Schedule icon
Webhook icon
Script icon
Process icon
Query icon
If icon
SlackIncomingWebhook icon
Log icon

Automate AML transaction monitoring and velocity alerts using DuckDB

Use Kestra and DuckDB to calculate rolling transaction velocity, flag smurfing attacks, and alert compliance teams without moving sensitive data.

Categories
BusinessData

Automating Anti-Money Laundering (AML) transaction monitoring prevents regulatory fines by flagging high-risk user behavior, such as structuring, smurfing, and velocity spikes, before the next reporting cycle.

This blueprint ingests a batch of transaction data and utilizes an in-memory DuckDB query to compute rolling volume and velocity metrics. If any account breaches the dynamically calculated risk threshold, the pipeline automatically halts and routes the anomaly context directly to the compliance team's Slack channel for human triage.

How it works

  1. fetch_transaction_batch generates mock transaction data (or fetches an upstream settlement batch), simulating recent payment and transfer events.
  2. calculate_velocity_risk uses Kestra's embedded DuckDB task to calculate sliding window velocity and risk scoring, returning accounts that breach the severity_threshold input.
  3. triage_gate evaluates the flagged results and routes a detailed escalation directly to Slack if anomalies are detected, otherwise logging a clean batch.

What you get

  • A fully local, zero-dependency AML risk assessment pipeline.
  • Automated Slack escalations containing the top suspect's ID, transaction volume, and calculated risk score.
  • A clean audit trail of daily batch processing logs for compliance reporting.

Who it's for

  • Data Engineers and FinTech Ops teams responsible for regulatory compliance.
  • Security teams tracking anomalous behavior or account takeovers.

Why orchestrate this with Kestra

Batch processing financial transactions requires rock-solid reliability. By orchestrating this in Kestra, you replace fragile cron jobs with a declarative pipeline that guarantees execution, handles upstream data dependencies, and alerts your team instantly if the pipeline fails or if high-risk activity is detected. Since DuckDB runs embedded, sensitive transaction data never leaves your infrastructure.

Prerequisites

  • A Slack workspace with an incoming webhook configured.

Secrets

  • SLACK_WEBHOOK_URL: Slack incoming webhook URL for compliance alerts.
  • WEBHOOK_KEY: Authentication key for event-driven trigger execution.

Quick start

  1. Configure the SLACK_WEBHOOK_URL and WEBHOOK_KEY secrets in your Kestra namespace.
  2. Execute the flow to run the mock transaction generator.
  3. Review the Slack alert generated by the injected "smurfing" anomaly.
  4. Replace the Python data generator with your own database query or file ingestion task.

How to extend

  • Connect io.kestra.plugin.jdbc.postgresql.Query to pull live transactions directly from your primary database instead of generating CSVs.
  • Add a Loop task (io.kestra.plugin.core.flow.Loop) to process transactions regionally and route alerts to different Slack channels based on the user's jurisdiction.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.