Lynx AML logo
Security Fraud · Data Governance Quality

Lynx AML

Lynx AML is a modular anti-money-laundering suite for financial institutions, combining customer and payment screening, transaction monitoring and tailored watchlist delta lists. It applies NLP and AI to name matching to cut false positives while keeping decisions auditable.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is Lynx AML?

Lynx AML is the anti-money-laundering line of Lynx, a Spanish vendor based in Boadilla del Monte, near Madrid, that also sells fraud prevention and money-mule detection. It is sold to financial institutions as four named modules that can be bought and deployed separately: Lynx Customer Screening for onboarding and lifecycle checks against sanctions, PEP, watchlist and adverse-media sources; Lynx Payment Screening to identify and block payments involving prohibited entities; Lynx AML Transaction Monitoring, delivered as an API module that plugs into a case-management system the institution already runs; and Lynx Tailored Delta List, which builds a watchlist change list matched to the institution's own policy and refreshes it daily.

The technical argument centres on name matching. Lynx says its engine uses natural language processing to cleanse, standardise and enrich watchlist names, generating millions of variations across more than a hundred languages, then narrows the search with an AI similarity score. The variations it claims to handle include homophones such as Sara and Sarah, cultural spellings such as Muhammad and Mohamad, different alphabets, partial company names, compound patterns such as De la Cruz, and deliberate misspellings. The stated aim is to widen coverage first and tighten second, so that fewer genuine payments are stopped.

Around that engine sit a no-code rule builder supporting nested and typology-driven rules with risk-based thresholds, a sandbox that predicts how a rule change would affect alert volumes, an embedded case-management layer that classifies and assigns alerts automatically, and real-time reporting dashboards. Lynx positions all of this as AI with guardrails: rules are not hard-coded, configuration changes are logged, and the vendor presents explainability to regulators as a design goal rather than an afterthought. The platform is described as ISO 20022 native while remaining compatible with MT formats, and its product sheet calls the architecture API-first and headless.

The published performance figures are the vendor's own and are not independently audited: under one per cent false positives, over ten million name variations analysed, sub-second average response, and hundreds of transactions screened per second. Lynx has been listed by outside analysts, including as a Representative Vendor in Gartner's 2025 Market Guide for Anti-Money Laundering and as Best of Breed by Chartis.

What it does

  • Screen customers against sanctions, PEP, watchlist and adverse-media sources in real time or in batch
  • Screen and block payments involving prohibited or sanctioned entities
  • Monitor transactions with nested, typology-driven rules and risk-based thresholds
  • Generate a tailored watchlist delta list, refreshed daily, and reconcile changes in a single view
  • Simulate new rules and thresholds in a sandbox before pushing them to production
  • Triage, assign and investigate alerts in a configurable case-management workflow
  • Track AML operations through real-time KPI and KRI dashboards
Audience

When to use Lynx AML / When not to

A quick filter to help you decide if Lynx AML is the right fit.

When to use Lynx AML

  • Compliance teams at banks, fintechs and payment processors that carry AML and counter-terrorist-financing obligations
  • Institutions drowning in false positives from legacy name-screening engines and looking to narrow alerts without missing risk
  • Financial institutions that want to add intelligence on top of an existing AML stack rather than rip it out and replace it
  • Organisations that must explain and defend every screening rule to a regulator or an auditor
  • Firms moving to ISO 20022 payment formats while still running MT messages in parallel

When not to use Lynx AML

  • Small businesses and individuals: the entire site addresses regulated financial institutions and nothing else
  • Anyone wanting to sign up and try the product alone, since there is no self-service registration, no free plan and no free trial
  • Buyers who need a published price before opening a conversation, as no rate card exists anywhere on the site
  • Developers who expect to read public API documentation before committing, because none is published
  • Teams looking for a mobile application, as Lynx offers no iOS or Android app
Get started

How to use Lynx AML

A typical end-to-end flow, from setup to results.

