Financial-crime surveillance ADGM · UAE Mauritius

Surveillance that can show its work.

Supervisors have stopped asking whether you hold controls. They now ask whether the controls work.

SonarPulse scores every customer and watches every transaction — graph typologies, machine-learning anomaly detection, per-alert narrative rationale — then leaves behind the evidence trail an examiner asks for. One record, from onboarding through to filing.

TMX · Alert 4417 FLAG
Round-trip pattern across three counterparties

Funds left the subject account and returned within 61 hours via two intermediaries sharing a registered address. Value retained: 3.1%. Graph typology round-trip matched at depth 3; behavioural velocity 4.2× the 90-day baseline.

Model anomaly-iforest v4 · challenger
Decision by Rule + ML, human-confirmed
Audit sha256 · 9f2c…41ab ✓
53%
of banks run false-positive rates above 20%
37%
manually review more than 40% of alerts
61%
growth in compliance hours at large banks over ten years, against 20% for total hours
$25–50
cost of investigating a single alert
Liminal, The State of AML Compliance in 2026 · Bank Policy Institute · mid-size bank benchmark

The shift

Three supervisors changed the test in the space of four months.

Holding a control is no longer the standard. Demonstrating that it detects financial crime is.

January 2026
AMLA assumed EU AML/CFT supervision

A single supervisory authority, applying one standard across the bloc rather than twenty-seven national interpretations.

February 2026
FATF moved evaluations to outcomes

The fifth-round methodology weights real-world results — enforcement, beneficial ownership transparency, sanctions implementation — over documented procedure.

April 2026
FinCEN proposed effectiveness grading

A framework that grades programmes on whether they actually detect financial crime, not on whether the paperwork is in order.

The root cause

The alert problem is a data problem.

Asked to name their single biggest transaction monitoring challenge, AML leaders did not say tuning. They said integration.

A well-tuned rule running on siloed, stale or incomplete data will throw false positives however well it is tuned. Stale occupation fields, missing beneficial ownership, absent transaction purpose codes — each forces a rule to fire on partial context. Buying a better engine does not fix a broken handover between the customer record and the payment stream.

Integration with existing systems 27%
False positives 16%
Detecting sophisticated schemes 15%
Liminal, 2026 — leading answers, single response

The lifecycle

One record, six stages, evidence at every step.

Most vendors are KYC-first extending into monitoring, or monitoring-first extending into KYC. Select a stage to see what it produces.

SonarPulse

Capture the entity, not just the name.

KYC and KYB across six entity types — individual, corporate, trust, foundation, partnership and vessel — each with a purpose-built data model. Ownership and UBO hierarchies are captured as a tree, biometric identity and document verification run at source, and collection links are secure and tokenised.

Evidence this stage leaves behind

  • Ownership tree with UBO and shareholder roles, versioned at capture
  • Document verification result with OCR, liveness and MRZ check
  • Timestamped record of who collected what, and from which channel

The Sonar Score

Set the weights yourself. Decompose the result in front of an examiner.

The score is composed of independently deployed modules, each carrying a configurable weighting. Risk appetite is set by your policy, not hard-coded by a vendor — and every rating breaks back down into the modules that produced it.

Move a weight and watch the band move. That is the same arithmetic your MLRO will walk a supervisor through.

Composite rating
Marine fuels trader · Fujairah
51.4
Medium risk
Sanctions & PEP signal 18 × weight 40% = 7.2
Adverse media signal 62 × weight 25% = 15.5
Business & ownership signal 88 × weight 20% = 17.6
Jurisdiction signal 74 × weight 15% = 11.1
Bands — low below 50 · medium 50 to 75 · high above 75 Weights normalised to 100

Depth

Screening is becoming a bundled commodity. Surveillance is not.

Analytics firms are folding screening into managed services and competing on price. The capabilities below are the ones that are hard to bundle, and they are the ones a fifth-round evaluation actually tests.

Graph typology detection

Smurfing, layering and round-trip patterns resolved across counterparties, not scored transaction by transaction. Ownership trees for corporate, trust, foundation, partnership and vessel structures feed the same graph.

Machine-learning anomaly detection

Isolation-forest anomaly scoring on behavioural signals — velocity, geography, device history — under champion/challenger model governance, so a model change is a recorded event rather than a silent one.

Explainable decisioning

Every APPROVE, FLAG or DENY carries a narrative rationale naming the rule, the typology and the behavioural signal that fired. UAE guidance requires AI models affecting AML decisions to be inventoried, documented, validated and explainable.

Tamper-evident audit chain

A SHA-256 hash chain over the audit log with chain verification, so an evidence pack can be shown to be unaltered rather than asserted to be. Row-level audit of who did what, and when, sits underneath it.

Jurisdictional fit

One country. Five supervisory regimes. Each with its own rulebook.

The UAE runs CBUAE, SCA, DFSA, FSRA and VARA side by side, and ADGM adds a further split — FSRA supervises financial firms and virtual asset providers, while the Registration Authority monitors AML compliance for ADGM-licensed DNFBPs.

Global vendors treat this as a configuration problem. We treat it as the design brief — goAML filing, Ministry of Economy high-risk country circulars, Real Estate Activity Reports, and hosting that keeps customer PII inside the jurisdiction that supervises it.

Banks & PSPs Fintechs & VASPs Corporate service providers Trust & company administrators Real estate DNFBPs
Authority Perimeter
FSRA Financial firms and virtual asset providers in ADGM
DFSA Firms in the Dubai International Financial Centre
CBUAE Financial institutions in mainland UAE and commercial free zones
VARA Virtual asset activity in Dubai
Ministry of Economy Designated non-financial businesses and professions
FSC Mauritius Financial services in Mauritius, where the scoring engine was developed

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu