Security built for sensitive compliance workflows

AgentAML is designed to protect your agency's compliance records, evidence files, and customer data with enterprise-grade access controls and audit logging.

Security principles

Organisation-level data separation

Each agency's data is stored in a completely isolated environment. No cross-tenant data access is possible by design.

Role-based access control

Four distinct roles with clearly defined permissions ensure staff only access data relevant to their responsibilities.

Protected evidence files

Uploaded compliance documents and evidence files are access-controlled and linked to specific customer files.

Audit logging

Every user action is timestamped and logged with user identity, action type, and file reference. Logs are immutable.

Human review for AI outputs

AI-generated content is always clearly labelled as a draft and cannot be applied to a file without explicit human approval.

Secure export records

Exported AML customer file packs are generated on demand and include the full audit trail and compliance officer decision.

Role-based access control

Four defined roles ensure every team member has the right level of access — no more, no less.

Organisation Owner
  • Full access to all files and settings
  • Manage staff and roles
  • Configure organisation profile
  • Access all reports and exports
Compliance Officer
  • Review and approve customer files
  • Access risk assessments
  • Generate AI draft summaries
  • View all evidence and audit trails
Staff Member
  • Create and update customer files
  • Upload evidence documents
  • Complete CDD checklists
  • Submit files for review
Viewer / Auditor
  • Read-only access to assigned files
  • View audit trails
  • Download approved export packs
  • No edit permissions

AI is a drafting assistant, not a decision-maker

AI-generated content must be reviewed before use in compliance decisions.

Important: AI outputs are drafts only

Draft summaries and evidence prompts stay under compliance officer control. Risk summaries, missing evidence alerts, and file notes are all clearly labelled as drafts and cannot be acted upon without explicit compliance officer review.

AgentAML supports AML/CTF workflow management, evidence collection, internal review, and record keeping. It does not provide legal advice and does not replace the agency's responsibility to comply with applicable AML/CTF obligations. AI-generated content is a draft only and must be reviewed by an authorised person.