What AML / KYC means in practice
Anti-Money Laundering and Know-Your-Customer are the twin regulatory frameworks governing financial-entity customer-identification, screening, transaction monitoring, and suspicious-activity reporting. The AI implications are pervasive: KYC onboarding uses biometric ID extraction (Annex III high-risk under the EU AI Act), AML transaction monitoring uses ML-driven alert generation (Article 25 trigger when fine-tuned per-customer), and sanctions screening uses fuzzy matching and entity-resolution (auditable under both EU AI Act and the relevant AML supervisor's expectations). MindMap's OnboardX KYC accelerator and the AML alert-triage workflows ship into deployments that explicitly carry Annex III evidence collection — risk management, data governance, technical documentation, oversight protocols — as first-class engineering concerns.
Related terms
Sovereign AI →
An architecture where customer data never leaves the network perimeter, model weights run on customer-controlled hardware, inference logs stay in the customer's SIEM, and the entire stack can operate air-gapped.
Annex III high-risk AI →
The schedule in the EU AI Act listing AI use cases automatically classified as high-risk — biometric ID, credit scoring, HR screening, healthcare diagnostic support, critical infrastructure, education, justice.
RBI Master Direction on IT Governance →
The Reserve Bank of India's master directive on IT governance for regulated entities — specifies that AI/ML model lifecycle artefacts must be hosted under the regulated entity's exclusive control.
SAMA Cyber Resilience Framework →
The Saudi Central Bank's cyber-resilience framework — sets the technology and data-residency expectations for regulated financial institutions, with explicit AI provisions in the 2025 update.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.