Frequently asked
The questions due diligence actually asks
Short answers to the questions that come up in evaluation: architecture, governance, coverage, what leaves the bank when Investigations screens a name, and what EyesClear deliberately does not do.
Questions
Can AML AI run fully on-premises?
Yes. EyesClear deploys inside the bank’s own environment — on-premise or private cloud — and the AI runs on that same infrastructure behind a private LLM gateway. No customer data and no model inference goes to an external cloud or a third-party vendor. Data sovereignty is guaranteed by architecture, not by contract.
Who approves an AI-drafted SAR narrative?
An analyst. The AI drafts from the alert and the full evidence set; the analyst reviews, edits and signs. AI is the maker and the analyst is the checker — nothing closes and nothing files without that signature.
How does retroactive typology reprocessing work?
One engine serves real-time and back-dated processing as two modes. You update the typology, re-run it across the entire transaction history the same night, and review the new alerts the next morning. No vendor statement of work, no multi-month remediation project.
Does EyesClear replace our screening system?
No. EyesClear does not screen payments in real time. It takes the sanctions and name-matching alerts your screening platform raises and resolves them through the same maker-checker workflow. Its own analysis can also flag sanctions concerns for referral to the screening team.
How long does deployment take?
Days, rather than a multi-month integration programme. Detection, case management and reporting arrive as one platform on a single data fabric that connects to the warehouses you already run, so there is no new data-lake programme to complete first.
Which regulatory reports are supported?
Configurable report types, field catalogues and transformation rules generate Türkiye’s MASAK ŞİB/STR submissions on the current schema (Communiqué No. 30), the CRS and FATCA regimes, and other complex outputs — with submission tracking, retry handling and scheduling. A new report type is configuration, not development.
How is the LLM prevented from accessing bank systems?
By architecture, not by policy. The LLM runs inside EyesClear only, with no access to bank systems, databases or applications. It sees the case data the Platform hands it, and nothing else. Everything the agents can do is defined by tools written in-house, each a known, audited capability with defined inputs and outputs.
What data sources can EyesClear ingest?
Universal connectors take SWIFT and ISO 20022 (MT103, pacs.008, camt and related messages are handled natively), real-time queues such as MQ and Kafka, and database and file sources covering CRM, transactions, risk and KYC — all mapped into the single data fabric.
Does the AI crawl our internal systems?
No. Data enters through rules-based collection that your analysts and technology teams control — every source, field and refresh is explicitly configured. Some tools in the market crawl internal data instead; in our view that pattern is not secure enough for a bank. Nothing is read that was not explicitly granted.
What efficiency gain should a pilot validate?
Measure it rather than take a figure from us. The two numbers to watch are average handling time per case and analyst hours returned to higher-value work, both before the pilot and during it. Every case EyesClear touches carries its own timestamps and audit trail, so the comparison is drawn from your own book rather than quoted from someone else’s.
Is EyesClear SaaS?
No. EyesClear is not multi-tenant SaaS. It runs inside the bank’s own environment as containerised microservices — that is the point of it. It is the investigation and decision platform inside the bank.
What if we have no GPU infrastructure?
EyesClear can arrive with right-sized private AI hardware, so the LLM layer comes inside the perimeter as equipment rather than as a cloud dependency. Ask us where that option stands for your environment.
Can our compliance team change rules without us calling you?
Yes — that is the design. Compliance officers edit rules and typologies directly, and your team designs what a case captures through dynamic forms that go live without a vendor change request. Every material change still passes through a maker-checker (four-eyes) workflow with a full record of who requested it and who approved it.
Can we use EyesClear Investigations without the Platform?
Yes. Investigations runs on its own: an analyst screens a name and gets a report back, with nothing to integrate and nothing to deploy, so it can be used on the day an account is opened. It also feeds whatever case system you already run. Inside the Platform it becomes the external-evidence step of a case, but that is an option rather than a requirement.
What leaves the bank when we screen a name?
The name being screened and the search terms derived from it, sent to the public sources and the language models the service uses. That is the whole of it — no customer file, no transaction, no alert. Investigations has no connection to the Platform’s data fabric and no access to customer records or cases, and no provider trains on the queries sent or on the reports produced. Treat a screening as a public-record enquiry about a named subject and scope it the way your policy scopes one.
Why is Investigations hosted rather than on-premise?
Because the evidence it gathers is on the open web, so the search has to happen there. Putting the service inside the bank would not keep the enquiry inside the bank; it would only move where the request originated. The bank’s own data stays where it always was — the Platform and all of its AI inference run inside your perimeter.
How do we defend a public-record finding to an examiner?
Every relationship and every risk finding is reported with a verbatim quote, and that quote is checked against the page it was taken from before the finding is kept. Anything that cannot be located in its source is discarded rather than reported, and nothing is inferred. A finding records what a source says, with its date, its severity and its provenance: an allegation is labelled an allegation, an investigation is not a charge, and a charge is not a conviction. Where nothing is found, the report says nothing was identified in the sources searched — never that the subject is clean.
Is Investigations really free?
It is free for financial institutions and their regulators, with five screenings to start and no integration work. Sign up with a work email from a financial institution or a regulator.
How would we defend the AI to an examiner?
The AI never decides on its own. Every output traces back to the source data and is reviewed, edited and approved by an analyst before it is acted on, so there is no black-box score to defend. All evidence, case history and decisions are held centrally with full audit trails, and activity logging records who opened which screen and what they did.
If a question is not here, ask it — the architecture ones are our favourites.
Try it on a name you already know
Investigations is free for financial institutions and their regulators — five screenings to start, nothing to integrate. Or book a demo and we will run the Platform on your own scenarios.
