Introducing Complead. One AI-native platform for financial crime compliance. Read the story
New Ready Integrations available Check the new integrations

Complead News All

From Sanction Scanner to Complead: Why Now, and Why This Way

Six years ago, in a small office in Istanbul, we were chasing a simple question: why does compliance technology have to be this expensive, this slow, and this hard to get? 

Our answer to that problem was Sanction Scanner. Software that screened watchlists, delivered PEP data no one else was covering properly, and made compliance teams’ lives easier. Reliable, and built to be used. 

Today the question itself has changed. Now we’re asking: does compliance have to be a process where a person stares at half a dozen screens and systems and eventually arrives at a decision? Or can we build something that pulls every risk process into one system, sees the risk, constructs the reasoning, assembles the file, and leaves only the judgment to a human? 

Our answer to that question is Complead. An AI-native compliance, risk, and fraud infrastructure. This piece is about why it exists, what we intend to build, and what we believe is coming. 

Four parts: where we came from, why we changed our name, why we’re entering the US now, and where we think this industry goes over the next decade. 

This isn’t a press release. As the person who started this company, I want to share the thinking behind the move, and the excitement behind it, exactly as it is. 

What we built in six years 

When we founded Sanction Scanner, the market was split in two. On one side, enterprise platforms with six-figure annual licenses and implementation cycles measured in quarters. On the other side, nothing. There was no serious option for a growing fintech, a payment institution, or a mid-sized bank. 

We went into that gap and built three layers. 

The data layer 

We consolidated more than 3,000 data points and over 1,500 lists from 220+ countries into a single structure, updated in real time. 

This was far harder than it sounds. Every list has its own format, its own quirks, its own update rhythm. There is no shared standard between OFAC’s SDN file and a finance ministry bulletin from an Asian jurisdiction. One publishes hourly XML; the other scans a PDF and posts it to a website. A single name appears across five lists with five different spellings. 

But the genuinely hard part was never sanctions. It was PEP. 

Sanctions lists have an owner. OFAC publishes. The EU publishes. The UN publishes. You find the source, connect to it, and monitor it. PEP has nothing of the sort. There is no official, centralized, global register of politically exposed persons anywhere in the world. Who counts as a PEP changes from country to country. FATF sets a frame; every regulator interprets it differently. A municipal mayor is a PEP in one jurisdiction and not in another. 

And it isn’t a list. It’s a living organism. Every election, every cabinet reshuffle, every resignation, every appointment moves the data. The harder problem isn’t even the individual: it’s the spouse, the child, the business partner, the adviser. Relatives and close associates turn PEP data from a list of names into a network of relationships. Then there’s the question of how long someone remains a PEP after leaving office, and the answer to that varies by country too. 

We built this data country by country, source by source, institution by institution. We stood up systems that track official gazettes, parliamentary records, and government announcements in local languages. We classified it, related it, and time-stamped it. When a customer queries a name today, years of that work sits behind the answer. 

Then came the stress test. We only really understood what we’d built in February 2022. When the Russia sanctions landed, the lists began changing at a pace with no precedent. Thousands of new entries, measures taking effect within hours, jurisdictions contradicting each other. Our team barely slept for weeks. But the system held, and not one customer had a single day of data lag or disruption. It was the most instructive period of our six years. 

That data layer is our single largest technical asset today. 

The product layer 

We started with name and transaction screening. Then adverse media, transaction monitoring, fraud detection, customer risk assessment, KYB, SWIFT screening, and ongoing monitoring. Not independent tools; integrated systems that run seamlessly against each other. 

We designed them not as modules sold separately but as one system that resolves into a single view of the customer. The reason is simple: in the real world, risk doesn’t arrive in pieces. A customer’s absence from a sanctions list says nothing about their transaction behavior. Looking clean in the media says nothing about the transparency of their ownership structure. 

Fusion is the result. Onboarding risk, transaction behavior, fraud signal, and media footprint converge into a single score. What surfaces in one module instantly changes the decision in another. That isn’t an integration. It’s one system on one data layer. 

The access layer 

We treated the API as the product, not an add-on. Sub-200-millisecond response times, uptime above 99.95%, integrations that finish in hours. We don’t charge integration fees. 

