Compliance Controls Library

Reference dossiers on AML, KYC, sanctions, fraud, and risk controls. What regulators expect, what good looks like, and the audit findings to avoid.

Showing 1–20 of 26 controls

Page 1 of 2

3-D Secure Authentication payments

3-D Secure Authentication (3DS) is a payment security protocol that authenticates cardholders during online transactions, adding a ...

AI Governance AI-governance

AI Governance is the framework of policies, model validation procedures, oversight structures, and documentation standards that ensure AI ...

Alert Prioritization AML

Alert Prioritization is the AML control that ranks transaction monitoring alerts by risk severity so investigators work the highest-risk ...

AML / Fraud Training and Awareness regulatory

AML / Fraud Training and Awareness is the compliance control that ensures every employee who handles transactions, customers, or compliance ...

Behavioral Analytics AML

Behavioral analytics is an AML control that builds statistical baselines of individual customer activity over time and flags deviations ...

Behavioral Biometrics fraud

Behavioral biometrics is the continuous analysis of user interaction patterns (typing cadence, mouse velocity, swipe pressure, device ...

Beneficial Ownership Verification KYC

Beneficial Ownership Verification (also called UBO verification) is a KYC control that identifies and verifies the natural persons who ...

Business Continuity Planning operational-resilience

Business Continuity Planning (BCP) is the documented process by which a financial institution ensures critical compliance operations remain ...

Case Management AML

Case Management is the AML workflow control that governs how a financial institution receives, investigates, documents, and resolves ...

Currency Transaction Report Filing AML

Currency Transaction Report (CTR) Filing is the compliance control that requires US financial institutions to report cash transactions ...

Customer Due Diligence KYC

Customer Due Diligence (CDD) is the process through which financial institutions verify customer identity, understand the purpose of ...

Customer Risk Rating KYC

Customer Risk Rating (CRR) is the AML/KYC process by which a financial institution assigns each customer a risk score, typically Low, ...

Data Quality Monitoring operational

Data quality monitoring is the ongoing process of measuring, correcting, and governing the accuracy, completeness, consistency, and ...

Device Fingerprinting fraud

Device fingerprinting is a fraud detection control that identifies and risk-scores devices accessing banking systems by collecting ...

Enhanced Due Diligence KYC

Enhanced Due Diligence (EDD) is the intensified customer verification and ongoing monitoring applied to high-risk relationships, mandated ...

Fraud Rules Engine fraud

A fraud rules engine is a real-time, configurable decision system that financial institutions use to evaluate transactions against defined ...

Human-in-the-Loop Review AI-governance

Human-in-the-Loop Review (HITL) is an AI-governance control that requires a qualified human reviewer to assess, confirm, or override ...

Incident Response operational-resilience

Incident Response is the documented process a financial institution uses to detect, contain, investigate, and report security and ...

Independent Testing regulatory

Independent Testing is a mandatory AML/BSA compliance control requiring a qualified, independent function to periodically review whether an ...

Ongoing Monitoring KYC

Ongoing monitoring is the continuous review of customer transactions, relationships, and risk profiles to detect suspicious activity and ...