Visena Documentation

AML · customer due diligence · risk classification

Compliance where the work happens.

AML in Visena covers the whole obligation in one place: the risk model your firm authors itself, the kundetiltak — the customer due diligence measures — a case worker runs step by step, the KYC form the customer fills in on their own portal and signs with BankID, and the portfolio that says, at any moment, who is up for review, who is waiting for approval, and who has been flagged.

For firms subject to hvitvaskingsloven, the Norwegian AML Act · audit · accounting · advisory

The map

Three surfaces that feed each other

None of the three stands alone. AML-konfig is the configuration screen that holds the risk model and the KYC forms; the model it publishes is the one a kundetiltak freezes. The class that kundetiltak concludes is the one Risikoklassifisering — risk classification, the portfolio list — shows, and what the portfolio spots is what opens the next cycle. Kundeportalen, the customer portal, is where the customer answers and signs. The order never changes, and every step leaves a trail.

AML-konfig risk model and KYC forms draft → published Kundetiltak five steps · one open at a time deadline 30 days Risikoklassifisering the whole portfolio alert · due date · four eyes Kundeportalen the KYC form · BankID signing frozen at start class registered sent answered signed due date · alert · event opens a new cycle
AML-konfig publishes the model version a kundetiltak freezes at start. The kundetiltak sends the KYC form to Kundeportalen, where the customer answers and signs, and the class it concludes is the one Risikoklassifisering shows. A due date, an alert or an event opens the next cycle — same engine, new reason.

One published model version at a time, one open kundetiltak per customer, and one list that sees all of it.

The surfaces

Who does what, and where

The setup is done once and maintained by a few people. The kundetiltak are run by many, every day. The portfolio is read by the hvitvaskingsansvarlig, the firm's AML compliance officer — and by everyone who wants to know where a customer stands.

Kundetiltak

Five steps, in this order

One kundetiltak per customer is open at a time, it saves as you work, and it has a deadline: 30 days from the company being created at onboarding, 30 days from the opening of a cycle that keeps running. Both deadlines are set per instance.

Step 01

Services

Which services the customer is to have, and whether the company itself is a reporting entity under hvitvaskingsloven. That choice feeds both the risk points and which questions the customer actually gets.

Step 02

Screening

Lookups against Stø, the external screening and monitoring provider (PEP, sanctions, adverse media), and against BRREG, with the actual value and the points for each outcome, next to the company data and the documents. The step is read only: you assess, you do not edit.

Step 03

Dispatch

The KYC form goes to whoever is to answer for the company, by email and optionally SMS. The form version is frozen on the round, and the status track is followed live: Sendt, Åpnet, Påbegynt, Fullført — sent, opened, started, completed.

Step 04

Assessment

The answers are read against the model: points per answer, the grouped score basis, the control measures the model has triggered — and the four-eyes gate when it applies: the oppdragsansvarlig, the engagement partner, approves before the hvitvaskingsansvarlig.

Step 05

Conclusion

The class is registered on the company with the score as its basis, prospects are promoted to customers, the selected projects are created, ongoing measures are put into operation — and the cycle closes with a snapshot that stands.

The risk model

From factors to class

The model is data, not code: the firm decides which factors count, what they are worth, and where the boundaries between the classes fall. The system does the arithmetic — the same way every time.

  • 1Factors and outcomes. Every risk factor (industry, country, ownership, cash intensity, PEP, sanctions, service type) has named outcomes, and every outcome carries points.
  • 2Score. The customer's answers, the screening and the master data give one outcome per factor. The sum — plus a justified manual adjustment, if there is one — is the basis, and it is always shown broken down per factor.
  • 3Class. The score thresholds decide the class. A new configuration ships with three: Lav (low; up to and including 0 points, review every 24 months), Normal (1–29, 18 months) and Høy (high; 30 and above, 6 months). Classes can be changed, added and removed.
  • 4Consequence. The class sets the review interval, decides whether enhanced ongoing monitoring applies, and which control measures are triggered — four eyes among them.
  • 5Foreløpig klassifisering. The preliminary classification: the system recalculates the whole portfolio in the background and shows what the model would say today, side by side with the registered class. A divergence is a decision, not a surprise.
poenggrunnlag · example
# the outcomes are read from the model version the cycle froze
Bransje · høyrisiko-bransje           +15
Land · registrert utenfor EØS         +10
Kontantintensiv virksomhet · Ja        +8
PEP · treff på reell rettighetshaver  +12
Manuell justering · begrunnet          +0
                                   ──────
Sum                              45 poeng

klasse            «Høy»        # 30 and above
gjennomgang       hver 6. måned
kontrolltiltak    fire øyne · forsterket
                  løpende overvåking

The numbers are an example, and the labels are the Norwegian ones on the screen. The factors, the points and the thresholds are the firm's own, and they are read from the model version the kundetiltak froze — not from the one published today.

