Discai AML KYT
Discai AML KYT is a cloud transaction-monitoring solution that uses machine learning to flag money laundering for banks and financial institutions. Built by Discai NV, a KBC Group subsidiary, it targets fewer false positives and explainable scoring.
What is Discai AML KYT?
Discai AML KYT, for Anti-Money Laundering Know Your Transaction, is the first commercial solution released by Discai NV, a wholly owned subsidiary of KBC Group created to bring to market the artificial intelligence applications the bank had built in-house. It is aimed at financial institutions that must monitor transactions under anti-money-laundering rules, and the vendor describes it as a scalable cloud based solution.
The detection engine rests on five families of machine learning models. A foundation model learns from historical data through supervised learning; focus models target specific cases; a networking model examines links between individuals; anomaly models pick up deviations; and a blending model aggregates everything into one score that tells an investigator where to look first. The offer is modular, with more than 4,000 features available, and Discai insists on explainability, promising no black boxes, just insight, so that the way each score is calculated can be understood and audited.
Data reaches the platform through a standardised interface based on structured CSV files. The client's model is trained on the client's own databases over four to six weeks, and retrained every year. Day-to-day work happens in a user portal, with continuous monitoring of processing. The product comes either as a plug-in on top of existing systems or as a complete AML Detection Suite.
What anchors it is KBC. The technology ran for years inside the bank in Belgium before it was ever sold, was then validated with an external body, and more than 100 data scientists work on the solutions. Discai displays an ISO 27001 certification covering its deployments. KPMG and Tech Mahindra are named as integration partners, and Protegrity appears under an Accelerated by label; the logos shown under Trusted by, namely UBB, K&H, CSOB, CBC and KBC, are customers, all of them KBC Group entities.
What is published has limits worth knowing. Discai claims efficiency gains of 40% to 60% in European banks while doubling the number of reported cases, but no methodology, date or independent verification backs those figures. No price is public, no API is documented, and no data hosting country is named.
What it does
- Detect suspicious behaviour automatically, both known and new, including inside complex schemes
- Prioritise alerts through automated customer scoring backed by an explainable audit trail
- Build a holistic customer profile by combining internal KYC data, transaction history and external sources
- Reduce false positives compared with traditional rule-based engines
- Produce a single aggregated score through the blending model to steer investigations
- Exchange data with existing systems through a standardised interface using structured CSV files
- Retrain the models every year, included as standard
When to use Discai AML KYT / When not to
A quick filter to help you decide if Discai AML KYT is the right fit.
When to use Discai AML KYT
- Banks and financial institutions required to monitor transactions under anti-money-laundering regulation
- Compliance teams drowning in false positives produced by traditional rule-based engines
- Organisations that need explainable, auditable risk scoring they can defend in front of a supervisor
- Institutions already equipped with an AML stack that want to plug in a detection module rather than replace everything
- Financial crime and AML investigation teams that need their alerts prioritised before they open cases
When not to use Discai AML KYT
- Individuals and very small businesses: this is an enterprise product sold through a sales contact
- Buyers who want to sign up online, self-serve, or compare a public price list before talking to anyone
- Teams looking for a mobile app or a documented public API: neither exists, and data moves as structured CSV files
- Organisations that need to be live in days: the vendor describes four to six weeks of client model training on top of data preparation
- Teams shopping for a KYC onboarding tool: the scope here is transaction monitoring, and internal KYC data is an input rather than the function sold
How to use Discai AML KYT
A typical end-to-end flow, from setup to results.
- Book a free AML KYT demo through the form on the Discai site; an expert guides you through the platform
- Move into a commercial discussion, where pricing is quote-based and a proof of concept is available
- Prepare your data against the documented data model and the stated data quality prerequisites
- Integrate through the standardised interface, exchanging structured CSV files, guided by the onboarding playbooks
- Have Discai train the model on your own data, which the vendor times at four to six weeks
- Add optional elements where relevant, such as client-specific data fed into the scoring, or extra modules
- Run daily operations in the user portal: review prioritised alerts and open investigations
- Rely on the local helpdesk for support, with continuous updates and annual model retraining
Pros & Cons
Pros
- Technology proven in production inside a banking group before it was ever put on the market
- Backed by KBC Group: continuity, regulatory expertise and more than 100 data scientists
- Claimed explainability and an audit trail, the central argument in front of regulator expectations
- Fewer false positives and prioritised alerts, meaning a lighter workload for compliance teams
- Annual retraining and regulatory updates included in the licence fee
- ISO 27001 certification displayed by Discai
- Pricing structure presented as transparent and predictable: fixed fee, number of active customers and modules
Cons
- No public amount: any figure requires contacting the sales team
- No free trial and no free plan; only a guided demo is offered
- No public API and no online technical documentation; exchange happens through CSV files
- Long implementation: four to six weeks of model training on top of the data preparation work
- No hosting country or region named, no data processing agreement published, and no named list of sub-processors
- No documented option letting a client exclude its data from model training
- Customer references on display all come from the KBC group (UBB, K&H, CSOB, CBC, KBC), and neither the number of screened clients nor the list of deployment countries is given in figures
Pricing & Plans
No free plan is published for Discai AML KYT, and no public entry price point is available. The site sets out a pricing structure only: a fixed fee, the number of active customers, and the modular choices made by the client, with continuous annual upgrades included in the licence fee. No amount and no currency are disclosed, and prospects are directed to Contact us for more details. A free demo is offered and a proof of concept is available, without any indication of whether the latter is free of charge.
