One platform from the first transaction to the filed goAML report — with AI that drafts, and humans who decide.
Regulators expect timely, accurate, explainable reports. The tooling most institutions run makes that harder, not easier.
Rules tuned once and never revisited produce mountains of false positives. Analysts triage noise instead of investigating risk.
Monitoring, screening, case management and filing live in separate systems. Data is re-keyed, evidence is lost, and nobody can reproduce a decision.
An STR is assembled by hand from several systems, validated only when the regulator rejects it, and a schema change means a rebuild.
Leaders want AI's speed, but cannot let it touch regulated decisions, leak customer data, or act without an audit trail.
"Who approved this, on what evidence, and can you reproduce it?" is answered from spreadsheets and memory.
Investment banks and brokers need market-abuse and securities-transfer surveillance on top of AML — usually a separate product.
Detect, investigate, decide, report and evidence — in a single system built around the people who answer to the regulator.
built-in detection scenarios, tenant-tunable
report types: STR · SAR · CTR
role-based work areas, default-deny access
paths for AI to execute a regulated decision
Every rule is versioned data with named, tenant-overridable parameters — not code. Change it, backtest it on your own history, then activate it with maker-checker.
Mapped to recognised typologies, each with a backtest fixture and coverage-map entry.
The Sentry Agent drafts; people act. AI has no write path to anything with regulatory consequence — by design, not by policy.
Subject, accounts, transactions and indicators are assembled from customer, account and transaction data — with a provenance map showing what came from where and what is missing.
Paste the FIU response; reasons are parsed; a correction is drafted as v2 with the original reference; a different MLRO approves; the original is superseded.
Versioned schema packs: a new regulator schema is installed, mapped and regression-checked — not re-engineered. Filed reports keep the schema they were built under.
On-track, due-soon and overdue per configured jurisdiction timetable; the clock restarts at an FIU rejection. Automatic daily CTR generation.
STR, CTR, declined-business and training registers; board packs; every view and download of an XML logged with its checksum.
Orders, trades and free-of-payment transfers are first-class events — so market-abuse and custody patterns sit beside AML typologies, not in another product.
Orders, executed trades, cancel rate, alerts by scenario, value by instrument and venue — from a dedicated analytics store.
| Group | Works in | Can | Cannot |
|---|---|---|---|
| Analyst / Senior Analyst | Alerts · Cases · Customer 360 · Screening · Rules | Investigate, build cases, request AI memos, propose dispositions and STRs, backtest rules | Approve their own work; see restricted STR data |
| MLRO / Deputy MLRO | Approvals · Reporting · KPIs | Confirm and file STR/SAR/CTR, record rejections, approve corrections, release batches | Approve their own corrections (a second MLRO must) |
| Risk Manager | Risk · EDD | Tune and score customer risk, run EDD | File reports |
| Administrator | Admin · Tenants · Ops console | Configure tenants, users, reference data, schema packs, jobs and health | File reports or approve regulated decisions |
| Auditor / Regulator | Audit trail · Sample reviews | Read everything they are entitled to; record review findings | Change anything — every action is disabled |
| Integration engineer | API · Mapping Studio | Connect and monitor source systems | Approve or file regulated reports |
Separation of duties is checked in the handlers, not only the screens: the preparer can never be the approver for STR corrections, rule activation, screening confirmations or CTR release.
TOTP and passkeys with step-up for sensitive actions; single sign-on ready. Default-deny authorisation on every page and endpoint.
Who, what, before and after — hash-chained so alteration is detectable, with database-level immutability for the application role.
Tenant id on every tenant-owned table with enforced query filters, covered by isolation tests; optional row-level security as defence in depth.
STR-linked cases, report XML and even reporting aggregates are visible only to the privileged policy; every export is watermarked and logged.
No PII in logs; PII pseudonymised before any AI call; retention policies with signed deletion certificates; signed webhooks and HMAC-verified ingestion.
Dashboards read purpose-built analytics stores fed by events, so heavy analysis never slows monitoring.
Outbox-published facts
Insert-only, idempotent
Columnstore, rebuildable
Role-gated, tenant-scoped
Modules talk only through contracts and events; architecture tests fail the build if a boundary is crossed.
.NET 10; IIS or container; rolling, additive-first migrations; documented DR runbook.
HMAC-signed APIs, ISO 20022, FIX, webhooks, field-scoped egress, signed embeds.
A structured, owner-by-owner plan with entry and exit criteria at every step. Indicative 10–16 weeks, dominated by data quality and tuning — not software.
Curricula for analysts, MLROs, administrators, auditors, integration engineers — plus a securities add-on — with hands-on labs.
Admin and analyst guides, API reference, goAML runbooks, UAT pack, schema-upgrade procedure, release & DR runbook.
Tiered support with severity-based response, a regulatory-change process, and a monthly release cadence.
Detection, investigation and the validated regulatory report live in one system with one audit trail — no re-keying between tools.
Useful drafts, cited evidence, full logging — and no technical path to a regulated decision. Compliance leaders can adopt it without arguing with their examiner.
Separation of duties enforced in code, hash-chained audit, reproducible risk scores and reproducible alerts. "Prove it" has an answer.
Regulator schema changes arrive as content packs with a compatibility harness — not as a rebuild — and filed history is never rewritten.
Banks, SACCOs, fintechs and investment houses on one engine, one data model and one governance model.
Thresholds, lists, queues, workflows and deadlines are tenant settings. Every feature is built to be sold to the next client without a code change.
A scoped proof of value: load a sample of your customers and transactions, tune three scenarios on your history, and walk an STR from alert to validated report with your MLRO in the room.
Sources, report types, jurisdiction.
Your data, your scenarios, your MLRO.
Timeline, owners, service model.