Find the risk.
Prove the decision.
Screening, transaction monitoring, customer risk rating, case management and SAR/STR reporting in one analyst workspace. A single codebase serves a tier-1 bank and a small intermediary alike — cloud or on-premise, at parity.
Not an AML problem so much as a fragmentation problem.
Risk scoring lives in one spreadsheet, sanctions screening in a separate tool, transaction alerts in a third system — and the evidence an examiner asks for is scattered across inboxes and shared drives. Point tools and manual process create more risk than they remove.
The cost is not only operational. An AML programme that cannot show its evidence on demand is hard to defend, regardless of how diligent the team actually is.
- Decisions cannot be reconstructed
When a regulator or auditor asks why a customer was rated low-risk, or why an alert was closed, the answer sits in someone's memory or a deleted email rather than an immutable log.
- Work is duplicated and inconsistent
The same customer is screened in one system, scored in another and investigated in a third, with no shared view of how those decisions connect.
- Spreadsheets do not scale or survive scrutiny
Manual scoring models and ad-hoc watchlists drift out of date, lack version history, and offer no four-eyes control over the overrides that matter most.
What changes when the programme runs on one record.
Screening, risk rating, monitoring, cases and reporting share one entity context — so the evidence is there when the question comes.
The data, the rule, the score and the reasoning sit one click away, in an append-only audit log.
Multi-script, locale-aware matching, a structured false-positive workflow and entity resolution take the look-alikes out of the queue.
Case, EDD and the SAR/STR lifecycle live in the same workspace, handing off to goAML for the filing itself.
Modules are licensed by tier and switched on per tenant — screening and risk rating first, monitoring and AI when you are ready.
Every surface, one entity context.
From a customer's first screen to a filed report, every action lives in the same workspace — no swivel-chairing between tools. Click through the real surfaces an analyst and MLRO use every day.
| Match | Query | Confidence | Top reason |
|---|---|---|---|
| a91f3c… | Fatima Al-Mansouri | 0.924 | PEP list exposure |
| c20b7e… | João da Silva | 0.871 | Sanctions partial |
| e4d109… | Apex Holdings Ltd | 0.642 | Adverse media |
| 7b8a52… | Chen Xiaoming | 0.588 | Name-only match |
| 1f60aa… | Wei Logistics | 0.512 | High-risk geography |
Eleven modules, license-gated by tier.
Turn on only what a tenant is licensed for — the rest stays hidden.Provider sync (Dow Jones, World-Check), manual upload, versioning and freshness dashboards — so screening always runs against current lists, and you can prove it.
Multi-script, locale-aware matching across sanctions, PEP and adverse media, with a false-positive workflow — so analysts spend their time on genuine matches, not look-alikes.
Six-factor CRA across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides — so every rating has a reviewable history.
Rule DSL with batch and streaming, a back-test harness, tuning lab and versioned promotion — so a rule change is tested and traceable before it fires in production.
Queues, RFI cycle, SLA pause/resume, linked-case graph and enhanced due diligence — so no alert ages out unowned, and connected cases are seen together.
Draft-to-submit lifecycle with FRC Kenya direct, goAML universal and manual-download fallback — so a report can still go out when a portal is down.
Resolved entities, links, clusters and a beneficial-owner graph wired into the case workbench — so an analyst sees who is really behind a customer without leaving the case.
REST, SFTP, Kafka, CDC and ISO 20022 connectors with idempotency, replay and a dead-letter queue — so a failed overnight feed never becomes a silent monitoring gap.
ONNX runtime and a first-party model registry, four-eyes activation, a kill switch and SHAP top-3 reasons — so every AI score can be explained to an examiner, and switched off in one click.
A read-only, OIDC-federated build for supervisors with evidence packs and acknowledgements — so an examination runs on shared evidence rather than email attachments.
Obligation registry, change-notice ingest and per-tenant acknowledgement tracking — so a new circular becomes a tracked task, not a surprise at the next inspection.
Every AI score comes with its reasons — and a human decides.
Models run in-process on an ONNX runtime with a first-party registry. Activation needs four eyes, a kill switch is one click away, and every inference is logged with model version and an inputs hash.
Built once. Deployed anywhere, for any sector.
The same binary serves a global bank with a regulator on-premise and a small intermediary in the cloud. The difference is configuration and licence — not code.
Dual-backend abstractions mean every feature works identically on Azure and on your own Kubernetes — same code, validated to parity.
Modules switch on by tier. Endpoints check the licence; anything unlicensed is hidden.
For every institution that has to run an AML programme and stand behind it.
Built for the reporting entities of the region — under the FRC in Kenya, the FIA in Uganda, the FIU in Tanzania and the FIC in Zambia and Rwanda — against the wider FATF and ESAAMLG framework.
Deposit-takers and insurers carrying the full screening, monitoring and reporting obligation.
High-volume, real-time flows that need streaming monitoring and fast, multi-script screening.
Smaller compliance teams that start with screening, risk rating and case basics and switch on more later.
Designated non-financial businesses and professions brought into the AML/CTF net by their regulators.
Frequently asked questions.
Is this a full AML programme or only a reporting tool?
It is the full programme — customer risk assessment, screening, transaction monitoring, case management, entity resolution and more. STR/CTR reporting is one capability within it, and the actual goAML filing is handed off to the dedicated Creodata goAML Reporting Platform.
Can we run it entirely on-premises?
Yes. The platform deploys to on-premises Kubernetes — using Postgres 16, RabbitMQ, MinIO, OpenSearch and Keycloak — with the same features as the Azure Managed Application deployment. Dual-backend abstractions keep the two environments identical.
Do we have to adopt every capability at once?
No. Each capability is an independent, separately licensed service. Per-tenant module gating lets you start with what you need and switch on additional services over time.
How does the platform handle AI decisions for audit?
Every AI surface shows its model and version label, SHAP top-three explanations and a confidence percentage, and requires a human Accept, Modify or Reject. Decisions are logged with the model version, an inputs hash and the SHAP output, and models can only be activated under four-eyes approval, with a kill switch and rollback available.
From alert to filed SAR/STR, without leaving the workspace.
See the AML platform run on a realistic alert queue, tuned to your sector pack, in a live demo.
More on AML Platform
Adverse Media Screening: Catching the Risk Sanctions Lists Miss
Sanctions and PEP lists only show known, designated risk. Adverse media screening surfaces the rest — how negative-news screening works, how to filter for relevance and recency, and where it fits in onboarding, EDD and periodic review.
Audit-Ready AML: Evidence-First Investigations and the Four-Eyes Principle
When an examiner asks you to walk through a single decision, can you? How an append-only audit trail, evidence-first design and the four-eyes principle make every AML decision reconstructable — and inspections far less painful.
AML Case Management: From Alert to Disposition Without Losing the Audit Trail
A walk through the AML case lifecycle — queue assignment, the RFI cycle, SLA management, linked-case investigation, EDD, escalation, and the decision to file or close — built so every step leaves an audit trail.