Service · Software development

Custom KYC/AML compliance software.

Custom software for Know Your Customer, anti-money laundering checks and ongoing compliance monitoring. We don't build a second ComplyAdvantage or Refinitiv. We build the sector-specific flow, the case management layer and the integration between all your sources that off-the-shelf packages don't solve for your situation.

KYC onboardingAML screeningUBO researchTransaction monitoring

Custom compliance software: what we do and don't do.

For standard screening against EU, UN and OFAC sanctions lists, PEP databases and adverse media feeds, good products already exist: ComplyAdvantage, NameScan, Sumsub, Onfido, Trulioo, Refinitiv World-Check, LexisNexis Bridger, Themis and Encompass. We have no intention of competing with them. Building our own sanctions list feed or maintaining a worldwide PEP database is a scale game we won't enter, as it rarely delivers anything fundamentally better than what is already on the market.

What we do build is the layer around them: the sector-specific KYC flow for trust offices, notaries, fiduciaries or crypto exchanges. The case management layer where your compliance officer handles files, flags escalations and records sign-off. The integration of multiple sources (the Chamber of Commerce register (KvK), iDIN, a purchased sanctions list API, your own customer database and your CRM) into one coherent file. And the risk scoring engine that fits your client base, not a generic retail bank.

For institutions falling under the Wwft, Wft, Wtt or DNB and AFM supervision, this is often where the gains lie. Your sanctions list provider does what it needs to do. Your own onboarding process, ongoing monitoring of existing relationships, UBO verification via KvK, periodic review of high-risk clients and the audit trail for the supervisor are often still spreadsheet work, semi-manual flows in SharePoint or loose modules in a CRM not designed for the purpose. That is where we provide custom software, built around the standard products you already pay for: not beside them, and certainly not instead of them.

Three types of KYC/AML compliance software we build.

Most projects start with one of these three and grow organically from there. In the first conversation we advise which variant will deliver the most for your type of institution and your client base.

First engagement · fixed sprint budget

KYC onboarding and client acceptance

A streamlined onboarding flow for new clients: identification via iDIN or passport scan with OCR and chip reading, KvK integration for business relationships, UBO enquiry with automatic mapping of the ownership structure, PEP and sanctions list checks via your existing screening provider, risk classification based on your own acceptance policy, and recording of the complete client acceptance file. Includes an escalation flow to the compliance officer when the risk score exceeds the threshold, and automatic notification to the relationship manager once the file is complete.

iDIN & passport OCRKvK integrationUBO researchRisk classification
Mid-sized project · fixed sprint budget

Compliance case management and monitoring

The software your compliance officer uses every day: a case management environment where alerts from screening, transaction monitoring and ongoing monitoring come in, are assessed, documented and closed. Workflows for handling true hits and false positives, the four-eyes principle for high-risk cases, automatic alerts when a review deadline is approaching, and an FIU reporting module with the right fields for the Dutch reporting chain. For ongoing monitoring, we re-screen your existing client base every night against the latest sanctions list and PEP updates, and flag adverse media relating to an existing client.

Case managementFour-eyes principleOngoing monitoringFIU reporting
Larger project · fixed sprint budget

Compliance platform and transaction monitoring

A complete compliance platform with deep integration across your core systems: transaction monitoring with its own rules engine that detects patterns (structuring, unusual geographic flows, transaction volumes outside the client profile), risk scoring that adapts to client type, dashboard reporting for DNB and AFM, and ongoing lifecycle monitoring from onboarding through to offboarding. Includes integration with your CRM, ERP, core banking system or investment administration, plus an audit trail that demonstrably records every action in the system for later inspection.

Sanctions screening carries its own obligation of immediate freezing and reporting, and the risk lies in the list changing while your file stays the same. See Sanctions Act software.

If the relationship begins away from the office, the check often comes after the transaction. How to bring that moment forward and enforce the block at the point of transaction is covered in the sanctions check app at the point of transaction.

If you act as a service provider to financial clients, there is a second layer of accountability: evidence that your own control measures have been carried out. See the app for signing off controls.

Transaction monitoringRules engineDNB reportingAudit trail

What you receive at the end of a project.

A production-ready compliance environment that connects to your existing screening providers and core systems, plus everything around it so you can manage it yourselves or have your IT partner manage it.

