+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. If you already run an agent covering part of this scope, that part is not charged again: only the real extension is priced. Request a quote
● B2B offer — Banking, finance & insurance

Financial crime alert casework: the alert arrives built, the analyst decides on the evidence

Your monitoring system raises alerts; the cost lies in working them up. Your agent takes the alert exactly as it came out — with its source, the version of the scenario that fired and the reason it fired — files each case under the investigation purpose it belongs to, matches people and counterparties while naming their divergences, rebuilds the chronology of the transactions, attaches the records and writes down what is missing before anyone can decide. Hosted in France: a case file says who is being looked at and why, so it stays in the house. Closing an alert, resolving a name match and filing a report belong to the designated reporting officer — a person the law names and the administration knows.

Hosted in France Investigation purposes kept apart Records attached, gaps named The reporting officer decides

Updated on

Deployed in a few weeks
Financial crime alert casework · hosted in France
Where do this year's alerts stand?
Every alert is taken in with its source, the version of the scenario that fired and the reason it fired, then filed under its investigation purpose — transaction vigilance, sanctions, fraud, market abuse — which do not share recipients or access rights.
Every case file carries its dated transactions, its attached records, its favourable and unfavourable items at equal rank, and its missing items named.
An alert the data cannot settle comes back undetermined, never closed.
🔗 Sourced · alerts from the client's own monitoring system, with scenario version and intake date
Can it file the report itself?
The draft statement of facts is written, complete and ready to review: dated transactions, attached records, drafted questions, missing items named.
The filing itself belongs to a person the law names: article R. 561-23 of the French Monetary and Financial Code identifies the reporting officer to Tracfin and to the supervisory authority, and any change is notified without delay. It is that name which makes the report stand — and the file is waiting, built, on the day of the alert.
✎ Framing · file built, review, signature and filing by the designated reporting officer
Local inference · no data outside the EU
Case files hosted in France
Sovereign by designLocal inference or hosting in France
Dated, kept evidenceSource, rule version, time of consultation
TurnkeyDesigned, installed and run for you
The reporting officer decidesThe agent builds the case, it files nothing
✦ In brief

A Blue Lemon Agent for financial crime alert casework. It takes in the alerts your own monitoring system has already raised — the agent does not monitor transactions, your system stays yours, calibrated and supervised by you — then it keeps the four investigation purposes apart, matches entities across several attributes without ever silently resolving a divergence, dates the transactions, attaches the records and hands over a case file together with a draft statement of facts. Closing the alert and filing the report belong to the designated reporting officer, identified to Tracfin and to the supervisory authority. It runs on local inference or is hosted in France: your case files stay with you, an architecture designed to reduce exposure to extraterritorial legislation, location alone guaranteeing no immunity.

100 %
hosted in France in the target architecture
0
transfers outside the EU in the target architecture
9
casework modules included in the core offer
0
alerts closed without a human decision

Reference points describing our offer, not results measured at a client. No detection rate, false-positive rate or coverage rate is claimed: none has been measured. How much you gain on your own alert volume, systems and headcount is confirmed by a pilot.

The context

What does an AI agent bring to your alert casework?

An alert whose transactions are dated, records attached and gaps written down is settled within the sitting; a raw alert is worked up again by every hand that picks it up.

! What is at stake

The ACPR reviewed automated transaction-monitoring systems across thirty-six groups and entities, and recalls that the system belongs to the regulated firm, which calibrates and supervises it, human vigilance keeping a decisive part in it (ACPR, “Automated transaction-monitoring systems for AML/CFT”, published 26/04/2023; the publication itself states that it does not assess the regulatory compliance of the practices described). The joint ACPR and Tracfin guidelines hold vigilance over transactions and reporting together (joint guidelines, in force since 23/04/2025). What actually holds things up is not the decision: it is gathering the transactions, tracking down the records, matching entities that are not spelled the same way twice, and rebuilding a chronology. That work is systematic, and it can be prepared.

Our answer

Your analyst opens a file that is already built: transactions dated, records attached, questions drafted, and what is missing written down together with the exact place to look for it. The four investigation purposes share no file, no access rights and no grounds for access: money laundering, sanctions, fraud and market abuse have neither the same recipient nor the same authorised people. A name match is never an identity: matching and diverging attributes are set side by side, and the name match stays open until a person resolves it. Local inference or a dedicated, isolated resource hosted in France: a file that says who is being looked at, and why, does not leave the company.

The decisive point

Your case files: sovereignty, separation and secrecy

A case file names people, transactions and suspicions. Its confidentiality is not a drafting precaution: it is a condition of going live.

Local inference

The agent can run on a machine inside your organisation: no alert, no record and no case file leaves the network.

Hosting in France

Otherwise, a dedicated, isolated resource hosted in France under French law — your alerts, your records and your files: processing and access operated in the European Union targeted by the architecture.

