NZ AML/CFT Act 2009 · System of record

Your AML programme,
one source of truth.

Opefin ingests your firm's own risk policy and runs it as a live scoring engine — replacing the spreadsheet, reconciling every client claim against bank evidence, and producing an audit-defensible risk score for each case.

Runs in shadow mode, parallel to your process
Case · AML-2041MEDIUM-HIGH
Client risk2.0
Source of funds3.0
Geography1.5
Transaction behaviour2.4
Inherent 2.8 → Residual 2.4 Evidence-backed
The problem

A rigorous programme deserves more than a spreadsheet

If your firm actually scores risk, runs EDD, and answers to a supervisor, generic checkbox tools don't fit. The pain is specific.

01

The programme lives in a spreadsheet

Risk weightings, thresholds and document requirements sit in an Excel file only your MLRO fully understands — hard to apply consistently, harder to defend under review.

02

Claims and bank data never line up

A client declares a source of funds; the statement says otherwise. Reconciling the declaration against the evidence is manual, slow, and exactly where real risk hides.

03

The audit trail is assembled after the fact

When a supervisor asks how a decision was reached, the reasoning gets reconstructed from email and memory instead of read straight off the case.

Auto-calibration

We calibrate to your policy — not the other way around

Upload your existing AML programme and risk matrix. Opefin extracts it into a live scoring tree that mirrors your categories, weightings and thresholds. Review it against the source document, confirm each rule, and it becomes the single source of truth every case is scored against.

  • Import from Excel, PDF or CSV — no rebuild from scratch
  • Your tree, your dimensions — nothing hard-coded by us
  • Inherent score, then residual once evidence mitigates it
  • One calibrated template, shared across every professional
AML policy · risk scoring Confirmed
Overall riskweighted mean
Client riskmean
PEP statusPEP → 3.0 override
Adverse mediahit → +1.0
Source of fundsmax
Declared vs evidencemismatch → 3.0
Country riskfrom register
extracted from AML-programme.pdf — review before saving
DeclaredBank evidence
Salary — Employer LtdDirect credit — Employer Ltd
Property sale — $180,000Settlement — $180,000
Gift — familyTransfer — matched
— not declared —Binance withdrawal
1 undeclared sourceEDD REQUIRED
Claim ↔ evidence

Every claim, matched to the bank record

Clients declare their source of funds and upload documents; Opefin pulls the transactions via Open Banking and reconciles the two. Declared income that never lands, deposits that were never declared, structuring, crypto — raised as alerts for your reviewer to dispose of, without moving the score until a human decides.

  • Open Banking pull from ANZ, ASB, BNZ and Westpac
  • OCR extraction from payslips, statements and contracts
  • Undeclared income, spikes and structuring surfaced automatically
  • Score stays evidence-backed — never an AI guess
The workbench

One reviewable case, the whole MLRO workflow

Scoring, screening, source-of-funds review, RFIs and sign-off — the entire workflow in a single case, calibrated to your programme.

01

Scored on open

Inherent and residual risk, EDD triggers and decline recommendations computed the moment identity and bank data land.

02

Screened

Sanctions, adverse media and watchlist hits surfaced inline, with the source behind every match.

03

Resolved by RFI

Missing evidence? Send a client RFI and track the back-and-forth on the case, not in your inbox.

04

Signed off and sealed

Senior approval, a decision record, and a portable certificate — with the full audit trail attached.

July 2026 · DIA single supervisor

Defensible when the supervisor asks

From July 2026 every reporting entity must review its programme and risk assessment under a single, better-resourced DIA supervisor. Opefin keeps your calibrated policy, every case decision and its evidence in one auditable record — so “how did you reach this risk level?” has a straight answer, not a reconstruction.

1 SoT
Policy, cases and audit trail
s.33
Reliance-ready certificates
Shadow
Parallel to your process
AML certificate SEALED
Risk levelMedium-High
Inherent → residual2.8 → 2.4
EvidenceOpen Banking + IDV
Review due24 months
full audit trail attached · verifiable seal

Bring your programme. We'll calibrate it.

Start in shadow mode — we run your real cases in parallel with your current process, so you see the results on your own data before you change anything.