InfoSecured financial AI assurance

AML AI Assurance Evidence Kit

Turn an AML AI review into evidence a decision owner can follow.

Review AI-supported anti-money laundering (AML) monitoring in one Excel workbook. Connect the alert workflow, evidence, testing, analyst actions and changes to a clear decision and follow-up.

Version 1.1 · 16 worksheets · 24 AML review prompts

Put it to work

Review the parts of AML monitoring that AI changes.

The pack is designed for financial-crime, AML, model-risk, technology-risk, internal-audit, compliance and AI-governance teams. Start with the decision the review needs to support.

Review alert prioritization
Test whether ranking, suppression or queue logic changes effective coverage, review timing or escalation.
Assess an AML model or AI change
Connect a new model, rule, threshold, data source or vendor release to affected claims, evidence and retesting.
Examine analyst oversight
Record what reviewers saw, what authority they had, what they did and whether the downstream effect occurred.
Prepare an assurance or audit discussion
Bring unresolved findings, evidence limitations, failed tests, change events and the decision basis into one reviewable record.

Inside version 1.1

16 worksheets. One connected review.

Working registers start blank. The fictional example is isolated on its own sheet, and live summary measures are driven only by your records.

Start
Start Here
Choose the review scope, follow the first-review sequence and understand the workbook’s checks.
Define
Review Brief · Claims · Risks & Controls
Monitoring scope, population, AI role, criteria, testable assertions and accountable safeguards.
Examine
Evidence · Tests · Human Oversight
Evidence roots, scope fit, sampling, observed results and verified human intervention effects.
Trace AML work
AML Workflow
Alert-review stage, AI output, reviewer action, rationale, escalation, handoff and outcome.
Track change
Model & Data Events
Model releases, rule and threshold changes, data issues, vendor changes and reassessment needs.
Act and decide
Findings · Decisions · Review Summary
Correction, closure verification, linked evidence/tests/findings, conditions and reassessment.
Use the references
Field Guide · Review Library · Worked Example · Sources & Method
Field examples, 24 AML prompts, a connected scenario and source/migration notes.
Specialist registerAML Workflow
FieldWhat it records
Workflow stageAlert generation, prioritization, review, escalation, case support, QA or another bounded stage.
AI / automation roleWhat the component detected, scored, ranked, summarized, recommended or routed.
Reviewer actionThe human action taken after reviewing the available information.
Rationale / decision basisThe evidence, criteria and uncertainty behind the reviewer action.
Outcome statusWhether the workflow item remains open, awaits information, escalated, resolved or closed.

Use the same Claim ID across the records. Separate link tables connect decisions to supporting evidence, tests and findings.

Built for working in Excel: editable fields, dropdowns, filters, frozen identifiers, direct worksheet guidance and formula-driven completion checks. Core and specialist registers include prepared rows for review work.

24 AML assurance prompts

Choose prompts for population coverage, data quality, alert generation, prioritization and suppression, reviewer authority, escalation, QA, model and data changes, delayed labels, performance, vendor change, evidence provenance and decision traceability.

Each prompt connects a testable claim to a failure to examine, a control objective, a suggested test and evidence to request. Select prompts because they fit the institution’s workflow and criteria—not because every prompt is universally required.

Follow one review

Does prioritization create an unreviewed population?

The fictional worked example follows an alert-ranking workflow from claim to restricted use. It tests whether lower-priority and suppressed items receive the institution-defined handling, and whether the evidence actually covers that population.

  1. Claim

    Lower-priority alerts still receive the defined review treatment.

    The review specifies the population, release and queue-handling criterion before examining results.

  2. Evidence

    The reconciliation covers only part of the workflow.

    Generated alerts reconcile to the queue, but upstream suppressions are excluded. A management deck repeats the same underlying analysis.

  3. Test

    Suppressed records lack a traceable rationale.

    Sampling identifies records whose suppression cannot be reconstructed from the approval and evidence trail.

  4. Decision

    Restrict use until the failed path is corrected.

