Credit Risk & AMLR Compliance — Audit-ready by design

Every decision.
Documented. Traceable. Defensible.

RyskFlow is the governance intelligence platform for credit risk and AMLR compliance. From first intake to signed proposition — every step recorded, every mandate on file, every dossier ready for the regulator.

Tamper-evident audit trail Mandate-based governance AMLR module in development

What RyskFlow does

Not just a risk tool.
A governance record.

Credit risk assessment is only half the job. The other half is being able to prove, months or years later, exactly what was decided, by whom, under which mandate, based on which policy version — and why.

RyskFlow captures that proof automatically. Every phase transition, every scoring decision, every override, every four-eyes approval is written to an immutable audit chain that survives any regulator visit or internal review.

The result is not just better-governed credit decisions. It is a platform that turns operational discipline into institutional memory — and makes compliance a by-product of good process, not a separate effort.

The same audit architecture now extends to AMLR compliance: CDD, UBO verification, PEP screening and transaction monitoring — documented, versioned and audit-ready from day one.

Audit Trail — Dossier #2847
Intake — dossier aangemaakt
2026-05-08 09:14 · Analist A. de Vries · Policy v4.2
Scoring klaar — risicoscore 3 / LTV 68%
2026-05-08 14:37 · Analist A. de Vries · Scoring v3.1
Wacht op fiat — Senior Risk Officer vereist
2026-05-08 14:38 · Mandaat v7 · €850K, klasse 3
Gefiatteerd — 4-ogen afgetekend
2026-05-09 10:02 · Sr. Risk Officer R. Smit + COO
Propositie uitgeleverd — KIIS gegenereerd
2026-05-09 10:18 · Hash: a3f7c2d1 · Policy snapshot bewaard

Platform modules

Three modules. One audit foundation.

Each module shares the same tamper-evident audit architecture, mandate register and RBAC layer — so governance is consistent across every process.

●  Live
🏢

Credit Risk — Vastgoed & MKB

Full audit-trail dossier management for real estate and SME lending. From intake through scoring to mandate approval and proposition delivery.

  • DSCR, LTV and risk scoring per segment
  • Mandate register — who approves what
  • Four-eyes principle per mandate rule
  • KIIS, termsheet and proposition generation
  • Phase workflow with time tracking
  • Policy-versioned decisions
●  Live
📊

GRC Module

Governance, risk and compliance reporting in a single panel — for regulators, management and internal audit.

  • KRI dashboard — portfolio-level risk indicators
  • DORA incident registration & export
  • AFM annual reporting & KIIS register
  • RBAC matrix — transparent role overview
  • ISAE evidence export (signed chain)
  • Policy governance & 4-eyes proposals
⬡  In development
🔍

AMLR Compliance Module

The same governance architecture applied to AML/KYC compliance — built to AMLR Article mapping, ready for AMLA supervision.

  • CDD / KYC client dossiers (Art. 16-24)
  • UBO register & verification (Art. 22-23)
  • PEP & sanctions screening (Art. 25-29)
  • Transaction monitoring (Art. 50-54)
  • FIU reporting (Art. 69-74)
  • CO / MLRO compliance dashboard

Credit workflow

Every phase. Every event. On record.

The credit workflow is not just a process — it is an audit sequence. Every transition is timestamped, actor-stamped and policy-stamped. Irreversible. Reproducible.

1

Intake

Dossier created, data loaded from SQL/CRM, initial policy snapshot attached

2

In behandeling

Analyst works scoring, financing structure and credit base — time tracked automatically

3

Scoring klaar

Decision proposal and motivation completed — FTR ratio recorded

4

Wacht op fiat

Escalated to required mandate level — mandate version logged at time of escalation

Propositie uitgeleverd

KIIS, termsheet and proposition generated, hashed and delivered — audit chain sealed

Governance architecture

Built for the regulator visit you cannot predict

Every design decision in RyskFlow starts with the same question: can we reproduce this — exactly — two years from now?

