AML Alert Investigation & SAR Narrative Engine
A done-for-you managed service that takes a financial institution's raw transaction-monitoring alerts and returns examiner-ready, fully documented dispositions — cleared/no-SAR investigation files or filing-ready SAR narratives — so the institution's own designated BSA Officer simply reviews and signs. An internal AI production engine does intake, enrichment, adverse-media scanning, pattern analysis, and first-draft narratives at near-zero marginal cost; certified financial-crime investigators own the judgment chokepoints. The institution stays the accountable filer; we are its outsourced investigations unit, not a co-pilot it has to operate.
1Thesis
Every U.S. financial institution is legally required to monitor transactions, investigate every alert, and file a Suspicious Activity Report (SAR) when warranted. The work is enormous and mostly waste: roughly 90–95% of transaction-monitoring alerts are false positives Verified, yet each one still needs a documented, defensible investigation. The country generated about 4.7 million SARs in FY2024, averaging ~12,870 filings every day Verified. Financial-crime compliance cost U.S. and Canadian institutions roughly $61 billion in 2024, with labor as the dominant driver and 99% of firms reporting rising costs Verified.
We sell the outcome, not the software: an alert that arrives as noise leaves as a closed, examiner-defensible case file with a clear disposition and an audit trail — and, where activity is reportable, a complete SAR narrative ready for the BSA Officer's signature. The institution's analysts and managers stop drowning in queue; their licensed BSA Officer keeps every filing decision and signature. Our internal AI engine does the 80% that is extraction, enrichment, scoring, and drafting; our certified investigators do the 20% that is judgment and escalation.
This is not a co-pilot. Software vendors (Unit21, Hawk, SymphonyAI, Lucinity) sell platforms the institution's own staff must operate, and pure-offshore BPOs sell undifferentiated analyst hours that never lower the alert burden. We occupy the gap a thinner version of which AML RightSource already proved is real — a technology-led managed investigations service accountable for examiner-ready output — but rebuilt AI-native so that each frontier-model improvement raises our margin instead of eroding our price.
2Discovery rationale
This run scanned banking/fintech compliance, KYC/AML, fraud operations, insurance operations, legal document production, and government paperwork. Within banking and fintech, AML alert investigation and SAR production stood out on four independent, Verified signals: (1) a legally mandatory, high-volume, document-heavy workload — 4.7M SARs/year and tens of millions of underlying alerts; (2) a structural waste problem — 90–95% false positives — that is precisely the kind of high-volume triage AI is now good at; (3) a severe and worsening labor constraint — 77% of institutions cite staffing as a top AML challenge, with some of the highest turnover in financial services Verified; and (4) brutal enforcement stakes, including FinCEN's record $1.3B penalty against TD Bank in October 2024 and 36+ BSA/AML actions in 2024 alone Verified.
It beat the other finalists because it is the rare market where the work is mandatory by law (not discretionary spend), recurring at huge unit volume (not annual or episodic), and already commonly outsourced — AML RightSource alone runs 3,000+ analysts as a managed service Verified. The decisive insight: the incumbents' cost structure is human-hours-per-alert, so an AI-native engine that collapses the cost of the false-positive 90% wins on both margin and turnaround without asking the buyer to change who signs the SAR.
It is distinct from every prior blueprint in this portfolio. Prior runs covered healthcare claims/auth/enrollment, multiple tax niches, trade/customs, ESG disclosure, and immigration. None touched financial-crime operations, the BSA/AML regulatory regime, a BSA-Officer buyer, alert/SAR unit economics, or FinCEN as the governing authority.
3Candidate comparison
Five candidates generated this run; the top three were deep-validated. Scores are 1–5 composite across the 15-factor rubric in Step 5.
