Credit Risk, AMLR & EU AI Act — Audit-ready by design

Every decision.
Documented. Traceable. Defensible.

RyskFlow is the governance intelligence platform for credit risk, AMLR compliance and the EU AI Act obligations now heading for credit-scoring systems. From first intake to signed proposition — every step recorded, every mandate on file, every dossier ready for the regulator.

Tamper-evident audit trail Mandate-based governance AMLR compliance — demo-ready

What RyskFlow does

Not just a risk tool.
A governance record.

Credit risk assessment is only half the job. The other half is being able to prove, months or years later, exactly what was decided, by whom, under which mandate, based on which policy version — and why.

RyskFlow captures that proof automatically. Every phase transition, every scoring decision, every override, every four-eyes approval is written to an immutable audit chain that survives any regulator visit or internal review.

The result is not just better-governed credit decisions. It is a platform that turns operational discipline into institutional memory — and makes compliance a by-product of good process, not a separate effort.

The same audit architecture now extends to AMLR compliance and to the EU AI Act's transparency and record-keeping requirements for algorithmic credit decisions.

Audit Trail — Dossier #2847
Intake — dossier created
2026-05-08 09:14 · Analyst A. de Vries · Policy v4.2
Scoring complete — risk class 3 / LTV 68%
2026-05-08 14:37 · Analyst A. de Vries · Scoring v3.1
Pending fiat — Senior Risk Officer required
2026-05-08 14:38 · Mandate v7 · €850K, class 3
Approved — four-eyes signed off
2026-05-09 10:02 · Sr. Risk Officer R. Smit + COO
Proposition delivered — KIIS generated
2026-05-09 10:18 · Hash: a3f7c2d1 · Policy snapshot retained

Platform modules

Four modules. One shared governance foundation.

Credit Risk, Desk, AMLR and Recovery all run on the same tamper-evident audit chain, the same mandate register and the same GRC and MI reporting — governance and management information are included in every module, not a separate purchase.

RyskFlow Desk — Financial Intermediaries

Structured, governed credit assessment for financial intermediaries and lenders — from first application to approval, with an audit trail behind every decision.

  • DSCR, LTV and risk scoring per segment
  • Streamlined workflow, built for fast, governed credit decisions
  • Mandate register — four-eyes per rule
  • Tamper-evident audit chain — every decision reproducible and defensible
  • Plugs directly into the AMLR module for integrated AML/KYC checks
  • Policy-versioned decisions — always traceable to the policy in force
  • GRC & MI reporting included as standard

AMLR Compliance Module

Full AML/KYC compliance for financial service providers — 27 modules deep, from CDD dossiers to live sanctions screening, built for AMLA supervision.

  • CDD / KYC dossiers — legal entities & natural persons
  • Live OpenSanctions & PEP screening
  • MLRO dashboard & CARC workflow
  • FIU reporting — goAML XML export
  • DORA, AI Act & AVG modules included
  • CO / ECO compliance dashboard
  • GRC & MI reporting included as standard

Credit Risk — ECSP Platforms

Full audit-trail dossier management for real estate and SME lending, purpose-built for European Crowdfunding Service Providers — including every ECSP-mandated compliance gate.

  • DSCR, LTV and risk scoring per segment
  • Zakelijkheidstoets & KIIS generation (ECSP-mandated)
  • Publication & disbursement condition gates
  • Mandate register — four-eyes per rule
  • Termsheet and proposition generation
  • Policy-versioned decisions
  • GRC & MI reporting included as standard

Recovery — Special Servicing

Early signalling and structured guidance for dossiers that need extra attention — from early-warning trigger to a completed recovery plan, with a tamper-evident audit chain behind every action.

  • Automated early-warning triggers (DSCR, LTV, phase stagnation)
  • Watchlist with per-dossier prioritisation
  • Recovery plan & case management per debtor
  • Escalation & collaboration workflow
  • Full audit trail per action taken
  • Mandate register with four-eyes principle for every recovery track

Credit workflow

Every phase. Every event. On record.

