AML Compliance Workflow Digitisation for a Tier-1 Digital Bank
Compliance & AMLCompleted 14 November 2025

AML Compliance Workflow Digitisation for a Tier-1 Digital Bank

Replaced a patchwork of spreadsheets, email threads, and manual sign-offs with a unified, fully traceable AML case-management workflow handling 2,400+ monthly alerts across KYC, transaction monitoring, and sanctions screening.

Next.jsNode.jsPostgreSQLKeycloakAWSTerraformOpenSearch
Duration14 weeks
Budget$185,000
Team Size7 people
RegionEMEA
  • Unified case management for KYC refresh, TM alerts, and sanctions reviews
  • Role-based workflow with maker / checker / compliance sign-off segregation
  • Full audit trail with deterministic event logging (immutable append log)
  • Automated SLA tracking, breach alerts, and regulatory reporting exports
  • Deep-link integration with core banking transaction engine
  • Regulator-friendly traceability with per-case export package
  • SSO + MFA with Keycloak and fine-grained permission model

The client was relying on a fragmented compliance environment with dozens of spreadsheets, shared drives, and email approvals. Average time to close a medium-risk KYC case was 9.2 days, and the team could not produce a clean, defensible audit trail on demand.

Discovery & Workflow Mapping

We mapped every existing path through the three compliance streams, identified 17 hand-off points that lacked traceability, and consolidated them into four standard workflows with explicit decision gates.

Engineering Delivery

The new platform unifies KYC refresh, transaction-monitoring alerts, and PEP/sanctions reviews under a single case fabric. Every change produces a verifiable event log with cryptographic hashing to support regulator-requested samples.

The existing process ran across three compliance teams with no shared taxonomy. Documents lived in personal inboxes and shared folders, and every audit cycle required weeks of manual reconciliation to reconstruct how decisions were made. SLA breaches were only spotted after the fact.

We delivered a single case-management layer with four standard workflows, integrated SSO, automated checklist evaluation, and an immutable event log. Integrations pulled transaction data from the core bank, enriched it with sanctions data, and created pre-populated cases for analysts.

Median case closure time dropped from 9.2 days to 1.8 days (80% reduction). Audit preparation time fell from 6 weeks to 2 days. SLA adherence rose from 73% to 99.4%. Two successive regulatory audits closed with zero findings against the new platform.

We no longer dread audits. What used to take six weeks of digging through emails and spreadsheets now generates a clean, defensible export in two minutes. The team genuinely enjoys using it, which we never expected for a compliance tool.

Amaka K.Head of Compliance, Digital Commerce Bank