Skip to content
Bankautomation

Compliance workflow automation that an auditor can follow

A compliance workflow is only worth automating if the automation makes the control stronger. Speed alone is not the point. Reproducibility is.

Run the demo

camt.053 · NOSTRO USD · value date 03 sep 2026

Nostro cash break, sample data

Match rate

75.0%

Breaks

4

At risk

$533.9k

Oldest

4d

Date ±1d
Amount

This console matches the first rows a side. It left out statement and ledger , so anything in them is not counted below. To run a full file, .

BRK-001

Aged 0d

$219,105.40

2026-09-03 · both sides

REF//FX/SPOT/7741 · INTERBANK FX DESK

Amount differs by 164.80 USD (0.075%)

Re-price the ledger leg on the correspondent rate source for the value date and post 164.80 USD to FX variance.

FX RATE SOURCE

→ Treasury Ops

BRK-002

Aged 4d

$187,650.00

2026-08-30 · ledger

PAY/90012/R · KESTREL LOGISTICS

Second ledger entry for 187,650.00 USD against REF//PAY/90012

Confirm the original entry REF//PAY/90012 cleared, then reverse this posting under maker-checker and note the reversal on the original item.

DUPLICATE POSTING

→ Finance

BRK-003

Aged 0d

$123,760.00

2026-09-03 · both sides

REF//TRF/554121 · HALCYON TRADING

Statement 61,880.00 vs ledger 123,760.00 (50% short)

Split the ledger posting and match the settled leg; leave the residual 61,880.00 USD open against the same reference.

PARTIAL SETTLEMENT

→ Payments Ops

BRK-004

Aged 0d

$3,410.00

2026-09-03 · statement

REF//CHG/Q3FEES · CORRESPONDENT CHARGES

On the statement, nothing in the ledger

Post 3,410.00 USD to the charges account for the period and add it to the standing accrual so it stops surfacing as a break.

FEE NOT ACCRUED

→ Finance

Everything matched under these tolerances.

Tighten the date or amount tolerance to see the breaks it was absorbing.

Correspondent statement

camt.053 · NOSTRO USD

Value date Reference Amount
2026-09-02 REF//NONREF/2026090301 1,284,500.00
2026-09-02 REF//INV/88231 96,400.00
2026-09-03 REF//TRF/554120 452,180.25
2026-09-03 REF//FX/SPOT/7741 218,940.60
2026-09-01 REF//SEPA/33421 74,220.00
2026-09-03 REF//CHG/Q3FEES 3,410.00
2026-09-03 REF//TRF/554121 61,880.00
2026-09-02 REF//PAY/90012 187,650.00
2026-09-02 REF//INV/88245 242,015.00
2026-09-03 REF//TRF/554133 18,905.50
2026-09-01 REF//PAY/90044 505,300.00
2026-09-03 REF//INV/88260 132,640.75

Internal nostro ledger

Core banking export

Value date Reference Amount
2026-09-02 NONREF/2026090301 1,284,500.00
2026-09-02 INV/88231 96,400.00
2026-09-03 TRF/554120 452,180.25
2026-09-03 FX/SPOT/7741 219,105.40
2026-08-31 SEPA/33421 74,220.00
2026-09-02 PAY/90012 187,650.00
2026-09-03 TRF/554121 123,760.00
2026-08-30 PAY/90012/R 187,650.00
2026-09-02 INV/88245 242,015.00
2026-09-03 TRF/554133 18,905.50
2026-09-01 PAY/90044 505,300.00
2026-09-03 INV/88260 132,640.75
Matched pairs are tinted on both sides. Breaks carry the brass left rule and appear in the worklist.

Sample data only. Matching runs in your browser; classification is written by the model when you press Run. Matching done in your browser. Writing classifications… Classifications written by the model on this run. Decision support, not a compliance determination. The classification model was unavailable, so the built-in rule classifier wrote these. Same matching, same numbers. This console classifies up to 12 runs a minute and this run went over, so the built-in rule classifier wrote these. Same matching, same numbers. Wait a minute for the model, or . The model wrote the first 8 classifications; the rule classifier wrote the remaining .

Open the full resolver

Three properties that separate a control from a task list

  • Separation of duties. The person who proposes an action is not the person who approves it, and the system refuses to let them be.
  • Versioned rules. The rule that applied when the item was worked is recorded on the item, not inferred from today's configuration.
  • Complete evidence at the time of work. Attachments and rationale are collected while the item is open, not reconstructed at quarter end.

Where maker-checker belongs

ActionMakerChecker
Write off an unmatched item Operations analyst Team lead, with a reason code
Reverse a duplicate posting Operations analyst Second analyst or lead
Change a matching tolerance Process owner Head of operations
Change a routing target Process owner Head of the receiving team
Dispose of a compliance case Analyst Compliance reviewer
Certify an account Preparer Reviewer, never the preparer

Swipe the table sideways to read every column.

SLAs that mean something

An SLA on a compliance queue is only useful if breaching it is visible before the breach matters. Bankautomation ages every item from the event that started it, not from when someone opened it, and escalation is a state change rather than an email somebody might read.

The evidence pack

For a period and a scope, the export contains the items, their classifications, every action with its actor and timestamp, the approvals, the attachments and the rule versions in force. It is one action because assembling evidence by hand is exactly the work that makes teams cut corners under pressure.