Reduced extraterritorial exposure

For your case files, the architecture aims to reduce exposure to the Cloud Act and FISA 702; location in France or in the European Union alone guarantees no immunity.

Four purposes, four walls

Transaction vigilance, sanctions, fraud, market abuse: each purpose has its own file, its own authorisations and its own grounds for access. No generic role runs across them.

Secrecy of the report

The existence of a report is disclosed to no unauthorised third party. Article L. 574-1 of the French Monetary and Financial Code attaches a criminal penalty to breaching that confidentiality: the access route must make disclosure materially impossible, and that requirement is tested before go-live.

Human oversight and traceability

Strictly a supporting agent: no alert closed, no name match resolved, no report produced or transmitted automatically. Classification under Regulation (EU) 2024/1689 is carried out on your real use, with your own counsel; the agent brings its logs to it, not a finding of compliance.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For entities under a sector-specific regime — credit institutions, investment firms, portfolio management companies, essential or important entities — SecNumCloud and reinforced hosting options are available according to your level of requirement. Whether a given text applies is checked entity by entity, and this page is neither a finding nor a guarantee.
Demonstration

See the agent at work

4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Gestion Vaubécourt — authorised portfolio management company, eleven funds including two unlisted real-estate funds

Sector
Fund management (French NAF class 66.3) — authorised portfolio management company: collective management of listed assets, two unlisted real-estate funds, direct distribution and distribution through financial investment advisers
Headcount
38 staff, including one head of compliance and internal control, one second-level reviewer, nine fund managers, six sales staff and four in unitholder services
Unitholders served
11 funds, 4,800 unitholders of which 310 are legal entities; assets under management doubled in four years with no change in compliance headcount
Orders of magnitude
118 transaction-vigilance alerts on subscriptions and redemptions last year, 46 order-surveillance alerts, 700 files in periodic review of which 90 rated high risk and reviewed every year
Systems already in place
Order-entry system, position keeping, the transfer agent's document platform for subscriber records, order-surveillance system, and the French national asset-freeze register consulted on the Treasury's website — the agent works on the extracts that are deposited; nothing is replaced or migrated
Who decides
The head of compliance and internal control, the reporting officer designated to Tracfin and to the supervisory authority under article R. 561-23 of the French Monetary and Financial Code. Their name is given to the administration, and any change is notified without delay
Room for improvement
Of last year's 118 vigilance alerts, 41 files were closed citing a record that was never attached. The median delay between the alert and the first record gathered was 9 working days. And the 118 vigilance alerts and the 46 order-surveillance alerts were worked up in the same shared folder, although their recipients and the people authorised to see them are not the same

Gestion Vaubécourt doubled its assets under management in four years without strengthening compliance. The head of compliance and internal control works up the vigilance alerts alone, checks the orders, runs the periodic reviews and remains the only person authorised to report. The agent runs on local inference on a machine inside the company, takes in the alerts the systems in place have already raised and hands back built files: dated transactions, attached records, drafted questions, missing items named. The four tabs follow the year, from the intake of the alerts to the draft statement of facts handed in person to the designated reporting officer.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

