# Welcome to the Customer Support

At Tiller, we understand the complexities and evolving nature of Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations. That's why we've curated a range of resources and guides explaining Verify by Tiller's services.

{% hint style="info" %}
**Verify by Tiller:** A robust digital solution that provides high-quality customer ID verification and customer due diligence (CDD) for regulated and supervised businesses. The cutting-edge technology that powers this solution, coupled with the highest quality data sources, ensures a service of the highest regulatory standards.
{% endhint %}

{% embed url="<https://vimeo.com/868287110?share=copy>" %}
Verify by Tiller - KYC checks made simple
{% endembed %}

## What is Verify by Tiller?

Get acquainted with the service and its benefits.

{% content-ref url="/pages/hVR8nyK8fvzLm6VduObh" %}
[What is Verify by Tiller](/service-information/what-is-verify-by-tiller)
{% endcontent-ref %}

{% content-ref url="/pages/cjsL9QyS6ThBGXjqWrY4" %}
[The Checks](/service-information/the-checks)
{% endcontent-ref %}

{% content-ref url="/pages/GfO83MjcpB8r1StrqMb1" %}
[Help & Support](/help-and-support/faqs)
{% endcontent-ref %}


# What is Verify by Tiller

Providing high-quality customer due diligence for regulated and supervised businesses.

{% hint style="info" %}
**Verify by Tiller:** A robust digital solution that provides high-quality customer ID verification and customer due diligence (CDD) for regulated and supervised businesses. The cutting-edge technology that powers this solution, coupled with the highest quality data sources, ensures a service of the highest regulatory standards.
{% endhint %}

## The Verify Portal

The Verify Portal, help businesses to manage and streamline their Know Your Customer (KYC) processes: <https://app.tiller-verify.com/>.

An intuitive interface for inviting customers, conducting identity verification, and reviewing compliance-related checks. The portal simplifies management of KYC, AML, and CDD obligations by providing a hub where administrators can oversee customer verifications.

**What is it for?**

1. **Send invites:** Create applications and send out invites to your customers. They can complete their check on our mobile app.
2. **Monitor applications:** Offers a holistic view of customer progress, verification results, and check information for each customer.
3. **Customer reports:** Get status updates of each application and download our comprehensive customer report to store on your records.
4. **Customise settings:** Admin users can manage company details, user roles, and account settings, offering a tailored experience to match business requirements.

For more information on the Verify Portal and how it works, please see the [Broken mention](broken://pages/ESwIgABucUGZ3i5VC9QL) section.&#x20;

## The Verify App

The Verify Mobile App is used by your customers to perform their checks. They send information and complete the process directly from their smartphone. It offers a convenient and user-friendly approach to providing the information the business needs for their AML process.&#x20;

Working together with the Verify Portal, the app ensures a configurable journey for customer onboarding tasks.

**The Verify Process:**

1. **Invitation:** Customers receive an email invitation containing a unique invite code, valid for 7 days and instructions to download the app.
2. **Complete actions:** The user must accept the end-user terms and complete the required actions for the checks (e.g. scan identity document). The actions needed depend on the type of application.&#x20;
3. **Check the results:** Once all actions are complete both the customer and business will receive an email confirmation. The check can be reviewed in the Verify Portal.


# The Verify Portal

A platform to manage your KYC applications.

Businesses use the Verify Portal to manage and streamline their customer Know Your Customer (KYC) process.

The portal simplifies the management of verifying your customers and fulfilling AML obligations by providing a hub where administrators can manage applications, view detailed check results, manage, and download comprehensive reports. It works together with the Verify Mobile App, providing a seamless, secure, and compliant customer onboarding experience. For detailed guidance on how the portal works please see the [Broken mention](broken://pages/ESwIgABucUGZ3i5VC9QL) section.

## Application Overview

The "Applications" section of the Verify Portal is where users create, manage and review applications. You can view all in-flight application in both a 'card' and 'table' view. Each application has a status of either 'New', 'In Progress', 'In Review', 'Completed' or 'Rejected'.

**Application Status Tracking:** Each application has a status of either 'New', 'In Progress', 'In Review', 'Completed' or 'Rejected'. So you can monitor the progress of all applications and quickly identify ones that need your attention at a glance.

**Creating New Applications:** Users can start new applications by clicking the "+ New Application" button. The process involves a straightforward workflow for adding individuals to the application and sending out verification invites.

**Search and Filter:** Searching enables users to quickly find specific applications using reference IDs or individual names. The filter option allows the sorting of applications based on criteria such as date, type, or consultant, facilitating efficient management.

## Viewing Applications

You can select an application to view key information about the application and participants associated with it. This includes general details about the application, checks completed and the details about the participants associated with it.

## Participant View

You can view comprehensive information about the indivdiual, their progress, and check results. Users can access detailed information about check statuses and review results, empowering them to oversee, and take action for each participant. As part of the review process, checks in the 'Review' status can be manually accepted or rejected.

## Profile and Settings

Users can access their profile details and update their personal information, such as email addresses and passwords. This feature ensures that users can manage their accounts securely and efficiently.

Accessible only to admin users, the Settings section allows the management of company details, user accounts, and application types. Admin users can add, modify, or remove users and update company information, such as logos and branding elements. Additionally, admin users can customise and manage their PEP, Sanction, and Adverse Media checks directly within the settings area as per their business requirements.


# The Verify Mobile App

The Verify Mobile App is downloaded by customers to provide information and complete their checks. It has been designed to make the verification process quick and easy for customers, eliminating the need for manual processes. Following a few simple steps, customers can complete their verification process in less than 10 minutes.  For more detailed information, please visit the following link: [Broken mention](broken://pages/gAPX8iRYPzrl4TywuRw8)

The steps involve the following:

1. &#x20;Download the app
2. &#x20;Input the invite code from their email
3. &#x20;Accept the terms and conditions&#x20;
4. &#x20;Get your document ready&#x20;
5. &#x20;Complete the checks

The journey is straightforward and easy to navigate.&#x20;

<figure><img src="/files/8yo775ffQwvQa7eTZnLD" alt="" width="375"><figcaption><p>APP User Guid</p></figcaption></figure>


# The Checks

Verify can perform many checks on customers as part of their KYC record.

The section below describes what information can be captured and checks that can be completed.

{% hint style="info" %}
**Application Types:** Applications can be configured to only perform the checks you need. Keeping the journey concise to your business needs.&#x20;
{% endhint %}

* [Personal Details Capture](/service-information/the-checks/personal-details-capture)
* [Identity Document, Biometric Face Match and Liveness](/service-information/the-checks/identity-document-biometric-face-match-and-liveness)
* [International Address Verification](/service-information/the-checks/international-address-verification)
* [PEP and Sanction Screening](/service-information/the-checks/pep-and-sanction-screening)
* [Adverse Media Screening](/service-information/the-checks/adverse-media-screening)
* [Proof of Address Upload](/service-information/the-checks/proof-of-address-upload)
* [Geolocation Check](/service-information/the-checks/geolocation-check)
* [Source of Funds](/service-information/the-checks/source-of-funds)


# Personal Details Capture

## Personal Details

Personal details are captured from your customer and checked against the originally invitation details. This helps to ensure that the individual record is accurate.

The following information is captured:

* First name
* Middle name(s)
* Last name
* Date of birth
* Gender (male, female, other)

This will highlight any mismatches between your record and what the customer has submitted through the Verify app.

## Nationality and Place of Birth

Applications can also be configured to capture both nationality and place of birth. This can help firms gather richer information about their client and may have internal processes around these two elements.&#x20;

Tiller is looking to implement further optional checks around the nationality and place of birth in the future.&#x20;


# Identity Document, Biometric Face Match and Liveness

At the core of our resilient AML platform is an uncompromising commitment to security and accuracy, driven by our advanced Identity Document, Biometric Face Match, and Liveness verification engine. Recognizing the stringent demands of modern regulatory environments, our digital identity verification process is certified against the [**UK Government’s Digital Identity and Attributes Trust Framework (DIATF)**](#user-content-fn-1)[^1]. This certification along with our [**ISO 30107-3 iBeta Accreditation Level 2 PAD**](#user-content-fn-2)[^2] liveness certification is a direct reflection of the rigorous, and high standards of our system, empowering your business to confidently prevent fraud, streamline onboarding, and meet complex KYC/AML obligations with absolute technological certainty.

## Identity Document Verification

Identity document verification is done by scanning and validating the integrity of a government-issued identity document. Verify support Passports, Driving Licences, or National ID Cards.&#x20;

The document verification process uses image analysis techniques, Physical tamper checks, and electronic chip-based verification to confirm the integrity of the provided ID document.

