Reference
AI Assistant User Guide
Every slash command in the cabinet AI Assistant, the MCP tools behind them, and how to drive the same checks from ChatGPT or Claude.
1. What This Covers
Two surfaces, one engine. The in-cabinet AI Assistant is a chat interface built into the client cabinet, with slash commands that open guided forms for each workflow. The MCP connector lets a customer drive the same checks from their own ChatGPT or Claude client, with no slash commands — the model picks a tool from the wording of the request. Both surfaces call the same underlying tools, so a screening result means the same thing regardless of which one produced it.
Example company, person and vessel names throughout this guide are fictional. Where a name is a real public office holder (the PEP examples), that is deliberate — the point of a PEP check is that the office is a matter of public record.
2. How To Use The AI Assistant
Type a question in plain language, or type / for a guided form.
- Chat interface. Ask about sanctions, TARIC or compliance in plain language — the assistant picks the right tool and runs the check.
- Slash commands. Type
/and select a prepared workflow. Each command opens a form with exactly the fields that workflow needs. - Three main entry points.
/entityfor KYC and name sanctions,/goodsfor goods / CN / TARIC,/paymentfor ISO 20022 XML. Everything else is a narrower, faster path to one of those three.
3. Command Summary
Sixteen slash commands across five categories.
| Command | What it does | Category |
|---|---|---|
/entity | Guided sanctions/KYC screening for a person, company, bank, vessel or aircraft. Alias /screen. | Screening |
/audit | Point-in-time screening against the sanctions state on a chosen past date, including delisted records. Alias /history. | Screening |
/lv-frozen | Latvian counterparty KYC against the Latvia FID frozen-assets registry. | Screening |
/vop | Verification of Payee (EPC288-23) close-match screening for a payee name. | Screening |
/pep | Politically Exposed Person check — an EDD risk signal, not a sanctions block. | Screening |
/vessel | Vessel screening by name and/or IMO, before port service, onboard work or supply. | Screening |
/goods | Guided CN/TARIC form: report, overview, sanctions, duties, measures, description or search. | Goods |
/report | Client-ready HTML compliance report for a CN code and country. | Goods |
/overview | Compact CN card: description, duty signal, measures, sanctions status. | Goods |
/embargo | RU/BY goods embargo check by CN code, direct and group-level matches. | Goods |
/duty | Duty rates only — third-country, customs union, preferential. | Goods |
/measures | Full TARIC measures — prohibitions, licences, VAT, duties. | Goods |
/code | Find a CN code by product description or numeric prefix. | Reference |
/describe | CN classification hierarchy, without measures or sanctions. | Reference |
/sources | The live sanctions and export-control source catalog. | Sources |
/payment | ISO 20022 screening form — one-shot report or a persisted PaymentCase. | Payments |
4. Screening — /entity
The general-purpose screening form. Target type defaults to Legal person and also offers Natural person, Bank / BIC, Vessel and Aircraft — there is no "any type" option here; pick the type that matches the subject. Fields: name or identifier, country, date of birth, registration number, threshold (default 75), result limit (default 10), and an optional as-of date with an "include historical closed" toggle for a point-in-time variant of the same form.
There is no address field on /entity itself — address-assisted matching is available on /audit and through the API/MCP form directly, not the /entity slash command.
Example requests:
- Individual KYC before account opening — Natural person ·
Igor Sergeyevich Orlov· countryRU· DOB1968-11-02. - Company counterparty check — Legal person ·
Northbridge Trading Ltd· countryRU. - Bank / BIC screening — Bank / BIC ·
NBTRRUMM. - Registration-number check —
40003698011as both name and registration number.
Returns matches with score 0–100, source, regulation, grounds, DOB, registration number and a score explanation. For OFAC vessels the result also carries vessel particulars (type, flag, tonnage) and owner/controller related parties parsed from the OFAC advanced relationship graph — useful for shadow-fleet and beneficial-owner review.
5. Screening — /audit
Re-screens against the sanctions state on a selected past date — "What did we know about client X on transaction date Y?" Unlike /entity, the name/identifier field here is optional and the as-of date is required; /audit also exposes an Address field for a separate address-match signal. Uses SCD2 sanctions-list history and includes delisted records by default (include_historical_closed defaults to on, the opposite of /entity's default).
Example requests:
- Regulator defense — "Was company X sanctioned when we processed transaction 2026-04-15?" Name
Karvela Machinery ZAO· as-of date2026-04-15· include delisted: yes. - Previous-year KYC audit — Name
Dmitri Volkov· as-of date2025-12-01· include delisted: yes.
