Fraud, sanctions, and AML checkpoints

Fraud, sanctions, and AML checkpoints. A practical lesson in the complete pipeline for banking and payments practitioners.

Plain language meaning

Fraud, sanctions and AML checkpoints test whether the loan application can proceed safely by checking identity risk, synthetic application signals, sanctions exposure, customer due diligence concerns and money-laundering risk before a banking decision is completed.

This topic is about control checkpoints inside a bank lending pipeline. It should not drift into transaction message processing or post-decision operational routing.

In a real bank, this is not a loose technology idea. It is a controlled operating step where customer facts, banking policy, model behaviour, human authority, legal obligations and retained evidence must line up. AI and ML can improve speed, consistency and detection quality, but the bank must still prove why the process was fair, explainable, secure, monitored and fit for purpose.

Where it sits in the banking AI journey

This card belongs to The Complete Pipeline. The working flow is Application risk, Fraud signals, Sanctions screen, AML risk, and Control outcome.

Read the flow as a banking control journey. Each stage needs a source system, a decision purpose, a failure mode, a control owner, a fallback path, a customer-impact view and retained evidence. Without those elements, the bank may have automation, but it does not yet have a bank-grade AI process.

Banking data and evidence

The important data points are identity match, device risk, application velocity, sanctions match, PEP status, adverse media flag, source of funds note, and CDD risk rating. These items matter because they influence lending eligibility, affordability, fraud risk, compliance treatment, operational queueing, regulatory reporting, customer explanation and audit traceability.

The evidence pack should include fraud score, sanctions screening result, AML risk rating, case note, disposition code, reviewer decision, and audit trail. A strong bank can replay the case from source data to feature values, model output, control result, human review, final outcome and monitoring result. A weak bank only knows that a system produced an answer.

Controls that make AI adoption safe

The core controls are fraud rules, model referral, sanctions list screening, false-positive review, CDD review, enhanced due diligence, and case escalation. These controls make the topic bank-grade because they tie technical output to approved policy, legal obligations, model governance, operational resilience and management accountability.

AI can help compare records, detect anomalies, retrieve policy, summarise case evidence, prioritise work, highlight weak signals and improve investigator consistency. It should not invent missing facts, ignore failed checks, bypass authority, hide uncertainty, decide material customer outcomes without approval or create explanations that cannot be tied back to approved sources.

Regulatory and governance lens

For banking use cases, model risk, fair lending, adverse-action explanation, credit-risk governance, data lineage, operational resilience, AML/CFT risk-based controls, sanctions compliance, fraud information sharing and auditability can meet in the same workflow. The practical design must therefore be narrower and more disciplined than a generic AI design.

The practical test is simple: if a reviewer asks why the bank used the data, why the model output was trusted, why the customer received that action, why an alert was cleared, why an exception was approved, or why a regulatory record was prepared, the evidence must already exist.

Diagram walkthrough

Read the diagram from left to right as Application risk, Fraud signals, Sanctions screen, AML risk, and Control outcome. The diagram is a control map, not decoration. It shows the minimum route by which data, AI or ML output, human action and audit evidence should connect.

Use it as a 30-minute study method. For each box, ask what system produces the data, what can go wrong, what control detects the weakness, who reviews the case, what customer or regulatory impact could arise and what record proves closure.

Most important mistake to avoid

The common failure is treating fraud, sanctions and AML as afterthoughts after credit approval, instead of hard control gates that can stop, refer or condition the loan journey.

The correction is to slow down the thinking, not necessarily the process. A well-designed banking AI process can be fast, but every fast step must still leave behind source lineage, control evidence, decision reason, human accountability, monitoring data and issue ownership.

Source anchors for accurate study

Federal Reserve SR 26-2, dated 17 April 2026, supersedes SR 11-7 and SR 21-8 for traditional model risk management and clarifies that generative and agentic AI need governance through broader risk-management controls.

NIST AI RMF 1.0 uses Govern, Map, Measure and Manage functions for AI risk management, and NIST AI 600-1 adds generative-AI risk actions for content provenance, hallucination, data protection, cybersecurity and human oversight.

U.S. Regulation B, 12 CFR 1002.9, requires specific principal reasons for adverse action in covered credit decisions, including when a creditor uses an AI model. CFPB Circular 2022-03 was withdrawn on 12 May 2025; do not cite it as current guidance. Primary sources: https://www.consumerfinance.gov/rules-policy/regulations/1002/9 and https://www.consumerfinance.gov/compliance/guidance/withdrawn-guidance/.

The EU AI Act treats AI systems used to evaluate creditworthiness or establish credit scores for natural persons as high-risk, except certain fraud detection and prudential capital contexts.

