DataFab / Utilities / Financial crime
Governed utility · banking, payments & financial services
The unit sees fragments. Give it one customer.
Core banking, payments, customer records, screening, trade finance, documents and a dozen vendor tools each hold a sliver of the truth — and none of them share an entity, a schema or a story. DataFab resolves them in place into one governed graph of customers, counterparties and money flow, then runs governed agencies over it from detection to defensible narrative.
The brief
“Clear the backlog. Cut the false positives. Move to perpetual KYC. Get the ultimate beneficial owner right. Do it without adding headcount, without moving customer data anywhere, and be able to show the regulator exactly why every single decision was taken.”
Every one of those is the same problem wearing five faces: the unit does not have one customer. It has twelve records that no system agrees are the same person, and every control is applied to the copy in front of it rather than to the party itself.
Resolve the entity and the five problems change shape at once. Duplicate alerts collapse. Screening runs against the real party rather than a string. Ownership becomes traversable. Review becomes event-driven because the graph knows when something changed. And the answer to why stops living in somebody’s memory.
Fragmented data
The same customer exists a dozen times, reconciled by hand, never by the system. Controls apply to the copy, not the party.
Alert backlogs
Rules fire in isolation on unresolved records; investigators drown in volume, most of it the same customer arriving repeatedly.
Periodic review
A calendar-driven refresh cycle that is stale the day it completes, and blind to the change that actually mattered last Tuesday.
Opaque ownership
Chains that stop at the first offshore layer, with the gap recorded as a blank field rather than as a finding somebody must act on.
No lineage
When the regulator asks why, the answer is reconstructed months later from screenshots, spreadsheets and recollection.
The shape of it
Governed agencies, over one fabric.
Beneath, the Knowledge Fabric reads and resolves the estate in place. Above it, governed agencies reason, decide and act, with every output traceable to source — all wrapped in security, privacy and observability spanning every layer.
Perpetual KYC
The file is never finished.
Periodic review exists because nothing was watching. When the graph is live against source, review stops being a calendar event and becomes a consequence: a directorship changes, a sanction lands, an address moves, a payment pattern breaks — and the file reopens itself, at the risk tier that change deserves.
A change in the estate
New account, new counterparty, new document, new payment behaviour, a completed dispute, a closed product — any of it can move the risk position.
A change in the world
A sanctions listing, a registry filing, an adverse-media item, a court record, an officer appointment — matched against what you already hold, not screened blind.
The work comes to you
The system stops being a place you go and becomes something that raises the case, with the evidence already assembled and the reason for raising it stated.
Screening
Screen the party, not the string.
A screening engine that compares text to a list will always trade false positives against missed matches, because it is solving the wrong problem. Resolution happens at the ontology level here: the fabric reasons over entities, not strings, so a name rendered in Arabic, Cyrillic, Han or Latin script resolves to one party — and one name never silently collapses two people.
Most of the noise is not bad matching. It is the same customer arriving eleven times through eleven systems, each generating its own alert against its own copy. Collapse the copies into one governed record and a large share of the queue disappears before a threshold is ever touched — with the collapse itself recorded, scored and reversible.
Under the utilities
Lineage, joins and a graph that stays current.
Ownership & control
Chains to natural persons — and an honest halt.
Traversal runs until it reaches natural persons or cannot proceed. Where it cannot, the halt is reported as a finding with the level reached, the percentage unresolved and the reason — not written into the file as a blank field that nobody is accountable for.
Control, not just ownership
Shareholding, directorship, signatory rights, trusteeship and effective control carried as typed relationships, each with confidence, source and date on the edge.
The link written nowhere
A directorship in a filing plus a shareholding in a register plus a party already screened elsewhere in the estate. The conclusion exists only between them, and only a graph returns it.
The chain is watched
A new filing, a transfer of shares or a change of officer reopens the traversal and re-scores the party — automatically, with the trigger recorded.
Alert triage
Clear the queue by resolving first.
Because the graph already knows what an entity is, rules express intent rather than brittle joins. “Funds in from a high-risk counterparty, out within twenty-four hours” is written against meaning. Change a threshold, replay history, see the effect — before it reaches production.
| Rule work | How it behaves here | What that buys the unit |
|---|---|---|
| Authoring | Expressed over resolved entities and typed relationships | A typology survives a source-system change |
| Versioning | Every rule pinned, dated and immutable once used | You can say which rule produced which decision |
| Back-testing | Replayed against historical state, not today’s | Tuning evidenced before a threshold moves |
| Dismissal | Requires a stated rationale, recorded against the entity | No silent closure to defend two years later |
| Escalation | Routed with the graph context already attached | The analyst opens a prepared file, not a blank one |
The workforce
Six agencies, each with one job.
An agency is a coordinated team of agents serving one purpose. Each runs at the autonomy its risk allows, from quietly assisting an analyst to acting under policy — and every one of them is composed by your people in the Studio, not shipped as a black box.
Monitoring
Watches flows and networks for typology hits continuously, against the live graph rather than a nightly extract.
