The CAIBots KYC/AML Agentic AI platform is a continuously running compliance intelligence layer that operates across three simultaneous time horizons: new customer onboarding (CDD/EDD), perpetual KYC monitoring, and real-time transaction screening. Seven specialized AI sub-agents run in parallel against five peer data source tools. Agent pipeline runtime: <10 seconds end-to-end.
Capability
Status
Implementation Notes
Retail / Commercial / Institutional CDD/EDD
Covered
All three DD levels. Correct regulatory routing. 25%/10% UBO thresholds enforced. FinCEN CDD Rule 31 C.F.R. §1010.230 compliant. Automatic tier assignment — SDD (<30), CDD (30–65), EDD (>65 or any PEP/sanction adjacency).
Perpetual KYC — Event-Driven Monitoring
Covered
Score drift >15pts triggers automated refresh with no analyst request. Replaces calendar-based periodic review entirely. 60–70% pKYC workload reduction vs. traditional scheduled review programs.
52-Pattern Typology Transaction Monitoring (FATF/FinCEN-curated)
Covered
All 52 curated patterns: structuring, layering, TBML, bulk cash, MSB patterns, hawala (core). Connector architecture for Actimize/Verafin (institution-licensed, bidirectional by design). For structuring: calculates total avoided CTR reporting amount and maps full counterparty network.
OFAC / EU / UN / HMT Sanctions Screening
Covered
Real-time — not batch. Fuzzy name matching handles transliteration variants and name permutations. 2-hop PEP proximity screening. SDN cache TTL 1 hour — system never relies on stale list data for more than 60 minutes. Immediate blocking on any SDN hit.
SAR / CTR Filing Automation
Covered
Mandatory HITL approval gates all filings. Direct FinCEN BSA E-Filing post-approval. Agent never auto-files. BSA Officer is always the filer of record. 30-day SAR clock tracked with T-14 and T-7 escalation alerts. CTR auto-populated on qualifying cash events within 15 calendar days. OFAC blocking report filed within 10 business days of confirmed SDN hit.
FinCEN 314(a) / 314(b)
Covered
14-day window tracking. See Scenario 07 — live 314(a) batch match with BOI non-compliance (foreign reporting company — 2025 rule scope) and circular UBO detection. Automated search executed on every 314(a) batch receipt. 5-year lookback applied automatically. HITL gate for BSA Officer response decision. 314(b) voluntary sharing referral generated when Knowledge Graph identifies cross-institution patterns. See Scenario 09 — registration-first 314(b) response workflow with SAR-status disclosure structurally excluded.
Beneficial Ownership & CTA BOI (2025 rule scope)
Covered
Full UBO traversal to natural persons. Shell company, circular ownership, and nominee structure detection. FinCEN BOI cross-reference via the institution’s authorized access, where in scope (2025 interim final rule: foreign reporting companies registered in the U.S.). CDD-Rule beneficial-ownership certification discrepancy flags triggered automatically when certified BOI diverges from detected ownership.
Correspondent Banking Risk
Covered
See Scenario 06 — live correspondent banking EDD with FFIEC Chapter 13. SWIFT path risk assessment, nested correspondent chain analysis, HIFCA designation checking, de-risking workflow with advisory HITL for significant relationships. See Scenario 10 — De-Risking Committee: three signatures with rationale, individualized fair-access basis, confidentiality-safe exit letter. Multi-hop correspondent risk propagated through Knowledge Graph.
TM Alert Disposition (False Positives)
Covered
Scenario 11: alert investigated, structuring hypothesis tested and REJECTED with counter-evidence; close-with-evidence memo (5 pillars) → KYC Analyst concurrence; rule-tuning queued under SR 11-7 governance — never auto-applied. Answers the industry’s highest-volume pain: 90%+ of TM alerts are false positives.
Sanctions Near-Match Resolution
Covered
Scenario 12: strong-identifier match analysis (DOB, POB/nationality, documentation, aliases) reaches a documented NOT-the-listed-person determination; hold enforced until Sanctions Officer + BSA 4-eyes authorization; list-delta re-screen trigger set. Paired with Scenario 07’s true-match block: the system that proves a block proves a release.
Derived Risk Scoring (Engine of Record)
Covered
KYCRISK v1.0: score = round(Σ weight × dimension), weights published (geo .20 · product .15 · customer .25 · behavioral .25 · network .15); bands from policy thresholds (policy of record KYC-2026.07 #d3083beb84); every score computed at boot, never typed; audit line [risk@1.0] on every run.
Client-Side Session Verification
Covered
⛨ Verifier recomputes the full hash chain (SHA-256(prev | seq | ts | actor | msg)), reproduces all eleven risk derivations from published weights, and re-runs the SAR grounding check on the sealed narrative — in the reviewer’s browser, no server trust required.
Policy Threshold Sandbox
Covered
⚖ Live re-banding of all eleven scenarios against explorable SDD/EDD/SAR thresholds; statutory-class controls (sar_dual_review · ofac_dual_review · committee outcomes) display LOCKED with their dual-role matrices; exploration never persists; SR 11-7 change-management path stated.
Case Binder Export
Covered
⬇ One JSON export: policy-rules snapshot, engine block (weights + formula), per-scenario derivations, session grounding record, hash-chained ledger, and a written reconstruction procedure an examiner can follow offline.
PEP Screening & Adverse Media NLP
Covered
Dow Jones, Refinitiv World-Check, LexisNexis. 300+ monitored sources. 0–100 adverse media score with network propagation — UBO adverse media contaminates related-party network risk scores.
SR 11-7 Model Governance Framework
Covered
Back-testing (Gini >0.65 target), material change taxonomy with 7 defined change types, independent validation requirement framework. Full MRM documentation package included with every production deployment.
GDPR & Data Residency Architecture
Covered
PII boundary design — no PII in LLM prompts. DPIA template provided. EU regional deployment available (Pinecone Frankfurt, Neo4j AuraDB EU). Anthropic EU DPA with Standard Contractual Clauses available.
BSA Lookback Review Automation
Phase 2
Consent order lookback requires a distinct retroactive pipeline with different trigger logic and historical data traversal. Architecturally designed — not yet built. Estimated 8–12 weeks to production.
Real-Time Payments (FedNow / RTP)
Phase 2
Sub-100ms latency screening not yet architected. Agent-only pipeline: <10 seconds. Full CDD case (including HITL): <90 seconds end-to-end. Real-time payment rail screening requires dedicated low-latency inference path. Estimated 10–14 week build.
Capital Markets Surveillance
Out of Scope
Layering, spoofing, wash trading, MiFID II MAR — market abuse monitoring is a separate product domain from BSA/AML. Extension path available: 12–16 weeks as a parallel development track.