Heelius closes an L1 alert for $2.80 against a $32.90 loaded human cost
Now onboarding design partners across 6 markets

The AI analyst that
investigates every alert

Transaction monitoring generates alerts that are 90–98% false positives. Heelius runs the full L1/L2 investigation, reaches a disposition, and writes the narrative a regulator will read. Your analysts review escalations and a QA sample.

NO RIP-AND-REPLACE · SITS ON YOUR EXISTING TM SYSTEM

ALT-2026-88104 · Marcus D. Oyelaran · structuring

INVESTIGATING

Investigation trace

0s elapsed

  1. Parse alert · rule TM-STR-004structuring
  2. Retrieve KYC & relationship history
  3. Reconstruct 12-month transaction history
  4. Expand counterparty network · 2 hops
  5. Screen sanctions, PEP & watchlists
  6. Adverse media sweep · 42 languages
  7. Weigh evidence & reach disposition
  8. Draft regulator-grade narrative

Narrative draft

Evidence

Citations

Cost

Escalation matrix armed · 3 gates monitored

KYC retrievalTransaction reconstructionCounterparty graphSanctions adjudicationPEP & RCA resolutionAdverse mediaDisposition reasoningNarrative draftingSelf-QAKYC retrievalTransaction reconstructionCounterparty graphSanctions adjudicationPEP & RCA resolutionAdverse mediaDisposition reasoningNarrative draftingSelf-QA
94%
of alerts closed without a human touching them
design-partner median, month 4
2m 35s
median end-to-end investigation
against 42 minutes staffed
$2.80
fully-loaded cost per alert
versus $32.90 human equivalent
96.4%
QA concurrence on sampled dispositions
L3 reviewer agreement

The investigation

Eight passes, the same order a good analyst works in

Heelius does not summarise an alert. It performs the investigation — retrieving the same records an L2 analyst would pull, in the same sequence, and showing its work at every step.

01

KYC & relationship

Customer file, beneficial owners, declared source of funds, expected activity, prior dispositions and every open alert on the relationship.

18 records

02

Transaction reconstruction

The alerted window plus a trailing twelve-month baseline, tested for threshold proximity, velocity, round-value patterning and pass-through.

347 txns

03

Counterparty network

Entity resolution out to three hops. Shared devices, common funding addresses, sequential registrations and circular flow between nominally unrelated parties.

3 hops

04

Sanctions, PEP & RCA

Consolidated list screening with discriminator logic — the agent states which identifiers diverge, and never clears on a name mismatch alone.

4 lists

05

Adverse media

42 languages, deduplicated by event, each candidate tested for homonym risk against date of birth, employer and biography.

1,840 articles

06

Weighted reasoning

Aggravating and mitigating findings scored against the institution's own thresholds. Unresolvable evidence routes to a human — it is never rounded to clear.

8 findings

07

Narrative drafting

Six sections in the conventional order — subject, activity, findings, mitigants, screening, disposition — with a source citation on every asserted fact.

6 sections

08

Self-QA

Every assertion is traced back to a retrieved record before the case is released. Unsupported prose fails the check and is redrafted.

100% traced

Narrative engine

Prose that cannot outrun its evidence

Narratives are assembled from retrieved records, not written from a summary. Every asserted fact carries the record it came from — so an examiner can walk any sentence back to the ledger it was drawn from.

Retrieved evidence

  • F-15 cash deposits, 8,900–9,600 USD, none ≥ 10,000Deposit ledger
  • F-23 distinct branches within 14 daysDeposit ledger — location
  • F-3Declared monthly expectation 40,000 USDKYC profile CUS-448192
  • F-434,000 USD to BR counterparty, +72hWire ledger
  • F-50.71 fuzzy match discounted — DOB Δ 14yOFAC SDN + EU + OFSI
  • F-65-year tenure, 2 prior alerts, 0 filingsCase history

Unsupported prose fails self-QA and is redrafted before release

Generated narrative · ALT-2026-88104

ESCALATE

Activity under review

Alert ALT-2026-88104 was generated by rule TM-STR-004 covering eight transactions totalling 46,300 USD through the retail deposit channel between 20 and 25 August 2026. Five cash deposits ranging from 8,900 to 9,600 USD were placed across three distinct branches, none reaching the 10,000 USD currency-transaction reporting thresholdF-1F-2. The alerted volume represents 1.2× the customer’s declared monthly expectation of 40,000 USDF-3.

Findings

Within 72 hours of the final deposit, 34,000 USD was remitted to a Brazilian construction counterparty against an invoice reference that matches the supplier recorded at onboardingF-4. Sanctions screening returned a single 0.71 fuzzy candidate, discounted on a 14-year date-of-birth divergence and a non-matching jurisdiction under the institution’s two-discriminator ruleF-5.

