Getting Started
Set up your compliance workspace in minutes
Create your account
Sign up with your work email. Your organization workspace is provisioned instantly.
Select your plan
Choose Starter, Professional, or Enterprise based on your screening volume and feature needs.
Invite your team
Add Compliance Officers, Risk Managers, Analysts, and Auditors with role-based access.
Run your first screening
Navigate to Sanctions Screening, enter an entity name, and get real-time results in under 5 seconds.
Quick-start checklist
Implementation Guide
Full deployment playbook for enterprise teams
Phase 1: Foundation
- Configure SSO/SAML with your identity provider
- Set up role hierarchy (Admin → Manager → Analyst → Auditor)
- Define screening policy thresholds and match score minimums
- Configure data retention policies (default: 7 years)
- Enable audit logging to your SIEM if applicable
Phase 2: Workflows
- Build KYC/KYB onboarding workflows with approval chains
- Configure AML transaction monitoring rules and alert thresholds
- Set up automated batch screening schedules
- Define case escalation and SLA policies
- Configure regulatory change notification preferences
Phase 3: Integrations
- Connect CRM system (Salesforce, HubSpot) for customer data sync
- Integrate with core banking / transaction system via REST API
- Set up Slack/Teams webhooks for real-time compliance alerts
- Configure ServiceNow/Jira for case ticket creation
- Enable SFTP batch file exchange if needed
Phase 4: Go-Live
- Conduct UAT with compliance team on all screening workflows
- Run parallel screening test against known sanctioned entities
- Train compliance officers on adverse media and PEP procedures
- Establish ongoing monitoring schedule and alert review SLAs
- Document procedures for your regulatory compliance file
Administrator Guide
Platform administration, user management, and security
User Management
- Invite users via email or SSO provisioning
- Assign roles: Super Admin, Compliance Manager, Analyst, Auditor, Read-only
- Set data access scopes per user or team
- Force MFA for all users or privileged roles only
Security Settings
- Configure session timeout (default: 4 hours)
- Set up IP allowlisting for office network access
- Enable hardware security key (WebAuthn/FIDO2) support
- View active sessions and force-logout suspicious devices
Data Governance
- Set data retention policies per data category
- Configure automatic PII redaction in audit logs
- Enable cross-border data transfer controls
- Export full data archive for compliance audits
System Alerts
- Configure API rate limit alerts
- Set up uptime monitoring notifications
- Enable regulatory change digest emails (daily/weekly)
- Configure compliance deadline reminder schedule
Compliance Officer Guide
Day-to-day compliance workflows and regulatory reporting
Daily Compliance Workflow
Morning
- Review overnight alert queue
- Triage new screening hits
- Check regulatory deadline calendar
- Review cases pending your approval
Midday
- Run ad-hoc screenings for onboarding requests
- Review AML transaction monitoring alerts
- Update open cases with investigation notes
- Coordinate with risk team on EDD requirements
End of Day
- Sign off on cleared screening records
- Submit any SARs due today
- Update case statuses in the system
- Review next-day regulatory calendar
Regulatory Reporting
Generate audit-ready reports for regulators:
- Navigate to Reports → Regulatory Reports
- Select the reporting period and framework
- Choose output format (PDF for submission, Excel for analysis)
- Reports include digital timestamps and cannot be modified post-generation
- Archive copies are retained for 7 years automatically
SAR Filing Workflow
Use AI Copilot to draft Suspicious Activity Reports:
- Open the relevant case → click "Draft SAR"
- AI Copilot generates narrative from case data
- Review and edit the AI-generated draft
- Attach supporting evidence from the case file
- Export as PDF in your jurisdiction's required format
Risk Manager Guide
Enterprise risk framework, scoring, and portfolio monitoring
Risk Scoring Model
ComplianceOS AI uses a multi-factor risk scoring model (0–100) that combines: sanctions list match scores (40%), PEP classification (20%), adverse media volume and severity (25%), transaction behavior (15%). Thresholds are configurable per your risk appetite policy.
