AML Open Framework — Competitive Positioning Report¶
Date: 2026-04-27 (refreshed 2026-04-29) · Scope: post-Rounds 5-6 (PR #72), 24 dashboard pages, 991 tests · Companion: 2026-04-fintech-aml-reality.md for the FinTech buyer lens.
Deep-research output commissioned 2026-04-27 after Rounds 5-6 shipped. Author: deep-research-agent. Methodology: ~10 min web research across vendor sites, regulator notices, OSS repos, and industry analyst blogs. Refreshed 2026-04-29 with a buyer-archetype matrix, SR 26-2 effective-date implications, and Compliance Manifest naming consistency. Sources at the bottom of the file.
1. Competitive Landscape¶
Commercial enterprise platforms¶
The 2026 buyer field separates into four archetypes, and the framework competes against each differently.
Veteran rules-plus-ML platforms — NICE Actimize SAM, Oracle FCCM, SymphonyAI Sensa-NetReveal, FIS/SAS AML. These dominate Tier-1 RFPs by default; Actimize-style vendors win on enterprise-scale detection, regulator familiarity, and decades of typology libraries (SymphonyAI 2026 roundup, Alessa 2026 roundup). Differentiator: scale + audit comfort. Where the framework slots in: proof-of-concept tier at large banks (where Actimize's ~18-24-month deploy costs $50M+ TCO per Tookitaki 2025 buyer guide), and as a second-line challenger model for MRM independent re-implementation under SR 26-2.
AI-native challengers — ComplyAdvantage, Hawk:AI, Featurespace (Visa), Feedzai, Lucinity. Hawk:AI raised a $56M Series C in April 2025 and another $10M in Jan 2026 explicitly for "AML-as-a-service" (SiliconAngle 2025-04-08). They differentiate on cloud-native deployment, claimed false-positive reduction (ComplyAdvantage cites 65–85%, ComplyAdvantage TM page), and explainable-AI marketing. The framework slots in adjacent, not opposed — challengers win mid-market RFPs where the framework currently has no commercial sales motion; it competes for the same buyer only when the buyer specifically wants source-available code.
Graph/network specialists — Quantexa, Ripjar, Sayari. Quantexa's "contextual decision intelligence" graph is the marketed differentiator for complex layering investigations. The framework's network_pattern rule plus Mermaid renders is functionally narrower but ships in one binary; Quantexa requires multi-quarter integration. Slot: useful for case-level visualisation, not full graph-DB workloads.
Regtech utilities — Fenergo (KYC orchestration), ComplyAdvantage data, Refinitiv WorldCheck. Mostly orthogonal — they sell data and onboarding, not detection.
Open source / neighbour OSS¶
Three projects are real competitors today:
- Marble (checkmarble/marble) — the only commercially-backed OSS competitor, AGPL/MIT split, real-time decision engine, no-code rule builder, AI investigation assistant (Marble README, Marble docs). Strongest direct alternative; strength is the no-code UX and modern Go/TS stack. Weakness vs. AML Open Framework: no Compliance Manifest as source-of-truth, no MRM bundle, no jurisdiction-specific reporting templates, no deterministic-rerun guarantee.
- Jube (jube-home) — AGPLv3, ML-first (adaptive ANN), real-time scoring + workflow (Jube repo). Differentiates on built-in models. Weakness: ML-first design is exactly what FinCEN's NPRM and SR 26-2 push back against (model risk surface).
- FINOS OpenAML (finos-labs/dtcch-2025-OpenAML) — DTCC hackathon origin, on-chain AML focus, ML-classification of wallets (FINOS OpenAML repo). Narrow scope (crypto wallets), labs-stage, not a TM platform.
Apache Fineract, OpenCRE and Frankfurter are adjacent (core banking, control mappings, FX rates) — none compete on detection.
Internal "build it yourself"¶
Tier-1 / Tier-2 banks predominantly build on Databricks/Snowflake lakehouses with bespoke Spark or SQL rule libraries, plus a commercial alert manager bolted on top (Databricks AML pattern, Tookitaki 2025). Build-cost cited at >$50M/5y; only viable above ~5B txns/month. The framework displaces the rule-authoring + audit-trail + reporting layers of these stacks (which are the parts banks consistently underinvest in), while leaving the lakehouse storage layer untouched. The persona that lands is the second-line model-risk team that needs an independent, reproducible re-implementation to validate the production engine — not the production engine itself.
