Your monitoring vendor fires the alert. Everything after it — pulling account context, checking it against the KYC profile, resolving on-chain counterparties, and writing a narrative that survives examination — still costs your team four to eight hours per case.
Novaheim builds the AI systems that do that work. Every determination cites its source. Your officer signs every one.
Every engagement starts with a paid three-week diagnostic: a measured baseline of your alert volume, false positive rate, and hours per case — delivered as an assessment you can keep in the exam file, before any build begins.
BSA/AML · OFAC · FinCEN · FATF Travel Rule · GENIUS Act · FINTRAC · FCA / MLR 2017 · EU AMLR · State MTLThe alert is the cheap part.
A decade of vendor spend went into detection. The cost never lived there — it lives in the hours after the alert fires, and it scales with every customer you add.
One report ties up a senior analyst for most of a day, at $350–700 fully loaded. SAR work consumes 30–40% of a mid-market compliance team’s total hours.
Observed range across mid-market programs. BPI’s 2024 survey of 15 large banks reports 21.4 hours per SAR, against FinCEN’s 1.98-hour Paperwork Reduction Act estimate.
Analysts spend their days clearing noise. Tuning alone won’t fix it — the fragmented data underneath the detection logic is what keeps regenerating the alerts.
Bank Policy Institute, Getting to Effectiveness (2018): 19 institutions reviewed ~16 million alerts and filed ~640,000 SARs.
Every corporate customer is a file that has to be rebuilt on a refresh cycle. Ongoing review — not onboarding — is where regulators find the failures.
Fenergo’s 2023 survey of 1,100+ banking executives puts the average commercial KYC review at $2,598.
No extensions. When alert volume outruns team capacity, the backlog isn’t an efficiency problem. It’s a finding in an exam report.
31 CFR 1020.320(b)(3). Thirty further days only where no suspect is identified — never beyond 60.
Novaheim clears the work that doesn’t need judgment — assembling the evidence, resolving the counterparties, drafting the narrative — so your analysts spend their hours on the cases that do.
Every step leaves an audit trail. Every determination cites its source. Your officer makes the call, exactly as they do today.
Each system is built for your workflows, your regulatory environment, and the tools you already run. Fiat rails and on-chain, in the same case file.
Automated triage of AML alerts and exceptions across every rail your customers use. The system clears the noise your analysts shouldn’t touch and escalates real risk with the reasoning attached.
Four phases, each with a concrete deliverable and an exit ramp at every stage.
Thirty minutes on your compliance operation — alert volume, where the hours concentrate, how long a case takes from determination to filing, and what your next exam looks like. You leave knowing whether there’s a fit and exactly what the diagnostic would cover. No pitch deck, no obligation.
A paid three-week independent assessment of your AML operations. Structured interviews with your compliance function, a full review of your alert and case workflow, and a measured baseline most firms have never had — actual alert volume, actual false positive rate by rule, actual hours per case, and which thresholds have documented rationale.
Delivered as a dated, sourced assessment you can keep in the exam file, ending in a fixed-scope implementation proposal. 50% credits toward the build if it commences within 90 days.
One workflow, built in your environment, around the tools you already run. Measured against the baseline from the diagnostic. Ships with documentation, training, and a model validation pack your model risk function can review. Your team owns it completely.
Optional ongoing operation: model and prompt version control, quarterly evaluation runs delivered as evidence for your file, and updates to the reasoning layer when the rules move. You own the system either way — if you’d rather run it in-house, I’ll document handover and step away.
| Novaheim | Generic AI Agency | Hire an Analyst | Off-the-Shelf Tool | Do Nothing | |
|---|---|---|---|---|---|
| Covers fiat rails and on-chain | ✓ | ✕ | ~ | ✕ | ✕ |
| Understands BSA, OFAC, FinCEN, Travel Rule, AMLR | ✓ | ✕ | ✓ | ~ | ✕ |
| Audit trail on every determination | ✓ | ✕ | ~ | ~ | ✕ |
| Runs in your environment, you own it | ✓ | ~ | ✓ | ✕ | ✕ |
| Built around your existing tools | ✓ | ~ | ✓ | ✕ | ✕ |
| First workflow in production, measured against your baseline | ✓ | ✕ | ✕ | ~ | ✕ |
| Adoption support in scope | ✓ | ~ | ✓ | ✕ | ✕ |
| Available in-house full time | ✕ | ✕ | ✓ | ✓ | ✕ |
| Cost model | Scoped projects | Hourly burn | $150K+ salary | $2–5K/mo + gaps | Mounting risk |
An analyst understands the regulation; the question is whether one more analyst clears the backlog inside the 30-day window.
Every system integrates with the tools your team already uses. No new platforms to learn. No rip-and-replace.















I build the systems that handle what happens after the alert fires.
