Unit 6 / 11

Compliance, AML and KYC: Know Your Customer and Anti-Money Laundering AI

Gains:

  • Understand how AML (anti-money laundering) and KYC (know your customer) processes work and how artificial intelligence is used in transaction monitoring, scanning and file summary
  • Ability to use AI for suspicious transaction outline and customer risk profile summary, leaving the suspicious transaction reporting (STR) decision to the authorized compliance officer
  • Enforcement/PEP screening, mismatch, and ability to understand why compliance requires human oversight and maintain an audit trail

Banks don't just store money; It also holds the door to the financial system. Banks have legal obligations to prevent black money, terrorist financing and sanctioned funds from passing through this door. Two key processes enable this: KYC (Know Your Customer) is to verify who the customer is and the source of funds with which he or she is doing business; AML (Anti-Money Laundering) is to monitor transactions and identify suspicious ones. In Türkiye, the regulator of this field is MASAK (Financial Crimes Investigation Board) and banks are obliged to report suspicious transactions with suspicious transaction reporting (STR/SAR). AI is powerful at handling this massive volume of transaction monitoring, name scanning, and file summarization; But the STR decision is a decision that has legal consequences and belongs to the authorized compliance officer. The model produces a preliminary screening and a draft, it does not make decisions.

In this unit, we will see how AML/KYC works, how to use AI in transaction monitoring, screening and file summary, and why human oversight and audit trail is essential.

How KYC and AML work

  • KYC (customer recognition): Identity verification, identification of the real beneficiary (principal owner of the fund), risk classification. Tightened scrutiny applies to high-risk customers (e.g. PEP — Politically Exposed Person).
  • Transaction monitoring: Scanning the customer's transactions for known laundering patterns (smurfing — splitting large amounts into subthreshold parts, rapid entry and exit, unrelated account networks).
  • Screening: Comparison of names with sanctions lists and PEP lists.
  • Notification (STR): Notification to MASAK when the suspicion reaches a reasonable level.
Tip: In AML, the goal is not to "prove guilt" but to "report reasonable suspicion." The compliance officer is not a prosecutor; is obliged to evaluate the suspicion correctly and make the legal notification in a timely manner. This evaluation requires judgment and cannot be delegated to the model.

Where does artificial intelligence help

Quest

AI role

Who has the decision/approval?

Process tracking, pattern marking

Generating alerts

Compliance analyst examines

Name/sanction/PEP screening

Match candidate

Compliance officer confirms

Customer file summary

Summary draft

Analyst confirms

Risk profile draft

Classification draft

Confirms compliance

STR text draft

text draft

Authorized compliance officer decision/signature

Produces model pre-screening and drafting each line; The decision to report suspicious transactions rests with the authorized compliance officer.

False match problem

This is where name scanning produces the most common errors. There are thousands of people named "Mehmet Yılmaz"; A "Mehmet Yılmaz" on the sanctions list and your customer do not have to be the same person. This is called false positive match. The compliance officer must confirm the match with additional identifiers such as date of birth, nationality, identification number, etc. Both mistakes are serious: declaring an innocent customer sanctioned and missing a real match. Therefore, the decision is up to the person.

Note: "The model matched" does not mean "the person is the one". Declaring a customer as sanctioned by mistake not only causes serious harm to that person but also puts the bank at legal risk. The match is always confirmed with additional identifiers.

Four copyable templates

1) Process pattern pre-evaluation:

Your role: Assistant to the AML analyst who PREPARES the review. Sentencing. Series of anonymous transactions: [6 separate deposits of 9,800 TL in 10 days, different ATMs]. Task: What known laundering patterns (structuring, rapid entry-exit, etc.) might this series be similar to? Attribute every similarity to data; do not cast a "questionable verdict"; List the questions to review.

2) Name match confirmation checklist:

A customer name matched an enforcement/PEP list. List additional identifiers and steps the compliance officer should check to rule out a FALSE MATCH. Do not judge; Generate only the confirmation question set. (For example: date of birth, nationality, ID number, address overlap.)

3) Customer file summary (KYC review):

Your role: KYC file summary assistant. Add new information BASED on the anonymous file notes I gave you. Task: produce an orderly, neutral summary of the client risk assessment; mark any ambiguous or missing points as "[confirmation required]". The compliance officer will make the risk class decision.

4) STR text draft:

Your role: assistant who DRAFT suspicious transaction reporting.Base only on verified findings, do not add speculation. Explain in neutral, factual language why the transaction is considered suspicious. The final notification decision and signature belong to the authorized compliance officer; This is a draft. Findings: [verified transaction and observation notes]

Weak prompt / Strong prompt

Weak prompt:

Decide if this customer is suspicious, do I need to do STR? If the name matches the list, consider sanctioned directly.