The summary states whether each match was active or already delisted on the selected date.
6. Screening — /lv-frozen
A one-click check against the Latvia FID frozen-assets registry — whether a Latvian SIA, fund or person appears there because of an ownership/control link to an EU/UN sanctioned principal. Threshold defaults to 60, lower than the platform-wide 75, because Latvian names are usually distinctive enough that recall matters more than precision for this narrow registry.
Example requests:
- Latvian SIA screening before a deal —
Baltijas Tirdzniecība SIA. - Registration-number lookup —
50003698011. - Resident individual —
Igors Ozols.
On a match, the answer names the sanctioned principal and the legal basis — for example Reg. 269/2014 and the designated individual behind the link.
7. Screening — /vop
Verification of Payee under Regulation (EU) 2024/886. Each match returns an explicit EPC288-23 decision code:
| Code | Meaning |
|---|---|
MTCH | Match — allow |
CMTC | Close match — manual review |
NMTC | No match — block or investigate |
NOAP | Not applicable |
The chat card shows the top result code, scenario, normalized match, score, list and the Reg. (EU) 2024/886 audit badge.
Example requests:
- Before a SEPA transfer — payee name as on the instruction
Igor Sergeyevich Orlov· countryRU· DOB1968-11-02. - Legal person with BIC — payee
Vostok Pipeline OAO· registrationNBTRRUMM.
8. Screening — /pep
Screens a person against the Politically Exposed Persons layer. A PEP hit is an Enhanced Due Diligence (EDD) risk signal — not a sanctions block. It flags political exposure; it does not by itself refuse a relationship. Run /pep alongside /entity, not instead of it — a person can be both a PEP (EDD) and separately sanctioned (block).
Current source coverage: EU-27 and European Parliament office holders, plus official national sources — Georgia's ACB asset-declaration data, the Latvian Saeima, the Estonian Riigikogu, the Lithuanian Seimas, and a Central Asia parliamentary layer (Kazakhstan, Kyrgyzstan, Uzbekistan). This list has grown steadily since the layer launched and keeps growing; /pep's own result — not this guide — is the current word on coverage.
Each match returns pep_status (active or former, with the FATF/AMLD 12-month grace period after leaving office applied), the office held and its tenure, country and PEP class.
Example requests:
- Is
Jean-Claude Junckera PEP? CountryLU. - Was
Ursula von der Leyena PEP as of2018-01-01?
9. Screening — /vessel
A dedicated vessel-screening command — fixed to entity_type=vessel, so there is no target-type selector to set. Use it before port service, onboard work, offshore service or spare-parts supply.
Example request:
- Vessel name or IMO —
NS LEADER/SPARTA IV· IMO9339301.
As with /entity, an OFAC hit surfaces vessel particulars and owner/controller related parties from the advanced relationship graph — the vessel's own record is rarely the whole picture; the owner behind it usually is.
10. Goods — /goods
The universal goods entry point. Choose a workflow in the form: report, overview, sanctions, duties, measures, description or search. Best option when the operator does not remember the exact narrower command — /report, /overview, /embargo, /duty, /measures, /describe and /code are fixed-workflow shortcuts to the same underlying checks.
Example: CN/TARIC 7208510000 · country RU · date 2026-05-13 · language EN. With workflow report, this opens a client-ready HTML report.
Export-control text fields. The form also has four optional free-text fields — product description, invoice/shipping text, supplier spec, technical characteristics. They feed a keyword search into the military-list and dual-use layers described next, which a CN code alone cannot always trigger.