    The owner disables upstream suppression, reroutes affected items for review and requires daily reconciliation and historical impact assessment. Suppression stays disabled until correction and retesting support a new decision.

Keep coverage, evidence and human action connected.

Two documents can repeat the same underlying analysis. The example records that dependence, identifies the missing population, verifies the reviewer’s intervention and carries the failed test into the restriction and retest.

Your first review

Choose one AML workflow and one consequential claim.

Use a bounded scope first. Add claims, evidence and specialist records only where they help answer the decision question.

Download version 1.1

Excel .xlsx · 16 worksheets · 24 AML review prompts

  1. Read Start Here, then set the context. In Review Brief, define the workflow, population, AI role, version, review period and decision owner.
  2. Make the claim testable. Use Review Library to choose a relevant prompt. In Claims, define what must be true and what would fail the review.
  3. Challenge the evidence. Use Field Guide for example inputs. Record evidence roots and scope, test the workflow, examine sampling and label limitations, and verify reviewer effects.
  4. Carry gaps into the decision. Assign Findings, connect their IDs in Decisions, link supporting evidence and tests, and set conditions, owners and reassessment triggers. Review Summary surfaces gaps to examine.

Sensitive AML records: use organization-approved storage, access controls and retention practices. Reference detailed customer, alert, case or investigation evidence in the appropriate controlled repository rather than duplicating unnecessary sensitive information.

Decision boundary: the workbook structures assurance evidence. It does not make suspicious activity report (SAR) filing decisions, establish AML compliance or by itself validate a model. Formula checks flag record gaps; accountable reviewers judge the evidence and decision.

Method and sources

Use sources within their scope.

The architecture follows the current InfoSecured Review Kit: claims, evidence roots, tests, human effects, findings and explicit decisions. The AML specialization adds alert-workflow records, model/data events and a source-linked AML prompt library.

The source basis combines current U.S. BSA/AML materials, bank model/data guidance, AI risk and assurance references, and AML practitioner research. The workbook preserves each source’s scope instead of turning the source list into a universal compliance checklist.

Primary sources and research
  1. FFIEC BSA/AML Manual — Suspicious Activity Reporting: monitoring, alert management, decision-making and escalation context.
  2. FFIEC Suspicious Activity Reporting Examination Procedures: process mapping, filtering, alert management and testing questions.
  3. FinCEN Suspicious Activity Reporting FAQs, October 2025: selected SAR clarifications. The BSA does not require or expect documentation of decisions not to file a SAR; selected rationale fields support the institution’s own policy and assurance needs.
  4. OCC Bulletin 2026-13 — Revised Model Risk Management Guidance: nonbinding guidance for traditional statistical and quantitative models. Simple deterministic rules without the specified theoretical basis, generative AI and agentic AI are outside its defined scope.
  5. BCBS 239 implementation material: data aggregation and governance context. The 2026 newsletter is informational and introduces no new supervisory expectations; applicability depends on the institution and national implementation.
  6. NIST AI RMF 1.0: voluntary AI risk context, measurement, monitoring and change.
  7. Oztas et al., 2024: qualitative AML transaction-monitoring practitioner research.
  8. Königstorfer & Thalmann, 2022: AI-specific documentation and audit-evidence context.

The workbook contains the full source inventory and source-specific limitations. U.S. banking materials are a reference context; identify the rules, supervisory expectations and internal policies that apply to your institution before using a prompt as a review criterion.

What changed from v0.2?

The former v0.2 file was a 20-sheet public research prototype built primarily around documentation prompts and technical consistency checks. Version 1.1 consolidates that material into a working assurance structure: blank organizational registers, explicit claims and criteria, evidence roots, tests, human-oversight effects, findings and authorized decisions.

Two AML-specific registers preserve the strongest specialist value from the earlier v0.2 workbook: AML Workflow for alert-review and escalation records, and Model & Data Events for changes that can invalidate earlier evidence. Sources & Method contains migration guidance for older records.