Title

9+
Named U.S. sponsor banks hit with FDIC/OCC/Federal Reserve BSA/AML/BaaS-related consent orders or enforcement actions identified this run, Jan 2024 – Jun 2026 — Banking Dive, American Banker, OCC
2026
OCC issued a fresh consent order to Community Federal Savings Bank (sponsor bank for Wise and Crypto.com) for AML/BSA/SAR deficiencies — Banking Dive, American Banker
22
Banks reported in a March 2026 FDIC enforcement-order publication push — GovPing headline (proportion tied to BSA/AML not independently confirmed this run)
Draft-only
Regulatory guidance treats AI-drafted SAR narratives as permissible only when a human BSA Officer reviews, attests, and files — the signature stays human

LookbackClear is a done-for-you BSA/AML transaction lookback and consent-order remediation production desk for small-to-mid-size FDIC/OCC/Federal-Reserve-regulated sponsor banks running Banking-as-a-Service (BaaS) fintech-partner programs, who have just been ordered by their regulator to complete an independent historical lookback review of customer accounts and transactions after a cited BSA/AML/KYC/SAR program failure.

Final Decision

FINAL DECISION: BLUEPRINT

This candidate clears the evidence threshold and all six gates. A full build follows.

Executive Summary

Since 2024, U.S. federal banking regulators have opened a recurring, well-documented wave of enforcement actions against small and mid-size "sponsor banks" — community and regional banks that rent their charters to fintech companies under Banking-as-a-Service (BaaS) arrangements — citing BSA/AML program failures tied specifically to inadequate oversight of those fintech partners. This run identified at least nine distinctly named institutions hit with such actions in a roughly 30-month window: Blue Ridge Bank (OCC, Jan 2024), Lineage Bank (FDIC, Jan 2024), Sutton Bank (FDIC, Feb 2024), Piermont Bank (FDIC, Feb 2024), Mode Eleven Bancorp/Summit National Bank (Federal Reserve Bank of Kansas City, Mar 2024), Thread Bank (FDIC, May 2024), River Bank & Trust and Exchange Bank (FDIC), and Community Federal Savings Bank — sponsor bank for Wise and Crypto.com — (OCC, 2026). Several of these orders, and the standard industry practice described by consulting firms like Baker Tilly and Stout, require the sponsor bank to commission an independent third-party "lookback" review: a historical, evidence-documented re-examination of customer accounts and transactions to surface missed suspicious activity, file missing SARs, and remediate incomplete KYC/CDD records, typically against a hard regulatory deadline.

Today this work is fulfilled almost exclusively by traditional, hourly-billed compliance consulting and advisory firms (named examples found this run include Deloitte, Protiviti, Ankura, Baker Tilly, Stout, ARC Risk and Compliance, AML RightSource, and J.S. Held) — firms built around large-bank retainers and staffing models that are slow and expensive to mobilize for a $200M–$10B sponsor bank facing a 60–180 day regulatory clock. No AI-native, per-unit-priced alternative built specifically for this sponsor-bank/BaaS niche was found in this run's research. LookbackClear proposes to fill that gap: an AI-native lookback triage and evidence-production engine, priced per account/transaction batch reviewed (never hourly), with a trained AML analyst and the client bank's own BSA Officer as the human chokepoints who review, correct, attest, and file — never the AI, and never LookbackClear on the bank's behalf.

Timing is favorable and self-renewing: this is not a one-time regulatory event but a recurring pattern that has produced a new named enforcement action roughly every few months since 2024, with the most recent identified case (Community Federal Savings Bank) dated 2026 — meaning the buyer-trigger event (a fresh consent order) keeps recurring across a rotating cast of sponsor banks as BaaS partnerships continue to scale.

Thesis

BSA/AML transaction lookback remediation for BaaS sponsor banks is a narrow-buyer, deadline-driven, document- and data-heavy, already-outsourced compliance workflow triggered by a discrete, verifiable regulatory event (a consent order, MRA, or MRIA). It fits the preferred pattern precisely: a defined, currently-enforcement-active buyer segment (small/regional sponsor banks under BSA/AML consent orders) that already pays outside firms to solve exactly this problem; a workflow that decomposes cleanly into AI-automatable triage/evidence-assembly work plus a small number of licensed/authorized human chokepoints (the BSA Officer's SAR-filing decision and attestation, which FinCEN rules reserve to the institution itself); a real regulatory moat (BSA, the FinCEN SAR-filing rule, and OCC/FDIC/Federal Reserve consent-order enforcement mechanics); no physical labor; and a clear Sam Altman test pass — better models directly improve transaction-pattern triage, typology classification, and grounded SAR-narrative drafting, the exact tasks that dominate a lookback's labor cost today. It also passes every fatal-disqualifier check: the buyer is identifiable by name today (nine sponsor banks named this run alone); existing spend on this exact workflow is independently verifiable (named consulting-firm competitors selling "BSA/AML lookback" as a distinct service line); the SAR-filing licensing dependency is isolated to one clean, well-understood chokepoint rather than spread across the workflow; and the candidate is confirmed novel against all 498 prior manifest entries, which cover ongoing BAU alert-investigation/SAR-narrative work and one MSB compliance-program-filing desk, but no project-based, consent-order-triggered historical lookback offering for the BaaS sponsor-bank segment specifically.

Discovery Rationale

This run began by re-cloning the repository and verifying manifest.json's integrity before doing any new research, per this factory's standing operating rule given the documented history of a separate, unrelated automation repeatedly truncating that file. The manifest was found healthy and current at clone time: version 21, 498 runs, HEAD at commit 021e33d2 ("Auto-heal: restore manifest.json truncated at 7cfb7a4f8fe8, runs 498->0, restored 498 from 8c0d0b9481ba") — itself a prior session's healing commit, already pushed to origin/main and matching local HEAD exactly. No new truncation was found and no heal was required this run.

With a healthy 498-run manifest in hand, a systematic keyword sweep across the manifest's titles (covering healthcare admin, insurance, tax/compliance, legal ops, real estate/title/mortgage, HR/benefits, logistics, banking/fintech/AML, energy/utilities, education admin, clinical research, construction, elder/disability services, hospitality, and consumer/local-service back office) confirmed the manifest is extraordinarily dense — 481 of 498 entries are already "blueprint" decisions, heavily skewed toward regulatory-filing/compliance "engine"/"desk" businesses. Per this factory's operating rule to steer into underexplored adjacent terrain, research pivoted toward banking/fintech/KYC-AML, where the manifest contains exactly two entries ("AML Alert Investigation & SAR Narrative Engine" for ongoing BAU alert-queue work, and "SentryFile Clear" for MSB AML compliance-program filings) but zero entries touching BaaS sponsor-bank consent-order remediation, transaction lookbacks, or the specific 2024–2026 sponsor-bank enforcement wave. A keyword check for "lookback," "consent order," "sponsor bank," "BaaS," "Community Federal," "Piermont," and "Sutton" across all 498 prior titles returned zero matches, confirming the candidate untouched before research began in earnest.

