AML/CFT platform for obligated entities

MappRiskCompliance

End-to-end anti–money laundering and terrorist financing prevention — with AI as your copilot, not a black box.

KYC / CDDRisk matrix WatchlistsDue diligence UAF reportingAudit trail
412289 ACTIVE MATRICESHIGH RISKPEP AML/CFT SCORE BY FACTOR CustomerProduct ChannelGeographyTransactional RISK LEVEL 68 HIGH Enhanced due diligence
Contents

Everything this overview covers, at a glance.

The challenge

When the supervisor asks why you assigned that risk level, the Excel sheet has no answer.

For most obligated entities, AML/CFT compliance still lives in scattered spreadsheets, paper forms, and criteria no one can reconstruct. The cost isn't the duplicated work: it's the examination findings and the reputational damage that follows.

TodayWith MappRisk Compliance
Risk matrices in Excel, with no versioning or audit trail. An immutable, versioned matrix per customer, time-stamped.
Paper-based KYC, with the same data re-entered at every stage. A single digital file that feeds KYC → matrix → watchlists → report.
Watchlist searches with no auditable record. Every query retained for ten years, in line with FATF Recommendation 11.
Weights and risk levels assigned "because that's how it's always been." A documented, configurable risk-based approach, with its rationale.
A single user captures, assesses, and approves. Segregation of duties by design, in line with FATF Recommendation 18.

The difference isn't having a system instead of files. It's that evidence is produced as you work, not when the examination arrives.

Value proposition

Five ways MappRisk turns compliance into a living, defensible process.

A truly risk-based approach

Weighted factors, impact × likelihood, and due diligence levels derived from a methodology you configure and can justify.

Evidence ready for the regulator

Every matrix, every watchlist search, and every action is kept as an immutable record, exportable to PDF with an institutional template.

Integrated watchlist screening

A direct query to LexisNexis Bridger: sanctions, politically exposed persons, adverse media, and relationship networks, linked to the customer's risk matrix.

AI as a copilot, not a black box

Artificial intelligence proposes weights and levels and shows its reasoning. The Compliance Officer decides — and that decision goes into the audit trail.

Multi-sector from a single engine

Banks, brokerage firms, finance companies, and DNFBPs, each with their own catalogs and rules — with full isolation between entities.

In one line

The rigor the Superintendency expects, with the agility of a fintech.

Scope

The complete AML/CFT program cycle, without re-entering a single data point.

In the traditional model, each stage lives in a different tool: the Know Your Customer form on paper, the matrix in Excel, the watchlist search in a separate portal, and the report assembled by hand. No one can prove the four are about the same customer.

In MappRisk Compliance, a single file moves through the whole cycle. What's captured in Know Your Customer feeds the matrix; the matrix determines the due diligence level; the watchlist screening is linked to the file; and the report comes from it.

Each stage leaves its own time-stamped evidence. The file isn't reconstructed afterward: it's built as you work.

Know Your Customer Risk assessment Customer risk matrix Watchlist screening Due diligence Reporting and analytics Identification, profiling, PEP. Factors, weights, and AML/CFT score. Immutable, versioned record. Sanctions, PEP, and adverse media. Simplified, standard, or enhanced. Dashboards, pivots, and UAF filing.
Modules and features

Six modules covering everything from customer onboarding to examination evidence.

MODULE 01

Onboarding and Know Your Customer

Digitizes intake and turns it into queryable data, not a loose PDF.

  • Dynamic forms by party type (individual or legal entity) and by sector
  • A catalog of 248 countries compliant with the ISO 3166‑1 standard
  • ISIC Rev. 4 economic activities with an AML/CFT high-risk flag
  • Provinces and smart cascading between related fields
  • A regulatory-style PEP questionnaire: directly exposed or exposed through association
  • Auto-classification that forces enhanced due diligence when warranted
  • An immutable record of each intake, for auditability
MODULE 02

AML/CFT Risk Engine

The heart of the risk-based approach, configurable by the Compliance Officer.