11. Goods-Risk Layers Beyond TARIC
Every goods check stacks TARIC duties and measures with the RU/BY sanctions overlay, then adds a growing set of export-control and product-compliance layers on top. As of this writing that set includes:
| Layer | What it checks |
|---|---|
| EU Dual-Use (Annex I) | Potential export-controlled dual-use item |
| EU Military List | Potential military item |
| EU Reg. 2024/1485 Annex I/II | Russia internal-repression goods/software |
| EU CBAM (Annex I) | Carbon border adjustment declarant/reporting obligations |
| EU Deforestation Regulation (Annex I) | Commodity due-diligence and origin evidence |
| EU Anti-Torture Regulation | Prohibited or authorisation-controlled goods |
| EU F-gas Regulation | Substance, GWP, quota/licensing |
| EU ODS Regulation | Ozone-depleting substance content and licensing |
| EU Conflict Minerals (3TG) | Supply-chain origin and responsible-sourcing evidence |
| EU Cultural Goods Regulation | Age/value thresholds, import licence, provenance |
| EU Kimberley Process | Rough-diamond certification |
| EU Civilian Firearms controls | Export authorisation and end-user evidence |
| EU Mercury Regulation | Substance content and trade restrictions |
| EU Battery Regulation | Chemistry, labelling, conformity, due diligence |
| EU Waste Shipment Regulation | Route, destination, notification/consent procedure |
| EU PIC Hazardous Chemicals | Export notification and explicit-consent status |
| EU POPs restrictions | Concentration thresholds and exemptions |
| EU Drug Precursors (internal market and trade) | Licence/registration, declarations, suspicious-transaction duties |
| EU Explosives Precursors | Concentration thresholds, licensing, reporting duties |
This table is a snapshot, not a contract — new layers are added ahead of new EU regulations taking effect, and this document is not the place to track that in real time. A hit sets review_required; these are review signals, not automatic bans. When a controlled good is shipped to a Russia/Belarus evasion-corridor country (Türkiye, Kazakhstan, Armenia, Azerbaijan, Georgia, Kyrgyzstan, Uzbekistan, Tajikistan, Turkmenistan, UAE), the check also recommends enhanced end-user screening.
12. Goods — /report and /overview
Both are fixed-workflow alternatives to /goods for when you already know which depth of output you need.
/report — client-ready HTML report. Example: CN 8517130000 · country CN · language EN.
/overview — compact CN summary: description, main duty rate, sanctions signal, key measure types. Example: CN 8471300000 · country CN · language EN.
13. Goods — /embargo and /duty
/embargo — fast RU/BY goods embargo check by CN code (Reg. 833/2014, Reg. 765/2006). Returns direct matches and group-level matches separately. Steel example: CN 7208510000 · RU. Belarus example: CN 2710120000 · BY.
/duty — duty rates only, when non-duty measures would just be noise. Omits measures, footnotes and sanctions on purpose. Example: CN 6203420010 · CN · date 2026-05-13. Returns amount, expression and regulation per duty measure.
14. Goods — /measures
The full customs-measures list — duties, prohibitions, licences, VAT and legal references — as machine-readable output, without the HTML report wrapper. Country is optional; leave it empty for a global overview of all measures. Measure type is an optional filter, for example 277 for an export prohibition. Example: CN 8517130000, country empty, measure type optional.
15. Payments — /payment
Accepts pain.001 or pacs.008 XML. The assistant validates the message, parses the payment chain, resolves BICs through the deterministic waterfall (local cache → GLEIF → configured providers), screens every participant and prepares an HTML report.
| Mode | What it does | Tool |
|---|---|---|
| One-shot screening | Temporary report and screening_run_id, durable-temporary in Supabase until TTL; does not enter the case register. | screen_iso20022_payment |
| Persist PaymentCase | Same screening, saved as an audit-ready case: raw XML, message evidence, participant evidence, BIC/GLEIF evidence, matches, warnings and report. | create_iso20022_payment_case |
To save into cases: open /payment → paste the XML → enable Persist payment case → submit. The response includes case_id; follow-up evidence loads with get_payment_case_evidence. If the checkbox is off, read the saved one-shot result back with get_payment_screening_run — by run_id, or with no arguments at all for the latest active run. Don't resubmit XML unless a rerun is explicitly requested.
Examples: one-shot — pacs.008.001.12 · persist off · threshold 75. Persisted — pain.001.001.13 · persist on · threshold 75 · as-of date empty or historical.
Expected answer: top decision (clear / review required / hit / integrity error); message metadata (type, version, message id, XSD status); payment chain (role, name, country, identifiers, verdict); validation warnings; sanctions matches with source/regulation evidence; run_id + expiry, or case_id + state; the next step for the operator.
16. Reference — /code and /describe
/code — find a CN code by product description or numeric prefix. By description: electric motors · language EN. By prefix: 8517. Returns matching CN codes with descriptions.
/describe — classification hierarchy and description only (chapter → heading → subheading → CN), without measures or sanctions. Example: CN 8471300000 · language EN.
17. Sources — /sources
The sanctions and export-control source catalog: authority, jurisdiction, coverage, update frequency and last daily-sync status. Leave the category filter empty for everything, or set it to one of sanctions, export_control, legal_entity, tax_validation, customs or legal_reference.
The catalog now covers well over ninety sources and keeps growing — new sanctions regimes, national PEP layers and export-control lists are added roughly monthly. That makes /sources itself the current word on coverage, not a fixed list in a document like this one; use it whenever an auditor or a report asks "where did this come from, and how fresh is it."
