Agent-control plane for global-bank sanctions investigations, letting AI caseworkers gather evidence under local policy and audit trace.
Global banks want AI to help clear sanctions and AML investigation queues, but the real blocker is not model availability. Each region has different escalation rules, data-access limits, and narrative standards, so an agent that can freely search, summarize, or recommend across systems becomes a governance problem before it becomes a productivity gain.
Why now
- Financial-crime buyers are moving from chatbot experiments to software that can let AI execute real investigation steps.
- Any bank deploying agentic workflows now must prove governance, explainability, and human review before compliance will let automation touch live cases.
- Cross-border banks cannot ship one universal agent because regional policy and data rules differ, turning localization into immediate software work rather than a later feature request.
- The size of Quantifind's growth round suggests control software around risk operations is no longer a niche budget but a venture-scale category.
Catalyst. Quantifind's $200 million investment around Graphyte Agentic Middleware, regulatory alignment, and localized risk intelligence signals that banks now want AI to execute fincrime work, but only through a governed layer that can survive region-by-region oversight.
The idea
The product sits above existing case management and screening systems rather than replacing them. It ingests case metadata, customer records, prior alert outcomes, and local policy rules, then spins up least- privilege agents for narrowly defined tasks such as gathering adverse media, mapping beneficial ownership, or reconciling payment-chain inconsistencies. A supervisor layer checks every agent action against jurisdictional policy packs, requires human approval for sensitive steps, and generates cited investigation memos in the format each regional team already uses. The bank gets faster case assembly without handing a general-purpose agent unchecked access to regulated workflows. Over time, the company compounds an action- outcome dataset showing which agent playbooks clear alerts fastest without breaching policy.
What's different. Incumbent AML platforms store cases and risk data, while consulting firms write policy documents and shared services execute manual research. This company owns the control runtime between them: which agent may do what, with which data, under which regional policy, and with which human checkpoint. Its defensibility comes from jurisdiction pack libraries, connector coverage, and a growing corpus of action-level investigation traces that show how governed agent workflows actually perform in production.
| Beachhead | Tier-1 and Tier-2 transaction banks processing correspondent-banking and trade-finance alerts across London, Dubai, and Singapore, where regional investigations teams follow different sanctions, AML, and data-sharing rules but share a global case queue. |
|---|---|
| Wedge | An investigation control plane that launches bounded AI caseworkers to gather payment-chain, ownership, adverse-media, and prior-case evidence through approved connectors, applies jurisdiction-specific policy packs, and routes only exception-scored drafts to human investigators with a full audit log. |
| Non-obvious insight | Banks already own case systems, screening tools, and risk data. What changed is that AI can now perform real investigative steps, so the missing layer is a runtime that constrains agent behavior by jurisdiction, preserves human checkpoints, and turns every action into defensible evidence. The winner is not the smartest fincrime model; it is the control plane that makes agentic work admissible inside regulated operations. |
| Venture-scale path | Start with cross-border sanctions and AML investigations, then expand into correspondent due diligence, trade-finance screening, KYC refresh, SAR-support drafting, managed-service oversight, and eventually a full agent-governance layer for regulated risk operations. |
| Primary user | Global sanctions investigations and financial-crime transformation leaders at transaction banks running cross-border alert operations. |
|---|---|
| Secondary user | Regional AML policy owners and fincrime QA managers responsible for investigation standards. |
| Economic buyer | Global Head of Financial Crime, Chief Compliance Officer, or COO of transaction banking. |
| First customer | The sanctions investigations team at a global bank with USD clearing and trade-finance operations in London, Dubai, and Singapore, already running NICE Actimize or Quantexa plus shared-service investigators. |
|---|---|
| Buying trigger | A bank approves an AI pilot for fincrime investigations or opens a new regional booking center, forcing compliance to define how agents can access data and where human approval must remain. |
| Current alternative | Incumbent case-management suites, offshore investigation teams, internal playbooks, and manual evidence gathering across vendor portals and shared drives. |
| Switching reason | The control plane lets the bank keep its existing stack while adding governed agent execution, regional policy consistency, and action-level audit trace that generic copilots and services teams do not provide. |
| Pricing hypothesis | Annual enterprise subscription priced by governed workflow, active jurisdiction pack, and investigation volume, likely starting around $250k-$1M ARR plus implementation. |
Jobs to be done
| Job | Current alternative | Success metric |
|---|---|---|
| When a cross-border sanctions or AML alert lands in our queue, help our investigators gather the right evidence under local policy fast, so they can clear or escalate the case without breaching internal controls. | Manual research across case tools, vendor portals, shared drives, and offshore analyst handoffs. | Median time to case disposition and percentage of cases with complete cited evidence on first review. |
| When we pilot AI in financial-crime operations, help our compliance leadership define what the agent may do and how humans stay in the loop, so we can deploy automation without failing governance review. | Static playbooks, policy PDFs, one-off pilot guardrails, and generic copilots with manual supervision. | Time from pilot approval to production launch and percentage of agent actions captured with valid reviewer checkpoints. |
flowchart LR Buyer[Global bank sanctions lead] --> Pain[AI pilots stall on policy variance] Pain --> Product[Sanctions agent control plane] Product --> Outcome[Faster investigations with audit-ready oversight]
- Signal · 4/5The source names a concrete workflow and product architecture, but evidence depth is limited to one fetched report.
- Pain · 5/5Cross-border fincrime investigations are expensive, exam-sensitive, and operationally slow when evidence gathering and approvals fragment across regions.
- Wedge · 5/5Governing agent behavior inside one investigation queue is a narrow, repeated workflow with clear users, inputs, approvals, and success metrics.
- Defense · 4/5Jurisdiction packs, connector coverage, and action-outcome traces can compound into sticky advantage, though large incumbents could copy basic control features.
- Scale · 5/5A sanctions investigation beachhead can expand across multiple bank workflows and adjacent regulated industries that need governed agent execution.
