How Semak AML works
Semak AML is a name-screening gateway. It does not keep its own watchlist database and does not do its own matching. It sends each name you enter to a third-party screening data provider, shows you the potential matches that come back, and helps your staff record their review.
The screening flow
-
Sign in
Your staff log in with a password and a one-time code sent by email.
-
Enter the name
Enter the name of the individual or organisation and the identifying details the form asks for, such as date of birth and ID or passport number for an individual. These help tell apart people with similar names.
-
We ask the data provider
Our servers send the search to a configured third-party screening data provider. If the main provider is unavailable, a backup provider may be used. Your browser never connects to the provider directly.
-
See potential matches
The potential matches returned by the provider are shown as received, with the details the provider supplies, for your review.
Your review
Before generating the report, your staff can record a review decision for the result and add notes. Each review is attributed to the named user who entered it.
Semak AML does not make the match decision. You make the decision. Once the PDF report is generated, the screening record is locked and the review and notes can no longer be changed.
The PDF report
For each search you can generate a PDF report that includes:
- the name searched and the details entered;
- the date and time of the search;
- which data provider was used, and whether a backup provider was used;
- the result summary and potential match details returned by the provider;
- your review decision and notes, if entered (otherwise the report says the result was not reviewed before the report was generated);
- your organisation's name, the date and time the report was generated, and a unique report ID;
- a disclaimer explaining that results come from third-party data providers.
The report is a point-in-time snapshot. You can download it for a limited period after it is generated (currently 7 days). Please download it and keep a copy in your own records for as long as your organisation is required to. Semak AML is not your record-keeping system.
Prepaid tokens
Semak AML uses prepaid tokens: 1 token = 1 name search. If a search fails because of a platform or provider error, the token is credited back automatically.
Affordable prepaid tokens — contact us for pricing.
Security basics
- Two-step login. A password plus a one-time code sent by email. A browser you have signed in from before can be remembered for a limited time. The platform's most privileged administrator accounts use an authenticator app instead.
- Client separation. Each client organisation's users, searches and reports are kept separate from every other client's, enforced in the application and again in the database.
- Encrypted connections. The platform is served over HTTPS.
- Sign-in protection. Repeated failed sign-in attempts temporarily lock the account.
- Provider credentials. Data provider access keys are stored encrypted and are never shown to client users.
- Name-free emails. Notification emails do not include the names you screened.
What Semak AML is not
- It is not a watchlist database or a matching engine. Results come from third-party data providers.
- It is not a compliance determination, a legal opinion or a regulatory clearance.
- It is not your record-keeping system.
- It is not affiliated with Bank Negara Malaysia.
Semak AML helps you meet your screening obligations and supports your customer due diligence. Your organisation remains responsible for its own AML/CFT decisions and records.