No result found
This report needs a scored result to generate.
This is a static sample and does not depend on a scored result.
Back to the programme pageIllustrative example · fictional company, for format reference only
Three Outputs, One Regulated Function
Kelvin Bridge Payments
Kelvin Bridge Payments is a fictional MAS-licensed Major Payment Institution. Its example regulated function for this sample: cross-border remittance transaction-monitoring function. All three outputs below are built for that same function, not three unrelated exercises.
Three Produced OutputsGovernance Checklist — AI-Assisted Alert Triage
Decision scope: the AI model ranks flagged cross-border remittance alerts by suspected-activity likelihood. It does not close an alert, clear a customer, or file a Suspicious Transaction Report on its own.
Named owner: the Head of Financial Crime Compliance owns the model's ranking output and its escalation path. Any Tier 2 or Tier 3 alert is signed off by a named reviewer, not the model.
Audit trail: every auto-deprioritised low-risk alert is logged with the ranking factors that produced it, retained for five years, matching MAS's record-keeping expectation for AML systems.
AI-Literacy Baseline — Compliance & Operations Team
18 of 22 transaction-monitoring analysts can explain, unprompted, what data feeds the ranking model and what its output does and does not decide.
9 of 22 can independently walk a reviewer through why a specific alert was ranked the way it was, without pulling in a vendor call first.
The gap sits at the review layer, not the front line: analysts trust the ranking, but only a minority can currently defend a specific ranking under questioning.
AML Implementation Note — RegTech Integration
An anomaly-detection layer was added ahead of the existing rules engine, scored against six months of historical alerts before go-live, not switched on cold.
The false-positive rate on cross-border remittance alerts fell from 15.4% to 10.7% in the same backtest, with zero true positives reclassified as false.
The model's output stays advisory only until a defined 90-day parallel run closes; the legacy rules engine keeps sole filing authority throughout.
Kelvin Bridge Payments, its team-size figures and every score above are invented for this sample only, to show the shape of the output, not a real client's actual result. In the session, these three documents are built from the regulated function a participant's organisation actually brings into the room.
Three outputs on one page is deliberately not the same thing as one scored table, and it is worth being precise about why. A governance checklist, a literacy baseline and an AML implementation note answer three different questions, one about accountability, one about whether the people in the room can operate what was accountable for them, and one about whether the underlying model actually works better than what it replaced. Averaging them into a single number would hide the one relationship that actually matters here: the governance checklist's audit trail is only as good as the literacy baseline says the review layer is, and right now it says something specific and uncomfortable.
The governance checklist itself is in reasonable shape. A named owner exists, the decision scope is bounded correctly, an alert ranking is not a filing decision, and the audit trail's five-year retention already matches what I would expect a MAS reviewer to ask for. None of that is the constraint. The constraint is sitting in the second document: eighteen of twenty-two analysts can explain what the model does in general terms, but only nine can defend one specific ranking under questioning. That is not a minor training gap. It is the exact skill an internal audit committee or a MAS inspector will test for first, because "the model explained itself to me" is not an answer a regulator accepts from a compliance officer.
The AML implementation note's honesty is the thing I would point to first if I were presenting this to Kelvin Bridge's board. A false-positive reduction from 15.4% to 10.7% is a real result, but the note is explicit that the model stays advisory only until the ninety-day parallel run closes, and that the legacy rules engine keeps sole filing authority throughout. That sequencing discipline, proving a control before letting it carry filing weight, is precisely what separates a governance checklist a board can sign off on from one that only looks complete on paper.
My recommendation, and the one this programme's closing session builds live for a real regulated function, is to treat the literacy gap as the pacing item for the whole rollout, not a parallel workstream. Retiring advisory-only status before nine becomes eighteen would produce a technically compliant AML control operated by a team that cannot yet defend it, which is a worse position than the one Kelvin Bridge is in today.
One Integrated Roadmap
The governance checklist, AI-literacy baseline and AML implementation note above, checked against each other and sequenced into one plan, not three disconnected reports each running on its own timeline.
- Run a structured session for the 13 analysts who can't yet independently defend a ranking, using the actual flagged alerts from the backtest, not hypothetical cases.
- Assign each Tier 2 and Tier 3 escalation a named backup reviewer, so one analyst's absence can't stall the parallel run.
- Publish the governance checklist's audit-trail format to the whole team before the parallel run reaches its midpoint, not after.
- Continue the 90-day parallel run, comparing the anomaly-detection layer's ranking against the legacy rules engine's output alert by alert.
- Re-test literacy at the review layer; target 18 of 22 analysts able to defend a specific ranking unprompted, not just explain the model in general terms.