It requires legal judgment from the model, ignores mismatch, and does not establish an audit trail.

Powerful prompt:

Your role: assistant providing pre-screening and drafting to the compliance analyst, not decision maker. Itemize transaction patterns for similarity to known risks; Connect each item to data. Consider the name match a "candidate" and generate confirmation questions with additional identifiers. STR provision and signature belong to the authorized compliance officer. Mark the uncertainties.

The strong request positions the pre-qualifier as a draft, takes the mismatch into account, and leaves the decision to the official.

three mini cases

Case 1 — Configuration is captured. The model indicates 7 deposits in the range of 9,500-9,900 TL to an account from different branches in 8 days; all just below the reporting threshold. The analyst reviews it, finds that it is incompatible with the client's declared activity, and the authorized compliance officer verifies and approves the STR draft. The model pre-qualified, the decision was made humanely.

Case 2 — Incorrect match is eliminated. Screening matches a customer with a name on the sanctions list. The compliance officer compares the date of birth and nationality: they do not match. This is a mismatch; The record is deducted without causing any harm to the customer. If it were automatically marked as "sanctioned", an innocent person would be seriously harmed.

Case 3 — Risk of over-automation. One team proposes to automatically convert all alerts produced by the model into STR without ever reviewing them. This is rejected: not only are most alerts false positives, but an unjustified, audit-trailless notification flow is indefensible both before MASAK and in law. The process is rebuilt with human review and an audit trail.

Why the audit trail is the backbone of AML

In AML, it is as important to make a notification as to be able to show why you made that notification (or why you did not make it). When the auditor came years later he said "you saw this warning, why didn't you do STR?" he may ask; Your answer must be recorded and justified. That's why every step in the AML process leaves a trace:

  • Record of the alert: Which rule/model marked which action, with which score.
  • Record of the review: What did the analyst look at, what additional information did he collect, was there contact with the customer?
  • Justification for the decision: STR was/was not done and why; who approved it?

AI can quickly produce drafts of these records; but the accuracy and completeness of the record is the responsibility of the compliance officer. The situation of "We made the decision but did not write down why we made it" is the most untenable position in AML.

Tip: A good audit trail is based on the note made at the time of the decision, not the "I'll remember it later" assumption. The passage of time erases the details; Record the reasoning simultaneously with the decision. This is vital for both legislation and self-protection.

Common mistakes

  • Making the model dominant. Converting the alert to automatic STR; STR is a legal decision, it belongs to the compliance officer.
  • Ignoring the wrong match. Considering the customer as sanctioned without confirming the name similarity.
  • Disclosing suspicion to the customer. Saying "There is suspicion of laundering against you" (tipping-off); It is prohibited in most legislation.
  • Not leaving an audit trail. Failure to document the rationale for the warning, review and decision.
  • Bypassing the real beneficiary. Completing KYC without verifying the actual owner of the fund.
Attention: A deficiency in the AML/KYC field may be revealed in the audit years later and may impose a heavy administrative fine on the bank. Therefore, every decision must be reasoned, recorded and human-approved; "The system failed" is not an excuse.

In summary

KYC recognizes the customer and the source of funds, AML monitors transactions and identifies the suspect; Notification is made to MASAK via STR. AI is a powerful pre-screener in transaction monitoring, screening, and case summary, but STR and enforcement judgment rests with the authorized compliance officer. False matches are eliminated with additional identifiers, the audit trail is maintained at every step, no suspicion is disclosed to the customer. In one sentence: AI highlights suspect; The authorized officer makes the notification and compliance decision.

Application task

Define an anonymous series of transactions (such as multiple subthreshold deposits) and pre-evaluate the pattern with pattern 1. Then create a name match scenario and produce a confirmation checklist with the 2nd template and write down your decision when the date of birth/nationality does not match. Finally, produce a STR draft with the 4th template and check it for speculation; Note who has the final decision.

checklist

  • [ ] I treated the warning as a pre-emptive one; I did not convert it to automatic STR.
  • [ ] I confirmed the name match with additional identifiers (mismatch check).
  • [ ] In KYC, I observed the real beneficiary and source of funds.
  • [ ] I did not disclose the suspicion to the customer (tipping-off ban).
  • [ ] I recorded the rationale and audit trail of each step.
  • [ ] I left the STR/compliance provision to the authorized officer.