Visena Documentation
AML

Daily work

The five steps

The five steps of the kundetiltak ("customer measures") wizard, one at a time: pick the services, read the screening, send the KYC form, assess the answers that come back, and conclude with a risk class or a rejection. Every step has one gate, and the server rechecks every gate when you conclude.

The five steps of the kundetiltak wizard, the gate between each pair, and the three outcomes at least one service no gate the form is sent assessment complete 1 · Tjenester pick service areas services 2 · Screening Stø + BRREG screening 3 · Utsendelse KYC form to customer dispatch 4 · Vurdering answers and signing assessment 5 · Konklusjon class and decision conclusion «Be om utdypning» Avbrutt «Avbryt kundetiltak» Avslå reason + comment Opprett kunde class recorded
The five steps, with the gate that has to be in place before you can move on. «Neste» ("next") is never disabled — if something is missing you get a blocker list instead. From Vurdering, «Be om utdypning» sends another round to the customer; Konklusjon ends in «Opprett kunde» or «Avslå», and «Avbryt kundetiltak» closes the cycle without a conclusion from any open step. The keys under the step names are the values step takes in the address.

The frame around the steps — the step rail, the autosave, the score counter, the soft block and the frozen model version — is described in The kundetiltak wizard, along with how you start a cycle. This page takes one step at a time.

Step 1 · Tjenester

  • The card «Hvilke tjenester skal vi yte?» ("which services will we provide?") is a checkbox list of your firm's active service areas from AML-konfig, each with a name, a description and the point contribution («+N p» or «0 p») from the cycle's frozen model.
  • Below the list sits the checkbox «Firmaet er rapporteringspliktig etter hvitvaskingsloven» ("the company is an obliged entity under the AML act", hvitvaskingsloven § 4). The flag feeds flag factors in the model and question filters in the forms, so it decides both points and which questions the customer gets.
  • Every pick autosaves and updates the live score in the bottom bar at once. The gate onwards is at least one service.

Step 2 · Screening

The step is read-only. There is nothing to fill in and no gate — you read what the external lookups returned, and how many points they awarded.

  • Two factor cards: «Oppslag mot Stø» ("lookup against Stø" — PEP, sanctions and adverse media at Stø, the external screening and monitoring provider) and «Oppslag mot BRREG» (the Norwegian company register). Each card has a Faktor/Verdi/Poeng (factor/value/points) table where the outcomes are enriched with actual values — «62.100 Dataprogrammeringstjenester — Normal» — a summary chip «Treff +N poeng» ("hit") or «Ingen treff — 0 poeng» ("no hit"), and an intro that names «AML-konfig vN». The Stø card also shows the status and time of the last run («Søket utføres», «OK, komplett», «OK, delvis», «Genererer rapporter», «Feilet»).
  • «Firmadata & dokumentasjon» ("company data and documentation"): name, organisation number and sanctions chip, a fact box (legal form, year founded, NACE industry code, employees, general manager, chair, business address) and five fixed document cards — AML-rapport (Stø, PDF), Firmaattest (Brønnøysund, PDF), Eierkart (ownership graph), BRREG — enhet and BRREG — kunngjøringer. The PDF cards download and open in a new tab, the register cards open external pages, and a card with no available source is dimmed with «Ikke tilgjengelig» ("not available").
  • «Resultat — personer med offentlige roller (N)» ("result — people holding public roles"): beneficial owners and role holders merged by name. Each row has role chips, «Reell rettighetshaver (27,52 %)» ("beneficial owner"), a PEP chip, a date of birth and the badge «Kjent i Visena siden <år> · N roller». People with a Stø check of their own show «PEP-treff · +N p» or «Ingen treff · 0 p» and a downloadable AML report; rows without a check show «Screening pågår…» ("screening in progress") — nothing is guessed.
  • The data ticks in asynchronously. Switching back to the tab refreshes both the screening and the score, and partial data is tolerated: the step shows what exists.