- Track the false-positive rate weekly against the 10.7% backtest figure, not only at the 90-day mark.
- Bring the governance checklist, the re-scored literacy baseline and the closed-out AML implementation note to the same board pack, cross-referenced against each other.
- Retire the model's advisory-only status only if both the literacy target and the false-positive target hold for the full parallel run, not either alone.
- Rehearse the MAS-inspection version of the same three documents: same figures, addressed to a different reader.
What I want to flag about this roadmap, before anything else, is the order the three phases run in. It would be easy to sequence this as "fix the AML model, then train the team," because that is how most organisations I have worked with across twenty-plus markets actually plan a rollout: technology first, people afterward, as a kind of cleanup pass. This roadmap runs the opposite way on purpose, and that choice is the whole point of bringing workforce literacy into the same room as the governance and AML work, rather than scheduling it as a separate initiative six months later.
Weeks one to four exist entirely to close the review-layer gap before the parallel run gets serious, because training thirteen analysts against real flagged alerts, not hypothetical training-deck cases, only works if those alerts already exist to train against. That is a genuinely different exercise from a generic AI-literacy workshop, and it is the reason the literacy baseline was built from Kelvin Bridge's own backtest data rather than a template. Assigning named backup reviewers in the same phase is not paperwork; a nine-person bottleneck on Tier 2 and Tier 3 escalations is a single point of failure I have seen stall a compliance rollout for months when the one person who could sign off went on leave.
The middle phase, weeks five to eight, is where most organisations quietly let the literacy work slide, because a re-tested literacy score does not show up on a status update the way a falling false-positive rate does. Tracking both on the same weekly cadence, not just at the ninety-day mark, is what keeps the workforce side from becoming the thing nobody checks until it is already a problem.
What I would tell Kelvin Bridge's leadership directly is this: a false-positive rate improving from 15.4% to 10.7% will look, from outside compliance, like the project succeeded. It has not succeeded until the eighteen-of-twenty-two target holds at the same time, because a control the operating team cannot independently defend is not actually a control, whatever the backtest says about it. Weeks nine to twelve exist to prove both held together, not separately, which is the only version of "done" a workforce transformation lead should accept.
This roadmap and every week-by-week figure on it are invented for Kelvin Bridge Payments, a fictional company, so the format of what a participant leaves with can be judged before enquiring. In the session, this roadmap is sequenced live from the three outputs a participant's own organisation produces during the day.
A Position Defensible to Both a Board and a MAS Inspection
The three questions a board member and a MAS inspector will both actually ask, answered for Kelvin Bridge Payments's example function above, not left as an abstract compliance framework.
A wrong ranking mis-prioritises an alert's review order; it does not itself clear a customer or file a report. Every Tier 2 and Tier 3 alert still passes through a named human reviewer before any regulatory filing decision, so the cost of a wrong ranking is a delay or a missed priority signal, not an unchecked filing outcome.
Yes, for the ranking layer: every auto-deprioritised alert's ranking factors are logged at the moment of ranking and retained for five years. What is not yet demonstrable is the review layer's own consistency, since only 9 of 22 analysts can currently defend a specific ranking unprompted; that gap is the first item on the twelve-week roadmap.
Partially. 18 of 22 analysts can explain what the model does and does not decide, which is the literacy floor MAS and the EU AI Act's Article 4 both expect. Independently defending one specific ranking under questioning is a narrower skill, currently held by fewer than half the team, and is the constraint this whole roadmap is sequenced around closing.
10.7%
False-positive rate on cross-border remittance alerts, down from 15.4% in backtest
Illustrative AML implementation note, Kelvin Bridge Payments
18 / 22
Analysts who can explain what the model does and does not decide
Illustrative AI-literacy baseline, Kelvin Bridge Payments
5 years
Retention period for every logged alert-ranking audit trail
Illustrative governance checklist, Kelvin Bridge Payments
90 days
Length of the parallel run before the model's output can carry filing weight
Illustrative AML implementation note, Kelvin Bridge Payments
I have sat across the table from MAS inspectors often enough to know which of these three questions gets asked first, and it is never "does the model work." It is "what happens when it's wrong, and who catches it." Kelvin Bridge's answer here is the right shape: a wrong ranking delays or mis-prioritises an alert's review, it does not itself clear a customer or file a report, and every Tier 2 or Tier 3 alert still passes a named human reviewer before any filing decision. That distinction, between a ranking error and a filing error, is what keeps this whole architecture defensible rather than merely automated.