Portfolio Risk Monitoring
The Analytics module shows your organization's aggregate risk exposure by customer segment, geography, and product. Set automated alerts when portfolio risk score exceeds your defined threshold. Drill down to individual entity level from any chart.
Third-Party Risk (TPRM)
Vendor risk assessment uses structured questionnaires mapped to ISO 27001, SOC 2, and NIST CSF controls. Risk scores are calculated automatically. Reassessment schedules can be set per vendor tier (Tier 1: annual, Tier 2: biennial).
Regulatory Change Impact
The Regulatory Intelligence module highlights upcoming regulatory changes with impact assessment. Filter by your jurisdictions and industries. Subscribe to change alerts to receive email digest when new requirements are published.
API Documentation
RESTful API and Edge Functions reference
Authentication
Authorization: Bearer <your_supabase_anon_key>
X-Client-Info: complianceos-client/1.0
Endpoints
/functions/v1/screen-entityScreen individual or entity against sanctions and PEP databases
/functions/v1/screen-adverse-mediaScreen entity for adverse media articles via GDELT
/rest/v1/screening_requestsList all screening requests for your organization
/rest/v1/casesList all compliance cases
/rest/v1/casesCreate a new compliance case
/rest/v1/audit_logsRetrieve audit trail entries
Example: Screen an entity
https://your-project.supabase.co/functions/v1/screen-entity \
-H "Authorization: Bearer <token>" \
-H "Content-Type: application/json" \
-d '{"name":"Vladimir Putin","screenType":"all"}'
Integrations
Connect with your existing tools and systems
CRM
Available- Salesforce
- HubSpot
- Microsoft Dynamics
ITSM & Ticketing
Available- ServiceNow
- Jira
- Zendesk
Communication
Available- Slack
- Microsoft Teams
- Email (SMTP)
Identity & SSO
Available- Okta
- Azure AD
- Google Workspace
SIEM / Security
Enterprise- Splunk
- IBM QRadar
- Microsoft Sentinel
Core Banking
Enterprise- Temenos
- Finacle
- Flexcube
Data Warehouse
Enterprise- Snowflake
- BigQuery
- AWS Redshift
Crypto Compliance
Enterprise- Chainalysis
- Elliptic
- TRM Labs
Document Mgmt
Coming Soon- SharePoint
- Box
- Google Drive
Knowledge Base
Regulatory glossary, compliance frameworks, and deep-dives
KYC/KYB Fundamentals
KYC/KYBCustomer Due Diligence (CDD), Enhanced Due Diligence (EDD), Ultimate Beneficial Owner (UBO) mapping, and risk-based approach principles under FATF R.10.
Sanctions Screening Guide
SanctionsUnderstanding OFAC SDN, UN Security Council consolidated list, EU Consolidated, UK HMT, Australia DFAT — their legal basis, scope, penalties, and OFAC General Licenses.
PEP Classification
PEPFATF Recommendation 12 requirements, domestic vs. foreign PEP definitions, close associates and family members, and EDD requirements by jurisdiction.
AML Risk Typologies
AMLFATF ML/TF typology reports, common red flags, structuring/smurfing detection, trade-based ML indicators, and layering techniques.
UAE Regulatory Framework
UAECBUAE AML/CFT requirements, DFSA rules for DIFC entities, VARA virtual asset regulations, ADGM financial services regulation, FIU-UAE goAML system.
EU AI Act Compliance
AI GovernanceHigh-risk AI system classification, conformity assessment procedures, CE marking, fundamental rights impact assessment, and post-market monitoring obligations.
DPDP Act 2023 (India)
IndiaData Principal rights, Data Fiduciary obligations, consent mechanisms, cross-border data transfer conditions, Data Protection Board, and penalties under India's new data protection law.
