A truly risk-based approach
Weighted factors, impact × likelihood, and due diligence levels derived from a methodology you configure and can justify.
End-to-end anti–money laundering and terrorist financing prevention — with AI as your copilot, not a black box.
For most obligated entities, AML/CFT compliance still lives in scattered spreadsheets, paper forms, and criteria no one can reconstruct. The cost isn't the duplicated work: it's the examination findings and the reputational damage that follows.
| Today | With MappRisk Compliance |
|---|---|
| Risk matrices in Excel, with no versioning or audit trail. | An immutable, versioned matrix per customer, time-stamped. |
| Paper-based KYC, with the same data re-entered at every stage. | A single digital file that feeds KYC → matrix → watchlists → report. |
| Watchlist searches with no auditable record. | Every query retained for ten years, in line with FATF Recommendation 11. |
| Weights and risk levels assigned "because that's how it's always been." | A documented, configurable risk-based approach, with its rationale. |
| A single user captures, assesses, and approves. | Segregation of duties by design, in line with FATF Recommendation 18. |
The difference isn't having a system instead of files. It's that evidence is produced as you work, not when the examination arrives.
Weighted factors, impact × likelihood, and due diligence levels derived from a methodology you configure and can justify.
Every matrix, every watchlist search, and every action is kept as an immutable record, exportable to PDF with an institutional template.
A direct query to LexisNexis Bridger: sanctions, politically exposed persons, adverse media, and relationship networks, linked to the customer's risk matrix.
Artificial intelligence proposes weights and levels and shows its reasoning. The Compliance Officer decides — and that decision goes into the audit trail.
Banks, brokerage firms, finance companies, and DNFBPs, each with their own catalogs and rules — with full isolation between entities.
In the traditional model, each stage lives in a different tool: the Know Your Customer form on paper, the matrix in Excel, the watchlist search in a separate portal, and the report assembled by hand. No one can prove the four are about the same customer.
In MappRisk Compliance, a single file moves through the whole cycle. What's captured in Know Your Customer feeds the matrix; the matrix determines the due diligence level; the watchlist screening is linked to the file; and the report comes from it.
Each stage leaves its own time-stamped evidence. The file isn't reconstructed afterward: it's built as you work.
Digitizes intake and turns it into queryable data, not a loose PDF.
The heart of the risk-based approach, configurable by the Compliance Officer.
The central evidence of the risk-based approach: immutable, versioned, and defensible.
Screening against international and local watchlists, with an auditable record of each query.
From calculation to decision, with dual control and mandatory notes.
Risk observability and preparation of regulatory filings.
The risk-based approach made concrete as a transparent, documented, reproducible formula. Every weight, every level, and every threshold is configurable — and therefore justifiable.
risk = impact × likelihood
On a scale from 1 to N², according to the entity's active methodology.
weighting = (risk ÷ N²) × 100
Normalizes the value to a common scale, independent of the matrix size.
contribution = weighting × (weight% ÷ 100)
Each factor contributes according to the weight the entity assigned and justified.
AML/CFT score = Σ contributions
Calculated on the server, with a breakdown by factor and an audit trail for each component.
Illustrative values. Factors, their weights, and the scale are defined by each entity in its approved methodology.
It doesn't enter the weighting: it acts as a trigger. Once confirmed, it forces enhanced due diligence regardless of the score obtained.
Low-risk customers according to the entity's methodology, with proportionate information requirements.
The standard level of knowledge and monitoring applicable to most of the portfolio.
High risk or politically exposed person status. Reinforced requirements and approval by a higher authority.
Searching for a customer on an external portal and saving a screenshot is not defensible evidence. In MappRisk Compliance the query runs from the platform, is linked to the customer's file, and is retained with all its results.
The integration with LexisNexis Bridger Insight XG covers international sanctions, politically exposed persons, adverse media, relationship networks, and state-owned enterprises.
Profile, identity documents with their issuer, addresses, aliases, political positions with term and status, biography, and sources.
Who searched, for whom, when, and what was found. Retained in line with FATF Recommendation 11.
Each match is presented with its similarity score and its classification by category, so the analyst can dismiss or escalate with sound judgment.
Artificial intelligence in MappRisk Compliance does not make regulatory decisions or approve matrices. It eliminates the blank slate and the transcription work, so the team can spend its time on judgment — the one thing that can't be automated.
