Insights
Perspective

Manual vs. evidence-backed AML: why screenshots fail the audit

The gap between asserting a control works and proving it did, and what 'evidence-backed' actually means for AML and KYC.

CardinalGRC·June 2026·7 min read

Most AML evidence is a screenshot taken once a quarter. It shows that, on one day, a screen looked a certain way. It says nothing about the other eighty-nine days, and increasingly, that's the thing an examiner wants to know.

The problem with a screenshot

A screenshot has three weaknesses that compound. It has no provenance: nothing ties it to the system that produced it. It has no freshness: by the time it's filed it describes the past. And it has no continuity: it proves a moment, not a control operating over a period. Stack a year of them in a folder and you still can't answer the simplest supervisory question: was this control working the whole time?

The spectrum of evidence

Evidence for an AML control sits on a spectrum, and most programmes are further left than they think:

  • Manual attestation. Someone says the control is in place. Cheap, and worth roughly what it costs.
  • Automated collection. The platform pulls evidence from the source system on a schedule. Better: it has provenance and a timestamp, but still a periodic snapshot.
  • Live evidence. The control's own execution is the evidence: the actual screening calls, verification outcomes and monitoring signals, captured continuously with a provenance-stamped, tamper-evident trail.

The trap: activity is not effectiveness

Here is the nuance most vendors skip. A log proving your sanctions-screening engine ran is evidence that the detection layer fired. It is not evidence that a hit was adjudicated, escalated, or reported. An examiner who knows the difference will ask for both, and a feed of API calls that implies “continuously compliant” will not survive that question.

The honest design is therefore hybrid: use live evidence for the detection layer, where the system genuinely produces the proof, and attest the human disposition, where judgment is applied. Claiming a control is “continuously satisfied” from API logs alone is exactly the kind of overstatement supervisors have started to treat as a finding in its own right.

What to do now

You don't need to leap to fully live evidence overnight. You need to move off screenshots and toward provenance:

  • Replace point-in-time screenshots with evidence that carries a source, a timestamp and a validity window.
  • Separate, explicitly, the detection evidence from the disposition evidence, and capture both.
  • Make sure whatever you produce is exportable and verifiable by an outside party without taking it on faith.
  • Be conservative in what you claim. “Here is the screening event, and here is how it was adjudicated” beats “our AML is fully automated” every time.
The goal isn't a prettier dashboard. It's the ability to say, with a trail to back it: this control ran, here's the proof, and here's what we did about what it found.

That's the difference between manual and evidence-backed AML, and it's the difference between describing your programme and being able to defend it.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.