  1. Identify which of the four modules matches the gap in your existing AML stack, since each is sold separately
  2. Request a demonstration through the form on the site, or write to the general contact address, as there is no self-service sign-up
  3. Work through scoping with the vendor's team, which is where pricing and contractual terms are disclosed
  4. Connect your transaction and customer data using Lynx Layouts, which the vendor says needs no development work
  5. Select and configure the watchlist sources that match your policy and risk appetite
  6. Build screening and monitoring rules in the no-code rule builder, using nested and typology-driven logic where needed
  7. Run those rules in sandbox simulation to see how they would change alert volumes before going live
  8. Deploy the rules to production, which the vendor says takes effect immediately with no warm-up period
  9. Configure case-management workflows, review levels, assignment and priorities for your analyst teams
  10. Monitor operations through the real-time dashboards and tune rules and thresholds as risks change
Quick read

Pros & Cons

Pros

  • Modular design means an institution can add one capability without replacing a working AML system
  • Explainability is treated as a requirement: rules are not hard-coded, and configuration changes are logged for audit
  • The no-code rule builder is presented as usable by compliance and IT staff without developer involvement
  • Name-matching coverage is unusually broad, spanning non-Latin alphabets, phonetics and deliberate misspellings
  • Sandbox simulation lets teams test a rule change against alert volumes before it affects production
  • Independent analyst recognition is specific and dated, including Gartner in 2025 and Chartis in 2024 and 2025
  • A European vendor with a Spanish controller, an explicit GDPR claim and the AEPD as supervisory authority

Cons

  • No price is published anywhere: there is no pricing page, no rate card and no worked example, so budgeting requires a sales conversation
  • No free plan and no free trial are announced, and there is no way to evaluate the product without contacting the vendor
  • The architecture is marketed as API-first, yet no public API documentation exists to check that claim against
  • The published privacy notice covers only the website and says nothing about how client transaction data is handled inside the product
  • No data processing agreement, no subprocessor list and no hosting country or region are published, which is unusual for a product handling banking data
  • ISO 27001 and ISO 22301 are cited as frameworks the management systems are based on, never as certifications obtained; the distinction is easy to misread
  • The headline performance numbers are vendor claims, and the fifty-millisecond figure carries a footnote restricting it to TCP/IP socket connections on on-premise deployments
Pricing

Pricing & Plans

Lynx does not publish any price for Lynx AML. There is no pricing page on the site, none of the sixty-two pages listed in its sitemap carries a rate card, and no amount tied to a commercial offer appears anywhere in the pages reviewed. No permanent free plan and no free trial are announced. Commercial terms are obtained by requesting a demonstration or by contacting the vendor directly, which is consistent with an enterprise product sold to regulated financial institutions. In place of a price, Lynx argues the economics: fewer false positives, lower operational cost per alert, and reduced exposure to the cost of non-compliance. Buyers should expect a negotiated contract rather than a published tariff.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Lynx AML handles your data.

GDPR overview

GDPR compliance is claimed in explicit terms: the privacy notice states that Lynx Financial Crime Tech, S.A. fully complies with Regulation (EU) 2016/679. A Data Protection Officer is designated and reachable at privacy@lynxtech.com, and the supervisory authority named is the Spanish data protection agency, the AEPD. The notice enumerates the rights of access, rectification, erasure, restriction, objection, portability and the right not to be subject to automated individual decision-making. No Article 27 representative is designated, which is consistent with a controller established in Spain. Two limits deserve attention: the notice carries no effective date or version number, and it addresses only website data, saying nothing about the personal data processed inside the AML product on behalf of client institutions.

Who owns the data?

