KYC and AMLA alerts: AI sorting of complete files and those that need an analyst

How a bank, an asset manager or a firm can lighten its compliance workload: an AI model checks the completeness of KYC files and ranks alerts by priority, with decisions remaining human.

By houle Team

Published on 10/07/2026

Reading time: 9 min (1707 words)

KYC and AMLA alerts: AI sorting of complete files and those that need an analyst

In brief. A bank, an asset manager or a firm subject to the Anti-Money Laundering Act (AMLA) can lighten its compliance workload by giving an AI model a preparatory job: checking that a client onboarding file is complete and consistent, and ranking alerts by priority with a summary of the useful elements. Complete files with no warning signal move faster; the others reach the analyst already documented. The model closes no alert, accepts no client and decides on no reporting: these decisions remain human.

This article describes an illustrative scenario. It is not a named client and we give no quantified results.

The problem: analysts drowning in formal checks

In this scenario, two tasks weigh on the compliance department.

The first is checking files at client onboarding: is the identity document legible and valid, is the form on the beneficial owner signed, do the names match from one document to another, is the evidence of the origin of funds attached? Some of the back-and-forth with advisers can come from a missing document or an inconsistency of form.

The second is handling the alerts produced by screening and monitoring tools. Some may turn out to be groundless after checking (a proportion to be measured during the pilot), but each must be examined and documented.

In both cases, qualified analysts spend time on verification work, at the expense of actual risk analysis.

The process before and after

Before. The analyst opens each file and each alert in order of arrival, gathers the information from several systems, checks, documents and decides.

After, for onboarding files.

  1. The model reads the documents and checks the institution's checklist: documents present, signatures, validity dates, consistency of names, dates of birth and addresses.
  2. It notes inconsistencies between documents and elements that need clarification.
  3. A complete and consistent file is passed to the analyst marked "formal check passed". An incomplete file is returned to the adviser with the precise list of what is missing, before it even occupies compliance.

After, for alerts.

  1. The model gathers the context: client profile, history, previous alerts and their outcome.
  2. It proposes a priority level and writes a summary with the points for and against.
  3. The analyst handles alerts in order of priority, from a file that is already prepared. They decide and sign.

The rules belong to the institution

ElementThe model can prepareDecision reserved to a person
Completeness of the fileCheck the checklist, list missing documentsAccept an exception or a replacement document
Consistency of documentsNote differences in name, date, addressAssess whether the difference is explained
Beneficial ownerCheck that the form is present and consistentAssess the plausibility of the structure
Origin of fundsCheck that evidence is attached and matches the account givenJudge whether the explanation is plausible
Match against a listGather the elements of comparisonConfirm or rule out the match
Transaction alertPropose a priority, summarise the contextClose the alert, request clarification
Heightened riskFlag the criteria defined by the institutionClassify the relationship, decide whether to open or continue
SuspicionNothingAny assessment of a suspicion and any reporting

Two hard rules complete the table. First, certain situations are never downgraded by the model: politically exposed person (PEP), possible match against a sanctions list, a country or sector classed as high-risk by the institution, a complex structure. Second, the proposed priority never delays an alert: it changes the order of the queue, not the internal handling deadlines.

Human in the loop

  • Each alert is closed by an analyst, who validates or corrects the summary before signing.
  • Sample checks of files marked "formal check passed" and of alerts ranked low priority.
  • Four-eyes review maintained where the institution already provides for it.
  • A compliance owner designated for the checklists, criteria and thresholds.
  • Feedback loop: cases where the analyst contradicts the model are reviewed at regular intervals.

Audit trail and explainability

For each file and each alert, the system keeps the version of the checklist, the model version, the documents read, the discrepancies noted, the priority proposed, the analyst's decision and its reason. The summary cites the documents it relies on, so that the analyst can verify each statement in one click.

This is also what the supervisory authority expects. In its Guidance 08/2024, FINMA expects institutions to identify, assess, manage and monitor appropriately the risks linked to AI, and cites in particular the robustness, accuracy, explainability and bias of models, the quality and security of data, and dependence on third parties.

