Financial crime alert casework: the alert arrives built, the analyst decides on the evidence
Your monitoring system raises alerts; the cost lies in working them up. Your agent takes the alert exactly as it came out — with its source, the version of the scenario that fired and the reason it fired — files each case under the investigation purpose it belongs to, matches people and counterparties while naming their divergences, rebuilds the chronology of the transactions, attaches the records and writes down what is missing before anyone can decide. Hosted in France: a case file says who is being looked at and why, so it stays in the house. Closing an alert, resolving a name match and filing a report belong to the designated reporting officer — a person the law names and the administration knows.
Updated on
Every case file carries its dated transactions, its attached records, its favourable and unfavourable items at equal rank, and its missing items named.
An alert the data cannot settle comes back undetermined, never closed.
🔗 Sourced · alerts from the client's own monitoring system, with scenario version and intake date
The filing itself belongs to a person the law names: article R. 561-23 of the French Monetary and Financial Code identifies the reporting officer to Tracfin and to the supervisory authority, and any change is notified without delay. It is that name which makes the report stand — and the file is waiting, built, on the day of the alert.
✎ Framing · file built, review, signature and filing by the designated reporting officer
A Blue Lemon Agent for financial crime alert casework. It takes in the alerts your own monitoring system has already raised — the agent does not monitor transactions, your system stays yours, calibrated and supervised by you — then it keeps the four investigation purposes apart, matches entities across several attributes without ever silently resolving a divergence, dates the transactions, attaches the records and hands over a case file together with a draft statement of facts. Closing the alert and filing the report belong to the designated reporting officer, identified to Tracfin and to the supervisory authority. It runs on local inference or is hosted in France: your case files stay with you, an architecture designed to reduce exposure to extraterritorial legislation, location alone guaranteeing no immunity.
Reference points describing our offer, not results measured at a client. No detection rate, false-positive rate or coverage rate is claimed: none has been measured. How much you gain on your own alert volume, systems and headcount is confirmed by a pilot.
What does an AI agent bring to your alert casework?
An alert whose transactions are dated, records attached and gaps written down is settled within the sitting; a raw alert is worked up again by every hand that picks it up.
! What is at stake
The ACPR reviewed automated transaction-monitoring systems across thirty-six groups and entities, and recalls that the system belongs to the regulated firm, which calibrates and supervises it, human vigilance keeping a decisive part in it (ACPR, “Automated transaction-monitoring systems for AML/CFT”, published 26/04/2023; the publication itself states that it does not assess the regulatory compliance of the practices described). The joint ACPR and Tracfin guidelines hold vigilance over transactions and reporting together (joint guidelines, in force since 23/04/2025). What actually holds things up is not the decision: it is gathering the transactions, tracking down the records, matching entities that are not spelled the same way twice, and rebuilding a chronology. That work is systematic, and it can be prepared.
✓ Our answer
Your analyst opens a file that is already built: transactions dated, records attached, questions drafted, and what is missing written down together with the exact place to look for it. The four investigation purposes share no file, no access rights and no grounds for access: money laundering, sanctions, fraud and market abuse have neither the same recipient nor the same authorised people. A name match is never an identity: matching and diverging attributes are set side by side, and the name match stays open until a person resolves it. Local inference or a dedicated, isolated resource hosted in France: a file that says who is being looked at, and why, does not leave the company.
Your case files: sovereignty, separation and secrecy
A case file names people, transactions and suspicions. Its confidentiality is not a drafting precaution: it is a condition of going live.
Local inference
The agent can run on a machine inside your organisation: no alert, no record and no case file leaves the network.
Hosting in France
Otherwise, a dedicated, isolated resource hosted in France under French law — your alerts, your records and your files: processing and access operated in the European Union targeted by the architecture.
Reduced extraterritorial exposure
For your case files, the architecture aims to reduce exposure to the Cloud Act and FISA 702; location in France or in the European Union alone guarantees no immunity.
