FeaturesCompliance
Compliance
Compliance by design: suitability, appropriateness and documentation checks run inside the advice rather than after it, for people and agents alike.
Introduction & purpose
Compliance is a user of the platform, not an audience for its output. The checks run inside the advice itself: a flow that fails them cannot be submitted, whether an advisor, the client on a link, your own system through the API or an AI agent is filling it in.
Your compliance function has its own area in the platform. People with the Compliance role can open any client's advice read-only, and have five tools of their own:
- Clients review — every client's PEP and sanctions standing, and the ones that need a decision.
- Batch lookup — PEP and sanctions screening for every client in a view, in one run.
- Flow approvals — advice that has to be approved before it can go further.
- Flows review — completed advice, checked after the fact, with spot checks.
- Identity changes — who changed the details a client is screened against, and from where.
Suitability
The suitability rules are part of the flow, so the advice is checked as it is built, not reviewed afterwards. You decide which controls a flow uses, and the platform enforces them at submit:
- Risk bounds — a custom portfolio is checked live against the maximum equity share and volatility for the client's risk score. Outside the bounds, the flow cannot be submitted.
- Financial capacity — deposits above what the client can afford, or a liquidity buffer below your minimum, stop the flow.
- Knowledge and experience — a portfolio cannot hold a product type the client has not passed the assessment for.
- Sustainability preferences — a portfolio that does not match the client's preferences stops the flow until the advisor accepts the deviation or decides not to proceed.
- Client classification — recorded on the client under MiFID II. For professional clients and eligible counterparties, the product suitability rules do not apply.
Where your policy allows it, an advisor can go outside the risk bounds or override a failed quiz, but only with a written justification. It is recorded on the flow and can be printed in the suitability report, so the deviation is documented where the client and your compliance function will see it.
KYC and AML
Screening is part of the flow, not a separate errand. Put the PEP and sanctions lookup in a flow, and the flow cannot be submitted until it has run. For a company, the beneficial owners and the representative are taken from the company register and screened too.
- Clients review — every client's screening status in one place: needs review, accepted, blocked, not a match, no hits or never checked. Compliance decides each match, and every decision needs a reason. If the screening results change, the decision lapses and the client comes back for review.
- Block — a blocked client cannot start new advice, and none of their flows can move forward. The advisor sees why.
- Batch lookup — screen every client in a view in one run, whenever you choose.
- Identity verification — an ID document and liveness check with Sumsub, or signing with BankID or MitID, gives the client a verified ID. If their identity details are edited afterwards, the verification no longer counts.
- Identity changes — a log of who changed a client's name, national ID, country, date of birth or organisation number, and from where: the client editor, an ID document, a completed flow or the API.
Flow approvals
Flow approvals are the gate inside the process. For each flow, you choose which submissions a compliance user must approve before they can continue: none, all of them, or only those with PEP or sanction hits.
Once submitted, the advice is locked for editing. Compliance reviews it read-only, then approves it, or rejects it with a reason the advisor sees on the flow. The advisor can withdraw a request that is still waiting. A completed flow is final, and advice with a signed document cannot be reopened.
Your own systems can follow along: webhooks fire when an approval is requested, given, refused or withdrawn. If another system has to approve the advice too, the flow waits for its decision through the API.
Flows review
Flow approvals stop advice before it goes further. Flows review is the check after the fact: completed advice, with the facts that matter to compliance side by side.
- Filters — narrow the completed flows by period, advisor, flow, risk deviation, custom portfolio, sustainability, amount and review status.
- Spot check — let the platform pick flows at random, so the sample is not hand-picked.
- Flag, remark, approve — mark a flow for follow-up, add remarks as often as needed, or approve it. Every action needs a note, because a verdict without a reason is not evidence.
- Review history — every flag, remark and approval stays on the flow, with who made it and when.
Audit trail
The platform records what happened as it happens, on the client and on the flow:
- Activity log — each step of a flow's process, from submitted and sent to compliance to approved, signed and completed, with who did it and when.
- Compliance decisions — every approval, rejection, flag and remark, with who made it and when. Rejections, flags and remarks carry their reason.
- Screening — every PEP and sanctions lookup, and every decision on a match.
- Identity changes — who changed the details a client is screened against, and from where.
- The basis for the advice — at submit, the client's preferences and the generated portfolio are stored with the flow, so a later change doesn't rewrite what was advised.
- The suitability report — the generated document, with the product documents attached (KIDs and factsheets) and the client's signature.
Compliance reads all of it in the platform: on the flow, on the client, and in the compliance area.