AML software: what an AML-CFT solution must cover

September 29, 2026
Blog Image

AML software — also called AML-CFT compliance software or an anti-money laundering solution — supports the obligations to combat money laundering and terrorist financing: knowing your customers, assessing their risk, screening them, monitoring them and documenting every decision. With the EU AMLR regulation applying from July 10, 2027, many obliged entities are reviewing their tooling. Here is what an AML solution must cover and how to choose one.

Who needs AML-CFT compliance software?

All entities subject to AML-CFT rules (in France, Article L. 561-2 of the Monetary and Financial Code), including:

  • banks, credit, payment and e-money institutions;
  • insurance companies and intermediaries;
  • asset management companies and crypto-asset service providers;
  • accountants, auditors, notaries and lawyers for certain activities;
  • real estate professionals, dealers in high-value goods, gaming operators.

For a small organization, a spreadsheet may be enough at first. It stops being enough as soon as volume grows, customers are companies, or the supervisor asks you to prove what was done, when and why.

The 6 building blocks of a complete AML solution

1. Customer identification and verification (KYC / KYB)

This is the foundation: identify the customer, verify their identity against reliable sources, and for a legal entity, identify its representatives and beneficial owners. See how to choose a KYC solution and business KYC (KYB).

2. Sanctions, asset freeze and PEP screening

Every customer, and every related person, must be checked against sanctions lists (UN, European Union, national asset freeze registers, OFAC depending on your exposure), politically exposed persons lists and adverse media. Good AML software handles fuzzy name matching (transliterations, variants) without drowning the team in false positives.

3. Risk assessment and scoring

AML-CFT follows a risk-based approach: the level of due diligence depends on the customer's profile. The software must apply your risk classification — country, activity, product, distribution channel, ownership structure — and derive the level of due diligence from it: simplified, standard or enhanced. The score must be configurable and explainable. See our risk engine.

4. Ongoing monitoring

Due diligence applies throughout the business relationship. The software must detect what changes: a customer added to a sanctions list, a director who becomes a PEP, an expired ID, a change of beneficial owner in the register. And it must organize periodic file reviews according to risk level. See ongoing monitoring.

5. Alert and case management

An alert is only valuable if it is handled. The software must let you assign, investigate, comment on and close each alert, with a full audit trail. When a suspicion is confirmed, the analyst must have everything needed to prepare a suspicious activity report to the financial intelligence unit (Tracfin in France).

6. Audit trail and reporting

During an inspection, you must demonstrate that due diligence was carried out. The software must retain documents, check results, decisions and who made them, and let you export a complete file. It must also produce management indicators: pending files, open alerts, breakdown by risk level, overdue reviews.

AML software: selection criteria

  • Functional coverage: all six building blocks in one tool, or separate components that need to be connected?
  • Individuals and businesses: is KYB native, or an add-on?
  • Configuration without development: can you change your risk and due diligence rules yourself?
  • Screening quality: sources covered, update frequency, false positive management.
  • Customer experience: is the collection journey simple, mobile-friendly and branded?
  • Integration: API, CRM connectors, webhooks.
  • Security and hosting: data hosted in the European Union, GDPR-compliant contract, access logging.
  • AMLR readiness: does the vendor have a clear roadmap for the EU regulation?

What changes with the AMLR

On July 10, 2027, Regulation (EU) 2024/1624 replaces national transpositions of the 4th and 5th AML directives. The rules on due diligence, beneficial owner identification and record-keeping become directly applicable and harmonized across the Union, under the coordinated supervision of the new European authority, AMLA. For AML software, this concretely means: more precisely defined customer data to collect, regulated file update rules, and a greater need for traceability. Choosing a configurable tool avoids having to replace it in 2027.

Mistakes to avoid

  • Buying a screening tool and calling it an "AML solution". Screening is only one building block.
  • Hard-coding risk rules. Your classification will change; the tool must follow without an IT project.
  • Splitting KYC, KYB and AML across three tools. The file fragments, and so does your view of risk.
  • Forgetting periodic reviews. A file that was up to date at onboarding and never reviewed is a compliance breach waiting to happen.

Dataleon's AML-CFT solution

The Dataleon platform brings the building blocks of an AML-CFT framework together in a single file: collection through a white-label client portal, identity verification and document fraud detection, AML, sanctions and adverse media screening, a personalized and explainable risk score, ongoing monitoring and a complete audit trail. An AI agent prepares file reviews for your analysts. Data hosted in Europe.

FAQ

What is the difference between AML software and AML-CFT software?

None in substance: AML (anti-money laundering) is the common short form, while AML-CFT explicitly includes countering the financing of terrorism. In France, the equivalent term is LCB-FT.

Is AML software mandatory?

The law does not require a specific tool, but it does require results: identification, risk-based due diligence, screening, monitoring and traceability. Beyond low volumes, these are hard to guarantee without a tool.

Does the software file the suspicious activity report?

No. The decision to report belongs to the designated reporting officer. The software supports them by gathering the file's evidence and alert history.

Request a demo to see Dataleon's AML-CFT platform applied to your processes.

Auteur
Dataleon

Autres blogs connexes

No items found.

Frequently Asked Questions

Does Dataleon provide support?
Yes. Every client receives dedicated support, including technical assistance via email and video conferencing, comprehensive documentation, and code samples for integrating our APIs. Our engineers help you define your KYC and KYB workflows, complete the integration, and go live without service interruption. A dedicated point of contact remains available afterward to monitor your volumes, adjust your control rules, and answer your business and technical questions.
Are my files deleted after processing?
Yes. Your documents are encrypted in transit and at rest, processed, and then automatically deleted after the retention period you define. You remain the sole owner of the data transmitted: it is neither resold nor used for any purpose other than performing your checks. You can also trigger the immediate deletion of a file from the interface or via the API, keeping only the analysis results necessary for your compliance obligations.
Can Dataleon be integrated into our tools via API?
Yes. Dataleon connects to your information system via a documented REST API, real-time webhooks, and connectors for your existing tools, such as CRM, core banking, DMS, or electronic signature solutions. Verification flows, scoring rules, risk thresholds, and validation workflows are fully customizable to align with your internal procedures. Our teams can also develop custom processes if your specific use case requires it.
Can I test Dataleon before committing?
Yes. You can enjoy a 15-day free trial, with no obligation, to verify your own identity documents, proof of address, and business documents, and to evaluate the quality of our extraction and KYC/KYB checks. During these 15 days, you will have access to the interface and test API keys to validate your end-to-end technical integration. We also offer a personalized demo with an expert to help you build a workflow tailored to your business.
Are you GDPR compliant with servers located in France?
Yes. Dataleon is GDPR compliant, and all data processing and storage are carried out in France on the infrastructure of Scaleway, a sovereign French hosting provider. We implement encryption for data in transit and at rest, data minimization, granular access control, and full audit trails for all operations. A Data Processing Agreement (DPA) and our security documentation are provided to facilitate your internal and regulatory audits.

Automation that makes compliance invisible.

Dataleon, the missing link between your compliance and your growth. KYC, KYB, and AML-CFT, finally all in one place.