Insights

Snowflake pattern graphic with "1 alert, 4 hours" caption

The 1% Problem Isn’t a Technology Problem

Every AML officer knows the number, even if they’ve learned not to say it out loud: somewhere around one percent of illicit financial flows get caught by the global anti-money-laundering apparatus. It’s not a controversial figure. UNODC, FATF, and two decades of academic work all land in the same half-percent-to-three-percent range.

It’s also a strange number. Banks spend billions a year on transaction monitoring. Regulatory expectations climb every cycle. And the headline detection rate hasn’t meaningfully moved in twenty years. Something is wrong with the model, not the effort.

The queue was never going to solve this

Start with the arithmetic. A modern transaction monitoring system at a regional institution generates alerts at a rate that outpaces analyst capacity by something like 50:1. The team triages, clears what it can, escalates a fraction, and files SARs against an even smaller fraction of that. The rest gets closed, not because it’s been investigated, but because the queue has to drain somehow.

The instinct is to make the alerts smarter. Better rules, more machine learning, sharper scoring. That’s been tried for the better part of a decade, and the gains are real but bounded, because the underlying unit of analysis is still a single transaction, or a small cluster of them. A transaction is an artifact. A network can produce ten thousand of them in a week using different counterparties, different corridors, different shells, different mules. Each one is cheap to make and cheap to abandon.

Scoring artifacts is like scoring snowflakes. You can do it with real precision, and the snow keeps falling.

Twenty years, no movement

That’s the part worth sitting with. This isn’t a story about an industry that hasn’t tried. It’s an industry that has thrown enormous resources at a fixed detection ceiling and kept hitting it. More alerts, more analysts, more sophisticated scoring — and the number barely moves.

When more effort against the same problem produces the same result year after year, the problem usually isn’t a lack of effort. It’s that the unit of analysis is wrong. As long as the discipline is built around chasing disposable artifacts — one transaction at a time — the ceiling stays exactly where it is, no matter how good the tooling gets.

That reframe — from “we need better artifact detection” to “we’re detecting the wrong thing” — is the starting point for rethinking how AML programs are built, and it’s a question worth asking of any program: are you scoring snowflakes, or are you watching the storm?

If this tension sounds familiar in your own program, Section 2 offers a thirty-minute working session for AML leaders at regional institutions — no pitch, just a walk through your risk footprint.

Let’s talk.