8 citationsheelius-investigator-4.2policy-pack us-bsa-2026.08Confidence 68%

Model architecture

A pipeline, not a prompt

A language model alone cannot pass a model-risk review. Heelius separates retrieval, graph inference, scoring and generation into four governed layers, so each one can be evaluated, versioned and challenged on its own terms.

RetrievalL1

Deterministic evidence layer

Typed connectors to your core, TM system, KYC store, card and wallet ledgers. Retrieval is deterministic and replayable — the same alert pulls the same records a year later, which is what makes a case defensible on examination.

Typed schemaReplayableNo free-text search
Graph MLL2

Entity resolution & network features

A learned linkage model resolves counterparties across devices, addresses, registrations and payment references, then extracts network features — circularity, fan-in/fan-out asymmetry, cluster co-registration, hop distance to known typologies.

Linkage model3-hop expansionTypology proximity
ReasoningL3

Weighted disposition model

Findings are scored as aggravating or mitigating against your institution's own thresholds, not a vendor default. The score is calibrated, so a stated 75% confidence means the disposition holds roughly 75 times out of 100 on held-out reviewed cases.

CalibratedPolicy-conditionedAuditable weights
GenerationL4

Constrained narrative synthesis

Language generation is confined to composing retrieved facts. A verification pass re-checks each assertion against source records and rejects any sentence that cannot be grounded — the failure mode is a blank section, never an invented one.

Citation-boundVerifier passNo free assertion

Evaluation · held-out adjudicated set

n = 41,200 · refreshed quarterly · champion/challenger

Precision on escalation
0.94
of escalations, share a human also escalated
Recall on true suspicion
0.991
of human-confirmed suspicion the agent surfaced
False-negative rate
0.9%
held-out set of 41,200 adjudicated alerts
Calibration error
0.021
expected calibration error, 10-bin
Narrative groundedness
99.8%
assertions traceable to a retrieved record
Median latency
155s
intake to released narrative

Every model version ships with a model card, a documented evaluation protocol and a challenger held in parallel. Drift on population stability, disposition mix and QA concurrence is monitored per typology and per corridor, with automatic reversion to human routing when a segment moves outside its control band.

Where the model has to change

Two markets the incumbents were not built for

Legacy investigation tooling assumes a correspondent bank's data model and a Western analyst's budget. Both assumptions break in the places where alert volume is growing fastest.

Emerging markets

Mobile money and agent networks

Operators in Nairobi, Lagos, Dhaka and Manila carry the same FATF obligations as a tier-1 bank on a fraction of the compliance budget — and alert volumes that scale with subscriber counts, not revenue. Heelius investigates agent float velocity, SIM-cluster co-registration, device overlap between nominally independent tills and cross-border corridor anomalies.

  • Agent and till-level typologies out of the box
  • Device, SIM and handset entity resolution
  • Local-currency thresholds and regulator narrative formats
  • Runs at per-alert prices a 30-analyst team cannot match
Read the approach
Virtual assets

Stablecoin and on-chain flows

Chain analytics tells you an address is risky. It does not tell you whether your customer's use of it is suspicious. Heelius joins on-chain attribution to the fiat side of the relationship — bridge structuring below travel-rule thresholds, unhosted-wallet exposure, mixer hop distance, related-party settlement back to a registered UBO.

  • Bridge and cross-chain hop tracing
  • Travel-rule threshold structuring detection
  • Unhosted wallet and mixer proximity scoring
  • Fiat off-ramp reconciliation to the KYC record
Read the approach

Deployed against

NeobanksPayment facilitatorsMobile money operatorsRemittance & MSBsVirtual asset providersSponsor banks
SOC 2
Type II
ISO
27001
GDPR
DPA + SCCs
Residency
EU · US · KE · SG
Retention
Zero model training on customer data

The economics

Priced per alert, against a line item you already have

No seat licences and no platform minimum. You pay for investigations completed, which means the saving is legible to a CFO on the first invoice.

24K
$2.80

Annualised

$8,100,288

net saving against a fully staffed L1/L2 function

Human-only baseline
$9,475,200
Heelius investigations
$806,400
Residual human review (6%)
$568,512
121

analyst-equivalents of investigation capacity, redeployed to escalations and quality assurance

Assumes 42-minute median handling time and a $47 fully-loaded hourly analyst cost

Run it against your own backlog

Send a month of closed alerts. Heelius re-investigates them blind and you compare its dispositions and narratives against what your team actually filed. No integration required for the benchmark.