AI advises.Humans decide.The system proves it.
Ledgerline, an AML alert triage platform built to show governance, risk and compliance enforced in code: seven controls, each one tested, none of them a policy document.
Ledgerline
AML alert triage, case management and suspicious activity reporting for a bank's financial-crime unit. AI assists analysts; it does not decide. Synthetic data only.
Two layers. A deterministic rules engine raises the alerts from versioned detection rules, parameters and FATF jurisdiction lists: same input, same output, every artefact owned and dated. A large language model drafts the triage summary and the SAR narrative from the case evidence: probabilistic by nature, which is why it is advisory only, checked against the evidence it cites, confidence-capped and switchable off.
- Domain
- Banking, AML operations
- Frameworks
- MAS FEAT, MAS AI Risk Management Guidelines, ISO/IEC 42001 Annex A
- Status
- Live, frozen at a named commit, access on request
What a regulator actually asks.
Not whether the model was accurate. Who closed the alert, on what evidence, whether the AI could have done it alone, and whether the record can be trusted. Ledgerline was built so that each of those questions is answered by the system itself.
Seven controls, each one tested.
- 01
Humans decide.
No AI output can change the status of an alert or a case. Only a named seat can, and the trail records it.
- 02
AI is advisory.
Every AI summary is checked against the evidence it cites, declares what it could not verify, and its confidence is capped below certainty.
- 03
Kill switch.
One action disables the model for everyone. Restarting it requires two administrators.
- 04
Tamper-evident trail.
Every action is hash-chained. Any seat can verify the chain; only a reviewer or an administrator can export it.
Seven controls, continued.
- 05
Deterministic rules.
Detection rules, parameters and the FATF jurisdiction lists are versioned, owned, dated and attested. The system names any artefact past its review date.
- 06
Protected attributes excluded.
Nationality, gender and similar attributes are removed at build time. A test fails if they reappear.
- 07
Separation of duties.
The role-by-decision matrix is generated from the API, not written by hand. Building it found two defects; both were fixed before release.
Stated, not hidden.
No independent model validation. No disparity measurement across groups. No formal AI policy document. No management-review cycle. Two production-readiness gates remain open. All of this is written in the system's own governance page, next to the controls that do work.
Where each control sits.
Each control is mapped to MAS FEAT principles, the MAS AI Risk Management Guidelines and ISO/IEC 42001 Annex A, by domain: access and identity, human oversight, audit trail, model governance, data and protected attributes, detection parameters, monitoring and drift, third party. The mapping is a working document, not a certification claim.
See it.
A read-only seat is sent by email, usually within two working days. Synthetic data, no client information.