  • Risk factors by party type, with a percentage weight that adds up to one hundred
  • Elements scored by impact and likelihood
  • Sector-specific catalogs with a regulatory reference per factor
  • A methodology configurable as a 3×3, 4×4, or 5×5 matrix
  • Automatic rescaling of all elements when the methodology changes
  • Risk levels with editable label, range, and color
  • An AML/CFT score calculated on the server, with a breakdown by factor
MODULE 03

Customer Risk Matrix

The central evidence of the risk-based approach: immutable, versioned, and defensible.

  • An immutable record of each assessment: factors, weights, levels, score, and due diligence level
  • Versioning by document: one customer, one active matrix
  • Editing creates a new version and preserves the full history
  • A manual editor for entities with their own CRM that only need to calculate and file
  • Sales representative and branch details, plus the transaction amount and currency
  • A basis for aggregates and for preparing the Cash Transaction Report
  • A PDF report with an institutional template: cover page, summary sheet, and corporate header
MODULE 04

Watchlist Screening

Screening against international and local watchlists, with an auditable record of each query.

  • A direct query to LexisNexis Bridger Insight XG
  • International sanctions, politically exposed persons, and adverse media
  • Relationship networks and state-owned enterprises
  • Search of individuals or legal entities, filtered by entity type
  • A complete match profile: identity, documents, addresses, aliases, and positions held
  • Linking of the screening to the customer's risk matrix
  • A consolidated report: matrix and watchlists in a single document
  • Usage through annual allowances, with a quota shareable among related companies
MODULE 05

Due Diligence and Review

From calculation to decision, with dual control and mandatory notes.

  • Simplified, standard, and enhanced levels derived from the score
  • Automatic escalation for politically exposed persons or high risk
  • An officer review workflow: approve, reject, or refer
  • Mandatory notes and an audit log of each decision
  • Configurable approval for matrices created by the sales representative
  • Dual control in line with FATF Recommendation 18, or self-approval per policy
  • In-platform and email notifications, with the PDF attached on approval
MODULE 06

Reports, Analytics, and Dashboards

Risk observability and preparation of regulatory filings.

  • An AML/CFT dashboard with the entity's real data
  • Active matrices, high risk, enhanced due diligence, politically exposed persons, and items pending review
  • Screenings performed and trends over time
  • A panel of FATF and GAFILAT lists, with the blacklist and grey list
  • Analytical reports that pivot the matrices by any dimension
  • Country, activity, branch, representative, or amount range, with chart, table, and export
  • A catalog of reports by sector with the designated operations of each subsector
  • A history of each customer's risk evolution over time
Risk engine and methodology

The supervisor doesn't ask what risk you assigned. They ask why.

The risk-based approach made concrete as a transparent, documented, reproducible formula. Every weight, every level, and every threshold is configurable — and therefore justifiable.

Step 01 · Inherent risk of the element risk = impact × likelihood

On a scale from 1 to N², according to the entity's active methodology.

Step 02 · Weighting of the selection weighting = (risk ÷ N²) × 100

Normalizes the value to a common scale, independent of the matrix size.

Step 03 · Contribution to the score contribution = weighting × (weight% ÷ 100)

Each factor contributes according to the weight the entity assigned and justified.

Result AML/CFT score = Σ contributions

Calculated on the server, with a breakdown by factor and an audit trail for each component.

Score composition CustomerProduct ChannelGeographyTransactional 30%20% 20%20%10% AML/CFT score 68 · High

Illustrative values. Factors, their weights, and the scale are defined by each entity in its approved methodology.

Outside the summation

Politically exposed person status

It doesn't enter the weighting: it acts as a trigger. Once confirmed, it forces enhanced due diligence regardless of the score obtained.

Due diligence levels

Simplified

Low-risk customers according to the entity's methodology, with proportionate information requirements.

Standard

The standard level of knowledge and monitoring applicable to most of the portfolio.

Enhanced

High risk or politically exposed person status. Reinforced requirements and approval by a higher authority.

Watchlist screening

Screening against watchlists, with proof that it was done.

