Skip to content
VerifiX — secured by ITSEC

Why VerifiX

UAE journeys already built. Full API one click away.

Most verification vendors hand you an empty rule builder and a sales cycle. VerifiX ships with verification journeys pre-configured for the UAE and wider GCC market, and gives you complete API access the moment you deploy — so compliance does not rebuild policy from scratch and engineering does not wait to start integrating.

Journey templates are a starting point, not legal advice. Each journey's mapping to a specific regulator obligation stays a visible placeholder until confirmed: Each journey step states the obligation it addresses.

Pre-set journeys

Journeys built for how UAE entities actually onboard

Each journey bundles the checks, risk weights, escalation paths, and evidence requirements for one onboarding scenario. Deploy as-is, then adjust to your own risk appetite.

Virtual asset service provider onboarding

Retail and institutional onboarding journey for exchanges, brokers, and custodians, with wallet screening wired into the same decision.

Corporate / entity onboarding

KYB journey covering entity documents, ownership structure, and UBO verification down to natural persons.

Individual onboarding (resident and non-resident)

Document, liveness, and biometric match journey with Emirates ID and passport paths, plus non-resident handling.

Enhanced due diligence

Escalation journey for high-risk customers: extended screening, source-of-funds collection, and senior sign-off.

Ongoing monitoring cycle

Periodic re-screening and risk-based review scheduling, with change alerts routed to your case queue.

Reporting and audit pack

Decision records, reviewer actions, and evidence exports assembled per case for internal audit and regulator requests.

UAE PASS integrationComing soon

Onboarding via UAE PASS digital identity is on the roadmap, so UAE residents can be verified with their national digital ID inside the same journey. Availability date: UAE PASS integration is in progress

Primary market focus: United Arab Emirates and the wider GCC. Coverage beyond that: United Arab Emirates today, with the wider GCC next

Regulator by regulator

Every journey, explained per regulator

Each supervisory authority in the UAE onboards a different population under a different rulebook. VerifiX ships a separate journey per authority: the same engine, a different sequence of checks, evidence, and escalation. Open one to see the full step order it runs.

These journeys describe the checks VerifiX runs, not the text of any rulebook. The mapping from each step to a specific legal obligation stays a visible placeholder until confirmed with counsel.

VARA — Virtual Assets Regulatory Authority (Dubai)Virtual asset service providers licensed to operate in Dubai (excluding DIFC).

journey: uae_vara_vasp_onboarding

  1. 1Customer classification: retail, qualified, or institutional — routes the customer down a different evidence path from the first screen.
  2. 2Identity: Emirates ID or passport capture, document authentication, liveness and biometric match against the captured document.
  3. 3Residency and jurisdiction check: resident vs non-resident path, plus restricted-jurisdiction screening before any account is enabled.
  4. 4Sanctions, PEP, and adverse media screening on the natural person and, for institutional accounts, on the entity and its controllers.
  5. 5Wallet and counterparty screening (KYT): the customer's declared deposit wallet is screened for exposure before the first transaction.
  6. 6Risk scoring and decision: clear, escalate to EDD, or reject — with source-of-funds collection when the score crosses the escalation threshold.
  7. 7Ongoing: periodic re-screening, transaction monitoring rules, and re-verification triggers on material change.

Evidence retained

Decision record, screening hits with reviewer disposition, document images, biometric result, wallet screening report.

CBUAE — Central Bank of the UAEBanks, exchange houses, finance companies, payment service providers, and stored-value facility holders.

journey: uae_cbuae_financial_institution_onboarding

  1. 1Product-based risk tiering: the account or wallet product being opened sets the baseline customer risk tier.
  2. 2Identity verification: Emirates ID for residents, passport plus visa evidence for non-residents, with document authenticity and liveness checks.
  3. 3Address and contact verification where the product tier requires supporting proof.
  4. 4Sanctions and domestic list screening, PEP determination including family members and close associates, and adverse media.
  5. 5Purpose of relationship and expected activity capture, used later as the baseline for transaction monitoring.
  6. 6Risk-based approval: standard approval, or escalation to enhanced due diligence with senior management sign-off for high-risk relationships.
  7. 7Ongoing: continuous screening, periodic review scheduled by risk tier, and suspicious activity case creation for internal reporting.

Evidence retained

Customer risk assessment, screening evidence, identity documents, approval trail, periodic review history.

CMA — Capital Market Authority (UAE)Securities brokers, investment managers, crowdfunding platforms, and other capital-market participants onshore.

journey: uae_cma_investor_onboarding

  1. 1Investor classification: retail, professional, or institutional, driving the evidence and suitability path.
  2. 2Identity and, for entities, KYB: trade license, constitutional documents, ownership chain, and UBO verification to natural persons.
  3. 3Authorized signatory and representative verification for corporate and institutional accounts.
  4. 4Sanctions, PEP, and adverse media screening on the investor, entity, directors, and beneficial owners.
  5. 5Source of funds and source of wealth capture for higher-risk or higher-value relationships.
  6. 6Risk score, decision, and four-eyes review before the account is enabled for trading.
  7. 7Ongoing: re-screening and periodic refresh, with alerts on ownership or control changes.

