Quiet rules are still a finding
A rule that never fires can look harmless. In a transaction monitoring audit it is often the opposite: a stated control that no longer matches the corridors you serve.
We ask three questions. Was the rule designed for a product you still offer? Did thresholds drift so far that nothing qualifies? Is ownership missing so nobody notices either way?
Fintech teams in Hong Kong often inherit rule packs from earlier product launches. Audits that only count open alerts miss the silent gaps. Sampling dormant rules against current risk narratives is a small step that prevents larger surprises later.