Searching for a customer on an external portal and saving a screenshot is not defensible evidence. In MappRisk Compliance the query runs from the platform, is linked to the customer's file, and is retained with all its results.

The integration with LexisNexis Bridger Insight XG covers international sanctions, politically exposed persons, adverse media, relationship networks, and state-owned enterprises.

Complete match profile

Profile, identity documents with their issuer, addresses, aliases, political positions with term and status, biography, and sources.

Ten-year audit trail

Who searched, for whom, when, and what was found. Retained in line with FATF Recommendation 11.

Categories queried Customer screened International sanctions Politicallyexposed Relationshipnetworks State-owned enterprises Adversemedia Locallists

Each match is presented with its similarity score and its classification by category, so the analyst can dismiss or escalate with sound judgment.

Applied artificial intelligence

The AI proposes. The Compliance Officer decides.

Artificial intelligence in MappRisk Compliance does not make regulatory decisions or approve matrices. It eliminates the blank slate and the transcription work, so the team can spend its time on judgment — the one thing that can't be automated.

Every piece of reasoning generated by the AI is retained. If the officer adjusts a suggestion, the change is recorded as their decision. Nothing is approved on its own.

Assisted weight distribution

The model suggests the weighting of factors by party type, accompanied by its reasoning. The officer approves or adjusts it.

Suggested levels per element

Recommended impact and likelihood with AML/CFT calibration judgment, consistent with the active methodology.

Your own regulatory context

The AI draws on the country, the applicable regulations, and the document library the entity uploads: GAFILAT typologies, manuals, and internal policy.

Deliverables

What your AML/CFT program can present in an examination.

The proof that a compliance program works isn't the screen — it's the document you can hand over when the request arrives.

Customer risk matrix

An immutable record with the full breakdown of factors, weights, and score, in PDF with an institutional template.

Watchlist screening report

Detail of matches, similarity scores, and sources queried, with date and user.

Consolidated report

Risk matrix and watchlist results brought together in a single document.

Action audit log

Who did what and when, by entity, on each file and each due diligence decision.

Analytical and aggregate reports

By sector, risk level, amount, politically exposed person status, or any dimension of the file.

STR and CTR preparation

Structured case data ready for preparing the report to the Financial Analysis Unit (UAF).

Security, governance, and audit trail

Trust infrastructure, built in — not bolted on.

In compliance, the separation of duties is not an organizational preference: it's a requirement. The platform enforces it in access control, so that whoever onboards a customer cannot be the one who approves their risk level, unless the entity's policy so provides.

Predefined roles
Compliance Officer Deputy Officer Analyst Auditor Senior Management Sales Representative Administrator

Each role is defined on a configurable permissions matrix. The predefined roles are a starting point, not a straitjacket.

Isolation between entities

Each obligated entity operates with its data fully separated. No user can see information from another entity.

Reinforced authentication

Two-factor authentication by email, configurable inactivity logout, and federated sign-in with Microsoft.

Immutable audit log

Every sensitive action is recorded in an unalterable way, with user, date, and affected object.

Regulatory retention

Evidence is not deleted. Users with history are blocked rather than removed, to preserve the audit trail.

Regulatory alignment

Built on the Dominican framework and international standards.

Compliance isn't added at the end: the data structure, the catalogs, and the reports come straight from the regulation.

Dominican framework

Ley No. 155‑17 (AML/CFT law) Decreto No. 408‑17 (Decree No. 408‑17) UAF · STR and CTR

International standards

FATF · Recommendation 1Rec. 10 Rec. 11Rec. 12Rec. 18 Rec. 20Rec. 22/23Rec. 24/25 GAFILAT · Regional typologies

Sector supervisors

Superintendencia de Bancos (Superintendency of Banks) Superintendencia del Mercado de Valores (Superintendency of the Securities Market) Superintendencia de Seguros (Superintendency of Insurance) DNFBP regulators

Adaptable to other money laundering prevention frameworks in Latin America, for entities operating in several countries.

