Smaragd
Modular anti-money-laundering and compliance suite from German software house GFT, built for banks, fintechs and insurers. Five interlocking modules cover payment and customer screening, transaction monitoring, correspondent banking and customer risk scoring, with explainable AI throughout.
What is Smaragd?
The Smaragd Compliance Suite is a modular financial-crime compliance platform published by GFT Software Solutions GmbH of Konstanz and sold under the group brand Smaragd by GFT. It is aimed at institutions that have to prove, transaction by transaction, that they are meeting anti-money-laundering, know-your-customer and sanctions obligations.
The suite is built from five solutions that can be bought separately or run together. Transaction Monitoring detects suspicious activity by combining established rule sets with AI, and ships with a library of AML typologies, a no-code rule editor and a sandbox for testing detection scenarios before they go live. Payment Screening checks payments against sanctions lists in real time, instant payments included. Customer Screening handles onboarding and periodic checks at volume. Correspondent Banking Monitoring gives visibility over every party in cross-border flows. The Customer Risk Solution assesses money-laundering, fraud and terrorist-financing risk with configurable models across the customer lifecycle.
Eight functions run across all five: a report engine, user and access management, centralised alert management, activity logging and archiving, an integration platform exposing web services, explainable AI, configurable workflows, and central configuration of rules, customer groups, translations and filters with versioning. The transaction monitoring module adds white listing, a 360-degree customer view, statistically derived dynamic thresholds and a GoAML module for filing suspicious activity reports.
Explainability is the recurring theme: the vendor presents each alert classification with the risk factors behind it, so that analysts and auditors can follow the reasoning. GFT claims the suite is the compliance engine behind seven of the ten largest banks in Germany, with more than seventy customers worldwide, over twenty countries covered and twenty-five years of market presence.
Release 2026.1 is oriented towards the incoming European framework, naming AMLD6, AMLR, the regulatory technical standards and the new AMLA authority, and adding multidimensional customer risk assessment and fuller historical tracking of risk decisions. There is no public pricing and no self-service trial: the product is sold through a guided demo and a project implementation.
What it does
- Monitor transactions in real time and surface suspicious activity linked to money laundering
- Screen payments and customers against sanctions lists, including instant payments
- Score and rescore customer risk across the whole customer lifecycle
- Track correspondent banking flows and every party to a transaction
- Build and test detection rules without code, in a simulation sandbox
- Prepare and file suspicious activity reports to the financial intelligence unit via the GoAML module
- Produce audit-ready reports, dashboards and activity logs for regulators and auditors
When to use Smaragd / When not to
A quick filter to help you decide if Smaragd is the right fit.
When to use Smaragd
- Compliance officers and AML analysts in banks who must monitor transactions and clear alerts against AMLD6, AMLR and sanctions rules
- KYC and customer-screening teams handling high onboarding volumes who need risk scoring rather than manual review
- Correspondent banking and trade finance specialists who must keep visibility over counterparties in cross-border payment flows
- Compliance leads at neobanks, BaaS platforms and payment firms that need AML, KYC and sanctions checks in place from day one
- Insurers monitoring customers, brokers and claims workflows under Solvency II and comparable regional regimes
When not to use Smaragd
- Small businesses wanting to buy online: there is no price list, no free plan and no self-service sign-up anywhere on the site
- Teams that need to evaluate a tool before speaking to a salesperson, since the only entry point is a booked demo
- Developers looking for a documented public API: the integration layer is advertised as a product function but nothing is published
- Organisations outside financial services and other regulated sectors, as every use case shown is sector-specific
- Users who need a mobile app or a working language other than English or German
How to use Smaragd
A typical end-to-end flow, from setup to results.