Candidate Comparison

#CandidateBuyerComposite score /5Verdict
1BaaS sponsor-bank BSA/AML lookback & consent-order remediation desk (SELECTED)BSA Officer / Chief Compliance Officer at a small-to-mid-size FDIC/OCC/Fed-regulated sponsor bank under an active BSA/AML consent order or MRA4.4Winner — nine named enforcement events across 2024–2026 (recurring, not one-off), verifiable existing consulting spend on the identical workflow, clean FinCEN-defined SAR-filing chokepoint, confirmed untouched in the manifest
2Restaurant/hospitality third-party delivery-platform (DoorDash/Uber Eats/Grubhub) commission & fee-overcharge audit-recovery deskIndependent and small-chain restaurant owners3.0Rejected — real evidence gathered of a 2026 FTC proposed rule on unfair/deceptive delivery fees and restaurants publicly reporting large fee losses, but the workflow archetype (auditing a platform's commission/fee line items for overcharges) directly parallels the manifest's existing “OTA Commission Recovery Engine” and would read as a near-duplicate pattern in a different vertical; the underlying task is comparatively mechanical (low intelligence threshold) and the FTC rule itself may shrink the very problem being monetized; per-restaurant buyer budget and willingness-to-pay is also weaker than the banking candidate
3Small-parcel and freight invoice audit & overcharge-recovery serviceMid-market shippers using UPS/FedEx/LTL carriers2.4Rejected — this exact niche is already served at scale by multiple named, mature contingency-fee incumbents (Reveel, ICC Logistics, ParcelRecovery, Mindful Logistics, ZDSCS) found actively marketing this service today; zero competitive whitespace, and the archetype overlaps the manifest's existing “Carrier Detention & Accessorial Recovery Desk,” “Layline” ocean detention/demurrage engine, and “Distributor Deduction Recovery Desk” entries
4K-12 IEP/special-education procedural-compliance & due-process documentation deskSchool district special-education directors2.6Rejected — drafting due-process-complaint responses and procedural-safeguards documentation risks edging into representing a district in a parent dispute (unauthorized-practice-of-law adjacency); the IEP-software market is already crowded with incumbents (Embrace, CentralReach, AbleSpace, SLP Now) selling tools rather than proof of an outsourced-labor spend gap; this run found no comparable active-enforcement-event evidence (no equivalent to the sponsor-bank consent-order wave) to establish buyer urgency
5Home-care agency EVV (Electronic Visit Verification) compliance & claim-denial recovery deskMedicaid HCBS/personal-care agency owners2.8Rejected — the manifest already contains adjacent “EVV”- and “HCBS”-referencing entries and a saturated “medical-necessity/documentation-completeness desk” pattern (100+ variants); the AI-native wedge is also constrained by state-mandated EVV vendor lock-in (Sandata, HHAeXchange integrations required), which dilutes the pure-AI moat relative to the banking candidate's clean data-ingestion model

CODE Validation

Consumer/Buyer Trend

A recurring, accelerating wave of federal banking-regulator enforcement actions against small and regional sponsor banks specifically citing fintech-partnership BSA/AML oversight failures, running from Blue Ridge Bank and Lineage Bank (Jan 2024) through Sutton Bank, Piermont Bank, Mode Eleven Bancorp/Summit National Bank, and Thread Bank (2024) to Community Federal Savings Bank (2026), plus FDIC actions against River Bank & Trust and Exchange Bank. [Verified — each institution and action independently named in Banking Dive, American Banker, and/or OCC's own enforcement-action releases]

Opportunity

The specific underserved gap: named specialist and Big 4 consulting firms (Deloitte, Protiviti, Ankura, Baker Tilly, Stout, ARC Risk and Compliance, AML RightSource, J.S. Held) already sell BSA/AML lookback and remediation engagements, but on the traditional hourly/FTE-staffed consulting model built for large-bank retainers — not a per-unit-priced, AI-native offering sized for a $200M–$10B sponsor bank under a hard regulatory deadline. [Inferred from the vendor landscape observed and standard consulting engagement norms; exact billing structure of each named firm's lookback offering was not independently confirmed line-by-line this run]

Demand

Direct evidence of active, paid demand: Baker Tilly's own published guidance describes lookbacks as commonly triggered by regulators or auditors and recommends engaging an independent third party; Stout markets a named case study ("Managed a regulatory mandated BSA AML transaction look-back"); AML RightSource publishes guidance specifically on lookback and remediation projects. [Verified]

Economic Sizing

At least nine distinctly named sponsor banks were hit with BSA/AML/BaaS-related consent orders or enforcement actions in the roughly 30-month window this run could confirm (Jan 2024–Jun 2026) — almost certainly an undercount, since this run did not conduct an exhaustive primary search of the FDIC/OCC/Federal Reserve enforcement-action databases (a March 2026 FDIC press round-up alone was reported to cover 22 banks, though the BSA/AML-specific share of that batch was not independently confirmed this run). Given that lookback engagements commonly span hundreds to thousands of historical accounts per program and that BaaS sponsor banks often run multiple fintech programs simultaneously, and given that comparable regulatory-mandated remediation engagements are reported elsewhere in this factory's own manifest and in general industry commentary to run into six-to-seven-figure engagement sizes, a plausible addressable spend of roughly $300,000–$2,000,000+ per triggered lookback engagement is a reasonable planning range. [Inferred — a directional range built from named enforcement-event frequency and general remediation-engagement scale commentary, not a confirmed per-engagement price found this run; see Claim Table]

Rubric Scorecard

GateScore /5Explanation
Low trust burden (already outsourced)5Sponsor banks under consent orders are already required or strongly advised to hire independent third-party firms for lookbacks — outsourcing this exact task is the regulatory norm, not something to be sold in for the first time
Low task-level judgment4Transaction-pattern triage, typology screening, and evidence-package assembly decompose cleanly into AI-automatable steps; real judgment concentrates at account-disposition confirmation and the SAR-filing decision itself
High intelligence threshold4Requires synthesizing transaction histories, KYC/CDD files, typology patterns (structuring, layering, high-risk-jurisdiction exposure), and the specific scope language of each consent order
Regulation as moat5The Bank Secrecy Act, FinCEN's SAR-filing rule (only the institution may file), and OCC/FDIC/Federal-Reserve consent-order enforcement mechanics create a durable, expertise-heavy regulatory structure a generic competitor cannot casually replicate
No physical labor5Fully remote, document- and transaction-data-based
Sam Altman test4Better models directly improve transaction-pattern triage accuracy, typology classification, and grounded, citation-backed SAR-narrative drafting — the exact bottleneck tasks in a lookback today

Target Buyer

Primary buyer: the BSA Officer or Chief Compliance Officer of a small-to-mid-size FDIC/OCC/Federal-Reserve-regulated sponsor bank (roughly $200M–$10B in assets) running one or more Banking-as-a-Service fintech-partner programs, who has just received a consent order, Matter Requiring Attention (MRA), or Matter Requiring Immediate Attention (MRIA) citing BSA/AML/KYC/SAR program deficiencies and mandating (or strongly inviting) an independent lookback review.

Economic decision-maker: the bank's CEO or Chief Risk Officer, typically acting on board-level urgency once a consent order is public and a remediation deadline is running; outside regulatory counsel is frequently involved in vendor selection alongside the BSA Officer.

Jobs-to-be-Done

“My regulator has just ordered us to complete an independent BSA/AML lookback across our fintech-partner program's historical accounts within a fixed deadline, but my own BSA/AML team is already understaffed — that's how we got this order in the first place — and the Big 4/specialty consulting firms that normally do this work are slow to staff and bill by the hour at a scale my bank can't easily absorb. I need a complete, examiner-ready lookback — account-by-account dispositions, a full evidence package, and draft SAR narratives ready for my own BSA Officer to review and file — delivered inside my deadline, priced so I know my cost before I start.”

