Nestack Agent Care
Industries / Banking / KYC & periodic review

Banking AI agent · Financial crime

KYC Onboarding & Periodic-Review AI Agent

Check identity evidence, trace the ownership chain, assemble source-of-funds and rating inputs at onboarding and at refresh — with the rating, acceptance and any suspicion left to the officers who own them.

4–6 weeksTypical delivery
Your stackDeployment
Officer onlyRisk rating
Agent CareAfter launch

What this agent does

Assembles the file, rates no one

In
01

Take new-customer cases, trigger events and the reviews the cycle has fallen due on.

02

Collect identity documents, ownership filings and source-of-funds evidence on the agreed channels.

Reason
03

Check each identity document against its own security features and the data already held.

04

Trace ownership and control layer by layer, and record the layer at which the chain stops.

05

Read registry filings and the customer's own declaration against each other and mark the differences.

Decide
06

Score the file against the client's CDD standard and list the gaps, expiries and open layers.

07

Route thin evidence, register discrepancies and anything the standard flags to the officer who owns it.

Out
08

Present the rating inputs as evidence, each with its source, its date and the gaps still open.

09

Write to the customer file only inside the approval boundaries agreed during implementation.

Product statement

The agent collects, traces and assembles. The customer risk rating, accepting or exiting a customer, deciding that anything is suspicious and any report that follows stay with named bank staff, and what may be said to a customer is limited to the evidence the file needs.

Example workflow

One customer file, end to end

AgentHuman
1Case openedA new customer, a trigger event, or the review the cycle has fallen due on
2Identity evidence checkedDocuments against their own security features, the data against the record already held
3Ownership tracedLayer by layer through filings and registers, until a natural person or a layer that will not resolve
4Wealth and rating inputs assembledSource of funds, source of wealth, expected activity and what has changed since the last review
No human action required

Stages 1 to 4 run without a person in the loop — collection, tracing and assembly finish before anyone is asked to open the file. A layer that will not resolve ends that stretch on the spot.

5DecisionSplits on file completeness and the standard's own flags
File complete to the standard

Reaches the officer's queue ready to be rated.

Gap, discrepancy or broken chain

Goes to the officer who owns that gap first.

KYC officer or MLRO

Reads the evidence, the chain as far as it was traced and the gaps on it, then sets the customer risk rating.

Rate · Correct · Re-request evidence
Rated — handed back
6File updated and queuedWritten only where access and policy allow; the risk-rating field is left empty for the officer
7Outcome evaluatedEvidence completeness, chain depth reached, discrepancies raised, officer corrections and re-work by cohort
Corrections

Evidence the officer re-gathers or re-reads is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Setting or changing a customer risk rating.
Accepting a customer, or exiting one.
Deciding that a customer or a payment is suspicious.
Filing, drafting or disclosing a suspicion report.
Automation boundaryAgent acts unaided
Collect identity, ownership and source-of-funds evidence.
Trace ownership and control through the filings, and record where the chain stops.
Set registry against declaration and raise the gaps, expiries and unresolved layers.
Assemble the rating inputs with their sources and dates.
Writes run only inside the approval boundaries agreed during implementation. The risk-rating field is not one of them.
Any wording that hints a report exists.
Clearing a screening match or a PEP hit.
Signing off a chain that stopped early.
Changing the CDD standard or the review cycle.

Example output

One periodic review, annotated

Everything the agent assembles is attached to the document or the register it came from.

KYC file · one periodic reviewIllustrative example
Customer
Case
Chain traced
Handed to
Confidence
Risk rating
Private company, layered ownership
Periodic review, cycle now due
3 of 4 layers
Officer — chain incomplete
88%
Not set by the agent
As receivedThe case as the review calendar raised it, and the structure as the filings describe it — nothing on this side is inferred.
Evidence used Registry filing, dated Nominee declaration Prior review file
Why it stopped at layer threeThe fourth layer resolves to a nominee holder in a register that publishes no owners.
ActionRateCorrectRe-request evidence
What the score decidesConfidence decides how much the officer re-gathers, not how risky the customer is.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every file opened or refreshedNew customers, trigger events and the review calendar
03Evidence & chain

Work to the bank's own standard

Measure the file against the CDD standard in force for that customer type, the evidence it names and the depth it expects traced.