The Basel Framework IRB standards require banks to estimate and validate PD, LGD and EAD using relevant data, meaningful risk differentiation and ongoing governance.

FFIEC BSA/AML examination guidance expects suspicious activity monitoring systems to be risk-based, explainable by management, periodically reviewed and independently validated where appropriate.

Federal Reserve SR 26-3 and FinCEN's 12 June 2026 Section 314(b) materials clarify fraud-related information sharing under the USA PATRIOT Act safe-harbor framework for participating financial institutions.

OFAC's Framework for Compliance Commitments describes sanctions compliance programme components including management commitment, risk assessment, internal controls, testing and auditing, and training.

Three controls, three decision records

In the fictional loan journey, a device change may trigger a fraud challenge, a party match may require sanctions investigation, and transaction patterns may create an AML alert. These are not interchangeable scores. Fraud review tests whether the application or account activity is suspicious; sanctions screening follows applicable restrictions and match disposition; AML monitoring examines activity in a wider context. The pipeline should record the payload screened, rule or model version, result, reviewer authority, timestamp and final disposition for each control. A fraud model's low score does not clear a sanctions match, and an AML alert is not itself proof of criminal conduct.

Test a changed customer name after an earlier screening clearance. The bank must determine which checks rerun on the final payload, and no downstream decision should inherit a clearance tied only to an older version. Test a control timeout: the approved fallback must be explicit, with an operational owner and customer status that does not invent a result. Sensitive investigation notes should stay within permitted access, while the lending workflow receives only the state and action it is authorized to use. The audit trace should show which checkpoint held the application, what evidence resolved it, and when the next stage became eligible.

Banking practice note: customer purpose

For fraud, sanctions, and aml checkpoints, customer purpose is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from identity match to fraud score. Then ask which control from fraud rules proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

AI can assist by comparing records, detecting unusual patterns, retrieving approved policy, summarising weak evidence, prioritising exceptions and preparing review notes. The bank should not allow a generated explanation, a confident score or a convenient dashboard to replace validation, consent, human judgement, customer communication, regulatory judgment or issue closure.

A strong implementation records the source event, data timestamp, consent or lawful basis, model or prompt version, feature values, score or generated output, threshold, reason code, user action, exception status, monitoring result, owner review and final outcome. That record lets risk, compliance, audit, technology and operations speak from the same facts.

Banking practice note: consent and lawful use

For fraud, sanctions, and aml checkpoints, consent and lawful use is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from device risk to sanctions screening result. Then ask which control from model referral proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: source lineage

For fraud, sanctions, and aml checkpoints, source lineage is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from application velocity to AML risk rating. Then ask which control from sanctions list screening proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: KYC and identity

For fraud, sanctions, and aml checkpoints, KYC and identity is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from sanctions match to case note. Then ask which control from false-positive review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: account behaviour

For fraud, sanctions, and aml checkpoints, account behaviour is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from PEP status to disposition code. Then ask which control from CDD review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: feature freshness

For fraud, sanctions, and aml checkpoints, feature freshness is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from adverse media flag to reviewer decision. Then ask which control from enhanced due diligence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: point-in-time correctness

For fraud, sanctions, and aml checkpoints, point-in-time correctness is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from source of funds note to audit trail. Then ask which control from case escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: model version

For fraud, sanctions, and aml checkpoints, model version is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from CDD risk rating to fraud score. Then ask which control from fraud rules proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: decision threshold

For fraud, sanctions, and aml checkpoints, decision threshold is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from identity match to sanctions screening result. Then ask which control from model referral proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: reason code

For fraud, sanctions, and aml checkpoints, reason code is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from device risk to AML risk rating. Then ask which control from sanctions list screening proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: human review

For fraud, sanctions, and aml checkpoints, human review is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from application velocity to case note. Then ask which control from false-positive review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fraud control

For fraud, sanctions, and aml checkpoints, fraud control is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from sanctions match to disposition code. Then ask which control from CDD review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: sanctions control

For fraud, sanctions, and aml checkpoints, sanctions control is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from PEP status to reviewer decision. Then ask which control from enhanced due diligence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: AML control

For fraud, sanctions, and aml checkpoints, AML control is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from adverse media flag to audit trail. Then ask which control from case escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fair lending

For fraud, sanctions, and aml checkpoints, fair lending is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from source of funds note to fraud score. Then ask which control from fraud rules proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: regulatory reporting

For fraud, sanctions, and aml checkpoints, regulatory reporting is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from CDD risk rating to sanctions screening result. Then ask which control from model referral proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: operational exception