- AML case-management and screening vendors
- Regional compliance advisory firms
- Data providers for adverse media, ownership, and payments intelligence
- Maintaining policy packs and approval workflows
- Building connectors and least-privilege agent controls
- Improving playbooks from investigation outcomes
- Jurisdiction policy-pack library
- Case-action audit graph and workflow templates
- Integrations into case, screening, and data providers
- Let banks add AI caseworkers without losing human oversight or explainability
- Encode jurisdiction-specific policy into repeatable investigation workflows
- Shorten alert-resolution time while preserving audit-ready evidence
- Design-partner rollout on one cross-border investigations queue
- Quarterly policy-pack updates tied to regulatory and corridor changes
- Expansion through new jurisdictions and adjacent workflows
- Direct enterprise sales to financial-crime transformation leaders
- Regional compliance and sanctions conferences
- Partnerships with regtech integrators and fincrime advisory firms
- Global transaction banks
- Correspondent banking and trade-finance risk teams
- Fincrime managed-service providers serving large banks
- Product and integrations engineering
- Compliance domain specialists and policy operations
- Enterprise sales and implementation
- Annual SaaS subscription
- Implementation and connector fees
- Premium policy-pack and managed-governance modules
Market
| TAM | $250.0M Bottom-up estimate: ~250 global Tier-1/Tier-2 cross-border banks and comparable institutions x modeled $1.0M annual spend for a governed investigation-control layer; the spend assumption is only a small fraction of existing financial-crime operations budgets. |
|---|---|
| SAM | $48.0M Beachhead estimate: ~60 banks operating relevant London/Dubai/Singapore or adjacent EMEA/APAC investigation hubs x modeled $800k annual spend for sanctions and AML investigation control across a limited set of jurisdiction packs. |
| SOM | $9.0M Reachable year-3 estimate: 12 banks x modeled $750k average annual contract value, assuming land-and-expand from one live investigations queue into adjacent policy packs and workflows. |
Executive takeaways
- The pain is real, but the wedge is narrower than generic AML AI: banks already buy detection and case systems, yet still lack a governed runtime for semi-autonomous investigation work across jurisdictions.
- Why now is strong because AI adoption has become mainstream in financial services, but regulators and buyers still expect human checkpoints, auditability, and explainable controls before agents touch live cases.
- Competition is intense from AML suites, decision-intelligence platforms, and new agentic vendors, so the startup only wins if it becomes the cross-stack control plane rather than another point solution.
- London, Dubai, and Singapore are attractive because cross-border sanctions and AML processes are complex, but jurisdiction-pack maintenance is a real operating risk and should be validated early.
Market definition
This category is governed agent infrastructure for sanctions and AML investigations: a control layer that sits above screening engines, case systems, and data vendors to let bounded AI caseworkers gather evidence, draft memos, and route exceptions under bank-specific policy.
Customer and buyer
The economic buyer is a global head of financial crime, sanctions, or compliance operations at a large bank. Day-to-day champions are sanctions investigations leaders, AML transformation leads, QA managers, and policy owners who need faster case throughput without losing control of reviewer checkpoints and audit trace.
Buying triggers
- Rising compliance cost and screening-alert growth make investigation productivity an immediate budget problem rather than an experimental AI project. [95][97]
- Banks are already adopting AI, but most automated use cases still keep humans in the loop, which creates demand for a governed agent runtime instead of an unconstrained copilot. [79][80][88][89]
- Cross-border sanctions obligations and targeted-financial-sanctions rules create pressure to encode local policy and escalation logic by jurisdiction. [76][99][101][102]
Willingness to pay
Budget exists inside financial-crime modernization and investigations operations: banks already spend tens or hundreds of millions on compliance work, and incumbent vendors already sell enterprise AML and case-management layers, so a governed control plane can fit an existing spend category if it demonstrably cuts manual review and audit friction. [95][96][69][41]
Category dynamics
Tailwinds
- Financial-crime compliance spend and alert pressure continue to rise, which makes investigation efficiency easier to justify economically.
- AI adoption is already mainstream inside financial services, creating a window for governed agent workflows to move from pilots into production.
- Recent launches and funding show that the market is productizing agentic financial-crime infrastructure, not just talking about it.
Headwinds
- Incumbent vendors already cover broad parts of AML, screening, and case management, so a startup faces a high proof threshold to win the control point.
- Cross-border regulatory heterogeneity raises implementation and maintenance cost from day one.
- Banks still struggle with data silos, legacy tooling, and operational complexity, which can delay time to value even when the product thesis is sound.
Validation signals
- Quantifind’s $200M growth round explicitly around AI-native risk intelligence and agentic middleware validates venture-scale interest in the control layer around fincrime operations.
- NICE Actimize and Quantexa both now market agentic or agent-ready financial-crime offerings, showing buyers are moving past generic copilots toward controlled execution.
- Fenergo reports that tackling financial crime is the top AI investment priority in 2025 and that 47% of surveyed UK/US institutions already use AI in compliance operations.
- Screening vendors now market hard automation claims such as 65-85% routine false-positive remediation or material false-positive reduction, confirming that buyers want measurable workflow improvement.
Regulatory & technical constraints
- Any system used in sanctions workflows must support a risk-based compliance program with management commitment, risk assessment, internal controls, testing/auditing, and training.
- Dubai/UAE deployments must incorporate targeted-financial-sanctions processes, policies, and penalties under the UAE framework rather than rely on generic global configurations.
- Entity resolution, data unification, and context assembly are core technical constraints because legacy AML tools rarely give investigators a complete counterparty view by default.
- UK sanctions compliance requires frequent policy updates and clear operational understanding, which pushes product design toward configurable policy packs rather than hard-coded workflows.
Competition
Most rivals attack adjacent control points rather than the exact one proposed here. NICE Actimize owns broad AML and case management, Quantexa owns connected-data and contextual decisioning, Quantifind and ComplyAdvantage push screening and risk-intelligence automation, and Lucinity pushes AI-native investigator workflow. The opening is a neutral control plane that governs what agents may do across those systems, with jurisdiction-aware policies and evidence-grade traceability.
