Compliance flag auto-resolution
LLM agent resolves common compliance flags, such as name mismatch or address variants, by querying authoritative reference sources without human review.
Banking processAcquireOnboardOpenFundTransactServiceReviewClose
By Don, DoneThat’s AI coach · updated
Only close flags on the allow-list
The agent may auto-resolve a compliance flag only when that flag type sits on a closed allow-list you own. Every other flag stays in the analyst queue, including flags that resemble an allowed type.
Speed is the point of this control, and only for the types you named. The model does not get a mandate to be reasonable, to tidy the file, or to recast an off-list flag as an on-list one. If the type is not on the list, the agent does not close it, recommend a close, or rewrite the exception code.
Keep the list short enough that an ops lead can recite it. For retail onboarding, the useful members are formatting and transcription problems that already have a source of truth:
- Name mismatch when family name is identical and the difference is a documented class of variant: given-name order, omitted middle name, hyphenation, or a spelling variant the source itself records.
- Address variants when the named source shows the same premise and the difference is notation: Street versus St, flat or unit formatting, a directional prefix.
- Date-of-birth format differences when the source confirms the same calendar date.
Do not add sanctions hits, PEP hits, adverse-media hits, or address-not-found. Those are not formatting problems. Closing a name-mismatch flag also does not change the file's risk path. Risk-tiered onboarding routing still applies to the rest of the case.
Treat a new flag type as a control change. The owners of exception policy add it. A busy week in operations is not a reason to widen the list in the prompt.
Query a named source and write the cite
Auto-resolution is a query plus a cite, not a similarity score. The agent must retrieve a specific record from a named source, then write which record it used and why that record closes this flag.
Name the source in policy before go-live. Typical sources for this work are the identity-document extract already stored from capture, the application record in the origination system, and bureau or identity reference data from providers in the class of Experian. The agent does not browse the open web, does not ask the customer to confirm, and does not complete a missing field from general knowledge.
The cite is the audit artifact. At minimum it records:
- The flag type and the two values that raised it.
- The source name and a stable pointer: extract ID, bureau enquiry reference, or core application ID.
- The comparison rule that fired, stated as an operation (for example, middle name present on the source, initial only on the application).
- The time of the query.
If the source returns nothing, several plausible records, or a record that does not actually contain the variant, the agent leaves the flag queued. It does not invent a matching address, fill a postcode, or pick the nearest street. A composed premise is fabricated evidence. Later controls will treat it as a verified residence.
Origination and core systems in the class of Temenos still hold the application and the original flag. Case layers in the class of Salesforce still hold analyst work when a flag is not closed. The agent is not a second system of record. It writes the cite onto the flag or case so a reviewer can replay the close without reading a chat transcript.
The identity extract used as a source is the same artifact produced when you pre-populate the application from ID extraction. If that extract is missing, stale, or from a document type you do not accept, there is no query to run and the flag stays open.
Example: name mismatch against the passport extract
A UK current-account application shows the name Jonathon A. Patel. Capture has already stored a passport MRZ extract for the same session: family name PATEL, given names JONATHAN AMIT. The onboarding engine raises name_mismatch.
The allow-list includes this flag type with one named source, the passport extract from this application. Open web search is not a source. A nickname table is not a source. The allowed differences are a given-name spelling variant of the MRZ given name, and a middle name on the source versus an initial on the form, when family name is identical.
The agent reads the stored extract, confirms the family name, confirms JONATHAN versus Jonathon under the written spelling-variant rule, confirms AMIT versus A, and closes the flag. The cite states that it closed name_mismatch against passport MRZ extract [extract-id], family name identical, given name JONATHAN / Jonathon, middle AMIT / A.
That is the entire close. The agent does not re-tier the customer, skip agentic KYC orchestration, or treat the file as ready to book.
The nearby failures are the ones to train against. If the form said Jon Patel and the passport said JONATHAN AMIT PATEL, treating Jon as Jonathan is not identity proof unless Jon appears on the source. Queue it. If the same file also carried a sanctions or PEP hit on a similar name, the agent does not close that hit because the passport looks clean. Screening is not an allow-list flag.
Sanctions, invented addresses, and nicknames stay with an analyst
Never auto-resolve a sanctions hit. Name similarity to a list entry is exactly why an analyst exists. An agent that looks up a biography, compares dates of birth, and declares a false positive is running unapproved screening, not exception handling. Apply the same stop to PEP. Send those flags to the screening process you already operate, including adverse media screening when that is a separate control.
Unmatched address is the other hard stop. A variant close is allowed only when the named source already shows that premise. If the bureau file or internal address file returns nothing, or returns a different building, the agent must not compose a likely address from the postcode, a maps hint, or the customer's free text. Inventing a match writes a false residence into the file.
Nickname matching fails the same test. Bob for Robert, Liz for Elizabeth, or Mike for Michael is social usage, not a source. The allow-list may include a nickname only when the named record itself stores both forms. If the source shows only the legal name, the flag stays queued.
Do not partially close a clustered alert. If the model resolves the friendly name-mismatch, leaves the sanctions component for a human, and thins the file, the analyst sees a cleaner picture than the evidence supports. If any constituent flag is off-list, the cluster stays queued.
If you want to add fuzzy address or nickname-equals-legal-name because analysts already close most of those items, you are changing the control. Analysts can reject a bad suggestion. An auto-close cannot.
Keep the allow-list reviewable after go-live
Sample auto-closes the way you sample analyst closes. Confirm the source pointer still resolves, and confirm the rule on the list is the rule the agent applied. A cite that is only a paragraph of rationale, with no pointer, fails the sample.
Do not grow the list because the model is confident. Confidence is not a source. KYC exception-policy owners decide whether a new variant class is low-risk enough to auto-close. Engineering implements the query and the cite schema. Operations reports which queued types consume time. Neither group widens the list alone.
When work spans an origination or core system (Temenos-class), a case layer (Salesforce-class), and bureau or identity reference data (Experian-class), keep one allow-list and one cite schema. Duplicate lists per vendor drift. The flag type, the source, and the cite should mean the same thing wherever the analyst opens the file.
Is this worth automating for you?
Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.
DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.
Measure the baseline first