Why
This card exists because of a sentence written on another one. The institutional custody study card promised a separation — which parts are engineering (MPC, approval state machines, AA policies) and which parts are a licence you either have or do not — and then set the licence half aside. Nearly every card since has hit the same wall from a different angle. Verifiable credentials prove an institution signed something but not that the claim is true, so someone has to decide which issuers count. Zero-knowledge selective disclosure can prove an investor is eligible without revealing a birthday, but eligibility is defined by a regulator, not a circuit. The multichain RWA card's hardest question turns out to be who is liable for overissuance rather than how to detect it. In each case the technical work stops at the same boundary, and the boundary is worth studying directly rather than repeatedly noting in passing.
Why it is live, 2026-08-20. At the Financial AX Risk & Compliance 2026 conference in Seoul, 송근섭, head of the Korean association of certified anti-money-laundering specialists, argued that financial crime has gone cross-border faster than AML has: digital assets and new payment rails are dissolving the boundary between sectors, so customer identification, beneficial-ownership checks, sanctions screening and suspicious-transaction analysis have to be raised together rather than firm by firm. His practical instruction was to stop waiting for complete data and AI governance before starting, and to run a proof of concept on a controllable task — STR analysis was his example — then widen the scope once effectiveness is shown. His limit was that AI must not become a shortcut past the expert: an organisation should use it to strengthen the analyst's judgment, not to route around it. Those two instructions point at the same task from opposite directions, and that tension is what this card can actually measure.
How it works
Planned as a reading study with a map as its output, not an essay. The Korean layer first, since that is the one that would actually bind: 특금법 registration for a VASP, the 실명확인 입출금계정 requirement that gates everything else, 트래블룰 above the threshold, and the domestic solutions that carry it (CODE, VerifyVASP) — which are, structurally, the same institution-to-institution fact transport the RWA card is about, solved by consortium rather than by protocol. Then the international frame: FATF Recommendation 16 and the originator/beneficiary fields it demands, sanctions screening against OFAC and equivalents, STR and CTR reporting duties, and the risk-based approach that decides how much diligence each customer gets. The output worth producing is a two-column map: obligations a protocol can actually carry (screening a destination address, enforcing a transfer allowlist, proving eligibility without disclosure) against obligations that require a licensed entity with staff and liability (filing a suspicious transaction report, deciding a risk rating, answering a regulator). The tension to keep in view throughout is that AML is built on knowing who, and most of this catalogue is built on not needing to know — reusable KYC credentials are the one place those two genuinely meet, and the interesting question is whether a reused credential satisfies a regulator who wants the underlying evidence on file.
The tension in the 2026-08-20 position, and how to measure it
STR triage is precisely where a model substitutes for the analyst's first-pass judgment. So "start with STR" and "do not bypass the expert" aim at the same task from opposite directions, and the speech offers no test that tells them apart. On an org chart they are identical — a human signs either way.
What separates them is measurable:
| Signal | Augmenting | Being rubber-stamped |
|---|---|---|
| Analyst override rate | Non-trivial and stable | Falls toward zero |
| Override precision | Overrides are right more often than the model | Overrides are noise |
| Time per case | Falls, then plateaus | Falls to a signature |
| Escalations the model did not flag | Still happen | Stop happening |
The claim worth testing: an AI that augments leaves a non-trivial override rate whose overrides are correct more often than chance; an AI that is being rubber-stamped shows a collapsing one. That is automation bias, and it needs no bank's data — a synthetic alert queue and two arms reproduce the shape.
One correction to the governance advice
"Do not wait for perfect governance" is right, and it is not the same as "start without an audit trail." An STR is a regulated filing examined after the fact, so the minimum a PoC owes is a decision record from day one: inputs, model version, score, what the analyst did, and why. That is a far smaller thing than full AI governance, and conflating the two is how good advice becomes an excuse.
Where the partnership point lands
The closing argument — that information and expertise sit scattered across firms, supervisors and private specialists, so public-private partnership matters — belongs in this card's existing two-column map rather than in a new card. Sharing typologies is fact transport, which this catalogue already knows how to think about. Deciding a risk rating and signing a filing is not. Add it as a third row: obligations a consortium can carry, sitting between what a protocol can carry and what only a licensed entity can.