Bucephalus, Silbad's turnkey platform, detects and prevents the full spectrum of Illicit Financial Flows (IFF) — from fraud, money laundering and terrorist financing to trade mispricing, shell-company concealment and sanctions evasion.
Real-time fraud detection, continuous AML monitoring, sanctions screening, full case management and regulatory reporting — in one auditable, federated, verifiable-by-design solution. The goal is not detection alone, but provable, auditable decision-making across every IFF channel your institution is exposed to.
The same operating targets as our KPI table — agreed per pilot, measured jointly. Silbad surfaces prioritised, evidence-backed alerts; your team decides.
Traditional rule-based fraud systems leave banks exposed. The cost of inaction is measured in millions — and in trust.
Synthetic identities, mule networks, and AI-generated deepfakes are defeating static rules. Authorities catch barely 1% of laundered funds — the rest flows undetected through the global financial system.
GDPR and banking secrecy laws prohibit sharing raw transaction data with third parties — yet cross-institution intelligence is critical to catching sophisticated schemes.
Legacy systems drown compliance teams in noise. Each SAR investigation takes up to 22 hours, while 40% of customers abandon onboarding due to excessive friction.
Legacy fraud detection systems create a paradox: enormous spending, minimal results. Here's what the industry data reveals.
of AML alerts in traditional rule-based systems are false positives, drowning compliance teams in noise.
Industry averageof the estimated USD 0.8–2 T laundered annually is intercepted. Criminals exploit gaps between siloed institutions.
UNODC estimatespent globally on AML compliance — much of it on investigating low-quality alerts that lead nowhere.
LexisNexis Risk Solutionsactual investigation time per suspicious activity report, versus the 2-hour regulatory estimate.
Independent researchBucephalus is one integrated platform that covers the full financial-crime lifecycle — from the first identity check to the final regulatory report. It doesn't only detect; it gives compliance teams a system they can operate, govern and prove.
KYC, CDD and UBO discovery with a risk-based approach. Customers are classified into low, standard and enhanced due-diligence tracks before the first transaction is processed.
Every transaction is screened against AML scenarios, statistical baselines and the customer's own behavioural profile. Risk recalibrates as the relationship evolves.
Payment-time fraud scoring returns approve, step-up authentication or block in under 500 ms — well below the PSD2 SCA timing budget.
Live screening against EU, OFAC, UN and national sanctions, PEPs and adverse media — applied to both parties on cross-border payments.
Alerts are auto-prioritised and packaged into cases with evidence, history and recommended actions. Analysts work in a structured queue, not a spreadsheet.
STR / SAR submission, PSD2 fraud reporting, internal MI and supervisory exports — all generated from the same audit-grade event log.
AI scoring, graph analytics, behavioural baselines and rule scenarios working together — not in silos.
Case management, SLA control and analyst workflow built around how teams actually run AML and fraud.
Every alert, decision and report is fully traceable — explainable to a supervisor, an auditor or a court.
Bucephalus is not a point tool. It is a turnkey, end-to-end platform that detects, disrupts and documents the full spectrum of Illicit Financial Flows (IFF) — every criminal and commercial channel through which illicit value crosses a regulated institution.
Flows arising from or connected to predicate criminal offences.
Card fraud, account takeover, authorised push-payment (APP) fraud, social engineering and identity fraud.
Placement, layering and integration of criminal proceeds — structuring, smurfing, round-tripping, mule networks.
Detection of low-value, dispersed funding patterns aligned with FATF R.5 and EU CFT obligations.
PEP screening, kickback patterns, unexplained wealth flows and politically sensitive counterparties.
Proceeds-of-crime flows from tax evasion, VAT carousel fraud (MTIC) and criminal tax offences.
Typology-driven detection of exploitation-linked payments, recruiter-victim patterns, migrant smuggling channels.
Narco-economy cash-proxy flows, trade-based laundering, bulk cash placement and corridor anomalies.
Ransomware pay-outs, business email compromise (BEC), pig-butchering, crypto off-ramp laundering.
Screening against EU/UN/OFAC, dual-use goods, front companies and proliferation-finance typologies.