18. Reading A Case Verdict
Every persisted case — goods, chemical, entity or payment — carries a business verdict layered on top of the raw per-item status (clear / review / hit / error, the vocabulary used throughout this guide). The verdict folds in risk signals and evidence gaps together, and it's what a case's closure screen and audit trail actually key off:
| Verdict | Meaning |
|---|---|
ALLOW | No hit, no review signal, no evidence gap |
ALLOW_WITH_EVIDENCE_GAP | No sanctions hit, but some validation, source or enrichment evidence is incomplete |
REVIEW_REQUIRED | Human review is needed before relying on the result |
BLOCK | A sanctions hit, prohibition, or integrity failure prevents automatic clearance |
INVALID_INPUT | The item could not be validated or processed |
A case's overall verdict is the most severe verdict among its items — one BLOCK item makes the whole case BLOCK, regardless of how many others cleared. Any verdict other than a clean ALLOW requires an explicit reviewer acknowledgement before the case can close, and that acknowledgement — together with the full decision packet as it stood at that moment — is written to the audit trail, so a later review sees the reasoning that existed at closure time, not just whatever the case's evidence looks like today.
19. What To Ask Next
Useful for demos, QA and operator training — each checks that the assistant keeps context and can read a tool result it already has, rather than re-running the check.
| Command family | Useful follow-up questions |
|---|---|
/entity, /audit, /vessel | Why this score? Which aliases or identifiers matched? Which lists and regulations? Historical or delisted status? Ownership/control signals? What should the operator do next? |
/lv-frozen | Frozen-assets record or ordinary sanctions entry? Who is the sanctioned principal? Which Latvian legal basis applies? |
/vop | Which EPC code — MTCH, CMTC, NMTC, NOAP? Why close match rather than exact? Which payee fields need correcting? |
/pep | Active or former, on which as-of date? Which office and country? Does the 12-month grace still apply? Also on a sanctions list? |
/goods, /report, /overview | Which workflow and CN code? Legal basis and source links? Executive summary for the client? Should the full report open? |
/embargo | Direct or group-level match? Which CN/heading level triggered it? Which regulation? |
/duty | Third-country or preferential rate? What changes with a different origin? Which non-duty measures were intentionally omitted? |
/measures | Which measure types apply — prohibitions, licences, anti-dumping, VAT, additional codes? |
/code, /describe | Which code is most likely, and closest alternatives? Where does it sit in the hierarchy? |
/sources | Which sources are enabled, and when did they last sync? Which are used for entity/goods/payment specifically? |
/payment | Who requires review and why? Validation warnings? Run expiry or case_id/state? Riskiest participant? How to persist it into a case? |
20. MCP Tools Behind The Assistant
Every slash command and natural-language request resolves to one of these MCP tools underneath. Grouped by category rather than by command, because several tools — the run-getters especially — aren't triggered by any single slash command; they're read by a follow-up question after a form already ran.
KYC/AML screening
| Tool | Role |
|---|---|
screen_entities | Core sanctions screening for people, companies, vessels, banks, aircraft |
screen_entity_vop | Verification of Payee close-match classification (EPC288-23) |
screen_pep | Politically Exposed Persons screening |
open_entity_screening_form (+ short alias entity) | The /entity widget; runs screen_entities and persists a run for follow-up |
lookup_ofac_asset_related_parties | OFAC owner/operator/related-party metadata for vessels and aircraft — relationship evidence only, not a screening result on its own |
get_entity_screening_run | Re-reads a recent entity-screening form run without rerunning it |
Goods / customs / export control
| Tool | Role |
|---|---|
get_compliance_report, check_trade_compliance | Full goods check: TARIC, duties, sanctions overlay, goods-risk layers |
get_overview, get_measures, get_duties | Narrower fixed-scope views of the same evaluation |
check_sanctions | RU/BY goods embargo only |
search_cn_codes, get_cn_description | Classification search and hierarchy, no measures |
search_chemical_substances | ECICS lookup by CAS RN, CUS, EC number, InChIKey or name |
search_export_control_candidates | Candidate matches across EU Military List, EU Dual-Use, US EAR/ITAR and UK sources; entity/end-user hits route to screen_entities instead |
open_goods_screening_form (+ short alias goods) | The /goods widget |
get_goods_screening_run | Re-reads a recent goods-form run without rerunning it |
KYB / business registry
| Tool | Role |
|---|---|
search_business_registry | Company-register search — Latvia, Estonia, Kazakhstan, Poland (KRS by number) |
get_business_registry_profile | Company card, related-party records and source evidence for LV/EE/KZ/PL |
screen_business_entity_with_related_parties | Resolves a registry company, expands related parties, screens them — without writing a case |
Payments (ISO 20022)
| Tool | Role |
|---|---|
validate_iso20022_payment | Structure/XSD validation and the six-node payment chain |
screen_iso20022_payment | One-shot screening of every participant |
create_iso20022_payment_case | Persists an audit-ready PaymentCase |
get_payment_screening_run, get_payment_case_evidence | Re-read a one-shot run or a persisted case without rerunning it |
open_payment_screening_form (+ short alias payment) | The /payment widget |
resolve_payment_bics_agentic | MCP-only web-search assist for unresolved BICs — never changes a verdict on its own |
Explainability
| Tool | Role |
|---|---|
list_sanctions_sources | The live source catalog behind /sources |
get_connector_metadata | Connector self-description for clients that can't browse MCP resources or prompts |
21. Connecting External AI Clients
Customers can drive the platform from their own ChatGPT or Claude, without ever touching the cabinet.