Errors: which ones, and who bears them

  • Relevant alert ranked low priority. This is the most serious error. It is limited by the hard rules, by the fact that no alert is closed without an analyst, and by sample checks. Responsibility remains entirely that of the institution: using a tool does not shift it.
  • Groundless alert ranked high priority. The cost is analyst time, as today.
  • Inconsistency not noted in a file. It can still be seen by the analyst, who remains responsible for acceptance.
  • Inaccurate summary. A model can state something the documents do not say. Systematic citation of sources and validation by the analyst are the safeguards.

Legal framework: a few reference points

To be validated by your legal department and your compliance function:

  • Duties of due diligence. Art. 6 of the Anti-Money Laundering Act (AMLA) requires the financial intermediary to identify the purpose and nature of the business relationship, the extent of the information depending on the risk, and to clarify the background of a transaction or a relationship, in particular where they appear unusual or involve a heightened risk. Relationships with politically exposed persons abroad are deemed to involve a heightened risk in all cases.
  • Duty to report. Art. 9 AMLA requires the Money Laundering Reporting Office (MROS) to be informed immediately where there is a well-founded suspicion. No sorting step must delay this assessment, which remains human.
  • Lawyers and notaries. Art. 9, para. 2, AMLA subjects them to the duty to report only if they carry out a financial transaction for a client and the information is not protected by professional secrecy within the meaning of art. 321 of the Swiss Criminal Code.
  • Banking secrecy. Art. 47 of the Banking Act punishes the disclosure of a secret by an officer, employee or agent of a bank. The use of an external provider must be examined from this angle.
  • Data protection. The Federal Act on Data Protection (FADP) applies: subcontracting (art. 9), disclosure abroad (art. 16), impact assessment in case of high risk (art. 22).

These texts change. Check the version in force before relying on them.

Why an open-source model hosted in Switzerland suits this case

KYC files bring together the most confidential material an institution holds: identity, assets, origin of funds, sometimes data on criminal proceedings. A model run on the institution's infrastructure or in a data centre in Switzerland avoids sending this content to a model vendor and limits questions of secrecy and outsourcing.

Two other reasons matter. Stability: a model that does not change without your decision can be validated once, then revalidated at each version change, which corresponds to sound model risk management. And independence: FINMA cites dependence on third parties among the risks to be managed.

The formal checking task is well within reach of medium-sized open-source models (Llama, Mistral, Qwen or Gemma families). For alert summaries, quality must be verified closely on your own cases, in the languages of your files. Our decision guide details the criteria.

How a pilot runs and is measured

  1. Test on closed files and alerts, anonymised if necessary. The priorities proposed are compared with the actual outcomes.
  2. Parallel operation. The analysts work as usual; the model prepares in the background and the two are compared.
  3. Going live on a limited scope: one type of client or one category of alerts, with reinforced sample checks.
IndicatorWhat it measures
Files returned to the adviser before reaching complianceThe analyst time freed
Formal discrepancies found by the analyst and not noted by the modelThe reliability of the formal check
Relevant alerts ranked low priorityThe risk to keep at zero
Agreement between proposed priority and alert outcomeThe quality of the sorting
Summaries corrected by the analystThe reliability of the summaries
Handling time for priority alertsThe benefit for risk management
Onboarding time for a complete fileThe benefit for the client

Limits: when not to automate

  • The assessment of a suspicion and the decision to report.
  • The acceptance or refusal of a relationship.
  • Complex structures and relationships with heightened risk.
  • Situations where the checklist is not stabilised or varies from one team to another.
  • Documents in languages or scripts that the model reads poorly.

Frequently asked questions

Can the model close groundless alerts? In the scheme we recommend, no. It prepares and ranks. Closure is decided and signed by an analyst.

Does it replace our screening tool? No. It comes after, on the alerts the tool produces and on the documents in the file.

Does the supervisory authority accept this type of tool? FINMA does not prohibit the use of AI; it expects appropriate governance and risk management. Responsibility remains that of the institution.

Can a small organisation benefit from it? Yes for the formal checking of files, which pays for itself quickly. Sorting alerts requires sufficient volume.

What happens to the test data? It stays on the infrastructure defined for the pilot, with a retention period set in advance.

Going further

See our KYC monitoring and compliance solution and the same scheme applied to small insurance claims or to minor liability claims at a hospital.

Our AI consulting starts with a discovery workshop with your compliance team. Contact us to talk about it.


References

Questions about this article?

Our experts are here to help you understand the details and implications for your business. Get personalized advice tailored to your situation.