What the agents may do, and who answers for it.
Your model-risk function owns this tool whether or not you built it. This page is what it needs, in writing.
Controls, not capabilities. Nothing here needs a benchmark to defend it.
1. Bounded authority
The agents read, extract and correlate. They do not exercise discretionary authority.
Small, low-risk cases can run straight through when the bank has approved deterministic rules.
That is policy automation, not an agent verdict. Exceptions go to a named officer.
agent authority · gather only · policy path or named-officer decision
2. Outside the policy path, a named human decides
Human verdicts carry the officer. Automated paths carry the approved rule and version.
Refusals are recorded exactly like approvals. A decision not taken is visible in the record, not absent from it.
3. Everything the model saw and said is kept
Full prompt and response logs. Evidence snapshots of each source as it stood at decision time.
Append-only and hash-linked. Database triggers block deletion and rewrite.
A verdict replays against what was available then, not against today's data.
That is the difference between reviewing a decision and taking it again.
trace · hash-linked reasoning · field-level provenance · evidence snapshots · prompt and response logs
4. Where inference runs
Client data at rest is in Switzerland, always.
Inference is Switzerland by default. On Infomaniak, CH only. On AWS Europe (Zurich, eu-central-2), CH with EU as the declared boundary.
The choice is yours, and the regions are declared per deployment.
The guard is an allow-list of those regions. A call outside them is refused.
production guard · if llm.region not in deployment.declared_regions: raise ResidencyViolation()
Our inference hosts are also our sub-processors, listed by name and country on sub-processors.
The models are our own, running on those hosts. There is no third-party model API in the path to send a case to.
5. Coverage is measured, and gaps are declared
A source that could not be reached is named, and the result is marked incomplete.
A failed source is never a clean result. Absence of matches over a gap is not clearance.
A tool that degrades quietly is worse than one that stops.
coverage · 100+ consolidated sources · 5 core sanctions regimes · global PEP databases · adverse media in 75+ languages · corporate registries across 130+ jurisdictions
6. Model change control
A model change is a change to the system of record, not an implementation detail.
Inference runs on the hosts named in your deployment. A change that moves it is a sub-processor change.
The change record from the production pilot, 4.5 weeks:
210 improvements implemented · reported issue to production in minutes to hours
The model and its version are written into the audit record with the verdict, so a replay years later names what produced it.
Moving inference to a different host is a sub-processor change, which carries 30 days written notice and a right to object.
7. Evidence for your AI classification
We do not publish a legal classification for your use case.
Your deployment, modules and policy path determine the assessment.
We provide the control evidence your legal and model-risk teams need:
- The agents gather. They hold no discretionary decision authority.
- Bank-approved deterministic rules may automate small, low-risk cases.
- Cases outside that policy path go to a named human.
- Full prompt and response logs plus evidence snapshots, kept append-only.
- Inference regions declared per deployment, data at rest in Switzerland.
The signed deployment record states the active controls and decision path.
8. What we do not claim
No accuracy figure. A number from our own test set is not evidence to your model-risk function.
The method instead: your cases, your officers, alongside your current process, measured by you.
That is how the numbers on this site were produced.
The officers' own KPI journals, reconciled line by line against production data. The method is published.
Quick, low-risk cases can be fully automated under rules your bank approves.
SOC 2 and ISO 27001 are planned.
Ask us for the rest
Vendor questionnaires, an entry for your AI inventory, or a walk through the audit trail on one of your own cases: contact@complai.ch.
related · security and residency · sub-processors · methodology