🔐

Tamper-evident audit chain

Every event is hash-chained. Deletion is structurally impossible. Any two-year-old decision is fully reproducible with actor, mandate version and policy snapshot.

🗂️

Mandate register

Configurable per role, segment, amount, LTV and risk classification. Four-eyes per mandate rule. Every fiat records which mandate version was active at approval time.

📜

Policy versioning

Every decision is stamped with the policy version in force at that moment. Version changes create a new snapshot — old decisions remain linked to their original policy.

⏱️

Automatic time tracking

Elapsed time and effective working time per phase per actor — automatically derived from UI activity, no manual clocking. Direct input for SLA management and capacity planning.

📈

KPI dashboard

FTR ratio, escalation ratio, override ratio, turnaround time per phase and per analyst — automatically generated, no manual input required.

🔑

RBAC & role isolation

Role-based access control with transparent matrix. Analysts, risk officers, compliance managers and admins see exactly what their role permits — nothing more.

AMLR Module

Credit risk governance.
Now extended to AMLR compliance.

The AMLR module is not being built from scratch. It inherits the full governance architecture of the credit risk platform — the same audit chain, mandate register, RBAC and policy versioning — and applies it to AML/KYC compliance documentation.

The methodology is based on a proven CDD tool already deployed in production (NN, 2022), adapted to the stricter requirements of AMLR (EU Regulation 2024/1624) which becomes directly applicable from July 2027.

  • Art. 16-24 CDD / KYC client dossiers with completeness badge
  • Art. 22-23 UBO register with verification workflow
  • Art. 25-29 PEP & sanctions screening
  • Art. 50-54 Transaction monitoring
  • Art. 69-74 FIU suspicious activity reporting
  • Art. 8-10 Risk assessments with scoring engine
  • Art. 15-17 Outsourcing register & governance
  • Art. 9(2) CO / MLRO compliance dashboard
Reused from credit risk platform
Tamper-evident audit chain
Hash-chained events — AMLA-exportable, regulator-ready
Mandate register & RBAC
Which role accepts which risk class — four-eyes required at High / Unacceptable
Scoring engine & override flow
10-dimension risk scoring, override with motivation, policy-versioned
Policy versioning
Every CDD decision stamped with the policy version active at that moment
Dossier snapshot pattern
KYC client profiles versioned and diff-tracked per review cycle

Built for

Who uses RyskFlow?

Any organization where credit decisions or AML compliance must be documented, governed and audit-ready.

ECSP Platforms

European Crowdfunding Service Providers needing KIIS generation, credit workflow governance and AFM reporting in a single compliant system.

Alternative Lenders

Non-bank lenders requiring structured credit processes with full audit trails, mandate-based approvals and regulator-ready documentation.

Compliance & Risk Teams

CCOs, CROs and risk officers who need evidence — not just process. Documentation that survives an AFM, DNB or AMLA supervisory visit.

Financial Institutions

Banks and lending institutions replacing manual, Excel-based credit and CDD workflows with a governed, audit-ready platform.

AMLR-obliged Entities

Any entity within AMLR scope — lenders, PSPs, asset managers — that needs a systematic, documented AML/KYC compliance record.

Internal Audit & Management

Management and audit teams that need KPI dashboards, FTR ratios and time tracking derived automatically from operations — not manual reports.

Our background

Built from the inside out.

RyskFlow was designed by a practitioner who has sat on both sides of the credit table — as the analyst building the dossier and as the compliance officer defending it to the regulator. The audit architecture is not a theoretical exercise. It is the answer to the question: what would I have needed to have on record?

30+
Years in credit risk, KYC/AML and compliance at major Dutch financial institutions
3
Integrated modules: Credit Risk, GRC and AMLR — one audit foundation
2
Live credit risk modules (Vastgoed + MKB) with AMLR module in active development
1
Core principle: every decision must be reproducible, two years later, by anyone

See RyskFlow in action

Request a demo and we will walk you through the credit risk workflow, the audit chain and the AMLR module in development.

Or reach us directly: info@ryskflow.com