Blog
Compliance, privacy, verification
Practical writing on KYC, AML, privacy engineering, and fraud prevention — for teams that verify customers where they already chat.

PEP Screening: Classifying Political Exposure Without Over-Flagging
Politically exposed persons require enhanced scrutiny, not blanket rejection. A look at classification tiers, RCA linkage, and declassification practices.

Face Matching: Comparing a Selfie to an ID Without Keeping Either
How 1:1 face matching binds a live selfie to a document photo, what the error rates actually mean, and how to run it without retaining biometric data.

Injection Attacks: The Deepfake Threat Liveness Alone Misses
Presentation attacks fool the camera; injection attacks bypass it entirely. Here is how selfie verification breaks and what stops each class.

Perpetual KYC: Replacing Calendar Reviews With Event Triggers
Periodic KYC refresh cycles miss risk between reviews and waste effort on static customers. Here's how event-driven monitoring closes both gaps.

Sanctions Name Matching: Fuzzy Logic Without False Positive Floods
Transliteration, phonetics, and thresholds decide whether a sanctions screen catches a real hit or buries analysts in noise. Here's how the matching actually works.

First-Party Fraud: When the Real Customer Is the Threat
First-party fraud uses genuine identities to deceive. Here's how it differs from account takeover and what onboarding signals actually catch it.

Source of Funds vs Source of Wealth: Documenting Money's Origin
Two terms compliance teams often conflate. Here's how source of funds and source of wealth differ, what evidence each demands, and how to collect it without overreach.

Proof of Address: Verifying Where Someone Lives Without Overcollecting
Address verification is often the weakest link in onboarding. Here's how to confirm residence reliably while collecting the least data that satisfies the requirement.

Customer Risk Scoring: Building a Rating Model That Holds Up
How to build a customer risk rating model that regulators accept: input factors, weighting, calibration, and the governance that keeps it defensible.

Synthetic Identity Fraud: When the Person Was Never Real
Synthetic identities blend real and fabricated data to pass onboarding. Here is how these profiles are built, why they slip through, and how to detect them.

Step-Up Verification: Adding Friction Only When Risk Demands
A risk-based approach to onboarding collects the minimum first, then escalates checks only when signals justify it. Here is how to design the escalation ladder.

Filing a SAR: From Alert to a Report That Holds Up
A suspicious activity report is only as strong as its narrative. Here is how to move from a triggered alert to a filing an investigator can act on.

Money Mule Detection: Finding Accounts That Launder for Others
Money mule accounts pass KYC cleanly, then move funds for criminals. Here is how the signals appear and how to act before the network scales.

Document Tampering: Spotting Forged IDs at Onboarding
How forged and altered identity documents get through onboarding, and the layered checks — visual, structural, and cryptographic — that catch them.

Adverse Media Screening: Finding Risk in the News Cycle
Negative news screening surfaces risk that sanctions and PEP lists miss. Here is how to structure sources, matching, and disposition without drowning in noise.

Structuring Detection: Catching Deliberately Small Transactions
How to detect structuring and smurfing in transaction monitoring — the thresholds, typologies, and tuning that separate real signal from noise.

The EU Identity Wallet: KYC Without the Full Reveal
Verifiable credentials let a user prove a claim without exposing the whole document. Here is what the EUDI Wallet means for onboarding flows.

Age Assurance: Proving Age Without Harvesting Identity
Age checks don't have to mean collecting a full identity file. Here's how to verify a threshold while minimizing what you store.

The Travel Rule: Sharing Originator Data Between VASPs
How the FATF Travel Rule works, what data must accompany a transfer, and the engineering choices that keep counterparty exchange from leaking more than it should.

Reading the ePassport Chip: NFC Verification Beyond the Photo
How the NFC chip inside modern passports lets you verify identity documents cryptographically — and what it takes to read one during a chat-based onboarding flow.

Beneficial Ownership: Unwrapping Corporate Layers in KYB
Identifying the humans behind a corporate customer means tracing ownership chains, applying control tests, and verifying people — not just registry entries.

PEP Screening: Classifying Politically Exposed Persons
Politically exposed persons carry elevated risk by role, not by wrongdoing. Here's how to classify PEPs, family, and associates without drowning in false hits.

KYC Data Retention: How Long to Keep, When to Delete
Retention is where compliance and privacy collide. A practical look at setting KYC record schedules that satisfy AML rules without hoarding personal data.

Liveness Detection: Telling Real Faces From Presentation Attacks
Liveness detection separates a live person from a photo, video, or mask. Here's how presentation attacks work and what signals expose them.

Perpetual KYC: Replacing Calendar Reviews With Event Triggers
Periodic KYC refresh on a fixed calendar wastes effort and misses risk. Here's how event-driven monitoring reworks the review cycle.

Sanctions Screening: Lists, Thresholds, and the False Positive Tax
Sanctions screening is easy to run and hard to run well. A look at list hygiene, match thresholds, and cutting false positives without missing true hits.

Name Matching Across Alphabets: Screening Names That Don't Spell Themselves
Sanctions and watchlist screening lives or dies on name matching. Here's how transliteration, phonetics, and thresholds shape false positives and misses.

Source of Funds vs Source of Wealth: Documenting Origin
Source of funds and source of wealth are distinct checks that regulators expect you to separate. Here is how to collect, verify, and store both without over-asking.

Proof of Address: Verifying Residence Without a Utility Bill Pile
Proof of address is the KYC step most likely to stall onboarding. Here is how to verify where someone lives with fewer documents and cleaner data.