&#x20;**1. Visual & Data Integrity Checks (Optical)**

The system relies on Optical Character Recognition (OCR) and template matching using the camera's high-resolution image.

* **MRZ Checksum Validation:** For passports and ID cards with a Machine-Readable Zone (the code at the bottom), the software calculates the check digits (mathematical checksums) to ensure the data lines are valid and have not been generated by a random number generator.
* **VIZ vs. MRZ Consistency:** It extracts data from the **Visual Inspection Zone (VIZ)**, the normal text fields like Name and Date of Birth using **OCR** and compares it against the data in the **MRZ**. Any mismatch (e.g., a name spelled differently or a date altered in one place but not the other) triggers a failure.
* **Template Matching (Pattern Recognition):** The image is compared against our providers global library of document templates. The software verifies the precise location of logos, the font type and size, and the background "guilloche" patterns (fine wavy lines) to ensure they match the issuing authority's standards.

&#x20;**2. Physical Security & Tamper Detection**

To detect forgeries or "presentation attacks" (spoofing), the system analyses the physical properties of the document image.

* **Photo Tampering Detection:** The algorithms analyse the pixel density and edges around the photo area to detect "paste-over" attacks (where a fraudster glues a new photo over a stolen ID) or digital manipulation.
* **Material Presence (Liveness):** The system checks for artifacts that suggest the document is not real plastic or paper. This includes detecting **screen refresh rates** (moire patterns) if someone is holding a phone up to the camera, or **lack of depth** if they are presenting a printed paper photocopy of an ID.

&#x20;**3. Electronic Verification (NFC for Passports)**

When a passport or e-ID is available and the phone is NFC-enabled, the system performs the "Gold Standard" cryptographic checks. This is the most reliable way to verify integrity because the data is cryptographically signed by the issuing government.&#x20;

* **Chip Access (BAC/PACE):** The app reads the MRZ to generate a key (Basic Access Control or PACE) to unlock the RFID chip. If the chip cannot be unlocked using the printed MRZ data, it suggests the physical page does not belong to the chip (a cloned or altered page).
* **Passive Authentication (Data Integrity):** The software validates the **Document Signer Certificate (DSC)** against the Country Signing Certificate Authority (CSCA). This confirms that the data on the chip was signed by the government and has not been altered by a single byte since issuance.
* **Active Authentication (Cloning Detection):** The chip is sent a random "challenge" which it must sign with its private key. A cloned chip will not have the private key and will fail this test, proving the physical document is the original.

## Biometric Face Match

Biometric technology is critical to reliable identity verification. During the user journey, clients are required to capture a ‘selfie’.

The This process involves **Biometric Feature Extraction**, where the software maps the geometry of the face from both the selfie and the ID photo. It typically analyses 68 specific nodal points, measuring the distance between the eyes, the width of the nose, the depth of the eye sockets, and the shape of the jawline. The algorithm creates a mathematical template for each image

The result of this comparison is a Similarity Score (or **Confidence Score**). The system generates a probability percentage (0–100) indicating how likely it is that the two images depict the same individual. This score is compared against a pre-defined Acceptance Threshold.

Beyond the standard geometric match, the process performs **Deepfake & Injection Attack Detection**. While liveness detects physical masks, this specific check ensures the camera feed itself hasn't been hijacked. It analyses the video stream for pixel inconsistencies, unnatural lighting boundaries, or metadata anomalies that suggest the image was generated by AI or injected via a virtual camera driver rather than captured directly by the phone’s hardware lens. This ensures the "person presenting" is physically holding the phone, not digitally simulating the camera input. This is why we only use native mobile apps to capture images and not web-based capture or allow image uploads. By using native apps we can prevent hijacking of the video stream.

If an e-passport is used, the chip photo will be extracted using NFC (Near Field Communication) technology. This provides a gold standard of verification as the chip photo, portrait photo and selfie photo are all cross-validated as part of the check.

## Passive Liveness Test

Liveness detection is designed to ensure that the biometric data provided during an identity verification process comes from a real, live person rather than a spoof or static image. Unlike methods that rely on real-time challenges, passive liveness runs silently in the background without requiring any physical interaction from the user.

The system analyses natural visual cues, such as skin texture, light reflections, and micro-movements, to distinguish a live human face from a photograph, mask, or video. By doing so, passive liveness adds an extra layer of security against spoofing attacks while keeping the verification process seamless and frictionless for the user.

The advanced passive liveness technology is certified as meeting the highest international standard of [**ISO 30107-3 iBeta Accreditation Level 2 PAD**](#user-content-fn-3)[^3]**.**

Certification to this standard requires to the following to have been achieved:

* **ISO 30107-3:** This international standard is the foundational framework for testing and evaluating how effectively a liveness detection solution can detect and defend against presentation attacks (spoofing attempts like photos, videos, or masks).
* **iBeta Accreditation:** iBeta is an independent testing lab accredited to perform testing against the ISO 30107-3 standard.
  * **Level 1 PAD:** Confirms basic attack detection capabilities.
  * **Level 2 PAD:** A higher, more robust level of certification that involves more sophisticated attack scenarios and is considered the gold standard for enterprise-grade solutions.

## Personal Details Match

The personal information is taken using OCR (optical character recognition) from the identity document. For e-passports, NFC is also used to extract personal information. The details are then checked against the personal details provided by the customer. Ensuring that it is the same person and the cross-referencing with the invite details sent from the portal.

[^1]: The UK digital verification services trust framework is the set of rules and standards that show what a good digital identity looks like.

    Digital verification services are then independently certified against the trust framework to prove they are following the rules.

[^2]: ISO 30107-3 iBeta Level 2 PAD is an independently tested, globally recognized biometric security standard that certifies a liveness detection system can successfully block sophisticated spoofing attempts, such as realistic 3D silicone masks and artificial physical models.

[^3]:


# International Address Verification

International residential address verification uses a number of data providers with access to regional data source providers within the supported countries. Verify by Tiller uses data sources direct from government agencies, credit agencies, utility companies and landline telecommunication providers. Mobile telecommunication providers, marketing lists or other sources which do not meet regulatory standards are not used.

When verifying the address, Verify determines which in-country data sources are available and most likely to be able to obtain a match and get the provider to confirm if the credentials provided match their records. By matching directly to the original data source provider, we ensure the data is as up to date as possible. The number and degree of match is then used to confirm if the individual is a resident at their stated address.

## Address sources

Tiller partners with a number of carefully selected regional agents who have access to specific in-country regulatory-quality data sources. Tiller’s Verify application will only use one or more of the following data source types to verify the residential address of an individual:

* Credit Agency Databases,
* Government Databases (e.g., Voter, Social Security, Population/Citizenship Registries)
* Utility Company Databases (e.g., Electricity, Water, Gas, Telephone (excluding Mobile)).

Regulators make provision for the address to be verified against such data sources and Verify includes which data source types were used in the verification results it provides back via its API.

It is necessary to support residential address checks to temporarily share name and address PII information with a data source provider for the match check to be performed. Tillers legal agreements with our providers strictly restricts the use and retention of the PII information shared. PII data is only permitted to be used for the purposes of confirming a name and address match and may not be retained or used for any other purposes. The providers are also contractually required to adhere to all provisions of GDPR.

Tillers systems and data are hosted within the EU/EEA, however, where an individual being checked is resident outside the EU it is necessary for Tiller to share that individuals PII data with the data source providers in that individual’s country of residence. Tillers legal agreements with our providers include the modernised 2021 EU SCC (Standard Contractual Clauses) that have been “pre-approved” by the European Commission, ensuring appropriate data protection safeguards covering international transfers of PII data.

The above data handling & verification model is that same as that used by our larger enterprise customers such has HSBC, who received a confirmation of ‘no objection’ from the JSFC (Jersey Financial Services Commission) when they submitted their outsourcing request to use Tillers services to them.


# PEP and Sanction Screening

PEP and Sanction screening uses an external data provider. They maintain a correlation database of PEP Tier 1, 2, 3 & PEP by association OECD categorises lists which are updated daily from various sources, such as official government websites or national assemblies of foreign offices, CIA World leaders list, open source verified repositories and selected media websites.

For Sanction screening, the database is collated and updated daily from the following sources: FCO UK Sanctions List, US Department of the Treasury - Office of Foreign Assets Control (OFAC), US Department of State - Bureau of International Security & Non-Proliferation Sanctions, UN Security Council Committees, EU Sanction records, US Defence Trade Controls and other international government and local authority resources.

