A statutory MLRO substrate,
firewalled from the rest of your compliance estate.
The MLRO Console gives the named officer (and deputy) a confidential workspace for internal SARs — separate RLS, no AI indexing, tipping-off banners on every screen, hash-chained decision log, and FIU external-report markers. Board reporting receives aggregate counts only.
Triage queue with three SLA clocks
- SAR-DEMO-001Cash structuring · Saltire FiduciaryAck overdue · +6h
- SAR-DEMO-002PEP linkage · Saltire TrustFIU consideration overdue
- SAR-DEMO-003Adverse media · Saltire WealthCase open · decision today
- SAR-DEMO-004Sanctioned counterparty hitExternal report due +4d
Why this matters: SLA pressure is visible the moment the MLRO logs in. The 24-hour acknowledgement leg is automated via the sar-ack email template. Once a SAR is triaged, the "initial FIU consideration overdue" tile drops it — clocks reflect actual decisions.
Case workspace + hash-chained decision log
Why this matters: Every decision carries its rationale and a hash link to the previous entry. The contemporaneous record the supervisor expects — without a "trust me" attachment anywhere in the chain.
FIU external-report marker (existence + reference only)
Why this matters: RegAlign records that you reported, when, and the FIU reference. It deliberately does not store the report body — the FIU's own system remains authoritative, and your substrate stays minimal.
Board pack receives aggregates only
Themes for the period: adverse-media spikes (4), structuring patterns (3), sanctions-screening near-misses (2). Drill-down is gated to MLRO/Deputy.
Why this matters: The board gets the oversight it needs without the legal risk of record-level disclosure. The MLRO never has to choose between "tell the board too much" and "leave NEDs unable to challenge".
Annual MLRO report — written from the case data
- · Typology trends (by quarter) — 12 month rolling.
- · Decision-volume statistics, FIU interaction counts.
- · Training gap themes from internal SAR root-cause tagging.
- · Control-gap findings surfaced (sanitised, non-tipping-off).
Why this matters: The report builds from the same record set the supervisor would inspect. Finalise → approve workflow with hash-chain seal at sign-off.
MLRO tables (mlro_internal_sar, mlro_case, mlro_decision_log) are gated by private.is_mlro_or_deputy(). SAR submitters can insert but never read the queue.
Case + decision content is excluded from Compass retrieval, classifier cache, and every AI prompt. The substrate is firewalled from the model layer.
Append-only decision log with SHA-256 chain (prev_hash → hash). Tamper-evident without any extra tooling.
The board pack pulls counts and themes — never record-level. Same source data, two different audiences, one set of permissions.
See it on your own data
The sandbox runs against the seeded Saltire tenant with 4 SARs across the SLA matrix and a worked case (CASE-DEMO-003) with a hash-chained decision log.