The published privacy notice covers only the personal data that Lynx collects through its own website: contact-form enquiries, job applications and requests to visit its premises. For that data the controller is Lynx Financial Crime Tech, S.A. (tax ID A-10971489), which states that it will not disclose the data to third parties and will not transfer it outside the European Union. Crucially, the site publishes nothing about who owns or controls the banking transaction data processed inside the AML product itself. No data processing agreement, no subprocessor list and no contractual terms for the software are available publicly, so ownership of customer data is governed by a contract that prospective buyers can only see after contacting sales.

Reuse rights

Nothing on the public site grants or describes any reuse right for an end user. The privacy notice is limited to website data and lists narrow purposes only: answering contact enquiries, running recruitment processes, managing physical access to the premises and meeting legal obligations, each based on consent or on a legal obligation. It states that this data is neither shared with third parties nor transferred to third countries. For the AML product, the site says the AI model is trained on diverse datasets and that the Daily Adaptive Model is retrained daily, but never says whose data feeds that training, whether a customer can object, or what a customer may do with the outputs. Those questions are answered only in a private contract.

Data retention & training

Retention summary
The retention rule is stated without any figure. Lynx says personal data is kept for as long as necessary to manage the service requested, after which it remains blocked for as long as needed to bring, exercise or defend claims arising from the processing. No duration in days, months or years is given, and no anonymisation or automatic deletion schedule is described. This rule applies only to the data collected through the website, such as contact enquiries and job applications. No retention policy is published for the transaction and customer data processed inside the AML product, so those periods would be set by contract rather than by anything readable on the site.
GDPR contact

Hosting summary

Lynx publishes no hosting location for client data. Neither a country nor a region is named anywhere on the site, and no trust or security page beyond a policy statement exists. What can be established is limited: the publisher is Lynx Financial Crime Tech, S.A., established in Spain, and the privacy notice states that the personal data it collects through the website is not transferred to third countries or to international organisations, with the Spanish AEPD as supervisory authority. That statement covers website data only. On delivery, the product fact sheet describes native SaaS, while a performance footnote on the homepage refers explicitly to on-premise deployment, so both models appear to be available. The IP address serving the public site resolves to an anycast content delivery network, which says nothing about where the product runs. In short, jurisdiction is Spanish by controller, but the hosting location of client transaction data is simply not disclosed and would have to be established contractually.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Lynx AML.

  • The privacy notice covers only the website; it says nothing about how the personal and transaction data of client institutions is handled inside the AML product itself
  • No data processing agreement, subprocessor list or hosting location is published, so a buyer cannot assess the data chain before entering a contract
  • Three of the mailto links on the privacy page point to an address on lynxfctech.com, a different domain from the site, meaning a GDPR request sent by clicking from the page leaves for another domain; the contact and demo pages show one address but link to a third domain again
  • ISO 27001 and ISO 22301 are named as the standards the management systems are based on, not as certifications held, and a fast reader will very likely record this as certification
  • No documented way exists for a client to exclude its data from model training, even though the vendor advertises a model that retrains daily
  • Performance figures are vendor-declared and carry restrictive footnotes; treating the sub-fifty-millisecond number as a general guarantee would be a mistake, as it is stated only for socket connections on on-premise deployments
  • Automated screening invites over-reliance: an engine that promises fewer false positives can quietly erode the analyst scrutiny that catches the cases a rule was never written for
Setup

Setup & Integrations

Technical difficulty

This is an enterprise integration project, not a sign-up. There is no self-service route: the path starts with a commercial demonstration. Lynx works hard to reduce the effort afterwards, with data ingestion through Lynx Layouts that it says needs no development, rules and workflows configured from a no-code interface, and a claim that no developers are required. The transaction monitoring module can also slot into an existing case-management system through its API. Even so, connecting live transaction flows, tuning rules and validating them against a regulator's expectations remains substantial work for a compliance and IT team.