| Candidate | Buyer | Outcome sold | Score | Evidence | Verdict |
|---|---|---|---|---|---|
| AML Alert Investigation & SAR Narrative Engine | BSA Officer / Head of Financial Crime (fintechs, MSBs, community banks & CUs) | Cleared, examiner-ready alert dispositions + filing-ready SAR narratives | 4.6 | Strong / mostly Verified | SELECTED — mandatory, high-volume, already-outsourced, AI attacks the 90% waste |
| Unemployment Insurance (UI) claims management | HR / Finance at mid-market employers | Protested improper claims + reduced UI tax rate | 3.7 | Moderate | Rejected — lower intelligence threshold, hearing/labor component, entrenched incumbents (Equifax, Thomas & Co.), thinner margins |
| Medicare cost report (CMS-2552-10) prep | Hospital CFO / reimbursement director | Filed cost report maximizing reimbursement | 3.6 | Moderate | Rejected — concentrated, slow buyer; annual cadence = low unit volume per client; harder to scale nonlinearly |
| Mechanic's-lien & construction payment-notice filing | Subcontractor / GC credit managers | Preserved lien rights via timely statutory filings | 3.4 | Moderate | Rejected — borderline UPL on lien filing; Levelset/Procore dominate; low price point |
| ACA 1095-C reporting + IRS Letter 226-J penalty defense | HR / benefits leaders at large employers (ALEs) | Filed ACA returns + abated ESRP penalties | 3.5 | Moderate | Rejected — seasonal; penalty defense is lumpy/contingent; adjacent to prior HR/tax themes; weaker recurring volume |
Adjacency note: this is financial-crime operations, not KYC onboarding or sanctions-list screening. It is distinct from any document-prep or recovery business in the portfolio because the unit of work is a regulator-mandated investigation with a signature chokepoint, not a filing, refund, or dispute.
4Hard disqualifier check
| # | Disqualifier | Status | Reasoning |
|---|---|---|---|
| 1 | Customer-facing co-pilot / SaaS rather than done-for-you | Pass | We deliver finished dispositions and SAR narratives; the buyer reviews and signs, does not operate our system. |
| 2 | Requires physical labor / field crews / equipment | Pass | Fully digital: documents, transaction data, public records, narratives. No site visits. |
| 3 | Pricing depends on hourly billing / cost-plus staffing | Pass | Priced per alert disposition and per SAR narrative, plus a fixed monthly platform retainer. |
| 4 | Cannot plausibly reach 50%+ gross margin | Pass | The dominant cost (analyst hours on the false-positive 90%) is exactly what the AI engine collapses; margin expands as automation rises. |
| 5 | Buyer cannot be identified clearly | Pass | The BSA Officer / Head of Financial Crime is a named, legally required role at every regulated institution. |
| 6 | Workflow cannot be decomposed into repeatable steps | Pass | Alert → enrichment → analysis → disposition → (SAR draft) → QA is a well-defined, documented pipeline. |
| 7 | Fully automates regulated judgment without licensed/expert review | Pass | By design: certified investigators handle judgment; the institution's BSA Officer makes and signs every SAR-filing decision. Accountability stays with the filer. |
| 8 | Substantially duplicative of a prior blueprint | Pass | No prior run touched financial crime, BSA/AML, FinCEN, or alert/SAR economics. |
| 9 | Likely illegal / un-incorporable licensing | Unclear→Mitigated | Managed AML services are established and lawful (e.g., AML RightSource), but regulators are explicit that accountability cannot be outsourced. Mitigation: structure as work-product + recommendation; the institution's BSA Officer decides and files. See §21. |
| 10 | Core demand claim unverified / not inferable | Pass | Demand is anchored in verified mandatory volumes, costs, staffing pain, and an existing managed-services market. |
| 11 | Frontier models more likely to commoditize than strengthen | Pass | Models attack our largest cost line. Moat is the regulated workflow, examiner-tested QA, audit trails, and institution-specific tuning — not the model. |
| 12 | Cannot be tested with a small bounded pilot | Pass | A single mid-size fintech queue (a few hundred alerts/month) is a complete, instrumented pilot. |
No disqualifier fails outright. Item 9 is the principal regulatory constraint and is engineered into the operating model rather than waved away.
5Rubric scorecard
Extended factors (1–5): outcome-pricing potential 4.5; gross-margin potential 4.5; buyer urgency 4.7; competitive whitespace 3.8 (managed AML exists but is not AI-native); novelty vs. prior outputs 5.0; fit with current AI capability 4.4; evidence quality 4.5; distribution feasibility 3.8 (long trust-sale cycle); compliance feasibility 4.0. Composite 4.6.
6Opportunity
The serviceable wedge is not the entire $61B; it is the investigations layer — the human hours spent triaging alerts and writing SARs — concentrated at institutions that cannot afford a 3,000-analyst incumbent: fintechs and their sponsor banks, money services businesses (MSBs), crypto/virtual-asset platforms, and community banks and credit unions. These are exactly the segments named in recent enforcement (Evolve Bank & Trust, Paxful, broker-dealers) and exactly the ones with thin internal teams and surging alert volume.
