At a Glance
| Metric | Before | After |
|---|---|---|
| Escalated investigations per year | 25,000 | 25,000 |
| Standard investigation, time to disposition | ~2 hours | 48 to 60 minutes |
| Complex investigation | 20+ hours | 8 to 10 hours |
| SAR narrative drafting | Hours | Minutes |
| Cost per escalated investigation | ~$435 | $174 to $218 |
| Annual investigation cost | $10.9M | $4.4M to $5.4M |
| Analyst hours on investigation | 72,500 | 36,000 to 44,000 hours returned |
| Time to detection, genuine activity | Baseline | Down 35% to 50% |
| Filing decision | Human | Human, unchanged |
| Audit coverage | Partial | 100% of decisions replayable |
$5.4M to $6.5M per year in investigation cost reduction.
And 36,000 to 44,000 analyst hours moved off assembly work and onto judgment.
Challenge
Clearing the noise is only half the AML problem. The other half is what happens to the alerts that survive triage, and this is where a bank's most experienced people do their least valuable work.
- Roughly 25,000 alerts a year escalate into real investigations. And what happens next is almost entirely assembly: KYC profile from one system, transaction history from another, counterparty records from a third, adverse media by hand, then a timeline pieced together.
- Two hours for a standard case, past twenty for a complex one. At one global bank analysts averaged four hours per alert, most of it spent ruling things out rather than establishing anything.
- $435 per escalated investigation, about $10.9M a year. But the money was not the point. The people qualified to spot a laundering network were spending their week doing data entry, and the ones who were good at it burned out and left.
- Time to detection suffered. A case sitting in an assembly queue is a case not being decided, and in AML the interval between the activity and the filing is a number the regulator looks at directly.
- Narrative quality became uneven. When narrative writing is a manual craft under backlog pressure, SARs vary by author. The SAR FAQs FinCEN issued on 9 October 2025 clarified expectations on completeness, including that critical items be answered or affirmatively marked unknown, and a thin filing invites a second look at the whole programme.
- The bank did not want the investigator out of the decision. It wanted everything that happened before the decision taken away.
The base every saving is measured against
25,000
Escalated investigations a year
~$435
Cost per escalated investigation
$10.9M
A year, and 72,500 analyst hours, spent mostly on assembly
Solution
- Every alert gets triaged, and noise clears with a documented rationale. Genuine risk is enriched, classified, and escalated to a human as a near-complete case, so the analyst's day stops being a queue to empty.
- Evidence assembly happens before a person opens the case. KYC profile, transaction history, counterparties, and adverse media consolidated in parallel rather than pulled from three systems by hand.
- Activity is classified against known typologies. And against the bank's own scenario library, so the disposition carries a typology rationale rather than a score.
- Separation of duties is a defensibility requirement. An examiner needs a clean split between gathering evidence, classifying risk, and reaching a conclusion. That is why it is many narrow agents rather than one model.
- Analysis runs inside the bank's boundary. Control plane and storage sit in the bank's region, each investigation in its own guest kernel, with egress allowlisted in the kernel so transaction data cannot leave.
- The filing decision stays with a human. Permanently and by design. The agents assemble, classify, and draft. The person decides.
What happens before the case is opened
The analyst's two hours
Already done on arrival
KYC profile
KYC profile
Pulled from one system
Consolidated into the case
Transaction history
Transaction history
Pulled from another
Consolidated into the case
Counterparties and adverse media
Counterparties and adverse media
Chased as time allowed
Classified against typologies
The SAR narrative
The SAR narrative
Written by hand under backlog
Drafted from the evidence gathered
The filing decision
The filing decision
A human, on a thin file
A human, on a complete one
Outcome Derived
The filing decision stays with a human, permanently and by design. What changed is what the investigator is holding when they make it.
- Standard investigation from two hours to 48-60 minutes. And complex cases from twenty-plus hours to eight to ten, a 50% to 60% compression on escalated work.
