AML risk scoring · KYC onboarding

Score every client.
Defend every decision.

Documented, defensible AML risk assessments for financial services firms — scored, evidenced, and ready for examination.

FATF-alignedMLR 2017CSSF 24-847AMLA-ready
Live risk preview
1.3 Low
LowMedium-LowMedium-HighHigh
A UK national — clean on paper. The weighted score sits Low.
Every score cited to a regulator Screening audit trail MLRO sign-off workflow Tenant-isolated by design
The problem

“Who approved this client, and on what basis?”

When a regulator asks, most firms can't answer quickly — because onboarding lives in spreadsheets, inboxes, and individual judgement.

01

Inconsistent

The same client scores differently depending on who assessed them. No two analysts weight risk the same way.

02

Indefensible

No record of why a decision was made, or which methodology applied at the time. An audit becomes an archaeology dig.

03

Under pressure

AMLA's single rulebook is arriving. Undocumented, bespoke processes are on the wrong side of it.

The platform

One defensible path from onboarding to decision

Risk scoring engine

A graduated, FATF-aligned score across nine weighted factors — with overrides for the risks that can't be diluted.

Explore the platform

Screening & disposition

Sanctions, PEP and adverse-media screening with every hit dispositioned on a permanent record.

See screening in action

Regulatory defensibility

Every score mapped to its basis in FATF, MLR 2017, CSSF 24-847 and the AMLA Regulation.

Read the evidence

See it on a real onboarding

A 20-minute walkthrough with your own scenarios — scored, screened, and exported as a regulator-ready record.

The platform

Risk decisions, engineered.

A five-step assessment that scores each client against a documented, FATF-aligned methodology — and produces a record built to survive examination.

Live, weighted risk scoring

A graduated score across nine factors, grouped by FATF risk category — with hard overrides and floors for risks that must never be averaged away.

  • Geographic 40% · Customer 40% · Product 20%
  • Material sanctions and confirmed PEPs force the rating
  • The rating updates live as the analyst works

Structured AI analysis

An on-demand, section-by-section breakdown of every risk factor — with a clear CDD recommendation an MLRO can review in minutes.

  • Geographic, customer, product, screening, ownership
  • The platform makes the case; a human owns the decision
  • Persisted to the signed record

Governance built in

Analyst to compliance review to MLRO sign-off — enforced automatically on every High-rated relationship, with roles and permissions throughout.

  • MLRO sign-off required on High ratings
  • Versioned methodology, reconstructable years later
  • Multi-tenant with row-level data isolation

Regulator-ready output

A complete assessment record assembled as the analyst works — rating, factor breakdown, screening history, ownership register, and sign-off chain.

  • Full factor-by-factor reconciliation to the score
  • Exportable PDF in a consistent house format
  • Tamper-evident, hash-chained audit trail
The workflow

The platform makes the case. A human owns the decision.

Step 01

Assess

An analyst completes the assessment; the engine scores it live against your methodology.

Step 02

Screen

Every party is screened; each hit is dispositioned with a rationale on the permanent record.

Step 03

Review & sign

Compliance reviews; the MLRO signs off — required automatically on every High-rated relationship.

Step 04

Defend

Export a regulator-ready record, versioned and reconstructable years later.

Built to be examined

Every capability above exists for one reason: so your firm can answer for its decisions, quickly and completely.

Screening

Every hit. Every disposition.
Permanently.

Screen every party against sanctions, PEP and adverse-media lists. Try it below — this is the same flow your analysts use in the platform.

Screening demo Provider: integrated · not yet run
Entities (1)
Entity · United Kingdom
Awaiting run
Individuals (1)
Individual
Awaiting run
PEP
82% match
World-Check PEP list · listed 12/04/1968
Senior government official (Deputy Minister, 2015–present). Listed as a domestic PEP.
SCREENED  01/01/1950 MATCH  12/04/1968 DOB MISMATCH

Dispositions are recorded with the analyst, timestamp and rationale — and filed to a permanent register, exportable for audit.

Filed. Not forgotten.

Six months from now, nobody remembers a hit existed — let alone why it was discounted. Here, the hit, the reasoning, and the analyst are on the record permanently: a screening register organised by deal, exportable to CSV and PDF, backed by a tamper-evident audit trail.

Screening that survives scrutiny

See the full flow — screening, disposition, register, and export — on your own scenarios.

