF Call for Action / Increased Monitoring lists Geographic risk grading with a maintainable country table Jurisdiction risk table facts ("has jurisdiction risk level"); "Transactions with call for action jurisdictions"; "Transactions with enhanced monitoring jurisdictions"; both "Jurisdiction - …" typology rules
FATF Professional Money Laundering (2018) and mule/structuring typologies Behavioural detection of structuring, rapid movement and money-mule networks "Cash deposits just below the internal cash threshold" and the structuring sub-model; the pass-through/outflow-ratio features and the rapid-movement sub-model; the payer-dispersion features and the mule sub-model (including "Mule - inbound credit matched to an interbank fraud report")

A6. Fraud data-sharing context

Provision Obligation Implementing rules
Cifas National Fraud Database — members must check and act on confirmed fraud markers A fraud marker precludes closure, voids benign explanations, and routes to investigation "Block - fraud database marker on customer"; "Override - fraud marker voids benign explanations"; "Escalate - fraud database marker on the customer"
PSR APP reimbursement regime (interbank fraud reports/recalls) Matched inbound fraud proceeds are treated as suspected criminal property "Mule - inbound credit matched to an interbank fraud report" (strong, cf 95); "Block - inbound fraud report match"; "Override - fraud report voids benign explanations"; "Evidence - inbound fraud report"

Part B — Rules → regulation and policy basis

Every rule family in the graph, with its trace. Family names use the rule name prefixes in the XML; counts reconcile to the 157 rules in the graph.

# Rule family (names in XML) Rules Regulatory / policy basis
B1 Transaction classification and totals ("Classify …", "… value items", "Total … value") 9 MLR reg 28(11) scrutiny; FATF R.10 — the arithmetic substrate of transaction scrutiny
B2 Known-counterparty recognition and coverage ("Transactions with expected counterparties", "Transactions with the declared salary payer", "Known counterparty value items", "Total known counterparty value", "Share of total flow involving recognised counterparties") 5 Reg 28(11) consistency-with-knowledge test; JMLSG 5.7 rational-explanation principle (recognised counterparties are the KYC-known baseline)
B3 Near-threshold structuring features ("Cash deposits just below the internal cash threshold", count, dates, first/last, span) 6 FATF structuring typology; reg 33(1)(f) unusual patterns; firm policy calibration (band and windows on TM Policy)
B4 Velocity features ("Dates of all alerted transactions", "Most recent activity date", inbound/outbound date rules, "Days between first inbound and last outbound", "Outbound value as a share of inbound value") 8 FATF rapid-movement/professional-laundering typology; reg 33(1)(f)
B5 Cash-intensity and profile features ("Cash share of inflows as a percentage", "Inflows as a multiple of expected monthly turnover") 2 Reg 28(11) expected-activity consistency; JMLSG 5.7
B6 Mule dispersion features ("Unrecognised inbound payers", "Count of distinct unrecognised payers") 2 FATF money-mule typology (dispersed third-party fan-in)
B7 Corporate wire features ("Outbound international wires", "Round amount outbound wires", "Outbound transactions to unrecognised overseas counterparties") 3 FATF corporate-flows typologies (round-amount layering); reg 33(6) geographic/channel risk factors
B8 Jurisdiction exposure ("Transactions with call for action jurisdictions", "Transactions with enhanced monitoring jurisdictions") 2 Reg 33(1)(b)+(3)(a) (call for action); reg 33(6) (increased monitoring); FATF lists
B9 Salary recognition ("Inbound credits matching the declared salary pattern", "Salary credit value items") 2 JMLSG 5.7 / Ch 6 rational explanation — declared salary is legitimate expected activity
B10 Customer risk factors ("Factor - …" ×10, "Credible recent financial crime media finding") 11 Reg 18 risk assessment; reg 35(1) PEP systems; reg 28(11)(b) CDD currency; JMLSG 5.7 feedback of monitoring outcomes; adverse-media weighting is L2-analyst practice under reg 33(6) risk factors
B11 Context scoring and tiers ("Points for each identified risk factor", "Customer context risk score", "Tier - …" ×4) 6 Reg 18 risk assessment operationalised; reg 19 documented procedure (points table on the policy surface)
B12 New/reactivated account ("New account for mule assessment", "Reactivated dormant account for mule assessment") 2 FATF mule typology (new or dormant accounts as mule vehicles)
B13 Closure blocks ("Block - …" ×8) 8 Fraud match/marker: Cifas duty and PSR regime; sanctions: routes to the sanctions regime (escalation, not closure); call-for-action: reg 33(1)(b); stale KYC: reg 28(11)(b)/reg 27(8); credible media: reg 33(6); prior SAR: s.330 recurrence caution; staff-raised: K Ltd
B14 Defeater overrides ("Override - …" ×6) 6 Same provisions as B13 — where a hard risk state exists, benign explanations must be disregarded, not weighed
B15 Typology sub-models ("Structuring - …" ×2, "Rapid movement - …" ×2, "Mule - …" ×3, "Mismatch - …" ×2, "Jurisdiction - …" ×2, "Cash intensity - …" ×2, "Round amounts - …" ×1) 13 FATF typologies (structuring, professional laundering/rapid movement, mules, round-amount corporate flows); reg 33(1)(f) unusual/large/no-apparent-purpose; reg 28(11) profile deviation; the strong/moderate grades calibrate Da Silva suspicion vs JMLSG unusual
B16 Defeaters ("Defeater - …" ×4) 4 JMLSG Ch 6: unusual activity that is rationally explained is not suspicious. Salary pattern, recognised counterparties, declared seasonal trade, and documented case-file explanations (property sale, loan drawdown, inheritance) are the codified benign explanations. The dominance and precedent conditions stop an explanation excusing more than it explains
B17 Suppression and net signals ("Benign explanation suppresses a typology", "Strong signal that survives suppression", "Moderate signal that survives suppression and is not already strong", "Alert exhibits a surviving …" ×2) 5 JMLSG Ch 6 examine-then-decide sequence; the suppression map deliberately excludes deliberate-conduct typologies (structuring, mules, call-for-action nexus) which no innocent explanation can excuse — s.330 caution
B18 SAR candidates ("SAR - …" ×6) 6 POCA s.330 / FATF R.20 reasonable-grounds standard; Da Silva calibration; recurrence rules reflect s.330 caution on previously reported customers
B19 Escalate candidates ("Escalate - …" ×8) 8 Reg 33(1)(f)/reg 28(11) enhanced scrutiny; reg 35(5) PEP monitoring; Cifas duty; sanctions-process routing; K Ltd staff-suspicion rule; JMLSG beyond-merely-unusual
B20 RFI candidate ("RFI - a single unexplained moderate anomaly") 1 JMLSG Ch 6 examine/enquire before reporting; s.333A constrains the enquiry to neutral wording
B21 Close candidates ("Close - all indicators carry benign explanations", "Close - no indicators and activity consistent with profile") 2 Reg 28(11) satisfied-scrutiny closure; FCG 3.2.5A documented rationale; the knownness gates implement the principle that closure is an affirmative finding — unknown screening results, missing profiles or unknown ratings can never close (SYSC 6.3.1R risk management)
B22 Precedence ladder ("Flag - …" ×4, "Final - …" ×5 including the default) 9 Governance requirement (FCG 2.2 systematic decision-making): exactly one outcome per alert; the most serious available disposition prevails; unresolved cases default to Request Information, never to closure
B23 Evidence layer ("Evidence - …" ×24) 24 FCG 3.2.5/3.2.5A documented, accessible decision records; FCG 2.2 MI; JMLSG Ch 6 documentation of the nominated-officer evaluation trail; set-aside and disregard notes keep the full reasoning visible per FCA expectations
B24 Rationale layer ("Rationale - …" ×4) 4 FCG 3.2.5A written rationale; each rationale cites its governing standard verbatim (s.330/Da Silva/s.333A; reg 28(11)/reg 33; JMLSG unusual-vs-suspicious; FCA FCG closure documentation)
B25 Next steps ("Next step - …" ×4) 4 s.331 nominated-officer referral; SYSC 6.3.9R MLRO function; s.333A neutral-enquiry constraint; FCG closure documentation
B26 Review routing ("Review - …" ×3) 3 Reg 35(5) senior-management involvement in PEP relationships; FCG governance expectations on high-risk dispositions and SAR quality

