Zum Hauptinhalt springen
European AML Compliance

AML Technology & Operations: turn AMLR requirements into working systems and delivery

Readiness does not rest on policy documents. It rests on the systems, data, workflows, case files and teams that perform due diligence, screening and monitoring every day.

S+P Compliance helps financial institutions translate AMLR requirements into an effective technology and operating model, connecting governance, customer due diligence platforms, screening, transaction monitoring, rulebook design, data quality, case management, testing and managed operations. The objective is not to make a platform technically live. It is to make your systems work as regulatory controls — on reliable data, with risk-based workflows, documented decision paths, effective escalation and evidence that holds up under review.

See our services

What you get

  • Target operating model for due diligence, screening and monitoring
  • Calibrated scenarios and thresholds with documented rationale
  • Data quality rules with named ownership per field
  • Operational capacity for reviews, alerts and backlog reduction
Article 26 AMLR Article 28 AMLR Article 10 AMLR Vendor independent Applies 10 July 2027

Audit-ready for BaFin and external auditors

Division of responsibilities

What S+P delivers

  • Functional specification, target process and data model
  • Rulebook, scenarios and thresholds prepared and calibrated
  • Test concept, test cases and support during functional acceptance
  • Data quality rules, error analysis and file remediation
  • Operational processing of due diligence, screening and alert work

What remains with the institution

  • Approval of material rules, models and changes
  • Technical configuration, development and system operation
  • Decisions on suspicious activity reports to the national FIU
  • Decisions on sanctions freezes and termination of relationships
  • Independent oversight by the control function and audit by the third line

S+P specifies, calibrates, tests and processes. Approval of the rulebook and any decision carrying reporting or freezing effect stays within your own governance and delegated authorities.

Why AMLR changes technology and operations

An institution can hold a fully compliant policy and still not be ready. What gets examined is not the text but the effect: whether customer records are current, whether scenarios fit the business model, whether hits are handled within deadlines and whether it can be shown why a case was closed.

AMLA’s draft guidance on ongoing monitoring under Article 26(5) AMLR points at two operationally intensive areas. The first is keeping customer documents, data and information current through periodic and event-driven reviews. The second is designing, implementing and testing a framework for monitoring transactions and activities. The guidance also expects monitoring outputs to be assessed and escalated effectively, and ongoing monitoring to stay integrated with customer due diligence rather than running beside it.

Both points land on the system layer — on data fields, workflows, rulebooks and evidence — and on the operating model behind them. Readiness therefore has to cover the architecture and the delivery capacity together, because a well-configured system still produces backlogs when nobody has the capacity to work it.

Typical challenges

Six findings that usually appear together.

Systems do not reflect the policy

The platform is live, but risk categories, review cycles, triggers for enhanced due diligence, ownership structures, screening workflows and escalation rules are not consistently configured. What the policy requires does not happen in the system.

Customer and ownership data is incomplete

Missing identification data, outdated ownership information, absent country attributes, unassigned risk classes and inconsistent account and transaction records all reduce the effectiveness of screening and monitoring directly.

Rulebooks are out of date

Scenarios, thresholds, indicators and customer profiles have not been reviewed, calibrated, tested or documented since implementation. The settings may still be reasonable, but the reasoning is no longer available.

Alert volumes overwhelm the team

High hit rates, unclear prioritisation, incomplete case files and missing investigation guidance create backlogs. Attention spreads evenly instead of concentrating on genuinely higher-risk cases.

Technology governance is fragmented

Regulatory requirement, functional specification, change request, release, test evidence, acceptance and operating documentation are managed separately rather than in one traceable process. Changes then happen without a recorded rationale.

Evidence is incomplete

It cannot be demonstrated why an alert was closed, a customer was rated, a review was completed or a scenario was amended. The decision may have been correct; the record does not carry it.

Our services

Eight building blocks, available individually or as one programme.

Target operating model

A model that ties systems, roles, data and controls into something that can actually be steered.

  • Target architecture for due diligence, screening, monitoring and case management
  • Roles for business, operations, compliance, technology, data and audit
  • Interfaces between first, second and third line
  • Process design for onboarding, reviews, alerts, escalation and remediation
  • Data model and data ownership framework
  • Access rights, approval limits and audit trail requirements
  • Service levels, quality assurance and metrics framework
  • Management reporting and evidence model
  • Interfaces with head office, EU parent and local entities

Customer lifecycle technology

Functional design and operation of the platform across the whole customer lifecycle.

  • Data model and mandatory fields for the customer file
  • Identification and verification workflows
  • Document collection, validation and evidence storage
  • Case management for standard and enhanced due diligence
  • Customer risk classification in the system
  • Review cycles and trigger event design
  • Event-driven refresh of customer information
  • Deadlines, reminders and follow-up workflows
  • Data migration, remediation, testing and functional acceptance

Beneficial ownership operations

Ownership and control data captured so that it actually reaches screening and case work.