2. Where the Framework Actually Wins¶
Defensible "every line written by a human" moat. FinCEN's April 2026 NPRM and SR 26-2 (joint Fed/OCC/FDIC, SR 26-2 letter, effective April 17 2026) explicitly fold BSA/AML transaction monitoring, sanctions screening and CDD into the model-risk inventory. ML-first vendors (Hawk, Feedzai, Jube) now carry a model-validation tax on every typology; the framework's Manifest entries with regulation_ref are not models under SR 26-2 — they are policy artefacts. Buyer that lands: second-line MRM/validation function at any Cat-2+ bank, plus FinCEN/OCC examiners.
SR 26-2 effective-date implications (12 days old as of this refresh). SR 26-2 went live 2026-04-17, meaning every Cat-2+ examination cycle from now through end-2026 will test against the new joint framework rather than the 2011 SR 11-7 baseline. The change is not theoretical — three concrete effects: (1) every TM scenario, sanctions screening rule, and customer-risk-rating model is now named model risk and must carry SR-26-2-aligned documentation (validation, ongoing monitoring, change control); (2) examiner Q&A from the FRB and OCC published in the same April 2026 window emphasises independent re-implementation as one of three acceptable validation methods, which is the exact slot the framework's deterministic re-run + hash-chained audit ledger fills; (3) the 12-month implementation tail closes April 2027, so any buyer planning to ship a SR-26-2-aligned program before that deadline starts the procurement decision in Q3-Q4 2026. What this changes for the framework's positioning: the second-line model-risk team isn't just an adjacent persona — they're the natural early-2026 champion. Marble, Jube and the commercial AI-natives all add validation surface; the framework subtracts it.
Deterministic re-run + hash-chained audit ledger. Every commercial platform produces operational logs; none publish a same-Manifest + same-data + same-seed = identical-output guarantee. Combined with the Round-3 MRM bundle (SR 26-2 / OCC 2026-13 aligned), this makes the framework usable as the independent challenger model the new guidance now expects, without buying a second commercial license. Buyer: MRM Director / Chief Model Risk Officer.
ISO 20022 native ingestion (Round 5). SWIFT MX-only cutover was 2025-11-22 (BNY end-of-coexistence note); full structured-address deadline is Nov 2026. Marble, Jube, OpenAML have no ISO 20022 adapter in tree. Commercial — Actimize, ComplyAdvantage, Hawk all support it but as a paid module, not a documented spec. Shipping pacs.008/009/004 + pain.001 + Travel-Rule field validator + 28-row purpose-code reference + 44-row return-reason library as one binary is currently uncontested in OSS and cheaper than any commercial module. Buyer: correspondent-banking / payments-ops team at a challenger or VASP.
Investigation-aggregator vs. alert-centric platforms (Round 6). FinCEN's NPRM language switched to "investigation outcomes" as the unit of effectiveness; deterministic INV-{sha256[:16]} grouping with three explicit strategies plus auto-bundled STR ZIP (network Mermaid + narrative + goAML XML + manifest) is the right shape. Most commercial platforms still measure SAR-per-alert, not investigation-per-typology. Buyer: BSA Officer / FIU lead at challenger banks; also consultancies running pre-exam mock reviews.
One-binary deployability. Pip-installable, DuckDB-in-memory, Streamlit + FastAPI in the same repo. Honest time decomposition: time-to-first-alert on synthetic / sample data measured in minutes; pilot on production data in weeks (data ingestion + mapping + sanity-checking); defensible program (thresholds tuned + 2LoD reviewed + MRM dossier signed) in months. Compared to the 9-24 month commercial deploy window cited in Tookitaki 2025, the framework collapses demo to minutes, pilot to weeks, and defensible to months — not days. Buyer: regtech consultancies (mock RFP-responder kits), fintech compliance teams, academic FinCrime programmes.
Multi-jurisdiction templating. 7 example specs covering US/CA/EU/UK/VASP/cyber-fraud is unmatched in OSS and rare commercially (most vendors charge per-jurisdiction module). Buyer: cross-border challenger banks, EMI/PI applicants needing AMLA-ready evidence.
What it does not win on: real-time sub-second scoring at billions-of-txns scale, sales/support contracts, vendor risk-management process for tier-1 procurement, brand recognition.