Verifiability

What matters is that it holds up afterwards

A kundekontroll — customer due diligence under the AML Act — has to be readable in two years, by somebody else, and give the same answer. That is why these four are not settings you can turn off.

Ongoing follow-up

Customer due diligence is not just onboarding

Five triggers open a kundetiltak. They all use the same engine, the same rules and the same assessment surface — only the reason differs, and the reason stays on the cycle for good.

ONB

Onboarding

A new customer or a new prospect. This is the one that runs in the wizard.

PER

Periodic review

The class's own interval has run out. The status track shows OK, due soon or overdue.

HND

Event

An alert from the monitoring: the cycle remembers which alert triggered it.

MAN

Manual reassessment

A press report, a customer meeting or an internal observation — source and description are required.

OFF

Offboarding

The customer relationship ends, with a reminder of the five-year retention duty.

The words

The words you will meet in the screens

The short version. All of them are used throughout the rest of the AML documentation.

  • HVA — hvitvaskingsansvarlig. The AML compliance officer: decides the assessment, sees the MF-rapport reports and approves last when four eyes applies. Appointed per firm.
  • OA — oppdragsansvarlig. The partner responsible for the engagement. Approves before the hvitvaskingsansvarlig when four eyes has been triggered.
  • Kundetiltak. The due diligence itself: one cycle in five steps, with one open at a time per company.
  • Modellversjon. A published risk model version. One draft and one published at a time; the rest are archived and immutable.
  • Spørsmålssett. The question set — the form version that was sent. The answers are always read against that one, never against a newer one.
  • Foreløpig klassifisering. What the model would say today, calculated in the background. Always marked «FORELØPIG» — the registered class is the one that counts.
  • RRH — reell rettighetshaver. The beneficial owner, the person behind the ownership. Proposed from master data in the form, and often the one who answers and signs.
  • MF-rapport. Melding om mistenkelige forhold: the suspicious-activity report to Økokrim, hvitvaskingsloven § 25 and § 26. Recorded as structured data, with a receipt.

Everything in the AML section

Seven pages, in the order the work happens: the setup first, then the daily work, then operations and reporting. Every page exists in English and Norwegian.

Using Visena · AML

Setup

The risk model

AML-konfig, section by section: factors, classes, service areas, controls, the NACE and country tables, recalculation triggers and versioning.

risk-model.html →
Setup

KYC form builder

Building the form the customer signs: question types, sections, conditions and skip rules, answer validation, translations, import and export.

form-builder.html →
Setup

Conditions and skip rules

Section and question conditions in one place: the operators, expression trees and typed operands, the live condition preview, and how a skip rule decides what the customer is asked next.

conditions.html →
Daily work

The kundetiltak wizard

An onboarding cycle end to end: services, screening, dispatch, assessment and conclusion — plus moving a customer onto a newer model version.

customer-measures.html →
Daily work

The KYC portal

What the customer receives and sees: the email and its link, SMS notification, the portal itself, BankID signing, and the status track from Sendt through to Fullført.

kyc-portal.html →
Daily work

Risk classification

The portfolio list: the KPI strip, the table and its sorting, both filter surfaces, the detail panel with its four-eyes approval tab, and the company card.

risk-classification.html →
Operations

Ongoing monitoring

The cycles that keep running — PER, HND, MAN and OFF — the «Vurder syklusen» (assess the cycle) workspace, the approval deep flow, appointing the responsible officer, and deviation alerts.

ongoing-monitoring.html →
Reporting

Reports and exports

The suspicious-activity report to Økokrim, the portfolio report, the Excel export, and country exposure under section 4.

reporting.html →