Flows arising from tax abuse and commercial manipulation.
Under- and over-invoicing of goods and services to shift value across borders — a primary IFF channel identified by UNCTAD and GFI.
Non-arm's-length intra-group pricing used to erode the tax base. Cross-references OECD BEPS and DAC6 hallmarks.
Layered ownership, nominee directors, opaque trusts — mapped against the EU Central BO Registers and FATF R.24/R.25.
Conduit entities in low- or zero-tax jurisdictions, treaty-shopping and hybrid mismatch patterns.
Oil, metals and agri-commodity trading as vehicles for corruption, kickbacks and value-extraction models.
From the first onboarding check to the final audit export, Bucephalus covers every step that compliance, fraud and risk teams are asked to operate today.
Identity verification, document validation, ultimate beneficial owner discovery and dynamic risk classification — onboarding becomes a control point rather than an open door.
Continuous transaction monitoring combining rule-based scenarios, statistical anomaly detection, behavioural baselines and geographic risk overlays.
Sub-second scoring on every payment with device fingerprinting, behavioural biometrics and transaction context. Decisions returned to the channel: approve, step-up (SCA) or block.
International sanctions and PEP screening with fuzzy matching, transliteration handling and explainable match scores — applied at onboarding and on every relevant payment in real time.
Automatic case creation from alerts, priority queueing, evidence collection and structured decision workflow — the analyst always sees why an alert exists and what to do next.
STR / SAR generation, PSD2 fraud reporting, internal management reports and one-click audit export. Templates align to local FIU requirements across the EEA.
Every decision, model version, rule change and analyst action is captured in an immutable, time-stamped audit log — designed for supervisory inspection and DORA-grade traceability.
No single technique catches modern financial crime. Bucephalus combines four detection layers and surfaces the reason for every alert, so analysts and supervisors can see why, not just what.
Expert-authored scenarios for known typologies — structuring, smurfing, layering, suspicious payment corridors. Tunable per institution and product line, no coding required.
Distribution and threshold deviation against the customer's own history and peer-group baselines. Catches the slow drift that rule libraries always miss.
Supervised gradient-boosted models for fraud scoring and unsupervised models for emerging-pattern discovery. Continuously retrained on confirmed labels and analyst feedback.
Beneficiary, device and counterparty graphs reveal mule networks, fan-out structures and circular flows that look innocent transaction-by-transaction.
A composite score is built from dozens of signals — these are the most influential ones that show up in nearly every alert explanation.
Every alert, score and block carries a structured explanation:
Required by the EU AI Act for high-risk AI systems and by supervisors auditing automated decisioning under DORA.[1][2]
Bucephalus is built as a federated defence network: the Silbad Hub and every bank's Autonomous Station Agent sit on the same peer-to-peer ring and communicate continuously, context-aware, under AI orchestration — not through brittle request-response APIs. Data stays sovereign; intelligence flows.
Bucephalus is not a hub-and-spoke platform. The Silbad Hub and every bank's Autonomous Station Agent sit on the same ring and communicate as peers. Messaging is not request-response; it is continuous, context-aware and governed by AI — peer-to-peer decentralisation, orchestrated by federated AI.
Each Station scores transactions locally at the edge, shares only anonymised patterns across the ring, and benefits from models, typologies and threat intelligence that evolve in real time. The Hub participates as a peer — aggregating, curating, redistributing — not as a gatekeeper or single point of failure.
The Silbad Federated Defence Network is AI-driven, continuously operating, context-aware infrastructure purpose-built for financial-crime defence. It combines peer-to-peer decentralisation — no central data lake, no gatekeeper — with intelligent orchestration: AI decides what flows across the ring, when, and in what context. Raw transaction data stays inside every bank; only anonymised intelligence moves.
Most AML and fraud platforms centralise transaction data in the vendor's cloud — a direct tension with GDPR, banking secrecy and operational resilience under DORA. A federated architecture keeps the data inside every bank, lets local station agents decide at the edge, and uses AI orchestration to share only anonymised patterns across the ring. The result: full sovereignty, verifiable decisions, and a single platform compliance teams can prove is theirs. This direction aligns with public-policy work by FATF (federated analytics for public-private AML information sharing) and the BIS Innovation Hub (Project Aurora / Aurum on privacy-preserving analytics).
