Release 22092026 – Quantum of Solace

SAR reporting moves into cases this release: a dedicated reporting stage, Sweden SAR drafting with an AI-written narrative and PDF filing, and a workspace-

September 22, 2026

What's New at spektr

Features

Case reporting stage and SAR workflow

You can now handle reporting directly on the case. A built-in Reporting stage is entered automatically when the first report draft is created, and each report follows a fixed lifecycle: Draft, Under review, then Approved or Disregarded, with Sent for jurisdictions that support direct submission. The MLRO can approve, send back with feedback, or disregard, and a case can hold several reports per jurisdiction, each with an automatic reference such as SAR-2026-xxxx. On filing, the covered transactions and the customer profile are marked as reported, and drafting, approving, and filing are permission-controlled in role settings. Rolling out behind a feature flag; available on request.

What this changes for you: When enabled, reporting becomes a tracked stage on the case instead of a manual step outside it. Teams that draft SARs should be briefed on the review flow.

SAR report generation for Sweden

You can now draft and file a complete Sweden SAR from the case. The draft uses a structured form and gets an AI-generated reason for suspicion with a per-claim reasoning trail, and each report carries its own evidence documents and covered transactions, frozen once approved. Filing renders the PDF, stores it as a case document, and notifies the workflow recipients. Five more jurisdictions already appear in the create dialog, each with the reason it cannot be filed yet. Note: pre-fill currently covers the report reference and triggering alert only, and required-field validation is still to come. Rolling out behind a feature flag; available on request.

What this changes for you: No change to your current workflows. This becomes relevant once SAR filing is enabled for your workspace.

FIU Report Register

You can now see every FIU report across all cases in one workspace-level register, found under platform settings. The register supports search and filters (jurisdiction, report type, status, date range, filed by), exports to CSV with one row per report including the customer identifier and filing dates, and downloads the filed report PDFs as a ZIP with a manifest. Each row links back to its case and report, and access respects case permissions. Rolling out behind a feature flag; available on request.

What this changes for you: No change to existing workflows. Once enabled, this is where you answer "how many customers were reported, and when", for example for an auditor.

Website Sentinel: keyword lists and flag threshold

You can now manage Website Sentinel's keyword list from platform settings, starting from spektr's base list and overriding it per organisation with a CSV upload. A new minimum-hits setting controls how many distinct keywords a scan must detect before it flags, so one stray match no longer flags a site. Payment scheme logos placed as footer images are now detected reliably.

What this changes for you: Keyword configuration now lives in platform settings; update any internal documentation that points to the old location. Scans may flag less often once you set a threshold.

Custom prohibited words and categories

You can now import your own prohibited word lists and categories into Website Sentinel via CSV or XLSX, with a preview before anything is saved. A toggle controls whether your list augments or replaces spektr's defaults, custom categories take part in the AI classification pass like built-in ones, and every hit in the scan report is labelled by source. Entries can be filtered and deleted in a management view, imports are capped at 5,000 terms, and every import and delete is audit-logged. Rolling out behind a feature flag; available on request.

What this changes for you: No change to your current workflows. This becomes relevant when you want industry-specific or regulator-mandated terms scanned.

Website Checker v3: advanced merchant risk checks

Website Checker v3 adds a new set of merchant risk checks: business model versus declared MCC, price reasonableness, website professionalism, prepayment and dropshipping signals with a delivery-time threshold, scheme logo verification, and an expanded prohibited-category list. Text checks work across English, Swedish, Danish, Norwegian, and German, and each check reports pass or flag with evidence in a single risk report. Rolling out behind a feature flag; available on request.

What this changes for you: No change to existing workflows. This becomes relevant for merchant-acquiring portfolios once enabled.

Execution-time evidence capture

Screening and AI outputs are now captured as evidence at execution time: screenshots, HTML snapshots, provider JSON responses, and AI inputs and outputs. Each artifact is stored by ID, so a review stays verifiable even if the source URL later stops working or a provider changes format, and reviewers can open the captured evidence inline with a captured-at timestamp. Rolling out behind a feature flag; available on request.

What this changes for you: No change to existing workflows. Once enabled, historical reviews remain inspectable even when source links rot.

Improvements

Policy engine reasoning in plain language

The policy engine's AI reasoning no longer shows raw node IDs or internal field keys. User-facing text now uses readable labels and descriptions across all result types.

What this changes for you: Policy results read differently: same conclusions, plain language. Worth a heads-up to anyone who quotes reasoning output.

Website Sentinel risk score, available downstream

The Website Sentinel's overall risk score is now a named output field, so downstream process nodes can use it in routing, conditions, or as input to other steps. Existing processes keep working unchanged.

Prohibited categories, available downstream

The Website Sentinel node now outputs the detected prohibited categories (for example gambling, weapons, adult content) as a list, so processes can route or act on specific categories, including custom ones. Existing processes are unaffected.

More accurate AI summaries

AI-generated customer and case summaries now read key fields such as dates, amounts, and statuses through a grounding step, with calculations done server-side. Summaries report the correct value or say unknown instead of guessing. Rolling out behind a feature flag.

This release also includes bug fixes, platform and performance work.

Every release has a story behind it
Get exclusive deep-dives into what we shipped, why we built it,
and behind-the-scenes from the product team:

Put AI agents to work
across your workflows

Join the banks and financial institutions already running compliance at scale with spektr.