Financial crime alert casework · hosted in France
The year's 164 alerts are taken in and sorted: 118 transaction-vigilance alerts on subscriptions and redemptions on one side, 46 order-surveillance alerts on the other. Two routes, two sets of authorisations, two recipients.
Keeping them apart is not tidiness: transaction vigilance and suspicious orders and transactions do not share a recipient authority, and they do not share the people authorised to know about them. A single shared folder shows everyone what belongs to the other side.
What every alert now carries, and what was nowhere before: the system it came out of, the scenario that fired, with its version, the exact reason it fired, the time it was raised and the time it was taken in.
The result, alert by alert:
· 152 complete alerts — scenario, version and reason all present, ready to work up;
· 12 alerts returned as undetermined, and I am publishing the figure because it does not flatter me: your order-surveillance export does not carry the scenario version. Without the version, the rule applied cannot be quoted, and an alert whose governing rule is unknown is not worked up blind.
The fix, and it is a small one: that export already carries the scenario code; one field is missing. I have written the change request with the exact field name and a sample line — on your last three deposits, it would have brought those 12 down to zero.
What I suggest next: open one alert exactly as it comes out of the system, raw, so you can see precisely what I receive. alert-statement_two-routes.pdf164 alerts, 2 routes, 152 complete, 12 undetermined
⛓ Sourced · extracts deposited on 02/09: order-surveillance system, position keeping, transfer agent's document platform
Show me one alert exactly as it comes out of the system. I want to see what you receive.
Here it is, untouched: alert VIG-2026-0118, raised on 1 September at 23:41 by your monitoring system on an atypical redemption.
What it carries in its own right: scenario RACH-04, version 2, adopted on 12 January 2026, the reason it fired — a full redemption requested less than twelve months after onboarding, to an account opened in a State other than the one of subscription — the unitholder identifier, the fund concerned and the timestamp.
The monitoring system stays yours, and that is good news for you: you calibrate it, you version it, you supervise it, and it is at your premises that your supervisory authority examines it. The ACPR says as much in its publication of 26 April 2023 on automated transaction-monitoring systems, drawn from a review of thirty-six groups and entities: the system belongs to the regulated firm, which calibrates and supervises it, and human vigilance keeps a decisive part in it. I come in after it fires, on the human part.
The four items I went and fetched to complete it, and where from: the profile known since onboarding (customer reference data), the last twelve months of movements on the fund (position keeping), the subscriber's records (the transfer agent's document platform), and the most recent periodic review file.
The raw alert runs to eight lines. The worked-up file runs to forty-three, and it is ready. Let us go through it. incoming-alert_VIG-2026-0118.pdfInput record · raw alert, scenario RACH-04 v2, reason it fired
⛓ Sourced · alert VIG-2026-0118 of 01/09 23:41, scenario RACH-04 v2 of 12/01/2026; ACPR publication of 26/04/2023, consulted on 07/09/2026
And last year's 41 files, closed citing a record that was never attached?
All 41 are reopened, and each one names the exact record that is missing and the system that holds it. It is no longer a list of reproaches; it is a shopping list.
What the sorting produced:
· 29 records found on the transfer agent's document platform — they existed, they had simply never been attached to the file. They are attached now, with their deposit date. Those 29 files are complete and waiting for your review.
· 9 records to request from the unitholder or their adviser: source-of-funds evidence for seven of them, a renewed identity document for two. All nine requests are drafted, on your letterhead, ready to go out under unitholder services' signature.
· 3 files where the record cited does not exist and never did. They stay open as undetermined, with what would settle them written down.
The rule I suggest you adopt, and it fits on one line: a record that is cited is attached, or its absence is written down together with what would lift it. Run across your 118 files from last year, it would have stopped all 41 before they were closed — instead of letting them surface in an inspection.
The gain sits somewhere other than in those 41: a file closed citing a missing record costs twice — once at closing, and once when it has to be rebuilt two years later without the person who worked it up. reopened-files_41-missing-records.pdf41 files, 29 records found, 9 requests drafted, 3 undetermined
⛓ Sourced · 118 vigilance files from the previous year, transfer agent's document platform, closing log
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

Nine modules included in the core offer, from taking in the alert to the draft statement of facts. All of them work in support, under the authorised analyst's decision.

Included in your agent The 9 capabilities essential to this promise are included, at no extra cost.

Intake of your monitoring system's alerts

Takes in every alert exactly as it came out: its source, the version of the scenario that fired and the reason it fired. Your monitoring system stays yours — the agent neither replaces it nor recalibrates it.

Separation of the four investigation purposes

Money laundering, sanctions, fraud, market abuse: each purpose has its own file, its own access rights and its own route. Recipients and authorised people differ, and nothing crosses from one purpose to another.

Matching of people and counterparties

Matches people, accounts and counterparties across several attributes, and sets what agrees beside what diverges. A divergence is never silently resolved: the name match stays open until it is judged.

Chronology and map of relationships

Rebuilds the timestamped sequence of transactions and the map of their relationships — accounts, counterparties, channels. Links are shown; no causal link is asserted.

Case file

Gathers the transactions, the attached records, the questions asked, the favourable items, the unfavourable items and the missing items — each one named, with the exact place to look for what is missing.

Draft statement of facts

Drafts the statement of facts, plainly marked as a draft, and hands it to the designated reporting officer. Filing stays their act: article R. 561-23 identifies that person to Tracfin and to the supervisory authority.

Four-eyes review

Separates the roles, requires a written reason for every opinion, keeps the analyst's signature and logs the disagreements between the first and the second level.

Quality follow-up on the handling

Tracks alert age, reopened cases, differences of assessment between levels and observed scenario changes. The follow-up is on the handling, never on the people doing it.

Sovereign AI

The hosting and confidentiality foundation the agent rests on.

Controls and safeguards These 8 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Named and dated human approval on closing an alert, on resolving a name match and on any draft statement of facts Any missing data makes the result “undetermined” and never “satisfied”: a box ticked with no record does not exist Every record cited is attached to the case file, or its absence is written down together with what would resolve it Every rule applied carries its version and the date it was consulted Favourable items and unfavourable items kept on an equal footing, on screen as in exports The four investigation purposes share no file, no access rights and no grounds for access The analyst who works up the case is not the one who approves it, and the log keeps both names No imported content is executed as an instruction: an ingested document is data
The gain

Where does the time of a casework go?

