+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
● B2B offer — Banking compliance

Banking compliance: files assembled, evidence kept

A know-your-customer file and an anti-money-laundering check rest on documents, verifications and a flawless audit trail. Your agent assembles these files according to your procedures, gathers the documents expected, applies your control rules and keeps the evidence of every verification. Hosted in France in a qualified environment: your customers' data stays with you. Every decision rests with the authorised compliance officer.

Hosted in France Client data protected GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
KYC/AML compliance · hosted in France
Assemble the know-your-customer file for this new business relationship.
File assembled according to your procedures: identification documents gathered, consistency of the information verified, the checks in your control framework applied.
Every verification keeps its source, its date and its result.
Two points call for the judgement of an authorised officer: they are presented at the top.
🔗 Sourced · the documents in the file and the control framework
Can we approve the business relationship?
The file is complete and documented, with the two points flagged and the material that bears on them.
Approving a business relationship, or reporting a transaction, rests with the authorised officer: these are regulated acts.
✎ Support · file documented, the officer's decision
Local inference · no data outside the EU
Files hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
Your banking compliance department decidesThe agent prepares, never rules
✦ In brief

A Blue Lemon Agent banking compliance agent assembles your know-your-customer files and your anti-money-laundering checks according to your procedures: documents gathered, consistency verified, rules applied, with every verification keeping its source, its date and its result. Approving a business relationship or reporting a transaction rests with the authorised officer. Hosted in France in a qualified environment, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.

100%
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
6
compliance uses ready to deploy
0
decision taken without human approval

These figures describe our offer, not results measured at a client. How large the gain is on your volume of files and the breadth of your control framework is confirmed by a pilot.

The context

What does an AI agent bring to your banking compliance?

In banking compliance, the quality of the evidence kept counts as much as the check performed.

! The issue

A banking compliance check calls for gathering documents, applying a control framework and keeping the evidence of every verification. All three requirements are methodical and lend themselves to systematic execution. The judgement, on the other hand, rests with an authorised officer — the agent prepares and documents it.

Our answer

Your compliance department has files that are assembled, consistent and documented, where every verification keeps its source and its date. Approving a business relationship or reporting a transaction are regulated acts that belong to the authorised officer. Local inference or qualified hosting in France: your customers' identification and financial data does not leave your perimeter.

The decisive point

Your customers' identification and financial data: sovereignty & compliance

Know-your-customer data and anti-money-laundering checks call for the highest level of protection and traceability. Here is how it is achieved.

Local inference

The agent can run on a machine belonging to your organisation: no identification data and no financial data leaves the network.

Hosting in France

Otherwise, a dedicated and isolated resource hosted in France, under French law — your know-your-customer files and your checks: processing and access within the European Union targeted by the architecture.

Reduced extraterritorial exposure

For your customers' identification and financial data, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.

Isolated resource

No pooling: an environment strictly dedicated to your institution and its control procedures.

Evidence of every verification

Source, date and result are kept for every verification; encryption, role-based access and logging your auditors and your regulator can work from.

AI Act: governed deployment

The agent is strictly in support; no business relationship is approved and no report is filed automatically; traceability and human oversight from end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For every file in this area, as a matter of principle, SecNumCloud and reinforced hosting are options depending on your requirements. A single architecture is designed to answer both the GDPR and extraterritorial exposure. Designed for deployment in line with the GDPR and the AI Act, after the processing, roles and context-specific risks have been assessed.
Demonstration

See the agent at work

5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Banque Ostrelle — regional bank for professionals and businesses

