LONDON -
Thursday, 10. September 2026
(GLOBE NEWSWIRE) -- Shufti, the Glocal identity verification and
full compliance lifecycle provider, announced the launch of Transaction
Trust Monitoring (TTM), an agentic FRAML engine that carries a case
from the first suspicious transaction through investigation to a
regulator-ready report, in one workflow.
TTM scores each transaction against the identity Shufti verified
at onboarding. It then routes alerts through a role-gated investigation
process and generates a report in the format required by the Financial
Intelligence Unit for the Money Laundering Reporting Officer to review
and approve. It integrates with existing KYC and case management systems rather than replacing them.
FRAML brings
fraud and anti-money laundering controls into a single discipline. In
TTM, both sets of signals are scored in the same pass, so a pattern
spanning both typologies is assessed once against one customer record.
Where Transaction Trust Monitoring Differs
- Unifies KYC and KYT on one in-house stack: Identity
verification at onboarding and ongoing transaction monitoring run on a
single platform Shufti owns end-to-end, with no acquired modules and no
third-party stitching, so each customer carries one risk score and one
audit trail.
- Identity-to-transaction continuity: Each transaction is scored against a biometrically verified customer, with deepfake and synthetic identity defences at onboarding, and behavioural biometrics and device fingerprinting after login, all inform that score.
- Screening depth behind every decision: More than 4,000 watchlists and
6M+ PEPs with sanctions coverage across OFAC, OFSI, EU CFSP, DFAT and
the UN Consolidated List, and multilingual contextual adverse media.
- 1,600+ data points per transaction, scored in under 500ms: Every
transaction is checked against location, device, banking, and threshold
data, plus more than 15 velocity checks running from one minute to 180
days, and comes back with one risk score from 0 to 100.
- AI explainability, audit-ready at every step: Every alert carries a case summary, a tier classification, a false-positive assessment, and a recommended next action.
- AI rule Builder, live now: Describe
a rule in plain language, and Shufti builds it, calibrated by industry,
regulation, and risk appetite, then backtests it against 90 days of
history to show projected alert volume, precision, and fraud caught by
value.
- Alerts routed by score under role-based control: Scores
of 75 and above go to the MLRO, 50 to 74 to L2 investigation, and 25 to
49 to L1 triage, each stage carrying its own service level. Flagged
transactions can be placed on a soft hold and sent to an analyst queue
for review rather than being automatically declined.
- MLRO authorisation on every filing: The AI triage co-pilot drafts narratives and recommends actions and does not execute a filing itself.
- Built-in controls on every rule and every alert: Twenty-four
ABSOLUTE rules always trigger and cannot be suppressed. Every decision
is held on a five-year immutable audit trail, and unscoreable
transactions return a NOT ASSESSABLE verdict.
Watch the video below to see how Transaction Trust Monitoring works in practice.
https://www.youtube.com/watch?v=G-beTCoCK54
In addition to all, behaviour is also measured against each
customer's own pattern, using a rolling 90-day baseline across 16
dimensions, while linked devices, IP addresses and contact details
expose multi-accounting and money mule networks.
Four AI agents are live across the lifecycle, with three more
covering rule recommendation, data readiness and regulatory change
monitoring in development. MCP integration allows external AI tools to drive a firm's monitoring setup.
"Compliance teams are covering more jurisdictions
and more volume without proportionate headcount, and the work that does
not scale sits after the alert," said Frayam Asif, Chief Technology Officer at Shufti.
"We designed TTM where agents score fraud and AML risk inside the
payment path, with checks completing before settlement and an analyst
opens a case that is already prepared. For our clients, that means less
time assembling a case and more time deciding on it, with no added
friction for the customer."
Reporting closes the workflow. Suspicious activity and suspicious
transaction reports are generated in the regulator's native XML,
including FinCEN BSA XML 2.0 for United States reporting and goAML, the
UNODC schema used by Financial Intelligence Units across Europe, the
Middle East, Africa and Asia Pacific. The MLRO reviews, edits, and
authorises each report, after which the firm downloads and submits the
file with no manual XML assembly or re-keying.
Each filing is logged, with case data, analyst notes, and score
explanations available for examination. Threshold reports are
obligation-based rather than suspicion-based, so they auto-batch daily
under a deadline timer, with the MLRO retaining oversight and able to
pause any batch.
The TTM launch is featured in the Shufti
Innovation Drop, offering a closer look at its capabilities through a
live product demonstration. Watch the full Transaction Trust Monitoring demo here.
Availability
TTM is available now to banks and financial institutions, payment
service providers, remittance businesses and MSBs, fintechs and
neobanks, virtual asset service providers and iGaming operators, over a
RESTful API and SDK, with sandbox access and on-premise deployment.
Detection covers SWIFT and SEPA flows, cumulative player history,
corridor and agent-level monitoring, and wallet screening, on-chain risk
scoring, and Travel Rule support on the same engine as fiat, across 240 countries and territories.
Transaction Monitoring Software can
be configured as a standalone solution or as part of the complete
Shufti compliance lifecycle, from onboarding through ongoing monitoring.
Shufti has also published A Guide to Risk-Aligned Transaction Monitoring, which
sets out the FATF requirements for monitoring, the five principles the
HKMA recommended for selecting a system, and the framework changing
under Regulation (EU) 2024/1624 from July 2027.
Read the guide to understand what risk-aligned transaction monitoring looks like in practice. Or contact the Shufti team to request a demo.
About Shufti
Shufti is a Glocal full compliance lifecycle platform,
managing compliance from sign-up and onboarding through authentication,
monitoring, and remediation. Shufti is the first provider in Europe to
achieve iBeta Level 3 conformance for
presentation attack detection, and holds PCI DSS, SOC 2 Type II, and
ISO 27001:2022. It ranks first on G2 for identity verification and AML,
with more than 40 badges across global and regional markets.
Follow Shufti on LinkedIn and YouTube for the latest news and updates.
Media Contact
Aroosa Virk
Brand and Communications Manager
Shufti
partnership@shuftipro.com