Gains:
- Understand how AML (anti-money laundering) and KYC (know your customer) processes work and how artificial intelligence is used in transaction monitoring, scanning and file summary
- Ability to use AI for suspicious transaction outline and customer risk profile summary, leaving the suspicious transaction reporting (STR) decision to the authorized compliance officer
- Enforcement/PEP screening, mismatch, and ability to understand why compliance requires human oversight and maintain an audit trail
Banks don't just store money; It also holds the door to the financial system. Banks have legal obligations to prevent black money, terrorist financing and sanctioned funds from passing through this door. Two key processes enable this: KYC (Know Your Customer) is to verify who the customer is and the source of funds with which he or she is doing business; AML (Anti-Money Laundering) is to monitor transactions and identify suspicious ones. In Türkiye, the regulator of this field is MASAK (Financial Crimes Investigation Board) and banks are obliged to report suspicious transactions with suspicious transaction reporting (STR/SAR). AI is powerful at handling this massive volume of transaction monitoring, name scanning, and file summarization; But the STR decision is a decision that has legal consequences and belongs to the authorized compliance officer. The model produces a preliminary screening and a draft, it does not make decisions.
In this unit, we will see how AML/KYC works, how to use AI in transaction monitoring, screening and file summary, and why human oversight and audit trail is essential.
How KYC and AML work
- KYC (customer recognition): Identity verification, identification of the real beneficiary (principal owner of the fund), risk classification. Tightened scrutiny applies to high-risk customers (e.g. PEP — Politically Exposed Person).
- Transaction monitoring: Scanning the customer's transactions for known laundering patterns (smurfing — splitting large amounts into subthreshold parts, rapid entry and exit, unrelated account networks).
- Screening: Comparison of names with sanctions lists and PEP lists.
- Notification (STR): Notification to MASAK when the suspicion reaches a reasonable level.
Tip: In AML, the goal is not to "prove guilt" but to "report reasonable suspicion." The compliance officer is not a prosecutor; is obliged to evaluate the suspicion correctly and make the legal notification in a timely manner. This evaluation requires judgment and cannot be delegated to the model.
Where does artificial intelligence help
Quest
AI role
Who has the decision/approval?
Process tracking, pattern marking
Generating alerts
Compliance analyst examines
Name/sanction/PEP screening
Match candidate
Compliance officer confirms
Customer file summary
Summary draft
Analyst confirms
Risk profile draft
Classification draft
Confirms compliance
STR text draft
text draft
Authorized compliance officer decision/signature
Produces model pre-screening and drafting each line; The decision to report suspicious transactions rests with the authorized compliance officer.
False match problem
This is where name scanning produces the most common errors. There are thousands of people named "Mehmet Yılmaz"; A "Mehmet Yılmaz" on the sanctions list and your customer do not have to be the same person. This is called false positive match. The compliance officer must confirm the match with additional identifiers such as date of birth, nationality, identification number, etc. Both mistakes are serious: declaring an innocent customer sanctioned and missing a real match. Therefore, the decision is up to the person.
Note: "The model matched" does not mean "the person is the one". Declaring a customer as sanctioned by mistake not only causes serious harm to that person but also puts the bank at legal risk. The match is always confirmed with additional identifiers.
Four copyable templates
1) Process pattern pre-evaluation:
Your role: Assistant to the AML analyst who PREPARES the review. Sentencing. Series of anonymous transactions: [6 separate deposits of 9,800 TL in 10 days, different ATMs]. Task: What known laundering patterns (structuring, rapid entry-exit, etc.) might this series be similar to? Attribute every similarity to data; do not cast a "questionable verdict"; List the questions to review.
2) Name match confirmation checklist:
A customer name matched an enforcement/PEP list. List additional identifiers and steps the compliance officer should check to rule out a FALSE MATCH. Do not judge; Generate only the confirmation question set. (For example: date of birth, nationality, ID number, address overlap.)
3) Customer file summary (KYC review):
Your role: KYC file summary assistant. Add new information BASED on the anonymous file notes I gave you. Task: produce an orderly, neutral summary of the client risk assessment; mark any ambiguous or missing points as "[confirmation required]". The compliance officer will make the risk class decision.
4) STR text draft:
Your role: assistant who DRAFT suspicious transaction reporting.Base only on verified findings, do not add speculation. Explain in neutral, factual language why the transaction is considered suspicious. The final notification decision and signature belong to the authorized compliance officer; This is a draft. Findings: [verified transaction and observation notes]
Weak prompt / Strong prompt
Weak prompt:
Decide if this customer is suspicious, do I need to do STR? If the name matches the list, consider sanctioned directly.