The credit workflow is not just a process — it is an audit sequence. Every transition is timestamped, actor-stamped and policy-stamped. Irreversible. Reproducible.

1

Intake

Dossier created, data loaded from SQL/CRM, initial policy snapshot attached

2

In progress

Analyst works scoring, financing structure and credit base — time tracked automatically

3

Scoring complete

Decision proposal and motivation completed — FTR ratio recorded

4

Pending fiat

Escalated to required mandate level — mandate version logged at time of escalation

Proposition delivered

KIIS, termsheet and proposition generated, hashed and delivered — audit chain sealed

Built in, not bolted on

GRC and MI: the foundation under every module

GRC (Governance, Risk & Compliance) and MI (Management Information) aren't separate add-ons. GRC is the layer that records who made which decision, under which mandate and which policy. MI turns those same dossiers automatically into portfolio insight and steering information. Both are included with Credit Risk, Desk, AMLR and Recovery — never a separate purchase.

GRC — records that survive the regulator visit

Every design decision starts with the same question: can we reproduce this — exactly — two years from now?

Tamper-evident audit chain

Every event is hash-chained. Deletion is structurally impossible. Any two-year-old decision is fully reproducible with actor, mandate version and policy snapshot.

Mandate register

Configurable per role, segment, amount, LTV and risk classification. Four-eyes per mandate rule. Every fiat records which mandate version was active at approval time.

Policy versioning

Every decision is stamped with the policy version in force at that moment. Version changes create a new snapshot — old decisions remain linked to their original policy.

RBAC & role isolation

Role-based access control with transparent matrix. Analysts, risk officers, compliance managers and admins see exactly what their role permits — nothing more.

AFM & KIIS reporting

Annual reporting and the per-project KIIS register are generated directly from the platform — no more manually maintained spreadsheet for the regulator.

DORA incident classification

Incidents are automatically assessed against the statutory minor/non-major/major criteria, with tracking of the AFM reporting deadlines (T+4h, T+72h, T+30d).

MI — steering without a manual reporting cycle

The same dossiers, automatically turned into portfolio insight — not an export from last week.

Portfolio dashboard

Inflow, phase funnel, SLA breaches (>120 days) and segment split in one view — straight from the active dossiers, not an export from last week.

Automatic time tracking

Elapsed time and effective working time per phase per analyst — automatically derived from dossier activity, no manual clocking. Direct input for capacity planning and coaching.

KPI dashboard

FTR ratio, escalation ratio, override ratio and turnaround time per phase and per analyst — automatically generated, no manual input required.

Early-warning & watchlist

DSCR, LTV and phase-stagnation triggers flag dossiers that need attention, with a watchlist that flows into the Recovery module.

PD backtesting

The modelled PD is periodically tested against the actual observed default rate per risk class — validation, not a black box.

Repayment-plan review

Requests to amend a repayment schedule go through a two-step flow: advice from the analyst, ratification by a second reviewer — four-eyes here too.

Regulatory horizon

Built ahead of the deadline you can already see coming

The EU AI Act's enforcement machinery is no longer theoretical. Two dates now define what's next for algorithmic credit decisions specifically.

2 August 2026 — already in force
Article 50 transparency obligations take effect

AI-generated content must carry machine-readable marking, and AI interactions must be disclosed to users. Fines of up to €15M or 3% of global annual turnover. The direction of travel is now enforced, not proposed.

2 December 2027 — high-risk systems
Annex III obligations reach credit scoring

High-risk AI system obligations apply, with credit-scoring algorithms named explicitly in Annex III. Risk management, technical documentation, automatic logging and human oversight become mandatory. (Postponed from August 2026 under the June 2026 Digital Omnibus agreement.)

Art. 9
Risk management system

Policy-versioned scoring engine with documented weights, thresholds and override rules per tenant.