Designing an approval chain that people will not route around

Every control that is more painful than the work it governs gets bypassed, usually with good intentions and a plausible reason. An approval chain that survives contact with a busy month end has three properties: it is proportionate to the risk of the action, the approver has enough context to decide without asking questions, and the path for a genuine emergency exists and is recorded rather than improvised.

  1. 01Scale the chain to the action. A write-off of a small item and a change to a matching tolerance are not the same risk and should not require the same number of approvals.
  2. 02Give the approver the case. An approval request that shows only an amount will be approved on trust. One that carries the item, its history, the proposed action and the reason gets a real decision.
  3. 03Make the emergency path real. A documented break glass route, with a mandatory reason and an automatic post-event review, is safer than a chain nobody can satisfy at 11pm.
  4. 04Escalate on time, not on memory. An approval that sits unactioned should escalate by itself, because a queue that depends on somebody remembering is not a control.

Segregation of duties, in the system rather than the procedure

Most policies state that the proposer and the approver must differ. Whether that holds in practice depends entirely on whether it is enforced by software or by a sentence in a document. The system version is unambiguous: the approve action is not available to the person who proposed, regardless of their permissions, and the attempt is logged. The procedural version depends on a busy person choosing correctly under deadline pressure, which is a weaker control than it appears in a policy review.

Role design supports this and is worth doing carefully once. Preparer, reviewer, approver and read only, scoped by account, entity and process line, covers the overwhelming majority of cases. The temptation to create bespoke roles per team produces a permission model nobody can explain, which becomes its own audit finding.

Age, SLA and breach are three different numbers

MechanismWhat it measuresWhat it should trigger
Age Time since the event that started the clock Visibility, always, on the first screen
SLA threshold Age against an agreed target for that item type Escalation before the breach, not after
Breach Target exceeded A recorded exception with an owner and a reason
Backlog trend Population age distribution over time A capacity or process conversation, not an individual one

Swipe the table sideways to read every column.

The distinction that matters is between age and SLA. Age is a fact about an item. An SLA is a promise about a class of item. Reporting only breaches hides a population that is aging steadily inside its target and will breach together, which is the failure mode that surprises people.

One vocabulary across two floors

Operations and compliance are usually run as separate worlds with separate tools, and the work has the same shape in both: an item that needs a decision, an owner, an age, a required evidence set and an approval. Running both on one vocabulary has practical effects beyond tidiness. A team lead can read either queue without translation. Reporting to a risk committee aggregates rather than being assembled. And a control improvement made on one floor is immediately available on the other, instead of being rebuilt.

What to automate first

Start with the action that carries the most risk and the least structure today, which in most banks is either a write-off or a tolerance change. Both are usually approved by email. Moving one of them into an enforced chain with a reason code and a versioned record takes very little configuration and changes what an auditor finds. Once that pattern exists, extending it to the rest of the action list is repetition rather than design.

The same mechanics run reconciliation exceptions, which is why the operations floor and the compliance floor can share one vocabulary. See exception management for the engine and security and compliance for the control detail.

Questions about compliance workflow automation

Can approval chains have more than two steps?

Yes, chains are configured per action type and can depend on amount, account or risk. The constraint the system enforces is that a person cannot approve their own proposal.

What if we need a break glass path?

Emergency actions can be permitted for named roles, and every use is flagged, logged and surfaced in a report specifically so it can be reviewed rather than quietly relied on.

Does automation weaken our control environment?

It changes where the control lives. A tolerance applied by a person 200 times a day is not a control, it is a habit. The same tolerance, approved and versioned, applied consistently and reported on, is one.

Can we model our own workflow states?

Queues, states, required evidence and approval chains are configuration. What is not configurable is the ability to switch off the audit trail.

More banking automation pages

Every process line we cover, in one place.

Account reconciliation software Where the differences start, account by account. Bank reconciliation software Statement against ledger, MT940 and camt.053 native. Automated reconciliation software Match rates, tolerances, and what auto-match must never mean. Payment reconciliation software Instructed, settled and posted, reconciled three ways. Financial reconciliation software The same engine, framed for the finance team. ATM reconciliation software Cash, switch and network settlement, balanced daily. Credit union reconciliation software Corporate, share draft, card, ATM and shared branching. ACH reconciliation software Origination, receipt, returns and FedACH settlement. Federal Reserve account reconciliation Master account, FIRD, Fedwire and FedNow against the GL. Correspondent bank reconciliation Due from, due to and respondent settlement against the GL. AML compliance software Program workflow, evidence and cadence. Not a detection model. KYC automation software Onboarding and periodic refresh, queued and evidenced. AML software for banks What to ask, and what to refuse to buy. BSA AML monitoring software Alert triage as a worklist, not a second inbox. RPA for banks Why screen-scraping bots break, and what replaces them. General ledger reconciliation software Sub-ledger to GL, and the suspense account nobody owns. Balance sheet reconciliation software Certification, sign-off and the quarter-end pack. ISO 20022 payment automation Structured data, repair rates and CBPR+ deadlines. Nostro reconciliation automation The most bank-specific reconciliation there is.

Get started

Put your first reconciliation on rails

Create an account, and we will email you how onboarding works and what a first source connection looks like. The Reconciliation Break Resolver is open to try right now, on sample data, without an account.

Run the demo

No card required to create an account. Sample data only in the demo. Bankautomation is operations software, not a regulated service.