AML/KYC & Transaction Monitoring on AWS — 10-Week FFIEC/FinCEN Build
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Stand up a FinCEN/FFIEC-ready AML/KYC and transaction monitoring platform on AWS in 10 weeks — not 10 months — with a BSA-Officer-in-the-loop workflow from day one.
Kriv AI's 10-week deployment stands up Amazon Neptune, Redshift, SageMaker, Bedrock (with Guardrails), Lake Formation, CloudTrail, and S3 Object Lock as a cohesive AML/KYC stack inside your AWS account. We deploy, validate, and hand over operations with a documented runbook, a model inventory, an alert-triage workflow, a Neptune-backed UBO graph, and SAR narrative drafts that always pass through documented human review by your BSA Officer or designated compliance reviewer.
Show the rest of the publisher’s description (15 more lines)
Why banks, credit unions, MSBs, fintechs, and crypto exchanges engage Kriv AI
AML enforcement is a top US financial regulatory priority.TD Bank's $3.1B 2024 BSA settlement, Binance's $4.3B 2023 resolution, and Wells Fargo consent-order cycles have pushed regulators, boards, and correspondent banks to demand visible, documented, defensible transaction monitoring.FinCEN AML/CFT Rule (2026), CIP/CDD/BO requirements, FFIEC BSA/AML Manual, and OFAC 50% Rule raise the bar. Legacy vendors (Verafin, Oracle FCCM, NICE Actimize, SAS, Fiserv) run 12–24 month implementations at license prices small institutions can't justify.
What we deploy
Amazon Neptune UBO & network graph — entities, related parties, beneficial owners, shared addresses / devices, shell-company indicators, OFAC 50% Rule traversal
SageMaker behavioral monitoring — peer-group baselining, structuring / smurfing signals, unusual wire / ACH patterns, cash-intensive-business typologies, TBML, correspondent anomaly scoring
KYC / CDD / EDD orchestration wrapping Customer's existing licensed vendor (Alloy, Socure, Persona, Jumio, LexisNexis, ComplyAdvantage, Dow Jones); licensed vendor remains system-of-record
Bedrock agents with Guardrails — alert-triage summaries, investigator-assist narratives, SAR narrative drafts, disposition memos. Every output routes through BSA-Officer approval — drafts are evidence, not filings; Kriv files nothing.
Redshift AML data warehouse — transactions, accounts, parties, alerts, cases, sanctions hits, KYC history; lookback + tuning + exam-response analytics
Lake Formation row + column-level access for PII, EDD subjects, jurisdiction segmentation
CloudTrail + S3 Object Lock (WORM) governance trail — immutable capture of model invocations, overrides, dispositions, SAR-draft review, FFIEC retention
QuickSight dashboards — Alert Volume + Tuning, Case Aging, Sanctions Hit Rate, Model Drift, AML Governance Evidence
Governance artifacts — AML model inventory, tuning + lookback templates, SAR-quality review, BSA/AML risk-assessment scaffolding, vendor AI policy stub
10-week engagement. Weeks 1–2 Design (NDA, OFAC inventory, prior-exam review, Neptune UBO schema, FFIEC/FinCEN control map). Weeks 3–5 Build (core-banking + card + ACH + wire + crypto feeds → Redshift; Neptune UBO ingest; KYC vendor integration; SageMaker + Bedrock with BSA-Officer review gating). Weeks 6–7 Evals + tuning (above-the-line / below-the-line templates, sanctions hit-rate calibration, model cards, analyst UAT, SAR-narrative review). Weeks 8–9 Cutover prep + shadow-mode pilot. Week 10 Cutover.
Three tiers. Starter $95K (1 core feed; UBO on existing CDD; 2 pipelines; 2 agents; 1 KYC vendor; v1 governance) — community banks $500M–$2B, CUs, single-product MSBs, early-stage fintechs. Professional $175K (2 feeds; UBO + related-party; 4 pipelines; 4 agents; 2 KYC vendors; v2 governance + tuning/lookback) — community banks $2B–$10B, BaaS sponsors, mid-stage crypto. Enterprise $275K (3 feeds; full UBO + OFAC 50% + shell indicators; 6 pipelines; 5 agents; multi-tenant Lake Formation; correspondent view; full pack + model cards; 3 KYC vendors; 30-day hypercare) — regional banks, large CUs, established crypto exchanges. Optional Additional Core Feed $25K each. EDP-eligible — AML/KYC platform engagement fees ($95K–$275K) count toward your AWS Enterprise Discount Program commitment (up to 25%). AWS infrastructure (Neptune, Redshift, SageMaker, Bedrock, Lake Formation, S3) billed separately. Contact info@kriv.ai to structure a private offer against your EDP or PPA.
Important disclosures. AWS infrastructure billed separately. Kriv is not a bank, credit union, MSB, money transmitter, broker-dealer, trust company, BaaS operator, VASP, or crypto exchange; holds no banking/MSB/VASP license and is not registered with FinCEN. Kriv files no SARs, CTRs, Form 8300, 314(a)/(b) responses, or any FinCEN/OFAC/IRS/state/foreign filings. BSA Officer retains sole filing authority; Bedrock outputs require BSA-Officer approval. Kriv does not replace licensed KYC/sanctions vendors. CTA BOI reporting remains with reporting companies and counsel. No FinCEN/FFIEC/OFAC certification exists. Customer retains all data, filings, regulator communications, and operational responsibility post-handover. Not legal, regulatory, tax, compliance, or investment advice.
Highlights
Highlighted by the publisher on AWS Marketplace.
10-week AWS-native AML/KYC build — Neptune UBO graph + SageMaker + Bedrock SAR drafting with BSA-Officer review enforced. Neptune entities, related parties, beneficial owners, shared addresses/devices, shell-company indicators, and OFAC 50% Rule traversal. Six SageMaker pipelines (behavioral monitoring, structuring, sanctions-triage, correspondent/trade-based, plus more on Enterprise) with model registry + drift + tuning evidence. Five Bedrock agents covering alert-triage and SAR drafts.
FFIEC/FinCEN/OFAC-aligned governance evidence pack — Kriv files nothing; BSA Officer retains sole filing authority. Aligned to FinCEN's final AML/CFT Program Rule (effective Jan 1, 2026), FFIEC BSA/AML Examination Manual, OFAC 50% Rule, CDD/CIP. Deliverables: model inventory, tuning + lookback templates, SAR-quality review template, BSA/AML risk-assessment scaffolding, vendor AI policy stub. Wraps Customer's licensed KYC/sanctions vendor — Kriv replaces no vendor.
AWS Select + Databricks + Anthropic CPN partner — white space: no AWS-native AML + UBO graph + Bedrock SKU today. Three tiers: Starter $95K (1 core feed; community bank $500M–$2B, single-product MSB, early-stage fintech); Professional $175K (2 feeds; community bank $2B–$10B, fintech BaaS, mid-stage crypto); Enterprise $275K (3 feeds + OFAC 50% traversal + multi-tenant Lake Formation + correspondent view + 30-day hypercare; regional banks, established exchanges, top BaaS).
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