Step 3 · Utsendelse

This is where you prepare the KYC round and send it. Opening the step prepares the first round against the first published customer-control form. With no published version, the step says «Ingen publiserte kundekontroll-skjemaer. Publiser et skjema i AML-konfig → Skjemabygger først.» ("no published KYC forms — publish one in AML-konfig → Skjemabygger first") — see KYC form builder.

What you prepare

  • «Reelle rettighetshavere» ("beneficial owners", «N forhåndsutfylt fra BRREG» — N prefilled from the company register) gives you full editing of the list: rows prefilled from master data with the source badges BRREG, Manuell or Kunde, and editable fields for identity (name and date of birth, or year of birth only), ownership share, address, country and citizenship, contact details, role and national identity number. Rows can be added and removed, and everything autosaves. At the foot sits the strip «Audit-logg — endringer på RRH-listen» ("audit log — changes to the beneficial owner list") with the system line «Forhåndsutfylt fra Brønnøysundregistrene: N reelle rettighetshavere.»; the full audit trail is kept on the server.
  • «Spørsmål om virksomheten» ("questions about the business", «N spørsmål til kunde · M med forhåndsutfylt kontekst») shows the question set from the chosen form version, filtered on the services and the customer flags, with the threshold amounts already filled in and «↳» indentation for conditional child questions. A version selector switches published version — the switch is confirmed, and context notes and extra questions are discarded. Each question has a note field where you prefill context for the customer.
  • «Tilleggsspørsmål» ("extra questions") are your own free-text questions to the customer. «Legg til spørsmål» creates them, pending items show a «…» badge, and they can be removed again.

The send card

  • The recipient is picked from a dropdown fed by the people from the screening — owners badged «Reell rettighetshaver», role holders with their role — plus «Annen mottaker …» ("other recipient"). Beside it sit the email field and an optional message, and the summary «Klar for utsendelse: X RRH forhåndsutfylt, Y spørsmål med forhåndskontekst, Z tilleggsspørsmål» ("ready for dispatch"). «Send skjemaet» ("send the form") requires a name and an email («Mottaker (navn og e-post) må velges før utsendelse»), confirms the recipient, saves everything pending, and sends.
  • «Annen mottaker» is a role dropdown grouped by relation type, fed by the roles your firm has made available for customer control, plus a person search against the person register. Pick a person and the name, email and phone fill in automatically, and the email can be edited before sending. The role is stored structurally on the round and appears in the dispatch's heading. If the instance has configured no roles for customer control, the dropdown is empty with «Ingen roller er konfigurert for kundekontroll — velg person og skriv rolle manuelt» ("no roles are configured — pick a person and type the role"), and the old free-text field applies.
  • «Kommentar påkrevd ved godkjenning» ("comment required on approval") sets the requirement for this round. The checkbox inherits the form version's default, can be overridden before the round is sent, and applies only while the round is a draft: after sending, the requirement is locked together with the questions. An individual question may still carry its own override from Skjemabygger.
  • «Språk for utsendelsen» ("language for the dispatch") appears when the bound form version has more than one language, with the hint that the recipient sees the form in the chosen language and that texts with no translation appear in the primary language. The choice applies only while the round is a draft — after sending, the language is locked with the round.
  • «Fylles ut av saksbehandler» ("filled in by the caseworker"): if the form version allows it, the send card shows a mode choice — «Utsendelse» or «Fylles ut av saksbehandler». In caseworker mode the recipient, email and SMS are hidden entirely, you answer the questions yourself, and the main button changes to «Fullfør utfylling» ("complete the filling in"), which requires every active question to have an answer. The round goes straight to answered — no portal, no email, no signing — and step 3 counts it as a completed dispatch. The mode is a choice per round, is reset if you change form version, and only forms badged «Kan fylles ut av saksbehandler» can be put in it. Try «Send skjemaet» anyway and it is refused with «Utsendelsen fylles ut av saksbehandler og sendes ikke ut».

