← Files VeraARCHIVED FILE
privacy/workstreams/aml-review.json
2.69 KB · Oct 5, 2026 · 18:29 UTC
{
"schema_version": 3,
"workstream": "aml-review",
"display_name": "AML review",
"role": "workflow",
"governed_paths": [
"skills",
"scripts",
"references"
],
"governed_shared_paths": [
"vendor/modules/vera_assurance"
],
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"model_context": {
"policy": "real_case_data_may_enter_selected_runtime_model_context",
"classes": [
{
"id": "aml-review-evidence",
"purpose": "Analyse client AML evidence, explanations, prior reviews and proposed decisions",
"content": "Selected original identity, ownership, screening, contractual, accounting and bank evidence; client explanations; previous assessment and decisions; source citations, findings, alternatives, questions, proposed risk rationale and optional existing calculation. Entire selected files may enter the model when needed; no automatic anonymization or fixed excerpt cap. Later review may read the complete prior record and new evidence.",
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
]
}
]
},
"external_boundaries": [
{
"id": "current-source-research",
"kind": "public_research",
"destination": "Current primary and professional public sources selected for the case",
"purpose": "Verify the current source basis for legal and professional proposals",
"content": "Legal or professional research topics, public-source queries and selected source URLs; direct client identifiers are not used in the public research route",
"optional": false,
"requires_confirmation": false,
"runtime_profiles": [
"openai-codex",
"anthropic-cowork"
],
"controls": [
"Record retrieval, version, temporal scope, and reuse status for selected sources.",
"Keep credentials, authentication codes, cookies, screening-provider tokens, and direct client identifiers out of public research."
]
}
],
"security_controls": [
{
"id": "archive-binding",
"control": "The CLI requires a running portable v2 AML archive context and checks selected source paths against exact run receipts before reading them."
},
{
"id": "record-integrity",
"control": "Records bind source hashes, prior client and engagement identity, and exact proposal digests for decisions; content-addressed output never overwrites an earlier record."
}
],
"review": {
"reviewed_at": "2026-09-28",
"reviewed_by": "privacy-surface-review",
"basis": "external_boundary_review_of_workflow_source",
"source_fingerprint": "63d14a872c0befc46df9cf11ba35c9162b219e6c672177a998ed32b144e00c16"
}
}
SHA-256: 9e58d749fccbd99feb91d23b0f270740cedf292a1f249eefbb6ce6e88d71b593