| Competitor | Stage | Wedge | Pricing | Strength | Weakness vs. us |
|---|---|---|---|---|---|
| Quantifind | scale-up | AI-native investigations, watchlist screening, and sanctions intelligence on the Graphyte platform | Custom enterprise pricing; not publicly disclosed | Most direct evidence of the category: it combines explainable risk intelligence with agentic middleware and strong screening-investigations messaging. | Its center of gravity is risk intelligence and screening performance; the startup still has room to own the cross-stack jurisdiction-governance runtime as a more neutral control layer. |
| NICE Actimize | incumbent | End-to-end AML suite, sanctions screening, enterprise case management, and agentic investigation features | Custom enterprise pricing; not publicly disclosed | Deep installed base, auditable case-management posture, and explicit agentic AI positioning for investigations. | A large-suite posture can leave room for a faster neutral layer that works across mixed stacks and localized policy needs without a broader platform migration. |
| Quantexa | scale-up | Connected-data and decision-intelligence foundation for AML, KYC, and financial-crime investigations | Custom enterprise pricing; not publicly disclosed | Strong entity-resolution and contextual-data story that improves detection and investigation quality across large institutions. | It is stronger on context and detection than on the explicit permissions, reviewer checkpoints, and jurisdiction-pack runtime that govern every agent action. |
| Lucinity | scale-up | AI-native investigator workflow and case actioning for sanctions and fincrime teams | Custom enterprise pricing; not publicly disclosed | Investigator-centric UX and explicit workflow/action tooling make it credible for operational adoption. | The product reads as a strong workbench, but the startup can differentiate with deeper multi-jurisdiction policy governance and broader mixed-stack neutrality. |
| ComplyAdvantage | scale-up | Composable screening, transaction monitoring, and agentic workflows for compliance teams | Custom enterprise pricing; not publicly disclosed | Modern API-first posture and explicit agentic workflow messaging with routine alert auto-resolution. | Its current emphasis is more on screening and monitoring efficiency than on investigator-grade cross-jurisdiction control of end-to-end casework. |
Why incumbents do not win by default
- Cloud platforms. Cloud and standards layers provide guardrails and risk-management primitives, but they do not ship bank-ready sanctions policy packs, reviewer workflows, or mixed-stack case connectors by default.
- AML suites. Incumbent AML suites can embed agentic features and auditable case management, yet buyers still operate heterogeneous stacks and cross-jurisdiction processes that create room for a neutral orchestration layer.
- Decision-intelligence platforms. Connected-data platforms are strong at context, entity resolution, and detection, but that does not automatically make them the permissioning and approval runtime for every downstream investigator action.
- Screening and risk-data vendors. Screening vendors can auto-resolve routine alerts and improve risk intelligence, but the bank still needs a layer that decides when an agent may act, who approves, and how outputs become defensible evidence.
Business plan
Sanctions agent control plane is a governed investigation runtime for global banks that want AI to perform evidence-gathering work inside sanctions and AML investigations without failing compliance review. The beachhead is Tier-1 and Tier-2 transaction banks running cross-border alert queues across London, Dubai, and Singapore, where one global case flow meets different sanctions, AML, and data-sharing rules. The first product is not a new screening engine; it is a control plane that launches bounded AI caseworkers for payment-chain tracing, beneficial-ownership lookup, adverse-media gathering, and prior-case retrieval, then routes exception-scored drafts to human investigators with full action provenance. That wedge matches the clearest buying trigger in the research: a bank approves an AI pilot or opens a new regional booking center and must define what agents may do before touching live cases. Go-to-market should start with one sanctions queue, one incumbent case stack, and three jurisdiction packs because proof on cycle time and auditability matters more than broad workflow coverage. Banks already spend against financial-crime modernization and investigations operations, so the company can fit an existing budget line if it demonstrates measurable throughput gains. The main strategic risk is not model quality; it is whether policy-pack upkeep and enterprise integrations can stay software-like enough to preserve 70% gross margin. Research supports strong pain and timing, but it does not provide named customer references or direct proof that banks will buy a neutral control plane rather than wait for NICE, Quantexa, or services partners, so the first 12 months must validate paid pilots and pilot-to-production conversion.
Problem
- Cross-border sanctions and AML investigations still bounce among case tools, screening systems, data vendors, shared drives, and offshore analyst handoffs, which keeps case assembly slow and QA-heavy.
- AI pilots stall before production because banks cannot prove what an agent may access, draft, or escalate under UK, UAE, and Singapore policy and review rules.
Solution
- Deploy a neutral control plane above existing case-management, screening, and data systems that launches least-privilege agents for bounded evidence-gathering tasks under jurisdiction-specific policy packs.
- Record every agent action, evidence pull, reviewer edit, and final case outcome in an audit graph so banks can defend investigations and improve playbooks over time.
Why we win
- We start at the narrowest point of highest buyer anxiety: one cross-border sanctions queue where AI is useful now but governance blocks production, so the product augments existing stacks instead of asking for a rip-and-replace.
- Jurisdiction packs, cross-vendor connectors, and action-outcome traces create workflow-specific defensibility that generic copilots, advisory firms, and single-platform features do not compound as quickly.