Sector
Licensed regional bank — business accounts, equipment lending, factoring, merchant acquiring
Headcount
640 staff, including 18 in compliance (1 director, 9 authorised controllers, 5 analysts, 3 lawyers) and 210 in branches
People served
31,000 professional and business clients, served by 74 branches
Scale
4,800 client onboardings a year of which 2,100 are companies, 26,000 files in periodic review, 11,400 transaction monitoring alerts, 4,200 second-line checks
Tools in place
Core banking system, document vault, transaction monitoring tool and an internal control framework of 118 rules — the agent plugs in read-only, nothing is replaced or migrated
Who decides
The authorised controller approves every onboarding; the designated officer alone decides on any report; the compliance director settles the control framework
Room for improvement
Instructing a file takes 65 % of the file's time and is done by hand; applying the 118 rules takes 40 % of a review campaign; building the evidence takes 35 % of a check; onboarding a company takes 11 days and 14 % of applications are abandoned before the account opens

Ostrelle does not want to control less: it wants to control better and faster, because a file that drags for eleven days is a client who goes next door. The data it handles is its clients' identity documents, articles of association and financial flows. The agent runs on local inference on a machine belonging to the bank, or on a dedicated resource hosted in France; it plugs read-only into the core banking system, the document vault and the monitoring tool, it instructs and documents, and no onboarding and no report goes out without an authorised controller's decision. The exchanges below cover a year, from the first file instructed to the preparation for inspection.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

KYC/AML compliance · hosted in France
I went back through your 4,800 onboardings of the year and your 340 files in progress — the 340 have been instructed since last night, and I draw from them a figure your network carries without ever adding it up.
Onboarding is the moment the bank accepts a new client; know-your-customer is the set of identity and consistency checks that come before it.
The gap I measured, and it governs everything else: instructing a company file takes 65 % of the file's time — 130 minutes out of 200 —, and those 130 minutes are not control: they are documents being searched for, retyped and cross-checked.
What I hand over for each of the 340 files: the documents gathered and cross-checked, the consistency of the information verified point by point, the 118 rules of your framework applied with their result, and the points calling for an authorised controller's judgement set out at the top rather than scattered through the file.
What that shifts, calculated on your own timings: instruction goes from 65 % to 9 % of the file's time — from 130 minutes to 18. Across 2,100 company files, that is 3,920 hours given back to your branches and your analysts.
And the figure your commercial management will look at before the hours: onboarding a company takes 11 days at your bank, and 14 % of applications are abandoned before the account opens. On the 340 files instructed last night, the lead time falls to 2 daysthe only time left is the authorised controller's decision, and he decides on a complete file.
What I propose: that an authorised controller take the 12 oldest files this morning, approve or correct them, and tell me what he would have wanted to see at the top. Whatever he tells me about the twelve, I will apply to the other 328 before noon. know-your-customer-file_instructed.pdf130 minutes down to 18, 11 days down to 2
⛓ Sourced · 4,800 onboardings of the year, 340 files in progress, timings recorded by the network
Where do you find these documents? We cannot rely on just any source.
On a list of sources your lawyers have approved, and every document enters the file with the exact place it came from and the date I obtained it.
The four families of sources, and what each brings:
· Documents filed by the client — articles of association, director's identity document, proof of address. I read them, I cross-check them against each other, and I tell you what does not match.
· Public company registers — name, legal form, directors, date of registration, and the ownership chain up to the beneficial owners. The beneficial owner is the natural person who genuinely controls the company, beyond the companies that hold it.
· Sanctions lists and politically exposed persons lists, with the date and time of the search — it is that timestamp that makes the check stand up, not the result alone.
· Your own data — existing accounts of the group, past incidents, files of related companies. Across the 340 files, 47 had a link to an existing client that nobody had spotted.
The cross-checking, which is the real work: I compare the stated activity to the published activity code, the address on the proof to the one in the articles, the stated director to the published one, and the declared turnover to the accounts filed. Across the 340 files, 61 carried at least one discrepancy, and the 61 questions to the client are written, one per line, in a single email rather than in three successive chases.
The gain, for the client as much as for you: one single follow-up request instead of 2.4 on average last yearand it is the second chase that loses a director, not the first.
What I propose next: that your lawyers read over the list of sources and the equivalence rule attached to eachwhich source proves what, and for how long. It is written, it runs to three pages, and once signed it holds for the 4,800 files of the year. sources-and-equivalence-rules.pdf4 families of sources, 61 discrepancies across 340 files
⛓ Sourced · documents filed by clients, public company registers, lists searched and timestamped, the bank's client base
And when a document is missing, or out of date? That is our sore point on periodic review.
The file does not move without the document, and the document is requested on the day it is missing rather than at the next check. I have been through your 26,000 files in review.
Periodic review is the re-examination of a file for a client already onboarded, at a frequency your framework sets according to risk.
What reading the 26,000 gave:
· 4,940 files carry at least one out-of-date document — 19 %. Mostly directors' identity documents past their expiry and annual accounts not renewed.
· 2,180 of them are active high-volume clientsthe ones an inspection looks at first.
· The 4,940 renewal requests are written, each naming the document, its expiry date and the format expected. They go out in waves, at your pace, and I suggest starting with the 2,180.
A rule I hold to, and it protects you: a value I have not read, I do not write. A missing document never becomes “probably provided”, an untraceable beneficial owner never becomes “most likely the director”: I state what is missing, where I looked, who holds it, and I hand over the request already drafted to its recipient. That is what makes a ticked box in your file worth something.
The result measured over the first quarter of the campaign: 3,410 documents renewed out of 4,940 requested, average turnaround 9 days, and the remaining 1,530 are chased automatically at day 15 then escalated to the analyst at day 30 with the full chase history.
What I propose next: that every document be requested 45 days before it expires rather than after. Applied to the past year, that single rule would have prevented 3,900 of the 4,940 expiriesyou set the notice period, the rule is live the same day. out-of-date-documents_4940-of-26000.pdf19 % of files, 3,410 documents renewed
⛓ Sourced · 26,000 files in periodic review, document expiry dates, chase log for the quarter
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