Picking a role does not register the person in that role. The role on the round says who the form was sent to, and in what capacity. The recipient is not confirmed as a role holder on the company until the answer is in, and an automatic role link on dispatch is deliberately deferred.

The dispatch is real. With the AML module enabled for the instance, «Send skjemaet» sends an actual email to the recipient — it is the same switch that opens the AML surfaces, and there is no separate brake on the email. Tick «Send SMS-varsel til mottakeren» ("send an SMS notice to the recipient", off by default) and give a mobile number, and an SMS goes out too. With the switch off, the dispatch is recorded and nothing leaves the building.

What the recipient actually gets, and how the round is followed up, is covered in The KYC portal.

After sending

  • The editing is replaced by a read-only panel per round: «Utsendelse N · X spørsmål», a type chip («Innledende kundekontroll» for the initial control or «Oppfølging» for a follow-up), recipient and timestamp, a status pill and a locked version badge with a padlock. The content is assessed in step 4.
  • The status pill and the status track update themselves while you sit in the step: when the customer does something with the round, the chips move without you reloading the page. The refresh covers every round in the cycle, and it never interrupts work in progress — if there are unsaved assessments or conclusion fields, the refresh is deferred until they are saved. If the browser loses its connection, the status is fetched again when it reconnects.
  • The gate onwards is that the form has been sent, and a round completed by the caseworker counts as sent. You can move on to step 4 while the customer is still working — the step then shows a waiting state.

What the statuses mean, what the customer sees in the portal, how logging in and signing work and when reminders go out belong to The KYC portal.

Step 4 · Vurdering

Step 4 is the shared «Vurder syklusen» ("assess the cycle") workspace, run in onboarding mode — the same shell as the operational assessment on the company card (see Risk classification). Since a prospect has no recorded class, the surface shows a «Grunnlag» ("basis") card with a live score summary and the note «Førstegangs kundetiltak — ingen FØR/NÅ-sammenligning» ("first-time kundetiltak — no before/after comparison") instead of before/after rows. The decision and the class still belong to step 5.

The package that comes back

  • A waiting state while the round is out: the card «Skjemaet er sendt til <navn>» ("the form has been sent to") with a round summary and timestamp, and «Du varsles når svaret er signert» ("you will be notified when the answer is signed").
  • Once the answer is in, everything is gathered in one collapsible KYC block with the phase pill «Mottatt · til vurdering / ferdig vurdert · X av Y vurdert» ("received · for assessment / assessed").
  • Beneficial owners in return: one card per person with ownership share, date of birth and «ny RRH fra svaret» ("new beneficial owner from the answer") badges, the person's three PEP self-declarations (self, family, close associate) and the category badges «PEP (Stø)», «PEP (auto-Stø)», «Selvrapportert — du avgjør» ("self-reported — you decide") or «Ingen treff». The default verdicts are «Godkjent» ("approved") and «Be om utdypning» ("ask for elaboration"); self-reported rows get «Avvis · 0 p» ("reject") and «Godta som RCA» ("accept as RCA") instead, where RCA awards the PEP factor's RCA points and a rejected row is not carried into master data when you conclude.
  • The signing receipt shows the signatory, the role and the method, and has an assessment of its own.
  • «Svar på spørsmål — vurdering» ("answers to questions — assessment") lists every active answered customer question with its «↳» hierarchy and the customer's answer rendered per type. Each row has exactly one assessment panel: a verdict selector, an internal comment badged «Påkrevd» ("required") or «Valgfri» ("optional") according to the round's and the question's setting — a rejection and «Be om utdypning» always require a reason — and for «Be om utdypning» a required draft follow-up question.
  • The cursor lands in the text field as soon as you pick a verdict, and picking «Be om utdypning» with the editor already open moves it to the follow-up field — never out of a comment you are in the middle of. If the answer moved a risk factor, the row shows a points chip with the contribution; the wording is "contribution", because a MAX category does not necessarily take it into the total. «Endre» ("change") reopens a locked verdict.

