AI compliance operations · Licensed fintechs & digital asset firms

Your compliance stack detects. It doesn’t investigate.

Your monitoring vendor fires the alert. Everything after it — pulling account context, checking it against the KYC profile, resolving on-chain counterparties, and writing a narrative that survives examination — still costs your team four to eight hours per case.

Novaheim builds the AI systems that do that work. Every determination cites its source. Your officer signs every one.

BSA/AMLOFACFinCENFATF Travel RuleGENIUS ActFINTRACFCA / MLR 2017EU AMLRState MTL
The bottleneck

The alert is the cheap part.

A decade of vendor spend went into detection. The cost never lived there — it lives in the hours after the alert fires, and it scales with every customer you add.

4–8 hoursper SAR filedOne report ties up a senior analyst for most of a day, at $350–700 fully loaded. SAR work consumes 30–40% of a mid-market compliance team’s total hours.Observed range across mid-market programs. BPI’s 2024 survey of 15 large banks reports 21.4 hours per SAR, against FinCEN’s 1.98-hour Paperwork Reduction Act estimate.
92–97%AML false-positive rateAnalysts spend their days clearing noise. Tuning alone won’t fix it — the fragmented data underneath the detection logic is what keeps regenerating the alerts.Bank Policy Institute, Getting to Effectiveness (2018): 19 institutions reviewed ~16 million alerts and filed ~640,000 SARs.
$1,500–$3,500per KYB reviewEvery corporate customer is a file that has to be rebuilt on a refresh cycle. Ongoing review — not onboarding — is where regulators find the failures.Fenergo’s 2023 survey of 1,100+ banking executives puts the average commercial KYC review at $2,598.
30 daysfrom determination to filingNo extensions. When alert volume outruns team capacity, the backlog isn’t an efficiency problem. It’s a finding in an exam report.31 CFR 1020.320(b)(3). Thirty further days only where no suspect is identified — never beyond 60.

Novaheim clears the work that doesn’t need judgment — assembling the evidence, resolving the counterparties, drafting the narrative — so your analysts spend their hours on the cases that do.

Every step leaves an audit trail. Every determination cites its source. Your officer makes the call, exactly as they do today.

What we build

AI compliance systems for licensed fintechs and digital asset firms

Each system is built for your workflows, your regulatory environment, and the tools you already run. Fiat rails and on-chain, in the same case file.

Automated triage of AML alerts across every rail your customers use. The system clears noise your analysts shouldn’t touch and escalates real risk with the reasoning attached.

  • Cuts the 92–97% false-positive load before intake
  • Escalates with documented rationale, not just a score
  • Resolves on-chain counterparty context inline
  • Every disposition leaves an audit trail

The four to eight hours between a confirmed alert and a filed SAR, compressed. The system assembles the case file and drafts the narrative, every assertion cited to source.

  • Analysts open a complete case file, not a blank one
  • Drafted to FinCEN structure, every fact traceable
  • On-chain activity explained in examiner language
  • Your BSA Officer reviews, decides, and signs

Periodic review is where examiners find failures, and at most firms it still runs over email. The system rebuilds the file and diffs it against last cycle.

  • Ownership traversal to UBOs, every source recorded
  • Surfaces only what changed since the last review
  • Screens every entity against sanctions and PEP lists
  • Turns a multi-week cycle into a reviewable file

An always-on agent that answers policy questions from your own documented controls. The answer your team gets is the one in your program, not a guess.

  • Grounded in your policies and prior determinations
  • Cites the source control for every answer
  • Onboards new analysts in days, not months
  • Flags where your program is silent, never invents

Regulatory change monitoring, exam evidence assembly, vendor KYB, and compliance reporting. Each runs as a fixed-price project with a defined deliverable and a date it lands.

  • Fixed scope, fixed timeline, fixed price
  • Built around the tools you already run
  • Delivered with documentation and training
  • You own it — no subscription, no lock-in
How we work

A process built to de-risk the first step.

Four phases, each with a concrete deliverable and an exit ramp at every stage.