A developer opening our docs and shipping the same day was never a marketing promise. It was an engineering constraint, and it still is. A US customer completed their integration in a matter of hours. A customer writing millions of policies a month screens in under 100 milliseconds. In money transfer flows, people clear every control point in under 100 milliseconds. 

These numbers aren’t there to look good on a slide. They’re there so compliance never degrades the customer experience, and so the people doing this work every day have an easier time of it. 

Born global, scaled from Istanbul 

I want to write this section separately, because it was both the hardest part and probably the part I’m proudest of. 

We were built as a global company from day one. The product was in English, the documentation was in English, the data coverage was worldwide from the start. In 2020 we incorporated in the United Kingdom and made London our headquarters. We treated Turkey as a starting point, never as a ceiling. 

But let me be direct about this: it is not easy for a regtech company coming out of Turkey to sell software to Europe’s largest insurance groups, to established American institutions, and to a United Nations agency. Compliance is the industry where trust is most expensive. A bank’s compliance officer is putting billions of dollars of penalty exposure into your product’s hands. 

In those early years, we heard the same question in nearly every meeting: “Where are you from?” 

There is no rhetorical answer to that question. You can’t get past it with a deck, a reference, or a price. The only way through is for the product and the references to answer it for you. A query returning in 100 milliseconds in the demo. A screen that catches a name absent from every list but present in a news article three years old. A sanctions measure issued at midnight showing up in the system by morning. That’s the answer we tried to give, and I think we gave it. 

Today more than 800 companies across 80+ countries and four continents run on our platform. 

Fintech and payments is where we were born. iyzico, Turkey’s largest payment institution. Papara in digital banking. Midas in retail investing. Moka United in fintech-as-a-service. TPay in e-money and merchant onboarding. BPN, a Western Union partner, in remittance. Candex in B2B payments. Hometap in US home equity. What these companies have in common is an intolerance for latency: they will not accept compliance slowing down an onboarding flow or a payment flow. That demand is what actually shaped our product. 

Then came scale. In insurance we work with Zurich, Generali, and NN, among Europe’s largest groups. In automotive, BMW and Stellantis. In technology, Unity, Voodoo, and Delivery Hero. APMEX in US precious metals. Luxaviation, the Luxembourg-based aviation group. Loomis in cash management. MyFatoorah in the Middle East. Moldcell in Moldova, Ateshgah Life in Azerbaijan, AirHelp in Poland. And perhaps the one that means the most, UNOPS, the United Nations Office for Project Services. 

In Turkey, Hepsiburada, Kuveyt Türk, QNB, Türk Telekom, Borusan, and OYAK are on the platform. We went deep at home and out into the world at the same time. Very few companies manage both. 

External recognition followed. We made the Deloitte Technology Fast 50 Turkey three years running, once at number eight. We made the Deloitte Technology Fast 500 EMEA twice, placing us among the fastest-growing technology companies across Europe, the Middle East, and Africa. We were named to the FinCrimeTech50 as one of the world’s 50 best technology companies fighting financial crime, and to the RegTech100 in 2022. We hold 5.0 on Capterra and Gartner and 4.7 on G2, and those scores came from teams using the product daily, not from a marketing budget. We hold ISO 27001 and ISO 9001, built the infrastructure GDPR-compliant from the start, and offer EU data residency. 

But none of that is what I’m proudest of. What matters is what actually changed inside our customers’ operations. 

And it was never just screening. At Moldcell, 1.5 million users are protected, roughly 100,000 transactions are screened, about 10,000 are flagged for review, and more than 2% of those come back high risk. Monitoring a telecom operator’s financial services arm at that scale is orders of magnitude beyond list screening. 

AirHelp cut daily operational time by 62% and has paid out to more than 2.2 million passengers across 35 countries. The problem there was making sure compliance on the payout leg never left a passenger waiting. 

Octet operates across 72 countries with 4,500 member companies and reduced false positives by 70%, screening both sides of a trade, buyer and seller, simultaneously. 

For DLL Group, a global vendor finance company, speed was never the issue. It was case management, a complete audit trail, and a GDPR-ready structure. For TPay it was merchant KYC completing in seconds. For Moka United it was real-time risk alerting over a two-way API. For Ateshgah Life it was continuous, around-the-clock monitoring of more than 3,000 customers. 

