Integrated IT services Financial-services vertical Book a call

The defense & compliance layer
for financial services.

Mandala IT staffs and runs the fraud, AML, sanctions, and SAR-drafting functions your CRO, CCO, and CISO own jointly — under one contract, one investigator workspace, one audit chain. Pricing tracks alerts resolved and false-positive reduction, not seat count.

  • 0 AML software by 2030 (USD)
  • 0 Global AML fines / year
01 · Market

A multi-billion-dollar compliance imperative, expanding under regulator pressure.

Financial fraud, AML, and sanctions are no longer cost centers — they are the operational license to run a regulated business.

AML software market

0

Industry research band — software-only segment, growing 17% CAGR through 2030.

Global AML fines / year

0

Annual penalties levied on regulated institutions for AML / sanctions failures.

US SAR filings / year

0

Suspicious Activity Reports filed to FinCEN annually — ~3.6M in 2023.

Why budgets keep growing

Banks no longer ask if a fine will hit — only when. EU 6AMLD, EU AMLA, FinCEN BSA updates, and Bank of Israel Directive 357 keep raising the floor.

Why the model is shifting

Buyers are moving away from per-seat software licenses toward performance-based detection.

02 · Risk surface

The compliance & fraud landscape Mandala IT is built to defend against.

Eight overlapping risk categories — every one carries direct P&L exposure, regulator exposure, or both.

03 · The company

Mandala IT — built for the regulated edge of financial services.

Mandala IT operates inside the rapidly expanding fraud & compliance sector, delivering a unified detection-and-evidence layer designed to screen, score, and document every relevant event in real time.

  • KYC, sanctions and PEP screening at onboarding and on every transaction
  • Real-time transaction monitoring across cards, wires, ACH, and instant rails
  • Investigator workspace with 4-eyes controls and case-management workflow
  • Regulator-ready audit chain with 5–7 year immutable retention
  • False-positive reduction model with feature-attribution explainability

“The vision converges fraud and AML on a single engine: real-time detection, regulator-grade evidence, and aligned commercial incentives.

04 · Differentiator

Outcome-aligned compliance — priced against the work we deliver.

Base retainer holds the investigative team and the case-management workspace on call. Per-event fees track resolved alerts, drafted SARs, and measurable false-positive reduction — line items examiners read straight from your dashboard.

01

Predictable spend

Base retainer covers standing investigators. Per-event fees track investigative throughput — caps agreed before signature so finance has a worst-case line.

02

Aligned interests

Our fee rises when alerts close faster and false-positive volume drops — exactly the CRO's KPI.

03

Reproducible alert lineage

Every score replays bit-identical against archived feature inputs (SR 11-7 §V model-change documentation). Examiners get a paper trail by default.

04

Coverage without hiring

A real-time transaction-monitoring desk needs 6–10 analysts to staff properly. We staff it; you carry the retainer.

05

Examiner-readable metrics

Every billable event maps to a regulator-facing artifact: SAR drafted, alert resolved, sanctions hit cleared, model-change documented.

06

Vendor consolidation

Replace fraud + AML + sanctions point tools with one investigator workspace and one team that owns scoring, narrative, and filing.

05 · Pillars

What we cover for you.

Five pillars under one engine — the bundle every bank CRO / CCO / CISO buys together.

Detection pillars

  • Fraud prevention (ATO + CNP + payment)
  • AML & sanctions screening
  • Transaction security (wire / ACH / SWIFT)
  • Regulatory reporting (SAR / STR / CTR)

What it documents

  • Per-alert evidence and reasoning
  • Hash-chained audit trail (5–7 yr retention)
  • 4-eyes investigator decisions
  • Feature-attribution explainability per score

How it operates

  • Real-time scoring, sub-200ms per event
  • Investigator case workspace
  • Continuous false-positive tuning
  • Performance-based commercial model
Case study · anonymised under client NDA

How we closed a Tier-2 bank's SAR-quality regulator finding in 90 days.

Buyer profile

Tier-2 European retail bank

Footprint
~6M customers · 4 jurisdictions
Engagement
AML + investigative-desk staff aug · 18 months
Team deployed
8 investigators + 1 quant
Stack
NICE Actimize
  1. −38% False-positive rate 90-day window
  2. 2.1× SAR throughput per investigator-hour
  3. 100% Examiner re-review pass first cycle

The situation

The bank had received a regulator finding on SAR narrative quality and false-positive ratio (run-rate 11.4%). The compliance team was at 70% headcount and could not recruit fast enough to hit the remediation deadline.

What we did

  1. 01Embedded 8 investigators into the bank's NICE Actimize workspace within 14 days of SOW.
  2. 02Ran 90 days of alert resolution + SAR drafting under 4-eyes controls, documented to SR 11-7 §V standard.
  3. 03Tuned detection thresholds against measured false-positive cost, not raw rate.
  4. 04Built the reproducible-alert-lineage evidence chain examiners now request by default.
06 · Architecture

A six-layer compliance & defense stack — verdict + evidence on every event.

Every relevant event is evaluated by six cooperating layers in under two seconds.

