For banks, payment and e-money institutions, crypto-asset service providers and other obliged entities
When the supervisor asks whether you checked the customer, show the check as it was done.
An AML inspection, a lookback after a suspicious case, a request from the financial intelligence unit. The question is not only whether a file exists, but whether it existed before anyone knew it would be looked at.
- When it is tested
- An anti-money-laundering inspection; a lookback exercise; a request from the financial intelligence unit or a court.
- What you will be asked for
- The customer due diligence documents and information, and the records of transactions, kept for five years after the business relationship ends (Directive (EU) 2015/849, Article 40); for ICT incidents affecting these systems, how they were handled and reported (DORA, Articles 17 and 19).
- What goes wrong today
- KYC files are updated, re-scanned and remediated in batches. Afterwards nobody can show which documents were on file when the account was opened, and honest remediation looks like back-dating.
- What changes
- Each completed check is sealed at the moment it completes: a fingerprint of the documents seen, the screening result and the reviewer. Remediation adds new sealed versions, and the original stays provable beside them. Customer data never reaches us.
Sealing shows that a record existed unchanged from a given moment; whether your records are enough is yours to judge. What DORA asks
Try it in two minutes
- Choose a real file of your own: a completed due-diligence checklist or a screening report. It is read in your browser and never uploaded.
- Seal it on Seal a file. A free sandbox key is issued on the page; only a salted fingerprint reaches the log.
- Make a copy, change one character in it, and check both against the receipt at Check. The copy fails; the original passes.
From your own systems it is one API call per record. Integrate · Other industries