- Identify which of the five solutions you need, since each can be licensed on its own or as part of the full suite
- Book a demo through the form on the product site, or use the contact page to reach the sales team directly
- Attend the guided session, which runs 30 to 45 minutes and is tailored to your sector and use case
- Bring the right people: compliance officers, risk managers, AML and KYC leads and the IT owners of your regulatory systems
- Review the areas the demo covers: customer screening, transaction monitoring, case management and risk scoring
- Read the written follow-up GFT sends after the session summarising what was shown
- Ask for the deeper technical session if the fit looks right, then discuss a pilot
- Work through an implementation plan with GFT, choosing between a cloud-ready deployment and one embedded in your own infrastructure
- Connect the suite to your core banking systems and payment rails through the standardised interface and web services
- Once live, configure rules in the no-code editor and test them in the simulation sandbox before activating them
Pros & Cons
Pros
- A verifiable installed base in a demanding market: GFT states the suite runs at seven of the ten largest German banks
- Explainable AI is treated as a first-class feature rather than a footnote, which matters when an auditor asks why an alert fired
- Genuine modularity: each of the five solutions can be taken on its own, so the scope can match the obligation
- The no-code rule editor and simulation sandbox let compliance teams tune detection themselves without waiting on IT
- Suspicious activity reporting is built in through the GoAML module rather than handled outside the system
- Backing from a large listed group gives continuity and support depth that a young vendor cannot offer
- Recognised by the trade press, with Smaragd TCM named solution of the month by Bankmagazin
Cons
- No pricing whatsoever is published, and there is no free plan and no trial, so the cost cannot be assessed without entering a sales process
- There is no public API: the word never appears on the site and no developer documentation exists, even though an integration platform with web services is advertised as a product function
- No data processing agreement is published or offered, which is unusual for a product handling regulated customer data
- No security certification is claimed anywhere on the site, with no mention of ISO 27001 or SOC 2
- Nothing is published about where the platform's data is hosted or in which jurisdiction it sits
- The privacy notice covers only the website and contact services, so it answers few questions about the product itself
- Two different first-party figures are given for false-positive reduction, 70% on the suite page and 75% on the module and group pages
Pricing & Plans
No pricing is published. There is no free plan, no free trial and no self-service purchase path: the dedicated pricing page returns a genuine error, it is absent from the site's sitemap and from the footer, and no monetary amount appears anywhere in the collected pages. The suite is sold under contract, with a booked demo as the only published entry point, and the commercial scope is set by how many of the five modules are licensed. GFT argues the case on total cost of ownership rather than list price, citing reduced vendor dependence, configuration that customers can handle themselves and faster implementation. Prospective buyers should expect an enterprise quotation.
Data, GDPR & hosting
A consolidated view of how Smaragd handles your data.
GDPR overview
GFT Software Solutions GmbH is established in Germany, so the GDPR applies directly and no Article 27 representative is required or named. The privacy notice is structured along GDPR lines: it identifies the controller, names a Data Protection Officer, lists the rights of access, rectification, erasure, restriction, portability and objection, and points to the Baden-Wurttemberg supervisory authority for complaints. Transfers outside the EEA are acknowledged and said to be covered by contractual, technical and organisational measures. On the product side, GFT's own catalogue page states that Smaragd is aligned with AML, KYC, GDPR and Basel III requirements. That is a marketing claim rather than an attestation: no certificate, audit report or data processing agreement is published to support it.
Who owns the data?
The privacy notice published on the product site names GFT Software Solutions GmbH, Konstanz, as the data controller, with Ernst O. Wilhelm as Chief Privacy Officer acting as Data Protection Officer. Five separate contact routes are published for marketing, HR, complaints, breach reporting and general requests. Personal data may be shared across the GFT Group and transferred outside the European Economic Area, with contractual, technical and organisational safeguards claimed for those transfers. One limit matters: that document governs the website and GFT's contact services, not the customer data processed inside the compliance platform itself. Ownership of the transaction and customer records handled by the suite is not addressed anywhere in the published material.
Reuse rights
The published notice describes processing tied to running the website and the commercial relationship: contact and demo forms, newsletters, webinars, social media profiles and recruitment. Consent and legitimate interest are the stated legal bases, and consent can be withdrawn at any time. Named third-party tools all belong to the marketing stack rather than the product: Google Analytics, with data stored on servers in the United States, Microsoft Teams for online events, LogMeIn and Pardot. Nothing is published about what GFT may do with the transaction, customer or alert data that flows through the compliance suite, and no reuse rights, licence terms or restrictions for the customer are set out. Anyone needing that detail will have to obtain the contract.
