Alert disposition is the documented decision that closes an alert: close with no action, escalate to a case or enhanced due diligence, or refer for a SAR, plus the written reason why. The reason, not the outcome itself, is what proves your program is making sound calls.
What is alert disposition, in plain English?
Alert disposition is how an alert ends. Once an analyst has reviewed a flag, they have to close it out with a decision: close it with no action, escalate it to a case or enhanced due diligence, or refer it for a SAR. Crucially, the disposition is not just the choice; it includes the written reason that explains why that choice was correct.
That written rationale is the whole point. The outcome alone means little; a closed alert and an escalated alert both look fine until you read why. Examiners, QA teams, and auditors do not just count how alerts were resolved, they sample the reasoning to test whether the decision was actually justified by the facts in front of the analyst.
So disposition quality, not raw alert volume, is what most determines how defensible your program is. A team can work a huge number of alerts and still fail an exam if the rationales do not hold up, and a smaller team with disciplined, evidence-backed dispositions will look far stronger.
How an alert gets dispositioned
- Investigate — Work the alert. The analyst reviews the triggering activity and the customer context behind the flag.
- Decide — Choose the outcome. Close with no action, escalate to a case or EDD, or refer for a SAR.
- Justify — Write the reason. Record a rationale that actually supports the decision and addresses every flagged transaction.
- Review — QA samples the call. QA and examiners sample dispositions to test whether closes and escalations were justified.
A defensible disposition vs a weak one
What changes | Weak disposition | Defensible disposition |
Rationale | Copy-paste or boilerplate reason. | Specific to the customer and the activity. |
Coverage | Ignores some flagged transactions. | Addresses every transaction that fired. |
Consistency | Standards vary by analyst. | Same standard applied across the team. |
Evidence | Conclusion with no support. | Reasoning tied to the facts on file. |
What it looks like in practice
In practice
An alert fires on a customer for a series of large, round-number transfers. An analyst closes it with the note customer activity consistent with business, the same line they paste on dozens of alerts a week. On paper the alert is resolved.
During QA sampling, a reviewer pulls the alert and finds two of the flagged transfers had no plausible business explanation and were never addressed in the note. The disposition does not support the close. The reviewer reopens it, and the pattern of copy-paste rationales across the analyst's queue becomes a finding. The lesson: the outcome looked fine, but the reasoning, which is what gets tested, did not hold.
Why it matters for operators
When an examiner or auditor evaluates a monitoring program, they do not primarily count alerts; they sample dispositions and read the reasoning. That makes disposition quality the single biggest driver of how defensible the program looks. A well-run program can be undone by weak rationales, and a modest one can look strong on the strength of disciplined, evidence-backed decisions.
The recurring failures are predictable: copy-paste rationales that could apply to any customer, closes that never address every flagged transaction, and analysts applying different standards to similar alerts. Each one gives a reviewer a reason to doubt the underlying decision, even when the call was actually right. The fix is narratives that are specific, complete, and consistent.
What to watch in the data
- Copy-paste rationales. Identical notes across many alerts suggest the reasoning is boilerplate, not real analysis.
- Unaddressed transactions. A close that does not explain every flagged transaction leaves a gap a reviewer will find.
- Analyst inconsistency. Different standards applied to similar alerts signal a training or QA problem.
- Outcome without evidence. A decision recorded with no supporting facts cannot be defended on review.
- QA divergence. A high rate of reopened alerts in QA sampling points to systemic disposition weakness.
Quick questions
What are the possible dispositions for an alert?
Broadly: close with no action, escalate to a case or enhanced due diligence, or refer for a SAR. Each must be accompanied by a written reason explaining why that outcome fits the facts of the alert.
Why does the reason matter more than the outcome?
Because a closed or escalated alert looks fine on its own; what proves the decision was sound is the rationale behind it. Examiners and QA teams sample dispositions and read the reasoning to test whether the call was justified.
What is wrong with copy-paste rationales?
A generic note that could apply to any customer does not show that the specific alert was actually analyzed. When a reviewer finds the same line across many alerts, it undermines confidence in every one of them, even the correct closes.
Do I have to address every flagged transaction?
Yes. A disposition that closes an alert but ignores some of the transactions that fired it leaves an unexplained gap. A defensible rationale accounts for all the activity that triggered the alert, not just the easy parts.
How does disposition quality relate to alert volume?
Volume tells you how much work the program is doing; disposition quality tells you how well. Disposition quality drives how defensible the program is far more than raw volume, so a high count with weak rationales is not a strength.
Go deeper
- FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.
- FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.