The Painful Problem

When a BaaS sponsor bank's regulator finds BSA/AML program gaps — frequently a missing risk assessment of a fintech partner, absent beneficial-ownership documentation, or an unreviewed suspicious-activity backlog, as cited in the Thread Bank, Sutton Bank, and Piermont Bank orders found this run — the resulting consent order commonly requires the bank to retain an independent party to look back across historical transactions and customer files, surface any missed suspicious activity, file any resulting SARs, and document the entire process for examiner review, all within a fixed window that is frequently 60–180 days.

The bank facing this order is, almost definitionally, the same bank whose BSA/AML team was already too thin to catch the problem before a regulator did — it does not have spare internal capacity to staff a multi-thousand-account historical review on top of its ongoing compliance workload. Its two remaining options today are both painful: hire a traditional consulting firm at hourly/FTE-staffed rates that can run into the high six or seven figures and take weeks to fully mobilize, or attempt the lookback with its own stretched team and risk missing the deadline or producing a review an examiner later finds incomplete — precisely the failure mode that produced River Bank & Trust's and Exchange Bank's follow-on FDIC actions.

The Outcome We Sell

Not a transaction-monitoring dashboard the bank's own analysts must operate. The deliverable is the finished, examiner-ready artifact set: a complete per-account disposition log (clear / escalate / SAR-recommended) across the defined lookback scope; a fully documented evidence package per account (transaction summaries, supporting KYC/CDD records, and a cited audit trail of the reasoning behind each disposition); grounded, source-cited draft SAR narratives for every SAR-recommended account, queued for the bank's own BSA Officer to review, correct, attest, and file; and a rolled-up lookback summary report the bank can present to its own board and, through its own channel, to its examiner — all delivered against the bank's specific consent-order deadline, at a price known before the engagement starts.

First One-Feature MVP Wedge

ICPFDIC/OCC/Federal-Reserve-regulated sponsor bank, $200M–$10B in assets, 1–5 active BaaS/fintech-partner programs, under an active consent order, MRA, or MRIA citing BSA/AML/KYC/SAR deficiencies
Trigger eventA newly issued consent order or exam finding mandating an independent BSA/AML transaction lookback within a fixed deadline
PainCannot staff the lookback internally (the same understaffing produced the order), and traditional consulting-firm hourly rates and mobilization time threaten the deadline and the budget
One-feature MVP“Lookback Triage & Evidence-Package Desk”
InputExported historical transaction/account data for the defined lookback scope, existing CIP/KYC files, the bank's current risk-rating methodology, and the consent order's specific scope language
OutputPer-account disposition log, a complete evidence package with cited audit trail per account, draft SAR narratives for SAR-recommended accounts, and a rolled-up lookback summary report
Human chokepointA trained (ideally CAMS-credentialed) AML analyst reviews every AI-generated disposition before it is finalized; the bank's own BSA Officer reviews, corrects, attests to, and files every SAR recommendation — LookbackClear never files on the bank's behalf
Success metricLookback completed inside the regulator's deadline; disposition agreement rate with the BSA Officer's independent review at or above an agreed threshold (target 95%+); zero material examiner findings on subsequent review of the completed lookback
What they ask for nextAn ongoing perpetual/periodic KYC-refresh retainer, augmentation of the bank's day-to-day transaction-monitoring alert queue, and coverage of additional fintech programs as the bank's BaaS book grows

Evidence Summary

The core structural claim — that a recurring, multi-year wave of named sponsor-bank BSA/AML enforcement actions exists and each commonly triggers an independent lookback requirement — is Verified across multiple independent named sources (Banking Dive, American Banker, OCC's own release, Baker Tilly, Stout). The existence of a real, paid, human-staffed competitor tier selling lookback/remediation engagements today is Verified by name. What is explicitly Inferred rather than confirmed: the exact dollar size of a typical lookback engagement for this specific sponsor-bank segment (no single confirmed price was found this run), the total number of BaaS sponsor banks nationally, and whether any named consulting incumbent already runs an AI-native version of this exact offering (none was found, but the search was not exhaustive of every private firm's internal tooling). All pricing and market-sizing figures in this blueprint are explicitly presented as planning ranges, not confirmed industry data.

Claim Table (Verified / Inferred / Unverified)

ClaimLabelConfidence
Blue Ridge Bank (OCC, Jan 2024) and Lineage Bank (FDIC, Jan 2024) received BSA/AML consent orders tied to third-party/fintech-partner risk managementVerifiedHigh (named, dated, sourced to Banking Dive and OCC's own document)
Sutton Bank and Piermont Bank (both FDIC, Feb 2024) received consent orders citing BSA violations, deficient AML/CFT programs, and (Piermont) an unreviewed SAR backlog since Sept 2022VerifiedHigh (named, dated, sourced to Banking Dive)
Mode Eleven Bancorp/Summit National Bank (Federal Reserve Bank of Kansas City, Mar 2024) and Thread Bank (FDIC, May 2024) received orders citing fintech-partnership oversight and BSA/AML program gapsVerifiedHigh (named, dated, sourced to Banking Dive)
River Bank & Trust (Alabama) and Exchange Bank (Oklahoma) received FDIC BSA/AML consent ordersVerifiedMedium–High (named, sourced to Banking Dive; specific fintech-partnership linkage not independently confirmed for these two this run)
OCC issued a 2026 consent order to Community Federal Savings Bank, sponsor bank for Wise and Crypto.com, citing AML/BSA/SAR deficienciesVerifiedHigh (named, dated, sourced to Banking Dive, American Banker, and OCC's own May 2026 enforcement release)
A March 2026 FDIC enforcement-order publication round covered 22 banksInferredLow–Medium — headline-level only (source page could not be fetched due to robots.txt restriction); the BSA/AML-specific share of that batch is not confirmed
BSA/AML lookback reviews are commonly triggered by a regulator or auditor finding and are recommended to be run by an independent third party, producing SARs, investigation documentation, and a final reportVerifiedHigh (Baker Tilly's own published guidance)
Named consulting/advisory firms (Deloitte, Protiviti, Ankura, Baker Tilly, Stout, ARC Risk and Compliance, AML RightSource, J.S. Held) sell BSA/AML lookback or remediation services todayVerifiedHigh (each firm's own service pages/case studies)
Only the financial institution itself (via its authorized BSA Officer) may file a SAR with FinCEN; AI may draft and cite a narrative but must not decide to file or signVerifiedHigh (FinCEN's own guidance and a secondary industry analysis of 2026 AI-SAR practice, consistent with each other)
U.S. Treasury's June 2024 Request for Information framed AI as having significant potential to strengthen AML/CFT compliance, without a blanket authorization for AI-drafted narrativesInferredMedium — drawn from a single secondary industry-analysis source; the RFI's primary text was not independently retrieved this run
Typical dollar size of a BSA/AML lookback engagement for a $200M–$10B sponsor bankUnverifiedLow — no confirmed engagement-price figure found this run; the $300,000–$2,000,000+ range in this blueprint is an inferred planning range built from enforcement-event frequency and general remediation-engagement scale commentary, not a sourced number
Total number of BaaS sponsor banks operating in the U.S. todayUnverifiedLow — multiple market-research firms track the broader embedded-finance/BaaS market, but no single authoritative current count of sponsor banks specifically was found or extracted this run
An AI-native lookback triage engine can materially reduce analyst/BSA-Officer minutes per account versus a traditional consulting-staffed lookbackInferredMedium — reasoned from task decomposition (transaction-pattern triage and narrative drafting are AI-automatable; the filing decision is not), not yet operationally proven in this specific niche

