Daniel Chaves
Back to blog

Compliance

Central Bank compliance in practice: KYC and AML as part of the architecture

January 27, 20262 min read

Compliance is often treated as a "later" module — something bolted onto the architecture once the product is already done. In financial institutions, that approach gets expensive: rework, scattered data and slow onboarding.

KYC as part of the flow, not a standalone step

A customer's registration should feed the risk engine continuously, not just at account opening. Behavioral changes — volume, frequency, counterparties — need to automatically reclassify the customer's risk level.

Real-time transaction monitoring

AML rules that run in an overnight batch arrive too late for PIX. The architecture needs to evaluate every transaction on the critical path — or, when that isn't viable due to latency, within a window of seconds after settlement, with the ability to block and reverse (via MED) where applicable.

Reporting that doesn't turn into manual exceptions

Reports to the financial intelligence unit and other regulatory obligations should be generated from the same detection rules that feed monitoring — avoiding a situation where the compliance team maintains a parallel, divergent logic in spreadsheets.

Compliance as an internal product

Treating compliance as an internal product — with its own API, response SLAs and observability — is what lets it scale alongside the business, instead of becoming the reason onboarding takes days.