Every piece of reasoning generated by the AI is retained. If the officer adjusts a suggestion, the change is recorded as their decision. Nothing is approved on its own.
The model suggests the weighting of factors by party type, accompanied by its reasoning. The officer approves or adjusts it.
Recommended impact and likelihood with AML/CFT calibration judgment, consistent with the active methodology.
The AI draws on the country, the applicable regulations, and the document library the entity uploads: GAFILAT typologies, manuals, and internal policy.
The proof that a compliance program works isn't the screen — it's the document you can hand over when the request arrives.
An immutable record with the full breakdown of factors, weights, and score, in PDF with an institutional template.
Detail of matches, similarity scores, and sources queried, with date and user.
Risk matrix and watchlist results brought together in a single document.
Who did what and when, by entity, on each file and each due diligence decision.
By sector, risk level, amount, politically exposed person status, or any dimension of the file.
Structured case data ready for preparing the report to the Financial Analysis Unit (UAF).
In compliance, the separation of duties is not an organizational preference: it's a requirement. The platform enforces it in access control, so that whoever onboards a customer cannot be the one who approves their risk level, unless the entity's policy so provides.
Predefined rolesEach role is defined on a configurable permissions matrix. The predefined roles are a starting point, not a straitjacket.
Each obligated entity operates with its data fully separated. No user can see information from another entity.
Two-factor authentication by email, configurable inactivity logout, and federated sign-in with Microsoft.
Every sensitive action is recorded in an unalterable way, with user, date, and affected object.
Evidence is not deleted. Users with history are blocked rather than removed, to preserve the audit trail.
Compliance isn't added at the end: the data structure, the catalogs, and the reports come straight from the regulation.
Adaptable to other money laundering prevention frameworks in Latin America, for entities operating in several countries.
Each sector receives its own specific catalog of factors, with a regulatory reference and its own calibration. There's no need to reimplement the platform for each type of obligated entity.
Supervised by the Superintendencia de Bancos, with their own Know Your Customer and reporting obligations.
Under the regime of the Superintendencia del Mercado de Valores, with the particularities of the investor client.
With the factor catalog and designated operations specific to the insurance sector.
The most diverse group of obligated entities, each with its own designated operations and specific thresholds.
Calibrating AML/CFT judgment with the Compliance Officer is the phase that decides whether the platform helps or gets in the way. That's why it's a phase, and not an assumption.
Sector, obligations, and risk profile of the obligated entity.
Factors, weights, methodology, and risk levels.
Branches, users, roles, and permission scheme.
Provisioning and testing of watchlist screening.
Validation of AML/CFT judgment together with the Compliance Officer.
Onboarding, matrices, and screenings in production.
Support and continuous tuning of the model during operation.
An AML/CFT program that's auditable, defensible, and in real operation.
Yes. Each entity operates with strict isolation of its information: no user can access another company's data. Access control is by role and by entity, with two-factor authentication and an unalterable audit log of all actions.
No. The AI suggests weights and levels accompanied by its reasoning, but the regulatory decision is always made by the Compliance Officer. If they adjust a suggestion, the change is recorded as their decision and remains in the file's audit trail.
Yes. Matrices and watchlist reports are exported as PDFs with an institutional template, and analytical data is exported from the reports. The information belongs to the entity; the conditions for its return at the end of service are set out in the contract.
Yes. The manual matrix editor lets you calculate and file customer risk without using the intake wizard, and those matrices are indistinguishable from the rest for reporting purposes. Watchlist screening integrates the same way.
Watchlist searches and risk matrices are retained in accordance with the regulatory requirement, for a minimum of ten years under FATF Recommendation 11. Evidence is not deleted: users with history are blocked rather than removed, so as not to break the audit trail.
The platform automatically rescales the elements when the matrix dimension changes, and matrices already issued keep the methodology they were calculated with. History is not altered retroactively, which is exactly what a supervisor expects to find.
Built on Ley 155‑17, its implementing decree, and real supervisory practice — not adapted from a product designed for another jurisdiction.
Everything the platform does generates the proof the regulator will ask for later. There's nothing to reconstruct, because nothing was done outside the file.
Banks, brokerage firms, finance companies, and DNFBPs share the same risk engine, with catalogs and calibration specific to each sector.
Productivity without sacrificing regulatory validity: every suggestion comes with its reasoning, and every decision has a name behind it.
We'll show you the platform with your sector's factor catalog and your own risk methodology, not a generic example.