Scenarios · Risk & onboarding

KYC memos drafted by AI, decided by your analyst, provable to your examiner.

A risk team at a broker-dealer works onboarding cases from one review queue: the case documents land, the AI drafts the due-diligence memo from the file, and an analyst edits, approves, or escalates. Every step — the inputs, the AI draft, the analyst's decision — lands on a signed record. When an examiner asks how a decision was made and what the AI contributed, the firm hands over an export the examiner can verify independently.

What changes for your team: onboarding reviews move at the analyst's pace instead of the paperwork's — and "walk me through this decision" becomes an export you already hold, not a reconstruction from inboxes and shared drives.

Where the work happens

  • Studio — the onboarding review queue is an internal app your team describes and HASP builds: cases, documents, screening results, and statuses as plain records.
  • Assistant — drafts the KYC/CDD memo from the case file, citing the documents it drew on, with client data handled under your firm's data terms.
  • Audit & Trust — the signed export and published verification recipe an examiner runs on their own machine.

How it works

  1. Every onboarding case lands in one review queue.

    Identity documents, account paperwork, and screening results arrive as records in a Studio-built queue — one place per case, with statuses your team defines. No documents scattered across inboxes, no side spreadsheet tracking which case is with whom.

  2. The AI drafts the due-diligence memo from the case file.

    Assistant compiles the case documents and screening results into a structured KYC/CDD memo — what was reviewed, what was found, what remains open — citing the file it drew on. Client data goes to the model under your firm's data terms, and the request and response are recorded like every other action on the platform.

  3. Your analyst decides — and the decision is recorded.

    The draft is a starting point, not an outcome. The analyst edits the memo, resolves or escalates open items, and approves the case. Who approved, which memo version, and what changed between the AI's draft and the final text all land on the signed record — the human decision is on the trail, not implied by it.

  4. The examiner's question gets a verifiable answer.

    "How was this decision made, and what did the AI contribute?" is answered with an export: the case inputs, the AI draft, the analyst's edits, and the approval, each signed into a tamper-evident record. The examiner re-runs the published verification recipe on their own workstation — no access request, no vendor in the room.


Why this survives governance

  • Recordkeeping rules expect records that can't be quietly rewritten.

    SEC Rule 17a-4 requires broker-dealers to preserve electronic records either write-once or on a system that can recreate the original if a record is modified or deleted — and to furnish records to examiners in a reasonably usable electronic format. An append-only record preserves the original alongside every change, and an altered export fails verification instead of passing quietly — the properties the rule's audit-trail alternative is after.

  • Supervision obligations apply to AI with no carve-out.

    FINRA Rule 3110 requires a supervisory system reasonably designed for the firm's business, and FINRA has been explicit that existing supervision and recordkeeping obligations apply fully when AI tools enter the workflow. An AI-drafted memo with no record of human review is a supervision gap; a recorded analyst approval on every case is the evidence that supervision actually happened.

  • "What did the AI contribute?" can't be answered from memory.

    When the question comes — from an examiner, internal audit, or a customer dispute — the record distinguishes the AI's draft from the analyst's edits from the final approval, step by step. That's a signed trail the firm exports, not a narrative someone assembles after the fact and asks the examiner to accept.

Deploy this workflow in your environment.

Talk to us → Built for financial services → See Audit & Trust → Verification recipe →