Art. 11
Technical documentation

Every scoring model, weighting and knock-out rule is versioned and retrievable — not scattered across spreadsheets.

Art. 12
Automatic logging

Every scoring decision, override and approval is hash-chained automatically — no manual log-keeping required.

Art. 14
Human oversight

The four-eyes mandate register ensures every algorithm-assisted decision has a named, accountable human approver.

RyskFlow clients aren't starting their Article 9–14 compliance work in December 2027. They started it the day they onboarded.

AMLR Module

◆ Demo-ready — not yet deployed with a production client

Credit risk governance.
Now extended to AMLR compliance.

The AMLR module is not being built from scratch. It inherits the full governance architecture of the credit risk platform — the same audit chain, mandate register, RBAC and policy versioning — and applies it to AML/KYC compliance documentation.

The methodology is based on a proven CDD tool already deployed in production (NN, 2022), adapted to the stricter requirements of AMLR (EU Regulation 2024/1624), which becomes directly applicable from July 2027. In its current form the module is already 27 modules deep, including a live sanctions-screening integration and a goAML-format FIU export.

  • Art. 16-24 CDD / KYC client dossiers with completeness badge
  • Art. 22-23 UBO register with verification workflow
  • Art. 25-29 PEP & sanctions screening — live OpenSanctions API
  • Art. 50-54 Transaction monitoring
  • Art. 69-74 FIU suspicious activity reporting — goAML XML export
  • Art. 8-10 Risk assessments with scoring engine
  • Art. 15-17 Outsourcing register & governance
  • Art. 9(2) CO / MLRO compliance dashboard
Reused from the credit risk platform
Tamper-evident audit chain
Hash-chained events — AMLA-exportable, regulator-ready
Mandate register & RBAC
Which role accepts which risk class — four-eyes required at High / Unacceptable
Scoring engine & override flow
10-dimension risk scoring, override with motivation, policy-versioned
Policy versioning
Every CDD decision stamped with the policy version active at that moment
Dossier snapshot pattern
KYC client profiles versioned and diff-tracked per review cycle

Built for

Who uses RyskFlow?

Any organization where credit decisions, AML compliance or algorithmic risk assessment must be documented, governed and audit-ready.

ECSP Platforms

European Crowdfunding Service Providers needing KIIS generation, credit workflow governance and AFM reporting in a single compliant system.

Financial Intermediaries

Advisers and intermediaries structuring credit for clients via RyskFlow Desk — a lean workflow with full audit trail and mandate governance, built for the pace of the intermediary segment.

Alternative Lenders

Non-bank lenders requiring structured credit processes with full audit trails, mandate-based approvals and regulator-ready documentation.

Compliance & Risk Teams

CCOs, CROs and risk officers who need evidence — not just process. Documentation that survives an AFM, DNB or AMLA supervisory visit.

AMLR-obliged Entities

Any entity within AMLR scope — lenders, PSPs, asset managers — that needs a systematic, documented AML/KYC compliance record.

Internal Audit & Management

Management and audit teams that need KPI dashboards, FTR ratios and time tracking derived automatically from operations — not manual reports.

Our background

Built from the inside out.

RyskFlow was designed by a practitioner who has sat on both sides of the credit table — as the analyst building the dossier and as the compliance officer defending it to the regulator. The audit architecture is not a theoretical exercise. It is the answer to the question: what would I have needed to have on record?

30+
Years in credit risk, KYC/AML and compliance at major Dutch financial institutions
4
Modules — Credit Risk, Desk, AMLR and Recovery — with GRC & MI reporting included in every module
Dec 2027
EU AI Act deadline for high-risk credit-scoring systems — RyskFlow is already built for it
1
Core principle: every decision must be reproducible, two years later, by anyone

See RyskFlow in action

Request a demo and we will walk you through the credit risk workflow, the audit chain, the AMLR module and the EU AI Act readiness built into every decision.

Or reach us directly: info@ryskflow.com