Four purposes, four walls
Transaction vigilance, sanctions, fraud, market abuse: each purpose has its own file, its own authorisations and its own grounds for access. No generic role runs across them.
Secrecy of the report
The existence of a report is disclosed to no unauthorised third party. Article L. 574-1 of the French Monetary and Financial Code attaches a criminal penalty to breaching that confidentiality: the access route must make disclosure materially impossible, and that requirement is tested before go-live.
Human oversight and traceability
Strictly a supporting agent: no alert closed, no name match resolved, no report produced or transmitted automatically. Classification under Regulation (EU) 2024/1689 is carried out on your real use, with your own counsel; the agent brings its logs to it, not a finding of compliance.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyGestion Vaubécourt — authorised portfolio management company, eleven funds including two unlisted real-estate funds
- Sector
- Fund management (French NAF class 66.3) — authorised portfolio management company: collective management of listed assets, two unlisted real-estate funds, direct distribution and distribution through financial investment advisers
- Headcount
- 38 staff, including one head of compliance and internal control, one second-level reviewer, nine fund managers, six sales staff and four in unitholder services
- Unitholders served
- 11 funds, 4,800 unitholders of which 310 are legal entities; assets under management doubled in four years with no change in compliance headcount
- Orders of magnitude
- 118 transaction-vigilance alerts on subscriptions and redemptions last year, 46 order-surveillance alerts, 700 files in periodic review of which 90 rated high risk and reviewed every year
- Systems already in place
- Order-entry system, position keeping, the transfer agent's document platform for subscriber records, order-surveillance system, and the French national asset-freeze register consulted on the Treasury's website — the agent works on the extracts that are deposited; nothing is replaced or migrated
- Who decides
- The head of compliance and internal control, the reporting officer designated to Tracfin and to the supervisory authority under article R. 561-23 of the French Monetary and Financial Code. Their name is given to the administration, and any change is notified without delay
- Room for improvement
- Of last year's 118 vigilance alerts, 41 files were closed citing a record that was never attached. The median delay between the alert and the first record gathered was 9 working days. And the 118 vigilance alerts and the 46 order-surveillance alerts were worked up in the same shared folder, although their recipients and the people authorised to see them are not the same
Gestion Vaubécourt doubled its assets under management in four years without strengthening compliance. The head of compliance and internal control works up the vigilance alerts alone, checks the orders, runs the periodic reviews and remains the only person authorised to report. The agent runs on local inference on a machine inside the company, takes in the alerts the systems in place have already raised and hands back built files: dated transactions, attached records, drafted questions, missing items named. The four tabs follow the year, from the intake of the alerts to the draft statement of facts handed in person to the designated reporting officer.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
Keeping them apart is not tidiness: transaction vigilance and suspicious orders and transactions do not share a recipient authority, and they do not share the people authorised to know about them. A single shared folder shows everyone what belongs to the other side.
What every alert now carries, and what was nowhere before: the system it came out of, the scenario that fired, with its version, the exact reason it fired, the time it was raised and the time it was taken in.
The result, alert by alert:
· 152 complete alerts — scenario, version and reason all present, ready to work up;
· 12 alerts returned as undetermined, and I am publishing the figure because it does not flatter me: your order-surveillance export does not carry the scenario version. Without the version, the rule applied cannot be quoted, and an alert whose governing rule is unknown is not worked up blind.
The fix, and it is a small one: that export already carries the scenario code; one field is missing. I have written the change request with the exact field name and a sample line — on your last three deposits, it would have brought those 12 down to zero.
What I suggest next: open one alert exactly as it comes out of the system, raw, so you can see precisely what I receive. alert-statement_two-routes.pdf164 alerts, 2 routes, 152 complete, 12 undetermined
⛓ Sourced · extracts deposited on 02/09: order-surveillance system, position keeping, transfer agent's document platform
What it carries in its own right: scenario RACH-04, version 2, adopted on 12 January 2026, the reason it fired — a full redemption requested less than twelve months after onboarding, to an account opened in a State other than the one of subscription — the unitholder identifier, the fund concerned and the timestamp.
