Compliance

Compliance

Last updated: June 23, 2026

KYConnect helps regulated businesses meet their KYC, KYB, and AML obligations with configurable verification, screening, and audit tooling built around global regulatory standards.

1. Our Compliance Commitment

KYConnect builds identity verification and financial-crime prevention tools that help regulated businesses meet their Know Your Customer (KYC), Know Your Business (KYB), and Anti-Money Laundering (AML) obligations.

Compliance is central to our product design. We maintain internal policies, controls, and governance overseen by a dedicated compliance function, and we review them regularly against evolving regulation and guidance.

This page summarizes our compliance posture for prospective and existing customers. It is informational and does not constitute legal advice or a warranty of regulatory outcomes for your business.

2. Regulatory Frameworks

Our platform is designed to support customers operating under major global frameworks, including the Financial Action Task Force (FATF) Recommendations, the EU Anti-Money Laundering Directives (4AMLD, 5AMLD, 6AMLD), and the US Bank Secrecy Act (BSA) as administered by FinCEN.

We also support obligations under the UK Money Laundering Regulations and FCA expectations, and data-protection regimes such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).

Because requirements differ by jurisdiction and sector, our workflows are configurable so you can tailor verification and screening to your specific regulatory obligations.

FATF Recommendations

FATF Recommendations

Global AML/CFT standards underpinning our risk-based workflows.

EU AML Directives

EU AML Directives

Support for 4AMLD, 5AMLD, and 6AMLD obligations across the EU.

BSA / FinCEN

BSA / FinCEN

US Bank Secrecy Act due diligence and reporting support.

GDPR & CCPA

GDPR & CCPA

Data-protection by design across EU/UK and California regimes.

3. AML & CFT Program

Our tooling enables risk-based customer due diligence (CDD) and enhanced due diligence (EDD), ongoing monitoring, PEP and adverse-media screening, and risk scoring aligned with a risk-based approach.

We support detection workflows for suspicious activity and provide audit-ready records to assist your reporting obligations, including filing Suspicious Activity Reports (SARs) with the relevant authority.

We maintain our own internal AML governance, training, and independent review appropriate to our role as a technology provider.

Notice

Risk-Based Approach

Controls scale with risk: standard due diligence for lower-risk customers and enhanced due diligence, with ongoing monitoring, for higher-risk relationships such as PEPs or high-risk jurisdictions.

4. KYC & KYB Standards

For individuals (KYC), we support identity document verification, liveness and biometric face match, and email and phone verification to establish and confirm identity.

For businesses (KYB), we support registry checks, beneficial-owner (UBO) identification, director verification, proof of address, and company due diligence.

Verification standards can be configured per jurisdiction and risk tier so you can apply standard or enhanced measures where appropriate.

5. Sanctions & Watchlist Screening

We screen against major sanctions and watchlists, including those maintained by OFAC, the United Nations, the European Union, and HM Treasury, with configurable matching and ongoing rescreening.

Screening covers sanctions, politically exposed persons (PEPs), and adverse media, with case-management workflows to review and resolve potential matches.

List coverage and refresh cadence are maintained through reputable data providers; you remain responsible for adjudicating matches and making final decisions.

OFAC (US Office of Foreign Assets Control) sanctions lists

United Nations Security Council consolidated sanctions list

European Union consolidated financial sanctions list

UK HM Treasury / OFSI sanctions list

Politically Exposed Persons (PEP) databases

Adverse media and negative news sources

6. Data Protection & Privacy

We process personal data in line with applicable data-protection laws and our Privacy Policy, and we offer a Data Processing Addendum (DPA) for customers who require one.

We apply data minimization, purpose limitation, and defined retention periods aligned with regulatory record-keeping requirements, and we support international transfer safeguards such as Standard Contractual Clauses.

Biometric data is handled with heightened care and only where there is a lawful basis and appropriate consent.

7. Security Certifications

We operate an information-security program aligned with recognized standards and undergo independent assessment. Our controls target the confidentiality, integrity, and availability of sensitive verification data.

Controls include encryption in transit and at rest, role-based access, segregation of duties, logging and monitoring, vulnerability management, and incident response.

Current certification and audit reports (such as SOC 2 and ISO 27001) are available to qualified customers under NDA on request.

Certifications & Attestations

SOC 2 Type II

Independent attestation of security, availability, and confidentiality controls.

ISO/IEC 27001

Certified information security management system covering platform operations.

PCI DSS (via processors)

Payment data handled by PCI DSS-compliant payment providers.

GDPR / DPA

Data Processing Addendum and transfer safeguards available to customers.

Audit reports and certificates are available to qualified customers under NDA.

8. Record Keeping & Audit

We generate tamper-evident audit trails of verification and screening activity to support your record-keeping and examination needs.

Records are retained for periods aligned with AML and sector requirements, which commonly range from five to seven years, subject to your configuration and jurisdiction.

Audit logs and verification evidence can be exported to support regulatory examinations and internal reviews.

9. Reporting & Cooperation

We cooperate with lawful requests from regulators and law enforcement and disclose data only where legally permitted or required, applying appropriate review.

We provide the evidence and audit records you need to meet your own reporting obligations, while final regulatory filings remain your responsibility.

We notify affected customers of security incidents in accordance with our contractual and legal obligations.

10. Shared Responsibility

Compliance is a shared responsibility. KYConnect provides the verification, screening, and audit tooling; you remain the regulated party responsible for your own AML/CFT program and final decisions.

You are responsible for maintaining required licenses and registrations, configuring workflows to your risk appetite and legal obligations, and adjudicating verification and screening outcomes.

We support you with configurable controls, documentation, and expertise, but we do not assume your regulatory obligations.

KYConnect Provides

  • Verification, screening, and risk-scoring tooling
  • Configurable, jurisdiction-aware workflows
  • Tamper-evident audit trails and exports
  • Security controls and data-protection safeguards

You Are Responsible For

  • Maintaining licenses and your AML/CFT program
  • Configuring controls to your risk appetite
  • Adjudicating matches and verification outcomes
  • Filing regulatory reports such as SARs

11. Contact Compliance

For diligence questionnaires, security reports, or compliance documentation, reach our team below.

ComplianceCompliance Team

Email: [email protected]

Security: [email protected]

Phone: +1 (888) 555-0123

Hours: Mon-Fri, 9:00 AM - 6:00 PM EST

AddressRegistered Office

KYConnect Inc.

Compliance Department

123 Verification Boulevard

Suite 500

San Francisco, CA 94105

United States

Trust

Compliance You Can Build On

We invest continuously in our controls, certifications, and data sources so you can onboard customers confidently and meet your regulatory obligations with a trusted verification partner.

Version 2.1.0 • Effective June 23, 2026

View Privacy Policy