- SAR narrative drafting from hours to minutes. Because the narrative is assembled from evidence the crew has already gathered rather than composed from a blank page.
- $5.4M to $6.5M a year off a $10.9M base. Cost per escalated investigation falls from roughly $435 to between $174 and $218.
- 36,000 to 44,000 investigator hours returned. A redeployment argument, not a headcount one, and a different kind of hour from those recovered by clearing false positives. These belong to the bank's most experienced people.
- Time to detection improved 35% to 50%. A target measured against the bank's own Phase 0 baseline, not a borrowed industry benchmark. This is the number that matters most to an examiner, because catching genuine activity faster is what the regulator rewards.
- Every draft is built from the same evidentiary structure. Which removes the author-to-author variance of writing narratives by hand under backlog pressure. Against the SAR FAQs FinCEN issued on 9 October 2025 with the Federal Reserve, FDIC, NCUA and OCC, which clarified what a complete filing looks like, consistency is not cosmetic.
- 100% of decisions replayable, including recommendations not to file. The investigator's judgment sits on top of an inspectable evidentiary chain rather than a black-box conclusion.
What We Would Prove, and How
Phase 0 measures the bank's actual investigation time per case, cost per case, SAR volume, current time to detection, and its own narrative quality bar. That baseline becomes the contract's yardstick.
Build and integration to the monitoring system, KYC store, transaction data, and enrichment providers runs along allowlisted paths. Shadow mode follows, with agents assembling cases in parallel with the human team and producing draft narratives that are never filed. Agent dispositions are compared to investigator dispositions case by case. Go-live is gated on disposition agreement and narrative quality, not on speed.
Success criteria, agreed up front against the Phase 0 baseline: investigation time down at least 50%, no change in disposition accuracy against the human team, draft narratives meeting the bank's existing quality bar without additional rework, and 100% audit coverage of every decision.
Highlights
- Removes $5.4M to $6.5M a year from a $10.9M escalated-investigation base.
- Standard investigation time falls from about two hours to 48 to 60 minutes; complex cases from 20+ hours to 8 to 10 hours.
- Returns 36,000 to 44,000 experienced investigator hours a year from assembly work to judgment.
- SAR narrative drafting goes from hours to minutes; filing decision stays with a human, permanently.
- 100% of decisions are logged and replayable, including the reasoning behind every draft and every recommendation not to file.
Frequently asked questions
Does AML case management software replace the investigator?
No. The decision to file stays with a human investigator, permanently and by design. The agent crew gathers the evidence, resolves the network around an alert, and drafts the SAR narrative from what it found. The investigator reviews an assembled case and decides. What changes is that the person starts from evidence rather than from a blank page.
How long does an AML investigation take once the case assembles itself?
This blueprint models standard investigations falling from two hours to 48 to 60 minutes, and complex cases from twenty-plus hours to eight to ten. Those are modelled figures, not measured results. Phase 0 establishes the bank's actual investigation time, cost per case, and SAR volume first, and that baseline becomes the contract's yardstick.
Can SAR narrative drafting run inside our own environment?
Yes. The control plane and storage are self-hosted inside the bank's boundary, and each investigation runs in its own Firecracker micro-VM. Outbound access is allowlisted in the kernel with eBPF, so enrichment reaches approved adverse-media providers, watchlists, and registries and nothing else. Transaction data does not leave, because the path does not exist.
What happens when an examiner asks why a case closed without a filing?
The full decision chain replays, including recommendations not to file. Every decision is replayable: what evidence was gathered, which typologies were tested, which relationships were examined and dismissed, and why. The investigator's judgment sits on top of an inspectable evidentiary chain rather than a score the bank cannot explain.
How is the agent tested against our investigators before go-live?
Shadow mode. The agents assemble cases in parallel with the human team and produce draft narratives that are never filed. Agent dispositions are compared to investigator dispositions case by case. Go-live is gated on disposition agreement and narrative quality, not on speed.