2.5. Where the framework lands by buyer archetype¶
The 2026-04-29 landing-quadrant maps four named personas against team size and program complexity. This table maps each persona to the subset of the framework's wins they actually care about — so positioning matches the buyer in front of you, not the average.
| Archetype | Team size · program | Top-3 wins they care about | Wins that don't move the meter |
|---|---|---|---|
| ★ FinTech / EMI applicant (primary platform — landing default) | 1 MLRO, ≤5 FTE compliance · single jurisdiction, single product | (1) Pilot in weeks (vs 9-24 months commercial); demo on synthetic data in minutes (2) Cure-notice / examiner pack via one CLI command — once the program is running — and the investor-DD answer is a query, not a consultant engagement (3) Sponsor-bank cure-notice survival — all controls reproducible, no consultant dependency |
MRM dossier (no 2LoD yet); multi-jurisdiction templating (one regime); sub-second scoring (volume too low) |
| Mid-tier bank · pilot + 2LoD challenger | 5-25 FTE compliance · 2-3 jurisdictions, retail + commercial | (1) Independent challenger model under SR 26-2 — no second commercial license (2) Per-rule MRM dossier + 4-quarter backtester — answers "is rule X earning its keep" without vendor study (3) ISO 20022 native ingestion — faster than commercial paid module |
Cost compression (already have the commercial license sunk); investor-DD packet (not a fundraising motion) |
| Tier-1 bank · MRM challenger model | 50+ FTE compliance · 5+ jurisdictions, complex product mix | (1) Deterministic re-run + hash-chained audit ledger — the only OSS that publishes this guarantee (2) SR 26-2 / OCC 2026-13 aligned MRM bundle — drops into existing 3LoD attestation flow (3) Multi-jurisdiction templating — 7 example specs, AMLA-ready evidence |
Full production engine displacement (Tier-1s won't displace Actimize); no-code UX (have analysts who write SQL) |
| Scaling fintech / VASP · cross-border platform | 5-15 FTE compliance · 3+ jurisdictions, payments + crypto | (1) ISO 20022 + Travel-Rule field validator — uncontested in OSS, paid module elsewhere (2) Investigation-aggregator (INV-grouping + goAML XML export) — matches FinCEN NPRM "investigation outcomes" language (3) Multi-jurisdiction templating — same Manifest scales as the firm enters new geographies |
Sub-second real-time scoring (volume not yet there); brand-recognition signalling for procurement |
Reading guide: The same Manifest, the same engine, the same audit ledger serve all four. What differs is which capabilities are load-bearing in each pitch. A FinTech buyer doesn't care about the MRM dossier yet (no 2LoD); a Tier-1 MRM team doesn't care about time-to-first-alert (procurement runs 18 months regardless). Match the message to the meter.
3. Highest-Leverage Next Features¶
Excluded by memory: generative-AI rule authoring, native graph DB, in-tree alert-scoring ML.
Already on the user's Rounds 7-9 plan but re-ranked with current evidence — the AMLA July 2026 deadline (AMLA portal) and the FinCEN NPRM comment-period closing June 9 2026 (Federal Register 2026-07033) reshuffle the impact ÷ effort math.
#1 — Regulatory-change diff watcher (compliance/regwatch.py) · 3 days · IMPACT/EFFORT: HIGHEST¶
Hash every regulation_ref URL in every shipped spec; alert on drift. Why now: FinCEN BOI was narrowed in March 2025 (FinCEN BOI page) and FinCEN's April 7 2026 NPRM materially rewrites AML program requirements with a 12-month implementation tail — every example spec's regulator reference is at risk of going stale silently. No commercial vendor ships this because they own the rule library themselves; the framework needs it precisely because it doesn't.
Risk: false positives on cosmetic page edits (mitigation: textual-diff threshold + human approval gate).
#2 — AMLA STR/RTS effectiveness telemetry pack (metrics/outcomes.py + examples/amla_rts_2026/) · 6 days · IMPACT/EFFORT: HIGH¶
Alert→case→STR funnel with per-rule precision/recall, packaged against the AMLA RTS due July 10 2026 (AMLA 23 mandates, Protiviti AMLA readiness). FinCEN's NPRM enumerates the same metrics. One feature, two regulators, both with hard 2026 deadlines. Risk: outcome data depends on case-disposition labels the framework doesn't currently demand — needs schema additions to cases, not just metrics.