Deployment

Web appAPI
Company

Behind Lynx AML

Company name
Lynx Financial Crime Tech S.A.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇪🇸 Spain
Headquarters
Avda de Cantabria s/n, 28660 Boadilla del Monte (Madrid)
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇨🇦 Canada
Legal contact

Fundraising

Series A of EUR 17 million announced on 16 November 2023, led by Forgepoint Capital, with Banco Santander participating as an existing shareholder; the amount was also reported as approximately GBP 15 million and USD 18 million depending on the source. Arben Ventures is named among the investors by funding aggregators. No shareholding percentage has been published, and Lynx itself does not publish a funding page on its site.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Who is Lynx AML built for?
Regulated financial institutions: banks, fintechs and payment processors that carry anti-money-laundering and counter-terrorist-financing obligations. Nothing on the site addresses smaller organisations or individual users.
What are the modules of Lynx AML?
Four are named: Lynx Customer Screening, Lynx Payment Screening, Lynx AML Transaction Monitoring and Lynx Tailored Delta List. They are presented as separately deployable modules rather than a single bundle.
Do I have to replace my existing AML system?
No. The vendor's core pitch is that the modules layer on top of an existing stack, with the transaction monitoring module delivered as an API that plugs into a case-management system already in place. A full replacement of a legacy solution is also offered.
How much does Lynx AML cost?
No price is published. There is no pricing page and no amount tied to an offer anywhere on the site, so a quote is obtained only through a demonstration or a direct commercial contact.
Is there a free trial or a free plan?
Neither is announced. The site offers a demonstration on request and a downloadable product fact sheet, but no self-service trial and no permanent free tier.
Does Lynx AML have an API?
Yes, according to the vendor. The transaction monitoring module is described as an API module, and the product fact sheet calls the architecture API-first and headless, stating that every platform capability is reachable through APIs. However, no public API documentation is available to verify this before contact.
What does the claim of more than a hundred languages actually cover?
It refers to the name variations the screening engine analyses, not to the languages of the software interface. Lynx does not publish which interface languages the product supports.
Is Lynx certified to ISO 27001?
The site does not say so. Its cybersecurity policy describes an information security management system based on the ISO 27001 standard and a business continuity system based on UNE-ISO/IEC 22301:2019. These are stated as reference frameworks, not as certifications obtained.
Where is client data hosted?
The site does not publish any hosting country or region. It mentions native SaaS delivery and on-premise deployment, but no location is disclosed, and no data processing agreement or subprocessor list is available publicly.
Who publishes Lynx AML, and when was the company founded?
The publisher is Lynx Financial Crime Tech S.A., registered in Madrid with tax ID A-10971489 and based in Boadilla del Monte. The company describes a long research lineage originating in the Autonomous University of Madrid, but it does not publish a precise incorporation date anywhere on the site.
Conclusion

Should you pick Lynx AML?

Lynx AML is a credible, well-specified compliance platform whose strongest argument is precision in name screening. The four modules are clearly delineated, the decision to let institutions add one capability without replacing a working system is a genuine advantage in a market where migrations are painful, and the emphasis on explainability, logged configuration and rules that are not hard-coded speaks directly to what a regulator will ask. Recognition from outside analysts is specific and dated rather than vague, which is worth something in a category full of unverifiable claims.

The reservations are almost entirely about what is not published. There is no price, no free trial and no self-service path, which is normal for enterprise compliance software but means no independent evaluation is possible before a sales conversation. More significant for a product that processes banking transaction data, the public legal documentation is thin: the privacy notice covers only the website, and there is no data processing agreement, no subprocessor list and no stated hosting location. An architecture marketed as API-first with no public documentation behind it is a similar gap. Readers should also note carefully that ISO 27001 and ISO 22301 are described as frameworks the company's management systems are based on, not as certifications it holds.

For a compliance team with a concrete false-positive problem and the mandate to run a procurement process, Lynx AML is worth shortlisting and testing against real traffic. For anyone hoping to assess it from the outside, the published material sets a firm ceiling: the functional story is detailed, the commercial and contractual story is not disclosed at all.