The product does a far wider job than the name on the box suggests. Half the answer to why we changed that name is in these paragraphs. 

Why Complead, and why now 

“Sanction Scanner” was the right name on the day we founded it. That’s what we did. We screened sanctions lists. 

That is not what we do now. 

Today we build a customer’s risk profile at onboarding, monitor their transaction flow in real time, catch fraud patterns, unwind corporate ownership and ultimate beneficiaries, assemble the compliance team’s case file, and generate the report that goes to the regulator. Only a small slice of that is screening. 

The name was a photograph of the company. The company outgrew the frame. 

We saw it concretely in how inbound demand changed. Most requests in recent years didn’t start with “we’re looking for sanctions screening.” They started with “we want to run our entire compliance operation from one place.” Our name was bringing us customers and simultaneously narrowing what people thought we did. They knew us by the label on the box and discovered the contents late. 

The second reason matters more. We are no longer selling compliance software. We are building AI-native compliance, risk, and fraud infrastructure. Tomorrow it will probably be more than that. 

The distance between those two things is roughly the distance between an accounting package and a payments network. Software is something a person sits down and uses. Infrastructure gets embedded into the business and runs. 

Complead is the name for the second thing. It comes from three roots, and none of them is accidental. 

Compliance. The work itself. We’re not forgetting where we came from. Six years of data, PEP, and auditability sit inside that word. Being AI-native does not mean treating the rules of compliance lightly. The opposite: it means answering to those rules better than before. 

Complete. Wholeness. What actually hurts compliance teams isn’t a missing tool, it’s a fragmented picture. Screening over here, transaction monitoring over there, fraud somewhere else, case management in a fourth place, and risk disappearing into the gaps between them. Closing exactly that gap is what we set out to do when we built Fusion: one data layer, one view of risk, no blind spots. Complete is the name of the architecture. 

Lead. Getting in front. Compliance has spent years as the function that arrives second. A regulation is issued; the institution adapts. A criminal method changes; the system catches up later. An alert fires; an analyst chases it. We want to invert that order: a system that sees risk before it materializes and builds the reasoning in advance. And frankly, we mean the second sense of the word too. We intend to lead this category. 

All three together: a complete compliance infrastructure, and a compliance posture that stands in front. 

Why now? Because we’re at an inflection point in the technology, and the companies that catch it early will define the next decade. Rule-based compliance systems are running out of road. The next generation will be built on a different architecture, and we chose to build it from scratch rather than retrofit it. The rebrand is the visible surface of that decision, not the reason for it. 

Sanction Scanner isn’t going anywhere. It continues under Complead. No disruption, no migration, no contract change for any team using it. But the company’s identity is no longer defined by the name of a single product. 

Expanding into the United States 

We grew across Europe, the Middle East, Central Asia, the Caucasus, and Africa. Now we’re shifting our center of gravity to the United States, and I’m writing this as a step already taken rather than a statement of intent: we have incorporated in New York. 

This is not a representative office or a sales desk. It’s a local legal entity, a local team, and a structure that meets an American customer’s contracting, invoicing, data residency, and audit expectations locally. In compliance, these details aren’t decoration. They are the purchasing decision. A US bank’s procurement committee asks where a vendor is incorporated within the first ten questions. 

We took this step for three reasons. 

First, the market is there. More financial crime compliance spend happens in the US than anywhere else. The burden created by OFAC, FinCEN, and state-level requirements is a serious line item for large banks and fast-growing fintechs alike. 

And the incumbents dominating that market are expensive, unwieldy systems designed decades ago. Implementations measured in months, consultants required for every change, pricing closed to negotiation. It looks a great deal like the picture we saw in Europe six years ago. We read that picture once and read it correctly. We’ll be faster the second time. 

Second, our customers are already there. A significant share of the global companies on our platform have US operations. Working with American customers like APMEX, Hometap, and Candex taught us this market’s real requirements, audit expectations, and buying processes over a period of years. 

We’re not starting cold. We were already inside; we’ve simply decided to be there officially. 

Third, the timing. US compliance teams are under serious pressure on AI right now. Boards want efficiency; regulators want explainability. Very few systems can deliver both at once. 

