Learn more about the latest security and privacy threats

Compliance as a service

Compliance as a service, run by AI review desks.

Most compliance vendors sell you a tool and leave the queue with your analysts. Zyphe runs the queue. Each desk is an operated review line: agents work every case against your policy, build a file with the reasoning attached, and hand it to your team to approve. The decisions the law reserves for you stay with you.

Review desk on SLA YOUR QUEUE Screening hit · name match Negative news · periodic sweep AGENT PREPARES Compared against your matching policy Evidence gathered, each item cited to its source Rationale written out, not a confidence score APPROVAL BOUNDARY · ART. 18(3) Your reviewer decides Risk profile, the relationship, and any report to the FIU Approve Return

In short: Compliance as a service means a provider performs your compliance operations work rather than selling you a tool to do it with. Zyphe delivers it as operated review desks: you agree a queue and a service level, agents work every case against your own policy and produce a decision-ready file with the reasoning attached, and your team approves. Under Article 18 of the EU anti-money laundering regulation, six categories of decision are reserved to the obliged entity, including the customer risk profile, the decision to enter a business relationship, and reporting to the FIU. Those stay with your MLRO by design, not by exception.

Last reviewed 2026-08-20.

Which review desk should join your team?

Each desk is one queue, operated end to end. Start with the one that is costing you the most analyst hours, and add the next when the first is clearing.

Five desks, not a roster of a dozen. Everything listed here is work Zyphe operates today, because a published desk is a commitment, not a roadmap entry. If your queue is a different shape, tell us what it looks like.

How does an operated desk work?

The same four steps whichever queue you start with.

  1. 1

    Agree the queue

    You pick one queue and the slice of it a desk takes: a segment, a market, an alert type, or a volume band. Not the whole function, and not a platform migration.

  2. 2

    The desk runs on your policy

    Your matching thresholds, your risk taxonomy, your lookback periods. The desk applies the policy you approved. It does not bring its own and call it a best practice.

  3. 3

    Cases are worked to a service level

    The queue is worked continuously rather than accumulating until someone has capacity. Every case leaves with its evidence and its written rationale.

  4. 4

    Your team approves

    Reviewers see a prepared file and either approve it or send it back. The decisions the law reserves for the obliged entity never leave your side of the line.

What can you actually hand to a service provider?

Worth knowing before any vendor conversation, including this one.

AMLR ART. 18(1) Work a desk can take Most of the hours a compliance team spends Retrieving records and list entries Comparing against your matching policy Reading source coverage, not headlines Walking ownership chains to natural persons Screening every person the chain produces Drafting the rationale and assembling the file AMLR ART. 18(3) Never leaves your firm Not outsourced under any circumstances The business-wide risk assessment Internal policies, procedures and controls The customer risk profile Entering into a business relationship Reporting suspicious activity to the FIU Approval of the detection criteria Art. 18(2): the provider counts as part of your firm, you stay fully liable, and you must be able to demonstrate you understand the rationale behind its work. Narrow derogations exist in Art. 18(3)(e) and Art. 18(7). Neither reaches a typical bank, payment institution, EMI or CASP.

Never outsourced, under any circumstances

AMLR Article 18(3)

  • The proposal and approval of your business-wide risk assessment
  • The approval of your internal policies, procedures and controls
  • The decision on the risk profile attributed to a customer
  • The decision to enter into a business relationship or carry out an occasional transaction
  • Reporting suspicious activity, or threshold-based reports, to your FIU
  • The approval of the criteria used to detect suspicious or unusual transactions

And what that leaves

Everything else: the gathering, the comparing, the reading, the chain-walking, the drafting. That is the overwhelming majority of the hours a compliance operations team spends, and it is what a desk takes. Article 18(1) of Regulation (EU) 2024/1624 permits it explicitly, provided you notify your supervisor before the provider starts.

Two conditions come with it. Article 18(2) treats the provider as part of your firm and leaves you fully liable, and it requires you to be able to demonstrate to your supervisor that you understand the rationale behind what the provider does. Article 18(4) requires a written agreement and regular controls that the provider is applying your policies.