Screening
Resolves names and entities against watchlists, sanctions and adverse signals — the real party, in any script.
Triage
Ranks and dismisses noise with a stated, auditable rationale carried on the entity.
Investigation
Gathers evidence across the graph and assembles the case, with every element linked to source.
Narrative
Drafts the report grounded in cited evidence. The filing itself waits at a human gate.
Quality
Reviews, challenges and checks the work of the other agencies — a second line built into the first.
Investigation
The investigator just asks.
The whole platform meets the analyst as conversation. Ask in plain language; the agencies query the graph, act, and answer with cited evidence — rendering live widgets the analyst can drive rather than a paragraph they have to verify by hand.
Nothing in that exchange is unsourced. Every claim carries the record it rests on, every merge is reversible, and every consequential step waits on the analyst’s authority.
Why was customer C-4471 flagged, and who are they connected to?
Investigation agencyC-4471 triggered rapid pass-through: €1.2M received from a high-risk counterparty and moved out within 18 hours across three accounts. Two counterparties resolve to a single beneficial owner already on a watchlist. grounded in: transaction ledger · ownership graph · watchlist — view lineage
AnalystWas this customer reviewed in the last cycle?
Investigation agencyYes — reviewed and cleared. The ownership link post-dates that review by nine days and was never surfaced, because the review was calendar-driven. It is now attached to the file with the filing that missed it. reopened by: registry filing · confidence 0.91 · three sources merged
AnalystDraft the narrative.
Narrative agencyDrafted, with every statement linked to the record it rests on. Held at the gate for your approval. human gate · awaiting analyst authority · the gate itself is logged
Illustrative exchange showing the utility’s behaviour. Figures are example values, not measured results.
The financial-crime utilities
Every function is a utility on the Fabric.
The unit does not buy another point tool. Each financial-crime capability is delivered as a utility — composed from platform building blocks, run by an agency, over the one resolved graph. Turn them on; they share the same entities, the same lineage and the same governance.
Platform utilities — the building blocks every utility is composed from
01Watchlist & sanctions screening
Screen the resolved entity — not the raw string. Because the customer is already one resolved entity in the graph, screening matches a real party against lists, with aliases, languages and prior dispositions in view. Fewer duplicate hits, every decision explained.
Resolve, then match — names, aliases and identifiers reconciled before the list lookup. Disposition with rationale — hits cleared or escalated with a stated, auditable reason. Carry the decision forward — yesterday’s clearance informs today, so the same alias is never re-litigated.
Composed of
Run by the Screening agency · autonomy: clear the obvious, escalate the rest.
02Adverse media screening
The right story, on the right entity. DataFab ingests open and licensed sources, judges relevance, and attaches negative signals to the resolved entity — not to a name that might be three different people. Each signal is dated and traceable to its source.
Composed of
Run by the Adverse-media agency · grounded in cited articles, not generated summaries.
03Perpetual KYC
Customer risk that never goes stale. Periodic review becomes continuous. When the graph changes — a new counterparty, an ownership shift, a fresh signal — the customer’s risk is recomputed and, only if it matters, a review is raised.
Event-driven, not calendar-driven: reviews triggered by real change rather than an arbitrary cycle. Whole-customer view: risk judged across every account and relationship at once. Policy as configuration: the risk model and thresholds are owned by the unit, versioned and explainable.
Composed of
Run by the Monitoring agency · continuous, gated for material change.
04Transaction monitoring
Monitoring that knows who is involved. Scenarios run over money movement with the graph in scope — counterparty risk, ownership and history all in the same evaluation. The result is fewer, richer alerts that arrive ready to investigate.
Composed of
Run by the Monitoring agency · scenarios versioned, replayable against history.
05Ownership & network
See who is really behind it. Layered corporate structures become a traversable network. DataFab resolves entities across registries and internal records to surface the beneficial owner — and the hidden links between parties that look unrelated.
Pierce the structure: walk ownership chains to the ultimate beneficial owner. Find the hidden link: shared owners, addresses and counterparties across cases.
Composed of
Run by the Investigation agency · every link evidenced to source.
06Case & regulatory reporting
From evidence to filed report, in one place. The case assembles itself from the graph: evidence, documents, timeline and prior dispositions in a single file. The narrative is drafted with every claim linked to its source, ready for review and filing.
Composed of
Run by the Investigation and Narrative agencies · grounded, not generative.
The utilities, drawn
Each one composed from the same blocks.
The engagement
Not a software install. A transformation.
DataFab is delivered as a partnered programme: prove value on one utility, build the Fabric, compose the logic, stand up the agencies, then run it with you. Each phase is wrapped by a DataFab service — from consulting through to compliance as a service.
Mobilise & prove value
Data-strategy workshop, needs assessment, target operating model, and a proof of value on one utility — typically screening. Output: roadmap and a working proof of value.
Connect & unify
Connect sources in place, with no raw data leaving; data-quality assurance across the estate. Output: live connections and a quality baseline.
Build the Fabric
Discovery, schema and ontology generation, the dynamic knowledge graph and entity resolution. Output: a resolved graph and a derived ontology.
