Skip to content
VerifiX — secured by ITSEC

Solutions · Compliance & MLRO

Run compliance in one place. Defend every decision.

VerifiX gives MLROs, compliance officers, risk leaders, and technical teams one operating layer for KYC, KYB, AML, KYT, Travel Rule, review controls, and evidence exports.

Made in the UAEBuilt for UAE and GCC regulated entities

MLRO workspace

UAE VASP institutional EDD

Review

KYC

Passed

KYB

UBO verified

AML

1 hit cleared

Travel Rule

Ready

Decision evidence

Rule version, reviewer rationale, supporting documents, and export history are attached to the case.

Evidence bundleExport

MLRO evidence

The questions compliance must answer after go-live

The page is not just about checks. It is about proving why a customer was accepted, escalated, rejected, reviewed, or monitored.

Why the customer was accepted

Identity, entity, screening, risk factors, reviewer notes, and final decision are retained on the same case record.

Why the risk score changed

Risk weights, threshold hits, manual overrides, and policy versions are visible so a score is explainable later.

Who approved the exception

Four-eyes review records the actor, timestamp, rationale, and sign-off path for escalated onboarding or monitoring cases.

What happened after onboarding

Ongoing screening, monitoring alerts, periodic reviews, and disposition history stay connected to the original customer file.

What to send an auditor

Case-level exports package the decision, evidence, rule version, check results, and reviewer actions for supervisory review.

Where sensitive data lives

UAE-region hosting on AWS and Microsoft Azure, tenant isolation, retention controls, and the legal pack support vendor assessment.

From policy to production

Compliance owns the journey. Engineering gets a stable API.

VerifiX separates policy control from implementation work, so regulatory changes do not become fragile custom builds.

  1. 1

    Select the regulator journey

    Start from VARA, CBUAE, CMA, DFSA, FSRA, or a GCC configuration path, then tune risk appetite and evidence requirements.

  2. 2

    Set review controls

    Define escalation thresholds, four-eyes review, senior sign-off points, queues, retention, and export permissions.

  3. 3

    Issue sandbox access

    Technical teams receive sandbox credentials, deterministic test cases, webhook events, and stable journey IDs for integration.

  4. 4

    Test evidence outcomes

    Compliance and engineering test pass, fail, refer, EDD, rescreening, and Travel Rule paths before production approval.

  5. 5

    Move to production

    Once the checklist is signed off, production keys use the same API contract while compliance keeps journey control in the console.

  6. 6

    Defend and improve

    Review cases, tune thresholds, export audit packs, and keep changes versioned without turning every policy update into a release.

Compliance-approved journey
POST /v1/verifications
journey: uae_vara_institutional_edd
subject: corporate_customer
webhook: verification.completed
export: /v1/cases/{id}/evidence-bundle

Technical handoff

No black box between teams

  • Stable REST resources for verifications, entities, alerts, cases, and exports.
  • Webhooks return decisions and review events to your core system.
  • Journey versions keep policy changes traceable without changing the request shape.

Regulator-safe workflow

Map the buyer, the regulator, and the evidence before implementation

Use the matrix as a starting point for the implementation workshop. Exact obligation mapping is confirmed with your legal and compliance team before go-live.

VARA

MLRO and VASP compliance team
Retail, institutional, EDD, KYT, and Travel Rule paths
Identity, wallet risk, Travel Rule message record, screening disposition, and case decision

CBUAE

Financial-crime compliance and operations
Retail account, merchant, remittance, exchange-house, and periodic-review paths
CDD file, expected activity, screening result, risk score, approval trail, and monitoring alerts

CMA

Investor onboarding and compliance review
Investor classification, entity KYB, signatory verification, and source-of-funds routing
Classification record, UBO chain, signatory verification, screening outcomes, and review notes

DFSA

DIFC compliance and risk teams
Client due diligence, country-risk routing, EDD, and periodic review
CDD file, risk rationale, PEP/adverse-media disposition, sign-off record, and refresh history

FSRA

ADGM compliance and control functions
Client onboarding, virtual-asset risk, EDD, ongoing screening, and monitoring
Risk assessment, verification evidence, wallet exposure, escalation record, and alert outcome

GCC on request

Regional compliance program owners
Country-specific identity, entity, screening, and evidence settings configured with your team
Same case-file structure, adjusted for accepted documents and local supervisory expectations

Case file

One evidence bundle across every control

Every check writes into the same customer timeline, so the MLRO can reopen a case and see the journey, rule version, review decision, and downstream monitoring context together.

KYC

Document, liveness, face match, residency path, screening result, risk score

KYB

Registry data, trade license, ownership graph, UBOs, officers, signatories

AML

Sanctions, PEP, adverse media, match strength, analyst disposition, rescreening

KYT

Transaction rules, wallet risk, counterparty exposure, thresholds, alert outcomes

Travel Rule

Originator and beneficiary data, threshold trigger, counterparty message status

Review

Queue state, assigned analyst, second approver, rationale, policy version, export log

Give your MLRO and engineers the same operating picture

Request a sandbox to test the journey, webhook events, and evidence bundle against your own onboarding flow.