Follow-up rounds

  • The follow-up accordion: pick a follow-up set — a published follow-up form used as an internal checklist, where a switch is confirmed and discards old checklist answers — answer the internal caseworker questions («X av Y interne besvart»), and look at the basket «Oppfølging til kunde (N)» ("follow-up to the customer") holding the pending «Be om utdypning» texts. «Send oppfølging» gathers pending texts and checklist-triggered questions into a new round to the same recipient.
  • Answered follow-up rows sit under the question they elaborate, with «↳» indentation, the round badge «Utsendelse N» and a source pill, so the counter «N oppfølgingssvar venter på vurdering» ("follow-up answers awaiting assessment") points at rows right in front of you. Rows with no parent question in the list — checklist-triggered questions and follow-ups on a beneficial owner row or on the signing — stay in the round panel with their «Utløst av kundens svar: «…»» text. Internal questions triggered by a customer answer are nested the same way.
  • When the customer answers the follow-up, the original verdict is shown with a green «Kunden har svart» ("the customer has answered") marker and the customer's answer, ready for a final assessment.
  • Automatic choice of follow-up set: when no checklist is chosen, the dispatch is answered and exactly one published follow-up set has a name containing the proposed class, that set is chosen automatically with the note «Valgt automatisk fordi foreløpig klasse er <klasse>. Du kan bytte sett.» ("chosen automatically because the provisional class is <class> — you can change set"). A deliberate choice overrides the automation, and changing a chosen set is confirmed as usual.

What has to be finished

  • The completeness list on the step counts «Vurder kundens svar (X av Y vurdert)», «Vurder reelle rettighetshavere …», «Ta stilling til signeringen» ("decide on the signing"), «Besvar interne spørsmål (X av Y besvart)» and «N oppfølgingsrunder venter på svar fra kunden» ("follow-up rounds awaiting the customer's answer").
  • Every answered follow-up question needs a verdict of its own, and a draft «Be om utdypning» — including a text not yet gathered into a round — blocks the conclusion until it has been sent and answered, or deleted. The blocker list counts both explicitly: «N oppfølgingssvar venter på vurdering» and «N utkast til oppfølging må sendes eller slettes».
  • «Avdekket mistenkelige forhold?» ("suspicious matters detected?", hvitvaskingsloven § 26, the duty to report to Økokrim) is an internal note field that autosaves. «Send MF-rapport» opens the dialog «Registrer MF-rapport», and the row lists the reports already registered on the company.
  • Conditional steps: if the frozen model's control measures have triggered conditional steps, step 4 shows the same «Betingede steg» ("conditional steps") card as the operational surface. Each open step is handled with «Behandle →» ("handle" — a conclusion and a reason) or by sending an enhanced KYC form to the customer. Open steps block the conclusion.

Step 5 · Konklusjon

Score and manual adjustment

  • «Klassifisering — poengoversikt» ("classification — score overview") on the left has a large score card where the effective total is the frozen subtotal plus the manual adjustment, coloured by class, with a proposed class pill without a shield and the chip «inkl. manuell ±N» ("including manual"). Below it sit collapsible category groups — Kunde, Screening, Tjeneste, Transaksjon, Annet — with the basis per line.
  • «Manuell justering» is a slider from −25 to +25 with a live sum: «Automatisk X + manuell ±N = effektiv score Y». An adjustment other than 0 requires a reason — «Loggføres i revisjonssporet» ("recorded in the audit trail") — and the text reminds you that «Justeringen løper ut ved neste periodiske gjennomgang» ("the adjustment expires at the next periodic review").
  • «Løpende risikoreduserende tiltak» ("ongoing risk-reducing measures") shows locked rows that are always on, and triggered rows with a reason and an on/off switch. What you switch on here is put into operation when you create the customer.