The monitoring system stays yours, and that is good news for you: you calibrate it, you version it, you supervise it, and it is at your premises that your supervisory authority examines it. The ACPR says as much in its publication of 26 April 2023 on automated transaction-monitoring systems, drawn from a review of thirty-six groups and entities: the system belongs to the regulated firm, which calibrates and supervises it, and human vigilance keeps a decisive part in it. I come in after it fires, on the human part.
The four items I went and fetched to complete it, and where from: the profile known since onboarding (customer reference data), the last twelve months of movements on the fund (position keeping), the subscriber's records (the transfer agent's document platform), and the most recent periodic review file.
The raw alert runs to eight lines. The worked-up file runs to forty-three, and it is ready. Let us go through it. incoming-alert_VIG-2026-0118.pdfInput record · raw alert, scenario RACH-04 v2, reason it fired
⛓ Sourced · alert VIG-2026-0118 of 01/09 23:41, scenario RACH-04 v2 of 12/01/2026; ACPR publication of 26/04/2023, consulted on 07/09/2026
What the sorting produced:
· 29 records found on the transfer agent's document platform — they existed, they had simply never been attached to the file. They are attached now, with their deposit date. Those 29 files are complete and waiting for your review.
· 9 records to request from the unitholder or their adviser: source-of-funds evidence for seven of them, a renewed identity document for two. All nine requests are drafted, on your letterhead, ready to go out under unitholder services' signature.
· 3 files where the record cited does not exist and never did. They stay open as undetermined, with what would settle them written down.
The rule I suggest you adopt, and it fits on one line: a record that is cited is attached, or its absence is written down together with what would lift it. Run across your 118 files from last year, it would have stopped all 41 before they were closed — instead of letting them surface in an inspection.
The gain sits somewhere other than in those 41: a file closed citing a missing record costs twice — once at closing, and once when it has to be rebuilt two years later without the person who worked it up. reopened-files_41-missing-records.pdf41 files, 29 records found, 9 requests drafted, 3 undetermined
⛓ Sourced · 118 vigilance files from the previous year, transfer agent's document platform, closing log
The timestamped chronology, from the day of onboarding to the day of the alert: 17 movements over eleven months, including the initial subscription, three top-up payments, and the full redemption requested on 1 September to an account opened in a State other than the one of subscription. The map of relationships sets the accounts, counterparties and channels alongside it — the links are shown; no causal link is asserted: qualifying them is your reading, not mine.
The gap against the known profile, measured rather than felt: the profile recorded at onboarding stated an investment horizon of five to eight years. The redemption comes in month eleven. That gap is what makes the alert, and it can be quantified.
The two items that could explain it, found in your own records: a change of address declared to unitholder services on 14 June, and a letter of 3 July mentioning a property purchase. They are in the file, at the same rank as what points the other way — an item favourable to the unitholder is not a second-class record.
The three missing records, named, with the exact place to look: proof of the new bank domiciliation, source-of-funds evidence for the last top-up payment, and the acknowledgement of the change-of-address notification.
The question to put to the unitholder is drafted, in one sentence, revealing nothing about any examination.
The time benchmark, given as a fact about your past rather than as a promise: your median delay between the alert and the first record gathered was 9 working days last year. This file is built and readable within the hour after the deposit. What that will give across the 118 of the year remains to be established on your real data, and I will measure it file by file rather than announce it. chronology_VIG-2026-0118.pdf17 dated movements, profile gap quantified, 2 favourable items, 3 missing records
⛓ Sourced · 12 months of position keeping, customer reference data, transfer agent's document platform, unitholder services correspondence
Here is the complete case file, as you will open it: the dated transactions, the attached records with their deposit dates, the drafted questions, the items favourable to the unitholder and the unfavourable ones held at equal rank, and the three missing items named together with the system that holds them.