| Beachhead | Correspondent-banking and trade-finance sanctions investigation queues at Tier-1 and Tier-2 transaction banks operating across London, Dubai, and Singapore. |
|---|---|
| Wedge rationale | This queue has a clear buyer, a concrete AI-pilot trigger, repeated evidence-gathering steps, and measurable cycle-time and audit outcomes; broader AML or KYC expansion would add more systems and policy variance before trust is proven. |
| Sequencing | Start read-only and human-approved on one queue, then add more jurisdiction packs and adjacent investigation tasks before moving into deeper automation; sell direct to design partners first, then through integrators once deployment playbooks are repeatable; hire integration and policy depth before scaling quota sales. |
| Not yet | Replacing screening engines or transaction-monitoring systems. · KYC refresh, correspondent due diligence, and trade-finance onboarding outside the first investigation queue. · Fully autonomous case closure, SAR-support drafting, or regulator filing recommendations. |
| Wedge | Sell a paid design-partner pilot for one cross-border sanctions queue that runs bounded evidence-gathering agents in shadow or read-only mode, then convert to production once case-assembly time drops and compliance signs off on auditability. |
|---|---|
| Channels | Founder-led direct sales into global heads of financial crime, sanctions investigation leaders, and transaction-banking COO offices. · Co-sell with AML-suite integrators and regional compliance advisory firms already involved in investigations modernization. · Reference-driven expansion inside existing NICE Actimize or Quantexa programs after the first live queue proves value. |
| Funnel targets | Lead→qualified pilot 15-25%, qualified pilot→paid pilot 30-40%, paid pilot→production 50%+, first queue→second jurisdiction pack or adjacent workflow within 12 months in 40%+ of production accounts. |
| Pricing | Annual subscription priced by governed investigation queue, active jurisdiction packs, and case volume, with a paid pilot converting into roughly $350k-$750k production ACV plus implementation. This matches how banks budget modernization around specific workflows rather than per-seat investigator licenses. |
| MVP | MVP covers one cross-border sanctions investigations queue: connectors into an incumbent case platform and approved data vendors, three jurisdiction packs for the UK, UAE, and Singapore, bounded agent tasks for evidence gathering, reviewer approvals, audit logging, and cited memo export. It explicitly excludes new detection models, transaction monitoring, and autonomous case disposition. |
|---|---|
| 6 months | Ship the first production-ready sanctions queue with NICE Actimize- and Quantexa-adjacent connectors, policy-pack authoring, reviewer dashboards, and case-time benchmarking. |
| 12 months | Add AML investigations, second-stack connector coverage, policy-change workflow, and a partner deployment kit so one bank can roll the runtime into more corridors without custom engineering each time. |
| 24 months | Expand into correspondent due diligence, trade-finance screening, and KYC refresh while reusing the same permissioning, approval, and audit architecture. |
| Key bets | Read-only evidence gathering plus human checkpoints is enough to win paid pilots before the product automates higher-authority steps. · Three initial jurisdiction packs can be maintained with configurable software and limited policy ops rather than bespoke consulting. · Banks will accept a neutral overlay that coexists with NICE Actimize, Quantexa, and internal case tooling. |
| Revenue streams | Annual platform subscription for live governed investigation queues. · Implementation and connector-onboarding fees. · Premium jurisdiction-pack updates, audit-evidence exports, and managed-governance modules. |
|---|---|
| Unit of value | Governed investigation queue with active jurisdiction packs and bounded agent playbooks. |
| Target gross margin | 70% |
| Expansion levers | Add more corridors and jurisdiction packs inside the same bank. · Expand from sanctions investigations into AML investigations, correspondent due diligence, and KYC refresh. · Sell premium reporting, QA, and policy-change workflows to second-line compliance and internal-audit teams. |
| North-star metric | Monthly investigations completed through governed agent playbooks with required human checkpoints satisfied. |
|---|---|
| Input metrics | Time from pilot kickoff to first reviewed case. · Median case-assembly time reduction on the live queue. · Paid pilot to production conversion rate. · First-review acceptance rate of agent-prepared investigation memos. · Expansion from first queue to second jurisdiction pack or workflow. |
| Moats to build | Jurisdiction-pack library for UK, UAE, Singapore, and later corridors. · Cross-vendor audit graph linking agent actions, evidence sources, reviewer edits, and case outcomes. · Reusable connector and playbook library across case systems, screening vendors, and data providers. |
| Kill criteria | Fewer than 2 of the first 6 paid pilots convert to production at $300k+ ACV within 12 months. · Median evidence-gathering time does not improve by at least 30% on the first live queue without new control exceptions. · Each new jurisdiction pack still requires more than one month of custom policy work after the first three hubs. |
Milestones
- Package one incumbent-stack deployment path with UK, UAE, and Singapore policy packs.
- Sign 5-6 design partners and convert at least 2 into paid pilots.
- Put 1 queue into production with full audit trace and 30% or greater case-assembly improvement.
- Close the first regional advisory and implementation partnerships.
- Expand to 4-6 production banks and win second-queue or second-pack expansion in at least 2 logos.
- Add AML investigations, policy-change workflow tooling, and broader connector coverage.
- Bring packaged deployment under 8 weeks on the primary stack and make partner-sourced pipeline a meaningful share of new pilots.
- Reach 10-12 production banks and the modeled $9M reachable SOM trajectory.
- Expand into correspondent due diligence, trade-finance screening, and KYC refresh without becoming a generic compliance suite.
- Build a durable action-outcome dataset and jurisdiction-pack library that raises switching cost inside live bank operations.
flowchart LR Wedge[Cross-border sanctions queue] --> MVP[Bounded evidence-gathering agents] MVP --> Proof[Cycle-time reduction plus audit trace] Proof --> Expansion[More jurisdiction packs and adjacent workflows]
Founding team
| Role | Start timing | Rationale |
|---|---|---|
| Founder CEO | Month 0 | Own founder-led bank sales, design-partner recruitment, and packaging because early deals require executive education and fast iteration. |
| Founding eng | Month 0 | Build the first connector bundle, policy runtime, audit graph, and agent-orchestration controls needed for credible pilots. |
| Founding compliance product | Month 0 | Translate UK, UAE, and Singapore policy differences into productized approval logic and investigator workflows from day one. |
| Solutions architect | Month 4 | Shorten deployment cycles inside legacy bank stacks and protect core engineering from custom onboarding work. |
| Policy ops lead | Month 6 | Maintain jurisdiction packs, coordinate regulatory-advisory partners, and turn live customer changes into repeatable templates. |
| Head of partnerships | Month 9 | Turn integrators and regional advisors into a scalable channel after the first direct pilots prove repeatable deployment. |
Experiment roadmap
| Horizon | Experiment | Hypothesis | Success metric | Owner |
|---|---|---|---|---|
| 0–90 days | Run time-and-motion studies on two target-bank investigation teams using sampled sanctions cases. | Evidence gathering and narrative assembly represent a large enough share of investigator time to justify a control-plane wedge. | At least 30 sampled cases show evidence gathering plus memo drafting consumes 35% or more of handling time. | Founder product |
| 0–90 days | Demo a policy-pack and audit-trace prototype to six sanctions and AML buyers. | Buyers want queue-specific agent permissions and reviewer checkpoints more than a generic AI copilot. | Four or more prospects agree to pilot scoping or paid discovery after the prototype review. | Founder CEO |
| 0–90 days | Build a read-only connector proof of concept for one case stack and two approved data sources using historical cases. | The product can assemble cited draft memos end to end without breaching policy boundaries. | One design partner reviews 20 historical cases through the workflow within 45 days of kickoff. | Founding eng |
| 3–6 months | Convert discovery into two paid pilots on one cross-border sanctions queue. | Direct or partner-led budget exists before the product reaches full production authority. | Two paid pilots signed at $100k or more each with explicit production-go-live criteria. | Founder CEO |
| 6–12 months | Put the first queue into production and benchmark operational impact. | Pilot evidence is strong enough for compliance to approve live use on bounded tasks. | One production queue live with 30% or greater case-assembly improvement and no unresolved audit findings after 90 days. | Solutions lead |
| 6–12 months | Recruit two implementation or regulatory-advisory partners and test channel-sourced pipeline. | Partners can shorten procurement and deployment without turning the company into custom services. | Two signed partners and one partner-sourced paid pilot with deployment under 90 days. | Head of partnerships |
| 12–18 months | Expand one production customer into a second jurisdiction pack or adjacent investigation workflow. | Land-and-expand inside one bank is faster and cheaper than relying only on new-logo acquisition. | One production customer buys a second queue, corridor, or workflow within 6 months of initial go-live. | Policy ops lead |
Risk assessment
- R1Banks approve read-only pilots but refuse to grant production authority on live queues. — Start with bounded evidence-gathering tasks, require explicit human checkpoints, and measure reviewer trust before selling deeper automation.
