Skip to Content
Compliance Rules

Compliance Rules

VINCTA uses a deterministic rules engine based on European regulatory requirements. All rules cite their legal basis and produce auditable decisions.

Risk Methodology

VINCTA calculates customer risk using a transparent, rule-based approach aligned with German GwG and AMLD6 requirements.

Risk Score Calculation

Each customer receives a risk score (0-100) based on:

  • KYC verification outcome
  • Transaction monitoring alerts
  • Sanctions screening results
  • PEP status
  • Country risk factors

Vendor Risk Aggregation

When multiple vendors report on the same customer, the highest vendor risk assessment is displayed per GwG §10 risk-based approach.

Risk Classifications

ClassificationScore RangeDue Diligence
Low0-30Simplified (GwG §14)
Medium31-70Standard
High71-100Enhanced (GwG §15)

Alert Aggregation

VINCTA consolidates alerts from all connected vendors into unified customer profiles.

Identity Resolution

When alerts arrive from different vendors, VINCTA matches them to a single customer identity using:

  1. Exact match — Email, phone number, identification number
  2. Fuzzy match — Name variations with confidence scoring
  3. Manual review — Ambiguous matches flagged for analyst decision

Supported Alert Types

Alert TypeSource Vendors
Transaction MonitoringUnit21, HAWK AI
KYC DecisionsAlloy
Sanctions/PEP/Adverse MediaComplyAdvantage

Vendor Conflict Resolution

When vendors provide conflicting assessments, VINCTA applies deterministic resolution rules.

Conservative Principle

Per GwG §10, VINCTA automatically applies the highest risk classification when vendors disagree.

Example: Customer screened by both Alloy and ComplyAdvantage:

  • Alloy: Low risk (identity verified, no flags)
  • ComplyAdvantage: PEP match detected

Result: Case elevated to high priority, PEP review workflow triggered.

Active Rules

VINCTA ships with 15 validated rules based on AMLD6, German GwG, and DORA requirements:

Priority Rules

RuleRegulatory BasisEffect
PEP Priority OverrideAMLD6 Art. 20(a)Elevates PEP cases to high priority
High-Risk CountryGwG §15(3)Enhanced review for high-risk jurisdictions
Conservative PrincipleGwG §10Applies highest vendor risk

Blocking Rules

RuleRegulatory BasisBlocking Condition
Expired IDAMLD6 Art. 13(1)(a)Cannot approve with expired identification
PEP Source of FundsAMLD6 Art. 20(b)(ii)PEP cases require source of funds documentation
UBO IdentificationAMLD6 Art. 13(1)(b)Business customers require beneficial owner records

SLA Rules

PrioritySLATypical Cases
Critical4 hoursSanctions matches
High24 hoursPEP cases, high-risk countries
Medium72 hoursStandard TM alerts
Low7 daysSimplified due diligence

Rule Customization

Default rules can be customized per client: adjust thresholds, add client-specific rules, disable non-applicable rules, create jurisdiction variations.

Last updated on