  • Data model and documentation rules for ownership and control
  • Mapping of direct and indirect ownership
  • Documentation of ownership and control chains
  • Voting rights and control rights information
  • Register checks and discrepancy workflows
  • Review cycles and trigger events
  • Integration of ownership data into due diligence and screening
  • Evidence management and data quality controls
  • Managed operations for ongoing maintenance

Decisions on discrepancy reports to the national transparency register remain with the authorised function of the institution. S+P prepares and documents the case.

Screening technology and operations

From the screening matrix through the hit logic to day-to-day handling.

  • Screening policy and screening matrix
  • Scope for customers, owners, authorised persons, counterparties and payments
  • Matching and tuning requirements
  • Logic for politically exposed persons, family members and close associates
  • Sanctions, embargo and restrictive measures workflows
  • Adverse media categories and research guidance
  • Alert prioritisation and false positive rules
  • Batch screening and trigger-based rescreening
  • Case files, evidence, quality assurance and metrics

Transaction monitoring and case management

Functional design, calibration and ongoing operation of monitoring and case handling.

  • Risk assessment as the basis for the scenario catalogue
  • Scenario catalogue and functional rulebook
  • Customer profiles, segmentation and risk classes
  • Indicators, parameters and thresholds
  • Alert prioritisation and case types
  • Investigation guidance and case workflows
  • Escalation, deadlines, reminders and evidence model
  • Preparation of cases for reporting decisions
  • Backtesting, effectiveness analysis and quality assurance

Decisions on suspicious activity reports, sanctions freezes and termination of relationships remain with the authorised function of the institution. S+P prepares the case file, the supporting evidence and the documentation.

Data quality and data governance

Data quality as a running control process rather than a one-off clean-up before an audit.

  • Identification of critical data elements
  • Data ownership and responsibility model
  • Data quality rules and control catalogue
  • Checks on completeness, timeliness, plausibility and consistency
  • Customer, ownership, risk, account and transaction data
  • Error lists, data gaps and follow-up workflows
  • Data enrichment and event-driven updates
  • Reconciliation across due diligence, screening, monitoring and cases
  • Metrics, root cause analysis and remediation

Rulebook, model and change governance

Every parameter change justified, tested, approved and recorded.

  • Rulebook structure and version control
  • Documentation of scenarios, indicators and thresholds
  • Change request and approval process
  • Functional requirements for system changes
  • Test strategy, test cases and test data
  • User acceptance testing and functional sign-off
  • Backtesting and effectiveness analysis
  • Parameter and model risk documentation
  • Audit trail, exceptions and local calibrations

S+P prepares, analyses, calibrates and assesses the effectiveness of scenarios, indicators, thresholds and rulebooks. Approval of material rules, models and changes remains subject to your governance, decision rights and approval framework.

Implementation and migration office

The functional workstream of implementations, migrations and optimisation programmes.

  • Regulatory requirements and functional specification
  • Target processes, workflows and role model
  • Functional data mapping
  • Data quality and interface requirements
  • Use case selection and prioritisation
  • Test strategy, test cases and acceptance coordination
  • Training and rollout design
  • Migration plan, remediation and backlog strategy
  • Go-live readiness, hypercare and transition into operations

Managed operations

Processing under your policies, work instructions, decision limits and escalation rules.

Customer file operations

Onboarding support, document collection, periodic and event-driven reviews, data maintenance, ownership documentation, deadlines and evidence.

Alert operations

Alert intake and prioritisation, collection of customer, account and transaction information, case files, follow-ups and preparation for decision-making.

Screening operations

Pre-processing of sanctions, exposed person and adverse media hits under defined rules, false positive documentation, escalation and rescreening.

Remediation

Backlog reduction, overdue reviews and data gaps, refresh of customer and ownership data, completion of case files and transition into ongoing operations.

S+P works independently of software vendors, in existing and newly implemented landscapes. Where product or company names are mentioned, this describes possible system environments only and implies no partnership, certification or appointment by the named provider unless expressly published. Technical infrastructure, software development, licences and vendor support remain with the institution, the technology provider or the appointed technical implementation partner.

Four ways to engage

Depending on where your programme stands.

Assessment

Technology assessment

Before implementation, selection or migration: transparency over systems, data sources, rulebooks, alert volumes, case files, access rights and open issues.

Programme

Implementation office

For implementations, system changes and migrations: functional specification, data mapping, test cases, acceptance, training, go-live readiness and handover.

Project

Optimisation and remediation

For high alert volumes, elevated false positive rates, outdated scenarios or data gaps: calibration, backtesting, root cause analysis and file remediation.

Ongoing

Managed operations

Continuous delivery of defined customer file, screening, alert, data and evidence processes with agreed volumes, service levels and reporting.