#3 — TBML + APP-fraud spec pair (examples/trade_based_ml/ + examples/uk_app_fraud/) · 9 days · IMPACT/EFFORT: HIGH¶
TBML covers FATF/Egmont's continuing focus area (cited in the FATF Feb 2026 plenary outcomes); APP-fraud covers the PSR's expanding scope to CHAPS + Q2 2026 joint review. Together they answer the FRAML-convergence buyer question (Hawk FRAML report, Sutherland FRAML 2.0) without building a fraud engine — just demonstrating the framework can express the typologies. Risk: spec authenticity — needs a real practitioner review or it reads as theoretical (mitigation: cite specific PSR / Egmont indicator lists).
#4 — PSD3 / Verification-of-Payee (VoP) ingestion adapter (data/psd3/) · 5 days · IMPACT/EFFORT: MEDIUM-HIGH¶
PSD3 + PSR are expected in the Official Journal end-Q2 2026, with VoP / payee-name-match liability applying 24 months after entry into force (Norton Rose Fulbright PSD3 brief, Linklaters PSD3 update). Lands a payments-ops persona that today has no OSS option. Why now: the 2-year clock is the right window for a reference implementation to exist before banks have to procure one. Risk: spec instability between Council/Parliament agreement and Official Journal publication — mark the adapter "draft" with a version pinned to the agreed text.
#5 — FINTRAC pre-examination audit pack (aml audit-pack --jurisdiction CA-FINTRAC) · 4 days · IMPACT/EFFORT: MEDIUM-HIGH¶
The Canadian Schedule-I bank example spec is already in tree; FINTRAC's January 2026 examination manual update (FINTRAC examination guidance) makes the pre-exam evidence demand explicit. Clones the SR 26-2 MRM-bundle pattern to a second jurisdiction with proven format. Aligns with the user's stated Canadian-bank focus (memory). Risk: small TAM (Canadian FIs only); mitigation is to use it as the template for a 3rd/4th jurisdiction (FCA-UK, BaFin-DE) on the same skeleton.
Notable omissions, ranked by why-not¶
- AMLA central-register sandbox (Round 9 #5). Real signal but the register isn't operational until H2 2026 and the API surface is still in EBA advice. Defer until Q3 2026.
- Notabene/Sumsub Travel-Rule message-bus adapters (Round 7 #4). Already covered by Round 5's Travel Rule field validator at the Manifest layer; the message-bus integration is a vendor-specific runtime feature that bloats the binary.
- FedNow/RTP push-fraud detector pack (Round 8 #2). Genuinely valuable but requires the APP-fraud spec to land first as the shape-template; sequence after #3.
Sources¶
- SymphonyAI: Top 10 AML software for banks in 2026
- Alessa: Top 10 Transaction Monitoring Solutions 2026
- ComplyAdvantage: Best transaction monitoring software 2026
- Tookitaki: Best AML Solutions for Banks 2025
- Hawk:AI Series C, SiliconANGLE 2025-04-08
- Marble (checkmarble/marble) GitHub
- Marble docs
- Jube — open source AML & fraud TM
- FINOS Labs — OpenAML
- Databricks lakehouse AML pattern
- SR 26-2 Revised Model Risk Management guidance, FRB 2026-04-17
- OCC Bulletin 2026-13 — Model Risk Management
- FinCEN AML Program NPRM, Federal Register 2026-04-10
- FinCEN NPRM Fact Sheet (PDF)
- WilmerHale FinCEN NPRM client alert 2026-04-13
- AMLA — major step toward harmonised EU supervision
- Moody's: AMLA & AMLR review 2026
- Protiviti: AMLA Readiness Starts Now 2026-03-16
- STEP: EBA advice on AML standards ahead of AMLA launch
- FATF Plenary outcomes, Feb 2026
- FATF Plenary outcomes, Oct 2025 — AI horizon scan
- PSR APP scams reimbursement dashboard, Q3 2025
- Norton Rose Fulbright: PSD3 / PSR 2026 readiness
- Linklaters: PSD3 breakthrough
- Hawk: FRAML convergence US banks/credit unions
- Sutherland: FRAML 2.0 for Risk & Compliance
- BNY: ISO 20022 end-of-coexistence (Nov 22 2025)
- NICE Actimize: ISO 20022 Nov 2025 deadline
- FINTRAC examination guidance
- FinCEN BOI page