A policy you can actually run
Give Leela a policy. It finds the obligations and takes on the ones it can.
Not sure where to start?
Work with LeelaComplaint Management
Capture every complaint in one register, resolve it on a clock that matches its severity, and keep the sponsor bank informed. Complaints are the component of a compliance program that catches what policies, training, and testing miss.
Continuous intake, severity clocks from 1 to 45 business days, weekly public-channel checks, monthly bank reporting
Compliance Monitoring & Testing
Prove that your controls work on real activity, not just on paper. Continuous monitoring catches exceptions as they happen; periodic sample-based testing shows examiners and the sponsor bank that each control operated during the period.
Continuous monitoring, monthly sampling, quarterly and semi-annual test batteries, quarterly CEO and annual board reports
Risk Assessment
Know where your AML and regulatory risk actually sits, score it, and keep the picture current. The risk assessment is the document every other control traces back to, and the first thing an examiner or a sponsor bank asks for.
Annual AML and regulatory assessments, out-of-cycle refresh on material change, mitigation actions tracked to closure
KYC / CIP / KYB
Know exactly who you onboard, who owns them, and how much diligence each one needs, then keep that picture current. This is the gate that keeps shell companies and sanctioned parties off the platform, and the file an examiner opens first.
Verification before activation, tiered diligence, periodic reviews from quarterly to annual, continuous re-screening
Vendor Management
Know every vendor you depend on, how much risk each one carries, and prove you looked before you signed and keep looking after. Your sponsor bank inherits the risk of your critical vendors, so it approves them, examines them, and expects notice when they change.
Tiered diligence before engagement, sponsor bank approval for critical providers, annual reviews and attestations, quarterly reporting
AML Program
Stand up the written program the sponsor bank relies on: a named officer with real authority, trained staff, an independent test on the calendar, and a board that sees the numbers every quarter. This is the document an examiner reads first and the frame every other AML policy hangs from.
Officer designated in writing, training at hire and annually, independent test annually, board report quarterly, policy review annually
Change Management
Decide which changes are material, review them before they ship, and give the sponsor bank the notice its agreement promises. This is the process an examiner checks when a product launched, a vendor switched, or a policy moved without the bank hearing about it first.
Triage in 3 business days, review in 5, bank notice 10 or 30 business days ahead, validation within 30 days, quarterly log review
Sanctions / OFAC
Screen every customer, owner, and transaction against the OFAC lists, hold anything that looks like a match, and get the sponsor bank the facts it needs to block and report within the hour. Sanctions liability is strict, so the clocks in this policy are the control.
Screening before activation and in real time, daily list updates with re-screening, one-hour match notices, 24-hour false-positive write-ups, quarterly reporting, annual review and training
Issues Management
Put every finding, complaint pattern, audit result, and bank concern into one log, rate it, fix it on a clock that matches its severity, and prove the fix held before closing it. This is how you show the sponsor bank and an examiner that what testing finds gets corrected.
Critical escalation within 1 business day, high within 5, investigation and remediation clocks by severity, quarterly summary to the chief executive, annual report to the board
Transaction Monitoring
Watch every transaction on your rails against a documented rule library, work each alert to a written resolution on a clock, and send the sponsor bank a complete referral package when activity cannot be explained. The bank decides whether to file; your job is to make sure nothing reaches it late, thin, or not at all.
Daily alert review, alerts assigned in 1 day and reviewed in 2, investigations closed in 10, referrals sent in 2, monthly reporting, calibration at 90 days then annually
Incident Response
Know what to do in the first hour of a breach or outage, who decides, and who has to be told by when. The sponsor bank owes its regulator a 36-hour notice, so your clock is shorter than you think, and the incident log is what proves you met it.
Same-day triage, containment within 30 minutes to 8 business hours by severity, immediate and 4-hour bank notices, daily updates, closure report in 10 business days, annual tabletop
Marketing Compliance
Say only what you can prove, in language the sponsor bank has approved, through channels where the recipient agreed to hear from you. This is the gate every ad, page, script, and press release passes through, and the log the bank and an examiner will ask to see.
Review and bank approval per material, consent checks per campaign, accessibility testing and training annually, inventory kept continuously, program review annually
Insurance claims handling
Handle claims fairly and keep a defensible record of each decision.
Track the controls, evidence and open scope questions for California insurance claims.
Insurance licensing and distribution
Verify the people and entities authorized to distribute insurance.
Track the controls, evidence and open scope questions for New York insurance distribution.
Insurance information security
Protect insurer systems and nonpublic information.
Track the controls, evidence and open scope questions for New York cybersecurity.
Insurance privacy and health information
Control personal information, consumer rights and covered health data.
Track the controls, evidence and open scope questions for California insurance privacy; conditional federal HIPAA.
Insurance covered-product AML
Control money-laundering risk in covered insurance products.
Track the controls, evidence and open scope questions for Federal insurance AML.
Insurance annuity sales and best interest
Support appropriate annuity recommendations and supervision.
Track the controls, evidence and open scope questions for Texas annuity recommendations.
Insurance AI and underwriting governance
Govern AI and external data used in underwriting and pricing.
Track the controls, evidence and open scope questions for New York underwriting and pricing.
Insurance financial governance and reporting
Keep insurer financial, risk and governance filings accountable.
Track the controls, evidence and open scope questions for New York insurer reporting.