Compliance
Last updated: June 23, 2026
KYConnect helps regulated businesses meet their KYC, KYB, and AML obligations with configurable verification, screening, and audit tooling built around global regulatory standards.
1. Our Compliance Commitment
KYConnect builds identity verification and financial-crime prevention tools that help regulated businesses meet their Know Your Customer (KYC), Know Your Business (KYB), and Anti-Money Laundering (AML) obligations.
Compliance is central to our product design. We maintain internal policies, controls, and governance overseen by a dedicated compliance function, and we review them regularly against evolving regulation and guidance.
This page summarizes our compliance posture for prospective and existing customers. It is informational and does not constitute legal advice or a warranty of regulatory outcomes for your business.
2. Regulatory Frameworks
Our platform is designed to support customers operating under major global frameworks, including the Financial Action Task Force (FATF) Recommendations, the EU Anti-Money Laundering Directives (4AMLD, 5AMLD, 6AMLD), and the US Bank Secrecy Act (BSA) as administered by FinCEN.
We also support obligations under the UK Money Laundering Regulations and FCA expectations, and data-protection regimes such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).
Because requirements differ by jurisdiction and sector, our workflows are configurable so you can tailor verification and screening to your specific regulatory obligations.
FATF Recommendations
Global AML/CFT standards underpinning our risk-based workflows.
EU AML Directives
Support for 4AMLD, 5AMLD, and 6AMLD obligations across the EU.
BSA / FinCEN
US Bank Secrecy Act due diligence and reporting support.
GDPR & CCPA
Data-protection by design across EU/UK and California regimes.
3. AML & CFT Program
Our tooling enables risk-based customer due diligence (CDD) and enhanced due diligence (EDD), ongoing monitoring, PEP and adverse-media screening, and risk scoring aligned with a risk-based approach.
We support detection workflows for suspicious activity and provide audit-ready records to assist your reporting obligations, including filing Suspicious Activity Reports (SARs) with the relevant authority.
We maintain our own internal AML governance, training, and independent review appropriate to our role as a technology provider.
Risk-Based Approach
Controls scale with risk: standard due diligence for lower-risk customers and enhanced due diligence, with ongoing monitoring, for higher-risk relationships such as PEPs or high-risk jurisdictions.
4. KYC & KYB Standards
For individuals (KYC), we support identity document verification, liveness and biometric face match, and email and phone verification to establish and confirm identity.
For businesses (KYB), we support registry checks, beneficial-owner (UBO) identification, director verification, proof of address, and company due diligence.
Verification standards can be configured per jurisdiction and risk tier so you can apply standard or enhanced measures where appropriate.
5. Sanctions & Watchlist Screening
We screen against major sanctions and watchlists, including those maintained by OFAC, the United Nations, the European Union, and HM Treasury, with configurable matching and ongoing rescreening.
Screening covers sanctions, politically exposed persons (PEPs), and adverse media, with case-management workflows to review and resolve potential matches.
List coverage and refresh cadence are maintained through reputable data providers; you remain responsible for adjudicating matches and making final decisions.
OFAC (US Office of Foreign Assets Control) sanctions lists
United Nations Security Council consolidated sanctions list
European Union consolidated financial sanctions list
UK HM Treasury / OFSI sanctions list
Politically Exposed Persons (PEP) databases
Adverse media and negative news sources
6. Data Protection & Privacy
We process personal data in line with applicable data-protection laws and our Privacy Policy, and we offer a Data Processing Addendum (DPA) for customers who require one.
We apply data minimization, purpose limitation, and defined retention periods aligned with regulatory record-keeping requirements, and we support international transfer safeguards such as Standard Contractual Clauses.
Biometric data is handled with heightened care and only where there is a lawful basis and appropriate consent.
7. Security Certifications
We operate an information-security program aligned with recognized standards and undergo independent assessment. Our controls target the confidentiality, integrity, and availability of sensitive verification data.
Controls include encryption in transit and at rest, role-based access, segregation of duties, logging and monitoring, vulnerability management, and incident response.
Current certification and audit reports (such as SOC 2 and ISO 27001) are available to qualified customers under NDA on request.
Certifications & Attestations
SOC 2 Type II
Independent attestation of security, availability, and confidentiality controls.
ISO/IEC 27001
Certified information security management system covering platform operations.
PCI DSS (via processors)
Payment data handled by PCI DSS-compliant payment providers.
GDPR / DPA
Data Processing Addendum and transfer safeguards available to customers.
Audit reports and certificates are available to qualified customers under NDA.
8. Record Keeping & Audit
We generate tamper-evident audit trails of verification and screening activity to support your record-keeping and examination needs.
Records are retained for periods aligned with AML and sector requirements, which commonly range from five to seven years, subject to your configuration and jurisdiction.
Audit logs and verification evidence can be exported to support regulatory examinations and internal reviews.
9. Reporting & Cooperation
We cooperate with lawful requests from regulators and law enforcement and disclose data only where legally permitted or required, applying appropriate review.
We provide the evidence and audit records you need to meet your own reporting obligations, while final regulatory filings remain your responsibility.
We notify affected customers of security incidents in accordance with our contractual and legal obligations.
11. Contact Compliance
For diligence questionnaires, security reports, or compliance documentation, reach our team below.
Compliance Team
Email: [email protected]
Security: [email protected]
Phone: +1 (888) 555-0123
Hours: Mon-Fri, 9:00 AM - 6:00 PM EST
Registered Office
KYConnect Inc.
Compliance Department
123 Verification Boulevard
Suite 500
San Francisco, CA 94105
United States
Compliance You Can Build On
We invest continuously in our controls, certifications, and data sources so you can onboard customers confidently and meet your regulatory obligations with a trusted verification partner.
Version 2.1.0 • Effective June 23, 2026
View Privacy Policy