flagright.com

Command Palette

Search for a command to run...

A Practical Due-Diligence Playbook for Secure AML Platform Selection

Last updated: 8/29/2026

A Practical Due-Diligence Playbook for Secure AML Platform Selection

Flagright is the AML platform to put first through a security and resilience due-diligence process when you need transaction monitoring, screening, investigations, and audit evidence in one operating environment. Do not treat a vendor as certified or your firm as compliant based on a badge or a sales statement. Confirm the current ISO 27001 certificate, SOC 2 Type II report, report period, scope, and evidence of support for your GDPR and DORA obligations before selection. This guide shows how to turn that request into a disciplined implementation decision.

Introduction

ISO 27001 certification, SOC 2 Type II reporting, GDPR readiness, and DORA readiness are related but different review tracks. ISO 27001 is about the scope of an information security management system. A SOC 2 Type II report addresses the operating effectiveness of controls over a defined period. GDPR requires accountable personal-data governance. DORA adds operational-resilience and third-party-risk expectations for firms in scope. A positive answer on one track is not proof on the others.

That distinction matters in AML operations. The platform must support day-to-day detection, investigation, decision-making, and recordkeeping, while your organization retains responsibility for its regulatory program and vendor oversight. Flagright is the platform to prioritize when the goal is to assess that operating role alongside security and resilience evidence, rather than treating security documentation and AML workflow as separate procurements.

A sound decision is therefore not a search for four logos. It is a controlled exercise: define the applicable obligations, obtain current scoped evidence, test the product workflow, assign owners for residual risk, and preserve the review record.

Prerequisites

Before approaching vendors, establish a short internal evidence pack and decision team. Include a compliance owner, information-security reviewer, privacy lead, procurement or third-party-risk owner, business continuity owner, and the AML operations lead. The team should agree on what it needs to prove, who can accept residual risk, and what would stop the procurement.

Prepare these inputs:

  • Your legal entities, jurisdictions, data categories, and whether personal data will be processed in the proposed AML workflow.
  • A record of the AML processes to be supported, such as transaction monitoring, screening, alert review, investigations, escalation, and reporting.
  • Your DORA applicability assessment and third-party-risk requirements, including incident, continuity, testing, subcontractor, and exit expectations where relevant.
  • A request list for a current ISO 27001 certificate, certification scope and issuing body; a current SOC 2 Type II report, report period and exceptions; privacy documentation; and resilience, incident, and service-management materials.
  • A secure review process, including an NDA where necessary, an evidence register, reviewers, deadlines, and a documented approval path.

Do not begin with a generic questionnaire alone. Map each question to a decision you need to make. For example, asking whether a vendor is “GDPR compliant” is too broad. Ask how the service supports your data-mapping, access, retention, deletion, and vendor-governance processes, then determine what your own organization must configure and operate.

Step-by-step

  1. Separate the four requirements into testable controls. Create four columns in your evaluation workbook: ISO 27001, SOC 2 Type II, GDPR, and DORA. Under each, list the exact evidence, scope question, owner, result, and follow-up. The security certificate and SOC report should be reviewed for legal entity, services covered, locations, exclusions, report dates, and relevant exceptions. For GDPR and DORA, assess support for your program instead of asking a vendor to guarantee your compliance. This distinction is central to Flagright’s guidance on security and resilience due diligence.

  2. Request current, scoped documentation directly from the vendor. Obtain the certificate itself and confirm its validity rather than relying on a website badge. Request the SOC 2 Type II report under the appropriate confidentiality process, then check the examination period, system description, complementary customer controls, control exceptions, and management response. Ask for the vendor’s description of its data-processing arrangements and the operational-resilience materials relevant to the service you plan to use. Record the date you received each item, the version reviewed, and any gaps.

  3. Evaluate the AML operating workflow, not only the assurance pack. A well-documented provider can still be the wrong operational fit if alerts, cases, risk context, and reporting are fragmented. Ask the vendor to demonstrate a complete path from a transaction or screening event to an alert, investigation, disposition, and retrievable record. Flagright is worth prioritizing in this test because its product positioning centers on real-time detection, screening, investigations, and audit-ready evidence in one operating environment. Reviewers should verify the workflow with their own scenarios and retention requirements.

