AML Programme-Governance & Independent-Testing AI Agent
Assemble the programme evidence a board approves and a named independent tester opines on, reconcile the risk assessment to the controls, and track each order deliverable against the day count it carries.
A pillar is tested, and the agent opens one evidence set from the policy, training, monitoring and filing systems.
02
A legal-entity file is opened, and CDD at 31 CFR 1010.230 still applies — only foreign companies now file BOI.
Reason
03
A minute entry is drafted — the OCC asks for approval reflected in the minutes, the Fed and FDIC for it noted.
04
A risk is retired, and the agent shows which controls still map to it and which risks are now left uncovered.
05
A risk profile shifts, and the scope reopens — no rule sets a testing frequency, and change is the trigger.
Decide
06
A finding is raised, and it is logged against the element it hit, its owner and the evidence closure will need.
07
A training population is defined, and contractors, mid-period joiners and acquired lines are named in or out.
Out
08
An order article falls due, and the agent tracks the day count and whether no supervisory objection was sought.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The board approves and a named tester opines; if a signed opinion rested on a pack the agent mis-assembled, the next examination re-tests that period.
Example workflow
One element, evidence to opinion
AgentHuman
1Testing cycle openedBoard calendar, examination findings, order articles or a change in the risk profile
2Evidence assembledProgramme version, risk assessment, control mapping, training records and issue log, each with its source
3Pack draftedElement coverage, evidence gaps, open findings and confidence
4Controls appliedSource-currency checks, control-to-risk reconciliation, scope-coverage rules and confidence threshold
No human action required
Stages 1 to 4 run unaided, and nothing is approved or opined at any of them — the agent is assembling, and the officer's lane opens at the confidence gate.
5DecisionBranches at the confidence threshold
High confidence
Goes to the BSA officer to review.
Low confidence
Adds a second compliance read first.
Officer review
The pack is held with its evidence, its gaps and the confidence.
Accept · Amend · Send to second review
Accepted — goes to the board and the tester▼
6Programme record updatedOnly where write access and approval policy allow it
7Outcome evaluatedGaps the tester found, officer amendments, issues reopened and examination findings
Amendments
Every officer amendment is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Approving the programme — the board's own act.
Signing the scoped, dated testing opinion.
Accepting residual risk on any element.
Closing an MRA or a consent-order article.
Automation boundaryAgent acts unaided
✓Assemble the programme record and stamp what was current when.
✓Reconcile the risk assessment to the controls mapped to it for the named owner.
✓Test the evidence set against the configured element rules.
✓Flag what the pack is missing, and hold it for the officer.
Any write happens inside the boundaries agreed at implementation, never ahead of the board.
Judging whether a tester is independent.
Setting the scope of the independent test.
Certifying an order deliverable to the OCC.
Changes to element, evidence or escalation rules.
Example output
One programme element, annotated
The examinable artefact is the minute naming the version approved — this is that layer.
Programme evidence · single elementIllustrative example
Element
Evidence assembled
Version
Rule and record
Confidence
Approval record
Internal controls
Control-to-risk mapping reconciled to the current assessment
v4.2, 12 Mar 2026
12 CFR 21.21(c)(1) · OCC
91%
Minute entry, board of directors
As receivedTaken from the programme record and the board minute — nothing on this side is written by the agent.
A programme-wide evidence figure is carried by the pillars that hold the most documents, while the thin ones set the examination. Nestack reports the evidence-gap rate by pillar, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Board minute record
7.6%
3.6×
Review
Issue and MRA closure
5.5%
2.6×
Review
Risk-assessment currency
3.7%
1.8×
Watch
Internal-controls testing
1.6%
0.8×
Normal
Bar: evidence-gap-rate lift vs. internal-controls baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
Each cycle closes with a new evidence case
A cycle is done when the undocumented approval has become a case the next release must close. That suite is what the next test scoped is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Evidence gaps rise in one programme element.
02Diagnose
The programme approval nobody could find in a board minute is traced back to one cause — a version number the corporate secretary was never given.
03Improve
The fix gets a number, and the findings that raised it are held against it.
04Verify
No release while a touched evidence case is outstanding; it reruns until green.
05Learn
The case stays for good, and the elements it spans are recorded against it.
Learn → DetectThe return edge. The next detection runs against a suite one evidence case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Programme workflow discovery and boundary setting.
02GRC, audit and training-source assessment.
03Element, evidence and escalation-rule mapping.
04Programme-record ingestion and mapping.
05Control-to-risk reconciliation logic.
06Confidence scoring and escalation routing.
07Officer review workflow.
08GRC and audit-platform integration.
09Evidence and remediation cases.
10Guardrails and opinion controls.
11Programme-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne charter, one programmeProductionProduction GRC systemsAdvancedMultiple charters / entities
Introduced at Pilot
Assembly to your record and elements✓✓✓
Officer review✓✓✓
Evidence-coverage baseline✓✓✓
Introduced at Production
Reporting by pillar—✓✓
Review workflow in your systems—✓✓
Approved write-back—✓✓
GRC-platform integration—✓✓
Introduced at Advanced
Multi-agency element rules——✓
Multi-stage board approvals——✓
High issue volume——✓
Multi-charter programme controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your programme document and element structure→Programme-record ingestion and evidence mappingWeek 1
02Representative past testing cycles→Evidence baseline, source binding and coverage mappingWeek 2
03Your risk assessment and control inventory→Element, evidence and escalation-rule mappingWeek 1
04Access to relevant APIs, feeds or exports→GRC, audit and training-source assessment, then integration setupWeek 2
05Programmes you would not want tested→Finding cases and failure-mode testingWeek 4
06What no opinion may cover→Confidence scoring, escalation routing, guardrails and approval controlsWeek 3
07Named officers, and a tester reporting to the board→Officer review workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The weeks are taken from the board calendar, so the fifth band carries evaluation and the pilot.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Programme workflow discovery, element mapping and the automation boundaryW2Source integration and the evidence baselineW3Evidence workflow, reconciliation logic and review controlsW4Evaluation suite, coverage checks and failure-mode testingW5GRC integration, pilot elements and targeted correctionsW6One testing cycle run under the AML officer, then Agent Care handover
Reading the bandA bar covers the weeks its work is named in, and nothing else. The week 5 overlap is real, not padding.
At the end of W6Once the cycle validates, monitoring transfers to Agent Care.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Banking AI agent
Build a programme-governance agent around the minute that proves approval.
Show us your programme and your issue log. Your corporate secretary holds the minute an examiner asks for first, and we build to the rule in force — the 2024 NPRM is withdrawn, no successor final.