- ChatGPT. chatgpt.com → Connectors → add the Compliance MCP server.
- Claude. claude.ai → Settings → Connectors → Add MCP server.
After connection there are no slash commands — the model reads each tool's description and matches it to the wording of the request, so phrasing is the routing signal. Give unambiguous signals: an 8–10 digit CN code, an ISO-2 country code, "point-in-time" or "VoP" when relevant, "HTML report" when a deliverable is needed.
22. How The Assistant Chooses A Tool
A compact map of request wording to the tool it tends to trigger — useful for predicting behavior, not a strict grammar.
| Wording in the request | Tool likely called |
|---|---|
| CN code + country + "check", "report", "compliance" | get_compliance_report |
| CN code + "overview", "summary" | get_overview |
| CN code + "duty", "tariff" | get_duties |
| CN code + "measures", "prohibitions" | get_measures |
| CN code + RU/BY + "sanctions", "embargo" | check_sanctions |
| CN code + "hierarchy", "classification" | get_cn_description |
| Product description, no code | search_cn_codes |
| CAS RN / CUS / EC number / InChIKey | search_chemical_substances |
| "export control", "dual-use", "military list" | search_export_control_candidates |
| Name/company + "screen", "KYC", "sanctions list" | screen_entities |
| Vessel name/IMO + "owner", "beneficial owner" | screen_entities (vessel) → lookup_ofac_asset_related_parties |
| "as of date", "point-in-time", "audit" | screen_entities with as_of_date |
| "is X a PEP", political exposure | screen_pep |
| Payee name + "payment", "VoP" | screen_entity_vop |
| ISO 20022 XML, pain.001 or pacs.008 | validate_iso20022_payment → screen_iso20022_payment |
| Company registry, UBO, related parties | search_business_registry → screen_business_entity_with_related_parties |
| "where is the data from", "freshness" | list_sanctions_sources |
23. Tips
- Natural language works too. "Check Northbridge Trading Ltd in OFAC" works as well as opening
/entity. - Slash commands save time when you already know the workflow — the form opens with the right fields immediately.
- Limit and threshold. For broad, common names raise the result limit to see subsidiaries or namesakes; raise the threshold above 75 for stricter screening.
- As-of date. Empty means current state; setting a date switches to historical screening for that date.
- Open / Download HTML. For
/report,/goodsand/overviewthe card includes signed, time-limited Open report and Download HTML links. - Tool arguments. Each slash form has a collapsed JSON block showing exactly what was sent to the MCP tool — useful for debugging and training.
- CN codes and countries, externally. Over MCP, use 8 or 10 digits without spaces, and ISO-2 country codes — the model routes more reliably on unambiguous input.
24. What Not To Do
- Do not ask the assistant to bypass sanctions. It is built to refuse evasion requests and avoid tool calls for them.
- Do not send unnecessary personal data. Name, country, date of birth and registration number are enough for screening in almost every case.
- Do not rely on a model answer without a tool call. Ask explicitly to screen against the platform's lists — a plausible-sounding answer is not a screening result.
- Do not confuse goods embargo with entity screening. A CN code goes to the goods pipeline; a name goes to the entity pipeline. They answer different questions, and neither substitutes for the other.
Every compliance decision should trace back to a tool call and a named source — across both surfaces, the cabinet assistant and the external MCP connector, that rule doesn't change.