My background is statistics and applied analytics — seven years measuring model performance, false positive rates, and where automated systems fail. That discipline is what AML programs need and rarely have: monitoring stacks get tuned on intuition, and few teams can show an examiner why a threshold sits where it does.
I work across BSA/AML, OFAC, FATF Travel Rule, and the GENIUS Act stablecoin rules, and I read chains directly rather than relying on a vendor’s attribution. Most compliance stacks see the fiat leg and go blind at the chain boundary. That gap is why Novaheim exists.
Thirty minutes on your compliance operation — alert volume, false positive rate, where the hours concentrate, and what your next exam or audit looks like.
If there’s a fit, the next step is a paid three-week Compliance Automation Diagnostic: structured interviews, a full workflow review, and a measured baseline of where your program actually stands. No generic pitch deck. No obligation.
A paid three-week independent assessment of your AML operations, delivered as a dated, sourced document you can keep in the exam file.
It produces something most firms have never had: a measured baseline. Not estimates — actual alert volume, actual false positive rate by rule, actual hours per case, actual time from determination to filing, and a clear statement of which thresholds have documented rationale and which don’t.
It ends in a fixed-scope, fixed-price implementation proposal, so there’s no second discovery process. 50% credits toward the build if you proceed within 90 days.
Some firms take the assessment and act on it internally. That’s a legitimate outcome, and the reason it’s priced as real work rather than as a sales step.
Both — because under US law they’re frequently the same thing. A licensed payment company and a digital asset platform typically register with FinCEN as MSBs, run BSA/AML programs against the same pillars, and file SARs under the same 30-day deadline. What differs is the data.
Most compliance stacks handle fiat transaction data well and go blind at the chain boundary. We work across both — which matters more every quarter, as stablecoin flows land in companies that were never built to investigate them.
Into your environment, and nowhere else. Systems run in your cloud tenancy. Models are accessed through AWS Bedrock or Azure OpenAI inside that tenancy — customer data is not sent to third-party model providers and is not retained for training. We document the full data flow before any build begins, in a form your sponsor bank’s third-party risk review can evaluate directly.
The April 2026 interagency guidance that replaced SR 11-7 — SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026 — puts generative and agentic AI outside its scope, with a request for information still to come. Your model risk function has an open question and no supervisory answer yet, so we document against the framework you already run.
Every system ships with a validation pack: model inventory entry, documented intended use and limitations, the evaluation methodology and results against your own case set, prompt and model version control, and a change log that triggers revalidation when either moves.
This matters more than it sounds. A managed AI vendor can update its model without telling you — leaving your validation covering a version you’re no longer running. Systems built here are model-agnostic and run in your environment, so your MRM function controls the version and the change cycle.
To be explicit about independence: this documentation is first-line evidence for your independent validation function to review. It is not a substitute for independent validation.
Every system is built for your firm — not a shared platform, not a generic tool with your logo on it. It runs in your environment, integrates with the tools you already use, and ships with full documentation and training. Your team owns it completely. No platform subscription, no lock-in.
Every determination the system produces cites its source, and every step leaves an audit trail. Filing decisions stay with your BSA Officer, documented exactly as they are today.
No. You own the system outright — the code, the configuration, the documentation. That doesn’t change and there’s no platform subscription.
What’s optional is whether I keep operating it. Models get deprecated, prompts need retuning, regulations move, and your evaluation evidence needs refreshing for the file. Most firms would rather I handle that than build the capability in-house. If you’d rather take it over, I’ll document handover and step away.
Minimal. After the first call, we handle the technical work. Most builds require 3–5 hours of your team’s time across a few weeks for workflow input and review. You stay focused on your product and your users. We come to you only when a decision requires your judgment.
We measure against your baseline from day one, so ROI is concrete rather than claimed. The diagnostic establishes that baseline — alert volume, false-positive rate, hours per case, time-to-file — before anything is built. Most firms have never measured these, which is why the diagnostic is useful whether or not you continue with us.
The common wins show up within the first month: fewer false positives reaching analysts, faster case throughput, and shorter time from determination to filing.
Most AI tools fail for one of two reasons: they solve the wrong problem, or nobody adopts them. We avoid the first by starting with a specific workflow that’s already costing you measurable hours. We avoid the second by building around how your team actually works — and staying through adoption before we step away.
The deeper reason off-the-shelf tools underperform here is that they sit on top of fragmented data. Detection quality is limited by what the system can see, and most stacks can’t see across fiat and on-chain in the same case. That’s the layer we build.
Primarily US. We take selected engagements in English-operating markets where we can read every artifact the system produces — including the UK, Ireland, Canada, and much of EU fintech, where compliance functions run in English.
If your filing language isn’t English, we’ll tell you on the first call rather than three weeks in. In that case we can still build triage, KYB review, screening adjudication, and on-chain context — everything except regulator-facing narrative drafting.
When alert volume outruns team capacity, the 30-day clock doesn’t move. Let’s find the workflow costing you the most and build the system that clears it — with an audit trail on every determination.
Get in touch