Source-Claim Matrix

ClaimLabelSourceTypeDateConfidenceSection used
Piermont Bank, Sutton Bank FDIC consent orders over BaaS third-party partnersVerifiedBanking Dive — Piermont, Sutton banks hit with FDIC consent orders over BaaSTrade press2024/2026HighExecutive Summary, CODE, Claim Table
Running list of BaaS banks hit with consent orders in 2024 (Thread Bank, Mode Eleven Bancorp, Piermont Bank, Sutton Bank, Lineage Bank, Blue Ridge Bank)VerifiedBanking Dive — A running list of BaaS banks hit with consent orders in 2024Trade press2024HighExecutive Summary, CODE, Discovery Rationale, Claim Table
Fed hits Synapse partner Evolve with BSA/AML-related enforcement actionVerifiedBanking Dive — Fed hits Synapse partner Evolve with enforcement actionTrade press2024HighCODE, Market and Demand Evidence
OCC cites AML/BSA/SAR deficiencies at Community Federal Savings Bank, a fintech-partner sponsor bankVerifiedBanking Dive — OCC cites AML deficiencies at NY bank that partners with fintechsTrade press2026HighTitle, Executive Summary, Problem, Claim Table
Community Federal Savings Bank is the sponsor bank for Wise and Crypto.com; told to fix its AML programVerifiedAmerican Banker — Sponsor bank for Wise, Crypto.com told to fix AML programTrade press2026HighExecutive Summary, Buyer
OCC's May 2026 enforcement-action release naming Community Federal Savings BankVerifiedOCC — Enforcement Actions for May 2026Primary regulator release2026HighTitle stat card, Claim Table
FDIC hits River Bank & Trust (Alabama) and Exchange Bank (Oklahoma) with BSA/AML consent ordersVerifiedBanking Dive — FDIC hits Alabama, Oklahoma banks with consent ordersTrade press2024HighExecutive Summary, CODE, Claim Table
The OCC's recent consent order is a warning for community banks in the fintech-partnership spaceVerifiedFinancial Services Perspectives — The OCC's Recent Consent Order Is a WarningLaw firm analysis2026Medium–HighMarket and Demand Evidence, Regulatory Considerations
BSA/AML lookback reviews: triggers, deliverables (SARs, documentation, final report), and the recommendation to use an independent third partyVerifiedBaker Tilly — Examining institutions' key needs in a BSA/AML lookbackConsulting-firm insightCurrentHighCODE, Problem, Competitive Landscape
Stout has performed a regulatory-mandated BSA/AML transaction lookback as a named client engagementVerifiedStout — Managed a regulatory mandated BSA AML transaction look-backConsulting-firm case studyCurrentHighCODE (Demand), Competitor and Budget Validation
AML look-backs and remediation projects: guidance for institutions needing a fixVerifiedAML RightSource — Sometimes Things Need a FixConsulting-firm insightCurrentHighCompetitive Landscape, Competitor and Budget Validation
Regulatory remediation consulting is a named service lineVerifiedProtiviti — Regulatory Remediation ConsultingConsulting-firm service pageCurrentHighCompetitive Landscape
Anti-money laundering advisory services offered by a Big 4 firmVerifiedDeloitte — Anti-Money Laundering Advisory ServicesConsulting-firm service pageCurrentHighCompetitive Landscape
Only the institution files the SAR; AI can draft and cite a narrative but the signature stays human, per US/UK regulatory posture in 2026VerifiedZyphe — AI SAR Narratives in 2026: What Regulators AcceptIndustry analysis2026Medium–HighLicensing Boundary, AI-Native Advantage
March 2026 FDIC enforcement-order publication covered 22 banksInferredGovPing — FDIC Publishes Enforcement Orders for March 2026Aggregator headline (full page not fetchable)2026Low–MediumCODE (Economic Sizing)

Market and Demand Evidence

Demand signals are concrete and event-based rather than speculative: nine distinctly named sponsor banks have been hit with BSA/AML/BaaS-related consent orders or enforcement actions across a roughly 30-month window (Jan 2024–Jun 2026) spanning three different federal regulators (OCC, FDIC, Federal Reserve); a named law-firm analysis published in mid-2026 explicitly frames the Community Federal Savings Bank order as "a warning for community banks in the fintech partnership space," signaling more such orders are anticipated by practitioners; and a tier of established consulting firms (Deloitte, Protiviti, Ankura, Baker Tilly, Stout, ARC Risk and Compliance, AML RightSource, J.S. Held) already markets BSA/AML lookback and remediation services as distinct, named offerings, which is itself the clearest available proof that banks facing these orders pay real money for exactly this workflow today.

Active Buyer Conversations

Trade press and law-firm analysis published within the current cycle (Banking Dive's dedicated 2024 "running list" of BaaS consent orders and its 2026 Community Federal Savings Bank coverage, American Banker's naming of Wise and Crypto.com as CFSB's fintech partners, and Financial Services Perspectives' 2026 "warning for community banks" analysis) shows active, current, named professional discussion of exactly this compliance-enforcement pattern — not a stale or hypothetical trend.

Competitive Landscape

Two tiers of alternative exist today: (1) traditional Big 4 and specialty compliance-consulting firms (Deloitte, Protiviti, Ankura, Baker Tilly, Stout, ARC Risk and Compliance, AML RightSource, J.S. Held) who sell BSA/AML lookback and remediation engagements on an hourly/FTE-staffed consulting model, generally built for and priced toward larger-bank retainers; and (2) generalist AML transaction-monitoring/case-management software vendors (Hawk AI, Napier AI, Flagright, smartKYC, Unit21, and others found this run) who sell ongoing monitoring platforms the bank's own staff must operate, not a done-for-you project-based lookback service. No incumbent found this run combines an AI-native engine with per-unit/outcome pricing specifically packaged for the $200M–$10B sponsor-bank segment facing a fixed regulatory deadline.

Competitor and Budget Validation

The existence and active marketing of named BSA/AML lookback and remediation services by established consulting firms is itself the budget proof this factory requires: sponsor banks facing consent orders already engage and pay outside firms for this exact compliance obligation. LookbackClear is not a clone of either competitive tier — it is not a generalist monitoring platform the bank must operate (unlike the software vendors), and it does not sell hourly/FTE-staffed consulting time (unlike the Big 4/specialty tier) — it sells a fixed, per-account/per-outcome-priced production desk sized specifically for the sponsor-bank segment the traditional consulting tier is not structured to serve quickly or affordably at this asset scale.

Pricing Evidence and Proposed Pricing

TierPriceIncludes
Engagement Setup & Scoping (one-time, per lookback)$15,000–$40,000Consent-order scope mapping, fintech-partner data-schema ingestion, engagement plan aligned to the regulatory deadline, exception-queue design
Per-Account Triage & Disposition (Tier 1 — clean file)$45–$65/accountAutomated typology screening, disposition (clear/escalate/SAR-recommended), evidence package, analyst review
Per-Account Triage & Disposition (Tier 2 — escalation-required)$85–$110/accountTier 1 scope plus a written escalation memo and expanded evidence assembly for accounts requiring closer review
Per-Account Triage & Disposition (Tier 3 — SAR-recommended)$125–$150/accountTier 2 scope plus a grounded, source-cited draft SAR narrative queued for the BSA Officer's review and filing
Draft SAR Narrative (standalone add-on)$250–$450/narrativeA fully cited draft narrative for a specific account where disposition work was already completed by the client's own team
Perpetual/Periodic KYC-Refresh Retainer (post-lookback expansion)$2–$6/active account/monthOngoing periodic file-refresh monitoring for the fintech program(s) covered by the closed lookback

Pricing is per-account/per-unit and per-outcome (per completed lookback engagement, per account disposition, per drafted narrative), never hourly and never billed as a percentage of any recovered funds or fine amount — a percentage-of-outcome structure tied to enforcement or financial results would create an inappropriate incentive in a compliance-remediation context, so pricing is deliberately fixed per unit of completed, reviewable work.