Evidence retained

Classification record, entity documents, UBO chain, screening results, reviewer decisions.

DFSA — Dubai Financial Services Authority (DIFC)Firms licensed in the DIFC free zone, including banks, asset managers, and crypto token firms.

journey: difc_dfsa_client_onboarding

  1. 1Client type and service scope capture, which determines the applicable due diligence level.
  2. 2Identity verification for natural persons, or full KYB with ownership and control analysis for entities.
  3. 3Cross-border checks: country risk assessment for the client's residence, incorporation, and operating jurisdictions.
  4. 4Sanctions, PEP, and adverse media screening across the entity, its owners, and its controllers.
  5. 5Enhanced due diligence path for high-risk countries, PEPs, and complex ownership structures, including source-of-wealth evidence.
  6. 6Risk decision with documented rationale and compliance officer sign-off.
  7. 7Ongoing: risk-based periodic review and event-driven re-verification.

Evidence retained

Client due diligence file, country risk rationale, screening evidence, sign-off record.

FSRA — Financial Services Regulatory Authority (ADGM)Firms licensed in Abu Dhabi Global Market, including virtual asset and digital-asset businesses.

journey: adgm_fsra_client_onboarding

  1. 1Business relationship scoping: product, delivery channel, and client type set the initial risk rating.
  2. 2Identity or KYB verification, with UBO identification and verification down to natural persons.
  3. 3Jurisdiction and delivery-channel risk assessment, including non-face-to-face onboarding controls.
  4. 4Sanctions, PEP, and adverse media screening with documented disposition of every hit.
  5. 5Wallet and blockchain analytics screening where the client transacts in virtual assets.
  6. 6Enhanced due diligence and senior sign-off where the risk rating requires it.
  7. 7Ongoing: continuous screening, transaction monitoring, and scheduled refresh by risk rating.

Evidence retained

Risk assessment record, verification evidence, screening dispositions, monitoring alerts and outcomes.

Other GCC jurisdictionsSaudi Arabia, Qatar, Bahrain, Kuwait, and Oman — journeys follow the same structure with jurisdiction-specific identity and evidence paths.

journey: gcc_generic_onboarding

  1. 1Jurisdiction selection sets the accepted identity documents and local list screening.
  2. 2Identity or KYB verification against locally accepted documents.
  3. 3Sanctions, PEP, and adverse media screening including regional lists.
  4. 4Risk scoring, escalation, and review using the same engine and case queue as the UAE journeys.

Evidence retained

Same decision record and evidence pack structure as the UAE journeys.

One click to a live API

Deploy a journey, get the full API with it

Deploying a journey provisions your environment and issues sandbox and production credentials in the same step. There is no restricted tier of the API: every check, case action, and export available in the console is available over HTTP.

  • Journey referenced by a stable identifier — swap or edit it without changing your integration.
  • Webhooks for decision, review, and monitoring events.
  • Same audit trail whether a decision came from the API or the console.
Read the developer docs
POST /v1/verificationshttps://api.verifix.ae/v1
curl -X POST https://api.verifix.example/v1/verifications \
  -H "Authorization: Bearer $VERIFIX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "journey": "uae_vasp_retail_onboarding",
    "customer": { "type": "individual", "residency": "AE" }
  }'

What changes

Nothing breaks between compliance and engineering

Policy configuration
Compliance writes the policy, then waits for engineering to translate it into rules and thresholds.
Journeys arrive pre-configured for the UAE market and are edited in the console, not in code.
Integration
Weeks of scoping before the first verification call reaches production.
One click provisions your environment and full API credentials — sandbox and production keys together.
Change control
Every threshold tweak becomes a release with its own regression risk.
Rule changes are versioned with an audit trail; no redeploy, no broken integration.
Ownership
Compliance and engineering argue over one shared spreadsheet.
Compliance owns the journey; developers own the integration. Same platform, separate surfaces.

For developers

  • Full REST API and webhooks from the first minute — no gated endpoints.
  • Sandbox environment with deterministic test subjects.
  • Journey changes never break your contract: the request shape stays stable.
  • Hosted flow available when you don't want to build the UI.

For compliance

  • Pre-built journeys as a starting point instead of a blank rule builder.
  • Thresholds, risk weights, and escalation paths editable without engineering.
  • Four-eyes review and full decision audit trail on every case.
  • Evidence exports assembled per case — Verify report formats below.

Deploy a UAE journey and call the API today

Start in sandbox with a pre-built journey, or walk through the console with our team first.