One agent, several regulatory checks. All these uses work in support, subject to your approval.

Included in your agent The 4 capabilities essential to this promise are included, at no extra cost.
From 746 € excl. VAT / month

Assembling know-your-customer files

Gathers the identification documents your procedures call for.

Applying the control framework

Applies your control rules and presents the result obtained.

Evidence kept

Keeps the source, date and result of every verification performed.

Regulated sector

For the qualified hosting foundation, a dedicated offer exists.

Controls and safeguards These 5 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Sources, access rights and handling of questions with no answer Implement testing, explainability, human oversight and monitoring Record models, decisions, incidents and changes Protect consumers, data and regulated secrets

Need to go further?

These agents handle a different business process, with their own owner and their own price. They are added to this one.

Does your need fall outside this?

In 15 minutes we identify the most relevant agent — without oversizing the project.

Book the free audit Build your agent
The gain

How many files can a compliance department assemble?

By taking on the assembly of files and the building of the evidence, the effort shifts towards judgement. How large the gain is depends on your volume and remains to be confirmed by a pilot.

Assembling a file
Today · done by hand
File assembled
Applying the control framework
Today · done by hand
Rules applied
Building the evidence
Today · done by hand
Evidence kept
Indicative figures, not contractual, to be confirmed by a pilot on your volume of files and the breadth of your control framework. Approving a business relationship or reporting a transaction are regulated acts: they belong to the authorised officer.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

One package, one agent

A banking compliance agent (assembly, control framework, evidence), installed and operated for you.

Agility

Setup + controlled subscription

8,060 € excl. VAT setup
then 746 € excl. VAT/month — you invest at installation and pay a reduced subscription. Ideal for keeping the cost under control over time.
  • Installation, configuration and training for your teams
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, a dedicated and isolated resource
Order →
The simplest Serenity

All inclusive, no setup fee

1,191 € excl. VAT /month
all inclusive, immediate start. No upfront investment: a single subscription. Ideal for starting quickly and simply.
  • Setup included (installation, configuration, training)
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, managed end to end
Order →
100% Sovereign