Peers exchange context, scores and model updates as an ongoing stream — not one-shot API calls. The ring is always on, always reasoning.
What each peer shares, when, and with whom is governed by AI — not by hard-wired schedules. Relevance, risk and latency shape the flow.
Hub and Station agents are equals on the ring. No central data lake, no gatekeeper, no single point of failure — peer-to-peer decentralisation, applied to banking.
Every Station scores, decides and queues alerts locally. Self-adaptive rule generation and dynamic risk scoring run at the edge, close to the transaction.
Hash-chained audit logs, signed model artefacts and cryptographic attestation make every peer-to-peer message and model update independently verifiable.
Every high-impact decision is explainable and subject to analyst or four-eyes oversight. Continuous AI, deliberate humans — aligned with EU AI Act requirements.
Eight tightly integrated services, sharing a single audit-grade event log.
Scenario-based and statistical AML monitoring with case generation.
Real-time scoring with ML, device intelligence and behavioural signals.
Live screening with fuzzy matching against EU, OFAC, UN and national lists.
Workflow, evidence, decisions and SLA control for analyst teams.
STR / SAR, PSD2 fraud reporting and supervisory exports.
Role- and attribute-based access, MFA, step-up and session control.
OAuth2 / mTLS-protected inbound, outbound, internal and admin APIs.
Immutable, hash-chained event store covering every decision and change.
Bucephalus treats financial-crime tooling as critical ICT infrastructure under DORA[2]: explicit access models, segregation of duties, four-eyes approvals on every irreversible action and a complete trail to back it all up.
Combined RBAC and ABAC: roles define what a user can do, attributes (region, product, risk tier) refine when they can do it. Least-privilege is the default, not the exception.
MFA enforced for every privileged action, with step-up authentication for high-risk operations (rule changes, model deployments, STR submission).
Idle and absolute session timeouts, concurrent-session limits, device binding for administrators and full session telemetry to the audit log.
TLS 1.3 in transit, AES-256 at rest, customer-managed keys (BYOK) optional, and per-tenant cryptographic isolation.
The platform enforces SoD at the role and workflow level — incompatible permissions can't be granted to the same identity, and incompatible actions can't be taken in the same session.
The following actions cannot be taken by a single user. A second authorised reviewer must approve before the change takes effect — and both identities are written to the audit log.
Bucephalus exposes a clear API surface and ships with proven adapters for the systems your bank already runs. Most institutions move from contract to first scored transaction in weeks, not quarters.
Called by core banking, channels and payment systems to submit transactions and receive scoring decisions in real time.
Used by Bucephalus to push STR / SAR submissions, sanctions feedback and supervisory exports to authorities and partner systems.
Service-to-service traffic between detection engines, case management and the audit log — fully meshed with mTLS and SPIFFE identity.
Configuration, rule management, model lifecycle and tenant operations — segregated, audited and protected by step-up authentication.
Temenos, Finastra, Mambu, FIS, Oracle Flexcube, plus custom and legacy host systems via ISO 20022 / proprietary adapters.
Card switch, 3DS server, instant payments (SCT Inst, FedNow), wallets and processor integrations.
SWIFT MT/MX, SEPA, Target2, ISO 20022 — both screening at message ingress and post-event monitoring.
eIDAS, video-KYC vendors, document verification, sanctions and adverse-media data providers.
Streaming via Kafka / Pulsar, batch via S3 / Parquet, BI via standard JDBC, with native Snowflake and Databricks connectors.
SIEM (Splunk, Sentinel, QRadar), IAM (Okta, Entra ID, Keycloak), HSM and KMS, OpenTelemetry-native logging.
Bucephalus is designed around the regulatory reality of European banking — not retrofitted for it. The same audit trail that satisfies your internal audit also satisfies AMLA, the ECB, the EBA and your national supervisor.