7Evidence quality & source-claim matrix
| Claim | Label | Source / basis | Conf. | Business impact |
|---|---|---|---|---|
| 90–95% of AML transaction-monitoring alerts are false positives | Verified | FluxForce TM false-positive data; corroborated by NICE Actimize, Tookitaki | High | Defines the automatable waste the engine collapses; core to margin thesis |
| ~4.7M SARs filed in FY2024; ~12,870/day | Verified | FinCEN SAR Stats; Thomson Reuters Institute 2024 SAR report | High | Confirms mandatory, high-volume unit of work |
| U.S./Canada financial-crime compliance cost ~$61B (2024); 99% report rising cost | Verified | LexisNexis Risk Solutions True Cost of Financial Crime Compliance | High | Sizes the spend pool and proves cost pressure |
| ~$25–$50 cost per alert investigated | Inferred | FluxForce industry figure; consistent with loaded analyst pay ÷ throughput | Med | Anchors per-unit pricing and savings narrative |
| FinCEN's $1.3B TD Bank penalty (Oct 2024); 36+ BSA/AML actions in 2024 | Verified | Holland & Knight; Gibson Dunn 2025 year-end AML review; K&L Gates | High | Establishes severe willingness-to-pay driver (fear of enforcement) |
| Fintech/crypto enforcement: Paxful $3.5M (Dec 2025), broker-dealer $80M (Mar 2026), Evolve Fed action (2024) | Verified | Akin; Holland & Knight; Wolf & Co. | High | Validates the specific target segments and their acute pain |
| 77% of institutions cite staffing as a top AML challenge; highest-turnover function | Verified | Quantexa AML talent market; Hawk AI Top-10 AML challenges | High | The labor constraint we relieve; supports outsourcing demand |
| AML/KYC analyst pay ~$58k–$105k (role-dependent) | Verified | Salary.com; ZipRecruiter; Glassdoor 2025–26 | High | Sets the COGS benchmark our automation must beat |
| Managed AML services are established (AML RightSource: 3,000+ analysts) | Verified | AML RightSource site | High | Proves low trust burden — buyers already outsource this work |
| TM services revenue growing ~18.4% CAGR (2025–30) | Verified | Mordor Intelligence transaction-monitoring market report | Med | Tailwind for managed/services layer specifically |
| Agentic AI can draft regulator-ready SAR narratives and triage alerts with human approval | Verified | SymphonyAI, Lucinity, Hawk AI, Unit21; arXiv 2509.08380 | Med | Confirms the technical feasibility of the engine's core tasks |
| Accountability for AML cannot be outsourced; board/management remain responsible | Verified | FinCEN/OCC/FFIEC interagency statement; FFIEC BSA/AML Manual | High | Defines the licensing/liability boundary → institution signs every SAR |
| SAM of $50M–$150M for one AI-native operator | Inferred | Built from segment counts × plausible contract values | Low | Directional only; must be validated in pilots |
| Buyers will pay outcome/per-unit pricing for managed investigations now | Unverified | No direct primary source obtained this run | Low | Key risk; first validation milestone (see §27) |
8Why now
Verified market & regulatory changes
Enforcement has escalated sharply: FinCEN's record $1.3B TD Bank penalty (Oct 2024), 36+ BSA/AML actions in 2024, and continuing fintech/crypto/broker-dealer penalties into 2025–26 Verified. Compliance costs rose for 99% of institutions, and 77% now cite staffing as a top constraint Verified. Meanwhile the managed-services layer of transaction monitoring is the fastest-growing slice (~18.4% CAGR) Verified — buyers are actively shifting work to third parties.
Inferred AI-capability changes
The two highest-volume tasks — triaging the false-positive 90% and drafting the SAR narrative — are now within reach of frontier models plus retrieval, as evidenced by multiple vendors shipping agentic alert-triage and SAR-narrative drafting with human sign-off Inferred from vendor and research sources. The economic unlock is that the cost of the noise layer falls toward the cost of compute.
Unverified hypotheses (to test)
That mid-market buyers will (a) accept a per-disposition price, and (b) trust a startup with examiner-facing work product within a 3–6 month sales cycle Unverified. These are the first things the pilot must prove.