Its status, written at the top: undetermined. Missing data makes a file undetermined, never satisfied — a box ticked without a record does not exist. A file that cannot be assessed is not a file without risk, and calling it “compliant” would be the one real mistake available here.
What is already prepared and waiting only for your move:
· the request for the three records, drafted, addressed to unitholder services, with the deadline you set;
· the question to the unitholder, one sentence, which obtains the information without revealing that anything is being examined;
· the file itself, which recomputes as each record arrives — you re-enter nothing, and the forty-three lines already established stay put.
What belongs to you, and to no one else: pursue or close. No alert is closed without your intervention, whatever the outcome of the work — your signature is what gives a closure its standing in an inspection, and what makes the file hold.
The next step I suggest: that same RACH-04 scenario produced 19 alerts over the year. Eleven share this one's exact reason for firing. I can build all eleven files tonight, on the same pattern, and hand them to you in the format you have just approved. case-file_VIG-2026-0118.pdfOutput record · 43 lines, favourable and unfavourable at equal rank, status undetermined
✎ Framing · file returned as undetermined, records requested, closure reserved to the authorised analyst
The national asset-freeze register is a public State source, published by the French Treasury. The consultation was carried out by an authorised person in your company, and I keep the date and time of it with the file — that trace is what an inspector will ask for, not a screenshot.
What agrees and what diverges, set side by side:
· Company name — exact match, character for character.
· National identifier — diverging: the entity in your fund carries a French identifier; the listed entity carries none.
· Date of incorporation — nine years apart.
· Address — two different States.
· Declared beneficial owner — nothing in common in the records you hold.
One matching attribute out of five, four diverging. A matching company name is not an identity, and on its own it is never grounds to block. I leave the name match open: a divergence is not silently resolved, and that is what makes the file defensible either way.
The figure that does not flatter me, and I am publishing it: across your 310 legal entities, my matching proposals were rejected 7 times by your second-level reviewer during the dry run — every one of them a foreign entity with no national identifier, where the name was the only comparable attribute. 14 % error on that subset, and zero elsewhere.
The rule I drew from it, running ever since: an entity with no national identifier no longer receives an automatic matching proposal — it goes straight to human judgement, with its attributes set side by side. That is exactly what is happening on this file. matching-statement_legal-entity-subscriber.pdf5 attributes compared, 1 matching, 4 diverging, time of consultation kept
⛓ Sourced · national asset-freeze register consulted on 02/09 at 09:14 by an authorised person; subscriber records, transfer agent's document platform
The lawful route, in full, and it gets you what you are after:
· the body of indicators is assembled — five attributes set side by side, four of them diverging, with sources and times of consultation;
· the question to the subscriber is drafted: it asks for the entity's national identifier and its incorporation record, two items that settle the name match in a single reply, revealing nothing about any examination;
· the decision sheet is ready to sign, with the three possible outcomes and what each one commits you to;
· the file reopens on its own if the register is updated on this entity — I re-read the source and tell you, with the date.
What the four-eyes review produced on this file, and this is the part that will interest you most: the first level of analysis proposed pursue, the second level proposed undetermined until the subscriber replies. The disagreement is in the log, with both written reasons and both names. It is neither arbitrated by me nor erased: two reasoned opinions that diverge are worth more than a single opinion nobody discussed.
Who signs what: the head of compliance and internal control settles the alert's status; the second-level reviewer countersigns; any measure affecting the relationship with the unitholder is for management. Each of them is named in the file, with a date and a reason. case-log_four-eyes-review.pdf2 levels of analysis, 1 reasoned disagreement, access traced by purpose
✎ Framing · four-eyes review, disagreement logged, judgement to the head of compliance
What was taken in and handed back: 164 alerts taken in across two separate routes, 152 complete, 41 files reopened of which 29 completed, 10 records attached to each file on average, zero alerts closed without a human decision, zero writes into any external system.