## Sanction & Enforcement Sources

Please see below a list of sanctions and enforcement sources that are checked&#x20;

<details>

<summary>Sanction Source List</summary>

<table data-full-width="true"><thead><tr><th width="132">Country</th><th width="533">Sanction Source</th></tr></thead><tbody><tr><td>Algeria</td><td>Ministry of Interior-National Sanctions List (DZ-MOI-NSL)</td></tr><tr><td>Argentina</td><td>Ministry of Foreign Affairs United Nations Consolidated List (AR-MFAUN)</td></tr><tr><td>Australia</td><td>Australian National Security (AU-ANS)</td></tr><tr><td> </td><td>Commonwealth of Australia Law (AU-CWLAW)</td></tr><tr><td> </td><td>Department of Foreign Affairs and Trade (AU-DFAT)</td></tr><tr><td>Austria</td><td>Oesterreichische National Bank (AT-ONB)</td></tr><tr><td>Azerbaijan</td><td>Financial Monitoring Service (AZ-FMS)</td></tr><tr><td>Bahrain</td><td>Ministry of Information Affairs Domestic Terrorist List (BH-MIA-DTL)</td></tr><tr><td>Belarus</td><td>State Security Agency of Belarus- Sanction (BY-KGB-S)</td></tr><tr><td>Belgium</td><td>Royal Decree 28 December 2006 (BE-RD2006)</td></tr><tr><td>Canada</td><td>Freezing Assets of Corrupt Foreign Officials Regulations Tunisia (CA-FACFOTN)</td></tr><tr><td> </td><td>Justice for Victims of Corrupt Foreign Officials Regulations (CA-JVCFOA)</td></tr><tr><td> </td><td>Public Safety Canada (PSCA)</td></tr><tr><td> </td><td>Special Economic Measures against Belarus (CA-SPMEBY)</td></tr><tr><td> </td><td>Special Economic Measures against Burma (CA-SPMEBU)</td></tr><tr><td> </td><td>Special Economic Measures against Guatemala (CA-SPMEGT)</td></tr><tr><td> </td><td>Special Economic Measures against Haiti (CA-SPMEHT)</td></tr><tr><td> </td><td>Special Economic Measures against Iran (CA-SPMEIR)</td></tr><tr><td> </td><td>Special Economic Measures against Moldova (CA-SPMEMD)</td></tr><tr><td> </td><td>Special Economic Measures against Nicaragua (CA-SPMENI)</td></tr><tr><td> </td><td>Special Economic Measures against People's Republic of China (CA-SPMEPRC)</td></tr><tr><td> </td><td>Special Economic Measures against Russia (CA-SPMERU)</td></tr><tr><td> </td><td>Special Economic Measures against South Sudan (CA-SPMESS)</td></tr><tr><td> </td><td>Special Economic Measures against Sri Lanka (CA-SPMELK)</td></tr><tr><td> </td><td>Special Economic Measures against Sudan (CA-SPMESD)</td></tr><tr><td> </td><td>Special Economic Measures against Syria (CA-SYRIA)</td></tr><tr><td> </td><td>Special Economic Measures against Ukraine (CA-SPMEUA)</td></tr><tr><td> </td><td>Special Economic Measures against Venezuela (CA-SPMEVE)</td></tr><tr><td> </td><td>Special Economic Measures against Zimbabwe (CA-SPMEZW)</td></tr><tr><td> </td><td>Special Economic Measures (Extremist Settler Violence) (CA-SPMEESV)</td></tr><tr><td> </td><td>Special Economic Measures (Hamas Terrorist Attacks) (CA-SPMEHTA)</td></tr><tr><td>China</td><td>Ministry of Commerce-Unreliable Entity List (CN-MOC-UEL)</td></tr><tr><td> </td><td>Ministry of Foreign Affairs Sanctions Announcements (CN-MFASANA)</td></tr><tr><td> </td><td>Ministry of Public Security- Sanction (CN-MPS-S)</td></tr><tr><td> </td><td>Taiwan Affairs Office of the State Council (CN-TAOSC)</td></tr><tr><td>Cote d'Ivoire</td><td>National Financial Information Processing Unit (CENTIF) Sanctions (CI-CENTIF)</td></tr><tr><td>Czech Republic</td><td>Ministry of Foreign Affairs National Sanctions List (CZ-MFA-NSL)</td></tr><tr><td>Egypt</td><td>Domestic Terrorist List (EG-DTL)</td></tr><tr><td>Estonia</td><td>Ministry of Foreign Affairs- Sanctions (EE-MFA-S)</td></tr><tr><td>France</td><td>Ministère de l'Economie (FR-MINEFE)</td></tr><tr><td>Holy See</td><td>Law N.XVIII, Title VI, Article 71 Sanctions (VA-LXVIII)</td></tr><tr><td>Hong Kong SAR</td><td>Monetary Authority-Sanctions (HK-HKMAS)</td></tr><tr><td> </td><td>Safeguarding National Security Ordinance-Sanctions (HK-SNSO-S)</td></tr><tr><td>India</td><td>Ministry of Home Affairs of India (IN-MHA)</td></tr><tr><td>International</td><td>Consolidated Sanctions List (Sanctions)</td></tr><tr><td> </td><td>European Union List (EUList)</td></tr><tr><td> </td><td>Security Council Res 1533 (UN-SC-1533)</td></tr><tr><td> </td><td>Security Council Res 1718 (UN-SC-1718)</td></tr><tr><td> </td><td>Security Council Res 1970 (UN-SC-1970)</td></tr><tr><td> </td><td>Security Council Res 2048 (UN-SC-2048)</td></tr><tr><td> </td><td>Security Council Res 2140 (UN-SC-2140)</td></tr><tr><td> </td><td>UN Security Council Res 751 (1992) Al-Shabaab (UN-SC-751)</td></tr><tr><td> </td><td>UN Security Council Res 1267 (1999) 1989 (2011) &#x26; 2253 (2015) (UN-SC-1267)</td></tr><tr><td> </td><td>UN Security Council Res 1518 (2003) Iraq (UN-SC-1518)</td></tr><tr><td> </td><td>UN Security Council Res 1591 (2005) Sudan (UN-SC-1591)</td></tr><tr><td> </td><td>UN Security Council Res 1988 (2011) (UN-SC-1988)</td></tr><tr><td> </td><td>UN Security Council Res 2127 (2013) Central African Republic (UN-SC-2127)</td></tr><tr><td> </td><td>UN Security Council Res 2206 (2015) (UN-SC-2206)</td></tr><tr><td> </td><td>UN Security Council Res 2653 (2022) Haiti (UN-SC-2653)</td></tr><tr><td>Iraq</td><td>Terrorist Freezing Funds Committee International List (IQ-TFFC-IL)</td></tr><tr><td> </td><td>Terrorist Freezing Funds Committee National List (IQ-TFFC-NL)</td></tr><tr><td>Israel</td><td>Ministry of Defense Terrorism List (IL-MODTL)</td></tr><tr><td> </td><td>Ministry of Finance (IL-MOF)</td></tr><tr><td>Japan</td><td>Ministry of Finance Japan (JP-MOF)</td></tr><tr><td>Jordan</td><td>Tech Committee for Implementation of Security Council National List (JO-TC-NL)</td></tr><tr><td>Kazakhstan</td><td>Financial Monitoring Agency Financing Of Terrorism/Extremism (KZ-FMA-FTE)</td></tr><tr><td> </td><td>Financial Monitoring Agency Involvement in terrorist activities (KZ-FMA-ITA)</td></tr><tr><td> </td><td>Legal Statistics &#x26; Special Records General Prosecutor (KZ-CLSSR)</td></tr><tr><td>Kyrgyzstan</td><td>State Financial Intelligence Service under the Govt. Kyrgyz Republic (KG-SFIU)</td></tr><tr><td>Latvia</td><td>National Sanctions (LV-NatSanc)</td></tr><tr><td>Liechtenstein</td><td>Financial Market Authority of Liechtenstein (Sanctions) (LI-FMA-S)</td></tr><tr><td>Lithuania</td><td>Financial Crime Investigation Service-Sanctions (LT-FCIS-S)</td></tr><tr><td>Macedonia</td><td>Financial Intelligence Office Domestic List (MK-FIO-DL)</td></tr><tr><td>Malaysia</td><td>Ministry of Home