Alert triage
Screening alerts discounted per agent, per day
600
In short: Compliance as a service means a provider performs your compliance operations work rather than selling you a tool to do it with. Zyphe delivers it as operated review desks: you agree a queue and a service level, agents work every case against your own policy and produce a decision-ready file with the reasoning attached, and your team approves. Under Article 18 of the EU anti-money laundering regulation, six categories of decision are reserved to the obliged entity, including the customer risk profile, the decision to enter a business relationship, and reporting to the FIU. Those stay with your MLRO by design, not by exception.
Last reviewed 2026-08-20.
Each desk is one queue, operated end to end. Start with the one that is costing you the most analyst hours, and add the next when the first is clearing.
Works the screening queue your engine produces: compares each hit against your matching policy, writes the disposition and its reasoning, and escalates the ones that are genuinely unclear.
See the deskReads the underlying coverage rather than the headline, resolves whether the story is actually about your customer, classifies it against your risk taxonomy, and summarises with citations.
See the deskWalks the ownership chain through corporate registries to the natural persons behind it, screens them, and assembles the enhanced due diligence file including what could not be resolved.
See the deskReconstructs the account history behind each rule-triggered alert, tests it against that customer's own baseline and your typologies, and drafts either a reasoned close or a narrative your investigator can amend and file.
See the deskRe-runs the checks on customers falling due, compares what it finds against the file you already hold, and reports what actually changed rather than rebuilding a dossier nobody reads.
See the deskFive desks, not a roster of a dozen. Everything listed here is work Zyphe operates today, because a published desk is a commitment, not a roadmap entry. If your queue is a different shape, tell us what it looks like.
The same four steps whichever queue you start with.
You pick one queue and the slice of it a desk takes: a segment, a market, an alert type, or a volume band. Not the whole function, and not a platform migration.
Your matching thresholds, your risk taxonomy, your lookback periods. The desk applies the policy you approved. It does not bring its own and call it a best practice.
The queue is worked continuously rather than accumulating until someone has capacity. Every case leaves with its evidence and its written rationale.
Reviewers see a prepared file and either approve it or send it back. The decisions the law reserves for the obliged entity never leave your side of the line.
Worth knowing before any vendor conversation, including this one.
AMLR Article 18(3)
Everything else: the gathering, the comparing, the reading, the chain-walking, the drafting. That is the overwhelming majority of the hours a compliance operations team spends, and it is what a desk takes. Article 18(1) of Regulation (EU) 2024/1624 permits it explicitly, provided you notify your supervisor before the provider starts.
Two conditions come with it. Article 18(2) treats the provider as part of your firm and leaves you fully liable, and it requires you to be able to demonstrate to your supervisor that you understand the rationale behind what the provider does. Article 18(4) requires a written agreement and regular controls that the provider is applying your policies.
Both of those are design constraints, not paperwork. They are why every case leaves a Zyphe desk with a written rationale rather than a confidence score, and why your policy is the one being applied.
Two qualifications belong with that list. Article 18(3)(e) permits FIU reporting to be outsourced to another obliged entity in the same group and established in the same Member State. Article 18(7) lets a collective investment undertaking without legal personality outsource points (c), (d) and (e) to one of its service providers, once it has notified its supervisor and the supervisor has approved. Neither reaches a typical bank, payment institution, electronic money institution or crypto-asset service provider.
Approving an individual alert disposition is not itself an Article 18(3) requirement. The Regulation governs the decisions listed above; how much of the rest your team reviews is set by your own policy. Zyphe returns every case for approval because that is the service boundary we sell, not because a regulation compels it case by case.
Regulation (EU) 2024/1624 applies from 10 July 2027. National outsourcing rules apply until then.
We publish what we can verify. Figures below are from Zyphe deployments; detailed references are available under NDA.
Alert triage
Screening alerts discounted per agent, per day
600
Reviews at scale
Customer reviews handled with Zyphe agents
120,000+
Customer outcomes
Operational cost saved across deployments to date
$3.3M
Market coverage
Markets where Zyphe runs verification and screening
52
Design partner program
Paid pilots clearing a fixed slice of your review queue under SLA
Open
The three ways teams cover a growing review queue, and what each one actually costs once you count the loaded hours.
Hiring adds capacity you have to recruit, train and retain, and it takes months before the first alert is worked. A BPO is faster to stand up, but you are still buying hours, and consistency follows the shift roster. Run your own numbers on the comparison page before you talk to anyone.
Compare the threeCompliance as a service is a model where a provider performs compliance operations work on your behalf, rather than licensing you software to perform it yourself. It typically covers high-volume, well-defined work such as screening alert review, adverse media review, periodic KYC refresh and enhanced due diligence file preparation. The regulated firm keeps the obligations, the policy and the decisions. The provider takes the throughput.
A BPO scales by adding people, so cost tracks volume and quality tracks whoever is on shift that week. A desk scales by adding agent capacity against a policy that is applied identically every time, and every case carries the reasoning that produced it. The commercial difference is that you stop paying for hours. The audit difference is that consistency stops depending on staffing.
Software returns a decision or an alert and leaves the queue with your analysts. That is the part most teams are actually short-staffed on. A desk takes the queue. If you would rather run the work in-house, the same capabilities are available as product surfaces, and plenty of teams should choose that instead.
Not the ones that matter. AMLR Article 18(3) puts six categories of decision permanently with the obliged entity, and GDPR Article 22 constrains decisions based solely on automated processing that produce legal or similarly significant effects on a person. This is why Zyphe agents prepare cases and humans approve them. It is also why the reasoning is written out: AMLR Article 18(2) requires you to be able to demonstrate to your supervisor that you understand the rationale behind what your provider does.
Yes. AMLR Article 18(1) requires the obliged entity to notify its supervisor of the outsourcing before the service provider starts carrying out the outsourced task, and Article 18(4) requires a written agreement and regular controls to check the provider is actually applying your policies. The Regulation applies from 10 July 2027; your national outsourcing rules apply in the meantime, so check what your supervisor requires today.
That is the normal way in. A paid pilot takes a fixed slice of one queue under a service level, runs alongside your existing process rather than replacing it, and gives you real files to inspect. Teams that add a second desk do it once the first one is clearing.
Book a demo
Book a demo and bring a real slice of your review queue. We will work it, show you the files, and you will see exactly what your team still has to approve.