Regulatory and Compliance Considerations

Governing framework: the Bank Secrecy Act and its implementing FinCEN regulations, the FFIEC BSA/AML Examination Manual (including Appendix O on examiner transaction-testing techniques), FinCEN's SAR-filing rule (which reserves the filing decision and act to the financial institution itself), and the specific scope, deadlines, and remediation requirements set out in each client bank's own consent order, MRA, or MRIA. Regulatory posture on AI-drafted SAR narratives as of 2026 is one of conditional openness rather than blanket authorization or prohibition (per Treasury's 2024 RFI framing and industry analysis), meaning every AI-drafted narrative must be treated as a draft pending human review, never a final filed document.

Licensing Boundary

What AI may do: ingest and normalize historical transaction and account data; apply rule-based and ML-assisted typology screening (structuring, layering, high-risk-jurisdiction exposure, dormant-to-active account behavior, sanctions/PEP rescreening); draft per-account dispositions with cited reasoning; draft SAR narratives grounded in, and citing, the underlying case record; maintain the full audit trail; monitor for relevant FinCEN/OCC/FDIC/Federal Reserve guidance updates.

What trained (non-licensed) AML analysts may do: review every AI-generated disposition for accuracy and completeness before it is finalized; escalate ambiguous cases; assemble and quality-check the evidence package; project-manage the engagement against the consent-order deadline; communicate with the client bank's compliance team. AML/CAMS certification is a professional credential, not a state-issued license, so this layer of the workforce can scale without a licensing bottleneck — [Inferred distinction; not independently confirmed against every state's professional-licensing statute this run].

What only the client bank's own authorized BSA Officer/institution may do: make the final SAR-filing decision and file the SAR with FinCEN — per FinCEN's own rule, only the financial institution may file; attest to the completeness of the lookback to examiners; make final risk-acceptance decisions on any account disposition.

What LookbackClear must never claim or do: file a SAR on the bank's behalf; represent itself to examiners as the bank's agent of record; provide legal advice on consent-order negotiation strategy, enforcement defense, or settlement posture (referred to the bank's own outside counsel); guarantee a specific examination outcome, consent-order termination, or that the lookback will fully satisfy the regulator. Every deliverable is explicitly labeled "draft — pending BSA Officer review and attestation"; the engagement letter defines the service as data preparation, screening, and draft-narrative production, not legal representation, independent public accounting attestation, or investment/credit advice; a full, timestamped audit trail of every AI-drafted-then-human-reviewed step is retained per the client bank's own record-retention requirements. This is not legal, tax, medical, insurance, credit, debt-collection, or immigration advice.

AI-Native Advantage

AI changes the economics on four axes: speed (transaction-pattern triage and evidence-package assembly that takes a traditional consulting team days per account batch can be AI-drafted in a fraction of the time, with analyst and BSA-Officer time spent on judgment, not data entry); coverage (screening thousands of historical accounts against dozens of known typologies is a retrieval/pattern-matching task AI performs far more consistently than a manually staffed review team working under deadline pressure); consistency (the same current typology rule set and grounded-citation standard is applied to every account, reducing the variance that produces examiner findings on re-review); and cost curve (as frontier models improve at transaction-pattern reasoning and grounded narrative drafting, the AI engine's share of the per-account workload grows and the analyst's/BSA Officer's per-account review time shrinks, expanding margin without adding headcount).

Internal AI Engine Architecture

LayerFunction
1. IntakeSecure ingestion of the client bank's exported transaction/account data, existing CIP/KYC files, and the consent order's specific scope language
2. NormalizationAI parses and standardizes heterogeneous fintech-partner transaction schemas into a canonical per-account, per-transaction data model
3. Retrieval/KnowledgeCurrent FinCEN typology guidance, FFIEC examiner transaction-testing techniques (Appendix O), and the client bank's own risk-rating methodology held in a retrieval index
4. AI WorkbenchRuns typology screening across the full account/transaction set, drafts per-account dispositions with cited reasoning, and drafts grounded SAR narratives for SAR-recommended accounts
5. Deterministic RulesHard-coded thresholds from the client bank's own risk-rating methodology and the consent order's specific scope requirements (which accounts, which date range, which typologies must be checked)
6. Human ChokepointTrained AML analyst confirms every AI disposition; the client bank's own BSA Officer reviews, corrects, attests to, and files every SAR recommendation
7. QASecond-pass AI consistency check against the account's own transaction history and the consent order's scope before human review
8. DeliveryDisposition log, evidence package, draft SAR narratives, and rolled-up lookback summary report delivered via a secure client portal
9. Learning LoopAnalyst and BSA-Officer corrections feed back into typology-screening rules and narrative-drafting prompt libraries
10. Model PortabilityScreening and drafting prompts are provider-agnostic so the underlying frontier model can be swapped as capability/cost shifts

AI-vs-Human Operations Pipeline

AI tasks: transaction/account data normalization, typology screening across the full lookback scope, per-account disposition drafting with cited reasoning, grounded SAR-narrative drafting.
Human tasks: client intake and engagement scoping, analyst review and confirmation of every disposition, BSA Officer review/correction/attestation/filing of every SAR, client relationship management and examiner-facing coordination handled by the bank itself.
Automation tasks: data ingestion pipelines, deadline tracking against the consent order's own schedule, document version control.
Deterministic rule tasks: the client bank's risk-rating thresholds, the consent order's specific scope requirements, sanctions/PEP list rescreening triggers.
QC steps: AI self-consistency pass, analyst disposition review, BSA Officer review and attestation, periodic sample audit of closed lookback batches.
What must never be fully automated: the SAR-filing decision itself and the act of the BSA Officer signing/filing it.

Dynasty Translation Layer

Buyer translationBSA Officer/CCO of a small-to-mid-size sponsor bank, urgent risk = missing the consent order's remediation deadline or producing a lookback an examiner later finds incomplete, desired outcome = a complete, examiner-ready lookback with draft SARs ready for filing
Service translationDone-for-you lookback triage and evidence-production desk; client receives finished dispositions, evidence packages, and draft narratives, not a monitoring platform to operate
Workflow translationIntake/scoping → data normalization → AI typology screening and disposition drafting → analyst review → BSA Officer review/attestation/filing → delivery of lookback summary report → post-lookback retainer renewal
Tooling translationSecure client document/data portal, an AI screening-and-drafting workbench, a maintained typology-rule and FFIEC-guidance retrieval layer, and a simple case-management tracker for deadline management — favoring off-the-shelf tools before any custom platform
Sales translation“Your consent order's lookback deadline is running whether or not your team has spare capacity. We deliver examiner-ready dispositions and draft SARs your own BSA Officer reviews and files — priced per account, known before you start.”
Delivery translationFirst pilot engagements delivered manually by the founder plus one or two contracted CAMS-credentialed AML analysts; typology rules and narrative prompts harden as pilots complete
Expansion translationSingle-program lookback → multi-program sponsor-bank engagement → perpetual/periodic KYC-refresh retainer → eventually a light client-facing lookback-status portal

Anti-Duplication Analysis

The manifest's two prior banking/AML entries are "AML Alert Investigation & SAR Narrative Engine" (ongoing, business-as-usual day-to-day transaction-monitoring alert-queue investigation and narrative writing, for any bank's routine compliance operation) and "SentryFile Clear" (a Money Services Business's ongoing AML compliance-program and periodic filing desk). LookbackClear is not a clone of either: its trigger is a discrete, dated regulatory enforcement event (a consent order/MRA/MRIA) rather than routine BAU alert flow; its buyer segment is specifically BaaS sponsor banks under active enforcement, not any bank's day-to-day compliance desk or an MSB's ongoing filing program; and its workflow is a project-based historical lookback across a defined account/transaction population and time window, not an open-ended ongoing monitoring queue. No prior run in the 498-entry manifest references "lookback," "consent order," "sponsor bank," "BaaS," or any of the nine named enforcement-action institutions surfaced this run.