Affairs Sanctions (MY-MOHA-S)</td></tr><tr><td>Mexico</td><td>UIF Res 1267 (MX-UIF1267)</td></tr><tr><td> </td><td>UIF Res 1718 (MX-UIF1718)</td></tr><tr><td> </td><td>UIF Res 1988 (MX-UIF1988)</td></tr><tr><td>Moldova</td><td>Interinstitutional Supervisory Council-Sanctions (MD-ISC-S)</td></tr><tr><td>Monaco</td><td>Service d'Information et de Contrôle sur les Circuits Financiers (MC-SICCFIN)</td></tr><tr><td>Morocco</td><td>Commission for Application of United Nations Sanctions Local List (MA-CNASNU)</td></tr><tr><td>Mozambique</td><td>Financial Information Office of Mozambique- National Sanctioned List (MZ-GIFIM-S)</td></tr><tr><td>Netherlands</td><td>National Terrorism List (NL-NTL)</td></tr><tr><td>New Zealand</td><td>New Zealand Police List: UNSC 1373 (NZ-UN-1373)</td></tr><tr><td> </td><td>New Zealand Police List - UNSC 1267/1989 and 1988 (NZ-POLICE)</td></tr><tr><td> </td><td>Russia Sanctions Regulations (NZ-RSR)</td></tr><tr><td>Nigeria</td><td>Nigeria Sanctions Committee Nigeria Sanctions List (NG-NSCNSL)</td></tr><tr><td>Oman</td><td>National Counter Terrorism Committee Local List (OM-NCTC-LL)</td></tr><tr><td>Pakistan</td><td>National Counter Terrorism Authority-Proscribed Persons (PK-NACTA-P)</td></tr><tr><td> </td><td>National Counter Terrorism Authority-Proscribed Organizations (PK-NACTA-O)</td></tr><tr><td>Philippines</td><td>Anti-Terrorism Council Designation Announcements (PH-ATCSAN)</td></tr><tr><td>Poland</td><td>General Inspector of Financial Information- Sanctions (PL-GIFI-S)</td></tr><tr><td> </td><td>Ministry of Interior &#x26; Admin Persons &#x26; Entities Subject to Sanctions (PL-MOIA-S)</td></tr><tr><td>Qatar</td><td>National Terrorists Designation List (QA-NTDL)</td></tr><tr><td>Russia</td><td>Federal Security Service of the Russian Federation (FSB) Terrorist List (RU-FSB-TL)</td></tr><tr><td> </td><td>Presidential Sanctions Decree No. 252 (RU-PSD252)</td></tr><tr><td> </td><td>Presidential Sanctions Decree No. 1300 (RU-D1300)</td></tr><tr><td>Russian Federation</td><td>Federal Financial Monitoring Service (ROSFINMON)</td></tr><tr><td> </td><td>Ministry of Foreign Affairs (RU-MFA)</td></tr><tr><td>Serbia</td><td>Domestic List of Designated Persons (RS-DLDP)</td></tr><tr><td>Singapore</td><td>Attorney-General's Chambers Terrorism (SG-AGC)</td></tr><tr><td> </td><td>MAS Financial Measures Related to Russia (SG-MASFMR)</td></tr><tr><td>South Africa</td><td>Targeted Financial Sanctions List (ZA-TFSList)</td></tr><tr><td>South Korea</td><td>Korea Financial Intelligence Unit (KR-KOFIU)</td></tr><tr><td> </td><td>Ministry of Strategy and Finance-Sanctions (KR-MOSF-S)</td></tr><tr><td> </td><td>Prime Ministers Office (KR-PMO)</td></tr><tr><td>Sri Lanka</td><td>Financial Intelligence Unit UNSCR 1373 (LK-FIU1373)</td></tr><tr><td>Switzerland</td><td>State Secretariat for Economic Affairs (SECO)</td></tr><tr><td>Tajikistan</td><td>Financial Intelligence Unit of the National Bank of Tajikistan (TJ-NBT)</td></tr><tr><td>Thailand</td><td>Anti-Money Laundering Office (TH-AMLO)</td></tr><tr><td>Tunisia</td><td>National Sanctions List (TN-NSL)</td></tr><tr><td>Turkey</td><td>Ministry of Treasury and Finance Article 5 of Law 6415 (TR-MTFA5)</td></tr><tr><td> </td><td>Ministry of Treasury and Finance Article 6 of Law 6415 (TR-MTFA6)</td></tr><tr><td> </td><td>Ministry of Treasury and Finance Article 7 of Law 6415 (TR-MTFA7)</td></tr><tr><td>Ukraine</td><td>National Security and Defense Council of Ukraine (UA-NSDC)</td></tr><tr><td> </td><td>State Financial Monitoring Service (UA-SFMS)</td></tr><tr><td>United Arab Emirates</td><td>National Terrorist List (AE-NTLTER)</td></tr><tr><td>United Kingdom</td><td>FCO UK Sanctions List (UK-FCOlist)</td></tr><tr><td> </td><td>UK Home Office Proscribed Terrorist groups (UK-PROTER)</td></tr><tr><td>United States</td><td>Department Homeland Security- UFLPA Entity List (US-UFLPA)</td></tr><tr><td> </td><td>Department of State Cuba Prohibited Accommodations List (US-DOSCPA)</td></tr><tr><td> </td><td>Department of State-Sanction (US-DOS-S)</td></tr><tr><td> </td><td>Dept of State- Foreign Terrorist Organizations (US-DOS-FTO)</td></tr><tr><td> </td><td>Dept of State Terrorist Exclusion List (US-DOS-TEL)</td></tr><tr><td> </td><td>Executive Order 14064 (US-EO14064)</td></tr><tr><td> </td><td>OFAC CAPTA Sanctions (US-CAPTA)</td></tr><tr><td> </td><td>OFAC Directive 1 under Executive Order 14038 (US-EO14038)</td></tr><tr><td> </td><td>OFAC Foreign Sanctions Evaders List (US-OFACFSE)</td></tr><tr><td> </td><td>OFAC Non-SDN Communist Chinese Military Companies List (US-OFACCMC)</td></tr><tr><td> </td><td>OFAC Non-SDN Menu-Based Sanctions List (US-NSDNMBS)</td></tr><tr><td> </td><td>OFAC Sectoral Sanctions Identifications (US-OFACSSI)</td></tr><tr><td> </td><td>Bureau of Industry and Security (BIS)- Denied Persons List (BIS)</td></tr><tr><td> </td><td>Debarred Parties (DTC)</td></tr><tr><td> </td><td>Department of State Chemical and Biological Weapons Sanctions (US-CBWS)</td></tr><tr><td> </td><td>Department of State Cuba Restricted List (US-DOSCUBA)</td></tr><tr><td> </td><td>Department of State Executive Order 12938 (US-EO12938)</td></tr><tr><td> </td><td>Department of State Executive Order 13382 (US-EO13382)</td></tr><tr><td> </td><td>Department of State Export-Import Bank Act (US-EIBA)</td></tr><tr><td> </td><td>Department of State Iran, North Korea, and Syria Nonproliferation Act (US-INKS)</td></tr><tr><td> </td><td>Department of State Missile Sanctions Laws (US-MSL)</td></tr><tr><td> </td><td>Department of State Nuclear Proliferation Prevention Act (US-NPPA)</td></tr><tr><td> </td><td>Department of State Sanctions Transfer of Lethal Military Equipment (US-STLME)</td></tr><tr><td> </td><td>Department of State Sections 231 &#x26; 235 Countering Adversaries Act (US-DOS231a)</td></tr><tr><td> </td><td>Financial Crimes Enforcement Network Section 311 Special Measures (FinCEN 311)</td></tr><tr><td> </td><td>OFAC EO13808 (US-EO13808)</td></tr><tr><td> </td><td>OFAC Palestinian Legislative Council List (US-PLC)</td></tr><tr><td> </td><td>Office of Foreign Asset Control (OFAC) Ownership Interest Sanctions (OFACOWNINT)</td></tr><tr><td> </td><td>Office of Foreign Asset Control (OFAC) SDN List (OFAC)</td></tr><tr><td>Uzbekistan</td><td>Department for Combating Economic Crimes-International List (UZ-DCEC-IL)</td></tr><tr><td> </td><td>Department for Combating Economic Crimes-National List (UZ-DCEC-NL)</td></tr></tbody></table>

