A transaction monitoring alert marks a pattern your controls flagged. Ongoing monitoring is part of due diligence under MLR 2017 reg 28, which asks a firm to scrutinise transactions across a relationship. Reg 33 pushes a complex or unusually large transaction into enhanced due diligence. anonym.plus removes the customer's name, account, and amounts from an export on your device.
When this applies
A model team studies past hits to cut false positives. Tuning a rule set on live customer records is profiling, and UK GDPR Art. 22 governs decisions taken that way. The signal sits in the rule ID and the pattern, not the customer. So the tuning set is cleaned before it leaves the AML team.
How anonym.plus handles it
- Open the export in anonym.plus on your device.
- The tool flags the name, account, and amounts.
- Local OCR reads a scanned printout if attached.
- Keep the rule ID and trigger logic.
- Swap each identifier for a label.
- Save the clean copy locally.
What you need to provide
- The export (CSV-to-PDF, DOCX, or scan).
- An operator (Replace keeps the pattern readable).
- Optional batch for a folder of past hits.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Omar Reyes → [CUSTOMER] |
| Financial | UK_BANK_NUMBER | acct 7782 → [ACCOUNT] |
| Money | MONEY | £9,900 x4 → [AMOUNT] |
| Identifiers | UK_NINO | QQ 20 46 71 C → [NINO] |
| Dates | DATE_TIME | burst 03/2026 → [DATE] |
| Contact | PHONE_NUMBER | +44 117 555 9081 → [PHONE] |
Compliance achieved
- Backs the ongoing-monitoring duty that MLR 2017 reg 28 builds into due diligence.
- MLR 2017 reg 33 sends a complex or unusually large transaction to enhanced due diligence.
- Tuning on customer records is profiling, so UK GDPR Art. 22 and Art. 5(1)(d) both bear on it.
- Once an alert hardens into suspicion, POCA 2002 s.330 takes over and the raw record stays whole.
- Batch up to 20 exports in one local pass.
Anonymise monitoring alerts offline — see plans & start free →
Limitations & cautions
Your controls must retain the raw records for supervisory review. Clean only copies used to tune models or train staff. A rare amount-and-date pattern can still hint at one account, so review what stays.
Frequently asked questions
Can I redact the record my controls keep?
No. Keep the raw evidence for review. Reg 28 monitoring is judged on what the firm actually saw, so clean a copy for tuning or training instead.
Will the rule logic survive?
Yes. Allow-list the rule ID and trigger fields, so the signal stays while customer data is removed.
Why does UK GDPR Art. 22 matter here?
Art. 22 governs decisions taken by automated means with legal or similarly significant effects. An alert that can freeze an account sits close to that line, so a cleaned tuning set is the safer input.