Data minimisation & sovereignty by design
Strong Customer Authentication & fraud reporting
Designed to meet AMLD 6 / AMLR requirements
Operational resilience for critical ICT
Aligned with ISO 27001 controls
Transparent, explainable AI decisions
Answer five short questions. The tool will identify the applicable EU and international AML / CFT / fraud regulations and recommend the Bucephalus modules your institution needs to comply. Results are generated in your browser — nothing is transmitted until you choose to send them to us.
Select the option that best describes your licence.
This drives the applicable sector-specific obligations.
Jurisdictional scope drives sanctions, BO and travel-rule obligations.
Customer typology drives enhanced due-diligence and PEP screening requirements.
Volume drives DORA, ICT resilience and supervisory reporting thresholds.
Based on your inputs, the following frameworks apply and the indicated Bucephalus modules are recommended for an audit-ready operation aligned with the applicable rules.
Leave your details below and our team will send you a personalised information pack based on your regulatory profile — including a fit-gap assessment, module recommendations, and a pilot proposal. No obligation, no sales call unless you request one.
We have received your regulatory profile and contact details. Our team will send you a tailored Bucephalus information pack to your email address within one business day.
This assessment is an indicative mapping based on publicly available EU and international standards as of Q1 2026. It does not constitute legal advice. Final regulatory scope must be confirmed with your compliance function and competent authority.
Bucephalus is designed to meet the legislative and supervisory expectations of the European Union, the European Economic Area and the broader cluster of associated and candidate economies. Local language, local currency, local FIU formats — without forking the platform.
Full coverage of the EU acquis: AML Regulation (AMLR), AMLD 6, PSD2 / PSD3 / PSR, EU AI Act, DORA, GDPR and the EBA Guidelines on ML/TF risk factors and on the use of Remote Customer Onboarding (EBA/GL/2022/15).
European Economic Area members applying EU financial-services directives via the EEA Agreement, plus Switzerland which mirrors core AML and prudential standards through bilateral agreements and FINMA rules.
Jurisdictions in the EU enlargement and association process whose AML/CFT and supervisory frameworks are converging with the EU acquis. Bucephalus' rules and reporting templates can be configured for each national FIU.
Aligned with the recommendations of the global standard-setters that shape European supervisory expectations.
The analyst console, customer-facing decisioning messages and regulatory exports localise to the language(s) of each operating jurisdiction. STR / SAR narratives are generated in the FIU's required language with audit-grade translation lineage.
Plus on-request locale onboarding for any additional jurisdiction supported by your operations.
Bucephalus is multi-currency by design. Every amount is stored in its original ISO 4217 code, normalised against trusted reference rates, and used in FX-aware risk scoring and reporting.
Plus all other ISO 4217 currencies — including precious metals (XAU, XAG) and CBDC pilots where applicable.
Every transaction is stored in its original currency and in a configurable reporting currency, with reference-rate snapshots from the ECB, SNB, BoE and national central banks.
Risk thresholds and behavioural baselines are normalised across currencies — a HUF 5 M and a EUR 12 500 transfer trigger comparable scrutiny.
Detection of FX-based laundering patterns: layering through high-volatility corridors, round-trip currency arbitrage, mirror trades and hawala-like structures.
Currency- and corridor-specific sanctions logic (e.g. RUB / BYN restrictions, dual-use export corridors, embargoed counterparties) applied at the message level.
Bucephalus is engineered against measurable operating targets — the same targets that show up in pilot success criteria and production SLAs. Industry baselines for false-positive and detection rates are documented in our references.
Bucephalus is more than software — it's an operating model. Roles, workflows, SLAs and escalation paths are built in, so the platform reflects how supervisors expect AML and fraud to actually run.
Owns AML scenarios, manages alerts, signs off on STR/SAR submissions and is accountable to the supervisor for the bank's AML posture.
Investigates fraud alerts in real time, manages case workflows, calibrates thresholds for fraud-specific scenarios.
Sets the policy framework, reviews controls, runs the four-eyes approval process for high-impact changes.
Reads aggregate dashboards, defines risk appetite by product / segment / region, owns the risk register.
Operates the platform, manages identities, deploys updates and rotates secrets — explicitly separated from any AML or fraud decision authority.