For fraud, sanctions, and aml checkpoints, operational exception is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from identity match to AML risk rating. Then ask which control from sanctions list screening proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: customer harm

For fraud, sanctions, and aml checkpoints, customer harm is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from device risk to case note. Then ask which control from false-positive review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: audit trail

For fraud, sanctions, and aml checkpoints, audit trail is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from application velocity to disposition code. Then ask which control from CDD review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: data quality

For fraud, sanctions, and aml checkpoints, data quality is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from sanctions match to reviewer decision. Then ask which control from enhanced due diligence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: privacy minimisation

For fraud, sanctions, and aml checkpoints, privacy minimisation is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from PEP status to audit trail. Then ask which control from case escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: committee reporting

For fraud, sanctions, and aml checkpoints, committee reporting is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from adverse media flag to fraud score. Then ask which control from fraud rules proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: reconciliation

For fraud, sanctions, and aml checkpoints, reconciliation is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from source of funds note to sanctions screening result. Then ask which control from model referral proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: exception ownership

For fraud, sanctions, and aml checkpoints, exception ownership is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from CDD risk rating to AML risk rating. Then ask which control from sanctions list screening proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: monitoring cadence

For fraud, sanctions, and aml checkpoints, monitoring cadence is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from identity match to case note. Then ask which control from false-positive review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: closure evidence

For fraud, sanctions, and aml checkpoints, closure evidence is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from device risk to disposition code. Then ask which control from CDD review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: policy retrieval

For fraud, sanctions, and aml checkpoints, policy retrieval is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from application velocity to reviewer decision. Then ask which control from enhanced due diligence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: investigator feedback

For fraud, sanctions, and aml checkpoints, investigator feedback is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from sanctions match to audit trail. Then ask which control from case escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: model drift

For fraud, sanctions, and aml checkpoints, model drift is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from PEP status to fraud score. Then ask which control from fraud rules proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: control attestation

For fraud, sanctions, and aml checkpoints, control attestation is not a side detail. It decides whether the bank can connect the AI or ML output to a real banking purpose, a real customer or regulatory outcome and a real accountable owner. Study the topic as a banking process first and a model process second.

Trace one item from adverse media flag to sanctions screening result. Then ask which control from model referral proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: customer purpose

Trace one item from source of funds note to AML risk rating. Then ask which control from sanctions list screening proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: consent and lawful use

Trace one item from CDD risk rating to case note. Then ask which control from false-positive review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: source lineage

Trace one item from identity match to disposition code. Then ask which control from CDD review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: KYC and identity

Trace one item from device risk to reviewer decision. Then ask which control from enhanced due diligence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: account behaviour

Trace one item from application velocity to audit trail. Then ask which control from case escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: feature freshness

Trace one item from sanctions match to fraud score. Then ask which control from fraud rules proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: point-in-time correctness

Trace one item from PEP status to sanctions screening result. Then ask which control from model referral proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: model version

Trace one item from adverse media flag to AML risk rating. Then ask which control from sanctions list screening proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: decision threshold

Trace one item from source of funds note to case note. Then ask which control from false-positive review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: reason code

Trace one item from CDD risk rating to disposition code. Then ask which control from CDD review proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: human review

Trace one item from identity match to reviewer decision. Then ask which control from enhanced due diligence proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fraud control

Trace one item from device risk to audit trail. Then ask which control from case escalation proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: sanctions control

Trace one item from application velocity to fraud score. Then ask which control from fraud rules proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: AML control

Trace one item from sanctions match to sanctions screening result. Then ask which control from model referral proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Banking practice note: fair lending

Trace one item from PEP status to AML risk rating. Then ask which control from sanctions list screening proves the item was complete, current, authorised, relevant and fit for use. If that trace cannot be shown without manual guessing, the process is not yet bank-grade.

Three controls on one journey

A loan disbursement can trigger fraud checks, sanctions screening and ongoing AML monitoring at different points. A fraud score estimates a pattern; sanctions matching compares identities against a dated list; AML monitoring generates cases from activity under defined rules. A low fraud score cannot clear a potential sanctions hit or suppress required monitoring. Record each checkpoint's source, result, owner and final action.

Test a disbursement with a new destination, a fuzzy name candidate and an earlier unresolved monitoring alert. The model may recommend step-up, the sanctions case may require hold, and an analyst may investigate the alert under its own process. Preserve precedence and explain the customer status without exposing confidential controls. On model outage, mandatory checks continue and an approved fallback handles the remaining decision.

Related learning paths

This application uses JavaScript for the full interactive experience. This text summary is served for accessibility and search indexing.

Fraud, sanctions, and AML checkpoints · Malla Banking Academy