Interrogate the counterparty before the contract is executed — the ownership, the screening hits, the commission basis and the rationale — and hold the dated file for the approver who onboards.
A partner is proposed, and the ECCP of September 2024 wants the business rationale written down.
02
A percentage is agreed, and the ECCP asks whether it is commensurate with the services rendered.
Reason
03
A red flag surfaces, and the Resource Guide of July 2020 makes deliberate ignorance knowledge.
04
A commission is booked as something else, and 15 U.S.C. § 78m(b)(2)(A) bites with no bribe proved.
05
An intermediary acts on your behalf, and Bribery Act s.7 leaves only an adequate procedures defence.
Decide
06
A diligence step is designed, and Principle 4 of the March 2011 guidance governs third parties.
07
A large organisation is in scope, and failure to prevent fraud is in force from 1 September 2025.
Out
08
A contract nears execution, and after signature no honest record of the diligence can be made.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
Assembly and re-screening belong to the agent. The statute is unchanged and only enforcement policy moved; a named approver, never the agent, onboards the counterparty.
Example workflow
One counterparty, sources to onboarding
AgentHuman
1Counterparty proposedSponsor request, questionnaire, registry extract or an introduction made by the customer
2Diligence context assembledThe counterparty, the people who own and control it, the territory and scope proposed, and the day the deal team wants it live
3Rationale evidence draftedThe counterparty, the sources under it, the flags and completeness
4Controls appliedScreening checks, ownership-resolution checks, benchmark checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nobody is cleared at any of them — the agent builds the file, and the compliance read begins at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Reaches the compliance approver, who onboards.
Anything thin
Adds an ethics and compliance read first.
Compliance review
The file is held with its flags, its gaps and where each source came from.
Onboard · Append evidence · Send to compliance review
Onboarded — by the named compliance approver▼
6Partner and diligence records updatedOnly where write access and records policy allow it
7Outcome evaluatedSource completeness, flag disposition, compliance corrections and what review found
Corrections
Each compliance correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Clearing a counterparty for onboarding.
Deciding that a person is a foreign official.
Calling a red flag resolved or immaterial.
Judging a commission commensurate with services.
Automation boundaryAgent acts unaided
✓Build each counterparty file from the registry.
✓Record the business rationale and the compensation basis, dated.
✓Screen the counterparty, then re-screen on cadence.
✓Escalate a red flag to a named human rather than scoring it away.
No counterparty is cleared and none is onboarded except by a named person, on approval.
Declaring procedures adequate or reasonable.
Treating a payment as a permissible courtesy.
Setting whether the UK size thresholds are met.
Changes to the partner record or the flag register.
Example output
One counterparty flag, annotated
Our forced-labour import evidence agent assembles UFLPA evidence at the United States border; this is bribery and corruption risk inside a commercial relationship, before it is signed.
Diligence file · single counterpartyIllustrative example
Flag
Recorded as
Counterparty
Evidence of record
Confidence
Held for
Introduction at customer request
Raised at diligence, open and unresolved
Referral commission
Sponsor memo, 3 August 2026
Held open
The compliance approver, by name
As receivedDrawn from the registry extract and the sponsor memo, and it reaches exactly as far as they do.
What the record holdsRegistry extractSponsor rationale memoScreening hits reviewed
Why no flag is closed hereWhether this flag may be closed is a judgement for a named human.
ActionOnboardAppend evidenceSend to compliance review
What the score decidesBelow the threshold the file picks up a compliance read before the approver sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every counterpartyFrom the sponsor who wants it
03Evidence
Where the evidence is used
Nothing on this page is signed or certified under either regime: both ask instead for a dated record of what was found, what was concluded and why the relationship went ahead.
01Approved path
The record is the defence
Neither regime takes a filing: s.7 and the fraud offence are defences proved in court, on the record made while the relationship ran.
02Human review
What was checked, and not found
Enforcement since the pause is sparse, and that is the finding: DOJ charged Scoular on 17 July 2026 over customs brokers although the company did not know. No instrument extending or revoking EO 14209 was found, no corporate resolution of that year could be named, and no pause-era dismissal was verified.
04Build an evidence trail
The counterparty, the rationale recorded for it and the person who approved stay on file.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Counterparty and registry dataCompany registries · ownership sources Legal identity and control chains
Screening and watchlistsSanctions · PEP · adverse media Screening hits and versions
Deal team and sponsorsCRM · sponsor questionnaires Business rationale and proposed scope
Agent
Partner diligence evidence
Reads the counterparty Builds the record Holds for the approver
Contracts and paymentsContract repository · ERP Commission terms, payees and audit rights
Integration availability depends on the client's existing systems and API access.
Agent controls
Six ratchets between the model and the approver
Six ratchets turned one way only, the last the tightest. What holds at the end is drawn in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and diligence rules; EO 14209 paused enforcement on 10 February 2025, and the DOJ guidelines of 9 June 2025 set the terms since.Track
L4TraceabilityRecord each fact, its source, the date it was retrieved, the human who read it and every read of the file.Record
L3Approver releaseRelease the file only to the named approver who onboards; the ECCP also asks whether audit rights exist and were used.Gate
L2Screening guardrailsTest the file against the Resource Guide red flags of July 2020, where conscious disregard, wilful blindness and deliberate ignorance all count as knowledge.Restrict
L1Confidence thresholdsRoute a thin file to a compliance read first; the March 2011 guidance is not prescriptive and is not a safe harbour.Require review
Model coreEvidence assembled — the counterparty, its sources, the flags and completeness
L1 – L2Test whether a file may stand
L3Hands the onboarding to a person by name
L4 – L5Keep the counterparty and the rationale behind it
L6Holds the onboarding open when signals degrade
How Nestack evaluates it
Evaluate the whole assembly — not only the diligence file that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the file an investigator reads
Depth of coverage ▼
E1Final-output evaluationDid the file record what the sources actually show?
