Most AML evidence is a screenshot taken once a quarter. It shows that, on one day, a screen looked a certain way. It says nothing about the other eighty-nine days, and increasingly, that's the thing an examiner wants to know.
The problem with a screenshot
A screenshot has three weaknesses that compound. It has no provenance: nothing ties it to the system that produced it. It has no freshness: by the time it's filed it describes the past. And it has no continuity: it proves a moment, not a control operating over a period. Stack a year of them in a folder and you still can't answer the simplest supervisory question: was this control working the whole time?
The spectrum of evidence
Evidence for an AML control sits on a spectrum, and most programmes are further left than they think:
- Manual attestation. Someone says the control is in place. Cheap, and worth roughly what it costs.
- Automated collection. The platform pulls evidence from the source system on a schedule. Better: it has provenance and a timestamp, but still a periodic snapshot.
- Live evidence. The control's own execution is the evidence: the actual screening calls, verification outcomes and monitoring signals, captured continuously with a provenance-stamped, tamper-evident trail.
The trap: activity is not effectiveness
Here is the nuance most vendors skip. A log proving your sanctions-screening engine ran is evidence that the detection layer fired. It is not evidence that a hit was adjudicated, escalated, or reported. An examiner who knows the difference will ask for both, and a feed of API calls that implies “continuously compliant” will not survive that question.
The honest design is therefore hybrid: use live evidence for the detection layer, where the system genuinely produces the proof, and attest the human disposition, where judgment is applied. Claiming a control is “continuously satisfied” from API logs alone is exactly the kind of overstatement supervisors have started to treat as a finding in its own right.
What to do now
You don't need to leap to fully live evidence overnight. You need to move off screenshots and toward provenance:
- Replace point-in-time screenshots with evidence that carries a source, a timestamp and a validity window.
- Separate, explicitly, the detection evidence from the disposition evidence, and capture both.
- Make sure whatever you produce is exportable and verifiable by an outside party without taking it on faith.
- Be conservative in what you claim. “Here is the screening event, and here is how it was adjudicated” beats “our AML is fully automated” every time.
The goal isn't a prettier dashboard. It's the ability to say, with a trail to back it: this control ran, here's the proof, and here's what we did about what it found.
That's the difference between manual and evidence-backed AML, and it's the difference between describing your programme and being able to defend it.