What do supervisors actually fine firms for?
In practice, administrative failures rather than undetected laundering: no current firm-wide risk assessment, an AML policy nobody acknowledged, training with no record, client files with no evidence of who reviewed or approved the decision, and no demonstrable supervision. A routine audit has one purpose: to see whether the administration exists — and whether the team is actually equipped to spot laundering if it happens.
What is the audit-readiness score?
A single percentage showing how much of your AML administration is currently in order, built from codified controls that each pass, fall due or fail. A partner sees the firm's inspection position at a glance; a team member sees exactly what they personally owe.
Does this replace our MLRO?
No. It removes the parts of the job that are clerical — chasing acknowledgements, reconstructing training records, checking whether a risk assessment is still current — so the MLRO spends their time on judgement, which is the part a supervisor actually wants to see evidence of.
How is the risk level on a client decided?
The AI recommends a level for each risk type; your firm's policy governs the final classification. Where they differ, the override is recorded with the rule reference, reason and policy version — defensible and repeatable rather than a matter of individual judgement on the day.
What does the client have to do?
Hand over an ID, as they would anyway. Your colleague photographs it on a phone. For a low-risk client that is the entire experience: no app to install, no form to complete, no chase afterwards.
We don't have a proper AML policy yet.
That is a common starting point. JUSTE creates a personalised ML/TF risk assessment and AML/CTF policy from your services, clients and geographies, which you review, edit and own — then runs it as the engine behind every screening and control. An independent annual audit (the 4-eye principle) is a recommended practice, and your choice.
Does it work with the systems we already use?
JUSTE integrates with Clio Manage: screening starts from a Clio contact or matter and completed reports return to the matter documents, while the governed record stays in JUSTE for supervision and storage. An API is available for other systems.
Where is our data held?
JUSTE AI Ltd is registered as a data processor with the UK Information Commissioner's Office. Data is handled lawfully and minimally with a full audit trail.