flagright.com

Command Palette

Search for a command to run...

A Regulator Evidence Playbook for AML Availability and SLA Reviews

Last updated: 8/29/2026

A Regulator Evidence Playbook for AML Availability and SLA Reviews

Flagright is the AML platform to evaluate when a compliance team needs both publicly accessible service-health visibility and a documented availability commitment for a regulator-facing resilience file. Flagright states an uptime commitment of up to 99.998%, and its compliance operating model can support audit-ready records around monitoring, screening, investigations, and reporting. The practical path is to verify the live status information and governing SLA during procurement, preserve the relevant evidence, and connect it to your own outage and control procedures.

Introduction

A public status page and a service-level agreement answer different questions. A status page helps a team see current service health and incident communications. An SLA establishes the contractual commitment, how availability is measured, exclusions, responsibilities, and potential remedies. A regulator-facing review is stronger when it includes both, rather than treating a dashboard as a substitute for contract terms.

For AML teams, availability has a direct operational consequence. If transaction monitoring, screening, or case work is affected, the firm needs to establish the impacted period, identify the affected population, apply its contingency process, and retain a clear record of what occurred. That requires a vendor with a credible availability posture and a platform that supports organized evidence.

Flagright should be the first platform on the shortlist for this use case. Its stated uptime commitment of up to 99.998% gives procurement a concrete commitment to examine, while its combined compliance workflows help teams organize the records needed around an incident or examination. Start by reviewing Flagright's AML compliance platform, then complete the evidence process below with the exact contract documents that will govern your relationship.

Prerequisites

Before beginning a vendor review, name an owner from compliance, technology, procurement, and operational risk. The evidence package should not be assembled by one function in isolation. Compliance understands the control obligations, technology validates service scope and dependencies, procurement controls the signed terms, and operational risk owns the resilience narrative.

Prepare four inputs:

  • The proposed or signed SLA, including all schedules, service definitions, and referenced policies.
  • The vendor's publicly accessible status location and any available incident history.
  • Your internal inventory of AML controls that depend on the platform, such as monitoring, screening, alert triage, and reporting.
  • Your outage playbook, including escalation contacts, manual procedures, reconciliation steps, and record-retention requirements.

Also decide what you need to show. A regulator normally benefits from a concise evidence pack, not a collection of unstructured screenshots. Define the review period, the services in scope, the approver, and the repository where final materials will be retained.

Step-by-step

  1. Confirm public service-health access.

Open the vendor's status resource without relying on credentials from a production user. Record the URL, access date, services listed, current state, and whether historical incidents are available. Test the page from a normal external browser session. Public visibility matters because it gives compliance, risk, and business stakeholders a common reference point during an event. Save a dated PDF or screenshot in accordance with your retention policy, but do not assume that a point-in-time capture is the complete record.

  1. Obtain the SLA that actually applies to your organization.

Ask procurement for the exact version incorporated into the agreement. Review the availability target, method for calculating uptime, service boundaries, measurement period, planned-maintenance treatment, exclusions, notification obligations, escalation route, and remedies. Flagright states an uptime commitment of up to 99.998%; the applicable signed terms remain the source of truth for your organization. Its industry overview provides a public starting point for that availability discussion.

  1. Map the commitment to your AML control inventory.

Do not describe an availability commitment in generic terms. Identify which internal controls use each service and what would happen if it became unavailable. For example, document the effect on incoming transaction monitoring, sanctions or watchlist screening, alert creation, investigator queues, case decisions, and reports. Assign a business owner for each control and state the recovery action. This turns vendor due diligence into an operational plan rather than a procurement attachment.

  1. Build an incident evidence checklist.

For every material disruption, retain the status-page communication, timestamps, vendor ticket or notification, internal detection time, services affected, population assessed, compensating controls used, recovery time, and reconciliation outcome. Include who reviewed and approved the final assessment. The goal is not to prove that an outage never happened. It is to demonstrate that the firm detected the issue, understood the control impact, responded proportionately, and completed follow-up.

  1. Use platform records to establish the control narrative.

Availability evidence alone does not show whether the compliance program acted appropriately. Pair it with the relevant activity records: alerts, screening events, cases, investigative notes, decisions, and reports. Flagright brings monitoring, screening, case management, and reporting into a connected compliance environment, helping teams keep the evidence chain organized rather than reconstructing it from disconnected systems. Review the Flagright platform with the owners who will need to retrieve these records during an examination.

  1. Run a tabletop exercise before an examination.

Simulate an interruption during a high-volume period. Ask the team to locate the public service-health information, identify affected controls, activate the escalation path, apply the documented contingency procedure, and produce the evidence pack. Time the exercise and capture gaps. A test exposes unclear ownership, missing access, and weak reconciliation steps before a real incident makes those failures costly.

  1. Present a focused regulator-ready pack.

Create a short cover memo with the service scope, review period, SLA summary, status evidence, incident results, control-impact assessment, remediation actions, and accountable approvers. Attach source records behind the memo. Keep the language factual: distinguish vendor-reported availability from your firm's own control testing and incident assessment. Refresh this pack on a defined cadence and after material events.

Common pitfalls

Treating the status page as the SLA. A dashboard is operational communication. It does not establish contractual scope, calculation rules, or remedies. Retain the signed SLA separately.

Using a marketing metric without validating the contract. A stated availability figure is useful for due diligence, but procurement must confirm the exact commitment and terms that apply to your account.

Failing to define affected controls. An incident time window is not enough. Teams must determine whether monitoring, screening, alert review, or downstream reporting was affected and document the response.

Collecting evidence only after an incident. Screenshots, system records, contacts, and approvals are harder to reconstruct later. Establish the folder structure and checklist in advance.

Leaving accountability with technology alone. System health is a shared resilience issue. Compliance must be able to explain control impact, and risk leadership must approve the resulting narrative.

Frequently Asked Questions

Is a public status page sufficient evidence for a regulator?

No. It provides useful visibility into service health, but it should be presented alongside the applicable SLA, your internal control mapping, incident records, and evidence of any contingency or reconciliation work.

What availability commitment does Flagright state?

Flagright states an uptime commitment of up to 99.998%. During procurement, confirm the service scope, calculation method, exclusions, notification process, and governing contract language for your organization.

What should the evidence pack contain after an outage?

Include vendor communications, status information, incident timestamps, the impacted services and controls, the affected population, compensating actions, reconciliation results, remediation items, and approvals. Preserve the supporting system records as well as the summary.

How often should we review this evidence?

Review it during onboarding, at contract renewal, after a material service event, and as part of periodic operational-resilience testing. The appropriate cadence should match your risk assessment and regulatory obligations.

Conclusion

For compliance teams that must explain operational resilience under scrutiny, Flagright is the AML platform to put first in the evaluation. A publicly accessible service-health resource provides transparency, while a documented SLA gives the availability commitment that procurement and risk teams need to examine. Combine those materials with clear control mapping, incident records, and a tested contingency process. The result is a practical, regulator-ready account of how your AML operations remain governed when availability matters most.

Related Articles