9Customer & PMF
| Dimension | Detail |
|---|---|
| ICP (beachhead) | U.S. fintechs & their sponsor/BaaS banks, MSBs, and crypto/VASP platforms with 200–10,000 alerts/month and a thin (1–8 person) financial-crime team |
| Secondary ICP | Community banks & credit unions ($300M–$5B assets) with rising alert volume and hiring difficulty |
| Economic buyer | BSA Officer / Head of Financial Crime / Chief Compliance Officer |
| User | AML investigators, QC reviewers, the BSA Officer who signs filings |
| Urgent trigger | Exam finding or MRA, consent order/look-back, alert backlog, analyst resignation, new product launch spiking volume, sponsor-bank oversight demand |
| Alternatives | Hire/retain analysts (hard, expensive); offshore BPO (cheap, undifferentiated, no burden reduction); buy more software (still needs people to run it); do nothing (backlog → exam risk) |
| Jobs-to-be-Done | "Clear my alert queue defensibly, file accurate SARs on time, and survive my next exam — without growing headcount I can't hire." |
| Willingness to pay | Inferred high: enforcement penalties dwarf service fees; institutions already pay loaded analyst salaries and BPO contracts for the same work |
10The outcome we sell
Deliverable
For each alert: a closed, examiner-ready investigation file (disposition, rationale, evidence, audit trail). Where reportable: a complete, citation-supported SAR narrative ready for the BSA Officer's review and e-filing.
Acceptance criteria
Disposition is supported by documented evidence; narrative follows the "who/what/when/where/why/how" FinCEN standard; turnaround within SLA; QA pass; zero unsupported assertions.
Customer promise
"Hand us your alert queue; get back signed-ready dispositions and SAR drafts, faster and at lower total cost than running it in-house — with an audit trail your examiner will accept."
Exclusions
We do not file SARs (the institution files); we do not make the final filing decision; we do not provide legal advice; sanctions/OFAC blocking decisions remain the institution's.
Rework / make-good
Any case returned by the BSA Officer or flagged in exam is reworked free and root-caused; SLA credits if turnaround missed.
Success metric
Alerts cleared per SLA, SAR-draft acceptance rate by the BSA Officer, exam findings related to investigation quality (target: zero), and cost-per-disposition vs. the client's prior baseline.
11Internal AI engine architecture
The engine is internal infrastructure operated by our investigators. The customer never logs in to run it; they receive outputs and a portal to review/approve.
1. Intake layer
Secure ingestion of alerts from the client's TM system (Actimize, Verafin, Unit21, Hawk, in-house) via API/SFTP/export; plus customer KYC records, transaction logs, prior cases, and case-management exports.
2. Normalization layer
Map heterogeneous schemas to a canonical case model; entity-resolve customers/counterparties; dedupe; version every artifact; tokenize/segregate PII.
3. Retrieval & knowledge layer
Index FinCEN advisories & red-flag typologies, the client's BSA/AML policy & risk appetite, prior dispositions, SAR templates, and watchlist/adverse-media sources.
4. AI workbench layer
LLM agents extract facts, enrich with adverse-media/open-source intelligence, compute behavioral patterns, classify typologies, score risk, and draft the disposition rationale and SAR narrative.
5. Deterministic rules layer
Hard rules for sanctions hits, structuring thresholds, mandatory-SAR triggers, regulatory deadlines (30/60-day clocks), and "always-escalate" conditions — never left to probabilistic output.
6. Human chokepoint layer
Certified financial-crime investigators review AI work, resolve exceptions, and make recommendations; senior investigators handle complex typologies; the client's BSA Officer approves and files.
7. QA layer
Automated completeness/consistency checks + sampled human QC; citation verification; hallucination/false-positive-clearance red-team checks before delivery.
8. Delivery layer
Examiner-ready case file and SAR draft delivered into the client's case-management/portal with full audit trail; BSA Officer reviews, edits, signs, files in BSA E-Filing.
9. Learning loop
BSA Officer edits, QC findings, exam feedback, and false-positive patterns feed back into typology tuning, prompts, rules, and gold-standard examples.
10. Model-portability layer
Provider-agnostic abstraction so we swap/blend frontier models; offline evals gate every model change against a labeled case set before production.
12AI-vs-human operations pipeline
AI/rules own intake, enrichment, scoring, and first-draft generation (the bulk of effort). Humans own judgment, exceptions, and QA. The customer owns the filing decision and signature — the regulated accountability that cannot be delegated.
13Operations as product
The product is the production system, not heroic analysts. Variance is engineered out:
- SOP per typology & per client policy — structuring, rapid-movement, layering, mule activity, crypto on/off-ramp, trade-based, each with a required-evidence checklist.
- Structured intake contracts — every client onboard captures their risk appetite, SAR-decision rules, and case-management format into machine-readable config.
- Automated completeness checks — a case cannot advance until required evidence fields and citations are present.
- Exception queues & reviewer-assignment logic — routed by typology, risk, and investigator certification level.
