Template preview (excerpt)
2) System elements & development process
- Screening logic (sanctions/PEP rules + ML)
- Alert triage model(s)
- Case management and escalation
4) Performance metrics
- Precision/recall for alert triage
- False positive vs false negative handling
- Queue SLAs and reviewer throughput
View the worked example
Escalation:
- P0 (possible sanctions match): escalate to Compliance within 15 minutes
- P1 (high-risk alert): escalate within 2 hours
- P2 (medium alert): review within 1 business day
Before you begin
For compliance, risk, product, and ML ops teams shipping agentic Processes into regulated environments.
A system-type Annex IV template for KYC/AML Processes: onboarding screening, transaction monitoring, alert triage, and escalation procedures.
It focuses on defensible evidence: what rules/models were used, who reviewed alerts, and how false positives/negatives are handled.
When to use this resource
- Your system screens customers, flags suspicious activity, or recommends escalations (case management, SAR decisions).
- You need a provable trail for decisions, approvals, and configuration changes.
- You are aligning monitoring, sampling, and retention with audit requirements.
Information to gather
- Your screening + alert triage Process description and escalation steps.
- Decision authority and oversight requirements (who can approve/override).
- Metrics + thresholds (precision/recall, SLA, throughput).
- Retention policy and evidence export mechanism.
Review checklist
Use these checks in the review with your system owner. Confirm the applicable requirements and attach evidence for the decisions your team makes.
- Process boundary is explicit (advisory vs automatic).
- Data governance includes sensitive data handling and redaction rules.
- Metrics cover precision/recall, reviewer load, and queue SLAs.
- Oversight triggers exist for account closure, SAR recommendations, and high-risk alerts.
- Change control ties watchlist/rule/model changes to approvals and evidence.
Operating controls and evidence
- Govern
Policy-as-code checkpoints that block or require review for high-risk actions.
Versioned change control for model/prompt/policy/Process updates.
- Assure
Risk-tiered sampling reviews (baseline + burst during incidents or after changes).
Near-miss tracking (blocked / nearly blocked steps) as a measurable control signal.
- Prove
Configurable retention schedules, integrity verification, and an append-only Audit Trail.
Evidence Room export bundles (manifest + checksums) so auditors can verify independently.
Questions about this resource
What’s the highest-value evidence for KYC/AML audits?
A traceable link between alert decisions and the exact watchlists, rules, model versions, and reviewer actions in effect at the time.
How should we handle false positives?
Document thresholds, reviewer guidance, and how feedback updates rules/models. Retain the evidence of those changes and outcomes.
How do we handle sensitive data in logs?
Define redaction rules and store hashed references where possible; limit access and record all export actions.
What counts as a material change in KYC/AML?
Watchlist/rule updates, model changes, tool access changes, and Process changes that affect alert outcomes or reviewer burden.
Do we need sampling?
Sampling is useful for medium-risk alerts and for reviewer calibration; always-review triggers are common for the highest-risk cases.
What do auditors reject?
Evidence that cannot be verified or reproduced: missing versions, missing reviewer identities, or exports without integrity proofs.
Download file language: English