Four eyes: oppdragsansvarlig before hvitvaskingsansvarlig

The control measure's four-eyes gate (fire øyne) is triggered by three conditions: the proposed class is one of the high classes, the proposed class differs from the recorded class, or the manual adjustment changes the class. The recorded class is read from the last classification, without reading the cycle's own conclusion, so a periodic review that moves a classified customer down, and an adjustment that changes the class, need attestation just as a high class does.

  1. The OA card sits at the top when four eyes is triggered: the checkbox is on and locked, and the card is badged «Påkrevd · steg 1» ("required · step 1"). The HVA card shows only a locked note as long as the OA approval is missing.
  2. «Be om godkjenning fra oppdragsansvarlig» ("ask the engagement partner for approval") goes first. The OA request is never blocked, and an OA rejection can be requested again.
  3. Once OA has approved, «Godkjenning av hvitvaskingsansvarlig» ("approval by the AML officer") opens with a candidate selector and «Send til HVA-godkjenning». The server refuses an HVA request until an approved OA approval exists — a requested, undecided OA is not enough.
  4. The waiting state says «Syklusen kan ikke lukkes mens godkjenningen venter» and shows the decision controls (a comment and Godkjenn or Avslå) to everyone, but only the named approver may decide: anyone else gets «Bare den utpekte godkjenneren kan avgjøre forespørselen».
  5. Approved or rejected is shown with approver, comment and date. After a rejection a new request can be sent.
  • The candidate selector lists every active user, and the company's designated hvitvaskingsansvarlige are preselected where that designation is configured — see Risk classification.
  • If the measure setup does not trigger four eyes, the HVA card reads «Ikke påkrevd» ("not required") and the OA card is optional. The checkbox opens the same flow, and it cannot be cleared once a request exists.
  • With the OA approval missing, the conclusion is blocked with «Oppdragsansvarlig må godkjenne før hvitvaskingsansvarlig — send forespørselen først.» — as one message, not three.

The decision, and what concluding does

  • «Skal vi fortsette med kunden?» ("shall we go on with this customer?") is two radio cards. «Opprett kunde» lists what it entails: prospect → customer, added to monitoring (BRREG and Stø), the risk regime activated, and «Prosjekter som opprettes» ("projects to be created") — project templates linked to the cycle, which can be removed from the list. «Avslå» requires a mandatory reason (Risikoprofil for høy, Sanksjon-treff, PEP-eksponering, Manglende dok., Kommersielt valg, Annet) and a mandatory internal comment of at least 20 characters with a live counter («Mangler N tegn» / «Krav oppfylt»).
  • Concluding happens from the bottom bar and is confirmed per decision: «Opprett kunde og avslutt?» or «Avslå prospektet?». The server rechecks every gate, and if one fails you get the red list «Syklusen kan ikke konkluderes ennå» ("the cycle cannot be concluded yet") naming what is missing — a decision, a reason for the adjustment, the approvals in the right order, an unanswered request that must be decided or withdrawn, an incomplete step 4 assessment, or the rejection reason and comment.
  • On «Opprett kunde» the risk class and the score are recorded as the company's classification basis (and mirrored to the older risk value), the score basis is archived for audit, confirmed beneficial owners are written into the company's master data while rejected ones are skipped, a customer number is assigned, the chosen projects are created, the activated measures are put into operation, and the cycle closes.
  • On «Avslå» the reason and the comment are archived, the company stays a prospect, and the banner does not come back.
  • The end screens replace the wizard for a closed cycle: a green «Syklusen er lukket — <firma> er kunde» ("the cycle is closed — the company is a customer") with a summary (class and score recorded as the baseline, prospect raised to customer, ongoing measures in operation, project created), or a red «Prospektet er avslått» ("the prospect has been rejected") with the reason and the internal comment. Both link «Til firmakortet».