The first question every compliance procurement team asks about AI-drafted SARs is the right one: who signs, and what happens to liability when a model generates the narrative? The answer is non-negotiable, and it's the same answer for every vendor that wants to be enterprise-ready: the MLRO signs, always; the model drafts, never files.
This piece walks the reporter-of-record model — what it is, why it's load-bearing, and the audit infrastructure that makes the model stand up under examiner review.
The model
Three rules. They are constraints, not preferences.
- MLRO is always the named reporter. On every SAR, every SMR, every STR. The cryptographic signature is the legal instrument. The AI never carries the legal weight. This is built into the product as a hard constraint, not a configurable default.
- The reasonable-grounds judgement stays human. AML legislation across major regimes — AUSTRAC, FinCEN, FCA, MAS — assigns the reasonable-grounds determination to a named human officer. The AI presents evidence and a recommendation. The officer makes the determination. Drafting is delegable. Determination is not.
- Cryptographic signature binds to content. The MLRO's signature hashes the entire SAR content. Any post-signature edit invalidates the binding. Examiners can verify integrity independently, without vendor system access. This is the technical instrument that makes the legal model auditable.
Why it's load-bearing
Procurement teams ask this question first because the answer determines whether the rest of the diligence pack is worth reading. If the vendor's product can submit autonomously, every other question — citation discipline, model governance, audit infrastructure — is moot. The reporter-of-record question is the gate.
It's also the question that protects the MLRO personally. MLRO liability under AUSTRAC, FinCEN BSA, UK Money Laundering Regulations, and equivalent regimes elsewhere is personal. The MLRO is named on the SAR. The MLRO is the one regulators interview when something fails. A vendor model that diffuses signing across the AI is asking the MLRO to accept liability for a process they don't control. No serious MLRO accepts that.
The audit infrastructure
The reporter-of-record model needs three pieces of infrastructure to actually stand up. Without these, it's a marketing line.
Immutable evidence ledger
Every agent invocation, every MLRO override, every disposition, every signature event, every policy change — appended to an immutable, cryptographically attestable ledger. Append-only. Removals are detectable through the Merkle chain. Reconstructing a six-month-old case produces bit-identical evidence to the original.
Citation chain to source data
Every claim in a SAR narrative cites the source row it derives from — a specific Chainalysis trace, a specific Sumsub tier-change, a specific Snowflake row. The MLRO can drill into any citation in the review interface. Examiners can drill into any citation post-signature. The narrative is not detached from the underlying evidence.
Independent signature verification
The signature uses standard cryptographic primitives with public verification keys. An examiner with the signed SAR and the public key verifies integrity independently — no vendor system access required. This matters because vendors fail. Lock-in to a vendor for audit defensibility is itself an audit risk.
What examiners actually look for
We've walked the model with compliance officers, audit consultants, and legal teams across three jurisdictions. The convergence on what examiners care about is consistent.
Process integrity
Was the SAR drafted from evidence? Did the MLRO review the evidence before signing? Did the MLRO override the AI's recommendation, and if so why? The answers are all in the audit ledger and surface in the evidence pack export.
Model accountability
Which model drafted this SAR? What was its training disclosure? What were its known failure modes at the time of drafting? Who validated the model? SR 11-7 documentation, produced by default, addresses this directly.
Reasonable-grounds determination
Was the reasonable-grounds judgement made by a named human? Did that human have access to the underlying evidence? Did they sign cryptographically? The reporter-of-record model is the answer; the signature binding is the proof.
Where this fails
Two failure modes to design against.
Rubber-stamp signing
If the MLRO signs every draft without reviewing the evidence, the model collapses to autonomous filing in spirit if not in form. Override rates are tracked precisely to detect rubber-stamping — an MLRO with a 0% override rate is a signal, not a feature. Healthy override rates run 5–15% in mature deployments.
Off-platform signature
If the MLRO signs in DocuSign or a separate workflow instead of cryptographically inside the platform, the binding to content hash is lost. Edits post-signature are undetectable. Insist on in-platform cryptographic signature, not third-party document signing for SARs.
How to evaluate
Take to a vendor conversation:
- Ask the vendor to draft a SAR live, then ask the MLRO present to sign it
- Ask to see the cryptographic signature and verify it independently
- Ask for the SR 11-7 documentation for the model that drafted
- Ask to drill into a citation — pick any sentence, ask which row of evidence it derives from
- Ask to reconstruct a six-month-old SAR from the audit ledger
If the vendor passes those five tests, the reporter-of-record model is real. If they hand-wave on any of them, walk away.
How Cogentic implements this
MLRO signs every SAR cryptographically. The signature binds to the SAR content hash. Any post-signature edit invalidates the binding — examiners verify integrity independently using public keys. Cogentic never files autonomously. SR 11-7 documentation produced by default. Override rates tracked and surfaced for evaluation. Citation chain to source data on every narrative claim. Bit-identical reconstruction at any point inside the 7-year retention window.
It's not the only way to build defensible AI-augmented compliance. But it's the model we'll defend in any procurement conversation, in any examiner conversation, in any model-risk review.