  • The compliance environment itselfProduction plus staging environment, running in your cloud (Microsoft Azure, AWS or GCP) or managed by us in an EU region with demonstrable data residency.
  • Integrations with external data sourcesAPI integrations with KvK, iDIN, your chosen screening provider (ComplyAdvantage, Refinitiv, LexisNexis), your core banking system or CRM, and adverse media feeds where relevant.
  • Risk scoring model tailored to your client baseA transparent rules engine with scoring by country, sector, client type, transaction volume and product type, configurable by your compliance officer without a developer.
  • Codebase and architecture documentationFull source code in a Git repository, build and deployment instructions, and an architecture overview for your IT partner or in-house IT team.
  • Audit trail and supervisory reportingStandard exports for DNB, AFM and internal audit, plus demonstrable logging of every action taken in the system: who, what and when.
  • Training for compliance officers and relationship managersTwo sessions for key users within your team and a short video introduction for relationship managers who work only on client onboarding.
  • Maintenance contract (optional)Monitoring, backups, security patches, integration maintenance and ongoing development in response to changes in sanctions regimes or supervisory requirements. Fixed monthly fee, with several response-time levels.

When bespoke development is the right choice for your compliance.

Four patterns we repeatedly see among institutions that approach us. If you recognise one of them, we would be happy to talk further.

Industry-specific flow

A standard product doesn't fit your sector

You are a trust office, a notary, a fiduciary or a crypto exchange, and standard KYC suites are designed for a retail bank, not for your situation. The questionnaire, the UBO analysis, the risk criteria and the retention periods differ substantially. A bespoke onboarding flow built on top of a purchased screening feed is often a better fit than a suite you have to bend your processes around.

Fragmented sources

Data sits in five places

Client details sit in a CRM, transaction data in the core banking system, sanctions list hits in a separate tool from your screening provider, adverse media in a mailbox and the Wwft file on a shared drive. No one has a complete picture of a client. A bespoke compliance layer that brings these sources together into a single file makes your compliance officer's work considerably more efficient.

Your own risk model

Generic scoring doesn't work

An off-the-shelf solution gives every asset manager, every estate agent and every fintech the same risk classification. As a compliance officer, you know your client base has a different profile from that standard assumption. A bespoke rules engine, in which you can configure country, sector and transaction-volume rules, and which you can justify to DNB or AFM, produces far sharper alerts.

White-label for clients

You perform KYC for your clients

You are an accountancy firm, notary or trust office that is itself subject to the Wwft and must carry out KYC for corporate clients. You want to offer your clients a private environment in which they can submit identification, record UBOs and take part in the annual review, branded as yours rather than that of an external SaaS provider.

How a KYC/AML compliance project works.

1

Introduction and intake

A conversation in which we understand which supervision you fall under (DNB, AFM, BFT, NBA), which screening provider you currently use, which core systems are in place, which client types you serve and where the current flow falls short. We also map out the integrations required: KvK, iDIN, a purchased sanctions list API and your own client database. That way we already know, before the scope workshop, which smart API integrations form part of the project.

2

Discovery, scope and compliance requirements

A workshop with the compliance officer, a partner or director, and interviews with the people who currently carry out the onboarding and monitoring work. We map out the current process flows and check them against the applicable legislation and regulation (Wwft, Wft, Wtt, EU AMLD). We identify where bespoke development adds value and where your existing screening provider is perfectly adequate. At the end, you have a concrete scope, a sprint plan and a first screen flow for onboarding or case management.

3

Building in sprints

We work in two-week sprints and deliver a working, testable version at the end of each one. One compliance officer acts as product owner and one director or partner as sponsor. Early in the project we test the onboarding flow with real client cases, naturally in a sandboxed environment, so we can see where the flow runs into trouble before going live. A first tier is ready after a few sprints; a complete compliance platform with transaction monitoring runs over a project of several sprints. At the end of each sprint there is a short demo for the compliance team and a preview of the next sprint.

4

Rollout, training and ongoing management

A phased rollout to your compliance team and relationship managers, with parallel running against the existing process so we can confirm that no alert is missed. Training for key users within your team and a short video introduction for relationship managers. From go-live we provide monitoring, security patches, integration maintenance and ongoing development in response to changes in sanctions regimes or new supervisory requirements. For every change to the Wwft or extension of a sanctions list, we carry out the impact analysis and the adjustment at our own cost.

Frequently asked questions about KYC/AML compliance software.

The questions compliance officers, board members and MLROs usually ask us before a project starts.