- R2Incumbent vendors bundle similar agent-governance features into broader AML or case-management contracts. — Win on mixed-stack neutrality, faster deployment, and deeper multi-jurisdiction policy control rather than on broad suite breadth.
- R3Jurisdiction-pack maintenance becomes a services-heavy burden that compresses gross margin. — Limit the first release to three hubs, codify change management, and use regional advisors only where product configuration cannot absorb policy change.
- R4Legacy integrations and data-access approvals delay time to first value beyond what pilots can tolerate. — Package one primary stack, keep the first workflow read-only, and reject edge-case integrations that break the deployment playbook.
- R5Internal audit or model-risk teams reject evidence provenance and reviewer controls as insufficient. — Make action logs, reviewer approvals, and evidence lineage first-class objects in the MVP and involve control functions in pilot design.
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Banks approve read-only pilots but refuse to grant production authority on live queues. | High | High | Start with bounded evidence-gathering tasks, require explicit human checkpoints, and measure reviewer trust before selling deeper automation. |
| Incumbent vendors bundle similar agent-governance features into broader AML or case-management contracts. | High | High | Win on mixed-stack neutrality, faster deployment, and deeper multi-jurisdiction policy control rather than on broad suite breadth. |
| Jurisdiction-pack maintenance becomes a services-heavy burden that compresses gross margin. | Medium | High | Limit the first release to three hubs, codify change management, and use regional advisors only where product configuration cannot absorb policy change. |
| Legacy integrations and data-access approvals delay time to first value beyond what pilots can tolerate. | Medium | High | Package one primary stack, keep the first workflow read-only, and reject edge-case integrations that break the deployment playbook. |
| Internal audit or model-risk teams reject evidence provenance and reviewer controls as insufficient. | Medium | High | Make action logs, reviewer approvals, and evidence lineage first-class objects in the MVP and involve control functions in pilot design. |
| Title | Global sanctions investigations director at a Tier-1 correspondent bank |
|---|---|
| Profile | A 20,000-plus employee transaction bank using NICE Actimize or Quantexa across London, Dubai, and Singapore, with shared-service investigators and regional policy owners handling one global queue. |
| Trigger | The bank approves a live AI pilot for sanctions investigations or opens a new regional booking center that forces explicit agent permissions and human checkpoints. |
| Buyer | Global Head of Financial Crime Operations |
| Initial contract | $100k-$200k paid pilot on one sanctions queue and three jurisdiction packs, converting to a $350k-$750k annual subscription plus implementation once median case-assembly time falls by 30% or more and compliance approves production use. |
What must be true
- At least one target-bank segment treats governed AI investigations as a current 12-month buying priority with a named budget owner.
- A neutral overlay can land beside NICE Actimize or Quantexa without forcing a multiyear platform replacement.
- The first packaged deployment can connect one live queue, one case system, and key data sources in under 90 days.
- Governed agents can reduce median evidence-gathering or case-assembly time by at least 30% without creating audit exceptions.
- UK, UAE, and Singapore policy-pack maintenance can be handled with software and limited policy ops while preserving 70% gross margin.
Open diligence questions
- Which executive truly owns the budget: financial-crime operations, compliance, transaction-banking COO, or the incumbent transformation program?
- Can the first deployment plug into a live NICE Actimize or Quantexa workflow without a multi-quarter security review?
- What cycle-time and QA gains are required for a bank to justify $350k-$750k annual spend?
- How often do UK, UAE, and Singapore policy packs change, and what staffing model keeps them current?
- Why will banks buy this overlay instead of accepting Lucinity, Quantifind, NICE Actimize, or integrator-led alternatives?
| Call | Meet / investigate further |
|---|---|
| Conviction | Medium conviction because the control-point thesis is credible, but direct budget ownership and policy-pack economics still need proof. |
| Why believe | Banks already spend heavily on fincrime operations, and this wedge sits at a concrete AI-deployment gate where mixed-stack governance is still painful. |
| Why doubt | The startup can still lose if buyers prefer incumbent bundles or if jurisdiction upkeep turns the product into a services business. |
| Next diligence | Secure two paid pilots on one cross-border sanctions queue and measure case-time reduction, reviewer acceptance, and policy-update workload before underwriting a larger round. |
Financial model
| Year 1 revenue | $480K EBITDA $-1.22M · Cash EOP $1.78M |
|---|---|
| Year 2 revenue | $2.25M EBITDA $-966K · Cash EOP $812K |
| Year 3 revenue | $5.53M EBITDA $551K · Cash EOP $1.36M |
| ARPU (annual) | $750K |
|---|---|
| Gross margin | 70% |
| CAC | $223K Payback 5.1 months |
| LTV / CAC | 9.8x LTV $2.19M |
| Round | pre-seed · $3.0M |
|---|---|
| Runway | 24 months |
| Milestone | Reach 7 paying banks by Q2Y3, prove 2 in-logo expansion motions, and turn quarterly EBITDA positive before the seed process starts. |
Model sanity
- Revenue engine. Base revenue comes from growing paying banks from 2 at Y1 exit to 10 at Q4Y3 while blended annualized revenue per bank climbs from about $570K to $750K as second packs and adjacent workflows attach.
- Must go right. The deployment playbook has to compress toward the business plan's sub-8-week packaging target so a 14-person team can support 5 banks by Q4Y2 and 10 by Q4Y3 without dragging gross margin below target.
- Model breaks if. If pilot-to-production cycles slip a quarter or policy-pack upkeep keeps gross margin in the mid-60s, the downside case drives the cash floor toward roughly $250K before seed-ready proof appears.