01Approved path

Hand over a file already worked

Documents checked, the structure traced as far as the filings go and the rating inputs assembled, so the officer opens on the risk question rather than on collection.

02Human review

Say where the chain actually stopped

A layer that resolves to a nominee, a register that disagrees with the declaration, evidence that has gone stale — named as such, rather than passed on as a finished file.

04Build an evidence trail

Retain each document, the registers read with their dates, the chain as traced, the gaps, the officer's rating and what changed since the last review — on both paths.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Core & onboardingFIS · Fiserv · Jack Henry
Temenos · origination and CRM records
Identity verificationDocument capture · liveness checks
Data sources · authoritative registers
Registries & ownershipCompany registries · ownership filings
Corporate structure data

Agent

KYC onboarding & periodic review

Checks evidence
Traces ownership
Routes gaps

Screening & case systemsSanctions and PEP lists · adverse media
Alert and case management
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers before a file reaches an officer

Each control wraps the one inside it. A file clears every layer before it is queued, and the risk rating sits outside all six.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeReturn files to manual assembly if evaluations or production signals degrade.Roll back
L5TraceabilityRecord documents, registers read, chain depth, gaps, rating inputs and corrections.Record
L4Officer gateKeep rating, acceptance, exit and any suspicion decision with the named people who hold them.Gate
L3Confidentiality scopeOutreach wording is taken from approved templates and checked for scope.Restrict
L2Chain-depth ruleEach layer is recorded with its filing, and a chain short of a person stays open.Mark
L1Evidence checksCheck each document against its own features, the record held and the client's age limit.Verify
Model coreKYC file assembled — evidence checked, chain traced as far as the filings go, rating inputs and completeness confidence
L1 – L2Decide what the file may claim
L3Decides what may leave the file
L4 – L5Keep the rating with a person and the trail intact
L6Pulls automation back when signals degrade

How Nestack evaluates it

Evaluate the file an officer rates from — not only whether it looked complete.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the assembled file and the gaps on it
Depth of coverage ▼
E1Final-output evaluationWas the evidence complete and faithful to the documents supplied?
E2Step-level evaluationDid it trace every layer the filings allowed, and stop honestly where they did not?
E3Tool evaluationDid it read the right registers, records and prior review file?
E4Discrepancy recallWere register, declaration and document disagreements raised rather than reconciled away?
E5Slice evaluationHow does file quality change across specific customer cohorts?
E6Business outcomeHow much did the officer re-gather, and how many reviews closed on out-of-date evidence?
Floor — the rating an officer has to defend to an examiner

Failure modes

Where each failure originates in the agent

Seven failure modes plotted against the five stages of the agent lifecycle.

Agent lifecycleDirection of processing →
01 · Collection2 modes
KO-01

Document check fails by cohort

Rejection rises for some nationalities and document types.

KO-02

Replayed or generated capture

A synthetic image passes the capture step as a live one.

Stage gathersDocuments, filings, registers and the prior review file
02 · Tracing2 modes
KO-03

Chain stopped one layer early

A nominee or an agent is recorded as if it were the owner.

KO-04

Registers reconciled away

Two filings disagree and the convenient one is kept.

Stage tracesOwnership and control, layer by layer, to a person
03 · Assembly1 mode
KO-05

Stale evidence closes a review

The cycle is marked complete on documents past their limit.

Stage assemblesEvidence, rating inputs, gaps and what has changed
04 · Handover / write1 mode
KO-06

Outreach says too much

A request for evidence hints at why it was asked for.

Stage presentsThe file the officer opens and the queue it enters
05 · Change / Version1 mode
KO-07

Silent standard drift

A change to the standard moves what counts as complete.