Most companies either build a fast model they can’t explain, or cling to an explainable rules engine that’s too slow. We’re building precisely at that intersection, and I can’t think of a better moment to enter. 

We don’t treat the US expansion as a sales story. It means rethinking the product, the data, the reporting formats, and the audit trails around the American regulatory frame. A meaningful portion of our engineering investment is going there. 

What AI-native means, and what it doesn’t 

This is the most important section of this piece, because the term is being consumed so quickly in our industry that someone needs to speak plainly to preserve its meaning. 

The problem isn’t the model. It’s the ground under it. 

Look at this industry over the past two years and everyone is running the same race: add intelligence on top of the existing system. A better model, a better summary, a smarter assistant. 

We think the order was wrong from the start. 

What determines the quality of a compliance decision is not the intelligence of the model making it. It’s the integrity of the ground beneath it. However good your model is, if your PEP data is six months stale, it will give you the wrong answer faster and with more confidence. That is more dangerous than giving no answer at all. 

Intelligence built on weak data doesn’t produce errors. It produces confident errors. And in compliance, a confident error has a name. It’s called a penalty. 

This is also the root of what the industry calls its false positive crisis. Up to 95% of AML alerts going nowhere is not a staffing problem. It’s a resolution problem. The system fires because it cannot tell two people apart. Because it cannot reconcile two spellings of the same name, two records of the same person, or the perpetrator’s name and the victim’s name in the same article. 

That noise doesn’t get solved by analyst overtime. Fix the ground and most of it never existed. 

We spent six years building that ground. Consolidating 220 countries of lists, mapping PEP networks that have no official registry anywhere, structuring adverse media sources: none of that was an AI project. But it was the one prerequisite for AI working at all. Which is why our model layer isn’t something bolted onto the product late. It’s a floor that rose naturally on ground that was already there. 

Put simply: the industry built models and went looking for data. We built the data, and the models became possible. 

What intelligence does without ground under it 

Most of what carries the “AI” label today is missing that foundation. It shows up in three forms, and all three are crippled in the same place. 

The summary that can’t verify. It takes an alert someone else produced and restates it. With no data of its own, it can’t confirm a single claim it makes, it can only rephrase. Impressive in a demo, worthless in an exam. 

The assistant that answers but doesn’t act. It lets the analyst ask questions. But the analyst still drives every step, still forms the judgment, still writes the narrative. The engine is still a person; the assistant just pulled up a chair. 

The agent that acts but can’t cite. This is the dangerous one. It produces a decision and even writes a persuasive rationale. But ask it where that fact came from, what date it was true, and whether the source still holds, and it has nothing. In an examination, that is a bigger problem than the decision itself. 

What they share: none of them owns the data underneath. Each is repackaging someone else’s output. And in compliance, an answer you cannot source is not an answer. 

What we did about it 

That’s why we built Fusion, and we built it on one principle: the AI’s job is not to answer the analyst’s questions. It’s to do the work the analyst would have done. 

Today, Fusion’s AI agents resolve 77% of routine cases automatically. The agent takes the alert, gathers the relevant data, compares it against the customer’s full risk profile, checks prior decisions, writes the reasoning, and closes the file. What reaches an analyst is what genuinely requires human judgment. 

Rule-writing changed too. A compliance professional can now write a rule in plain language. No logic trees, no code, no consultant. Building, testing, and deploying a rule is five times faster. 

And the entity resolution problem we’d wrestled with for years went somewhere new once models were involved: false positive reductions of up to 97%. Whether “José Luis Hernández,” “Jose L. Hernandez,” and “J.L. Hernandez” are one person or three now gets an answer that accounts for context: the diacritics, the abbreviated middle name, the date of birth that’s off by a day, the address two states away. On a name that common, a system that only compares strings will either flag everyone or miss the one that matters. 

Adverse media saw a similar jump. Determining whether a name in an article is the perpetrator, the victim, or the reporter who wrote it is not something keyword search can do. Language models can, and do. 

The part that isn’t for show 

The hard part of AI in a compliance product isn’t running the model. It’s defending the decision. 

When an examiner asks why a decision was made, “the model said so” is not an acceptable answer. And it shouldn’t be, because in this industry an unexplainable decision is a decision not made. 

