Settlement Control Plane

Six deterministic stages. No human in the loop.

INGEST → MATCH → DETECT → CLASSIFY → GOVERN → REPORT. Each stage is obligation-aware: it knows which regulatory citation applies, what the SLA window is, and what the consequence of breach looks like.

01
INGEST
Parse, normalise, tag
02
MATCH
ISO 8583 pairing
03
DETECT
10-module detection
04
CLASSIFY
Obligation assignment
05
GOVERN
SLA enforcement
06
REPORT
Audit + alerts
Stage 01

Ingest

Parses raw settlement files in ISO 8583, ISO 20022, NACHA, and proprietary batch formats. Normalises into the Connexum canonical transaction model. Tags each record with participant source, timestamp, and schema version.

  • Multi-format parser
  • Canonical model mapping
  • Participant source tagging
  • Schema validation + rejection log
Stage 02

Match

Pairs authorisation records against clearing and settlement legs. Produces matched pairs, partial matches, and unmatched suspense entries. Resolves multi-leg transactions and reversals.

  • Auth-to-clearing pairing
  • Suspense auto-flagging
  • Reversal reconciliation
  • Batch-level proof
Stage 03

Detect

Runs all ten detection modules against the matched transaction set. Modules are independent and parallelisable. Each module emits a typed finding with citation, SLA window, and consequence level.

  • 10 independent modules
  • Typed finding schema
  • Citation-anchored outputs
  • Parallel execution
Stage 04

Classify

Assigns each finding to its regulatory obligation. Maps BSA, Reg E, OFAC, PCI, Visa VDR, MC MDR to the responsible participant. Produces the obligation schedule for GOVERN stage.

  • Regulatory mapping
  • Participant assignment
  • Obligation schedule
  • Priority scoring
Stage 05

Govern

Enforces SLA clocks. Escalates approaching deadlines. Initiates freeze protocols on OFAC match. Triggers SAR filing windows. All actions are append-only to the audit ledger.

  • SLA clock enforcement
  • OFAC freeze trigger
  • SAR window alert
  • Escalation routing
Stage 06

Report

Generates participant-scoped reports, audit-trail exports, regulatory filing packages, and the Connexum state snapshot. All outputs are signed and append-only. Supports API pull and push delivery.

  • Participant-scoped views
  • Signed audit export
  • Regulatory filing package
  • API push / pull delivery
Regulatory inputs

What Connexum reads and enforces.

Regulatory feeds

  • BSA — 31 CFR §1020.320 SAR thresholds
  • Reg E — §205.11 provisional-credit windows
  • OFAC — SDN list + Part 560 country schedules
  • PCI DSS — v4.0 Req. 10.7 log-retention rules
  • Visa VDR — 30-day stuck-transaction SLA
  • MC MDR — 45-day batch reconciliation SLA

Output artefacts

  • Matched pairs — auth ↔ clearing ↔ settlement
  • Suspense log — unmatched + partially matched
  • Obligation schedule — SLA clocks + assigned party
  • Compliance report — per-participant + aggregate
  • SAR package — filing-ready output
  • Audit ledger — signed, append-only, exportable

Obligation scheduler

Connexum runs a deterministic obligation clock for every active finding. Clock state survives restarts. SLA windows are indexed by citation, not configuration — the regulation IS the scheduler input.

  • Reg E — 10 business-day provisional credit
  • BSA SAR — 30-calendar-day filing window
  • Visa VDR — 30-day pipeline clearance
  • MC MDR — 45-day batch proof
  • OFAC — same-day freeze on SDN match
SLA enforcement

Consequences built into the detection, not the response.

RegulationSLA WindowConsequence of breachConnexum action
BSA 31 CFR §1020.32030 daysCriminal exposure + FinCEN civil penalty up to $25K/daySAR-window alert at day 20; package assembled at day 25
Reg E §205.1110 business daysMandatory provisional credit + reimbursement of any lossesProvisional-credit clock started on dispute receipt; escalation at day 8
OFAC 31 CFR Part 560ImmediateCivil penalty up to $311K per violation + criminal referralSame-day freeze trigger on SDN match; OFAC notice package generated
PCI DSS v4.0 Req.10.712 monthsCard-brand fine + loss of merchant / issuer privilegeContinuous log-chain audit; retention calendar enforced
Visa VDR30 daysNetwork penalty + dispute liability shiftStuck-transaction flag at day 20; VDR report at day 28
MC MDR45 daysChargeback liability shift + network penaltyBatch-discrepancy flag at EOD; MDR report at day 40
Next

See all ten detection modules.

Each module is independently configurable, citation-anchored, and tested against 15 adversarial breakage datasets.