- Confidence scoring — low-confidence AI output is auto-routed to senior review; high-confidence false-positive clears get lighter-touch QC.
- Immutable audit trail & version control — every action, model version, and edit logged for examiner reconstruction.
- Gold-standard library & red-team checks — labeled exemplars and adversarial tests run on every model/prompt change.
- Root-cause & postmortem loop — every BSA-Officer return, QC miss, or exam finding gets a documented root cause and a control update.
14No-holes quality engine
The failure modes that would sink this business are: missed true-positive activity (under-reporting), hallucinated facts in a SAR narrative, unsupported dispositions, and blown regulatory deadlines. Controls:
Against under-reporting
Conservative escalation defaults; mandatory-SAR rules are deterministic; recall-weighted QC sampling biased toward "should this have been a SAR?"; periodic blind re-review of cleared alerts.
Against hallucination
Every narrative assertion must trace to a cited source artifact; an automated citation-verification pass rejects unsupported sentences; narratives are grounded only in retrieved case data, never model "knowledge."
Against weak dispositions
Completeness gates, two-tier review for anything above a risk threshold, and a standardized rationale schema examiners recognize.
Against deadline misses
Deterministic 30/60-day SAR clocks with automated escalation, redundant alerting, and SLA dashboards visible to client and ops.
Quality is also the moat: the institution's exam outcome depends on it, and a clean exam history is the strongest possible reference.
15Pricing, pricing legality & unit economics
Primary model
Per-alert disposition fee + per-SAR-narrative fee + a fixed monthly platform/retainer. Indicative Inferred: ~$8–$20 per cleared alert disposition (tiered by complexity), ~$75–$200 per SAR narrative, plus a $5k–$25k/month platform & SLA retainer. This sits below the client's fully-loaded internal cost-per-alert (~$25–$50) while carrying healthy margin as automation rises.
Why not hourly
Hourly billing caps margin at labor and punishes us for getting faster. Per-unit pricing lets every automation gain flow to gross margin and aligns price with the value (cleared queue, filed SAR) rather than effort.
Pricing legality
Per-unit and fixed-fee pricing are clean here. We explicitly avoid any structure that could create an incentive to under- or over-report (e.g., paying per SAR filed in a way that rewards volume); fees are for investigation work product and drafts, not for filing decisions, which remain the institution's. Contingency/"success" pricing is inappropriate in a regulatory-reporting context and is not used.
Indicative unit economics Inferred
| Driver (per cleared alert, blended) | Launch | After 12 mo |
|---|---|---|
| Model inference + enrichment APIs | $0.80–$2.00 | $0.50–$1.20 |
| Human review minutes | ~6–10 min | ~1.5–3 min |
| Human/QA labor cost | $5–$9 | $1.50–$3.50 |
| Hosting / storage / case-mgmt | $0.40–$0.80 | $0.30–$0.60 |
| Blended COGS / alert | ~$7–$12 | ~$3–$5 |
| Implied gross margin | ~25–45% | ~60–75% |
SAR narratives carry more human minutes and price accordingly. Margin starts modest (human-heavy early) and expands toward software-like levels as automation rate climbs. Figures are inferred order-of-magnitude estimates to be calibrated in pilots.
16Nonlinear scaling plan
Revenue decouples from headcount by moving the false-positive 90% from human-minutes to compute-seconds. Targets Inferred:
As volume grows, fixed engineering and knowledge-base costs amortize and per-client tuning compounds (each client's history improves its automation rate). Margin expansion path: human-heavy services (yr 1) → AI-assisted services (yr 2) → AI-led with expert exceptions (yr 3), with gross margin tracking from ~30% toward 60–75%.
17Moat & Sam Altman test
Does it get stronger as models improve? Yes. Our single largest cost is human minutes spent clearing false positives and drafting narratives — exactly what better models reduce. Each model improvement lowers COGS and raises throughput without changing our price or the buyer's experience. We are architected for model portability so we ride the curve rather than betting on one provider.
The moat is not the model. It is: (1) regulatory trust & exam track record — a clean examiner history is extremely hard to replicate; (2) proprietary labeled case data & per-client tuning that lifts automation rates; (3) examiner-tested QA, SOPs, and audit trails as productized operations; and (4) the integration & trust relationship with the BSA Officer who stakes their license on our output.
