Skip to content

10 — Controls in the path

KYC, AML, sanctions and reporting engineered into the transaction path with a hash-chained audit trail.

Compliance functions drown in false positives because screening is tuned for defensibility rather than accuracy, and every alert costs an analyst regardless of quality. The result is a queue that grows faster than the team and a supervisor who sees backlog rather than control.

We rebuild screening, case management and reporting as one system: risk-based thresholds, entity resolution that reduces duplicate alerts, case tooling that captures the reasoning, and an append-only audit trail that makes the control evidenceable rather than merely present.

Common questions

How do you reduce false positives in sanctions screening?

Entity resolution first — most duplicate alerts are the same underlying party seen through different data. Then risk-based thresholds by corridor, customer segment and value rather than one global setting, and continuous measurement of alert-to-escalation rates so tuning is evidenced rather than argued.

What is a hash-chained audit trail and why does it matter?

An append-only log where each entry includes the hash of the previous one, so any retrospective alteration breaks the chain and is detectable. It matters because compliance evidence is only worth what its integrity is worth: a mutable log proves that a record exists now, not that it existed then.

Should compliance checks run before or after a transaction?

Before, wherever the control is preventive. Screening that runs after settlement produces a report, not a control. The engineering requirement is that the check is fast enough to sit in the path and fails closed — if the screening service is unavailable, the transaction does not proceed.

Next capability

Payment infrastructure

Bring us the hard part.

Forty-five minutes with the people who would actually run the build.