- Next-round proof. The seed story is 7 paying banks by Q2Y3, at least 2 in-logo expansions, partner-sourced pilots that convert, and quarterly EBITDA turning positive before the pre-seed cash floor tightens.
- Revenue (line, area)
- Cash EOP (dashed)
- EBITDA (bars, gray = loss)
- Founder / CEO
- Founding engineer
- Compliance product lead
- Solutions architect
- Policy ops lead
- Head of partnerships
- Platform engineer II
- Customer success / implementation
- Finance & ops manager
- Data / QA engineer
- Account executive
- Solutions architect II
- Platform engineer III
- Policy analyst
| Y3 revenue | Y3 EBITDA | Cash low point | Description | |
|---|---|---|---|---|
| Downside | Pilot-to-production approvals slip by a quarter, expansion is slower, and policy-pack upkeep stays more manual than planned. | |||
| Base | The connector and policy-pack playbook becomes repeatable enough to move from 2 paying banks at Y1 exit to 10 by Q4Y3 while gross margin only reaches target at the end of the period. | |||
| Upside | Partner-sourced pilots convert sooner, more banks add second packs or adjacent workflows, and deployment effort standardizes faster. |
| Variable | Downside | Upside | Cash impact | Revenue impact |
|---|---|---|---|---|
| sales cycle | Pilot-to-production conversion stretches by one extra quarter. | Reference customers compress the cycle to well under one quarter. | ||
| ARPU | Exit blended ARR per bank lands around $675K instead of $750K. | Expansion into more packs and adjacent workflows lifts exit ARR per bank toward $800K. | ||
| gross margin | Gross margin exits near 66% because policy-pack upkeep remains manual. | Gross margin exits near 73% as connectors and packs standardize faster. | ||
| CAC | Paid pilots require more founder time and partner sourcing lags, pushing CAC toward $280K. | Partner referrals and references lower CAC toward $180K. | ||
| hiring pace | Two Y3 hires are pulled into Y2 before repeatable expansion is proven. | The final policy and GTM hires wait until after Q3Y3 without slowing launches. | ||
| churn | Monthly churn rises to 3.0% as incumbents counterbundle faster. | Monthly churn stays near 1.0% because the governed queue becomes a sticky control point. |
Scenarios
| Scenario | Y3 revenue | Y3 EBITDA | Cash low point | Description | Key changes |
|---|---|---|---|---|---|
| Downside | $4.33M | $-140K | $250K | Pilot-to-production approvals slip by a quarter, expansion is slower, and policy-pack upkeep stays more manual than planned. |
|
| Base | $5.53M | $551K | $761K | The connector and policy-pack playbook becomes repeatable enough to move from 2 paying banks at Y1 exit to 10 by Q4Y3 while gross margin only reaches target at the end of the period. |
|
| Upside | $6.71M | $1.23M | $920K | Partner-sourced pilots convert sooner, more banks add second packs or adjacent workflows, and deployment effort standardizes faster. |
|
Sensitivity
| Variable | Downside | Base | Upside |
|---|---|---|---|
| ARPU | Exit blended ARR per bank lands around $675K instead of $750K. | Q4Y3 exit blended ARR per bank reaches $750K. | Expansion into more packs and adjacent workflows lifts exit ARR per bank toward $800K. |
| CAC | Paid pilots require more founder time and partner sourcing lags, pushing CAC toward $280K. | CAC stays around $223K per net new paying bank. | Partner referrals and references lower CAC toward $180K. |
| churn | Monthly churn rises to 3.0% as incumbents counterbundle faster. | Monthly churn holds at 2.0% once banks reach production. | Monthly churn stays near 1.0% because the governed queue becomes a sticky control point. |
| sales cycle | Pilot-to-production conversion stretches by one extra quarter. | Banks move from paid pilot to production in about one quarter after control approvals clear. | Reference customers compress the cycle to well under one quarter. |
| gross margin | Gross margin exits near 66% because policy-pack upkeep remains manual. | Gross margin reaches 70% in Q4Y3 and about 68%-70% across Y3. | Gross margin exits near 73% as connectors and packs standardize faster. |
| hiring pace | Two Y3 hires are pulled into Y2 before repeatable expansion is proven. | Hiring follows the integration-first sequencing in the business plan. | The final policy and GTM hires wait until after Q3Y3 without slowing launches. |
Key assumptions (22)
| ID | Name | Value | Unit | Source |
|---|---|---|---|---|
| A1 | Model start month | 2026-07 | YYYY-MM | [BP date 2026-06-30] The model starts in the first full month after the dated business plan. |
| A2 | Opening cash / pre-seed raise | $3.0M | USD | [BP fundingAsk targetFundingRangeUsd $3-5M + BP fundingAsk runwayMonths 18 + model cash trough] The base case uses the low end of the stated range because hiring stays integration-first and quarterly EBITDA turns positive by Q2Y3. |
| A3 | Starting paying banks (M1) | 0 | count | [BP milestones 0-12 months + BP experimentRoadmap] The company starts pre-revenue and must first convert design partners into paid pilots. |
| A4 | Paying customer definition | A bank logo paying for either a paid pilot or a production deployment on one governed investigations queue. | definition | [BP gtm.wedge + BP businessModel.unitOfValue] CustomersEop counts any bank already paying for a governed queue, even if it is still in pilot mode. |
| A5 | Paid pilot economics | $140K-$160K over roughly 4 months (~$35K-$40K per month) | USD per bank | [BP investorMemo.firstCustomer.initialContract $100k-$200k paid pilot] The base case uses a mid-range pilot contract spread across a four-month validation window. |
| A6 | Blended revenue per paying bank ramp | Y1 exit about $570K ARR, Q4Y2 about $648K ARR, and Q4Y3 about $750K ARR per paying bank. | USD per bank-year | [BP gtm.pricing $350k-$750k production ACV + Research market.som 12 banks x $750k] Blended realized revenue per bank only reaches the researched SOM level by Q4Y3 after expansion into more packs and adjacent workflows. |
| A7 | Year 1 paying-bank landing pattern | M1-M12 customersEop = 0,0,0,0,1,1,1,1,2,2,2,2 | count | [BP milestones 0-12 months sign 5-6 design partners, convert at least 2 into paid pilots, and put 1 queue into production] The base case reaches 2 paying banks by Y1 exit. |