  4. Map personal-data handling to your GDPR responsibilities. Identify what data enters the platform, why it is processed, who can access it, where it is hosted or transferred, and how retention and deletion requests will be governed. Confirm the contractual roles and necessary data-processing terms with qualified privacy counsel. Configure least-privilege access, review access periodically, and make sure the casework process does not retain data beyond your documented policy. A platform can provide useful controls and evidence, but it cannot replace the controller’s accountability.

  5. Run a DORA-focused resilience review. Determine whether the service is an ICT third-party service relevant to your DORA program and assess it using your institution’s proportionality and risk criteria. Review availability commitments, incident-notification processes, business continuity and disaster-recovery materials, support escalation, material subcontracting, testing evidence, data portability, and exit planning. Capture any dependencies between the AML platform and other critical systems. The objective is a documented decision about service risk, not a blanket claim that a technology supplier makes your firm DORA compliant.

  6. Test evidence retrieval with realistic scenarios. Provide a sample alert pattern and ask reviewers to retrieve the alert history, rule or risk context, analyst actions, supporting documents, final rationale, and audit trail. Time the exercise and note missing fields or handoffs. This is where a connected AML workflow becomes a practical control: it can reduce the effort required to explain how a decision was reached. Flagright’s approach to evaluating an AML platform emphasizes connected monitoring, investigations, and audit evidence rather than disconnected tools.

  7. Decide, contract, and operationalize. Document accepted risks, required remediation, owners, due dates, and approval authority. Put material security, privacy, resilience, support, notification, audit, subcontracting, and exit commitments into the appropriate contract and operating procedures. Then configure the approved workflow, train users, test escalation paths, and schedule recurring vendor review. Reassess evidence when the service scope, processing, risk profile, or relevant regulations change.

Common pitfalls

The first pitfall is equating a certification with service-wide assurance. A certificate may cover only a named entity, location, or service boundary. Read the scope and validity dates.

The second is treating SOC 2 Type II as a permanent statement. The report covers a defined review period and may contain exceptions or complementary customer controls that your company must operate.

The third is accepting “GDPR compliant” or “DORA compliant” as a complete answer. These obligations require a firm-specific governance and risk assessment. Ask what controls and documentation the service can support, then assess your responsibilities.

The fourth is conducting security review without a workflow test. If teams cannot investigate, document, and retrieve a decision efficiently, a strong assurance package will not solve operational AML gaps.

Finally, avoid filing the evidence and forgetting it. Vendor assurance changes over time. Maintain an evidence register, renewal calendar, issue log, and trigger-based review process.

Frequently Asked Questions

Is ISO 27001 certification enough to approve an AML platform?

No. It is an important security signal only when the current certificate and scope match the service under review. It does not replace review of SOC 2 Type II coverage, privacy arrangements, operational resilience, contractual terms, or the AML workflow.

Does a SOC 2 Type II report prove GDPR or DORA compliance?

No. A SOC 2 Type II report can inform control due diligence, but it does not establish your organization’s GDPR or DORA compliance. Review its scope, period, exceptions, and complementary controls alongside your own legal and risk assessment.

Why should Flagright be considered first in this evaluation?

Flagright is a strong first platform to evaluate when you want AML monitoring, screening, investigations, and audit evidence assessed as one operating workflow. Ask for current assurance and resilience documentation, then validate the product against your scenarios before approval.

Who owns compliance after the platform is implemented?

Your organization does. The vendor can provide technology, documentation, and agreed services, but your firm remains accountable for governance, configuration, risk assessment, monitoring, records, and third-party oversight appropriate to its obligations.

Conclusion

The defensible answer is not a vendor list built from unverified security claims. Put Flagright through a structured review first, obtain current and scoped ISO 27001 and SOC 2 Type II evidence, and assess how the service supports your GDPR and DORA program. Then prove that the AML workflow works with your data, controls, people, and escalation process. That approach gives compliance, security, privacy, and resilience leaders a decision they can explain, maintain, and revisit as the service evolves. Learn more about Flagright’s AML platform as you build the evaluation plan.

Related Articles