• International universal banks and private banks

Case study 2025

Anti-money laundering when every control must be evidenced

How international universal banks and private banks made their transaction monitoring audit-ready and manageable again

By SIMO GmbH

  • 70MTransactions a day
  • 6 hrsProcessing
  • 16 monthsData history
Jump to what prompted the engagement

What prompted the engagement and the supervisory framework

Supervisors expect an effective control system against financial crime: transaction monitoring that works, sound procedures for customer due diligence, traceable audit evidence, and documented internal safeguards. The existing setup could no longer produce that evidence to the required depth.

  • Risk-based monitoring

    Risk-based rather than blanket monitoring, supported by rule-based scenarios and machine-learning models.

  • A sound basis for decisions

    Reliable data and tested procedures as the precondition for controls that hold up under supervisory review.

  • Complete evidence

    Full documentation of all requirements, thresholds, settings, and changes, verifiable at any time.

Against that background, the task was to put transaction monitoring on a new footing and, at the same time, to build a processing basis that meets these requirements permanently and at the required speed.

Advisory work and delivery supervision

  1. Clarifying requirements between compliance, the business units, and IT

    Building and maintaining a binding reference for business, supervisory, and technical requirements. It brought together the customer due diligence requirements, the monitoring scenarios including thresholds, the data quality indicators, the requirements for evidence, and the analysis views for the business units.

    • agreed in workshops with compliance, the business units, and IT
  2. Business architecture and processing basis

    Establishing a processing chain that makes more than 70 million transactions with 16 months of history available daily within 6 hours. A complete view of the previous day’s activity was therefore available before the business day began, not after it. The chain ran on the cloud platform the institution had already standardized on, and the tools in use, among them Google Cloud Platform, BigQuery, and SparkSQL, followed the requirement rather than the other way around.

    • a complete view of the previous day available before the business day begins
    • provable origin for every record
  3. Securing the basis for decisions

    Continuous checks on the completeness, consistency, and integrity of the data sets, with alerts on any deviation. In addition, targeted ad hoc analyses bridged infrastructure outages without losing the ability to report.

    • deviations are detected before they become reportable
  4. Operations, support, and enablement

    Operation of the processing chain with continuous optimization. Support for the business units in tuning the monitoring rules, to reduce false positives and direct investigator capacity at the relevant cases. Enablement of internal staff so that the institution can take ownership of operations itself.

    • the knowledge stayed in house

Tools used, in service of the requirement

  • Processing large data sets

    Data sets at petabyte scale had to be available so that analysis could keep pace with the business day. The institution’s cloud platform carried this load with BigQuery, Cloud Storage, SparkSQL, and Hadoop.

  • Business integration

    Bringing data together across system boundaries that had grown over time, so that compliance, the business units, and management work from the same basis. The existing database landscapes, among them Oracle and Microsoft SQL Server, stayed in operation.

  • Regulatory control

    Rule sets for anti-money laundering and customer due diligence, implemented in NICE Actimize SAM and STAR.

  • Analysis and management reporting

    Analysis views for the business units and for management, supported by Looker, SQL Developer, and the institution’s own reporting tools.

Triggers and advisory approach

  • Trigger

    70 million transactions a day, with a complete view of the previous day required before business opens

    Advisory approach

    processing restructured and parallelized, history extended to 16 months

  • Trigger

    compliance, the business units, and IT pursued different objectives

    Advisory approach

    one binding reference, shared prioritization, and early analysis views

  • Trigger

    investigator capacity tied up by false positives

    Advisory approach

    thresholds and scenarios recalibrated, anomalies weighted by risk

  • Trigger

    dependence on external knowledge

    Advisory approach

    enablement of the internal teams and support during ongoing operations

Client feedback

We do not disclose client names for reasons of confidentiality. At SIMO GmbH, the trust of our clients is a core principle.

  • SIMO GmbH put our transaction monitoring on a new footing. Our compliance department was able to direct its capacity at the relevant cases.

    Chief Compliance OfficerInternational universal bank
  • Excellent, both technically and to work with. Detection quality is well above that of our previous systems. Ongoing monitoring has run reliably since go-live.

    Head of Financial Crime PreventionPrivate bank, operating nationwide
  • SIMO’s supervisory experience was decisive for us. The newly established transaction monitoring meets BaFin’s requirements and is designed for the European rules to come.

    Head of ComplianceInternational universal bank
  • What counts most for us is that every report we file today is properly justified and traceable.

    Senior Risk ManagerPrivate bank

Impact on the institution

  • a complete view with 16 months of history available in 6 hours
  • investigator capacity directed at the cases that actually matter
  • a processing basis that grows with the business
  • evidence that withstands a supervisory examination
  • control remains with the institution, not with the advisor

The case shows what enterprise business data strategy delivers in a regulated environment: a control function that does not merely exist on paper but works every day. What mattered was not the technology in use but clarity on accountability, requirements, and evidence between compliance, the business units, and IT.

SIMO GmbH roles on the engagement

  • Business Data Management Team Lead
  • Data Manager
  • Data Scientist
  • Data Quality Manager
  • Project Manager
  • Product Owner

How our articles are created and who is accountable for them is set out in our editorial standards.

Next step

Is your control function under audit pressure?

Let’s find out whether your evidence holds up when it counts and where it has gaps.

Book an initial call

45 minutes, by video, free of charge.

Start the check

How ready is your decision? Check it in 3 minutes.

Call +49 6021 625 63 40