產業導入

Bank KYC/AML automation: turning account opening and transaction monitoring from manual work into auditable production lines

Compliance teams process over 12,000 transaction alerts monthly; 99% of them are false positives. Each account review takes 40 minutes. The staff works hard. The rules engine manufactures the work. We used AI agents to transform account review and suspicious transaction reporting into auditable production lines: cutting false positive rates from nearly 99% to 20% and reducing review hours by 80%. Here's the story from a compliance and risk perspective.

By

Tenten AI 交付團隊

產業交付

Published

December 17, 2025

Read time

5 分鐘

KYC AML AI 自動化金融法遵反洗錢通報AI Agent 工作流前線部署工程銀行數位轉型

A regional bank's compliance director told me her team processes over 12,000 transaction-monitoring alerts every month. Fewer than 80 actually need to be reported. The rest, 99% of them, are false positives. A typical analyst's day looks like this: boot up, click through rows of red flags one by one, check transaction flows, write notes, move on. By end of day, she's cleared about 60%, and the backlog rolls forward.

The staff works hard. The rules engine manufactures the work.

What KYC/AML AI automation actually automates

KYC/AML AI automation uses AI agents to handle the repetitive but judgment-based steps in account opening review (KYC) and suspicious activity reporting (AML/STR) where decision patterns are stable. The goal is to convert them from manual work into an auditable production line. Not to replace compliance staff, but to pull them out of the alert firehose so they handle only cases that need human judgment.

What stays manual is equally important: the final decision to file STRs, responses to regulators, and risk appetite settings. Those remain human responsibilities.

Account opening: how the process splits

Here's how it used to work: customer uploads ID, business registration, and beneficial ownership documents. Staff manually cross-check fields, compare OCR output, and run name screening (sanctions lists, PEPs, adverse news). Any flag sends it back to the customer for more documents.

We split this into three steps. The first agent extracts documents and checks consistency: verifying that addresses, names, and tax IDs line up across documents, that passport expiration dates are valid. The second handles name matching, turning fuzzy hits from common names like "Wang Daming" into disambiguated results using birthdate, address, and entity relationships, instead of handing a list of possible matches to someone. The third generates a structured review summary with justification and source citations for each decision. Compliance staff read the summary, review the evidence, then approve or reject.

Suspicious transaction monitoring: the filtering approach

Transaction monitoring is trickier because false positive costs compound. Set rules too loose and you're drowning in alerts that no one can work through; set them too tight and you miss actual money laundering, then regulators fine you for it.

Our approach isn't to scrap the rules engine. Instead, we add an agent filter behind it. The agent reads the alert, pulls together the customer's transaction history, linked accounts, and transaction context, and first assesses whether this alert resembles a pattern previously closed as clean. For high-similarity cases, it auto-drafts a closure justification for human sign-off; for unusual contexts, it escalates and bundles the full investigative package so the analyst opens the case with complete context instead of piecing data together.

The key is auditability. Every agent decision leaves a trail, can be replayed, and can be examined by regulators. A polished demo doesn't matter. Passing internal audit and regulatory examination matters.

Results: accuracy and hours

MetricBefore (Manual)After (Agent Production Line)
Avg. time per account review42 min/case9 min/case
Name screening fuzzy hits per case needing human disambiguationAvg. 11Avg. 1.4
Monthly alerts requiring human review12,0003,400
False positive rate for escalated cases~99%~22%
Analyst daily case closures per person60210
Time to STR filingAvg. 6 daysAvg. 1.5 days

Sustaining the system after launch

These numbers didn't appear on day one. For the first two months, we worked constantly with the compliance team to define what counts as suspicious, translating their implicit rules into criteria the agent could understand. After launch, we spent a full quarter tuning thresholds and addressing edge cases. In one case, the agent misclassified a cross-border education fee remittance as layering activity. An analyst caught it, and we refined the rules.

Reducing false positives to 22% required more than a smarter model. It required engineers on site, working directly with the compliance team, getting rejected alongside them, and iterating. At Tenten, we deploy engineers directly to the compliance team. They work on actual cases, iterate with users, and stay until the system is stable and regulatory-ready.

One stuck workflow
is enough to begin

Tell us what the team does today, where it breaks down, and what a better working day should look like.