Detection feeds investigation feeds decision feeds reporting — and every step writes to the same audit log.
Inbound events scored in real time across rules, statistics, ML and graph layers.
Alerts auto-routed to the right analyst queue with evidence, history and recommended actions.
Decisions follow defined workflows with mandatory four-eyes approvals on irreversible actions.
STR / SAR, PSD2 fraud reports and supervisory exports generated from the same auditable record.
Designed with equal weight on the technology and the regulation.
Transaction data stays within your infrastructure. Our federated model means intelligence flows, raw data doesn't. Designed to align with GDPR, PSD2 and local banking law — no third-party data sharing required.
Scoring engineered not to slow your transaction pipeline, against the same < 500 ms target we hold ourselves to in our KPIs. While traditional SAR investigations take up to 22 hours per alert, Bucephalus pre-scores and prioritises — so your team spends time on real threats, not noise.
Every institution in the network strengthens every other. Currently, less than 1% of laundered funds are caught globally. Federated pattern sharing multiplies detection power — a fraud pattern recognised at one bank reaches the others with the next model refresh.
Industry-standard AML systems produce 95% false positives — costing 19% of total fraud budgets. In industry studies, AI-based scoring cuts false positives by up to 60%, while 40% fewer customers abandon onboarding due to reduced friction. Sources in the references section.
The pilot is designed to give your AML, fraud and risk leadership a defensible, evidence-based answer to the question “does this work for us?” — without disturbing your live customer experience.
The pilot covers all five core operational areas — not a sliver of the platform.
Joint scoping with your AML, fraud, risk and IT teams. We map data sources, target use-cases, KPIs and acceptance criteria.
Bucephalus Station deployed on-premise or in your private cloud. Identity, network and audit-log integration completed under your change management.
Full traffic mirrored into Bucephalus. The platform scores in parallel without affecting customer journeys, while we tune scenarios to your portfolio.
Bucephalus moves from observation to action on selected segments — typically high-risk corridors or instant-payment flows — under tight monitoring.
Joint review against the agreed KPIs. Outputs include a KPI report, complete audit trail and an operational validation deck for steering committee approval.
Every quantitative claim on this page is grounded in publicly available regulation, supervisory guidance, peer-reviewed research or independent industry studies.
Annex III lists fraud detection and creditworthiness assessment among high-risk AI use-cases, requiring transparency, human oversight and explainability.
https://eur-lex.europa.eu/eli/reg/2024/1689/ojRequirements for ICT risk management, incident reporting, operational resilience testing and third-party risk for EU financial entities.
https://eur-lex.europa.eu/eli/reg/2022/2554/ojIndustry surveys consistently report that 90–99% of AML transaction-monitoring alerts in rule-based systems are false positives — a long-standing finding repeated by multiple vendors and analyst houses.
https://www.flagright.com/post/aml-false-positives-the-95-problem-banks-cant-afford-to-ignorePeer-reviewed and applied research reports detection accuracy in the 92–96% range for deep-learning models on benchmark transaction data, with up to 60% reduction in false positives versus rule-only baselines.
https://www.sciencedirect.com/science/article/pii/S2667305323000509The UN Office on Drugs and Crime estimates that 2–5% of global GDP — roughly USD 800 billion to USD 2 trillion — is laundered annually, of which less than 1% is intercepted.
https://www.unodc.org/unodc/en/money-laundering/overview.htmlAnnual study putting global financial-crime compliance costs above USD 274 billion, with EMEA institutions carrying a disproportionate share.
https://risk.lexisnexis.com/global/en/insights-resources/research/true-cost-of-financial-crime-compliance-studyEU framework for anti-money laundering and countering the financing of terrorism, including the 2024 AML Package establishing AMLA and the AML Regulation.
https://finance.ec.europa.eu/financial-crime/anti-money-laundering-and-countering-financing-terrorism-eu-level_enPayment Services Directive 2, including Strong Customer Authentication and Article 96 fraud reporting requirements; PSD3 / PSR currently in EU legislative process.
https://eur-lex.europa.eu/eli/dir/2015/2366/ojTell us which fits, and we will come back to you with a tailored information pack — confidential, no commitment.