KYC & relationship
Customer file, beneficial owners, declared source of funds, expected activity, prior dispositions and every open alert on the relationship.
18 records
Transaction monitoring generates alerts that are 90–98% false positives. Heelius runs the full L1/L2 investigation, reaches a disposition, and writes the narrative a regulator will read. Your analysts review escalations and a QA sample.
NO RIP-AND-REPLACE · SITS ON YOUR EXISTING TM SYSTEM
ALT-2026-88104 · Marcus D. Oyelaran · structuring
INVESTIGATINGInvestigation trace
0s elapsed
Narrative draft
Evidence
—
Citations
—
Cost
—
Escalation matrix armed · 3 gates monitored
The investigation
Heelius does not summarise an alert. It performs the investigation — retrieving the same records an L2 analyst would pull, in the same sequence, and showing its work at every step.
Customer file, beneficial owners, declared source of funds, expected activity, prior dispositions and every open alert on the relationship.
18 records
The alerted window plus a trailing twelve-month baseline, tested for threshold proximity, velocity, round-value patterning and pass-through.
347 txns
Entity resolution out to three hops. Shared devices, common funding addresses, sequential registrations and circular flow between nominally unrelated parties.
3 hops
Consolidated list screening with discriminator logic — the agent states which identifiers diverge, and never clears on a name mismatch alone.
4 lists
42 languages, deduplicated by event, each candidate tested for homonym risk against date of birth, employer and biography.
1,840 articles
Aggravating and mitigating findings scored against the institution's own thresholds. Unresolvable evidence routes to a human — it is never rounded to clear.
8 findings
Six sections in the conventional order — subject, activity, findings, mitigants, screening, disposition — with a source citation on every asserted fact.
6 sections
Every assertion is traced back to a retrieved record before the case is released. Unsupported prose fails the check and is redrafted.
100% traced
Narrative engine
Narratives are assembled from retrieved records, not written from a summary. Every asserted fact carries the record it came from — so an examiner can walk any sentence back to the ledger it was drawn from.
Retrieved evidence
Unsupported prose fails self-QA and is redrafted before release
Generated narrative · ALT-2026-88104
Activity under review
Alert ALT-2026-88104 was generated by rule TM-STR-004 covering eight transactions totalling 46,300 USD through the retail deposit channel between 20 and 25 August 2026. Five cash deposits ranging from 8,900 to 9,600 USD were placed across three distinct branches, none reaching the 10,000 USD currency-transaction reporting thresholdF-1F-2. The alerted volume represents 1.2× the customer’s declared monthly expectation of 40,000 USDF-3.
Findings
Within 72 hours of the final deposit, 34,000 USD was remitted to a Brazilian construction counterparty against an invoice reference that matches the supplier recorded at onboardingF-4. Sanctions screening returned a single 0.71 fuzzy candidate, discounted on a 14-year date-of-birth divergence and a non-matching jurisdiction under the institution’s two-discriminator ruleF-5.
Model architecture
A language model alone cannot pass a model-risk review. Heelius separates retrieval, graph inference, scoring and generation into four governed layers, so each one can be evaluated, versioned and challenged on its own terms.
Typed connectors to your core, TM system, KYC store, card and wallet ledgers. Retrieval is deterministic and replayable — the same alert pulls the same records a year later, which is what makes a case defensible on examination.
A learned linkage model resolves counterparties across devices, addresses, registrations and payment references, then extracts network features — circularity, fan-in/fan-out asymmetry, cluster co-registration, hop distance to known typologies.
Findings are scored as aggravating or mitigating against your institution's own thresholds, not a vendor default. The score is calibrated, so a stated 75% confidence means the disposition holds roughly 75 times out of 100 on held-out reviewed cases.
Language generation is confined to composing retrieved facts. A verification pass re-checks each assertion against source records and rejects any sentence that cannot be grounded — the failure mode is a blank section, never an invented one.
Evaluation · held-out adjudicated set
n = 41,200 · refreshed quarterly · champion/challenger
Every model version ships with a model card, a documented evaluation protocol and a challenger held in parallel. Drift on population stability, disposition mix and QA concurrence is monitored per typology and per corridor, with automatic reversion to human routing when a segment moves outside its control band.
Where the model has to change
Legacy investigation tooling assumes a correspondent bank's data model and a Western analyst's budget. Both assumptions break in the places where alert volume is growing fastest.
Operators in Nairobi, Lagos, Dhaka and Manila carry the same FATF obligations as a tier-1 bank on a fraction of the compliance budget — and alert volumes that scale with subscriber counts, not revenue. Heelius investigates agent float velocity, SIM-cluster co-registration, device overlap between nominally independent tills and cross-border corridor anomalies.
Chain analytics tells you an address is risky. It does not tell you whether your customer's use of it is suspicious. Heelius joins on-chain attribution to the fiat side of the relationship — bridge structuring below travel-rule thresholds, unhosted-wallet exposure, mixer hop distance, related-party settlement back to a registered UBO.
Deployed against
The economics
No seat licences and no platform minimum. You pay for investigations completed, which means the saving is legible to a CFO on the first invoice.
Annualised
$8,100,288
net saving against a fully staffed L1/L2 function
analyst-equivalents of investigation capacity, redeployed to escalations and quality assurance
Assumes 42-minute median handling time and a $47 fully-loaded hourly analyst cost
Send a month of closed alerts. Heelius re-investigates them blind and you compare its dispositions and narratives against what your team actually filed. No integration required for the benchmark.