Skip to main content
AI Agents

Seven systems, one decision

If you have worked an alert queue, you will recognise the first half hour of a case. Very little of it is investigation.

CT

Cogentic Team

11 June 2026 · 5 min read

If you have worked an alert queue, you will recognise the first half hour of a case. Very little of it is investigation.

A transfer gets flagged. Before you can make any call on it, you need the transfer itself from the chain. The sender's KYC file. The receiving counterparty's registration status, and whether anyone has screened them recently. The sanctions and PEP results, which are with a second vendor. The customer's own history from the case system. The three similar cases from eighteen months ago, which are also in the case system, but only if you know the right search. And whatever the customer said when someone rang them, which is sitting in an inbox.

That is seven systems, and you are the thing connecting them.

Retrieval is not investigation

What tends to surprise people is how the time splits.

Very little of a case is spent weighing anything up. Most of it goes on finding, opening, copying, reformatting and cross-referencing. The judgement, once everything is genuinely in front of you, is usually quick. Plenty of experienced analysts know the answer early, then spend two hours assembling the evidence that lets them say it.

Fragmentation does not just slow that down. It makes the result worse, in three fairly specific ways.

Things get missed. Not often, and not anyone's fault, but a seven-source assembly done forty times a day will drop something eventually. Usually the source nobody thinks to check, which is usually the interesting one.

The case note becomes a reconstruction. It gets written afterwards, from what you remember looking at. That is a summary of an investigation rather than a record of one, and the difference only shows up when someone asks you to defend it two years later.

Consistency quietly erodes. Two analysts, the same alert type, different habits. One checks the counterparty's licence status and one does not, because there is no shared definition of what a complete evidence set looks like. Your procedure says what to consider. Nothing enforces what to open.

The usual answer, and why it has not worked

The instinct is to consolidate. One vendor for everything, or a data lake, or a case system that everything writes into.

The instinct is right and the project usually is not. Your screening vendor is good at screening. Your chain analytics vendor is good at chain analytics. Replacing either one to cut down on tab-switching is a large migration bought for an administrative benefit, and when a better vendor turns up you are back where you started, except now the fragmentation is contractual.

The other answer is to build the integration yourself, which works until it does not. The maintenance never ends, every vendor's API moves, and eventually the person who wrote it leaves.

What we do instead

An agent does the retrieval. It reads the systems you already have, with the access you already give your analysts, and assembles the full evidence set before anyone opens the case.

Three things about that matter more than the retrieval itself.

The evidence set is defined rather than discovered. What counts as complete for an alert type is written down, encoded from your own procedure, and applied the same way every time. The variation between two analysts on a Friday afternoon stops being a variable.

Every finding carries its source. You do not have to take the case note on trust. Each finding points at the record behind it, so you can disagree with a reading and go straight to the underlying document rather than starting again. And if a finding cannot name a source, it gets flagged, instead of sitting there looking like every other line.

It is a record, not a recollection. What was gathered, when, and from where is logged as it happens, so nobody has to write it up afterwards from memory. That turns out to matter a great deal later, which is what the third piece in this series is about.

Gaps show up in the first minute, not the third hour

One thing worth drawing out, because it is the part people do not expect.

When the evidence set is assembled against a defined standard, anything missing from it is visible immediately. A thin KYC file reads as a thin KYC file before anyone has spent an hour on the case. Where two systems disagree about a customer's address, they disagree in one place, on one page, rather than in two tabs opened an hour apart.

And where a source could not be reached at all, the case says so rather than reporting silence as a clean result. "Nothing found" and "not checked" are not the same sentence, and treating them as the same one is how a confident-looking case turns out to have a hole in it.

Problems surface earlier, which is generally when they are cheapest to do something about.

Who still decides

Somebody reads the case and makes the call. That is deliberate, and it is what the next piece is about.

The point

The bottleneck in most compliance teams is not the thinking. It is everything that has to happen before the thinking can start.

Take that away and you have not replaced anyone. You have given them back the part of the job they were hired to do.

CT

Written by

Cogentic Team

The Cogentic compliance team brings together experts in crypto regulation, AML compliance, and financial technology. We share intelligence to help VASPs navigate the complex world of Travel Rule compliance.

Related articles