Bucephalus is built around the regulatory obligations your team actually works against: EU AMLR / AMLD6, the AML Authority (AMLA) regime, EBA Guidelines, sanctions screening and national FIU reporting. Every alert arrives with its detection rationale, every case with an auditable decision trail, and every report in the format your FIU expects.
Compliance claims on this page map directly to EU AMLR, AMLD6, EBA ML/TF Risk Factors Guidelines and applicable national FIU reporting regimes. Coverage per jurisdiction is agreed in scope during the pilot.
Bucephalus is designed around the regulatory reality of European banking — not retrofitted for it. The same audit trail that satisfies your internal audit also satisfies AMLA, the ECB, the EBA and your national supervisor.
Data minimisation & sovereignty by design
Strong Customer Authentication & fraud reporting
Designed to meet AMLD 6 / AMLR requirements
Operational resilience for critical ICT
Aligned with ISO 27001 controls
Transparent, explainable AI decisions
No single technique catches modern financial crime. Bucephalus combines four detection layers and surfaces the reason for every alert, so analysts and supervisors can see why, not just what.
Expert-authored scenarios for known typologies — structuring, smurfing, layering, suspicious payment corridors. Tunable per institution and product line, no coding required.
Distribution and threshold deviation against the customer's own history and peer-group baselines. Catches the slow drift that rule libraries always miss.
Supervised gradient-boosted models for fraud scoring and unsupervised models for emerging-pattern discovery. Continuously retrained on confirmed labels and analyst feedback.
Beneficiary, device and counterparty graphs reveal mule networks, fan-out structures and circular flows that look innocent transaction-by-transaction.
A composite score is built from dozens of signals — these are the most influential ones that show up in nearly every alert explanation.
Every alert, score and block carries a structured explanation:
Required by the EU AI Act for high-risk AI systems and by supervisors auditing automated decisioning under DORA.[1][2]
Bucephalus is more than software — it's an operating model. Roles, workflows, SLAs and escalation paths are built in, so the platform reflects how supervisors expect AML and fraud to actually run.
Owns AML scenarios, manages alerts, signs off on STR/SAR submissions and is accountable to the supervisor for the bank's AML posture.
Investigates fraud alerts in real time, manages case workflows, calibrates thresholds for fraud-specific scenarios.
Sets the policy framework, reviews controls, runs the four-eyes approval process for high-impact changes.
Reads aggregate dashboards, defines risk appetite by product / segment / region, owns the risk register.
Operates the platform, manages identities, deploys updates and rotates secrets — explicitly separated from any AML or fraud decision authority.
Detection feeds investigation feeds decision feeds reporting — and every step writes to the same audit log.
Inbound events scored in real time across rules, statistics, ML and graph layers.
Alerts auto-routed to the right analyst queue with evidence, history and recommended actions.
Decisions follow defined workflows with mandatory four-eyes approvals on irreversible actions.
STR / SAR, PSD2 fraud reports and supervisory exports generated from the same auditable record.
Bucephalus is designed to meet the legislative and supervisory expectations of the European Union, the European Economic Area and the broader cluster of associated and candidate economies. Local language, local currency, local FIU formats — without forking the platform.
Full coverage of the EU acquis: AML Regulation (AMLR), AMLD 6, PSD2 / PSD3 / PSR, EU AI Act, DORA, GDPR and the EBA Guidelines on ML/TF risk factors and on the use of Remote Customer Onboarding (EBA/GL/2022/15).
European Economic Area members applying EU financial-services directives via the EEA Agreement, plus Switzerland which mirrors core AML and prudential standards through bilateral agreements and FINMA rules.
Jurisdictions in the EU enlargement and association process whose AML/CFT and supervisory frameworks are converging with the EU acquis. Bucephalus' rules and reporting templates can be configured for each national FIU.
Aligned with the recommendations of the global standard-setters that shape European supervisory expectations.
The analyst console, customer-facing decisioning messages and regulatory exports localise to the language(s) of each operating jurisdiction. STR / SAR narratives are generated in the FIU's required language with audit-grade translation lineage.
Plus on-request locale onboarding for any additional jurisdiction supported by your operations.
Bucephalus is multi-currency by design. Every amount is stored in its original ISO 4217 code, normalised against trusted reference rates, and used in FX-aware risk scoring and reporting.
Plus all other ISO 4217 currencies — including precious metals (XAU, XAG) and CBDC pilots where applicable.
Every transaction is stored in its original currency and in a configurable reporting currency, with reference-rate snapshots from the ECB, SNB, BoE and national central banks.
Risk thresholds and behavioural baselines are normalised across currencies — a HUF 5 M and a EUR 12 500 transfer trigger comparable scrutiny.
Detection of FX-based laundering patterns: layering through high-volatility corridors, round-trip currency arbitrage, mirror trades and hawala-like structures.
Currency- and corridor-specific sanctions logic (e.g. RUB / BYN restrictions, dual-use export corridors, embargoed counterparties) applied at the message level.
Answer five short questions. The tool will identify the applicable EU and international AML / CFT / fraud regulations and recommend the Bucephalus modules your institution needs to comply. Results are generated in your browser — nothing is transmitted until you choose to send them to us.
Select the option that best describes your licence.
This drives the applicable sector-specific obligations.
Jurisdictional scope drives sanctions, BO and travel-rule obligations.
Customer typology drives enhanced due-diligence and PEP screening requirements.
Volume drives DORA, ICT resilience and supervisory reporting thresholds.
Based on your inputs, the following frameworks apply and the indicated Bucephalus modules are recommended for an audit-ready operation aligned with the applicable rules.
Leave your details below and our team will send you a personalised information pack based on your regulatory profile — including a fit-gap assessment, module recommendations, and a pilot proposal. No obligation, no sales call unless you request one.
We have received your regulatory profile and contact details. Our team will send you a tailored Bucephalus information pack to your email address within one business day.
This assessment is an indicative mapping based on publicly available EU and international standards as of Q1 2026. It does not constitute legal advice. Final regulatory scope must be confirmed with your compliance function and competent authority.