Anti-Commoditization Analysis

If future general-purpose models make basic transaction-pattern screening and narrative drafting a free or near-free commodity, the service still wins on three fronts general models cannot replace on their own: (1) the trained-analyst-plus-BSA-Officer sign-off chain, which is a regulator-mandated human accountability structure (the signature stays human, per FinCEN's own rule) that no AI model can substitute for regardless of capability; (2) the accumulated, engagement-specific typology-rule and consent-order-scope library that makes each subsequent client's lookback faster and more precisely calibrated to what examiners actually flag; and (3) the maintained, always-current FFIEC/FinCEN guidance and typology-pattern retrieval layer itself, a standing asset that compounds in value as guidance keeps evolving (as it is doing now around AI-drafted SAR narratives) rather than a one-time build. The business is designed so the human-accountability-chain-plus-accumulated-context-plus-current-guidance layer, not raw screening capability, is the moat.

Service Delivery Workflow

Engagement scoping against the consent order's own language → secure data intake (transaction/account exports, CIP/KYC files) → AI normalization and typology screening across the full lookback population → AI-drafted per-account disposition and evidence package → analyst review and confirmation → BSA Officer review, correction, and attestation of every SAR-recommended account → SAR filing by the bank itself → delivery of the rolled-up lookback summary report → post-engagement retainer conversation.

Operations as Product

SOPs per typology category (structuring, layering, high-risk-jurisdiction exposure, dormant-to-active behavior, sanctions/PEP hits); a required-evidence checklist per account at intake; automated completeness checks before any disposition moves to analyst review; an exception queue for accounts the AI cannot confidently disposition (e.g., ambiguous cross-program transfers); analyst-assignment logic by typology complexity; confidence scoring on every AI-drafted disposition and narrative; a full audit trail of AI draft → analyst review → BSA Officer attestation → filed/closed status; version-controlled typology-rule and prompt libraries; gold-standard example dispositions used to calibrate new typology rules as the business expands coverage; and a root-cause postmortem for any disposition an examiner later questions on re-review.

No-Holes Quality Engine

Every deliverable passes: (1) an automated completeness check against the consent order's specific scope requirements, (2) an AI self-consistency pass against the account's own transaction history, (3) trained-analyst review of every disposition, and (4) BSA Officer review and attestation of every SAR-recommended account before filing. No disposition or SAR narrative leaves the pipeline without both analyst and (where a SAR is recommended) BSA Officer sign-off.

What the Human Expert Actually Does

TaskCredential neededMin/unit at launchMin/unit at day 90Automation pathMust-not-automate
Engagement scoping against consent-order languageAML/compliance experience180 (one-time per engagement)120AI drafts an initial scope summary from the consent-order text for reviewer confirmationFinal scope sign-off with the client bank
Per-account disposition reviewTrained AML analyst (CAMS preferred, not state-licensed)12/account5/accountAI drafts the full disposition and cited evidence package; analyst confirms or correctsFinal disposition confirmation on escalated/SAR-recommended accounts
SAR narrative reviewTrained AML analyst, pre-BSA-Officer review20/narrative10/narrativeAI drafts a fully cited narrative from the account's evidence package; analyst checks grounding before BSA Officer reviewN/A — feeds the BSA Officer, not a final filing
SAR filing decision and attestationClient bank's own authorized BSA Officer25/account (client-side)15/account (client-side)AI-prepared narrative and evidence package reduce the BSA Officer's data-gathering time; the filing decision itself is never automated or performed by LookbackClearThe filing decision and the act of signing/filing with FinCEN
Lookback summary report finalizationAML/compliance experience240 (one-time per engagement)150AI drafts the full rolled-up report from all account-level dispositions; reviewer finalizesFinal report sign-off delivered to the client

Minimum Viable Offer

“Lookback Triage & Evidence-Package Desk”: a complete per-account disposition log, evidence package, and (for SAR-recommended accounts) grounded draft SAR narratives, delivered in defined batches against the client bank's own consent-order deadline, priced per account reviewed, with a fixed engagement-setup fee covering scoping and data-schema ingestion.

Fulfillment Process

First pilot engagements delivered manually: founder handles engagement scoping and sales, one or two contracted CAMS-credentialed AML analysts review every AI-drafted disposition and narrative, and the client bank's own BSA Officer performs all filing decisions using a structured evidence-package handoff (no custom software required at launch). Typology rules, checklists, and prompts harden after each engagement based on what the analyst or BSA Officer had to correct.

Tools and Systems

Launch stack: a secure document/data portal for transaction-export upload and deliverable return, a structured data-normalization workbook, an LLM API for typology screening and narrative drafting with a maintained prompt library, a lightweight case-management tracker for deadline management across engagements, and direct secure-transfer channels with each client bank's own IT/compliance team. No custom software is required before first revenue; a client-facing lookback-status portal is a later-stage build once volume justifies it.

Human-in-the-Loop Quality Control

Every AI-drafted disposition and narrative is explicitly labeled a draft until analyst review (and, for SAR-recommended accounts, BSA Officer attestation); analyst and BSA-Officer corrections are logged and periodically analyzed to identify systematic AI screening or drafting errors; and no disposition, evidence package, or SAR narrative is delivered to a client bank without a named human reviewer and timestamp in the audit trail.

Nonlinear Scaling and Unit Economics

50%+
Target gross margin at steady state
6–10x
Target accounts processed per contracted AML analyst vs. a traditional consulting-staffed lookback model
<5 min
Target analyst review time per Tier-1 account disposition by day 90, down from an estimated 12+ minutes at launch

COGS breakdown: LLM inference and hosting (low, scales sub-linearly with account volume); contracted AML-analyst review minutes (tracked per account per engagement); QA sampling time; secure-portal and data-infrastructure costs; client support and engagement-management time; rework when analyst/BSA-Officer corrections reveal a screening or drafting gap; sales/business-development follow-up. Automation %: ~40% of triage/drafting effort AI-handled at launch, targeting 70%+ by day 90 and 80%+ by year one as typology rules and prompt libraries mature. Throughput: target 1–2 new engagement onboardings per month at launch across pilot-cohort banks, growing as typology libraries compound. Cycle time: target under 90 days from intake to a completed lookback for a mid-size single-program engagement, comfortably inside the 60–180 day deadlines typically observed in consent orders. Rework rate target: under 10% of AI-drafted dispositions requiring a major analyst rewrite by day 90. Escalation rate target: under 8% of accounts requiring founder-level or senior-analyst escalation. CAC payback: target under 4 months given the engagement-setup fee and first account-batch invoice are collectible early in the engagement. Conversion assumptions: qualified consent-order-triggered inquiry → signed engagement at 20–35% (a hard regulatory deadline creates real urgency once a prospect engages); completed lookback → post-engagement KYC-refresh retainer at 40%+. Retention assumption: a bank that converts to the ongoing retainer typically stays through its post-consent-order examination cycle, supporting multi-quarter retention once onboarded.