Both of those are design constraints, not paperwork. They are why every case leaves a Zyphe desk with a written rationale rather than a confidence score, and why your policy is the one being applied.

Two qualifications belong with that list. Article 18(3)(e) permits FIU reporting to be outsourced to another obliged entity in the same group and established in the same Member State. Article 18(7) lets a collective investment undertaking without legal personality outsource points (c), (d) and (e) to one of its service providers, once it has notified its supervisor and the supervisor has approved. Neither reaches a typical bank, payment institution, electronic money institution or crypto-asset service provider.

Approving an individual alert disposition is not itself an Article 18(3) requirement. The Regulation governs the decisions listed above; how much of the rest your team reviews is set by your own policy. Zyphe returns every case for approval because that is the service boundary we sell, not because a regulation compels it case by case.

Regulation (EU) 2024/1624 applies from 10 July 2027. National outsourcing rules apply until then.

Proof over promises.

We publish what we can verify. Figures below are from Zyphe deployments; detailed references are available under NDA.

Alert triage

Screening alerts discounted per agent, per day

600

Reviews at scale

Customer reviews handled with Zyphe agents

120,000+

Customer outcomes

Operational cost saved across deployments to date

$3.3M

Market coverage

Markets where Zyphe runs verification and screening

52

Design partner program

Paid pilots clearing a fixed slice of your review queue under SLA

Open

A desk, a hire, or a BPO?

The three ways teams cover a growing review queue, and what each one actually costs once you count the loaded hours.

Hiring adds capacity you have to recruit, train and retain, and it takes months before the first alert is worked. A BPO is faster to stand up, but you are still buying hours, and consistency follows the shift roster. Run your own numbers on the comparison page before you talk to anyone.

Compare the three

Frequently asked questions about compliance as a service.

What is compliance as a service?

Compliance as a service is a model where a provider performs compliance operations work on your behalf, rather than licensing you software to perform it yourself. It typically covers high-volume, well-defined work such as screening alert review, adverse media review, periodic KYC refresh and enhanced due diligence file preparation. The regulated firm keeps the obligations, the policy and the decisions. The provider takes the throughput.

How is an agent desk different from a compliance BPO?

A BPO scales by adding people, so cost tracks volume and quality tracks whoever is on shift that week. A desk scales by adding agent capacity against a policy that is applied identically every time, and every case carries the reasoning that produced it. The commercial difference is that you stop paying for hours. The audit difference is that consistency stops depending on staffing.

How is this different from buying compliance software?

Software returns a decision or an alert and leaves the queue with your analysts. That is the part most teams are actually short-staffed on. A desk takes the queue. If you would rather run the work in-house, the same capabilities are available as product surfaces, and plenty of teams should choose that instead.

Can AI make compliance decisions under EU law?

Not the ones that matter. AMLR Article 18(3) puts six categories of decision permanently with the obliged entity, and GDPR Article 22 constrains decisions based solely on automated processing that produce legal or similarly significant effects on a person. This is why Zyphe agents prepare cases and humans approve them. It is also why the reasoning is written out: AMLR Article 18(2) requires you to be able to demonstrate to your supervisor that you understand the rationale behind what your provider does.

Do we have to tell our supervisor?

Yes. AMLR Article 18(1) requires the obliged entity to notify its supervisor of the outsourcing before the service provider starts carrying out the outsourced task, and Article 18(4) requires a written agreement and regular controls to check the provider is actually applying your policies. The Regulation applies from 10 July 2027; your national outsourcing rules apply in the meantime, so check what your supervisor requires today.

Can we start with one desk?

That is the normal way in. A paid pilot takes a fixed slice of one queue under a service level, runs alongside your existing process rather than replacing it, and gives you real files to inspect. Teams that add a second desk do it once the first one is clearing.

Book a demo

Put one queue on a desk and watch it clear.

Book a demo and bring a real slice of your review queue. We will work it, show you the files, and you will see exactly what your team still has to approve.