| A8 | Year 2 and Year 3 customer milestones | Q1Y2 3; Q2Y2 4; Q3Y2 4; Q4Y2 5; Q1Y3 6; Q2Y3 7; Q3Y3 8; Q4Y3 10 | count | [BP milestones 12-24 and 24-36 months + BP gtm.funnelTargets] The base case stays within the plan band of 4-6 production banks by 24 months and 10-12 by 36 months. |
| A9 | Revenue recognition convention | Period revenue equals period-end paying banks times the blended realized revenue per paying bank for that month or quarter. | formula | [BP businessModel.revenueStreams + BP businessModel.unitOfValue] This keeps revenue directly traceable to customer count and the queue-plus-pack pricing structure. |
| A10 | Gross margin ramp | Y1 35%-45%, Y2 55%-67%, Y3 68%-70% | gross margin percent | [BP businessModel.targetGrossMarginPct 70 + BP operatingAssumptions + Research openQuestions] Early pilots absorb more connector and policy-pack labor before the model reaches the target margin by Q4Y3. |
| A11 | Hiring cadence | M1 founder CEO, founding engineer, compliance product lead; M4 solutions architect; M7 policy ops lead; M10 head of partnerships; M13 platform engineer II; M16 customer success / implementation; M19 finance & ops; M22 data / QA engineer; M26 account executive; M28 solutions architect II; M31 platform engineer III; M34 policy analyst. | timeline | [BP team startTiming + BP strategicChoices.sequencingRationale] Product, solutions, and policy hires come before scaled quota sales. |
| A12 | Engineering loaded compensation | Founding engineer $200K; platform engineers II/III $190K each; data / QA engineer $175K. | USD per year | [BP team roles + startup-finance heuristic] Senior integration and control-plane engineering talent is required, but the pre-seed plan remains lean for enterprise infrastructure. |
| A13 | Compliance and policy loaded compensation | Compliance product lead $170K; policy ops lead $150K; policy analyst $140K. | USD per year | [BP team roles + BP operatingAssumptions on policy-pack maintenance + startup-finance heuristic] The policy stack needs senior product judgment first, then lower-cost upkeep capacity later. |
| A14 | Solutions and implementation loaded compensation | Solutions architects I/II $155K each; customer success / implementation lead $145K. | USD per year | [BP team Solutions architect rationale + BP milestones deployment targets + startup-finance heuristic] Solutions hires are priced for bank integration work, but still below large-bank cash levels. |
| A15 | GTM loaded compensation | Founder CEO $150K; head of partnerships $180K; account executive $180K. | USD per year | [BP gtm.channels + BP team Head of partnerships rationale + startup-finance heuristic] Early selling remains founder-led and channel-assisted before a full sales bench exists. |
| A16 | G&A loaded compensation | Finance & ops manager $120K. | USD per year | [BP operations + startup-finance heuristic] Covers lean finance, vendor management, and enterprise customer administration. |
| A17 | Payroll allocation to P&L lines | Founder 70% S&M / 30% G&A; engineering 100% R&D; compliance product 80% R&D / 20% G&A; policy ops 70% R&D / 30% G&A; solutions architects 50% S&M / 50% R&D; customer success 40% S&M / 60% G&A; GTM 100% S&M; finance 100% G&A; policy analyst 60% R&D / 40% G&A. | allocation | [BP team rationales + BP operations] Used to roll headcount cost into functional P&L lines while keeping a separate salary line for transparency. |
| A18 | Non-payroll operating spend ramp | S&M non-payroll rises from $12K/mo to $38K/mo, R&D/cloud/compliance tooling from $24K/mo to $48K/mo, and G&A from $12K/mo to $26K/mo by Q4Y3. | USD per month | [BP operations + Research regulatoryTechnicalConstraints + startup-finance heuristic] Bank deployments require cloud sandboxes, legal/compliance support, partner travel, and audit tooling before spend can taper. |
| A19 | Cash conversion policy | EBITDA approximates cash movement. | formula | [startup-finance heuristic] Capex, taxes, debt service, and working-capital timing are assumed immaterial at this stage. |
| A20 | Monthly churn | 2.0% | percent per month | [startup-finance heuristic for early enterprise workflow SaaS] Sanctions and AML workflow control points should be sticky, but the model still assumes some logo loss before the product matures. |
| A21 | CAC convention | Y2-Y3 sales and marketing spend divided by 8 net new paying banks from Y1 exit to Q4Y3. | formula | [model calc using base-case S&M spend + BP gtm.funnelTargets] Captures founder-led selling, partnerships, and one scaled sales hire across the commercial build-out. |
| A22 | Next-round milestone for sizing the ask | By Q2Y3 reach 7 paying banks, show at least 2 in-logo expansion motions, and turn quarterly EBITDA positive. | milestone | [BP milestones 12-24 months + BP fundingAsk runwayMonths 18 + model cash curve] The pre-seed raise is sized to hit seed-ready proof and still preserve a buffer. |
flowchart LR DesignPartners[Design partners] --> PaidPilots[Paid pilots] PaidPilots --> ProductionBanks[Production banks] ProductionBanks --> ExpansionPacks[More packs and adjacent workflows] ExpansionPacks --> Revenue[Revenue] Revenue --> GrossProfit[Gross profit] GrossProfit --> Cash[Cash and runway]
Flags: CustomersEop counts paid pilots as paying banks in Y1 and early Y2, so true production-bank count is lower than the headline customer total until late Y2. · The Q4Y3 exit ARPU reaches the researched $750K annual spend level, so second-pack or adjacent-workflow expansion must land in several logos rather than pure single-queue pricing. · Revenue concentration stays high because Q4Y3 still depends on 10 banks; losing one renewal would move both growth and cash materially. · Cash uses EBITDA as a proxy, so enterprise billing milestones, implementation prepayments, or deferred revenue could shift the actual low point.
Top risks
- Policy-pack maintenance burden. Keeping jurisdiction rules current across sanctions, AML, and data-sharing regimes could become operationally heavy and slow expansion. Mitigation: Start with three financial hubs, build modular policy packs, and pair product updates with regional advisory partners.
- Pilot-to-production skepticism. Bank compliance teams may approve read-only experiments but resist giving agents live workflow authority. Mitigation: Launch with bounded evidence-gathering tasks, mandatory human checkpoints, and action-level logs before offering deeper automation.