Distribution Proof Table

ChannelWhy ICP is reachableFirst angleProof source
Public FDIC/OCC/Federal Reserve enforcement-action releasesEvery consent order naming a sponsor bank is published publicly and immediately upon issuanceDirect outreach referencing the bank's own newly published consent order and its specific deadline languageOCC/FDIC/Federal Reserve public enforcement-action pages; Banking Dive's ongoing tracking
BaaS regulatory-enforcement trackers and trade pressBanking Dive and similar outlets maintain running coverage of exactly these enforcement events as they happenEducational content responding to each newly reported consent order within days of publicationBanking Dive's dedicated running-list coverage found this run
Referral from regulatory/banking counsel and existing AML consulting firmsOutside counsel and generalist consulting firms who advise banks post-consent-order often cannot staff the lookback itself quickly and would rather refer or subcontract itWarm referral/subcontracting partnership offering white-label lookback triage capacityNamed consulting-firm service pages showing this referral/subcontracting pattern is normal in adjacent compliance practice
Direct outreach to newly-named banks in each fresh consent orderEach consent order is a discrete, dated, public trigger event with a known contact point (the bank's own compliance leadership)A specific, personalized read of the bank's own published order and its remediation deadline, not a generic pitchOCC/FDIC/Federal Reserve enforcement-action documents (primary, publicly available)
Search/AEO content on “BSA AML lookback cost” and “BaaS sponsor bank consent order remediation”BSA Officers actively search these exact phrases within days of receiving a consent orderDiagnostic landing page explaining what a lookback requires and a free scope-review CTASearch-relevant explainer content density observed this run (Baker Tilly, Stout, AML RightSource)

Sales and Outreach Plan

Lead with a free, no-obligation "Consent-Order Lookback Scope Review": a short structured intake of the bank's own published consent-order language that produces a written scope memo estimating account/transaction volume, likely typology categories in play, and a realistic delivery timeline against the bank's own deadline — positioned as a diagnosis grounded in the bank's actual order, not a generic demo. Outbound targets banks named in a newly published FDIC/OCC/Federal Reserve consent order citing BSA/AML/fintech-partnership deficiencies, prioritized by deadline proximity.

Founder-Led Content Plan

Content teaches the exact pain: what a BSA/AML lookback actually requires, how consent-order remediation deadlines typically work, what FinCEN's SAR-filing rule means for who can (and can't) file on a bank's behalf, what "independent third party" means in a lookback context, and what happened in each named 2024–2026 sponsor-bank enforcement action. Content deliberately avoids generic "AI compliance" framing and stays specific to the sponsor-bank/BaaS enforcement reality.

First 30 Days of Content

10 educational posts: what a BSA/AML transaction lookback actually requires; anatomy of a sponsor-bank consent order (using the publicly available Piermont/Sutton/Thread/Blue Ridge/Lineage/CFSB orders as reference points); why only the bank can file a SAR (and what that means for any vendor's role); what "independent third party" means in a lookback engagement; the FFIEC's own transaction-testing techniques (Appendix O) explained; how AI-drafted SAR narratives are treated by regulators in 2026; what a realistic lookback timeline looks like against a 60–180 day consent-order deadline; how sponsor banks can avoid a repeat finding on re-review; what BaaS third-party risk-assessment documentation should contain; a state-of-the-industry roundup of the 2024–2026 sponsor-bank enforcement wave.
3 diagnostic teardown formats: "We read a real, public consent order line-by-line — here's what its lookback scope actually requires"; "Anatomy of a SAR narrative that satisfies an examiner vs. one that gets kicked back"; "A sponsor bank's fintech-partner account volume, annotated for lookback scoping."
2 lead-magnet angles: free "Consent-Order Lookback Scope Review"; free BSA/AML lookback readiness checklist.
1 webinar/live-review idea: "Live review: what does your bank's consent order actually require for its lookback?"
1 outbound diagnosis template: a one-page "here's what we read in your bank's newly published consent order and what its lookback scope likely requires" memo.

Lead Magnet and Waitlist Plan

The free "Consent-Order Lookback Scope Review" is the core lead magnet: a short structured intake of the bank's own published consent-order text produces a written scope memo estimating volume, likely typology categories, and a realistic delivery timeline. This captures real pain signal (how large and urgent the bank's specific lookback is) and creates a natural next step (engage the paid Lookback Triage & Evidence-Package Desk). A lead is sales-ready when the scope review confirms a live deadline within 180 days and a named BSA Officer or compliance contact.

Warm GTM Plan

Early warm channel: regulatory/banking counsel and generalist AML consulting firms who advise banks post-consent-order but cannot quickly staff the lookback itself; offering them a referral or white-label subcontracting relationship is a low-friction warm intro. Consultative free scope reviews for early prospects (drawn from publicly named consent-order banks) build the first case studies.

Targeted Outbound Plan

Perfect-fit prospects: any bank newly named in an FDIC, OCC, or Federal Reserve consent order or enforcement action citing BSA/AML/KYC/SAR deficiencies tied to a fintech or BaaS partnership, prioritized by how recently the order was issued and how soon its remediation deadline falls. Outreach leads with a specific, personalized read of the bank's own published order, not a generic pitch.

Answer-Engine/Search Visibility Plan

Publish authoritative, citable explainers on BSA/AML lookback requirements, FinCEN's SAR-filing rule, and the 2024–2026 sponsor-bank consent-order pattern, written to be directly quotable by AI answer engines and search snippets, reinforcing the founder-led content plan above and capturing the specific deadline-driven searches BSA Officers run within days of receiving a consent order.

Pilot Design and Early-Demand-Trap Mitigation

First pilot cohort: 5 engagements, capped, drawn from banks with a publicly named, recently issued consent order and confirmed contact with a BSA Officer or compliance lead. Early-access incentive: 20% off the Tier 1/2 per-account rate in exchange for a detailed post-engagement feedback session and permission to reference an anonymized case study. Feedback mechanism: a structured post-delivery review logging every analyst/BSA-Officer correction to the AI's disposition or narrative draft. Product feedback (a systematic typology-screening or drafting gap AI keeps making) is distinguished from custom work (a client-specific edge case, such as an unusual fintech-partner transaction schema) by whether the same correction recurs across 2+ clients — recurring corrections become typology-rule or prompt-library updates; one-off edge cases stay manual. The team explicitly avoids the early-demand trap of treating a strong scope-review inquiry volume as proof of product-market fit; only signed, paid engagements and post-lookback retainer conversions count as validation.

Early-Access Feedback Flywheel

Every analyst or BSA-Officer correction to an AI-drafted disposition or narrative is logged with a reason code; reason codes recurring across engagements become SOP updates, typology-rule revisions, or new deterministic scope checks; the updated rule/prompt is re-tested against the next engagement's data before being trusted at scale.

Build-Before-Scale Checkpoints

After 5 pilots: harden the intake checklist and required-evidence list based on what was missing most often across engagements. After 10 pilots: harden typology-specific SOPs, the exception queue, and analyst-review checklists based on accumulated correction patterns. After 20 pilots: pause new onboarding until COGS per account, rework rate, escalation rate, and average analyst review time per account are all measured and within target before resuming growth. Acceptable temporary manual workarounds: founder or senior analyst personally handling an unusual fintech-partner transaction schema or edge-case typology. Signal the model isn't scalable: analyst review time per account is not decreasing pilot-over-pilot, or rework rate is not falling.

