The way to choose AML software is to stop evaluating demos and start evaluating answers. Every vendor demo looks the same: a clean dashboard, an instant verdict, a confident accuracy claim. The real choice is made by asking questions the vendor cannot rehearse, then listening for whether the answer contains numbers, mechanisms, and commitments or just adjectives. This guide gives you 14 of them, grouped into detection, coverage, operations, and deployment, with what a strong answer sounds like for each, so a weak one is obvious the moment you hear it.

If a vendor cannot answer a question in the meeting, that is the answer.

The 14 questions at a glance

#QuestionWhat a strong answer sounds like
1Do verdicts arrive before settlement, and at what measured latency?A number in milliseconds inside a stated budget, not the word "real-time."
2Is each verdict explainable rule by rule?Yes, with a per-rule decomposition you can hand to an examiner.
3How are false positives handled, and who controls tuning?Customer-side thresholds and rule weights, no vendor ticket required.
4Which behavioral signals does it read beyond the transaction?Device, IP, session, impossible travel, account history.
5What happens to in-flight transactions when an engine goes down?Fail-open, recorded degradation, automatic re-screening, compliance alerted.
6Which sanctions, PEP, and adverse-media lists are screened?Named lists including local African watchlists, with a stated update cadence.
7Does it cover onboarding to reporting in one platform?KYC/KYB, monitoring, case management, and reporting in one system.
8Can it screen historical transactions retroactively?Yes, bulk import of full history with results in hours, not weeks.
9What does the analyst queue show per alert?The verdict, the rules that fired, and the evidence behind each one.
10Is there an immutable audit trail?Yes, exportable and readable by an examiner without vendor help.
11Does it produce regulator-ready output?goAML-format STRs for the NFIU, ready to file.
12How is it integrated, and how fast is the first screened transaction?API plus CSV import; days to first screened transaction, not quarters.
13How is it priced, and what changes at scale?A written pricing model with the breakpoints where costs step up.
14Can we run a proof of concept on our own data before signing?Yes, on your historical transactions, with a success bar agreed in advance.

Detection: can it actually stop money before it moves?

1. Do verdicts arrive before settlement, and at what measured latency?

Every vendor claims "real-time." Almost none will commit to a number. Ask for the measured latency of a verdict and the budget it must fit inside. A strong answer sounds like: 142 milliseconds per verdict inside a 200ms budget, measured in production. Your payment rail has its own timeout; a screening layer that adds unbounded delay gets bypassed or breaks the customer experience. If the vendor answers with "sub-second," ask which second. Our own breakdown is in anatomy of a 142ms verdict.

2. Is each verdict explainable rule by rule, or is it a black-box score?

A score of 0.87 with no decomposition is unusable in an examination. CBN expectations on AI and ML governance run in one direction: you must explain why the system acted on a specific customer's money. A strong vendor shows a verdict that decomposes rule by rule: which rules fired, what each observed, and how the decision followed. A weak vendor talks about model accuracy instead. More on this in behavioral intelligence without black-box ML.

3. How are false positives handled, and what tuning control does the customer have?

False positive rate decides whether your analysts trust the system or route around it. Ask what alert precision looks like at an institution of your size, then ask who can change the thresholds. A strong answer: your compliance team adjusts rule weights directly, and every change is logged. A weak answer: tuning needs a professional-services engagement. If you cannot tune it yourself, the vendor owns your alert queue.

4. Which behavioral signals does it read beyond the transaction itself?

The transaction payload alone misses most account takeover and mule behavior. Ask what else the system reads: device fingerprint, IP history, session behavior, impossible travel between logins, the account's own history. A transfer that looks clean in isolation is often the last step of a takeover that started with a new device days earlier.

5. What happens to in-flight transactions when a screening engine goes down?

This is the question vendors least expect. Engines fail; the issue is whether a failure silently stops screening while transactions keep flowing. A strong answer has three parts: engines fail open so payments are never blocked by an outage, every degradation is recorded with the affected transactions, and those transactions are re-screened automatically on recovery, with compliance alerted throughout. A weak answer is an uptime SLA, which compensates you for the outage but does nothing about the transactions that slipped through unscreened. The full architecture is in screening integrity: never lose a transaction.

Coverage: does it screen what your regulator cares about?

6. Which sanctions, PEP, and adverse-media lists are screened, and are local African watchlists included?

Global vendors ship the major international lists and treat regional coverage as an afterthought. For a Nigerian institution, that is backwards. Ask for the list inventory by name, the update cadence, and whether local African watchlists are included. Also ask how fast a new designation reaches live screening; a name added on Monday that only screens after the next monthly update is a gap an examiner can find with one query.

7. Does it cover your full flow, or will you stitch three tools together?

Map the vendor's scope against your actual obligation: onboarding KYC/KYB, ongoing monitoring, case management, and regulatory reporting. Each boundary between tools is a place where context is lost and alerts fall over. A customer verified in one tool, monitored in a second, and cased in a third produces three partial pictures and an audit trail nobody can read end to end. Count the integrations the vendor's answer assumes you will build yourself.