So every agent output carries three things: the evidence it rests on, a narrative written in the format the examiner expects, and a transparent work log showing every step taken and every source checked. If it isn’t defensible, we don’t ship it. 

There’s an objection I hear often: AI can’t be used in regulated environments because you can’t explain how it works. That isn’t true. It’s an engineering problem, not a law of nature. It can be solved, and we solved it. 

Our agents are configured not to a generic template but to each customer’s own procedures, thresholds, and risk appetite. When your process changes, your team updates the agent in minutes, not through a six-month professional services engagement. 

And they scale. A chatbot is bound to the analyst: one person, one conversation, one investigation. That grows linearly. Agents run in parallel, thousands of alerts at once, without anyone pressing start. 

Most importantly, they compound. Every decision your analysts make, every escalation, every confirmed outcome feeds back and sharpens the next call. The more your team uses it, the better it gets. 

The third layer: compliance-as-infrastructure 

The biggest change is here, and very few people are talking about it yet. 

Compliance stops being a screen people log into and becomes a layer that runs between systems. Through APIs, through MCP, embedded directly inside other software. Inside a payment flow, inside an onboarding flow, inside an ERP. Without anyone opening a separate application. 

We’re serious enough about this to have already shipped against it: Sanction Scanner is listed in Claude’s connector directory. A compliance officer can ask for a name’s risk profile without leaving their working environment and get the answer straight from our data and decision layer. 

That may look like a small step. To us it’s the first link in how this work will be done. Five years from now, whether a compliance product even has an interface will be an open question. 

What I actually believe 

Hedging on these points helps no one, so let me be plain. 

AI will not replace compliance analysts. It will change the nature of the job. Instead of performing repetitive tasks yourself, you’ll be governing the AI’s decisions. Your expertise becomes more valuable, not less, because the quality of the system now rests on you. 

“Fewer alerts” is the wrong metric. The industry has spent years measuring itself by how far alert volume dropped. The real question is different: of the risk that actually existed, how much did you see? Reducing alerts is trivial. Raise a threshold and you’re done. The hard part is reducing them without missing anything. We judge a system less by the alerts it raises than by the ones it doesn’t. 

Compliance isn’t one problem. It’s two hundred. This is where most vendors quietly fall down. You cannot train a model on US data and sell it to the world. PEP definitions change across borders. So do name structures, alphabets, and the report format an examiner expects. An AI that performs well in one jurisdiction degrades silently the moment it crosses into another, and nobody tells you it happened. The hard part of global compliance infrastructure isn’t scale. It’s locality. 

And this isn’t only a product problem. Financial crime funds trafficking, cartels, terrorism, and exploitation. When compliance teams drown in meaningless alerts, the real threats slip through. Every alert closed correctly is capacity returned to the case that actually matters. I’ve been doing this for six years, and that’s the reason. 

One last thing 

Changing your name is not an easy call. You’re putting six years of accumulated trust, recognition, and search equity at risk. We didn’t take it lightly; we argued about it for months. There were people on the team who objected, and they weren’t wrong to. 

But what kills companies usually isn’t making the wrong decision. It’s making the right one too late. 

Compliance will change more in the next five years than it did in the previous twenty. Most of the systems that dominate the market today won’t make it to the other side of that change. The problem isn’t that their products are old. It’s that their architecture rests on a false assumption: that compliance is work bounded by the speed of a human being. 

That assumption no longer holds. 

Let me be direct: our goal is not to be a good alternative. It’s to redefine how financial crime is fought worldwide. If I’d said six years ago that we’d do it with a team that started in Istanbul, incorporated in London, and now reaches New York, nobody would have believed me. We believe it now, and the numbers back us. 

The question we asked on day one still stands. Only the scale of the answer has grown. 

The Sanction Scanner story isn’t over. It turned out to be chapter one of a much larger one. 

Today we’re introducing Complead. A new name, a new identity, a new claim. But none of that is the point. 

The point is this: we intend to write how compliance gets done from here. Come write it with us. 

 

Fatih Coşkun is Founder and CEO of Complead. He has spent over 15 years building payments, fintech, and banking technology. 

Originally published , updated

Back to news