Surveillance that can show its work.
Supervisors have stopped asking whether you hold controls. They now ask whether the controls work.
SonarPulse scores every customer and watches every transaction — graph typologies, machine-learning anomaly detection, per-alert narrative rationale — then leaves behind the evidence trail an examiner asks for. One record, from onboarding through to filing.
Funds left the subject account and returned within 61 hours via two intermediaries sharing a registered address. Value retained: 3.1%. Graph typology round-trip matched at depth 3; behavioural velocity 4.2× the 90-day baseline.
The shift
Three supervisors changed the test in the space of four months.
Holding a control is no longer the standard. Demonstrating that it detects financial crime is.
A single supervisory authority, applying one standard across the bloc rather than twenty-seven national interpretations.
The fifth-round methodology weights real-world results — enforcement, beneficial ownership transparency, sanctions implementation — over documented procedure.
A framework that grades programmes on whether they actually detect financial crime, not on whether the paperwork is in order.
The root cause
The alert problem is a data problem.
Asked to name their single biggest transaction monitoring challenge, AML leaders did not say tuning. They said integration.
A well-tuned rule running on siloed, stale or incomplete data will throw false positives however well it is tuned. Stale occupation fields, missing beneficial ownership, absent transaction purpose codes — each forces a rule to fire on partial context. Buying a better engine does not fix a broken handover between the customer record and the payment stream.
The lifecycle
One record, six stages, evidence at every step.
Most vendors are KYC-first extending into monitoring, or monitoring-first extending into KYC. Select a stage to see what it produces.
Capture the entity, not just the name.
KYC and KYB across six entity types — individual, corporate, trust, foundation, partnership and vessel — each with a purpose-built data model. Ownership and UBO hierarchies are captured as a tree, biometric identity and document verification run at source, and collection links are secure and tokenised.
Evidence this stage leaves behind
- Ownership tree with UBO and shareholder roles, versioned at capture
- Document verification result with OCR, liveness and MRZ check
- Timestamped record of who collected what, and from which channel
One pass across every list that matters.
Sanctions, PEP and adverse media in a single screening pass — OFAC, UN, EU, UK, World Bank and Interpol among 250+ sources, plus your own blacklists, a localised in-country PEP database at levels 1 to 3, and an aggregator across DOJ, CourtListener, SEC EDGAR and Supreme Court records.
Evidence this stage leaves behind
- Per-hit provenance: which list, which version, which date
- Match rationale including romanisation and normalisation applied
- False-positive dismissals recorded with the reviewer's reasoning
A rating that decomposes.
A per-tenant rules engine with versioning and rollback weights every module into a low, medium or high rating. Because modules are deployed independently, the model adapts by vertical and localises by jurisdiction — and the score can be taken apart in front of an examiner, module by module.
Evidence this stage leaves behind
- Module-level contribution breakdown for every rating
- The rule-set version that produced it, with rollback history
- Human confirmation or override, attributed and timestamped
Trigger events, not review calendars.
Perpetual KYC replaces the three-to-five year refresh cycle. Daily re-screening with hit-diffing raises only what changed, a daily worldwide media watch runs alongside it with per-hit category tagging, and a change in risk rating writes back to the customer record.
Evidence this stage leaves behind
- Hit-diff log showing exactly what changed and when
- Risk-rating change history across the life of the relationship
- Consolidated alert digest with per-hit category tagging
Fraud and AML in one engine.
Real-time ingestion on an ISO 20022-aligned schema, unified fraud and AML rule sets with sanctions rules in the same engine, graph typologies for smurfing, layering and round-trip patterns, behavioural signals across velocity, geography and device history, and isolation-forest anomaly detection under champion/challenger governance.
Evidence this stage leaves behind
- Narrative rationale per alert naming rule, typology and signal
- Model version and champion/challenger state at decision time
- APPROVE, FLAG or DENY with the full input vector retained
From alert to filed report, under four eyes.
Case management with state workflow, SLA tracking and breach escalation, role-based access, and goAML and FinCEN SAR generation with segregation between the reporting officer and the approving officer. Underneath it all sits a tamper-evident SHA-256 hash-chain audit log with chain verification.
Evidence this stage leaves behind
- Filed report with maker and checker recorded separately
- SLA timeline including any breach and its escalation
- Hash-chain verification proving the trail is unaltered
The Sonar Score
Set the weights yourself. Decompose the result in front of an examiner.
The score is composed of independently deployed modules, each carrying a configurable weighting. Risk appetite is set by your policy, not hard-coded by a vendor — and every rating breaks back down into the modules that produced it.
Move a weight and watch the band move. That is the same arithmetic your MLRO will walk a supervisor through.
Depth
Screening is becoming a bundled commodity. Surveillance is not.
Analytics firms are folding screening into managed services and competing on price. The capabilities below are the ones that are hard to bundle, and they are the ones a fifth-round evaluation actually tests.
Smurfing, layering and round-trip patterns resolved across counterparties, not scored transaction by transaction. Ownership trees for corporate, trust, foundation, partnership and vessel structures feed the same graph.
Isolation-forest anomaly scoring on behavioural signals — velocity, geography, device history — under champion/challenger model governance, so a model change is a recorded event rather than a silent one.
Every APPROVE, FLAG or DENY carries a narrative rationale naming the rule, the typology and the behavioural signal that fired. UAE guidance requires AI models affecting AML decisions to be inventoried, documented, validated and explainable.
A SHA-256 hash chain over the audit log with chain verification, so an evidence pack can be shown to be unaltered rather than asserted to be. Row-level audit of who did what, and when, sits underneath it.
Jurisdictional fit
One country. Five supervisory regimes. Each with its own rulebook.
The UAE runs CBUAE, SCA, DFSA, FSRA and VARA side by side, and ADGM adds a further split — FSRA supervises financial firms and virtual asset providers, while the Registration Authority monitors AML compliance for ADGM-licensed DNFBPs.
Global vendors treat this as a configuration problem. We treat it as the design brief — goAML filing, Ministry of Economy high-risk country circulars, Real Estate Activity Reports, and hosting that keeps customer PII inside the jurisdiction that supervises it.
| Authority | Perimeter |
|---|---|
| FSRA | Financial firms and virtual asset providers in ADGM |
| DFSA | Firms in the Dubai International Financial Centre |
| CBUAE | Financial institutions in mainland UAE and commercial free zones |
| VARA | Virtual asset activity in Dubai |
| Ministry of Economy | Designated non-financial businesses and professions |
| FSC Mauritius | Financial services in Mauritius, where the scoring engine was developed |
Start with a compliance health check.
A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.