</details>

<details>

<summary>Enforcement Sources List</summary>

<table data-full-width="true"><thead><tr><th width="147">Country</th><th width="745">Data Source Name</th></tr></thead><tbody><tr><td>Afghanistan</td><td>Appeal and Review Committee Decisions (AGEOPS) Vendors (AF-AGEOPS)</td></tr><tr><td> </td><td>DA Afghanistan Bank-Financial Transactions and Reports Analysis Center of Afghanistan (AF-FTRACA)</td></tr><tr><td>Africa</td><td>African Development Bank Group (AC-ADBG)</td></tr><tr><td>Albania</td><td>Albanian State Police (AL-POLICE)</td></tr><tr><td> </td><td>Albanian Supreme Court (AL-S.Court)</td></tr><tr><td> </td><td>Court of Appeal of Tirana (AL-CAT)</td></tr><tr><td> </td><td>District Court of Tirana (AL-AL-TIRA)</td></tr><tr><td> </td><td>General Prosecutor's Office (AL-GENPRO)</td></tr><tr><td>Andorra</td><td>Autoritat Financera Andorrana (AD-AFA)</td></tr><tr><td>Angola</td><td>Agência Angolana de Regulação e Supervisão de Seguros (AO-ARSEG)</td></tr><tr><td> </td><td>Banco Nacional de Angola (AO-BNA)</td></tr><tr><td> </td><td>Capital Markets Commission (AO-CMC)</td></tr><tr><td> </td><td>Ministry of Finance Press Releases (AO-MINFINP)</td></tr><tr><td>Anguilla</td><td>Anguilla Financial Services Commission (AI-FSC)</td></tr><tr><td>Antigua and Barbuda</td><td>Antigua and Barbuda Directorate of Offshore Gaming (AG-DOG)</td></tr><tr><td> </td><td>Financial Services Regulatory Commission (AG-FSRC)</td></tr><tr><td> </td><td>Office of National Drug Control Policy (AG-ONDCP)</td></tr><tr><td>Argentina</td><td>Administración Federal de Ingresos Públicos (AR-AFIP)</td></tr><tr><td> </td><td>Central Bank of Argentina (AR-BCRA)</td></tr><tr><td> </td><td>Comision Nacional de Valores (AR-CNDV)</td></tr><tr><td> </td><td>Corte Suprema de Justicia de la Nación Argentina (AR-CSJN)</td></tr><tr><td> </td><td>Judiciary Branch (AR-CIJ)</td></tr><tr><td> </td><td>Ministerio de Justicia y Derechos Humanos (AR-MJDH)</td></tr><tr><td> </td><td>Ministerio Público Fiscal (AR-MPF)</td></tr><tr><td> </td><td>Policía Federal Argentina (AR-PFA)</td></tr><tr><td> </td><td>Registro Público de Personas y Entidades Vinculadas a Actos de Terrorismo y su Financiamiento (AR-REPET)</td></tr><tr><td> </td><td>Superintendencia de Seguros de la Nación (AR-SDSN)</td></tr><tr><td> </td><td>Unidad de Informacion Financiera (AR-UIF)</td></tr><tr><td>Armenia</td><td>Central Bank of Armenia (AM-CBA)</td></tr><tr><td> </td><td>Investigative Committee of the Republic of Armenia (AM-ICRA)</td></tr><tr><td> </td><td>National Security Service (AM-NSC)</td></tr><tr><td> </td><td>Police of the Republic of Armenia (AM-POLICE)</td></tr><tr><td> </td><td>Prosecutor General's Office of Armenia (AM-GENPRO)</td></tr><tr><td> </td><td>Special Investigation Service of Armenia (AM-SIS)</td></tr><tr><td>Aruba</td><td>Central Bank of Aruba (AW-CBA)</td></tr><tr><td>Australia</td><td>Australian Building and Construction Commission (AU-ABCC)</td></tr><tr><td> </td><td>Australian Competition and Consumer Commission (AU-ACCC)</td></tr><tr><td> </td><td>Australian Crime Commission (AU-ACC)</td></tr><tr><td> </td><td>Australian Customs and Border Protection Service (AU-CBPS)</td></tr><tr><td> </td><td>Australian Federal Police (AU-AFP)</td></tr><tr><td> </td><td>Australian Prudential Regulatory Authority (AU-PRA)</td></tr><tr><td> </td><td>Australian Securities &#x26; Investments Commission (AU-ASIC)</td></tr><tr><td> </td><td>Australian Stock Exchange (AU-SX)</td></tr><tr><td> </td><td>Australian Taxation Office (AU-ATO)</td></tr><tr><td> </td><td>Commonwealth Director of Public Prosecutions (AU - CDPP)</td></tr><tr><td> </td><td>Consumer Affairs Victoria (AU-CAV)</td></tr><tr><td> </td><td>Department of Agriculture, Water and the Environment (AU-DAWE)</td></tr><tr><td> </td><td>Fair Work Ombudsman (AU-FWO)</td></tr><tr><td> </td><td>Independent Broad-based Anti-corruption Commission (IBAC) (AU-IBAC)</td></tr><tr><td> </td><td>Independent Commission Against Corruption (Australia) (AU-ICAC)</td></tr><tr><td> </td><td>New South Wales Environment Protection Authority (AU-NSW-EPA)</td></tr><tr><td> </td><td>New South Wales Police (AU-NSWP)</td></tr><tr><td> </td><td>Office of the Registrar of Indigenous Corporations (AU ORIC)</td></tr><tr><td> </td><td>Transactions Reports and Analysis Centre (AU-TRAC)</td></tr><tr><td> </td><td>Victoria Crime Stoppers (AU-VICCS)</td></tr><tr><td> </td><td>Victorian Ombudsman (AU-VO)</td></tr><tr><td>Austria</td><td>Austrian Competition Authority (AT-ACA)</td></tr><tr><td> </td><td>Austrian Financial Markets Authority (AT-AFM)</td></tr><tr><td> </td><td>Bundeskriminalamt.BK (Austrian Federal Investigation Bureau) (AT-.BK)</td></tr><tr><td> </td><td>Federal Ministry for Finance Unlicensed Company List (AT-BMF)</td></tr><tr><td> </td><td>POLIZEI (Austrian Federal Police) (AT-POLIZEI)</td></tr><tr><td> </td><td>Supreme Court of Justice (AT-OGH)</td></tr><tr><td>Azerbaijan</td><td>Head Police Department of Baku City (AZ-HPDBC)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of the Republic of Azerbaijan (AZ-MIARA)</td></tr><tr><td> </td><td>Ministry of National Security (AZ-MNS)</td></tr><tr><td> </td><td>Office of the Prosecutor General (AZ-GENPRO)</td></tr><tr><td> </td><td>State Security Service (AZ-SSS)</td></tr><tr><td>Bahamas</td><td>Central Bank of the Bahamas (свов)</td></tr><tr><td> </td><td>Royal Bahamas Police Force (RBPF)</td></tr><tr><td> </td><td>Securities Commission of the Bahamas (BS-SCB)</td></tr><tr><td> </td><td>The Insurance Commission of the Bahamas (BS-ICB)</td></tr><tr><td>Bahrain</td><td>Ministry of Foreign Affairs-Terrorist List (BH-MFA-TL)</td></tr><tr><td>Bangladesh</td><td>Bangladesh Financial Intelligence Unit (BFIU) (BD-BFIU)</td></tr><tr><td> </td><td>Bangladesh Securities and Exchange Commission (BD-BANSEC)</td></tr><tr><td> </td><td>International Crimes Tribunal (BD-ICT)</td></tr><tr><td> </td><td>Rapid Action Battalion (BD-RAB)</td></tr><tr><td>Barbados</td><td>Royal Barbados Police Force (BB-RBPF)</td></tr><tr><td>Belarus</td><td>General Prosecutor's Office (BY-GPO)</td></tr><tr><td> </td><td>Investigative Committee of the Republic of Belarus (BY-ICRB)</td></tr><tr><td> </td><td>Ministry of Internal Affairs (BY-MIA)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Brest region (BY-MIABR)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Gomel region (BY-MIAGO)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Grodno region (BY-MIAGR)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Minsk region (BY-MIAMI)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Mogilev region (BY-MIAMO)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Vitebsk region (BY-MIAVI)</td></tr><tr><td> </td><td>State Security Agency of Belarus-Enforcement (BY-KGB-E)</td></tr><tr><td>Belgium</td><td>Banking Finance and Insurance Commission (BE-CBFA)</td></tr><tr><td> </td><td>Belgian Competition Authority (BE-BCA)</td></tr><tr><td> </td><td>Belgium's Most Wanted by FAST (BE-BMW)</td></tr><tr><td> </td><td>Belgium Federal Police (BE-POLFED)</td></tr><tr><td> </td><td>Financial Services and Markets Authority (BE-FSMA)</td></tr><tr><td> </td><td>Tax Deficient Jurisdictions (BE-TDJ)</td></tr><tr><td>Belize</td><td>Belize International Financial Services Commission (BZ-IFSC)</td></tr><tr><td> </td><td>Central Bank of Belize (Belize War)</td></tr><tr><td> </td><td>The Belize Police Department (BZ-BPD)</td></tr><tr><td>Benin</td><td>Public Procurement Regulatory Authority (BJ-ARMP)</td></tr><tr><td>Bermuda</td><td>Bermuda Court (BM-BMC)</td></tr><tr><td> </td><td>Bermuda Monetary Authority (BMA) (BM-BMA)</td></tr><tr><td> </td><td>National Anti-Money Laundering Committee (BM-NAMLC)</td></tr><tr><td>Bolivia</td><td>Defense Ministry (BO-DM)</td></tr><tr><td> </td><td>District Attorney's Office (BO-DA)</td></tr><tr><td> </td><td>Internal Revenue (BO-IR)</td></tr><tr><td>Bosnia and Herzegovina</td><td>Council of Competition Bosnia and Herzegovina (BA-CCBH)</td></tr><tr><td> </td><td>Federal Ministry of the Interior of Bosnia and Herzegovina (Sarajevo Canton) (BA-FMI-SC)</td></tr><tr><td> </td><td>Federal Police Directorate of Bosnia and Herzegovina (BA-FPDBE)</td></tr><tr><td> </td><td>Federal Prosecution of Bosnia and Herzegovina (BA-FP-BH)</td></tr><tr><td> </td><td>Ministry of the Interior of Western Herzegovina Canton (BA-MIWHC)</td></tr><tr><td> </td><td>State Investigation and Protection Agency (BA-SIPA)</td></tr><tr><td> </td><td>The Court of Bosnia and Herzegovina (BA-COURT)</td></tr><tr><td> </td><td>The Prosecutor's Office of B&#x26;H (BA-PROSEC)</td></tr><tr><td>Botswana</td><td>Directorate on Corruption and Economic Crime (BW-DCEC)</td></tr><tr><td> </td><td>Non-Bank Financial Institutions Regulatory Authority (BW-NBFIRA)</td></tr><tr><td>Brazil</td><td>Acordo de Leniência (BR-AL)</td></tr><tr><td> </td><td>Administrative Council for Economic Defense (BR-CADE)</td></tr><tr><td> </td><td>Banco Central Do Brasil (BR-BCB)</td></tr><tr><td> </td><td>Banco Central do Brasil Disqualified (BR-BC)</td></tr><tr><td> </td><td>Cadastro de Entidades Privadas Sem Fins Lucrativos Impedidas (BR-CEPIM)</td></tr><tr><td> </td><td>Cadastro de Expulsões da Administração Federal (BR-CEAF)</td></tr><tr><td> </td><td>Comissão de Valores Mobiliários Alertas de Suspensão (BR-CVM-ASP)</td></tr><tr><td> </td><td>Comissão de Valores Mobiliários do Brasil (BR-CVM)</td></tr><tr><td> </td><td>Conselho de Controle de Atividades Financeiras (BR-COAF)</td></tr><tr><td> </td><td>Controladoria-Geral da Uniao (BR-IGU)</td></tr><tr><td> </td><td>DENARC (Departamento de Investigações sobre Narcóticos) (BR-DENARC)</td></tr><tr><td> </td><td>Departamento de Polícia Federal do Brasil (BR-DPF)</td></tr><tr><td> </td><td>Departamento de Polícia Rodoviária Federal do Brasil (BR-DPRF)</td></tr><tr><td> </td><td>Federação Nacional dos Policiais Federais FENAPEF (Brazil) (BR-FENAPEF)</td></tr><tr><td> </td><td>Instituto Brasileiro do Meio Ambiente e dos Recursos Naturais Renováveis (BR-IBAMA)</td></tr><tr><td> </td><td>Ministério da Fazenda (BR-MDF)</td></tr><tr><td> </td><td>Ministério do Meio Ambiente (BR-MMA)</td></tr><tr><td> </td><td>Ministério do Trabalho e Emprego (M.T.E.) do Brasil (BR-MTE)</td></tr><tr><td> </td><td>Ministério Público de Alagoas (BR-MPDA)</td></tr><tr><td> </td><td>Ministério Público do Acre (BR-MPA)</td></tr><tr><td> </td><td>Ministério Público do Estado da Bahía (BR-MPEB)</td></tr><tr><td> </td><td>Ministério Público do Estado da Paraíba (BR-MPEDP)</td></tr><tr><td> </td><td>Ministério Público do Estado de Goiás (BR-MPEG)</td></tr><tr><td> </td><td>Ministério Público do Estado de Minas Gerais (BR-MPDEMG)</td></tr><tr><td> </td><td>Ministério Público do Estado de Rondônia (BR-MPER)</td></tr><tr><td> </td><td>Ministério Público do Estado de Roraima (BR-MPEDR)</td></tr><tr><td> </td><td>Ministério Público do Estado de Santa Catarina (BR-MP-SC)</td></tr><tr><td> </td><td>Ministério Público do Estado de São Paulo (BR-MPESP)</td></tr><tr><td> </td><td>Ministério Público do Estado do Amapá (BR-MPEA)</td></tr><tr><td> </td><td>Ministério Público do Estado do Amazonas (BR-MPE)</td></tr><tr><td> </td><td>Ministério Público do Estado do Ceará (BR-MPEC)</td></tr><tr><td> </td><td>Ministério Público do Estado do Distrito Federal (BR-MPEDF)</td></tr><tr><td> </td><td>Ministério Público do Estado do Espíritu Santo (BR-MPEES)</td></tr><tr><td> </td><td>Ministério Público do Estado do Maranhão (BR-MPEM)</td></tr><tr><td> </td><td>Ministério Público do Estado do Mato Grosso (BR-MPEMG)</td></tr><tr><td> </td><td>Ministério Público do Estado do Mato Grosso do Sul (BR-MPEMGS)</td></tr><tr><td> </td><td>Ministério Público do Estado do Pará (BR-MPEP)</td></tr><tr><td> </td><td>Ministério Público do Estado do Río de Janeiro (BR-MPERJ)</td></tr><tr><td> </td><td>Ministério Público do Estado do Rio Grande do Norte (BR-MPERGN)</td></tr><tr><td> </td><td>Ministério Público do Estado do Rio Grande do Sul (BR-MPERGS)</td></tr><tr><td> </td><td>Ministério Público Federal (BR-MPF)</td></tr><tr><td> </td><td>Ministério Público Federal na Paraíba (BR-MPF-PAR)</td></tr><tr><td> </td><td>Most Wanted (BR-MW)</td></tr><tr><td> </td><td>National Register of Penalized Entities (BR-CNEP)</td></tr><tr><td> </td><td>Portal DA Transparencia (BR-PDT)</td></tr><tr><td> </td><td>Procuradoria da República na Bahia (BR-MPF-Bay)</td></tr><tr><td> </td><td>Procuradoria da República no Ceará (BR-PRC)</td></tr><tr><td> </td><td>Procuradoria da República no Maranhão (BR-PRM)</td></tr><tr><td> </td><td>Procuradoria da República no Rio de Janeiro (BR-MPF-Rio)</td></tr><tr><td> </td><td>Procuradoria da Republica no Tocantins (BR-BR-PRT)</td></tr><tr><td> </td><td>Procuradoria Geral da República do Brasil (BR-MPF-PGR)</td></tr><tr><td> </td><td>Procuradoria Geral da República do Brasil no Acre (BR-MPF-PRA)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado da Bahía (BR-PGEB)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado da Paraíba (BR-PGEDP)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado de Alagoas (BR-PG)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado de Minas Gerais (BR-PGEMG)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado de Rondônia (BR-PGER)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado de Santa Catarina (BR-MPF-SC)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado de São Paulo (BR-PGESP)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Acre (BR-PGEA)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Amapá (BR-PGE)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Ceará (BR-PGEC)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Distrito Federal (BR-PGEDF)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Rio de Janeiro (BR-PGERJ)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Espíritu Santo (BR-PGEES)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Maranhão (BR-PGEM)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Mato Grosso do Sul (BR-PGEMGS)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Pará (BR-PGEP)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Paraná (BR-PGE-Par)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Rio Grande do Norte (BR-PGERGN)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado do Rio Grande do Sul (BR-PGERGS)</td></tr><tr><td> </td><td>Procuradoria Geral do Estado Goias (BR-MPF-GO)</td></tr><tr><td> </td><td>Public Ministry of Piaui (BR-MPPI)</td></tr><tr><td> </td><td>Public Ministry of Tocantins (BR-MPTO)</td></tr><tr><td> </td><td>Secretaria da Receita Federal do Brasil (BR-RFB)</td></tr><tr><td> </td><td>Superior Tribunal de Justiça do Brasil (BR-STJ)</td></tr><tr><td> </td><td>Supremo Tribunal de Contas da União CADICON (BR-CADICON)</td></tr><tr><td> </td><td>Supremo Tribunal Federal do Brasil (BR-STF)</td></tr><tr><td> </td><td>Tribunal de Contas da União do Brasil (BR-TCU)</td></tr><tr><td>Brunei Darussalam</td><td>Anti Corruption Bureau (BN-ACB)</td></tr><tr><td> </td><td>Brunei Darussalam Central Bank (BN-BDCB)</td></tr><tr><td> </td><td>Ministry of Finance and Economy (BN-MOFE)</td></tr><tr><td> </td><td>Monetary Authority of Brunei Darussalam (BN-AMBD)</td></tr><tr><td> </td><td>Royal Brunei Police Force Most Wanted List (BN-RBPF)</td></tr><tr><td> </td><td>State Judiciary Department of Brunei Darussalam (BN-SJD)</td></tr><tr><td>Bulgaria</td><td>Bulgaria Ministry of Finance (BG-MOF)</td></tr><tr><td> </td><td>Bulgarian National Bank (BG-BNB)</td></tr><tr><td> </td><td>Bulgarian State Agency for National Security (BG-SANS)</td></tr><tr><td> </td><td>Bulgarian Supreme Court of Cassation (BG-BSCC)</td></tr><tr><td> </td><td>Commission for Combating Corruption and Withdrawal of Criminal Assets (BG-CWCA)</td></tr><tr><td> </td><td>Commission for Protection of Competition (BG-CPC)</td></tr><tr><td> </td><td>Energy and Water Regulatory Commission (BG-EWRC)</td></tr><tr><td> </td><td>Financial Supervision Commission (BG-FSC)</td></tr><tr><td> </td><td>Ministry of Interior (BG-MI)</td></tr><tr><td> </td><td>National Revenue Agency (BG-NRA)</td></tr><tr><td> </td><td>Prosecutor of the Republic of Bulgaria (BG-PRB)</td></tr><tr><td>Burkina Faso</td><td>Public Procurement Regulatory Authority (BF-ARCOP)</td></tr><tr><td>Cambodia</td><td>Extraordinary Chambers Courts of Cambodia (ECCC)</td></tr><tr><td> </td><td>Royal Gendarmerie of Cambodia (KH-GRK)</td></tr><tr><td>Canada</td><td>Alberta Insurance Council (CA-AIC)</td></tr><tr><td> </td><td>Alberta Law Enforcement Response Teams (CA-ALERT)</td></tr><tr><td> </td><td>Alberta Securities Commission (CA-AB-SC)</td></tr><tr><td> </td><td>Autorite Des Marches Financiers (CA-AMF)</td></tr><tr><td> </td><td>Alcohol and Gaming Commission of Ontario (CA-AGCO)</td></tr><tr><td> </td><td>Border Services Agency (CA-BSA)</td></tr><tr><td> </td><td>British Columbia Financial Institutions Commission (CA-BC-FIC)</td></tr><tr><td> </td><td>British Columbia Securities Commission (CA-BC-SC)</td></tr><tr><td> </td><td>Bureau de Decision Revision Quebec (CA-BDRVM)</td></tr><tr><td> </td><td>Canada Revenue Agency (CARA)</td></tr><tr><td> </td><td>Canadian Law Society Disciplined Lawyers (CADL) (CA-CADL)</td></tr><tr><td> </td><td>Canadian Regulators Disciplinary Actions Database (CA-CIRDA)</td></tr><tr><td> </td><td>Canadian Securities Administrators (CA-SECADM)</td></tr><tr><td> </td><td>Chartered Professional Accountant (CPA) (CA-CPA)</td></tr><tr><td> </td><td>Combined Forces Special Enforcement Unit-British Columbia (CFSEU-BC) (CFSEUBC)</td></tr><tr><td> </td><td>Commission des valeurs mobilières du Québec (CA-QC-CVMQ)</td></tr><tr><td> </td><td>Competition Bureau (CA-CB)</td></tr><tr><td> </td><td>Competition Tribunal of Canada (CA-CTOC)</td></tr><tr><td> </td><td>Edmonton Police Service (CA-CA-EPS)</td></tr><tr><td> </td><td>Environmental and Wildlife Enforcement (CA-EWE)</td></tr><tr><td> </td><td>Federal Court of Canada (CA-FCOC)</td></tr><tr><td> </td><td>Financial Consumer Services Commission New Brunswick (CA-FCNB)</td></tr><tr><td> </td><td>Financial Services Commission of Ontario (CA-ON-FSCO)</td></tr><tr><td> </td><td>Financial Services Regulatory Authority of Ontario (CA-FSRAO)</td></tr><tr><td> </td><td>Financial Transaction Reports Analysis Center (CA-FTRAC)</td></tr><tr><td> </td><td>Insurance Council of British Columbia (CA-ICBC)</td></tr><tr><td> </td><td>Insurance Council of Manitoba (CA-ICM)</td></tr><tr><td> </td><td>Investment Dealers Association of Canada (CA-IDAC)</td></tr><tr><td> </td><td>Investment Industry Regulatory Organization of Canada (IIROC) (CA-IIROC)</td></tr><tr><td> </td><td>Les 10 criminels les plus recherchés du Québec (CA-QC-10CR)</td></tr><tr><td> </td><td>London Canada Police Service (CA-LCPS)</td></tr><tr><td> </td><td>Manitoba Securities Commission (CA-MB-SC)</td></tr><tr><td> </td><td>Ministry of Service Alberta (CA-MSA)</td></tr><tr><td> </td><td>Ministry of the Québec Environment Administrative Monetary Penalties (CA-MEFCC-A)</td></tr><tr><td> </td><td>Ministry of the Québec Environment Convictions (CA-MEFCC-C)</td></tr><tr><td> </td><td>Mutual Fund Dealers Association (CA-MFDA)</td></tr><tr><td> </td><td>New Brunswick Securities Commission (CA-NBSC)</td></tr><tr><td> </td><td>Niagara Regional Police Service (CA-CA-NRPS)</td></tr><tr><td> </td><td>Nova Scotia Securities Commission (CA-NS-SC)</td></tr><tr><td> </td><td>Ontario Ministry of the Environment (CA-OME)</td></tr><tr><td> </td><td>Ontario Provincial Police (CA-ON-OPP)</td></tr><tr><td> </td><td>Ontario Securities Commission (CA-ON-OSC)</td></tr><tr><td> </td><td>OSFI Enforcements (CA-OSFIEnf)</td></tr><tr><td> </td><td>Ottawa Police Service (CA-OPS)</td></tr><tr><td> </td><td>Peel Regional Police (CA-PRP)</td></tr><tr><td> </td><td>Permanent Anti-Corruption Unit (CA-UPAC)</td></tr><tr><td> </td><td>Public Works and Government Services Canada (CA-PWGSC)</td></tr><tr><td> </td><td>Quebec Chambre de la Securite Financiere (CA-QCSF)</td></tr><tr><td> </td><td>Quebec Enterprises Ineligible for Public Contracts (CA-RENA)</td></tr><tr><td> </td><td>RBC Investor &#x26; Treasury Services (CA-RBC-ITS)</td></tr><tr><td> </td><td>Régie du Bâtiment Québec Restricted, Suspended and Canceled Licenses (CA-RBQRL)</td></tr><tr><td> </td><td>Revenu Quebec (CA-CA-RQ)</td></tr><tr><td> </td><td>Royal Canadian Mounted Police (CA-RCMP)</td></tr><tr><td> </td><td>Saskatchewan Financial and Consumer Affairs Authority (CA-SK-FCAA)</td></tr><tr><td> </td><td>Saskatchewan Financial Services Commission (CA-SK-SC)</td></tr><tr><td> </td><td>Suppression of Terrorism List (CA-JLW-SOT)</td></tr><tr><td> </td><td>Surete du Quebec (CA-SDQ)</td></tr><tr><td> </td><td>Tax Court of Canada (CA-TCC)</td></tr><tr><td> </td><td>Toronto Police Service (CA-TPS)</td></tr><tr><td> </td><td>York Regional