Customer Risk Scoring: Building a Model You Can Explain
A risk-based approach only works if you can justify every score. Here's how to build a customer risk rating that examiners, and your own team, can actually read.

Synthetic Identity Fraud: Detecting People Who Don't Exist
Synthetic identities blend real and fabricated data to pass KYC checks. Here's how the fraud is assembled and which signals expose it during onboarding.

Device Intelligence: Reading the Onboarding Session, Not the ID
The device behind an application carries signals no document does. Here's what to collect during onboarding, what to discard, and how to keep it proportionate.

Phone Number Intelligence: The Signals Hidden in a Number
A phone number is often the first data point you collect. Here's what it can reveal about risk before a customer uploads a single document.

Money Mule Detection: Finding Accounts That Launder for Others
Money mules turn clean onboarding into a laundering channel. Here's how to spot accounts moving other people's funds without over-collecting data.

The KYC Audit Trail: Proving What You Checked and When
Passing a KYC check is only half the job. If you can't reconstruct what you verified, when, and on what basis, an examiner may treat the check as if it never happened.

Adverse Media Screening: Filtering Signal From Noise
Adverse media screening surfaces reputational and criminal risk that sanctions lists miss — but only if you control the noise, sources, and retention around it.

Step-Up Verification: Escalating KYC Only When Risk Rises
A step-up model applies light checks by default and adds friction only when signals warrant it — cutting cost and abandonment while keeping high-risk cases covered.

KYC Drop-Off: Cutting Onboarding Abandonment Without Cutting Corners
Every abandoned KYC flow is lost revenue and wasted screening cost. Here is how to measure drop-off and reduce it without weakening your controls.

Face Match: Comparing the Selfie to the ID Photo, Privately
How 1:1 biometric comparison links a live selfie to the document photo, what error rates to expect, and how to run it without hoarding faces.

Document Tampering Detection: Catching Edited IDs in Chat
How to detect altered passports and ID cards using checksum math, cross-field consistency, and visual signals — without hoarding the images you inspect.

Reading the Chip: NFC Passport Verification in a Chat Flow
NFC chip reading validates a passport's cryptographic signature instead of trusting a photo. Here's how it works and where it fits in a chat-based flow.

KYB: Verifying Businesses Before You Verify Their People
Know Your Business onboarding demands registry checks, document collection, and UBO tracing before individual KYC begins. Here's how to structure it.

PEP Screening: Classifying Political Exposure Without Overreach
How to identify politically exposed persons, scope their associates, and apply proportionate due diligence without flooding your team with low-value matches.

UBO Discovery: Mapping Ownership Through Corporate Layers
How to identify ultimate beneficial owners behind layered corporate structures, verify their identity, and document the chain without collecting more data than you need.

Liveness Under Attack: Defending Selfie Checks From Deepfakes
Injection attacks and generative deepfakes are breaking traditional selfie liveness. Here is how to layer defenses without collecting more biometric data than you need.

Perpetual KYC: From Calendar Reviews to Event-Driven Refresh
Periodic KYC reviews miss risk between cycles and re-collect data you already hold. Here's how event-driven refresh cuts staleness without over-retaining.

Age Verification Without Handing Over the Whole ID
Most age checks collect far more than a yes/no answer. Here's how to prove someone is over a threshold without hoarding their full date of birth or document.

Sanctions Screening: Fuzzy Name Matching Without False Positives
How transliteration, aliases, and weak matching logic flood sanctions queues with noise — and the tuning choices that keep true hits visible.

Reusable KYC: Portable Credentials Without Re-Onboarding
Reusable KYC lets a verified customer prove identity across services without repeating full onboarding. Here's how portable credentials work and where the risks sit.

Proof of Address Without Hoarding Utility Bills
Address verification often means collecting sensitive documents you never needed. Here's how to prove residence while minimizing what you store.

Source of Funds vs Source of Wealth: Getting the Evidence Right
Source of funds and source of wealth are not interchangeable. Here's how to define each, what evidence to collect, and how to document it without over-hoarding data.

Synthetic Identity Fraud: Catching People Who Never Existed
Synthetic identities blend real and fabricated data to pass standard KYC. Here's how the fraud is built, why it slips through, and what signals expose it.

The FATF Travel Rule: Passing Originator Data Without Leaks
How virtual asset providers exchange originator and beneficiary data under the FATF Travel Rule — and how to do it without creating a new privacy liability.

Transaction Monitoring: Tuning Thresholds to Cut Alert Noise
Most transaction monitoring programs drown in false positives. Here is how to tune rules, segment customers, and document changes without weakening AML coverage.

Data Residency in KYC: Keeping Records Where Law Requires
Cross-border KYC data flows collide with residency mandates. Here's how to map obligations, segment storage, and prove where every identity record lives.

Money Mule Detection: Spotting Accounts That Launder for Others
Money mules move illicit funds through legitimate-looking accounts. Here's how to detect recruitment patterns, behavioral signals, and network structures.

Adverse Media Screening: Separating Signal From Noise
Adverse media checks can flood analysts with irrelevant hits. Here's how to structure sourcing, relevance scoring, and evidence capture without drowning in noise.

KYC Audit Trails: Proving Every Decision to Regulators
Regulators rarely dispute your KYC decision — they dispute whether you can prove how you reached it. Here's how to build an audit trail that holds up.

Writing SARs That Survive Regulator Scrutiny
A practical look at structuring suspicious activity reports so investigators can act fast and examiners find your narrative complete, timely, and defensible.

Device Fingerprinting for Fraud Signals Without Privacy Debt
Device intelligence catches fraud rings that document checks miss — but naive fingerprinting creates privacy and legal exposure. Here's how to build it responsibly.