It requires legal judgment from the model, ignores mismatch, and does not establish an audit trail.
Powerful prompt:
Your role: assistant providing pre-screening and drafting to the compliance analyst, not decision maker. Itemize transaction patterns for similarity to known risks; Connect each item to data. Consider the name match a "candidate" and generate confirmation questions with additional identifiers. STR provision and signature belong to the authorized compliance officer. Mark the uncertainties.
The strong request positions the pre-qualifier as a draft, takes the mismatch into account, and leaves the decision to the official.
three mini cases
Case 1 — Configuration is captured. The model indicates 7 deposits in the range of 9,500-9,900 TL to an account from different branches in 8 days; all just below the reporting threshold. The analyst reviews it, finds that it is incompatible with the client's declared activity, and the authorized compliance officer verifies and approves the STR draft. The model pre-qualified, the decision was made humanely.
Case 2 — Incorrect match is eliminated. Screening matches a customer with a name on the sanctions list. The compliance officer compares the date of birth and nationality: they do not match. This is a mismatch; The record is deducted without causing any harm to the customer. If it were automatically marked as "sanctioned", an innocent person would be seriously harmed.
Case 3 — Risk of over-automation. One team proposes to automatically convert all alerts produced by the model into STR without ever reviewing them. This is rejected: not only are most alerts false positives, but an unjustified, audit-trailless notification flow is indefensible both before MASAK and in law. The process is rebuilt with human review and an audit trail.
Why the audit trail is the backbone of AML
In AML, it is as important to make a notification as to be able to show why you made that notification (or why you did not make it). When the auditor came years later he said "you saw this warning, why didn't you do STR?" he may ask; Your answer must be recorded and justified. That's why every step in the AML process leaves a trace:
- Record of the alert: Which rule/model marked which action, with which score.
- Record of the review: What did the analyst look at, what additional information did he collect, was there contact with the customer?
- Justification for the decision: STR was/was not done and why; who approved it?
AI can quickly produce drafts of these records; but the accuracy and completeness of the record is the responsibility of the compliance officer. The situation of "We made the decision but did not write down why we made it" is the most untenable position in AML.
Tip: A good audit trail is based on the note made at the time of the decision, not the "I'll remember it later" assumption. The passage of time erases the details; Record the reasoning simultaneously with the decision. This is vital for both legislation and self-protection.
Common mistakes
- Making the model dominant. Converting the alert to automatic STR; STR is a legal decision, it belongs to the compliance officer.
- Ignoring the wrong match. Considering the customer as sanctioned without confirming the name similarity.
- Disclosing suspicion to the customer. Saying "There is suspicion of laundering against you" (tipping-off); It is prohibited in most legislation.
- Not leaving an audit trail. Failure to document the rationale for the warning, review and decision.
- Bypassing the real beneficiary. Completing KYC without verifying the actual owner of the fund.
Attention: A deficiency in the AML/KYC field may be revealed in the audit years later and may impose a heavy administrative fine on the bank. Therefore, every decision must be reasoned, recorded and human-approved; "The system failed" is not an excuse.
In summary
KYC recognizes the customer and the source of funds, AML monitors transactions and identifies the suspect; Notification is made to MASAK via STR. AI is a powerful pre-screener in transaction monitoring, screening, and case summary, but STR and enforcement judgment rests with the authorized compliance officer. False matches are eliminated with additional identifiers, the audit trail is maintained at every step, no suspicion is disclosed to the customer. In one sentence: AI highlights suspect; The authorized officer makes the notification and compliance decision.
Application task
Define an anonymous series of transactions (such as multiple subthreshold deposits) and pre-evaluate the pattern with pattern 1. Then create a name match scenario and produce a confirmation checklist with the 2nd template and write down your decision when the date of birth/nationality does not match. Finally, produce a STR draft with the 4th template and check it for speculation; Note who has the final decision.
checklist
- [ ] I treated the warning as a pre-emptive one; I did not convert it to automatic STR.
- [ ] I confirmed the name match with additional identifiers (mismatch check).
- [ ] In KYC, I observed the real beneficiary and source of funds.
- [ ] I did not disclose the suspicion to the customer (tipping-off ban).
- [ ] I recorded the rationale and audit trail of each step.
- [ ] I left the STR/compliance provision to the authorized officer.