On site, you own it

12,030 € excl. VAT setup
then 962 € excl. VAT/month · + hardware from 2,491 € (one-off purchase, in addition) — a sovereign computer installed on your premises, maintained remotely. Models run locally, your data returned at the end of the contract. 36-month commitment.
  • Hardware installed on your premises (you own it)
  • French / European AI models run locally
  • Secure remote maintenance (Pro support included)
Order →
Not included in the packages: AI consumption (model tokens), re-invoiced at real cost with no margin, and tracked in real time in your client area. Maintenance and supervision subscription for an initial term of 12 months for the Agility package, 24 months for the Serenity package and 36 months for the 100% Sovereign package, renewable; support levels (SLA 72 h / 24 h / 4 h) optional. Bespoke development, additional integrations or exceptional volumes are quoted separately. Support Monday to Friday, 9am to 6pm. Prices exclude VAT.
AI model: none of the AI models offered currently carries a fixed surcharge. When the selected model carries a cost, that cost is shown when you choose it, before you order, and re-invoiced at the cost incurred, with no mark-up; usage is billed at the publisher's price. Publishers' prices are published in US dollars: the amount re-invoiced is the amount in euros actually borne by Blue Lemon Agent on the publisher's invoice, at that invoice's exchange rate, with no commission or mark-up.
Included components and additional components Components included in the base offer: the Blue Lemon Agent software foundation, the AI models listed in the order journey, the standard channels (Microsoft Teams, Slack, WhatsApp Business, email, website chat, calendars, Microsoft 365 / Google Workspace, file storage, market VoIP telephony, professional social-media pages and accounts, Google Business Profile), hosting in France for the package chosen, backups, supervision, updates and support. If adapting the AI agent to your constraints, your needs or your requests requires other paid components — a third-party publisher's software licence, paid API access to one of your applications, hosting of health data, for which French law requires an HDS-certified host (art. L. 1111-8 of the French Public Health Code), SecNumCloud-qualified hosting, a speech synthesis service, particular hardware —, they are offered to you as an option or on quotation and re-invoiced at the cost incurred; nothing is committed without your written agreement. Where the artificial intelligence model you choose entails an additional cost, that cost is shown to you before you order and re-invoiced to you at the cost incurred, with no margin.
What to expect
Go-live 2 to 3 weeks
Agent designed, channels connected, team trained.
Steady state 4 to 7 weeks
After a few weeks of real use, once the agent's behaviour matches what you expect. Indicative estimate, adjusted to the options you keep. It is not a delivery commitment.
Our commitment

Four guarantees that matter in banking compliance

Your customers' data stays in FranceLocal inference or qualified hosting in France; no data entrusted to a third party, processing in the EU targeted, no data used to train a model.
Data in France, under French lawYour customers' identification and financial data: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
Your banking compliance department keeps the decisionThe agent produces control files that are assembled and traceable, which can be checked and altered; no approval is automated.
Human oversight & traceabilityOn your volume of files and the breadth of your control framework: systematic logging and tracking, in line with the AI Act.
Frequently asked questions

Your questions, our answers

Does the agent approve a business relationship?
No. It assembles the file, applies your control framework and keeps the evidence of every verification. Approving a business relationship is a regulated act that falls to the authorised officer.
Does it file reports?
No. Any report rests with the authorised officer. The agent gathers and documents the material that makes it possible to decide quickly.
Can the audit trail be shown to the regulator?
Yes: source, date and result are kept for every verification, with logging your auditors and your regulator can work from.
How is the control framework defined?
With you, at the design stage, from your internal procedures. The agent applies them as they stand and flags what they do not settle.
Where is the data hosted?
In France, on local inference or on qualified hosting, with the deployment objective of processing and access operated within the European Union and an architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
How long does it take to deploy this agent?
Several months as a rule, depending on the volume of files and the breadth of your framework, after a free audit then phases of design, integration and testing.
Let's talk

Let's size up the potential in your compliance checks

15 minutes to frame your procedures and your volumes — hosted in France, supervised, with no commitment.