RecordArc public release R21
Skip to main content

Practice Guides

Financial Crime proof-readiness checklist

A worked review using Ready, Weak, Missing, Ambiguous, and Conflicting conditions, with Missing/unverifiable kept as a separate evidence classification.

Proof-condition status matrix
  1. 01Ready
  2. 02Weak
  3. 03Missing
  4. 04Ambiguous
  5. 05Conflicting
RecordArc Editorial

In plain English

A Financial Crime record is proof-ready when each approved review dimension has an explicit question, expected and observed evidence, source authority, status, evidence classification, limitation, and next review action. The canonical dimension statuses are Ready, Weak, Missing, Ambiguous, and Conflicting. Missing/unverifiable is a separate evidence classification, and no composite readiness score is produced.

A simple example

A reviewer asks six evidence questions. Some can be answered, some are partial and one is blocked; the statuses stay separate instead of becoming a misleading readiness score.

Status and evidence classification answer different questions

A dimension status answers how the observed evidence affects one review question. Ready, Weak, Missing, Ambiguous, and Conflicting are the only canonical dimension statuses.

Missing/unverifiable classifies evidence that is unavailable or cannot be confirmed. A record-level review posture or group conclusion must be labelled separately and must not replace dimension status.

The canonical eleven-dimension registry

The checklist uses the approved repository registry rather than inventing dimensions for editorial depth.

Approved proof dimensions

Source identity and verification
Evidence lineage
Semantic mapping
Governing context linkage
Decision-time anchoring
Human-action identification
Rationale availability
Relationship completeness
Recorded outcome integrity
Reconstruction availability
Limitation disclosure

Worked illustrative use case: one Financial Crime review

An illustrative synthetic alert-review record retains source identities, transaction and customer evidence, a monitoring signal, alert, investigation actions, analyst rationale, approval, outcome, and timestamps. It is not the canonical public AML record and does not change that record's data.

The matrix below deliberately uses all five statuses to show how the registry works. Each row includes the review question, expected evidence, observed evidence, authority, status, evidence classification, limitation, and a next review action that does not prescribe a source decision.

Worked eleven-dimension matrix

Source identity and verification | Are owners known? | Expected profiles | Observed approved identities | Source systems | Ready | Source fact | Synthetic only | Confirm scope
Evidence lineage | Can values be traced? | Expected provenance | Observed complete references | RecordArc derived | Ready | RecordArc derived | Retained set only | Review exclusions
Semantic mapping | Is field meaning certified? | Expected approved mapping | One status meaning unresolved | Human owner | Ambiguous | Missing/unverifiable | Meaning cannot be inferred | Seek authorized certification
Governing context linkage | Which version applied? | Expected rule and policy versions | Rule retained, policy version absent | Policy owner | Missing | Missing/unverifiable | Applicability cannot be established | Request retained version
Decision-time anchoring | What existed then? | Expected event and decision times | Two source clocks disagree | Source systems | Conflicting | Source fact | Ordering remains disputed | Reconcile clock authority
Human-action identification | Who acted? | Expected role identifiers | Analyst and supervisor retained | Workflow owner | Ready | Source fact | Delegation not implied | Review role mapping
Rationale availability | Why was the outcome recorded? | Expected rationale | Concise rationale only | Analyst | Weak | Human-certified interpretation | Detailed notes unavailable | Record limitation
Relationship completeness | Are approved AML links present? | Expected five typed edges | One retained edge lacks source reference | RecordArc derived | Weak | Missing/unverifiable | No causal claim | Inspect provenance
Recorded outcome integrity | What did the source record? | Expected source outcome | Outcome and status retained | Workflow owner | Ready | Source-system outcome | Correctness outside scope | Preserve source reference
Reconstruction availability | Can chronology be rebuilt? | Expected retained events | All events order after clock reconciliation | RecordArc derived | Weak | RecordArc derived | Depends on documented assumption | Disclose assumption
Limitation disclosure | Are gaps explicit? | Expected limitations | One summary contradicts the detailed policy gap | Review owner | Conflicting | Missing/unverifiable | Summary cannot override evidence | Correct the summary

Synthetic example

No composite score

The matrix is useful because different dimensions can be Ready, Weak, Missing, Ambiguous, or Conflicting at the same time. A percentage would conceal which authority or evidence must be reviewed next.

  • Proof gap: decision-time policy version is Missing/unverifiable.
  • Reviewer question: can chronology be accepted while source clocks conflict?
  • RecordArc reconstructs the retained matrix; it does not remediate or redispose the alert.

What a later reviewer asks

The reviewer asks which dimensions are supported by source facts, which depend on human-certified meaning, which RecordArc-normalized or derived fields were introduced, and which gaps prevent a conclusion.

A next review action requests evidence, reconciles authority, or records a limitation. It does not recommend the source decision, assign a composite confidence score, or certify regulator readiness.

What RecordArc reconstructs and does not do

RecordArc can render the registry, retained evidence, provenance, statuses, classifications, limitations, and reviewer questions consistently.

It does not certify compliance, establish operating effectiveness, guarantee audit acceptance, create missing evidence, or prescribe an investigation or filing outcome.

Source references

  • FFIEC BSA/AML Manual: Suspicious Activity Reporting - US supervisory reference; institution-specific obligations still require qualified review. Jurisdiction: United States. Publication/update: Current online manual. RecordArc source review: August 3, 2026.
  • FATF Recommendations - International standards context; implementation and obligations vary by jurisdiction. Jurisdiction: International standard. Publication/update: Current consolidated recommendations. RecordArc source review: August 3, 2026.