Data, GDPR & hosting
A consolidated view of how Discai AML KYT handles your data.
GDPR overview
Discai is established in Belgium, inside the EU, so Belgian law and the Belgian supervisory authority apply. The site states that Discai processes your personal data in accordance with GDPR. The privacy statement enumerates the rights of access, rectification, erasure, objection and portability, and notes that identity may be verified before a right is exercised. A Data Protection Officer is appointed and reachable by letter at Discai NV, Data Protection Officer, Havenlaan 2, 1080 Brussels, or at dpo@discai.com. Complaints can be filed with the Belgian data protection authority, which is named explicitly. No Article 27 EU representative is designated, and none is required for an EU-established company. Two things are missing: no data processing agreement is published, and sub-processors are described only by category, never named.
Who owns the data?
Two different sets of data sit behind Discai, and the site only documents one of them. For the website, Discai NV is the controller: its privacy statement, in force since 7 March 2022, covers visitors and prospects and states that Discai is responsible for processing personal data. Intellectual property rights in the information and publications on the site are held by Discai NV or another KBC Group entity. The banking data handled by the solution is a separate matter: customers supply their own client and transaction databases, and Discai supplies and trains the models on them. No contractual terms setting out ownership of that customer data are published.
Reuse rights
The privacy statement lists four purposes for the personal data Discai collects through its website: meeting legal obligations, performing the contract, legitimate interests and direct marketing. The legitimate interests named include testing applications on personal data, evidence, and the defence of Discai's rights. Discai states that it does not sell or hire your personal data to third parties for their own use unless the person opts in, and that there are no data processing operations and processes that are fully automated, without any human intervention. Anonymised market insights may be offered, and visitors can object; objections to direct marketing go to the DPO by e-mail. Only analytics cookies are set, and only after the visitor has made a choice. Nothing on the site grants users any right to reuse Discai's own content, which remains the property of Discai NV or another KBC Group entity.
Data retention & training
Hosting summary
Discai names no hosting country and no hosting region anywhere on its site. The solution is presented as a scalable cloud based product built on a high-performance cloud platform, and the privacy statement says only that your data is processed at a limited number of locations, without situating those locations. Sub-processors are described by category, namely lawyers and consultants plus ICT providers and specialised fintech companies, but none is named. On the security side, Discai commits to technical and organisational measures covering premises, servers, network and transfers, displays an ISO 27001 certification behind its deployments, and shows a partnership with Protegrity for vaultless tokenisation and encryption under an Accelerated by label. The jurisdiction question therefore stays unanswered on the public site. Any institution with a regulatory constraint on where transaction data may sit will have to obtain the hosting locations, and the matching contractual commitments, directly from the vendor.
Things to keep in mind
Risks and trade-offs to weigh before adopting Discai AML KYT.
- Detection quality depends entirely on the data the client supplies: a poorly fed model degrades quietly, and nobody sees the case it missed
- Over-reliance on an automated score in a field where personal and regulatory liability stays with the human investigator
- Models are trained on customer data, so governance and legal basis must be settled contractually, and no documented option exists to exclude data from training
- No hosting country is named, so the jurisdiction your transaction data ends up in has to be clarified before contracting
- No published data processing agreement and no sub-processor list: due diligence has to be run outside the website
- Reversibility and vendor lock-in, with a supplier backed by a banking group that may be a competitor
- Possible bias in a model trained on one bank's history and then transposed to another institution
Setup & Integrations
Technical difficulty
Demanding: this is a project, not a self-service sign-up. Discai documents a data model describing what the solution requires, and integration runs through a standardised interface exchanging structured CSV files, with onboarding playbooks and shared best practice on data preparation, required quality and case history. Training the client's model takes four to six weeks. KPMG and Tech Mahindra are named as integration partners for organisations wanting outside help. Support comes from a local helpdesk with change, release and incident management commitments, and additional modules can be plugged in later. Expect real data engineering effort on the client side.
Deployment
Behind Discai AML KYT
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Discai AML KYT do?
Who is it for?
Who publishes the solution?
How much does it cost?
Is there a free trial?
How does it integrate with existing systems?
How long does it take to get started?
Is there an API?
Are the models trained on customer data?
What security guarantees are offered?
Should you pick Discai AML KYT?
Discai AML KYT is a narrow, vertical product sold business to business to financial institutions, and it should be judged as such. Its credibility comes from an unusual origin: the detection engine ran for years inside KBC in Belgium before it was ever offered to anyone else, and the vendor still leans on the group for regulatory expertise, continuity and a large data science team. For a compliance function that has to justify every alert to a supervisor, the emphasis on explainable scoring and an audit trail is the right argument, and it lines up with where financial crime regulation is heading.
The friction sits on the buying side. Nothing commercial can be assessed without a sales conversation: no amount is published, only a pricing structure. There is no technical documentation, no API, and no hosting jurisdiction named, so any security or procurement review has to be run off the website. The performance figures Discai puts forward, efficiency gains of 40% to 60% and a doubling of reported cases, are vendor claims, undated and without published methodology; treat them as a hypothesis to test in a proof of concept, not as an established result.
We would recommend it to banks and financial institutions already carrying a rule-based monitoring stack, with the data quality and case history to feed a model, and the project capacity to absorb four to six weeks of training on top of data preparation. Ask in writing for the hosting jurisdiction, the processing agreement and the sub-processor list, and settle how your data will be used for training before signing. This is not a tool you evaluate in an afternoon, and it is not aimed at individuals or small businesses.
- Choosing a selection results in a full page refresh.
- Opens in a new window.