Do you replace ComplyAdvantage, Refinitiv or a similar provider?
No. For standard sanctions list screening, PEP databases and global adverse media feeds, ComplyAdvantage, NameScan, Sumsub, Onfido, Trulioo, Refinitiv World-Check, LexisNexis Bridger, Themis and Encompass are strong products, and we do not position ourselves as a replacement for them. We would also not recommend a migration project on that basis. What we build is the layer around them: the industry-specific onboarding flow, case management, your own risk model and the integration of multiple sources that these providers do not solve for your situation.
Is a custom solution DNB- or AFM-compliant?
Compliance is first and foremost a property of your process and your policy, not of the software package. We build the system so that it enforces your policy document: identification, verification, risk classification, monitoring, periodic review, the four-eyes principle on high-risk cases and a watertight audit trail. On every project we work with your compliance officer or an external consultant to verify that the configuration aligns with your own adopted policy and with the relevant articles of the Wwft or the Wft. We do not make legal statements on behalf of your institution.
How does FIU reporting work from the system?
When a transaction or client case meets the criteria for an unusual transaction, a draft report is created in case management with all relevant fields pre-filled: identity details, transaction details, the type of unusual activity and the justification. Your MLRO or compliance officer reviews and submits it. The system tracks the status of every report (draft, submitted, query from FIU-NL, closed) and retains the full trail in line with the retention period under the Wwft.
Do you also build for trust offices and fiduciaries?
Yes, and that sector is a particularly good fit for custom development. The requirements under the Wtt, the type of client (e.g. international holding structures with multiple UBOs and administrators), the retention periods and the risk questionnaire differ considerably from what a retail-oriented standard suite supports. For trust offices we build onboarding flows that handle the typically more complex ownership structures, ongoing monitoring of the UBOs separately from the client entity, and reporting that matches the specific Wtt requirements for DNB.
Does this also work as a white-label for our clients?
Yes. For accountancy firms, notary offices and legal service providers that are themselves subject to the Wwft and need to perform KYC on their corporate clients, we build the software as white-label, with your brand instead of ours, your own policy rules in the rules engine and a client portal where your clients submit their identification, UBO details and the annual review themselves. Your compliance officer retains control through case management.
How secure is a dedicated compliance environment for our client data?
As standard we work with SSO via Microsoft Entra ID, Okta or a comparable identity provider, MFA for all users, encryption in transit and at rest, and a full audit log of who viewed or changed what and when. GDPR-compliant data processing is the starting point; for regulated institutions we carry out a DPIA as standard and, optionally, a penetration test by an external party in the final sprint. Hosting in an EU region is standard and we provide data processing agreements.
What determines the cost of a programme?
Four things: the breadth of scope (onboarding only versus a full compliance platform with transaction monitoring), the number of integrations with external sources (KvK, iDIN, your screening provider, core banking system, CRM), the stringency of the supervisory regime you fall under, and whether you hand over monitoring and ongoing development to us or take it on in-house. We outline the range in the first conversation, and we always deliver a fixed sprint price so you aren't caught out by surprises. More context on how we build up pricing can be found in our knowledge base on custom software costs.
Does this also suit organisations that aren't regulated?
Yes, increasingly so. Businesses that are not subject to the Wwft but still want to limit sanctions and fraud risks, such as larger e-commerce platforms, marketplaces, B2B distributors with international customers, or property developers, can benefit from a bespoke KYC flow for business relationships. The legal requirements are lighter, so the configuration is usually simpler, but the benefits in fraud prevention and reputational risk can be considerable.
Do you also build enterprise software for larger financial institutions?
Yes. For larger institutions, we also build enterprise software with deeper integrations, a multi-region setup, connection to a corporate identity provider and governance around ongoing development. The difference lies mainly in compliance intensity, infrastructure and how we set up change management: change advisory boards, a release cadence aligned with your IT organisation, and SLA levels for different parts of the system.
Do you also build KYC for insurers and accountancy firms?
Yes. For insurers under Wft supervision and accountancy firms subject to Wwft obligations, we build onboarding and monitoring flows that match their specific working processes. For accountancy firms, we often combine the KYC flow with a broader project; you can read more on our page about building accountancy software. For insurers, it fits with the wider acceptance and claims process; see our page on building insurance software.
How does the transition from our current tools and spreadsheets work?
In phases. We let your existing Excel trackers, shared drives and SharePoint folders run in parallel with the new system for a period, so compliance officers can get used to it and we can spot any shortcomings early. We carry out data migration using scripts written for your situation: relationships, ongoing cases, UBO registrations and historical reports are transferred in a checked way, with a rollback option should anything go wrong. Only once the team is comfortable and the first internal audit has passed successfully are the old tools archived.

Talk to us about your KYC/AML compliance software.

A no-obligation introductory call of half an hour. We listen to how your compliance process currently runs, which screening provider you use and where it's causing friction, and we give direction you can act on straight away, even if we ultimately don't work together.

Edit content