1Discovery Callduration 30 minobligation none

Thirty minutes on your compliance operation — alert volume, where the hours concentrate, how long a case takes from determination to filing, and what your next exam looks like. You leave knowing whether there’s a fit and exactly what the diagnostic would cover. No pitch deck, no obligation.

2Diagnosticduration 3 weekscredited 50%

A paid three-week independent assessment of your AML operations. Structured interviews with your compliance function, a full review of your alert and case workflow, and a measured baseline most firms have never had — actual alert volume, actual false positive rate by rule, actual hours per case, and which thresholds have documented rationale.

Delivered as a dated, sourced assessment you can keep in the exam file, ending in a fixed-scope implementation proposal. 50% credits toward the build if it commences within 90 days.

3Buildscope one workflowduration 6–12 weeks

One workflow, built in your environment, around the tools you already run. Measured against the baseline from the diagnostic. Ships with documentation, training, and a model validation pack your model risk function can review. Your team owns it completely.

4Operatecadence quarterlyterm annualcode ownership yours

A system in production needs evidence that stays current. Models get deprecated, prompts get retuned, and rules move — each one dates the validation your MRM function signed off on. Quarterly, we re-run the evaluation against your case set, version the changes, and deliver the results as a dated artifact for your file. When a regulation shifts, the reasoning layer shifts with it, documented.

Most firms keep this in place because rebuilding the capability in-house costs more than it saves. You own the system outright either way — the retainer buys the evidence cycle, not access to your own code.

Your alternatives

How we compare

Covers fiat rails and on-chainUnderstands BSA, OFAC, FinCEN, Travel Rule, AMLRAudit trail on every determinationRuns in your environment, you own itBuilt around your existing toolsFirst workflow in production, measured against your baselineAdoption support in scopeEvidence refreshed on a documented cycleRunning in production this monthCost model
NovaheimScoped projects
Generic AI AgencyHourly burn
Hire an Analyst$150K+ salary
Off-the-Shelf Tool$2–5K/mo + gaps
Do NothingMounting risk

An analyst understands the regulation; the question is whether one more analyst clears the backlog inside the 30-day window.

Fits your firm

Connects to your existing stack

Every system integrates with the tools your team already uses. No new platforms to learn. No rip-and-replace.

  • ComplyAdvantage
  • Alloy
  • Persona
  • TRM Labs
  • Chainalysis
  • Notabene
  • Elliptic
  • Unit
  • Synctera
  • Treasury Prime
  • Ethereum
  • Solana
  • Avalanche
  • Alchemy
  • Etherscan
  • The Graph
  • OpenZeppelin
  • Snowflake
  • Supabase
  • Qdrant
  • AWS
  • Azure
Bradley Behan
About

Meet the founder

I build the systems that handle what happens after the alert fires.

My background is statistics and applied analytics — seven years measuring model performance, false positive rates, and where automated systems fail. That discipline is what AML programs need and rarely have: monitoring stacks get tuned on intuition, and few teams can show an examiner why a threshold sits where it does.

I work across BSA/AML, OFAC, FATF Travel Rule, and the GENIUS Act stablecoin rules, and I read chains directly rather than relying on a vendor’s attribution. Most compliance stacks see the fiat leg and go blind at the chain boundary. That gap is why Novaheim exists.

Bradley BehanFounderLinkedIn
FAQ

Frequently asked questions

If your question isn’t here, a discovery call is thirty minutes and costs nothing.

Engagement & process

Thirty minutes on your compliance operation — alert volume, false positive rate, where the hours concentrate, and what your next exam or audit looks like.

If there’s a fit, the next step is a paid three-week Compliance Automation Diagnostic: structured interviews, a full workflow review, and a measured baseline of where your program actually stands. No generic pitch deck. No obligation.

A paid three-week independent assessment of your AML operations, delivered as a dated, sourced document you can keep in the exam file.

It produces something most firms have never had: a measured baseline. Not estimates — actual alert volume, actual false positive rate by rule, actual hours per case, actual time from determination to filing, and a clear statement of which thresholds have documented rationale and which don’t.