Crypto Asset Compliance
CryptoFATF Travel Rule requirements for VASPs, MiCA (EU) registration and white paper requirements, crypto sanctions screening methodology, and blockchain analytics.
Troubleshooting
Step-by-step fixes for common issues
Release Notes
What's new in each version of ComplianceOS AI
- Live OpenSanctions API integration for real-time sanctions & PEP screening
- GDELT-powered adverse media screening with 15-minute data freshness
- EU AI Act (2024) and ISO 42001 AI Governance module
- Crypto screening with blockchain analytics integration
- GDPR/UAE PDPL/India DPDP Act cookie consent framework
- Fixed mobile navigation showing incomplete menu after login
- HaveIBeenPwned password security check on registration
- Plan-based feature gating with graceful locked state UI
- Improved audit log performance for large datasets
- Regulatory Knowledge Graph: 250+ countries, 5,000+ regulators, 100,000+ regulations
- AI Copilot with RAG — contextual compliance guidance powered by GPT-4
- TPRM vendor risk assessment with automated questionnaires
- Cases module with full lifecycle management and PDF export
- KYC individual onboarding with ISO 195-country support
- KYB business verification with UBO mapping
- AML transaction monitoring with configurable rule engine
- Multi-currency risk scoring
Frequently Asked Questions
Answers to the most common questions
AI Copilot Usage Guide
Get the most from your AI compliance assistant
Example Prompts
"Summarize FATF Recommendation 15 and its implications for our crypto business"
"Draft a SAR narrative based on the transaction patterns in case #1234"
"What are the UAE VARA licensing requirements for a crypto exchange?"
"Compare UK FCA Consumer Duty with EU MiFID II investor protection rules"
"List the top 5 AML red flags for trade finance transactions"
"What controls do we need under ISO 42001 for our AI screening model?"
Best Practices
- Be specific about jurisdiction
- Reference case numbers or entity names
- Ask for "plain English" summaries
- Request citations for regulatory quotes
Limitations
- AI may make errors — verify critical advice
- Knowledge cutoff applies to recent changes
- Not a substitute for legal counsel
- Complex multi-country questions may need clarification
RAG Context
- Copilot accesses your org's compliance data
- Searches regulatory knowledge base in real-time
- Cites source documents in responses
- Context window: last 20 messages
Video Tutorials
Step-by-step walkthroughs for every module
Getting Started: First Sanctions Screening
BeginnerSetting Up Your Compliance Team & Roles
BeginnerKYC Individual Onboarding Deep Dive
IntermediateAML Transaction Monitoring Configuration
AdvancedUsing the AI Copilot for SAR Writing
IntermediateRegulatory Intelligence Navigation
IntermediateBuilding Custom Risk Rules
AdvancedExporting Reports for Regulators
BeginnerTPRM Vendor Assessment Workflow
AdvancedCrypto Screening & Blockchain Analytics
AdvancedAPI Integration: Webhooks & Real-time Events
AdvancedEU AI Act Compliance Checklist
IntermediateDownload Centre
Product documentation, specifications, and legal documents
ComplianceOS AI Product Brochure
PDF · 2.4 MB
OpenAPI 3.0 Specification
JSON/YAML · 180 KB
Implementation Checklist
PDF · 512 KB
Data Processing Agreement (DPA)
PDF · 340 KB
Security & Compliance Whitepaper
PDF · 1.8 MB
Regulatory Framework Coverage Map
PDF · 3.1 MB
AML Rule Library Reference
PDF · 890 KB
Integration Architecture Guide
PDF · 1.2 MB
Support & Contact
Get help from our compliance and technical experts
Live Chat
Instant support with compliance experts
Available 24/7
Email Support
Detailed technical and compliance queries
Response in 4 hours
Schedule Demo
Personalized platform walkthrough
Mon–Fri, 9am–6pm GST
Phone Support
Priority voice support for Enterprise
Enterprise plan only