E2Step-level evaluationDid the agent read the right registry, the right list version and the live ownership chain?
E3Tool evaluationDid it read and write the correct counterparty record and the correct flag?
E4Confidence calibrationDo low-confidence files actually attract more compliance corrections?
E5Slice evaluationHow does performance change across specific counterparty classes?
E6Business outcomeHow many files needed a correction before the approver onboarded?
Floor — the record the company answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each placed at the stage where it first bites.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
LU-03
Stale ownership read
The ownership chain is not the one now on the register.
Stage gathersThe parties, the owners, the hits and the dates
02 · Reasoning2 modes
LU-04
Rationale asserted, not shown
A rationale is recorded with no source under it.
LU-06
Pause read as repeal
Lighter enforcement is worked as a safe harbour.
Stage proposesThe flags, their sources and completeness
03 · Tool / write2 modes
LU-02
Thin file passed forward
A file moves on without the compliance read.
LU-05
Flag bound to wrong party
A hit is filed against the wrong counterparty.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
LU-01
Onboarded, evidence unrecorded
The file shows an approval but not what was found.
Stage returnsThe file a court or a regulator reads later
05 · Change / Version1 mode
LU-07
Silent screening drift
A list version moves while the file keeps the old clearance.
Stage tracksModel, prompt, screening rules and file fields
Sev-1 · a partner onboarded on no evidenceSev-2 · a red flag closed without reasonsSev-3 · source degrades, file held open
A class-level rationale-coverage figure can read clean while customer-introduced intermediaries carry most of the rework. Nestack reports the correction rate by counterparty class, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Customer-introduced intermediaries
10.6%
3.7×
Review
Sales agents and consultants
7.6%
2.6×
Review
Customs and logistics brokers
4.7%
1.6×
Watch
Resellers and distributors
2.2%
0.8×
Normal
Bar: correction-rate lift vs. reseller and distributor baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What an unexplained intermediary costs
The loop shuts when the unexplained intermediary is a regression case. That suite is what the next counterparty cleared is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on customer-introduced intermediaries.
02Diagnose
The consultant introduced by the customer, paid a percentage of the contract with no explicable role, is read back until one cause remains.
03Improve
Any change goes out numbered, with the counterparties that caused it attached.
04Verify
One counterparty case still failing is enough to hold the release back.
05Learn
One case joins the suite, one line joins the diligence record.
Learn → DetectThe return edge. The next counterparty is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, diligence assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Red-flag-escalation and approval-boundary work.
02Registry, screening and sponsor sources.
03Rationale-to-source and flag-disposition mapping.
04Counterparty evidence ingestion.
05Counterparty, source and flag binding.
06Completeness scoring and review routing.
07Compliance approver workflow.
08Screening and CRM integration.
09Red-flag and rationale cases.
10Guardrails and approval controls.
11Counterparty-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne class, one territoryProductionProduction diligence workflowAdvancedMultiple classes / territories
Introduced at Pilot
File assembly to your risk tiers✓✓✓
Compliance approver release✓✓✓
Intermediary-population baseline✓✓✓
Introduced at Production
Reporting by counterparty class—✓✓
Approver sign-off workflow in your systems—✓✓
Approved write-back—✓✓
Screening-source integration—✓✓
Introduced at Advanced
Multi-party ownership chains——✓
Cross-border evidence packs——✓
Large partner estates——✓
Multi-jurisdiction diligence controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, counterparty volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your live counterparties and the sponsors behind them→Counterparty mapping and source captureWeek 1
02Representative registry, screening and contract records→Source binding, flag logic and the diligence baselineWeek 2
03Your standing onboarding procedure and the approvers it names→Risk-tier mapping, flag binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Registry, screening and contract source assessment, then integration setupWeek 2
05Counterparties you would not want examined→Red-flag cases and failure-mode testingWeek 4
06What no diligence file may guarantee→Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named approver who onboards the counterparty→Handover to the compliance approver, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
This is a schedule and not decoration, which is why two of the phases genuinely overlap in week five.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Diligence workflow discovery, risk-tier mapping and the automation boundaryW2Source integration and the counterparty evidence baselineW3File assembly, flag logic and release controlsW4Evaluation suite, red-flag cases and failure-mode testingW5Screening integration, pilot counterparties and targeted correctionsW6One partner year run under the compliance approver, then Agent Care handover
Reading the bandEach bar takes the weeks its own work is named for, and week five carries a pair because the work does.
At the end of W6Once the diligence record validates, Agent Care assumes the agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Strategy AI agent
Build a partner diligence agent that finishes before the contract is executed.
Nothing here is signed and nothing is filed. Show us your last onboarding and the record it left: the rationale in the words of the sponsor, the screening hits reviewed, the commission basis, and the name of the person who proceeded anyway.