FATF compliance software for AML, KYC and the Travel Rule.
ComplianceSuite maps FATF Recommendation 1 risk-based approach, Recommendation 10 customer due diligence, Recommendation 16 Travel Rule, Recommendation 24 beneficial ownership, Recommendation 6 targeted financial sanctions and Recommendation 7 proliferation financing into one operating layer. Firms can show supervisors how each control is configured, when it ran and what evidence it produced.
- Risk-based customer onboarding and ongoing due diligence
- Sanctions, PEP and adverse-media screening
- Travel Rule data exchange for VASPs and CASPs
- Beneficial ownership, record-keeping and audit evidence
Risk-based AML and KYC controls
Apply a risk-based approach to customer acceptance, verification, enhanced due diligence and ongoing monitoring. Workflows match FATF Recommendations 1, 10 and 20, with configurable risk factors, scoring, review triggers and retained decision rationale.
- CDD, ECDD and simplified due diligence tiers
- Identity, business and beneficial-owner verification
- Ongoing monitoring and trigger-based reviews
- Risk scoring with documented overrides
Travel Rule compliance
Exchange originator and beneficiary information for virtual-asset and wire transfers, with jurisdictional thresholds, counterparty due diligence and evidence that the required data travelled with the payment.
- IVMS 101 across supported Travel Rule protocols
- Originator and beneficiary data validation
- Counterparty VASP and CASP risk checks
- Self-hosted-wallet verification evidence
Targeted financial sanctions and proliferation financing
Screen customers, counterparties, wallets and transactions against sanctions and proliferation-financing lists, resolve ownership and control, and keep a decision trail for freezes, rejections and regulatory reports.
- OFAC, UN, EU, UK OFSI and local sanctions lists
- Ownership and control resolution
- Freeze, block and rejection rationale
- STR/SAR and regulator reporting evidence
Evidence and reporting for supervisors
Every policy, rule, alert, case, approval and remediation action is time-stamped and exportable. Supervisory requests can be answered with a linked record rather than rebuilt from emails and spreadsheets.
- Policy and rule version history
- Alert-to-case decision lineage
- Population exports with audit stamps
- Remediation plans with owners and due dates
FAQ
Regulator questions, answered.
Who is the FATF compliance page for?
It is for banks, payment firms, fintechs, crypto exchanges, custodians and other obliged entities that need to demonstrate a risk-based AML/CFT programme aligned with FATF Recommendations. National transposition into local law still governs exact requirements.
Does ComplianceSuite guarantee FATF mutual-evaluation readiness?
No. The platform provides configurable controls, workflow and evidence management. Your legal and compliance teams are responsible for mapping local law, approving control design and preparing regulator submissions.
Which FATF Recommendations does the platform cover?
The most relevant are Recommendation 1 (risk-based approach), Recommendation 10 (CDD), Recommendation 11 (record-keeping), Recommendation 16 (Travel Rule), Recommendation 20 (suspicious transaction reporting), Recommendation 24 (transparency of legal persons), and Recommendations 6 and 7 (targeted financial sanctions and proliferation financing).
How does the Travel Rule map to FATF Recommendation 16?
VASPs and CASPs must obtain, hold and transmit originator and beneficiary information for virtual-asset transfers above local thresholds. ComplianceSuite supports the IVMS 101 data model and connects to Travel Rule networks while logging each exchange in the case file.
Can the platform support both AML and sanctions supervisors?
Yes. Screening, case management, freeze decisions and regulatory reports can be configured for the relevant national FIU, prudential supervisor and sanctions authority, with role-based access and immutable audit trails.
Where is FATF-related customer data hosted?
EU, US and other regional hosting is available, with AES-256 encryption at rest, TLS 1.3 in transit, role-based access, maker-checker controls and immutable audit logs. Deployment scope is agreed during implementation.
Map your FATF programme to operating evidence.
Book a session and we will show how AML, KYC and Travel Rule controls connect to the evidence your supervisors expect.
