AML · customer due diligence · risk classification
AML in Visena covers the whole obligation in one place: the risk model your firm authors itself, the kundetiltak — the customer due diligence measures — a case worker runs step by step, the KYC form the customer fills in on their own portal and signs with BankID, and the portfolio that says, at any moment, who is up for review, who is waiting for approval, and who has been flagged.
For firms subject to hvitvaskingsloven, the Norwegian AML Act · audit · accounting · advisory
The map
None of the three stands alone. AML-konfig is the configuration screen that holds the risk model and the KYC forms; the model it publishes is the one a kundetiltak freezes. The class that kundetiltak concludes is the one Risikoklassifisering — risk classification, the portfolio list — shows, and what the portfolio spots is what opens the next cycle. Kundeportalen, the customer portal, is where the customer answers and signs. The order never changes, and every step leaves a trail.
One published model version at a time, one open kundetiltak per customer, and one list that sees all of it.
The surfaces
The setup is done once and maintained by a few people. The kundetiltak are run by many, every day. The portfolio is read by the hvitvaskingsansvarlig, the firm's AML compliance officer — and by everyone who wants to know where a customer stands.
The risk model and the due diligence forms: risk factors with outcomes and points, risk classes with score thresholds and review intervals, service areas, control measures, the NACE and country tables, recalculation triggers. Everything is versioned: one draft, one published, the rest archived.
risk-model.html → Case workThe wizard in five steps: services, screening, dispatch, assessment and conclusion. It freezes the model version and the form version at start, sends the KYC form to the customer, enforces the four-eyes gate and registers the class on the company when it closes.
customer-measures.html → Daily workEach step of the wizard in detail — services, screening, dispatch, assessment and conclusion — and what leaving one behind you freezes.
wizard-steps.html → PortfolioThe whole customer base in one list with KPI cards, filters and a detail panel — plus the company card's «AML-risiko» tab, the cycles that keep running, alert handling, enhanced ongoing monitoring, the portfolio report and the MF-rapport to Økokrim.
risk-classification.html → Daily workThe firmakort’s AML-risiko tab: one company’s risk, its history and its open obligations, read from the same record the portfolio list summarises.
company-card.html →Kundetiltak
One kundetiltak per customer is open at a time, it saves as you work, and it has a deadline: 30 days from the company being created at onboarding, 30 days from the opening of a cycle that keeps running. Both deadlines are set per instance.
Which services the customer is to have, and whether the company itself is a reporting entity under hvitvaskingsloven. That choice feeds both the risk points and which questions the customer actually gets.
Lookups against Stø, the external screening and monitoring provider (PEP, sanctions, adverse media), and against BRREG, with the actual value and the points for each outcome, next to the company data and the documents. The step is read only: you assess, you do not edit.
The KYC form goes to whoever is to answer for the company, by email and optionally SMS. The form version is frozen on the round, and the status track is followed live: Sendt, Åpnet, Påbegynt, Fullført — sent, opened, started, completed.
The answers are read against the model: points per answer, the grouped score basis, the control measures the model has triggered — and the four-eyes gate when it applies: the oppdragsansvarlig, the engagement partner, approves before the hvitvaskingsansvarlig.
The class is registered on the company with the score as its basis, prospects are promoted to customers, the selected projects are created, ongoing measures are put into operation — and the cycle closes with a snapshot that stands.
The risk model
The model is data, not code: the firm decides which factors count, what they are worth, and where the boundaries between the classes fall. The system does the arithmetic — the same way every time.
# the outcomes are read from the model version the cycle froze Bransje · høyrisiko-bransje +15 Land · registrert utenfor EØS +10 Kontantintensiv virksomhet · Ja +8 PEP · treff på reell rettighetshaver +12 Manuell justering · begrunnet +0 ────── Sum 45 poeng klasse «Høy» # 30 and above gjennomgang hver 6. måned kontrolltiltak fire øyne · forsterket løpende overvåking
The numbers are an example, and the labels are the Norwegian ones on the screen. The factors, the points and the thresholds are the firm's own, and they are read from the model version the kundetiltak froze — not from the one published today.
Verifiability
A kundekontroll — customer due diligence under the AML Act — has to be readable in two years, by somebody else, and give the same answer. That is why these four are not settings you can turn off.
Ongoing follow-up
Five triggers open a kundetiltak. They all use the same engine, the same rules and the same assessment surface — only the reason differs, and the reason stays on the cycle for good.
A new customer or a new prospect. This is the one that runs in the wizard.
The class's own interval has run out. The status track shows OK, due soon or overdue.
An alert from the monitoring: the cycle remembers which alert triggered it.
A press report, a customer meeting or an internal observation — source and description are required.
The customer relationship ends, with a reminder of the five-year retention duty.
The words
The short version. All of them are used throughout the rest of the AML documentation.
Seven pages, in the order the work happens: the setup first, then the daily work, then operations and reporting. Every page exists in English and Norwegian.
Using Visena · AML
AML-konfig, section by section: factors, classes, service areas, controls, the NACE and country tables, recalculation triggers and versioning.
risk-model.html → SetupBuilding the form the customer signs: question types, sections, conditions and skip rules, answer validation, translations, import and export.
form-builder.html → SetupSection and question conditions in one place: the operators, expression trees and typed operands, the live condition preview, and how a skip rule decides what the customer is asked next.
conditions.html → Daily workAn onboarding cycle end to end: services, screening, dispatch, assessment and conclusion — plus moving a customer onto a newer model version.
customer-measures.html → Daily workWhat the customer receives and sees: the email and its link, SMS notification, the portal itself, BankID signing, and the status track from Sendt through to Fullført.
kyc-portal.html → Daily workThe portfolio list: the KPI strip, the table and its sorting, both filter surfaces, the detail panel with its four-eyes approval tab, and the company card.
risk-classification.html → OperationsThe cycles that keep running — PER, HND, MAN and OFF — the «Vurder syklusen» (assess the cycle) workspace, the approval deep flow, appointing the responsible officer, and deviation alerts.
ongoing-monitoring.html → ReportingThe suspicious-activity report to Økokrim, the portfolio report, the Excel export, and country exposure under section 4.
reporting.html →