There is a particular silence in a monitoring operations room at 4:55 on a Friday afternoon. The dashboards are still refreshing. The queue counter ticks up by eleven while you watch it. Nobody says the number out loud anymore, because saying it out loud makes it real, and the number has been real for months.
Every analyst in the room knows the arithmetic. The team closes maybe 900 alerts a week on a good week. The systems generate 1,400. The difference does not go anywhere. It sits. It ages. It compounds quietly, like interest on a debt nobody signed for.
This is how backlogs work. They are never a crisis on any single day. They are a crisis assembled from four hundred ordinary days.
Eighteen thousand to one hundred sixty-nine thousand
In April 2025, the New York Department of Financial Services fined Block Inc. $40 million. Buried in the consent order was a detail that every monitoring leader should have laminated and taped to their desk: the company’s transaction alert backlog had grown from roughly 18,000 alerts to more than 169,000.
Read that trajectory slowly. Nobody wakes up with 169,000 unworked alerts. You wake up with 18,000 and a plan. Then hiring slips a quarter. Then a new product launches and the scenarios triple. Then the tuning project gets deferred because the team is too busy working alerts to fix the thing generating the alerts the compliance equivalent of being too busy bailing to patch the hull. Each decision is defensible in isolation. Together they build a nine-fold increase, and a nine-fold increase is no longer an operations metric. It is evidence.
That is the part institutions consistently misjudge. A regulator does not see a backlog as a workload problem. A regulator sees 169,000 moments where suspicious activity might have gone unreported, each one an initial-detection determination the program never got to make the determination that starts the 30-day SAR clock in 31 CFR 1020.320 each one a small documented failure of the program to do the only thing it exists to do. The backlog is not adjacent to the violation. The backlog is the violation, counted.
A backlog is not a pile of work. It is a pile of undetected risk, sorted by how long you have ignored it.
Why “oldest first” is the worst instruction ever given
When the number finally becomes undeniable usually when an examiner asks for the aging report and someone has to build it for the first time the instinctive response is a remediation sprint worked oldest-first. Clear the 2024 alerts before the 2025 alerts. Show the regulator the aging curve bending down.
It feels rigorous. It is almost exactly backwards.
Alert age tells you when a detection scenario fired. It tells you nothing about whether the underlying activity was dangerous. A fourteen-month-old alert on a dormant account that triggered a threshold once and went quiet is not riskier than a three-day-old alert on an account cycling funds to a jurisdiction under a FinCEN advisory. Working oldest-first means your scarcest resource trained investigator attention is allocated by calendar rather than by threat. You are polishing the aging report while the live risk sits at the back of the queue, waiting its turn behind alerts that were never going anywhere.
We have watched teams spend months doing this. The aging chart improves beautifully. The SARs that mattered get filed late anyway.
The examiner’s second question, after “how big is the backlog,” is always some version of “how do you know the risky ones aren’t at the bottom?” If your answer is a first-in-first-out policy, you have just told them you don’t.
Triage: the emergency-room model
The teams that dig out genuinely dig out, not just flatten the curve for one exam cycle all end up building some version of the same thing: a risk-scored triage layer that sits above the queue and re-sorts it before a human touch anything.
The model is an emergency room, not a deli counter. Nobody in an ER is seen in arrival order. A triage nurse spends ninety seconds per patient and routes the chest pain ahead of the sprained ankle, however long the ankle has been waiting.
In monitoring terms, that means scoring every open alert against factors the original scenario never considered: the customer’s current risk rating, prior SAR history, counterparty exposure, whether the account is still active, and whether the pattern continued after the alert fired. Modern language-model tooling has made this dramatically more practical than it was even three years ago a well-governed model can read an alert, pull the customer context, and produce a draft disposition with cited evidence in seconds. Under human review, with sampled QA and full audit trails, that turns triage from a heroic manual project into a standing capability.
The output is tiers. Tier one gets an investigator today. Tier two gets one this week. Tier three and this is where programs need actual courage may not get a human at all.
Hibernation, and the courage to close
Tier three is the population everyone knows about and nobody discusses: alerts that fired on thresholds long since retuned, on customers who closed their accounts, on scenarios later found to be misconfigured. Working these one by one, with a full investigative write-up each, is how a backlog becomes a permanent institution with its own headcount and its own line in the budget.
The disciplined alternative is hibernation with tripwires: document a defensible, risk-based rationale for the population; close or suspend it in bulk; and set automated conditions that reopen any alert the moment its facts change the customer reactivates, a new alert fires on the same party, a negative-news hit lands. The rationale is written once, reviewed by QA, sampled by testing, and shown to the examiner as method rather than confessed as shortcut.
Regulators do not actually demand that every alert receive an identical ceremony. They demand that the program’s choices be risk-based, documented, and honest. A bank that says “we closed 22,000 low-risk alerts under this tested rationale, and here are the reopening triggers” is in a far stronger room than a bank that says “we are working through them in order and expect to finish next year.”
The metric that should replace age
Here is the discipline underneath all of it, the one sentence worth keeping if you keep nothing else: never let age become the risk metric.
The moment a program starts managing to “no alert older than 90 days,” it has substituted a proxy for the mission. Age is easy to measure, easy to chart, easy to promise. It is also strictly meaningless about harm. The dashboards that matter track risk-weighted disposition: what share of high-tier alerts reached an investigator within SLA, how fast the SAR clock is being met on the alerts that generate SARs, whether the intake rate and closure rate have actually converged or whether the queue is merely being drained into next quarter.
And the permanent fix is upstream anyway. A backlog is a symptom; the disease is a detection stack generating alerts faster than they can responsibly be judged. Sustained tuning threshold recalibration, scenario retirement, segmentation that reflects how customers actually behave is the only thing that closes the gap between 1,400 in and 900 out. Everything else is bailing.
The Friday-afternoon counter will always tick. The question is whether it ticks against a program that knows exactly which of those eleven new alerts matters, or one that will find out fourteen months from now, in a consent order, with the number printed for everyone to read.
How SG Analytics Helps
SG Analytics runs alert-review operations for banks, fintechs, and payment fintechs that need the queue brought back under control and kept there. Our teams combine experienced domain experts with production AI triage models that score, sort, and draft under documented human oversight which is how clients typically see false-positive volumes fall 40–60% while disposition quality holds up to independent QA.
Because we are vendor-neutral across the major monitoring platforms, the work starts from your stack, not a migration. Engagements range from backlog remediation surges to fully managed monitoring utilities, and everyone leaves behind the tuning, tiering, and hibernation governance that stops the queue from growing back.