- Incumbent workflow bundling. Case-management or screening vendors could add lightweight agent controls and bundle them into existing bank contracts. Mitigation: Win on cross-vendor governance, jurisdiction specificity, and faster deployment across mixed stacks that single-vendor tools do not cover.
Evidence
Cited sources (35)
- Quantifind. Investigations | Financial Crimes Use Cases | Quantifind · https://www.quantifind.com/use-case-investigations/
- Quantifind. Watchlist Screening | Financial Crimes Use Cases | Quantifind · https://www.quantifind.com/use-case-watchlist-screening/
- Quantifind. Sanctions Compliance | Financial Crimes Use Cases | Quantifind · https://www.quantifind.com/solution-sanctions-compliance/
- Quantexa. AML Software & Solutions - Quantexa · https://www.quantexa.com/solutions/aml/
- Quantexa. Sharper AML Decisions Start With Better Data · https://www.quantexa.com/solutions/cloud-aml/
- Quantexa. Trade AML - Quantexa · https://www.quantexa.com/solutions/trade-aml/
- Quantexa. Financial Crime Detection Solutions - Quantexa · https://www.quantexa.com/solutions/financial-crime/
- Lucinity. Sanctions at Speed: How to Bring Sanctions Screening up to Speed With Instant Payments - Lucinity · https://lucinity.com/blog/sanctions-at-speed
- Lucinity. Give Your Investigators the Power to Act—In One Unified System - Lucinity · https://lucinity.com/blog/actor-actions-case-manager
- NICE Actimize. Xceed AI Agents | NICE Actimize · https://www.niceactimize.com/xceed-ai-agents
- NICE Actimize. NICE Actimize AML Software Solutions · https://www.niceactimize.com/anti-money-laundering
- NICE Actimize. Enterprise Risk Case Management - NICE Actimize · https://www.niceactimize.com/enterprise-risk-case-management
- NICE Actimize. Sanctions Screening Software | NICE Actimize · https://www.niceactimize.com/anti-money-laundering/sanctions-screening
- ComplyAdvantage. Agentic Workflows · https://complyadvantage.com/mesh/agentic-workflows/
- ComplyAdvantage. Transaction Monitoring · https://complyadvantage.com/mesh/transaction-monitoring-software/
- Fenergo. Global Fincrime Operations Trends in 2025 · https://www.fenergo.com/global-fincrime-operations-trends-2025
- Chartis Research. Spotlight: Entity Resolution – Sanctions and Beyond - Chartis Research · https://www.chartis-research.com/financial-crime/watchlist-monitoring/7946626/spotlight-entity-resolution-%E2%80%93-sanctions-and-beyond
- Financial Stability Board. 2025 List of Global Systemically Important Banks (G-SIBs) · https://www.fsb.org/2025/11/2025-list-of-global-systemically-important-banks-g-sibs/
- UK Government. UK financial sanctions guidance · https://www.gov.uk/guidance/uk-financial-sanctions-guidance
- Financial Conduct Authority. Financial crime · https://www.fca.org.uk/firms/financial-crime
- Bank of England. Artificial intelligence in UK financial services - 2024 · https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024
- Bank of England. FS2/23 – Artificial Intelligence and Machine Learning · https://www.bankofengland.co.uk/prudential-regulation/publication/2023/october/artificial-intelligence-and-machine-learning
- NIST. AI Risk Management Framework · https://www.nist.gov/itl/ai-risk-management-framework
- AWS Documentation. Detect and filter harmful content by using Amazon Bedrock Guardrails - Amazon Bedrock · https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails.html
- GovCon Wire. Quantifind to Advance AI-Native Risk Intelligence Platform With $200M Investment - GovCon Wire · https://govconwire.com/articles/quantifind-200m-investment-graphyte-ai-risk-intelligence
- NICE. NiCE Actimize X-Sight ActOne Platform Redefines Financial Crime Investigations with Agentic AI | NiCE · https://www.nice.com/press-releases/nice-actimize-x-sight-actone-platform-redefines-financial-crime-investigations-with-agentic-ai
- Quantexa. Quantexa Makes Its Decision Intelligence Platform ‘Agent Ready’ to Solve the Hardest Problems in AI: Data Fragmentation & Context · https://www.quantexa.com/press/quantexa-makes-its-decision-intelligence-platform-agent-ready/
- Quantexa. Quantexa Launches Cloud AML Product for U.S. Mid-size and Community Banks · https://www.quantexa.com/press/quantexa-launches-cloud-aml-product-for-u-s-mid-size-and-community-banks/
- LexisNexis Risk Solutions. Study Reveals Annual Cost of Financial Crime Compliance Totals $61 Billion in the United States and Canada · https://risk.lexisnexis.com/about-us/press-room/press-release/20240221-true-cost-of-compliance-us-ca
- LexisNexis Risk Solutions. LexisNexis Risk Solutions Study Reveals Global Financial Crime Compliance Costs for Financial Institutions Totals More Than U.S.$206 Billion · https://risk.lexisnexis.com/about-us/press-room/press-release/20230926-global-financial-crime-compliance-costs
- LexisNexis Risk Solutions. LexisNexis Risk Solutions Report Reveals the Yearly Cost of Financial Crime Compliance Reaching $56.7 Billion, a 13.6% Increase for Financial Institutions in the United States and Canada Combined · https://risk.lexisnexis.com/about-us/press-room/press-release/20220929-report-reveals-the-yearly-cost-of-financial-crime-compliance
- LexisNexis Risk Solutions. LexisNexis True Cost of Compliance Study Finds Financial Crime Compliance Costs Hit Record High of U.S. $50.1 Billion in Asia Pacific · https://risk.lexisnexis.com/global/en/about-us/press-room/press-release/20220615-tcoc-apac
- Office of Foreign Assets Control | U.S. Department of the Treasury. A Framework for OFAC Compliance Commitments · https://ofac.treasury.gov/media/16331/download?inline=
- Dubai Financial Services Authority. Regulatory Framework | DFSA · https://www.dfsa.ae/what-we-do/aml-ctf-sanctions-compliance/regulatory-framework
- Executive Office for Control & Non-Proliferation. UN page | EXECUTIVE OFFICE FOR CONTROL & NON-PROLIFERATION · https://www.uaeiec.gov.ae/en-us/un-page