INGEST → MATCH → DETECT → CLASSIFY → GOVERN → REPORT. Each stage is obligation-aware: it knows which regulatory citation applies, what the SLA window is, and what the consequence of breach looks like.
Parses raw settlement files in ISO 8583, ISO 20022, NACHA, and proprietary batch formats. Normalises into the Connexum canonical transaction model. Tags each record with participant source, timestamp, and schema version.
Pairs authorisation records against clearing and settlement legs. Produces matched pairs, partial matches, and unmatched suspense entries. Resolves multi-leg transactions and reversals.
Runs all ten detection modules against the matched transaction set. Modules are independent and parallelisable. Each module emits a typed finding with citation, SLA window, and consequence level.
Assigns each finding to its regulatory obligation. Maps BSA, Reg E, OFAC, PCI, Visa VDR, MC MDR to the responsible participant. Produces the obligation schedule for GOVERN stage.
Enforces SLA clocks. Escalates approaching deadlines. Initiates freeze protocols on OFAC match. Triggers SAR filing windows. All actions are append-only to the audit ledger.
Generates participant-scoped reports, audit-trail exports, regulatory filing packages, and the Connexum state snapshot. All outputs are signed and append-only. Supports API pull and push delivery.
Connexum runs a deterministic obligation clock for every active finding. Clock state survives restarts. SLA windows are indexed by citation, not configuration — the regulation IS the scheduler input.
| Regulation | SLA Window | Consequence of breach | Connexum action |
|---|---|---|---|
| BSA 31 CFR §1020.320 | 30 days | Criminal exposure + FinCEN civil penalty up to $25K/day | SAR-window alert at day 20; package assembled at day 25 |
| Reg E §205.11 | 10 business days | Mandatory provisional credit + reimbursement of any losses | Provisional-credit clock started on dispute receipt; escalation at day 8 |
| OFAC 31 CFR Part 560 | Immediate | Civil penalty up to $311K per violation + criminal referral | Same-day freeze trigger on SDN match; OFAC notice package generated |
| PCI DSS v4.0 Req.10.7 | 12 months | Card-brand fine + loss of merchant / issuer privilege | Continuous log-chain audit; retention calendar enforced |
| Visa VDR | 30 days | Network penalty + dispute liability shift | Stuck-transaction flag at day 20; VDR report at day 28 |
| MC MDR | 45 days | Chargeback liability shift + network penalty | Batch-discrepancy flag at EOD; MDR report at day 40 |
Each module is independently configurable, citation-anchored, and tested against 15 adversarial breakage datasets.