By taking on the gathering of records, the rebuilding of the chronology and the assembly of the file, the effort shifts towards judgement. How much you gain depends on your volume and remains to be confirmed by a pilot.

Gathering the records and transactions of an alert
Today · done by hand
Records attached, gaps named
Rebuilding the chronology and the relationships
Today · done by hand
Chronology produced, links shown
Assembling the draft statement of facts
Today · done by hand
Draft written, to review and sign
Illustrative, non-contractual reference points, to be confirmed by a pilot on your alert volume, your systems and your headcount. No analysis turnaround is promised: it depends on your monitoring system and your resources. Closing an alert, resolving a name match and filing a report belong to the people the law designates.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Scope

A casework core offer, priced on your own monitoring system

Scope is framed on the number of alerts received, the number of investigation purposes opened, the systems read and the evidential retention period required. It is priced on quotation, after reviewing your need.

This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. Request a quote
Our commitment

Four commitments that matter for your case files

Your case files stay with youLocal inference or a dedicated, isolated resource hosted in France; no alert or record entrusted to a third party, no data used to train a model.
Data in France, under French lawYour alerts, your records and your case files: minimisation and location in France, an architecture designed to reduce exposure to extraterritorial legislation, location alone guaranteeing no immunity.
The designated reporting officer keeps the decisionThe agent builds files that can be checked and amended and drafts the statement of facts; closing, resolving a name match, signing and filing stay the acts of people named in the file.
Dated, logged evidenceEvery rule applied carries its version and the date it was consulted; every opinion carries its author, its date and its written reason; disagreements between levels of analysis stay in the log.
Frequently asked questions

Your questions, our answers

Does the agent monitor our transactions instead of our own system?
No, and this is not a setting. The monitoring system is yours: you calibrate it, you version it, you supervise it, and your supervisory authority examines it at your premises. The agent comes afterwards: it takes in the alert that system raised, with the version of the scenario that fired and the reason it fired, and works it up.
Can it report to Tracfin or file a suspicious transaction report?
No. Under article L. 561-15 of the French Monetary and Financial Code, the obligation to report falls on the persons listed in article L. 561-2: regulated persons, not tools. Article R. 561-23 goes further — the person authorised to report, the “reporting officer”, is identified by name to Tracfin and to the supervisory authority, and any change is notified to them without delay. On the markets side, suspicious transaction reporting goes through the AMF's channels, and the AMF describes two routes depending on the entity: the ROSA extranet for French investment firms and portfolio management companies, Sesterce for the others. The agent prepares the material; it opens no channel and sends nothing.
How does it connect to our systems?
Through the extracts you deposit, in the format you already produce, with their date — that is what works today and that is what is sold here. Reading your monitoring system, your case-management tool, your customer reference data or your document management directly is handled case by case, under a written mandate, after a feasibility study: it is announced only once it is established and documented.
Does it query sanctions lists, asset-freeze registers and politically exposed persons lists?
Not today, and we would rather write it than let it be assumed: no source of that kind is under contract, and an unproven capability is not sold. What does exist: the French national asset-freeze register is a public State source, consulted by an authorised person in your organisation; the agent keeps the date and time of that consultation with the file, and sets the matching attributes beside the diverging ones. Opening a contracted source is a decision currently pending.
What happens when a company name matches an entity in the asset-freeze register?
The body of indicators is assembled and presented, not concluded. The agent sets matching and diverging attributes side by side — national identifier, date of incorporation, address, declared beneficial owner — keeps the date and time the register was consulted, and hands the judgement to the head of compliance. A matching company name alone is neither an identity nor grounds to block, and freezing measures are decided by the competent authorities.
Can it close an alert on its own when nothing comes out?
No. No alert is closed without human intervention, whatever the outcome of the handling. Work that does not conclude comes back “undetermined” and states what is missing to settle it, with the exact place to look: a file that cannot be assessed is not a file without risk.
How do you keep the four investigation purposes apart?
They share no file, no access rights and no grounds for access. Transaction vigilance, sanctions, fraud and market abuse have neither the same recipient, nor the same authority, nor the same authorised people: the market abuse regime comes under Regulation (EU) No 596/2014 and the AMF, transaction vigilance under the French Monetary and Financial Code and Tracfin. No generic role runs across the four, and every access carries its grounds.
Does this page prove our compliance, or that the tool is approved?
No, on both counts. No ACPR publication approves a piece of software — the 2023 publication on automated monitoring systems states itself that it does not assess the regulatory compliance of the practices described. And the classification of your processing, under the GDPR as under Regulation (EU) 2024/1689, is done on the real use at your premises, with your data protection officer and your counsel. The agent produces dated records and logs that can be used in an inspection; it issues no finding of compliance.
Let's talk

Let us frame the scope on your alerts and your investigation purposes

15 minutes to frame your monitoring system, the purposes you have opened and your systems — hosted in France, supervised, no commitment.