18Buyer-specific go-to-market
This is a high-trust, regulated, mid-size-deal sale — founder-led outbound plus channel/referral, not waitlist or creator content. The buyer must trust us with examiner-facing work.
| Element | Plan |
|---|---|
| Why this GTM | BSA Officers buy on credibility and references; deals are $150k–$600k/yr and require security/oversight diligence — unsuited to self-serve motions |
| First 50 prospects | Fintechs & sponsor banks named in recent enforcement/oversight news; MSBs and credit unions with public exam pressure; warm intros from BSA-Officer networks (ACAMS) and compliance consultants |
| Trigger events | Exam findings/MRAs, consent orders/look-backs, alert backlogs, analyst departures, new product/volume spikes, sponsor-bank mandates |
| Outreach wedge | "We clear your alert backlog into examiner-ready dispositions and SAR drafts within SLA, for less than your loaded cost-per-alert — you keep every filing decision." |
| Credibility asset | Founder/advisor with ex-regulator or seasoned BSA-Officer pedigree; SOC 2 + sample examiner-ready case file; a "shadow run" comparing our output to the client's on their own historical alerts |
| Channel partners | BaaS/sponsor banks (push to their fintech programs), TM software vendors (services partner), AML consultancies, ACAMS community |
| Conversion path | Discovery → paid shadow run/backlog pilot on historical alerts → bounded live pilot → full managed contract |
| Sales cycle | ~3–6 months (faster when a backlog or exam finding forces urgency) |
| Acquisition / activation metrics | Pilots booked; shadow-run accuracy vs. client baseline; pilot→contract conversion; net revenue retention as alert volume grows |
19Pilot design & early-demand trap mitigation
We deliberately cap pilots at 2–3 design-partner clients and use them as instrumented laboratories, not a revenue land-grab.
Pilot cap & profile
2–3 clients: ideally one fintech/MSB and one community bank/CU, each with a real backlog and a cooperative BSA Officer.
Success criteria
SAR-draft acceptance rate by the BSA Officer ≥90% with minor edits; cleared-alert QC pass ≥97%; turnaround within SLA; cost-per-disposition below client baseline; zero deadline misses.
Manually constrained at first
Narrow typologies; heavier human review; we measure every manual workaround and every BSA-Officer edit.
Convert to product before scaling
Any repeated manual fix becomes a rule, prompt, template, or model-eval case. We will not add client #4 until automation rate, QC, and SLA hold for a full month.
Kill evidence
If under-reporting shows up in blind re-review, if BSA Officers won't accept AI-assisted narratives, or if automation can't beat loaded human cost — we stop.
No custom one-offs
We decline bespoke work that does not generalize across clients and improve the core engine.
20Competitive landscape
| Category | Examples | Why we differ |
|---|---|---|
| Managed AML services (incumbents) | AML RightSource, EY/consultancy managed services | Labor-led cost structure (3,000+ analysts); we are AI-native, so our cost-per-alert falls with model progress and we serve thinner-team mid-market accounts profitably |
| AI-native TM / case software | Unit21, Hawk, SymphonyAI, Lucinity, Verafin | They sell platforms the client operates; we sell the accountable outcome + labor relief and sit on top of whatever TM system the client runs |
| Offshore BPO | Generic compliance BPO shops | Undifferentiated hours, no burden reduction, weaker examiner defensibility; we lower the unit and raise quality |
| In-house team | Client's own analysts | Hard to hire/retain (77% staffing pain, high turnover); we flex capacity without headcount risk |
| Do nothing | Tolerate backlog | Backlogs = exam findings, MRAs, penalties (TD $1.3B); inaction is the riskiest option |
21Regulation, compliance & licensing boundary
The governing reality, per FinCEN/OCC/FFIEC: AML duties can be delegated but accountability cannot — the institution's board and management remain responsible Verified. We design entirely within that boundary.
| Activity | Who |
|---|---|
| Extract, enrich, classify, score, draft disposition & SAR narrative | Our AI engine |
| Review work product, resolve exceptions, recommend disposition | Our certified investigators |
| Decide whether to file a SAR; approve, sign, and e-file | Client's designated BSA Officer (never us) |
| OFAC/sanctions blocking decisions | Client |
| Legal advice / legal conclusions | Neither — out of scope (no UPL) |
- Prohibited claims: we never claim to "be" the institution's AML program, to file on its behalf, or to guarantee exam outcomes.
- Required controls: written service agreement defining responsibilities; the institution retains oversight and sufficient internal expertise; full audit logs; documented SOPs; SAR confidentiality (no tipping-off; strict access control).
- Data & privacy: GLBA-grade data handling, encryption, PII segregation, SOC 2; SAR information handled under FinCEN confidentiality rules.
- Pricing legality: per-unit/fixed fees only; no incentive tied to filing volume that could bias reporting.
