Purpose
Ensure AML/CTF/CPF systems provide accurate risk identification, controlled automation, protected data, traceable decisions and reliable escalation.
Scope
This procedure covers the KYC/IDV service, KYT and wallet analytics, sanctions screening, compliance case management, ERP and compliance dashboards, integrations, access, audit logs, backups, calibration, changes and third-party providers.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Maintain system inventory | Maintain inventory of AML systems, integrations, owners, administrators, vendors, supported services and authoritative configuration baselines | AML system and integration inventory |
| 2 | Confirm operating design | Confirm design supports identity/liveness checks, wallet and transaction risk analytics, sanctions-list screening, case and escalation tracking, approvals, resolution status, compliance reporting and audit preparation. Core components: KYC/IDV Integration (third-party ID verification, biometric checks, liveness detection); KYT & Wallet Risk Analytics (real-time blockchain risk scoring, automated wallet alerts for mixer/darknet/sanctions exposure); Sanctions Screening Tools (relationship screening, automatic list refresh); Case Management System (tracks alerts, escalations, approvals, STR/FFR/PNMR decisions with timestamps, roles, resolution status); ERP & Compliance Dashboard (centralized KPI visibility, outstanding alerts, risk exposure, internal reporting and audit prep) | AML system and integration inventory |
| 3 | Verify input completeness | Verify required client, transaction, wallet, counterparty and screening inputs are complete and that failed, stale or incomplete integrations are detected and cannot be treated as clearance | Audit-log and exception-monitoring evidence |
| 4 | Apply access controls | Apply least-privilege role-based access, named accounts, multi-factor authentication, segregation of incompatible duties and periodic access review. MFA and encryption at rest and in transit | Access matrix, MFA and access-review evidence |
| 5 | Protect sensitive data | Protect sensitive data through encryption in transit and at rest, approved retention, controlled export and confidential handling | Access and audit-log evidence |
| 6 | Preserve audit trails | Preserve tamper-evident timestamps, actors, decisions, changes, overrides and resolution status in audit trails for all compliance decisions | Audit-log and exception-monitoring evidence |
| 7 | Maintain backups | Maintain regular backups, off-site encrypted storage and tested restoration for material AML records and configurations | Backup and restore evidence |
| 8 | Control calibration changes | Control sanctions-list refresh, monitoring thresholds, alert grades, wallet-risk rules and other calibration through documented risk assessment, testing, approval, deployment and rollback | Configuration export and calibration approval |
| 9 | Test before production | Test material changes before production, including positive, negative, boundary, failure, retry and integration scenarios. Retain release approval | Change test pack, release and rollback record |
| 10 | Conduct vendor due diligence | Conduct due diligence before engaging or materially renewing third-party AML tools and monitor service, security, regulatory, resilience and change risks | Vendor due-diligence and annual review |
| 11 | Review system effectiveness | Review system effectiveness and vendor suitability at least annually and after major update, incident, provider change or control failure. Compliance Officer oversees system effectiveness and tool calibration | Vendor due-diligence and annual review |
| 12 | Escalate system issues | Escalate unauthorized access, configuration variance, unapproved change, control failure or unsupported system coverage to Compliance and Technology and track remediation | Audit-log and exception-monitoring evidence |
Evidence
- AML system and integration inventory
- access matrix, MFA and access-review evidence
- configuration export and calibration approval
- audit-log and exception-monitoring evidence
- change test pack, release and rollback record
- backup and restore evidence
- vendor due-diligence and annual review
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Processes: PRC-FCI-001 Financial Crime and Integrity, PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-AML-011 Ensure AML Technology and Systems Controls Operate
- Odoo assurance issue: ISS-IT-001 Confirm Odoo Compliance Automation Security Testing and Operating Evidence
- Crystal calibration issue: ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration
- Manual coverage: sections 9.1-9.5 and relevant technology elements of sections 4, 7, 10 and 14.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Created after a full AML manual rescreen to implement the dedicated technology and systems chapter.