Data retention & training
Hosting summary
GFT publishes nothing about where the compliance platform's data is hosted. No country, region, data centre or cloud provider is named for the product, and no residency commitment is made. The only locations that appear anywhere are tied to the website and marketing stack, not to the suite: Google Analytics, whose collected information is stored on servers in the United States, Microsoft Teams for online events, LogMeIn and GFT's Pardot marketing automation. Presenting those as the product's hosting arrangement would be misleading, so the hosting fields on this record are deliberately left empty. More broadly, the privacy notice states that GFT operates internationally and may share personal data within the group and transfer it to countries outside the European Economic Area, with contractual, technical and organisational measures said to provide an adequate level of protection. Buyers who need a jurisdiction commitment will have to obtain it contractually.
Things to keep in mind
Risks and trade-offs to weigh before adopting Smaragd.
- The imprint and contact page name GFT Software Solutions GmbH, while the homepage says Smaragd is a product of GFT Technologies: the publisher is the Konstanz subsidiary, not the listed parent
- The smaragd.ai domain is registered to GFT Technologies SE in Stuttgart, a different legal entity from the publisher named in the imprint
- The published figures need care: two first-party numbers for false-positive reduction disagree, 70% on the suite page against 75% on the module and group pages, and the homepage counters render as zero because the values are injected by script
- The privacy notice governs the website and contact services only, so any GDPR conclusion drawn from it about the platform itself is revocable
- No certification, no data processing agreement and no hosting location are published, which leaves the security and data-residency questions entirely to the contract
- An integration platform with web services is advertised while the word API never appears on the site and no documentation exists, so integration scope can only be pinned down with the vendor
- Automated alert scoring can breed over-reliance: explainability helps, but a team that stops challenging the model still ends up accountable for what it misses
Setup & Integrations
Technical difficulty
This is an enterprise deployment, not a sign-up. Implementation runs as a project after a demo, a technical session and usually a pilot. GFT offers a cloud-ready deployment for digital-first teams and an option embedded directly in the customer's own infrastructure, and connects through a standardised interface and web services to core banking systems, SWIFT and SEPA. Expect integration work and IT involvement. Once live, day-to-day tuning is deliberately easier: the no-code rule editor and simulation sandbox are designed so compliance staff can build and test rules without technical skills.
Deployment
Integrations
Supported languages
Behind Smaragd
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does the Smaragd Compliance Suite actually do?
Can I buy just one module rather than the whole suite?
How much does it cost?
How do I get started?
Who should attend the demo?
Is the AI explainable enough for an audit?
Does it help with the new European AML rules?
Can it file suspicious activity reports?
Does it offer an API?
What languages is it available in?
Should you pick Smaragd?
Smaragd is a mature, narrowly targeted product rather than a general-purpose AI tool. Everything about it points at one buyer: the compliance function of a regulated financial institution that has to detect financial crime and then justify every decision to an auditor or a regulator. The five modules map cleanly onto real obligations, the no-code rule editor and simulation sandbox give compliance teams genuine autonomy, and the emphasis on explainable AI addresses the objection that usually stops machine learning at the door of a compliance department.
The credibility rests on the installed base. GFT states the suite runs at seven of the ten largest banks in Germany, with more than seventy customers worldwide, and that claim is specific enough to be checked by any serious prospect.
The reservations are about transparency rather than capability. Nothing is priced, there is no trial and no self-service path, so the only way to learn what it costs is to enter a sales process. No data processing agreement is published, no security certification is claimed anywhere on the site, and nothing is said about where the platform's data is hosted. For a product handling regulated customer records that silence is notable, and the privacy notice does not fill the gap because it covers only the website. Two different first-party figures for false-positive reduction, 70% and 75%, are a smaller but similar signal.
For a bank or insurer already running a procurement process, Smaragd deserves a place on the shortlist and the missing detail can be demanded in the contract. For anyone hoping to evaluate a compliance tool independently before talking to a vendor, this is not that product.
- Choosing a selection results in a full page refresh.
- Opens in a new window.