Stage tracksModel, prompt, standard and threshold changes
Sev-1 · a boundary is crossed without a person Sev-2 · the file is wrong where it counts Sev-3 · collection degrades, more is asked

Affected slices

The structures that will not resolve to a person

A single-owner retail refresh is close to a records exercise — one person, one document, one register. What comes back unfinished crosses three jurisdictions, or is a name spelled two ways. Nestack reports by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Layered cross-border structures5.5%3.8× Review
Nominee and trust arrangements3.7%2.6× Review
Non-Latin-script name records2.8%1.9× Watch
Retail refresh, single owner1.1%0.8× Normal
Bar: unfinished-file lift vs. retail-refresh baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

An overdue review and a false complete are not the same miss

One of them is visible on a report the day it happens. The other reads as finished until somebody re-opens the evidence it closed on.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Re-gathered evidence, broken chains or discrepancy volumes move in one customer cohort.

02Diagnose

Narrowed to one step in the file — the document check, the layer that stopped, the register used or the age limit.

03Improve

The evidence standard, the chain rule or the staleness window is re-approved by the MLRO and version-linked.

04Verify

Re-assembled over files already rated, including the reviews that closed on out-of-date evidence.

05Learn

The structure that defeated the trace is kept as a case, and the cohort it came from is re-tested before release.

Learn → DetectThe return edge. Tightening what the agent asks for decides which customers a bank finds hard to keep, so each change is tested for pressure on whole categories before it ships.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, evidence and tracing, assembly, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01CDD standard and approval-boundary definition.
02Core, onboarding and registry API assessment.
03Customer-type and jurisdiction scoping.
04Identity capture and document checks.
05Ownership tracing and chain-depth rules.
06Source-of-funds and wealth evidence assembly.
07Rating-input assembly and gap scoring.
08Review cycle, triggers and change detection.
09Evaluation suite and cohort regression cases.
10Confidentiality scope and outreach wording.
11Customer-file write-back and case handoff.
12Observability, deployment and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne customer type ProductionCore and registry integration AdvancedCross-border / multi-entity
Introduced at Pilot
Identity evidence checks
Ownership tracing with chain depth recorded
Source-of-funds and wealth evidence
Review cycle and trigger events
Rating, acceptance and exit left to officers
Audit trail and baseline evaluation
Introduced at Production
Additional customer types and jurisdictions
Adverse-media and screening-source breadth
File write-back, observability and evaluation
Introduced at Advanced
Multi-jurisdiction registers and scripts
Enterprise controls across the book
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on customer types, registry and screening integrations, file volume, review-cycle scope, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your CDD standard and the evidence each customer type needs CDD standard and approval-boundary definitionWeek 1
02Access to core, onboarding, registry and screening systems Core, onboarding and registry API assessmentWeek 2
03The identity documents your customers actually present Identity evidence capture and document checksWeek 2
04How deep your policy expects an ownership chain to be traced Ownership tracing and chain-depth rulesWeek 3
05Your review cycle, trigger events and evidence age limits Review cycle, triggers and change detectionWeek 4
06Files that were re-worked, and reviews that closed too early Evaluation suite, cohort regression cases and failure-mode testingWeek 4
07Named officers, and what a request to a customer may say Confidentiality scope and outreach wording, then pilot filesWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Phases are drawn over the weeks they actually occupy. Week 5 carries both the cohort testing and the first supervised files.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1CDD standard, chain-depth policy and the automation boundary W2Identity capture and document checks on the first customer type W3Ownership tracing, source-of-funds assembly and gap scoring W4Evaluation suite, cohort testing and review-cycle rules W5Registry integration, supervised files and targeted corrections W6Officers rate from live files, then Agent Care starts
Reading the bandDocument-check performance is measured by nationality and document type in week 4, before the first supervised file runs in week 5.
At the end of W6Files have been assembled alongside your existing process and read by the officers who rate from them, then Agent Care takes over monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Banking AI agent

Build a KYC agent around the standard your officers already apply.

Show us your CDD standard, how deep your policy expects an ownership chain to go, and who sets a customer's risk rating today. We'll rebuild a set of files you have already rated, then tell you where each ownership chain actually stopped and how much of the evidence had expired before the review was signed.

Nestack Agents · KYC onboarding & periodic reviewAGT-BK-08 · Agent Care available after launch