It ends in a fixed-scope, fixed-price implementation proposal, so there’s no second discovery process. 50% credits toward the build if you proceed within 90 days.

Some firms take the assessment and act on it internally. That’s a legitimate outcome, and the reason it’s priced as real work rather than as a sales step.

Minimal. After the first call, we handle the technical work. Most builds require 3–5 hours of your team’s time across a few weeks for workflow input and review. You stay focused on your product and your users. We come to you only when a decision requires your judgment.

Primarily US. We take selected engagements in English-operating markets where we can read every artifact the system produces — including the UK, Ireland, Canada, and much of EU fintech, where compliance functions run in English.

If your filing language isn’t English, we’ll tell you on the first call rather than three weeks in. In that case we can still build triage, KYB review, screening adjudication, and on-chain context — everything except regulator-facing narrative drafting.

Data, security & model risk

Into your environment, and nowhere else. Systems run in your cloud tenancy. Models are accessed through AWS Bedrock or Azure OpenAI inside that tenancy — customer data is not sent to third-party model providers and is not retained for training. We document the full data flow before any build begins, in a form your sponsor bank’s third-party risk review can evaluate directly.

The April 2026 interagency guidance that replaced SR 11-7 — SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026 — puts generative and agentic AI outside its scope, with a request for information still to come. Your model risk function has an open question and no supervisory answer yet, so we document against the framework you already run.

Every system ships with a validation pack: model inventory entry, documented intended use and limitations, the evaluation methodology and results against your own case set, prompt and model version control, and a change log that triggers revalidation when either moves.

This matters more than it sounds. A managed AI vendor can update its model without telling you — leaving your validation covering a version you’re no longer running. Systems built here are model-agnostic and run in your environment, so your MRM function controls the version and the change cycle.

To be explicit about independence: this documentation is first-line evidence for your independent validation function to review. It is not a substitute for independent validation.

Every system is built for your firm — not a shared platform, not a generic tool with your logo on it. It runs in your environment, integrates with the tools you already use, and ships with full documentation and training. Your team owns it completely. No platform subscription, no lock-in.

Every determination the system produces cites its source, and every step leaves an audit trail. Filing decisions stay with your BSA Officer, documented exactly as they are today.

Fit & commercials

Both — because under US law they’re frequently the same thing. A licensed payment company and a digital asset platform typically register with FinCEN as MSBs, run BSA/AML programs against the same pillars, and file SARs under the same 30-day deadline. What differs is the data.

Most compliance stacks handle fiat transaction data well and go blind at the chain boundary. We work across both — which matters more every quarter, as stablecoin flows land in companies that were never built to investigate them.

You own the system outright — the code, the configuration, the documentation. That doesn’t change, and there’s no platform subscription. What’s ongoing is the evidence cycle: quarterly evaluation runs, prompt and model version control, and updates when the rules move. Most firms keep that in place rather than build the capability in-house. If you’d rather take it over, I’ll document handover and step away.

We measure against your baseline from day one, so ROI is concrete rather than claimed. The diagnostic establishes that baseline — alert volume, false-positive rate, hours per case, time-to-file — before anything is built. Most firms have never measured these, which is why the diagnostic is useful whether or not you continue with us.

The common wins show up within the first month: fewer false positives reaching analysts, faster case throughput, and shorter time from determination to filing.

Most AI tools fail for one of two reasons: they solve the wrong problem, or nobody adopts them. We avoid the first by starting with a specific workflow that’s already costing you measurable hours. We avoid the second by building around how your team actually works — and staying through adoption before we step away.

The deeper reason off-the-shelf tools underperform here is that they sit on top of fragmented data. Detection quality is limited by what the system can see, and most stacks can’t see across fiat and on-chain in the same case. That’s the layer we build.

Ready to start?

The backlog isn’t an efficiency problem. It’s a finding.

When alert volume outruns team capacity, the 30-day clock doesn’t move. Let’s find the workflow costing you the most and build the system that clears it — with an audit trail on every determination.