  1. L1

    Identity

    Decide who is on the other end — and whether they can transact.

    • KYC document verification with vendor-abstracted providers
    • Sanctions / PEP / adverse-media screening
    • Strong customer authentication (PSD2 SCA)
  2. L2

    Behavioral & transaction monitoring

    Decide whether the activity is legitimate, in real time.

    • Structuring, smurfing, layering and dormant-to-active pattern detection
    • Velocity, value-deviation and geographic-impossibility heuristics
    • ATO detection on every authenticated session
  3. L3

    API & banking-rail protection

    Stop the payload at the door — and at the rail.

    • ISO 20022 / SWIFT / FIX / open-banking PSD2 inline controls
    • Continuous vulnerability scanning of public-facing endpoints
    • API abuse detection — enumeration, business-logic abuse
  4. L4

    Threat & sanctions intelligence

    Decide whether the source is already known to be sanctioned or compromised.

    • OFAC / UN / EU sanctions and PEP lists, refreshed continuously
    • Adverse-media and breach-and-leak monitoring
    • Cross-tenant signal sharing
  5. L5

    Control plane & case management

    Your investigators' workspace. Where our hours and your per-event fees are reconciled each month.

    • Case management with 4-eyes controls and narrative templates
    • Real-time dashboards — alerts open, time-to-decision, false-positive trend
    • Multi-channel alerting and billing against the performance model
  6. L6

    Regulatory reporting

    Produce the evidence package the regulator will accept.

    • SAR / STR / CTR drafting with vetted narrative templates
    • E-filing connectors (FinCEN BSA E-Filing, IMPA goAML)
    • Hash-chained 5–7 year audit retention, examiner-ready exports
A suspicious wire, end to end · under 2 seconds
  1. 01Auth
  2. 02Tx pattern
  3. 03Rail check
  4. 04Sanctions / PEP
  5. 05Risk score
  6. 06Verdict
  7. 07Approve · hold · SAR
08 · Engage

Engage Mandala IT across the compliance surface of financial services.

Engagement terms

Issuer
Mandala IT (IT services consultancy)
Engagement model
Project · Managed · Retainer · Staff-aug
Minimum engagement
From USD 10,000 per engagement
Sector
Financial services · AML · fraud prevention
Pricing model
Outcome-aligned hybrid
Status
Open
Request proposal Book a 30-min discovery call instead

Tell us about your project

Leave your details — a Mandala IT consultant will follow up within one business day\.

How we handle your data — Privacy policy

Note. Scope, deliverables, timelines, and SLA tiers are agreed in a mutual Statement of Work. Commitments on this page are illustrative; binding terms live in the engagement contract.

09 · FAQ

Quick answers.

Does Mandala IT handle or transmit funds?

No. Mandala IT is a services firm, not a money-services business. We never custody, transmit, or hold funds; we deliver analyst hours, controls, and the evidence chain.

How does the outcome-aligned model work for a bank?

Base retainer covers the standing investigative team and the case-management workspace. Per-event fees track alerts resolved, SARs drafted, and measurable false-positive reduction — capped at a ceiling agreed before signature so finance has a worst-case line.

What about SOC 2, ISO 27001, and audit posture?

SOC 2 Type II audit and ISO 27001 certification are in flight. Pre-audit attestation package and Statement of Applicability available under NDA; we can be added to your TPRM register on request.

Which segments does Mandala IT target?

Tier-2 banks, regional banks, neobanks, and licensed fintechs (lenders, BNPL, crypto on/off-ramps, payment processors). Tier-1 banks are addressed via partner channels.

Do you guarantee outcomes?

We commit to measurable improvement against your baseline — quantified per engagement in the Statement of Work. SLA-backed commitments and clear remedies, not vague guarantees.

How fast can you start?

Scoping call within 2 business days. Signed Statement of Work typically within 7–14 days. Monitoring live within 30 days of SOW for standard engagements; emergency incident-response retainer can be activated within 24 hours.

Do you sub-contract any of the work?

We deliver primarily with directly-employed analysts and engineers. Where a vertical needs specialist coverage (forensics, firmware analysis, jurisdiction-specific filings), named partners are disclosed in the SOW before signature — never silently white-labelled.

What if we already use NICE Actimize / Quantexa / Hawk:AI / Sumsub?

We integrate with your existing AML / fraud / KYC stack rather than displace it. Our investigators staff the case workspace against your existing rules engine, tune detection thresholds against measured false-positive cost, and own the SAR-drafting and audit chain. If a tool is genuinely failing examiner expectations, we say so in writing.

Where does our data live? Can we keep it in-region?

Region-specific options — EU, UK, US, Israel, GCC — are scoped per engagement. BAA (US healthcare), DPA (EU), and ISO 27001-aligned controls are issued under the engagement contract. Production data and PII do not leave your designated region without written consent.

Can we see reference clients?

After the first scoping call, under mutual NDA. Most of our clients are regulated and contractually cannot be named publicly. Reference calls with comparable-size buyers in your vertical are arranged before SOW signature.