Purpose

Ensure AML/CTF/CPF systems provide accurate risk identification, controlled automation, protected data, traceable decisions and reliable escalation.

Scope

This procedure covers the KYC/IDV service, KYT and wallet analytics, sanctions screening, compliance case management, ERP and compliance dashboards, integrations, access, audit logs, backups, calibration, changes and third-party providers.

Steps

#ActionDetailsEvidence
1Maintain system inventoryMaintain inventory of AML systems, integrations, owners, administrators, vendors, supported services and authoritative configuration baselinesAML system and integration inventory
2Confirm operating designConfirm design supports identity/liveness checks, wallet and transaction risk analytics, sanctions-list screening, case and escalation tracking, approvals, resolution status, compliance reporting and audit preparation. Core components: KYC/IDV Integration (third-party ID verification, biometric checks, liveness detection); KYT & Wallet Risk Analytics (real-time blockchain risk scoring, automated wallet alerts for mixer/darknet/sanctions exposure); Sanctions Screening Tools (relationship screening, automatic list refresh); Case Management System (tracks alerts, escalations, approvals, STR/FFR/PNMR decisions with timestamps, roles, resolution status); ERP & Compliance Dashboard (centralized KPI visibility, outstanding alerts, risk exposure, internal reporting and audit prep)AML system and integration inventory
3Verify input completenessVerify required client, transaction, wallet, counterparty and screening inputs are complete and that failed, stale or incomplete integrations are detected and cannot be treated as clearanceAudit-log and exception-monitoring evidence
4Apply access controlsApply least-privilege role-based access, named accounts, multi-factor authentication, segregation of incompatible duties and periodic access review. MFA and encryption at rest and in transitAccess matrix, MFA and access-review evidence
5Protect sensitive dataProtect sensitive data through encryption in transit and at rest, approved retention, controlled export and confidential handlingAccess and audit-log evidence
6Preserve audit trailsPreserve tamper-evident timestamps, actors, decisions, changes, overrides and resolution status in audit trails for all compliance decisionsAudit-log and exception-monitoring evidence
7Maintain backupsMaintain regular backups, off-site encrypted storage and tested restoration for material AML records and configurationsBackup and restore evidence
8Control calibration changesControl sanctions-list refresh, monitoring thresholds, alert grades, wallet-risk rules and other calibration through documented risk assessment, testing, approval, deployment and rollbackConfiguration export and calibration approval
9Test before productionTest material changes before production, including positive, negative, boundary, failure, retry and integration scenarios. Retain release approvalChange test pack, release and rollback record
10Conduct vendor due diligenceConduct due diligence before engaging or materially renewing third-party AML tools and monitor service, security, regulatory, resilience and change risksVendor due-diligence and annual review
11Review system effectivenessReview system effectiveness and vendor suitability at least annually and after major update, incident, provider change or control failure. Compliance Officer oversees system effectiveness and tool calibrationVendor due-diligence and annual review
12Escalate system issuesEscalate unauthorized access, configuration variance, unapproved change, control failure or unsupported system coverage to Compliance and Technology and track remediationAudit-log and exception-monitoring evidence

Evidence

  • AML system and integration inventory
  • access matrix, MFA and access-review evidence
  • configuration export and calibration approval
  • audit-log and exception-monitoring evidence
  • change test pack, release and rollback record
  • backup and restore evidence
  • vendor due-diligence and annual review

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Created after a full AML manual rescreen to implement the dedicated technology and systems chapter.