Skip to main content

AML/CFT Screening · Statement of Conformance

AML/CFT Methodology & Audit

The methodology is the product. The audit trail is the proof.

A financial-crime screening decision should be traceable, standards-based, and inspectable end to end — never a score returned from a black box. This is how ours works, and how it stands up to a regulator.

Stated plainly
#

Anqa is a regulatory-technology provider — it supplies the screening methodology, the data and the auditable workflow. It does not hold client funds, carry on a licensed financial service, or act as an AML/CFT reporting entity, and it needs no financial-regulator licence to do what it does.

The accountable reporting entity remains the institution and, where relevant, its own customers. Anqa gives them a method that conforms to the standards and a record that evidences every step — the compliance decision, and the reporting obligation, stay where they belong. We say this directly, because that honesty is part of the assurance.

Built to the global standard, so jurisdiction doesn’t change the method
#

The methodology is built to the FATF Recommendations — the international standard from which every national AML/CFT regime is written. Conforming to FATF is conforming to the local regime.

What changes between countries is only which national and regional designation lists are screened, and where a report is sent. Both are configuration, not methodology — we ingest any national list (the regulator’s, and the institution’s own) as a free addition. No per-country re-engineering. No per-country re-certification. The same engine, the same audit trail, everywhere.

R.1 Risk-based approach R.6 TF sanctions R.7 Proliferation / UNSC R.10 Customer due diligence R.12 PEPs R.15 New technologies R.20 Suspicious-transaction reporting

One screen. Four checks. Each tied to the standard it satisfies
#

A single screen runs all four together — one screen is one name checked at one point in time.

CheckWhat it coversStandard
SanctionsUN, OFAC, EU, UK HMT/OFSI, plus national designations; strategic / dual-use and proliferation where applicableFATF R.6 · R.7
PEPDomestic, foreign and international-organisation PEPs, and relatives / close associatesFATF R.12
EnforcementDebarments, prosecutions, regulator and court actionsFATF R.10
Adverse mediaStructured into four tiers — legal & enforcement first, then tier-one press, then local outlets, with the lowest-reliability tier excludedFATF R.10 · R.1

Screening runs when the risk calls for it — and repeats on a risk-graded cycle
#

Point-in-time at onboarding. A name is screened before the relationship is taken on, against all four checks together, with results returned in real time.

Risk-based periodic re-screening. An entity is re-screened on a cycle set by its risk grading — typically 3, 6 or 12 months — producing a fresh consolidated report each time as an audit record.

Ongoing monitoring, optional. Continuous re-screening against updated lists, so an entity sanctioned after onboarding is surfaced automatically.

Dynamic risk assessment. The platform rebuilds an entity’s risk picture with each new data point, mapped to the FATF risk factors — nature and purpose, identification, product, delivery channel, geography — held as an immutable record.

Owned data, surfaced in full — no black box
#

160+ Authoritative sources
6h Refresh, as often as
~20M Canonicalised records

Owned, proprietary data — no reselling or redistribution restrictions.

We surface the full underlying record behind every hit — nothing hidden from the analyst or the regulator.

Canonical consolidation. Where an entity appears across many lists, every hit collapses into one item to disposition, with all underlying records held behind it — dozens of alerts become a single, richer review.

Match-confidence scoring separates true positive, plausible match and clean, so reviewers spend time on what matters.

Free list additions. Point us at any list — national designations or your own internal list — and we schedule it for refresh at no charge. This is the entirety of what adapting to a jurisdiction involves.

Every decision carries its evidence — tamper-evident, and reproducible
#

This is where audit meets AML/CFT. Every screen records a complete chain of provenance that a regulator can inspect and reproduce.

Source list

UN · OFAC · EU — with version and refresh time

Rule

What raised it

Confidence

The band applied

Reviewer

Analyst and checker — four-eyes

Decision

Dispositioned, with rationale

Timestamp

To the second

The log is append-only, SHA-256 hash-chained, and the database denies update and delete — the trail cannot be altered after the fact.

Full data lineage on every screen. You can always answer the regulator’s two questions: where did this come from, and why did you action it this way?

Reproducible point-in-time screening. The consolidated report produced on a given date can be regenerated and evidenced as the check performed at that time.

Immutable retention for the applicable regulatory period, and inspection-ready — built to welcome regulator and FIU interaction on demand.

Case management and four-eyes. Every alert flows into a workflow with a consolidated evidence bundle, configurable SLAs by risk, maker-checker review, and SAR/STR capture for the national FIU.

Where it runs is your choice — the controls travel with it
#

Tenant isolation via PostgreSQL row-level security — no data bleed between institutions.

Role-based access, maker-checker on dispositions, periodic access reviews.

TLS 1.3 in transit, AES-256 at rest; CIS-hardened; documented incident-response and BC/DR.

In-country, on-premises

Deploy on the institution's own infrastructure — compliance data stays in-country, meeting local residency and data-protection expectations without offshore transfer. Anqa's only cloud footprint is a relay for signed software and list refreshes; no customer data traverses it.

Anqa managed — Hetzner, Germany

Managed infrastructure runs on an ISO/IEC 27001-certified provider under EU / GDPR jurisdiction — deliberately EU, not US hyperscaler, so there is no US CLOUD Act exposure over client data.

Certification status — stated honestly
#

Independent VAPT, SOC 2 and ISO/IEC 27001 for Anqa itself are committed for the 2026 calendar year and are not yet in place. In the interim, assurance rests on the inherited Hetzner ISO 27001 (EU), a documented ISO-27001-aligned ISMS, and — under the on-premises model — the institution’s own certified environment carrying the infrastructure layer. We state this at true status rather than imply a certificate we do not hold.

What this means
#

A standards-based methodology, fully auditable and inspection-ready — on owned data, deployed under your control.

The price reflects a modern cost base. The rigour reflects the standards. Both are true at once — enterprise-grade assurance without the enterprise cost structure, built for the institutions and markets the incumbents chose not to serve.

For the matching layer beneath this methodology — how names are actually compared — see Anqa AML Smart Screen: Watchlist Screening Methodology.

ANQA LIMITED · t/a Anqa Compliance · NZ 8964870
Anqa Compliance is a technology provider; this page describes methodology and platform controls and is not legal advice or a compliance opinion. The institution remains the accountable party for its and its customers' AML/CFT obligations. Certain assurance items are stated at true status, including certifications in progress.

See the methodology in the product

Every screen Anqa runs carries the chain of provenance described on this page — source list, rule, confidence band, reviewer, decision, timestamp. Create an account and inspect it yourself.

Try for Free