SardineCon SF/2026

Learn More

O que é Disposition?

SUBSCRIBE

Disposition is the final recorded outcome on an alert or case, such as closed with no action, escalated, or referred for a SAR, together with the reasoning that supports it. It is the exact decision that QA reviewers and examiners sample to judge whether a program reaches sound, consistent conclusions.

What is disposition, in plain English?

Every alert and case has to end somewhere. The disposition is that ending: the decision of record plus the reasoning behind it. Common dispositions are closed with no action, escalated for further review, or referred for a SAR, though programs define their own set. The word covers both the outcome and the justification, because one without the other is not a real decision.

What makes a disposition strong is specificity. A good one addresses every element that got flagged and explains the outcome in terms of the actual facts of the case, not a dropdown reason that could apply to anything. A disposition that just says false positive with no explanation is a decision on paper but not in substance.

Disposition is the point where QA and examiners focus, because it is the clearest window into whether analysts are thinking consistently. If two analysts reach opposite calls on near-identical activity, the dispositions are where that inconsistency becomes visible.

How a disposition is reached

  1. Review — Work every flagged element. The analyst investigates each part of the alert or case, not just the headline trigger.
  2. Weigh — Assess against the facts. Findings are compared to the customer profile, history, and known typologies to judge whether suspicion holds.
  3. Decide — Choose the outcome. Close with no action, escalate, or refer for a SAR, matching the decision to what the evidence supports.
  4. Justify — Record specific reasoning. The rationale is written to the facts of this case, so a reviewer can follow how the conclusion was reached.

What it looks like in practice

In practice

Two analysts each get an alert on a customer receiving several mid-size transfers from a new counterparty. Analyst A writes: closed, no action, transfers consistent with the customer's stated payroll-processing business, verified against three months of prior identical activity and a matching invoice. Analyst B, on a nearly identical case, just picks false positive from a dropdown and closes.

During QA sampling, both closures are pulled. A's disposition is defensible because a reviewer can see the reasoning tied to facts. B's is flagged, because there is no way to tell whether the case was actually analyzed. When a whole team disposes like B, the inconsistency signals a training or procedure gap.

Why it matters to operators

Strong dispositions are what make a program defensible. When an examiner or QA reviewer samples closed work, they are not re-running the investigation; they are checking whether the recorded decision is supported and whether analysts reach the same call on similar activity. Wide inconsistency across a team is read as weak procedures or weak training, and it undermines confidence in every other decision the program made.

The practical failure to avoid is the template disposition: a generic reason that closes the case without engaging the facts. It leaves the flagged elements unaddressed and gives a reviewer nothing to trust. The fix is a standing expectation that every disposition names the specific facts behind the call, so consistency can be measured and the program can prove it thinks clearly.

Operator notes

  • Address every flagged element. A disposition that ignores part of what triggered the alert is incomplete, however confident it sounds.
  • Reason to the facts. The rationale should be specific to this case, not a reusable sentence that fits any file.
  • Measure consistency. Sample similar activity across analysts; divergent calls point to a training or procedure gap.
  • Beware dropdown-only closures. A reason code with no explanation is a decision QA cannot validate.
  • Consistency is a program signal. How uniformly a team disposes says more about program health than any single case.

Quick questions

How is disposition different from escalation?

Escalation is one possible disposition, moving the item up for further review. Disposition is the broader term for whatever final outcome is recorded, including no action, escalation, or a SAR referral, along with the reasoning.

Why do QA teams sample dispositions?

Because the disposition is the clearest evidence of analyst judgment. Sampling closed cases lets QA check whether decisions are supported by facts and whether the team reaches consistent conclusions on similar activity.

What makes a disposition weak?

Generic, templated reasoning that does not engage the specific facts, or a closure that leaves some flagged elements unaddressed. These read as decisions made without real analysis behind them.

Is a no-action disposition a problem?

Not at all, as long as it is supported. Most alerts legitimately close with no action. What matters is that the reasoning is specific and documented, so the close is defensible if it is later reviewed.

What does inconsistency across a team indicate?

Usually a weakness in procedures or training rather than bad analysts. If similar activity gets very different calls, the guidance is unclear, and similar customers are being treated unequally.

Go deeper

O que saber junto com Disposition