Defensibility

Every score, cited to a regulator

Every risk score maps to its basis in FATF Recommendations, MLR 2017, CSSF Circular 24-847 and the AMLA Regulation. Not a black box — a register an examiner can read.

Score 1 · LowListed / regulated entity — eligible for simplified diligenceFATF R.10 · MLR reg 37
Score 3 · Med-HighTrust — high-opacity vehicle, full controlling-person IDFATF R.25 · reg 28(4)
Score 4 · HighFATF Black List jurisdiction — automatic overrideFATF R.19 · UK OFSI
OverrideMaterial sanctions on any party — immediate HighFATF R.6 · reg 33
Score 3 · Med-HighComplex ownership — opacity multiplierFATF R.24 · CSSF §4.2

The whole model is surfaced live in-product — read from the scoring engine, never hardcoded — so documentation, display, and computation can never drift apart.

Weights sum to exactly 100%, verified live
Every rating floor tied to a named regulatory basis
Jurisdiction triggers applied uniformly — no country hardcoded
MLRO-owned methodology, reviewed and dated

An examiner doesn't have to trust the platform

They can read why. Ask for the methodology statement and the validation register in your demo.

AMLA & the EU single rulebook

Aligned with Europe's
new AML architecture.

The EU is harmonising anti-money-laundering supervision under a single rulebook and a new central authority. ComplyBase is built around the same principles — risk-based, documented, and proportionate.

2025

AMLA operational

The EU Authority for Anti-Money Laundering (AMLA) is established in Frankfurt and begins coordinating national supervisors.

2026

Standards & data

Technical standards are finalised and the supporting reporting framework applies from Q4 2026, ahead of the first selection round.

2027

Selection & rulebook

The first selection of directly-supervised entities begins, and the harmonised AML rulebook takes effect across the EU.

2028

Direct supervision

From 2028, AMLA directly supervises a tier of the most significant cross-border financial groups at group level.

Sources: AMLA · Direct-supervision standards (Jul 2026) · EBA reporting framework 4.3. Dates reflect the current published transition timeline.

What it means for you

Most firms will never see an AMLA examiner.

AMLA will directly supervise only a small tier of the largest cross-border groups. Until now, that supervision has rested entirely with national supervisors — and for the overwhelming majority of firms, it still will.

But the standard is harmonising. Your national regulator will hold you to the same risk-based, documented approach AMLA embeds. ComplyBase is how a firm meets that standard — without a big-bank compliance department.

300–400
cross-border groups directly supervised by AMLA
Everyone else
supervised nationally — to the same harmonised standard
Built on the same principles

How ComplyBase supports AMLA's direction

The single rulebook pushes every firm toward risk-based, harmonised, evidenced AML. That is precisely what ComplyBase was designed to deliver.

Harmonised methodology

AMLA's aim is consistent application of the same rules across the EU. ComplyBase applies one documented, FATF-aligned methodology to every assessment — no two analysts scoring the same client differently.

Risk-based approach

The rulebook is built on risk-based diligence. ComplyBase scores each client across weighted risk categories and tiers due diligence (SDD / CDD / EDD) to the outcome.

Proportionality

AMLA's standards are explicitly designed to be proportionate — detail scaling with risk. ComplyBase asks for enhanced information only where the risk profile warrants it.

Evidenced & auditable

Harmonised supervision depends on records that hold up under review. Every ComplyBase decision is documented, versioned, and reconstructable — with a tamper-evident audit trail.

Beneficial-ownership focus

Ownership transparency is central to the EU framework. ComplyBase captures UBO/SMO structures and weights ownership opacity as a first-class risk factor.

Ready to adapt

As AMLA's technical standards finalise through the transition, ComplyBase tunes its configurable methodology to match — a configuration change, not a re-engineering project.

ComplyBase is an independent product and is not affiliated with, endorsed by, or certified by AMLA or any regulator. The above describes how the platform's design aligns with the publicly stated principles of the EU AML framework.

Meet the standard before it meets you

A documented, versioned methodology that adapts to the technical standards as they finalise — configuration, not re-engineering.

Pricing

Straightforward plans that scale with your firm. Talk to us for a tailored quote.

Enterprise & partners

For larger firms and data partners — white-label deployment under your brand.

  • Everything in Launch
  • White-label & co-branded deployment
  • Your country-risk data as the scoring input
  • Tenant-isolated, multi-team environments
  • Methodology configuration & versioning
  • Priority support and onboarding
Contact sales

Not sure which fits?

Twenty minutes with your scenarios will answer it faster than a pricing table.