The second question is harder, and I would not let Kelvin Bridge present it as fully answered yet. Showing the control existed before a specific decision, not reconstructed after the fact, is demonstrable for the ranking layer: the audit log captures ranking factors at the moment of ranking, retained for five years, which is exactly the record-keeping standard I would expect under both the MAS AI Risk Management Guidelines and the EU AI Act's Article 12. But an inspector who is any good will not stop at "the log exists." They will pull a specific flagged alert and ask the reviewing analyst to walk them through it live, and today that only works reliably for nine of twenty-two analysts. A audit trail nobody in the room can narrate under questioning reads, to an inspector, as documentation built for the file rather than for the work.
The third question is the one I have watched compliance teams get wrong most often, because it is tempting to answer it about the vendor rather than the institution. Eighteen of twenty-two analysts understanding what the model does and does not decide is a real literacy floor, and it is the number I would lead with in a board pack. But "the workforce understands this control" and "the vendor understands this control" are not the same claim, and only the first one satisfies a regulator asking whether Kelvin Bridge itself, not ComplyAdvantage or Chainalysis, owns the judgement behind a filing decision.
Read together, these three answers describe an institution that built the right architecture and is honest about not yet having fully proven it operates it. That is a defensible position to bring to a board today. It becomes a defensible position to bring to a MAS inspection once the nine becomes eighteen.
Every question, answer and figure on this page is invented for Kelvin Bridge Payments, a fictional company, for illustration only. It is not a real client's actual compliance position, and no organisation named Kelvin Bridge Payments is a Praxora Lab client.
Your Three Practitioners
Every output on the previous three pages was built and reviewed by one of these three named practitioners, each accountable for their own block of the day, not a rotating cast of generalist trainers.
Terence Kok
Executive Director, AI Governance & Assurance Practice · Enterprise AI Strategist and Keynote Speaker
Enterprise AI strategist and former Chief AI and Innovation Officer at Meinhardt Group, with twenty-five years leading transformation programmes across Asia and the Middle East, specialising in impact assessment, governance and deployment methodology.
Sameen Khan, PBM
Global HR, AI and Workforce Transformation Leader
Global HR, AI and Workforce Transformation Leader with experience across 20+ markets spanning Asia Pacific, the Middle East, Africa and Latin America, based in Singapore.
Jason Lee
Head of Compliance & AI-Driven AML Specialist
Head of Compliance and MLRO with fifteen-plus years across banking, payments, fintech and digital assets, integrating AI and machine learning anomaly detection into AML, sanctions and transaction monitoring frameworks for regulated financial institutions.
The reason this programme puts three named practitioners in the room rather than one generalist covering all three disciplines is visible in exactly the way Kelvin Bridge's example plays out above. A governance framework built without Jason's AML fluency would have produced a checklist that reads well but doesn't survive a RegTech-specific question about false-positive reclassification. An AML implementation built without Sameen's workforce lens would have shipped the parallel run on schedule with nobody checking whether the review layer could actually defend it. And a literacy baseline built without a governance frame around it risks becoming a training-completion metric rather than a control anyone can point to under questioning. Each of us is accountable for one block precisely so none of those gaps gets averaged away inside a single generalist's judgement.
What the day is actually building, underneath the three separate documents, is the muscle to check them against each other before a regulator does it for you. That is a different skill from producing any one document well. Kelvin Bridge's own case shows why: on paper, all three outputs look reasonable in isolation. The governance checklist names an owner and a bounded decision scope. The literacy baseline shows a majority of the team above the explanation floor. The AML note shows a real, backtested improvement with sensible go-live discipline. It is only when you hold the three together, as the closing joint session forces a room to do, that the actual constraint surfaces: not one of the three documents individually, but the fact that the literacy baseline's weakest number, nine of twenty-two, is exactly the number that determines whether the other two documents' claims can be defended live, in front of either an internal board or an inspector.
That is also why this closing session runs with all three of us in the room together, not sequentially. A synthesis produced by one facilitator reading the other two blocks' outputs after the fact would catch the surface-level gaps. It would not catch the kind of gap Kelvin Bridge's example surfaces, where the constraint sits at the seam between two blocks rather than inside either one. Participants leave this programme with three connected documents and, more importantly, with a rehearsed answer to the question a regulator or a board member actually asks: not "is each of these individually complete," but "do these three things agree with each other, and can your own people say why."
Every score, quote and figure across these four pages is invented for Kelvin Bridge Payments, a fictional MAS-licensed payment institution, so the format of what a participant leaves with can be judged before enquiring. It is not a real client's deliverable, and no organisation named Kelvin Bridge Payments is a Praxora Lab client. The programme itself builds these three outputs, and the roadmap connecting them, from your own organisation's own regulated function, in the room, on the day.
One full day, three named practitioners, facilitated by Terence Kok, Sameen Khan and Jason Lee.