Reconciliation: B1–B26 sum to 157 rules — the full rule count of the delivered graph. Every rule traces to at least one provision or to the firm's documented policy calibration (reg 19), and every provision in Part A is implemented by at least one live, tested rule.


Data tables and their bases

Table (facts in XML) Basis
has jurisdiction risk level country rows FATF Call for Action / Increased Monitoring lists (illustrative maintenance table — refresh from FATF publications after each plenary)
26 TM Policy threshold facts Reg 19 documented policy calibration; each threshold is the firm's risk-based choice under reg 18
explanation suppresses typology map JMLSG Ch 6 rational-explanation principle; deliberate-conduct typologies deliberately absent (s.330 caution)
is directly reportable typology registry POCA s.330 — strong unsuppressed structuring or mule evidence alone meets the reasonable-grounds standard (FATF typology grounding)
is documented explanation type registry FCG 3.2.5A — only genuine case-file explanation types may defeat an indicator
factor carries points map Reg 18 risk-assessment weighting, documented per reg 19

Scope notes and data-contract duties

  • Sanctions: an unresolved sanctions match escalates and voids explanations here; freeze and OFSI reporting run in the firm's sanctions process outside this model (by design).
  • DAML consent (POCA s.335/336): post-referral mechanics are out of scope; the model's responsibility ends at Recommend SAR with nominated-officer routing.
  • Consumer-validation duties (feed contract): the alert intake feed must supply attribute-complete transaction rows (amount, direction, channel, counterparty, jurisdiction, date), non-negative amounts, and only in-scope review-period transactions. Malformed rows (negative amounts, dangling transaction references, stray out-of-window deposits) are upstream data-quality faults: the model's behaviour under them is pinned by dedicated tests (A08, A09, RT3) and documented rather than silently corrected.

← Back to the accelerator