7-Day / 30-Day / 90-Day Launch Plans

7 daysStand up the Consent-Order Lookback Scope Review intake form and landing page; build the initial typology-screening prompt library from the FFIEC Appendix O framework; contract the first one to two CAMS-credentialed AML analysts; identify and reach out to the banks named in the most recent 2024–2026 consent orders found this run whose remediation deadlines are still open
30 daysClose and onboard the first 1–2 pilot engagements; deliver first account-batch dispositions and evidence packages; publish the first 10 pieces of founder-led content; run the first live diagnostic webinar
90 daysComplete the 5-engagement pilot cohort; harden SOPs per the Build-Before-Scale checkpoints; convert completed lookbacks to post-engagement KYC-refresh retainers where applicable; measure COGS, rework rate, and analyst review time against targets before opening broader outbound

Metrics and KPIs

Scope-review-to-signed-engagement conversion rate; completed-lookback-to-retainer conversion rate; analyst and BSA-Officer minutes per account per engagement; rework rate (% of AI dispositions/narratives requiring major analyst rewrite); escalation rate; revenue per contracted AML analyst; gross margin; engagement on-time-to-deadline rate; zero material examiner findings on completed lookbacks upon re-review; client retention into the post-lookback retainer.

Risks and Mitigations

Key risks are covered in the exhaustive risk register below; the top three are the contracted-analyst bottleneck risk (mitigated by hardening typology-screening prompts/SOPs before scaling engagement count per the Build-Before-Scale checkpoints), the risk of a missed or understated suspicious-activity disposition (mitigated by conservative, analyst-and-BSA-Officer-reviewed thresholds and explicit non-guarantee disclaimers), and the risk of a regulator later finding the completed lookback itself incomplete (mitigated by the deterministic scope-checklist layer tied directly to the bank's own consent-order language).

Exhaustive Risk Register

1. Contracted AML analysts become the bottleneck as engagement count grows — Likelihood: Medium · Impact: High

Mitigation: hard pilot caps and the Build-Before-Scale checkpoints prevent onboarding faster than analyst review capacity; recruit additional contracted CAMS-credentialed analysts before the cap is breached.

2. A client bank's true suspicious-activity exposure is missed or understated by the AI triage layer — Likelihood: Low-Medium · Impact: Very High

Mitigation: conservative typology-screening thresholds, mandatory analyst review of every disposition, mandatory BSA-Officer review of every SAR recommendation (never AI-only), documented QA sampling, and explicit contractual non-guarantee language distinguishing triage/evidence preparation from the BSA Officer's independent filing judgment.

3. A regulator later finds the completed lookback itself incomplete on re-review — Likelihood: Low-Medium · Impact: Very High

Mitigation: deterministic scope-checklist layer built directly from the client bank's own consent-order language, analyst confirmation of scope completeness before delivery, and a full audit trail available for examiner review through the client bank's own channel.

4. FinCEN or a banking regulator tightens or restricts the permissible use of AI-drafted SAR narratives — Likelihood: Medium · Impact: Medium-High

Mitigation: maintain the "agent-drafted, human-attested" structure already consistent with 2026 regulatory posture; monitor Treasury/FinCEN guidance updates continuously and adjust the drafting workflow's grounding/citation requirements ahead of any tightening.

5. A single contracted AML analyst leaves, creating continuity risk mid-engagement — Likelihood: Medium · Impact: High

Mitigation: documented SOPs, typology-rule libraries, and a full audit trail make handoff to a second analyst tractable; recruit a backup analyst once past the first pilot cohort.

6. Fintech-partner transaction-data schemas vary widely across programs, causing a normalization error — Likelihood: Medium-High · Impact: Medium

Mitigation: exception queue for non-standard schemas at intake; analyst confirms every new program's schema mapping before it is trusted at scale; gold-standard example mappings maintained per fintech-partner type.

7. Named Big 4/specialty consulting incumbents (Deloitte, Protiviti, Ankura, Baker Tilly, Stout) build their own AI-native lookback offering and close the differentiation gap — Likelihood: Medium · Impact: Medium

Mitigation: speed of execution and per-unit pricing built specifically for the sponsor-bank asset scale these firms are not structured to serve efficiently today; build the accumulated typology-rule and consent-order-scope library described in Anti-Commoditization Analysis.

8. Client bank transaction/account data is mishandled, creating a data-security/privacy incident — Likelihood: Low · Impact: High

Mitigation: secure, access-controlled document/data portal; encryption at rest and in transit; minimal data-retention policy beyond what each engagement and the client bank's own record-retention requirements demand.

9. Pricing undershoots true analyst-time cost during the pilot phase — Likelihood: Medium · Impact: Medium

Mitigation: track actual analyst minutes per account from pilot 1 and adjust per-account pricing before broad outbound per the 90-day checkpoint.

10. A prospective client conflates this service with legal representation in consent-order negotiation or examiner defense — Likelihood: Low-Medium · Impact: Medium-High

Mitigation: explicit engagement-scope language and disclaimers stating the service prepares dispositions, evidence, and draft narratives and does not provide legal advice or examiner representation; referral relationship maintained with the client bank's own outside regulatory counsel.

11. The free Scope Review generates a large volume of inquiries with no live consent order or confirmed BSA Officer contact — Likelihood: Medium · Impact: Low-Medium

Mitigation: qualify leads by a confirmed, publicly verifiable consent order and a named compliance contact before allocating founder sales time; treat inquiry volume alone as a vanity metric, not validation (see Pilot Design).

12. A completed lookback surfaces a volume of SAR recommendations that overwhelms the client bank's own BSA Officer capacity to review and file within the deadline — Likelihood: Medium · Impact: Medium-High

Mitigation: batch delivery of dispositions in prioritized tranches (highest-risk accounts first) so the BSA Officer can begin filing before the full lookback is complete; transparent volume forecasting during engagement scoping so the client can plan its own review capacity.

What Could Kill This

The two scenarios most likely to kill this business are a sustained analyst-time bottleneck that never falls with AI leverage (making the unit economics no better than a traditional consulting-staffed lookback), and a completed lookback later found materially incomplete by an examiner on re-review before the deterministic scope-checklist layer and analyst/BSA-Officer review chain are fully hardened. Both are directly addressed by the pilot caps and Build-Before-Scale checkpoints above.

Go/No-Go Reasoning

Go. The buyer, trigger event, existing consulting-vendor spend, and BSA/FinCEN regulatory moat are all independently verifiable; the MVP wedge is narrow and deliverable within weeks of a bank's consent order being issued; the licensing boundary is manageable because the real dependency (the SAR-filing decision) is isolated to one clean chokepoint that FinCEN's own rule already reserves to the client bank, not spread across the workflow; and the candidate is confirmed novel against all 498 prior manifest entries, including four other candidates this run scored and explicitly rejected (delivery-platform commission recovery, small-parcel/freight invoice audit, K-12 IEP compliance, and home-care EVV compliance) before selecting this one.

Final Recommendation

Launch the Lookback Triage & Evidence-Package Desk MVP wedge targeting sponsor banks with a publicly named, recently issued FDIC/OCC/Federal Reserve consent order citing BSA/AML/fintech-partnership deficiencies, use the free "Consent-Order Lookback Scope Review" as the primary lead-generation motion, cap the first pilot cohort at 5 engagements, and expand into the post-lookback perpetual/periodic KYC-refresh retainer once the core triage-and-evidence-production workflow is hardened.

Source List