SardineCon SF/2026

Learn More

O que é Threshold?

SUBSCRIBE

A threshold is a configured value, such as an amount, a count, or a velocity limit, that triggers an alert or a reporting duty once activity crosses it. Where you set it decides the central trade-off in monitoring: catch more risk, or generate fewer false positives.

What is a threshold, in plain English?

A threshold is the tripwire in a monitoring rule. It is a set value that, once crossed, makes something happen: an alert fires, a case opens, or a mandatory report becomes due. The value can be an amount, such as a wire over a certain size, a count, such as more than a set number of transfers in a week, or a velocity, such as too much money moving too fast.

Thresholds live inside scenarios and rules. A scenario describes the behavior to watch; the threshold decides the exact point at which that behavior becomes worth flagging. Some thresholds are set by regulation, like currency reporting limits, and some are set by the firm based on its own risk appetite and data.

The reason thresholds are so consequential is that they set the central trade-off in monitoring. Set them to catch more risk and you generate more alerts and more analyst work. Set them to reduce noise and you risk missing genuine activity. Every threshold is a deliberate choice about where that balance sits.

The trade-off a threshold sets

Move a threshold up or down and two things change in opposite directions:

What changes

Threshold set too high

Threshold set too low

Coverage

Misses genuine risk that sits below the line.

Catches more, including borderline activity.

Alert volume

Fewer alerts, quieter queues.

Floods analysts with noise and false positives.

Main risk

Missed suspicious activity and exam findings.

Burnout, backlogs, and slow investigations.

How to defend it

Below the line testing to prove you catch enough.

Above the line testing to prove alerts are productive.

What it looks like in practice

In practice

A firm sets a scenario to alert on cash deposits over 10,000 dollars. Analysts notice a customer making repeated deposits of 9,500 dollars, always just below the line, several times a week. Individually each deposit stays under the threshold, so nothing fires.

The team recognizes this as structuring: the customer has clearly guessed the threshold and is deliberately sitting beneath it. They add an aggregation scenario that sums deposits over a rolling period and a separate rule for amounts clustered just below reporting limits. The lesson lands hard: a threshold everyone can guess is a threshold that gets gamed.

Why thresholds matter to operators

Thresholds shape both how much risk you catch and how much work lands on your team, which makes them one of the most scrutinized settings in a program. Set too high and examiners will ask what you missed; set too low and analysts drown in false positives while real cases wait. Every threshold needs a data backed justification, not a round number chosen for comfort.

They also face an active adversary. Criminals probe thresholds and structure activity to sit just beneath reporting levels, so thresholds cannot be static or predictable. That is why firms pair thresholds with aggregation rules, revisit them through tuning, and avoid relying on any single obvious line.

What to watch with thresholds

  • Just-below clustering. Amounts repeatedly landing just under a threshold suggest deliberate structuring, not coincidence.
  • Round number thresholds. Values chosen for tidiness rather than data are hard to defend and easy to game.
  • No aggregation. Per transaction thresholds with no rolling sum let many small transfers slip past a large single limit.
  • Stale settings. A threshold that fit last year's customer base may now miss risk or generate pure noise.
  • Missing justification. Any threshold you cannot back with data or regulation is an exam finding waiting to surface.

Quick questions

Who sets a threshold?

Some are set by law, such as currency transaction reporting limits, and cannot be changed. Others are set by the firm's financial crime team based on its risk appetite, customer base, and data, then reviewed through tuning.

Why not just set thresholds very low to catch everything?

Because very low thresholds bury analysts in false positives, slowing investigations and letting real cases sit in backlog. Catching everything in theory can mean catching nothing in practice, so coverage has to be balanced against capacity.

How do criminals game thresholds?

Mainly through structuring: breaking a large transaction into several smaller ones that each stay under a reporting or alerting limit. This is why firms add aggregation rules and watch for clustering just below the line.

How is a threshold different from a scenario?

A scenario defines the behavior to detect, such as rapid movement of funds. The threshold is the specific value inside that scenario that decides when the behavior is flagged. One scenario can contain several thresholds.

How often should thresholds change?

There is no fixed schedule, but they should be reviewed regularly through tuning and whenever your risk, products, or customer behavior shift. Static thresholds decay and eventually either miss risk or generate noise.

What is above and below the line testing?

It is how you justify a threshold. Above the line testing checks that the alerts you do get are productive; below the line testing samples activity just under the threshold to confirm you are not missing genuine risk.

Go deeper

O que saber junto com Threshold