Sectors served

A single engine, with catalogs and rules specific to each entity type.

Each sector receives its own specific catalog of factors, with a regulatory reference and its own calibration. There's no need to reimplement the platform for each type of obligated entity.

Financial intermediation entities

Supervised by the Superintendencia de Bancos, with their own Know Your Customer and reporting obligations.

Commercial banksSavings and loanCredit corporationsFinance companies

Securities market

Under the regime of the Superintendencia del Mercado de Valores, with the particularities of the investor client.

Brokerage firmsFund managersSecuritization companies

Insurance

With the factor catalog and designated operations specific to the insurance sector.

InsurersIntermediaries

Designated non-financial businesses and professions

The most diverse group of obligated entities, each with its own designated operations and specific thresholds.

Vehicle dealersConstruction companiesReal estate companies JewelersNotaries and lawyersNGOs and nonprofitsPolitical parties
Guided implementation

A collaborative process, not software that's handed over and forgotten.

Calibrating AML/CFT judgment with the Compliance Officer is the phase that decides whether the platform helps or gets in the way. That's why it's a phase, and not an assumption.

PHASE 01

Discovery

Sector, obligations, and risk profile of the obligated entity.

PHASE 02

Configuration

Factors, weights, methodology, and risk levels.

PHASE 03

Catalog loading

Branches, users, roles, and permission scheme.

PHASE 04

Watchlist setup

Provisioning and testing of watchlist screening.

PHASE 05

Calibration

Validation of AML/CFT judgment together with the Compliance Officer.

PHASE 06

Go-live

Onboarding, matrices, and screenings in production.

PHASE 07

Ongoing support

Support and continuous tuning of the model during operation.

OUTCOME

A living program

An AML/CFT program that's auditable, defensible, and in real operation.

Frequently asked questions

What people ask us before deciding.

Is my data isolated from that of other customers?

Yes. Each entity operates with strict isolation of its information: no user can access another company's data. Access control is by role and by entity, with two-factor authentication and an unalterable audit log of all actions.

Does the artificial intelligence make compliance decisions?

No. The AI suggests weights and levels accompanied by its reasoning, but the regulatory decision is always made by the Compliance Officer. If they adjust a suggestion, the change is recorded as their decision and remains in the file's audit trail.

Can I export my evidence?

Yes. Matrices and watchlist reports are exported as PDFs with an institutional template, and analytical data is exported from the reports. The information belongs to the entity; the conditions for its return at the end of service are set out in the contract.

Does it work if I already have my own CRM?

Yes. The manual matrix editor lets you calculate and file customer risk without using the intake wizard, and those matrices are indistinguishable from the rest for reporting purposes. Watchlist screening integrates the same way.

How long does the system retain the information?

Watchlist searches and risk matrices are retained in accordance with the regulatory requirement, for a minimum of ten years under FATF Recommendation 11. Evidence is not deleted: users with history are blocked rather than removed, so as not to break the audit trail.

What happens if I change the methodology midway?

The platform automatically rescales the elements when the matrix dimension changes, and matrices already issued keep the methodology they were calculated with. History is not altered retroactively, which is exactly what a supervisor expects to find.

Why MappRisk Compliance

Four reasons you notice during the examination, not during the demo.

01

Native to Dominican compliance

Built on Ley 155‑17, its implementing decree, and real supervisory practice — not adapted from a product designed for another jurisdiction.

02

Evidence by design

Everything the platform does generates the proof the regulator will ask for later. There's nothing to reconstruct, because nothing was done outside the file.

03

Multi-sector from a single engine

Banks, brokerage firms, finance companies, and DNFBPs share the same risk engine, with catalogs and calibration specific to each sector.

04

Explainable artificial intelligence, with a human in the loop

Productivity without sacrificing regulatory validity: every suggestion comes with its reasoning, and every decision has a name behind it.

Next step

Turn your AML/CFT program into a living, auditable, and defensible process.

We'll show you the platform with your sector's factor catalog and your own risk methodology, not a generic example.

OfficeSanto Domingo, Dominican Republic