8. Can it screen your historical transactions retroactively?

Two situations make this non-negotiable: switching vendors without a blind spot on everything before go-live, and checking a new typology against your full history. A strong answer: bulk import of your full transaction history, screened on day one, no code required. A weak answer is "the API is real-time," which quietly concedes that everything before go-live stays unscreened. How this works is in bulk import and retroactive screening.

Operations: will your team actually use it?

9. What does the analyst queue look like, and what does a verdict explain?

Your analysts will spend more hours in this screen than your executives will spend in the demo. Ask to see the queue, not the dashboard. For a single alert, the analyst should see the verdict, the rules that fired, the evidence behind each rule, and the customer's context, without opening another tool. If dispositioning one alert means exporting to a spreadsheet, multiply that by your daily alert volume and you have your real operating cost.

10. Is there an immutable audit trail an examiner can read without vendor help?

Every alert, decision, tuning change, and override should sit in a trail that cannot be edited after the fact. Two tests. Can you export it yourself, and does it capture the state of the rules at decision time, so you can defend a call made two years ago under thresholds that have since changed. If reconstructing history needs the vendor's engineers, the trail is a feature list, not a control.

11. Does it produce regulator-ready output?

In Nigeria this question has a concrete form: can the system produce goAML-format STRs for the NFIU, and does it track the deadlines that come with them. The STR clock is 24 hours from suspicion, and CTRs above ₦5 million for individuals or ₦10 million for corporates are due within 7 days. A strong answer generates the filing from the case, evidence attached, instead of retyping alert data into a portal under deadline pressure. The filing process is covered in how to file an STR with the NFIU.

Deployment and commercials: the true cost

12. How is it integrated, and how long to the first screened transaction?

Ask for the integration surface: API, batch, CSV import, or all three. Then ask for the elapsed time from signature to the first production transaction screened, at a reference customer of your size. A vendor with a CSV import path can have your historical data screened while the API integration is still in development.

13. How is it priced, and what costs appear at scale?

Get the pricing model in writing before the second meeting: per transaction, per account, per alert, or flat. Then model it at three times your current volume, because pricing that fits today can dominate the compliance budget in two years. Ask about charges that only appear at scale: alert overages, historical import fees, extra watchlists, extra analyst seats. Ours is on the pricing section of our site.

14. Can you run a proof of concept on your own historical data before signing?

This is the question that ends most evaluation theatre. Synthetic demos are curated. Your transaction history is not. A strong vendor runs a defined set of your historical transactions through the system and agrees the success bar in advance: detection on known-bad cases, false positives on known-good traffic, latency under your rail's budget. A vendor that declines a data-backed POC is telling you the demo is the best the product will ever look.

Red flags in vendor answers

  • No latency number. "Real-time" without milliseconds is a marketing claim, not an engineering commitment.
  • ML with no explanation. If the vendor cannot decompose a verdict rule by rule, your examiner will not accept it either.
  • No re-screening after outages. An uptime SLA without automatic re-screening means transactions pass unscreened and nobody knows.
  • Pricing only "after a scoping call." A model that cannot be written down in one email will not survive contact with your growth curve.
  • No POC on your data. Declining to be tested on real transactions is the loudest answer in the whole evaluation.

A note on build vs buy

Building in-house is a legitimate choice in a narrow set of cases: a large, stable engineering team, transaction patterns unusual enough that vendor rules fit badly, and the appetite to own the system for years.

Where in-house builds typically fail is not the detection engine. It is the unglamorous perimeter around it: keeping watchlists current day after day, maintaining an audit trail that survives examination two years later, and building retroactive screening so a new typology can be checked against your full history. These are maintenance obligations, not projects, and they outlive the engineers who wrote the first version. If you build, budget for the perimeter, not just the engine.

Where Finhaq fits

We built Finhaq to have good answers to these 14 questions. Six screening engines return an explainable, rule-by-rule verdict in 142ms inside a 200ms budget. Engines fail open, every degradation is recorded, and affected transactions are re-screened automatically. Behavioral trust scores feed the verdicts, and accounts below a score of 20 are interdicted with humans in the loop. Case management carries an immutable audit trail, reports come out in goAML-ready formats, and bulk CSV import screens your full history on day one with no code. At Buildbank MFB, this blocked over ₦97 million in suspicious value with zero false negatives.

If you are still scoping requirements, the free AML readiness assessment scores your current setup in three minutes and gives you a baseline to hold vendors against.


This article is general guidance for compliance and procurement professionals, not legal advice. Screening and reporting obligations are set by the Money Laundering (Prevention and Prohibition) Act 2022, CBN AML/CFT regulations, and NFIU directives. Always check the current instruments and your regulator's circulars.

Put Finhaq through the 14 questions

Bring this checklist to a 30-minute demo. We will answer every question on it, on your scenarios, with the numbers attached.