What the quality follow-up surfaced, and nobody was measuring:
· the median age of an alert between it being raised and the first record gathered: 9 working days last year; what the pre-built file changes will be measured on your real data, alert by alert, and the counter is in place;
· reopened files: 41 out of 118, all for the same cause, a record cited without being attached;
· differences of assessment between levels: 6 reasoned disagreements over the year, 4 of them settled in favour of the second level — which is the sign that your four-eyes review is doing something;
· observed scenario changes: 3 surveillance scenarios changed version during the year, one of them without compliance being told. That is not a reproach to your team: nothing flagged it. I now flag it the same day, with the old and the new version, because an alert is assessed in the light of the rule that produced it.
The time this shifts, task by task: gathering the records and the transactions took up most of a casework; rebuilding the chronology came next; assembling the draft statement of facts closed the march. Those three are prepared in advance and reach you done. What stays on your desk is the judgement — the one task you did not want to delegate. casework-statement_year.pdf164 alerts, 6 reasoned disagreements, 3 scenario changes, 0 external writes
⛓ Sourced · log of the year's 164 alerts, scenario version log, register of reasoned opinions
The filing itself carries your name, and that is a rule of law: under article L. 561-15 of the French Monetary and Financial Code, the obligation to report falls on the persons listed in article L. 561-2 — regulated persons, not tools. And article R. 561-23 goes further: the person authorised to report, the reporting officer, is identified by name to Tracfin and to the supervisory authority, and any change is notified to them without delay. It is that name, given to the administration, which makes the report stand; no signature from a tool produces that effect.
The route is given in full, and it runs in a single sitting: you review the draft, you complete it with what only you know, you sign it, you file it yourself. The file is ready on the day of the alert; only the signature is left — and it is precisely the signature that makes the report stand.
On the markets side, the same principle and two routes: reporting suspicious orders and transactions goes through the AMF's channels, and the AMF describes two routes depending on the entity — the ROSA extranet for French investment firms and portfolio management companies, Sesterce for other entities. You are in the first, and the material is ready in the same format.
What the access route guarantees, and it is a condition of going live rather than a usage guideline: the existence of a report stays known to authorised people only. Article L. 574-1 attaches a criminal penalty to breaching that confidentiality — so the separation is tested before go-live, not recommended afterwards. draft-statement-of-facts_VIG-2026-0118.pdfMarked as a draft, handed in person to the designated reporting officer, not transmitted
✎ Framing · draft handed in person, filing reserved to the designated reporting officer; French Monetary and Financial Code arts. L. 561-15, R. 561-23, L. 574-1 and the AMF “suspicious transactions” page updated 05/02/2026, consulted 07/09/2026
· I open and build a file as soon as an alert is deposited, without waiting to be asked. An alert raised on a Friday evening does not sleep until Monday. And the reverse holds: if a record arrives and closes the gap, I recompute the file and tell you, with the record and its date.
· I chase twice, seven days apart, unitholder services for a missing record. I stop there: a third chase is an escalation, and an escalation carries a name — yours.
· I mark “stale source” on any extract older than the threshold you set, and take its alerts out of the year's count. The move undoes itself as soon as a fresh extract arrives, with nothing to re-enter.
Six decisions wait for your signature, and they fit on one record: close an alert, pursue it, resolve a name match, accept an item as sufficient, sign a draft statement of facts, open a measure affecting the relationship. Six moves, six signatures, each with a name, a date and a written reason.
Where all this runs: on a machine inside your company, on sovereign AI — local inference, or a dedicated isolated resource hosted in France. A case file says who is being looked at and why: it does not leave the house, and the four investigation purposes share no file, no access rights and no grounds for access.