How we work

  1. 1

    Assessment

    Systems, data sources, workflows, rulebooks, alert volumes, case files, interfaces, access rights, controls and open issues.

  2. 2

    Target model and design

    Target processes, roles, data models, workflows, rulebooks, control logic, evidence requirements, metrics and service levels.

  3. 3

    Build and test

    Functional specification, data mapping, test cases, acceptance testing, work instructions, training, go-live readiness and hypercare.

  4. 4

    Operate and improve

    Defined operations, data quality, backlog reduction, alert handling, quality assurance, backtesting and continuous improvement.

Roles in delivery

Technology and processing touch all three lines of defence. What matters is that operational delivery, functional governance and independent assurance stay separated — particularly where one provider covers more than one building block.

S+P separates these levels through distinct teams, roles, access rights, decision limits and reporting lines.

LevelRole in technology and operationsS+P support
First line Maintains customer data, handles alerts, keeps case files, evidence and deadlines Managed operations and operational quality assurance
Second line Owns standards and rulebook, assesses risk, monitors, escalates and approves Reporting officer support, methodology, calibration and independent challenge
Technology and vendor Technical configuration, interfaces, development and system operation Functional specification, test cases and acceptance support
Third line Reviews systems, processes, controls and governance independently Internal audit, audit preparation and follow-up

What you gain

Systems that work as controls

Functional logic, workflows, data and evidence interlock instead of existing side by side.

Effectiveness

Sustainable data quality

Control rules, error lists and named ownership make data quality measurable and manageable.

Data

Manageable alert volumes

Prioritisation, guidance and processing capacity create focus on the cases that carry risk.

Capacity

Traceable rulebooks

Scenarios, changes, tests and approvals are versioned and can be reconstructed under review.

Assurance

Relieved specialist functions

Compliance, technology and operations gain time for risk decisions, oversight and system governance.

Relief

Readiness that is workable

Requirements become a concrete operating model with technology, roles, controls and capacity.

Delivery

Who we support

  • Credit institutions and specialist banks
  • International banks with German branches or subsidiaries
  • Private banks and independent institutions
  • Payment and e-money institutions
  • Investment firms and asset managers
  • Capital management companies
  • Fintechs and embedded finance providers
  • Crypto-asset service providers
  • Institutions implementing, migrating or optimising AML technology

Related services

European AML Compliance

The overview of our European AML services, from assessment through implementation to managed operations.

Back to the hub

AMLR Readiness

Gap assessment against AMLR and AMLA standards, with a prioritised roadmap to 10 July 2027.

Explore AMLR Readiness

Group AML Governance

Consistent standards across head office, EU parent, branches and subsidiaries, implementable locally.

Explore Group AML Governance

AML Audit & Remediation

Audit readiness, evidence management and closure of supervisory and audit findings.

Explore Audit & Remediation

German AML for International Banks

Local AML governance, reporting officer support and documentation prepared for the German supervisor.

Explore German AML Compliance

Talk to us

Describe your system landscape, the processes in scope and your timeline, and we will respond with an assessment.

Contact S+P Compliance

Frequently asked questions

Does S+P implement AML software technically?

No. We support regulatory and functional requirements, target processes, data models, rulebooks, testing, acceptance, training, go-live readiness and operations. Technical configuration, development, system operation and vendor support remain with the institution, the provider or the appointed technical implementation partner.

Can S+P develop scenarios and thresholds?

S+P prepares, analyses, calibrates and assesses the effectiveness of scenarios, indicators, thresholds and rulebooks, and documents the rationale. Approval of material rules and changes remains within your governance and decision framework, so responsibility for the control environment stays with the institution.

Can S+P operate customer file, screening and alert processes?

Yes. Standardised processing is performed under your work instructions, decision limits and escalation routes. Decisions on complex cases, suspicious activity reports, sanctions freezes and material actions remain with the authorised functions of the institution.

Which systems does S+P support?

We are vendor independent and work in existing as well as newly implemented landscapes. What matters is the regulatory process, the data, the workflow, the rulebook, testability and delivery capacity, not the product. The relevant system environment is captured during the assessment and reflected in the target model.

How is separation between operations and compliance maintained?

Operational work is performed by clearly separated first-line teams. The second line defines standards, assesses risk, monitors compliance and escalates material deviations. Where S+P covers both, teams, access rights and reporting lines are separated and documented in the role model, and internal audit provides independent assurance.

Is the service suitable for international groups?

Yes. We support groups running central platforms alongside local entities through role models, data flows, local functional requirements, rulebook governance, bilingual reporting and operational delivery on the ground. The design is agreed as part of group governance.

Technology alone does not create AML compliance

Effective financial crime controls require aligned systems, data, processes, people, governance and operational capacity. S+P Compliance combines regulatory design, compliance technology, data quality and managed operations into an operating model that works in daily business and holds up under review.

AML Technology & Operations: turn AMLR requirements into working systems and delivery