22Compact founding team & expert map
| Role | Why needed | FT / fractional | First hire |
|---|---|---|---|
| BSA/AML domain lead (ex-BSA Officer / ex-examiner) | Credibility, SOPs, examiner-grade quality bar, sales trust | Full-time (founder) | Day 0 |
| AI/automation engineer | Builds intake, retrieval, agents, evals, model portability | Full-time (founder) | Day 0 |
| Operations / QA lead | Runs the production system, exception queues, QC, root-cause | Full-time | Month 1–2 |
| Certified investigators (CAMS) | Judgment chokepoint & review | Start fractional/contract, scale with volume | Pilot |
| Compliance counsel / regulatory advisor | Service-agreement structure, regulatory boundary, exam posture | Fractional | Pre-pilot |
| Sales / channel lead | Founder-led outbound + BaaS/consultant channels | Founder early; hire post-pilot | Month 4–6 |
23Exhaustive risk register
1. Under-reporting (missed true positives) triggers client exam failure
2. Hallucinated facts in a SAR narrative
3. Regulators object to outsourced investigations / accountability concerns
4. TM software vendors bundle agentic auto-disposition and commoditize the service
5. Long, trust-heavy sales cycle starves early revenue
6. Data security / breach of sensitive financial & SAR data
7. SAR confidentiality / tipping-off violation
8. Per-unit pricing rejected; buyers insist on FTE/hourly
9. Integration friction with diverse TM / case-management systems
10. Investigator hiring/quality can't keep pace early (pre-automation)
11. Regulatory regime shifts (e.g., AML Act / FinCEN priorities, deregulation)
12. Concentration risk: losing one large client dents revenue
24Tech stack & build plan
Core stack
Cloud (SOC 2-ready VPC); Postgres for canonical case model; object store for artifacts; vector DB for typology/advisory/policy retrieval; queue/orchestration for the agent pipeline; provider-agnostic LLM gateway.
Enrichment
Adverse-media & sanctions/watchlist APIs, corporate-registry & open-source intel, the client's KYC/transaction feeds.
Eval harness
Labeled gold case set; offline accuracy/recall/citation-grounding evals gate every model or prompt change before production.
Review portal
BSA-Officer-facing review/approve UI with audit trail and SLA dashboards; investigator workbench internal.
Build sequence
- Phase 0 (wk 1–4): canonical case model, ingest connectors (1–2 TM systems), retrieval over FinCEN advisories + sample policy, baseline disposition + SAR-draft agents, eval harness.
- Phase 1 (wk 5–8): deterministic rules layer, citation verification, QC tooling, review portal, audit logging, SOC 2 groundwork.
- Phase 2 (wk 9–12): shadow run on a design partner's historical alerts; calibrate; harden exception queues and learning loop.
No vague "use agents." Agents are scoped to extraction, enrichment, classification, and drafting, each gated by evals, deterministic rules, and human review.
25Metrics & KPIs
Throughput
Alerts cleared/investigator/day; SARs drafted/day
Cycle time
Alert-to-disposition; alert-to-SAR-draft vs. SLA
Rework rate
BSA-Officer returns; QC-failed cases (<3% target)
Gross margin / COGS per unit
Blended COGS/alert; margin trending 30%→60–75%
Revenue per FTE
Target $700k+ at scale
Automation rate
% alerts cleared with light-touch human review (40%→75%)
Escalation rate
% routed to senior review
Evidence completeness
% cases passing completeness gate first time
Quality failure rate
Under-reporting catches in blind re-review (target ~0)
SAR-draft acceptance
% accepted by BSA Officer with minor edits (≥90%)
Customer acceptance
Cases accepted without major rework
Pilot conversion
Shadow-run → pilot → contract rate
26What could kill this
- One bad exam. If our work contributes to a client exam finding or a missed SAR, the reference damage could be fatal. Quality is existential, not a feature.
- Buyers won't trust a startup with examiner-facing work. If the trust sale proves unwinnable without a household-name brand, growth stalls.
- Platform vendors auto-dispose alerts inside the TM system well enough that thin teams no longer need managed labor.
- Automation can't beat loaded human cost at acceptable recall — margins never reach software-like levels and we're just another BPO.
- A regulator signals discomfort with AI-drafted SARs or outsourced investigations, chilling adoption.
- Data breach or SAR-confidentiality incident ends institutional trust overnight.