One point I argue mechanically rather than morally: I produce no per-person indicator on the speed or the severity of assessments. The mechanism is simple — such an indicator would become a target, and an analyst under pressure closes faster by looking less. The instrument would destroy what it measures. One exception, and it is not really one: whoever signs is named. A signature is not a counter. who-decides-what.pdf3 reversible moves, 6 signed decisions, 0 individual indicators
✎ Framing · three reversible moves, six signed decisions, local inference or hosting in France
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
What does the agent actually do?
Nine modules included in the core offer, from taking in the alert to the draft statement of facts. All of them work in support, under the authorised analyst's decision.
Intake of your monitoring system's alerts
Takes in every alert exactly as it came out: its source, the version of the scenario that fired and the reason it fired. Your monitoring system stays yours — the agent neither replaces it nor recalibrates it.
Separation of the four investigation purposes
Money laundering, sanctions, fraud, market abuse: each purpose has its own file, its own access rights and its own route. Recipients and authorised people differ, and nothing crosses from one purpose to another.
Matching of people and counterparties
Matches people, accounts and counterparties across several attributes, and sets what agrees beside what diverges. A divergence is never silently resolved: the name match stays open until it is judged.
Chronology and map of relationships
Rebuilds the timestamped sequence of transactions and the map of their relationships — accounts, counterparties, channels. Links are shown; no causal link is asserted.
Case file
Gathers the transactions, the attached records, the questions asked, the favourable items, the unfavourable items and the missing items — each one named, with the exact place to look for what is missing.
Draft statement of facts
Drafts the statement of facts, plainly marked as a draft, and hands it to the designated reporting officer. Filing stays their act: article R. 561-23 identifies that person to Tracfin and to the supervisory authority.
Four-eyes review
Separates the roles, requires a written reason for every opinion, keeps the analyst's signature and logs the disagreements between the first and the second level.
Quality follow-up on the handling
Tracks alert age, reopened cases, differences of assessment between levels and observed scenario changes. The follow-up is on the handling, never on the people doing it.
Sovereign AI
The hosting and confidentiality foundation the agent rests on.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
Banking compliance KYC/AML
Working up the customer file and the onboarding — identification, internal control framework, evidence kept — belongs to customer due diligence, which this agent consults rather than redoes.
Banking compliance KYC/AML from 746 € excl. VAT / month Discover the agent →Financial analysis & signals
Reconciling internal flows in the ERP and documenting accounting gaps is internal work, upstream of any regulatory alert and with no third-party entity involved.
Financial analysis & signals from 641 € excl. VAT / month Discover the agent →Regulatory control
Applying a framework of rules to documents and issuing findings is a generic control, with no transactional object and no reporting route.
Regulatory control from 721 € excl. VAT / month Discover the agent →In 15 minutes we identify the most relevant agent — without oversizing the project.
Where does the time of a casework go?
By taking on the gathering of records, the rebuilding of the chronology and the assembly of the file, the effort shifts towards judgement. How much you gain depends on your volume and remains to be confirmed by a pilot.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
A casework core offer, priced on your own monitoring system
Scope is framed on the number of alerts received, the number of investigation purposes opened, the systems read and the evidential retention period required. It is priced on quotation, after reviewing your need.
Four commitments that matter for your case files
Related resources
Your questions, our answers
Does the agent monitor our transactions instead of our own system?
Can it report to Tracfin or file a suspicious transaction report?
How does it connect to our systems?
Does it query sanctions lists, asset-freeze registers and politically exposed persons lists?
What happens when a company name matches an entity in the asset-freeze register?
Can it close an alert on its own when nothing comes out?
How do you keep the four investigation purposes apart?
Does this page prove our compliance, or that the tool is approved?
Other agents for banking, finance and insurance
Let us frame the scope on your alerts and your investigation purposes
15 minutes to frame your monitoring system, the purposes you have opened and your systems — hosted in France, supervised, no commitment.