KYC/AML & Financial Crime
9 pieces from Duczer East's practitioners on the architecture behind financial-crime compliance: sanctions and stablecoin rules read as system requirements, graph-based AML, document evidence, and the data foundations an examiner will test.
What this topic is about
Financial-crime compliance has always been a data problem wearing a legal one. The rules say who must be identified, what must be monitored and what must be reported. The institution's systems decide whether any of that can actually be done — whether beneficial ownership can be resolved across entities, whether a document's provenance survives ingestion, whether a decision made last quarter can be reconstructed with the data that was available at the time.
The pieces in this collection approach KYC/AML from that side. Some take a regulatory event — a sanctions authorization, Treasury's stablecoin rule — and read it as a system specification: which decisions land on the architect's desk rather than the compliance officer's, and where the implementation clock will actually be spent. Others work through the platform question directly: why graph-based entity resolution is becoming the center of AML architecture, what it takes for an AI agent to defend a decision made from a scanned record, and why the next examination finding is likely to be about the meaning of the data rather than the model.
Governance of the agents themselves — identity, permissions, and what SR 26-2 left with the bank when it carved agentic AI out of model-risk guidance — is a topic of its own. That work is collected in Agentic AI Governance & Model Risk.
Start here
The architecture argument: financial-crime controls that hold up under examination are built on data foundations, not rules.
-
Why Knowledge Graphs Are Becoming the Center of Gravity in AML Architecture
Entity resolution, relationship inference and monitoring converge on the graph. What that means for the platform underneath.
8 min read -
Your Agents Can Read the PDF. They Cannot Defend It.
Turning a financial record into structured, trustworthy data is the handoff most institutions have not designed.
6 min read -
Semantic Coherence Is the KYC Control Examiners Will Ask About Next
Why agentic KYC deployments will fail examination for reasons the model-risk framework was not built to catch.
4 min read
Sanctions, stablecoins and the rule as a spec
Regulatory events of 2026 read as compliance documents. Read again as an architect, each one is a system design requirement with a clock on it.
-
Iran Sanctions Relief Lasted Sixteen Days. Compliance Records Last Forever.
A short-lived authorization, and the burden of proving what the institution knew and when.
4 min read -
The Hidden Capex in Treasury's Stablecoin Rule
For the CFO and compliance lead: the rule turns a compliance question into a capital one on a twelve-month timer.
4 min read -
The GENIUS Act Just Became an Architecture Problem
Primary versus secondary market is a system boundary. Freeze-and-control on an open network is a control plane.
6 min read
Notes from the field
Shorter reads on developments worth knowing about.
-
Rethinking LLMOps for Fraud and AML
Compliance inference is a different serving workload from generation, and most stacks are tuned for the wrong one.
3 min read -
When Process Breaks Down, Fraud Finds a Way
Eight years of undetected loss because the controls were watching the wrong things.
3 min read -
Your AI Governance Chart Has One Name on It in Court
Courts are signalling that the deploying bank, not the vendor, owns the liability when AI causes harm.
3 min read
KYC/AML built on data your examiners can trace
Duczer East designs and builds the entity-resolution, monitoring and evidence architecture behind financial-crime compliance — on governed data inside your perimeter, with the audit trail that makes each decision defensible.