Compose the logic
Domain expertise, business-rule development, reference scenarios and risk scoring built with your specialists. Output: typologies, scenarios and scoring.
Build the agencies
Configure agencies and agents, set autonomy, wire the dialogue and agentic widgets, train the unit. Output: live agencies and the investigator console.
Assure & go live
Validation and replay testing, governance sign-off, rollout support and comprehensive user training. Output: signed off, in production.
DataFab leads
- The platform, the Fabric build and entity resolution
- Agency configuration, autonomy and the dialogue layer
- Governance scaffolding, lineage and audit by construction
- Run, monitoring and compliance as a service
The unit provides
- Access to sources within the boundary
- Domain expertise — typologies, rules and risk appetite
- Disposition standards and sign-off authority
- The investigators who drive the agencies day to day
Durations are illustrative model output, not contracted. Phases overlap and compress with scope and data readiness.
What the unit gets
Less noise. Faster cases. A defensible record.
Alert volume
Fewer, better alerts, raised on resolved entities rather than on twelve copies of the same customer.
Investigation time
Evidence assembled rather than hunted — the analyst opens a prepared file.
False positives
Context rather than isolated rule hits, so the threshold does not have to move to clear the queue.
Analyst capacity
The agencies do the gathering; the analyst spends judgement rather than hours.
Defensibility
Lineage on every decision, produced as the work happens rather than reconstructed later.
One picture of the customer
Resolved across every system, so risk is judged on the whole rather than on the fragment in front of you.
Alert to narrative in one place
Detection, investigation and reporting on the same graph, not three tools and a copy-paste between them.
Change without rebuild
New sources, new typologies and new rules extend the Fabric. Nothing is re-modelled from scratch.
Directional outcomes shown for illustration — model output, not contracted. Magnitudes depend on the unit’s data and configuration.
Trust & governance
In financial crime, an answer is only useful if it survives a regulator.
DataFab is built so that the right answer and its justification are the same artefact.
Grounded
Every answer traces to the resolved graph and its sources — grounded, not generative.
Attributable
Each claim carries its lineage — attributable and defensible, not guessed.
Reproducible
The same question yields the same, replayable result — it survives an audit.
Twelve compliance agencies are available out of the box — governance that ships with the platform, not a project bolted on after.
Defensibility
The answer to why is an artefact, not a memory.
Supervisors do not primarily ask whether the system found the right thing. They ask whether you can show how it decided, under which rules, on which data state, with whose authority — and whether the same inputs would produce the same result today.
Bounded by construction
Extraction and derivation are constrained by seed schemas. The system cannot invent entities outside them, and low confidence flags rather than fabricates.
Replay, years later
The data state, rule versions and execution path that produced a result — not an approximation reassembled from logs.
Ethical walls hold
Role- and attribute-based access at the graph, with compartments enforced across the connected environment. One fabric never means one undivided view.
Tamper-evident
Hash-chained and encrypted, auditor role only, no delete capability. Produced as the work happens.
The compliance stack
Twelve domain capabilities on one federated graph.
Two layers of domain capability sharing the same entities, the same lineage and the same governance — rather than twelve products each with its own customer master, its own permissions model and its own audit story to reconcile. The technologies beneath them are platform capability, documented on the platform pages.
Layer 01 — business utilities
Layer 02 — enterprise utilities
| Source system | What the fabric reads | What stays put |
|---|---|---|
| Core banking | Customer, account and product structure | Every record |
| Payments & ledger | Counterparty, flow and pattern metadata | Every transaction |
| CRM & onboarding | Relationships, contacts, onboarding state | Every record |
| Screening & case tools | Alerts, dispositions, case state | Every case file |
| Trade finance | Instruments, parties, documentary state | Every record |
| Document stores | Extracted text on request, with provenance | The source of record |
| Registries & lists | Governed enrichment, per-source isolated | Held at the provider |
Read-only, with your credentials, over the connection pattern your network allows. No ingestion, no secondary corpus, no customer data leaving the boundary.
Getting started
The first ninety days.
Deliberately small, and deliberately the part that hurts. One population, a handful of critical sources, and a governed agency running inside your boundary with the evidence produced as it works.
Plane and sources
A data plane stands up in your environment in hours. The first read-only connections are typically same-day; discovery begins cataloguing and profiling immediately.
Resolution on one population
Entity resolution runs at thresholds you set across a chosen book. Uncertain matches route to your people. The duplicate count becomes visible for the first time.
Semantic layer approved
The derived model is reviewed, corrected and approved by the people who own the domain — from evidence rather than a blank page.
First agency live
Triage or screening, composed by your team in the Studio, tested in a sandbox and published scoped and gated. Dispositions start carrying their rationale.
Assurance and replay
Enforcement points demonstrated against the engineering evidence pack; the audit and lineage stream proven end to end into your own security tooling; a historical case replayed under the rules in force at the time.
Next step
Bring one book and the systems behind it.
The fastest way to test this is the population you already know is duplicated, across the systems nobody wants to migrate. Resolution makes the scale of the problem visible in weeks.