The platform
Two engines, one customer record, one audit trail.
SonarPulse covers the customer side. TMX covers the transaction side. They share a record, so the context gathered at onboarding is the context a monitoring rule fires against.
Customer side
SonarPulse
Onboarding through to perpetual monitoring, delivered as an in-country cloud service.
01
Onboarding & KYB
Six entity types with purpose-built data models, UBO and shareholder hierarchy, document capture and biometric identity verification.
02
Sanctions & PEP
250+ global sanction, PEP and watchlist sources plus per-tenant blacklists and a localised in-country PEP database at levels 1 to 3.
03
Adverse media
International, local and home-country press, ICIJ and a daily worldwide media watch, with translation, sentiment and relevance filtering.
04
Legal & enforcement
A single-call aggregator across US DOJ, CourtListener, SEC EDGAR, UK Find Case Law and the Supreme Court of Mauritius.
05
Risk scoring
A per-tenant rules engine with versioning and rollback; category weights per entity type; a transparent low, medium or high rating.
06
Perpetual monitoring
Daily re-screening with hit-diffing and consolidated alerts, plus a daily adverse-media watch with per-hit category tagging.
07
Reporting & audit
Per-entity PDF and HTML due-diligence reports, STR and SAR drafting, and row-level audit trails.
Transaction side
TMX
Real-time fraud and AML in one engine, on-premises inside the payment perimeter.
01
Real-time ingestion
Transaction screening on an ISO 20022-aligned payment schema with country and currency validation.
02
Unified FRAML rules
Fraud, AML and sanctions rule sets running in one engine rather than three systems reconciled after the fact.
03
Graph typologies
Smurfing, layering and round-trip patterns resolved across counterparties at depth.
04
Behavioural signals
Velocity, geography and device history scored against a rolling baseline per subject.
05
ML anomaly detection
Isolation-forest anomaly scoring under champion/challenger model governance with version tracking.
06
Explainable decisioning
Per-alert narrative rationale behind every APPROVE, FLAG or DENY, with the input vector retained.
07
Filing & audit chain
goAML and FinCEN SAR generation under four-eyes control, over a tamper-evident SHA-256 hash-chain audit log.
Module · SPCDD
Risk-based re-KYC on autopilot, from renewal notice to audit-ready close.
The CDD-renewal module schedules periodic review by risk rating, reaches customers through a secure OTP-gated portal, collects and cross-validates updated data, and routes every case through per-field maker-checker review. Only the approved set is committed to your system of record — documents are handled in transit and never left at rest on the app.
01
Schedule
Risk-based due sweep, initial waves and ad-hoc triggers
02
Notify
Secure OTP link, reminder ladder, email-reply fallback
03
Collect
Form and documents, malware scan, cross-validation
04
Review
Per-field approve or reject, maker-checker sign-off
05
Commit
Approved set written to your system of record
06
Close
Audit evidence, register exports, webhooks
High-risk sign-off always dual-controlled
Hashed tokens · 14-day expiry · save & resume
Row-level tenant isolation
Renewal cadence: high 1yr · standard 3yr · low 4yr
Coverage
Aggregated sources, no single-vendor lock-in.
Premium watchlist feeds meter you per record, and costs balloon as you grow. SonarPulse aggregates official regulator lists, open and alternative datasets, court and enforcement records, live media and a localised in-country PEP database.
| Sanctions |
OFAC (SDN), UN, EU, UK (HMT/FCDO), World Bank, Interpol — among 250+ sources, plus your own blacklists |
| PEP |
Global PEP coverage, a localised in-country database at levels 1, 2 and 3, and relatives and close associates |
| Adverse media |
Global and regional press, ICIJ, daily worldwide watch, multilingual with translation and sentiment |
| Legal & enforcement |
US DOJ, CourtListener, SEC EDGAR, UK Find Case Law, Supreme Court of Mauritius |
| Market lists |
India RBI and SEBI, China BIS, UFLPA and NS-CMIC, among others |
| Name matching |
Multilingual romanisation, accent and punctuation normalisation, shared false-positive guards for generic tokens |
Regulatory fit
Built around the standards you are measured against.
Alignment is designed in rather than mapped afterwards, so the evidence a supervisor asks for is a report, not a project.
FATF Rec. 10 — CDD
Multi-source screening, risk-based rating, EDD triggers, all entity types including UBO, and scheduled periodic review.
FATF Rec. 11 — Records
Row-level audit of who and when, plus a tamper-evident hash-chain audit in TMX, with configurable retention.
FATF Rec. 16 — Travel Rule
Originator and beneficiary screening with subject resolution.
ISO 20022 · 3166 · 4217
Standards-aligned transaction schema with country and currency validation.
Aligned to ISO/IEC 42001 — AI governance
Explainable ML decisions, champion/challenger model tracking and per-alert narratives.
Aligned to ISO 37301 · 27001 · Wolfsberg
The RBAC, four-eyes control, screening evidence and audit logs a compliance or information security management system relies on.
Hosting
Hosted where your regulator wants it.
Customer PII stays inside your own jurisdiction rather than a foreign multi-tenant cloud. Private data centre or on-premises where it is mandated — the same codebase, configuration only.
SonarPulse
In-country cloud
Screening, scoring, monitoring and reporting hosted inside your jurisdiction. Private-DC or on-premises optional.
TMX
On-premises
Real-time transaction monitoring inside the payment perimeter, where the payment traffic already sits.
SonarPulse Connect
Integration layer
On-premises middleware feeding TMX from core banking and payment systems on an ISO 20022-aligned schema.
See it run on a sample of your own customers.
We will stand SonarPulse up in your region and walk onboarding, multi-source screening, risk scoring, monitoring and audit-ready reporting end to end.
Request a compliance health check