2790-day validation & launch plan
| Weeks | Focus | Actions & evidence to close |
|---|---|---|
| 1–2 | Regulatory & pricing grounding | Engage ex-examiner/BSA-Officer advisor & counsel; finalize the accountability boundary & service-agreement template; interview 8–12 BSA Officers to test per-unit WTP (closes the Unverified pricing claim) |
| 3–5 | Engine MVP | Canonical case model, ingest for 1–2 TM systems, retrieval over FinCEN advisories + sample policy, disposition + SAR-draft agents, eval harness on a labeled case set |
| 6–8 | Controls & QA | Deterministic rules, citation verification, QC tooling, review portal, audit logging; begin SOC 2 readiness |
| 9–11 | Shadow run with 1–2 design partners | Run engine on the client's historical alerts; compare disposition & SAR-draft quality to their own output; measure accuracy, recall, citation grounding, cost-per-disposition |
| 12 | Decision gate | Convert to bounded live pilot if success criteria met; otherwise iterate or kill |
Kill criteria
Stop if: BSA Officers reject AI-assisted dispositions/narratives in principle; blind re-review reveals material under-reporting; automation cannot beat loaded human cost at acceptable recall; or counsel/advisor flags an un-mitigable regulatory barrier.
28Sources
- FluxForce — False Positive Rates in Transaction Monitoring (2024 data): fluxforce.ai/statistics/false-positive-rates-transaction-monitoring
- Thomson Reuters Institute — SARs Report for 2024: thomsonreuters.com/.../sars-report-2024
- FinCEN — SAR Filings by Industry (SAR Stats): fincen.gov/resources/reports/sar-stats/sar-filings-industry
- NICE Actimize — Unpacking FinCEN's 2024 SAR Stats: niceactimize.com/blog/...2024-fincen-sar-stats
- LexisNexis Risk Solutions — True Cost of Financial Crime Compliance (US & Canada): risk.lexisnexis.com/.../true-cost-...-us-and-canada
- Holland & Knight — FinCEN Imposes Record Penalty on Broker-Dealer (2026): hklaw.com/.../fincen-imposes-record-penalty-on-broker-dealer
- Gibson Dunn — 2025 Year-End Developments in Anti-Money Laundering: gibsondunn.com/2025-year-end-developments-in-anti-money-laundering
- K&L Gates — Lessons From 2024 BSA/AML Enforcement Actions: klgates.com/Lessons-From-2024-BSA-AML-Enforcement-Actions
- Akin — FinCEN/DOJ Enforcement Against Paxful: akingump.com/.../enforcement-actions-against-crypto-company-paxful
- Wolf & Company — State of Banking Enforcement & Fintech Partners: wolfandco.com/.../state-banking-enforcement-actions-fintech-partners
- Quantexa — Inside the AML Talent Market: quantexa.com/blog/inside-the-aml-talent-market
- Hawk AI — Top 10 AML Challenges for Banks in 2025: hawk.ai/news-press/top-10-aml-challenges-banks
- Salary.com — KYC AML Analyst Salary: salary.com/research/salary/opening/kyc-aml-analyst-salary
- AML RightSource — Experts in Financial Crime Compliance (managed services): amlrightsource.com
- Mordor Intelligence — Transaction Monitoring Market Size & Drivers 2025–2030: mordorintelligence.com/industry-reports/transaction-monitoring-market
- SymphonyAI — How AI agents reduce AML investigation time: symphonyai.com/.../how-ai-agents-reduce-aml-investigation-time
- Lucinity — Autonomous Case Resolution With Agentic AI Workflows: lucinity.com/blog/advancing-aml-investigations-agentic-ai-workflows
- Lucinity — Outsourcing AML Operations in 2025: lucinity.com/blog/outsourcing-aml-operations
- arXiv 2509.08380 — Co-Investigator AI: Agentic AI for AML Compliance Narratives: arxiv.org/html/2509.08380v1
- FinCEN — Interagency Statement on Sharing BSA Resources: fincen.gov/.../interagency-statement-sharing-bank-secrecy-act-resources
- FFIEC — BSA/AML Examination Manual: bsaaml.ffiec.gov/manual
- Mayer Brown — FinCEN RFI on AML Compliance Costs (2025): mayerbrown.com/.../fincen-rfi-on-aml-compliance-costs
Hard-to-fool blueprint · generated 2026-06-29 00:00 UTC · run 00-01. Evidence is labeled Verified / Inferred / Unverified; decisive claims rely on verified sources. Market-size and unit-economics figures are inferred order-of-magnitude estimates. This is a business analysis, not legal, regulatory, financial, or investment advice.