Police (CA-YRP)</td></tr><tr><td>Cape Verde</td><td>Bank of Cape Verde (CV-CB)</td></tr><tr><td> </td><td>Ministério Público de Cabo Verde (CV-MP)</td></tr><tr><td> </td><td>Polícia Nacional de Cabo Verde (CV-PNCV)</td></tr><tr><td>Cayman Islands</td><td>Anti Corruption Commission (KY-ACC)</td></tr><tr><td> </td><td>Cayman Islands Monetary Authority (KY-CIMA)</td></tr><tr><td>Chile</td><td>Chile Superintendencia de Valores y Seguros (CL-SVS)</td></tr><tr><td> </td><td>ChileCompra (CL-ChCompr)</td></tr><tr><td> </td><td>Fiscalia de Chile (CL-FC)</td></tr><tr><td> </td><td>National Economic Prosecutor (CL-FNE)</td></tr><tr><td> </td><td>Poder Judicial de la República de Chile (CL-CSJ)</td></tr><tr><td> </td><td>Policía de Investigaciones de Chile (CL-PIC)</td></tr><tr><td> </td><td>Servicio de Impuestos Internos de Chile (CL-SII)</td></tr><tr><td> </td><td>Superintendencia de Bancos e Instituciones Financieras de Chile (CL-SBIF)</td></tr><tr><td> </td><td>Superintendencia de Casinos de Juego (CL-SCJ)</td></tr><tr><td> </td><td>Superintendencia de Pensiones de Chile (CL-SPC)</td></tr><tr><td> </td><td>Unidad de Análisis Financiero (CL-UAF)</td></tr><tr><td>China</td><td>Anhui Provincial Court (CN-ANHUPC)</td></tr><tr><td> </td><td>Anhui Taxation Bureau (CN-AHTB)</td></tr><tr><td> </td><td>Banking Regulatory Commission (CN-BRC)</td></tr><tr><td> </td><td>Beijing Taxation Bureau (CN-BTB)</td></tr><tr><td> </td><td>Central Commission for Discipline Inspection (CN-CN-CCDI)</td></tr><tr><td> </td><td>Central Commission for Discipline Inspection-Top 100 Fugitives (CN-CCDI100)</td></tr><tr><td> </td><td>China Banking and Insurance Regulatory Commission (CN-CBIRC)</td></tr><tr><td> </td><td>China Food and Drug Administration (CN-FDA)</td></tr><tr><td> </td><td>China National Development and Reform Commission (CN-CNDRF)</td></tr><tr><td> </td><td>China Securities Regulatory Commission (CH-CSRC)</td></tr><tr><td> </td><td>Chongqing Taxation Bureau (CN-CQTB)</td></tr><tr><td> </td><td>Credit China (CN-CC)</td></tr><tr><td> </td><td>Customs General Administration (CN-CUSTOM)</td></tr><tr><td> </td><td>Fujian Taxation Bureau (CN-FJTB)</td></tr><tr><td> </td><td>Gansu Taxation Bureau (CN-GSTB)</td></tr><tr><td> </td><td>Guangdong Provincial Court (CN-GUANPC)</td></tr><tr><td> </td><td>Guangdong Provincial Public Security Bureau (CN-GUANSB)</td></tr><tr><td> </td><td>Guangdong Taxation Bureau (CN-GDTB)</td></tr><tr><td> </td><td>Guangxi Taxation Bureau (CN-GXTB)</td></tr><tr><td> </td><td>Guizhou Taxation Bureau (CN-GZTB)</td></tr><tr><td> </td><td>Hainan Taxation Bureau (CN-HITB)</td></tr><tr><td> </td><td>Hebei Province Public Security Bureau (CN-HPPSB)</td></tr><tr><td> </td><td>Heilongjiang Taxation Bureau (CN-HLTB)</td></tr><tr><td> </td><td>Henan Taxation Bureau (CN-HATB)</td></tr><tr><td> </td><td>Hubei Taxation Bureau (CN-HBTB)</td></tr><tr><td> </td><td>Inner Mongolia Taxation Bureau (CN-NMTB)</td></tr><tr><td> </td><td>Insurance Regulatory Commission (CN-IRC)</td></tr><tr><td> </td><td>Jiangsu Taxation Bureau (CN-JSTB)</td></tr><tr><td> </td><td>Jiangxi Taxation Bureau (CN-JXTB)</td></tr><tr><td> </td><td>Jiin Taxation Bureau (CN-JLTB)</td></tr><tr><td> </td><td>Jilin Provincial Public Security Department (CN-JILI)</td></tr><tr><td> </td><td>Liaoning Taxation Bureau (CN-LNTB)</td></tr><tr><td> </td><td>Ministry of Civil Affairs (CN-MCA)</td></tr><tr><td> </td><td>Ministry of Finance (CN-MOF)</td></tr><tr><td> </td><td>Ministry of Justice (CN-MOJ)</td></tr><tr><td> </td><td>Ministry of Public Security-Enforcement (CN-MPS-E)</td></tr><tr><td> </td><td>Ministry of Supervision (CN-MOS)</td></tr><tr><td> </td><td>National Bureau of Corruption Prevention of China (CN-NBCP)</td></tr><tr><td> </td><td>National Bureau of Statistics (CN-NBS)</td></tr><tr><td> </td><td>Ningxia High Court (CN-NHC)</td></tr><tr><td> </td><td>Ningxia Taxation Bureau (CN-NXTB)</td></tr><tr><td> </td><td>People's Procuratorate-Anhui (CN-PP-AH)</td></tr><tr><td> </td><td>People's Procuratorate-Beijing (CN-PP-BJ)</td></tr><tr><td> </td><td>People's Procuratorate-Bingtuan (CN-PP-JSBT)</td></tr><tr><td> </td><td>The People's Bank of China - Administrative Punishment (CN-PBC)</td></tr><tr><td> </td><td>Tianjin Taxation Bureau (CN-TJTB)</td></tr><tr><td> </td><td>Xinjiang Uygur Autonomous Region Public Security Department (CN-CN-XJGA)</td></tr><tr><td> </td><td>Zhejiang Taxation Bureau (CN-ZJTB)</td></tr><tr><td>Colombia</td><td>Autorregulador del Mercado de Valores (CO-AMV)</td></tr><tr><td> </td><td>Colombian Air force - Press Releases (CO-CA-PR)</td></tr><tr><td> </td><td>Contraloría General de la República de Colombia (CO-CGR)</td></tr><tr><td> </td><td>Corte Suprema de Justicia, República de Colombia (Supr Court)</td></tr><tr><td> </td><td>Departamento Administrativo de Seguridad (DAS), República de Colombia (CO-DAS)</td></tr><tr><td> </td><td>Dirección de Impuestos y Aduanas Nacionales (CO-DIAN)</td></tr><tr><td> </td><td>Ejército Nacional de Colombia (CO-EJNA)</td></tr><tr><td> </td><td>Fiscalía General de la Nación, República de Colombia (CO-FGDLN)</td></tr><tr><td> </td><td>Judicial Branch, Superior Council of the Judiciary (CO-JBSCJ)</td></tr><tr><td> </td><td>Ministerio de Ambiente y Desarrollo Sostenible (CO-MADS)</td></tr><tr><td> </td><td>Ministry of Mines and Energy (CO-MME)</td></tr><tr><td> </td><td>Policía Nacional de Colombia (CO-POL)</td></tr><tr><td> </td><td>Procuraduría General de la Nación, República de Colombia (CO-PRO-GE)</td></tr><tr><td> </td><td>Superintendence of Ports and Transport (CO-SUPTRAN)</td></tr><tr><td> </td><td>Superintendencia de Industria y Comercio (CO-SIC)</td></tr><tr><td> </td><td>Superintendencia de Industria y Comercio - Decisiones de Competencia (CO-SIC-DC)</td></tr><tr><td> </td><td>Superintendencia de Industria y Comercio - Sentencias Competencia Desleal (CO-SIC-SCD)</td></tr><tr><td> </td><td>Superintendencia de la Economia Solidaria (CO-SES)</td></tr><tr><td> </td><td>Superintendencia de Sociedades (CO-SDS)</td></tr><tr><td> </td><td>Superintendencia Financiera de Colombia (CO-SC)</td></tr><tr><td>Costa Rica</td><td>Judiciary Republic of Costa Rica (CR-JRCR)</td></tr><tr><td> </td><td>Ministerio Público de Costa Rica (CR-MP)</td></tr><tr><td> </td><td>National Police of Costa Rica (Fuerza Pública) (CR-POLICE)</td></tr><tr><td> </td><td>Superintendencia General de Entidades Financieras (CR-SUGEF)</td></tr><tr><td> </td><td>Superintendencia General de Valores de Costa Rica (SUGEVAL) (CR-SUGEVAL)</td></tr><tr><td>Cote d'Ivoire</td><td>Platform Fighting Cybercrime (CI-PLCC)</td></tr><tr><td>Croatia</td><td>Commission for the Resolution of Conflicts of Interest (HR-CRCI)</td></tr><tr><td> </td><td>Croatia Police (Ministry of Interior) (HR-CP)</td></tr><tr><td> </td><td>Croatia's State Prosecutor's Office (HR-CSPO)</td></tr><tr><td> </td><td>Croatian Competition Agency (HR-CCA)</td></tr><tr><td> </td><td>Croatian Financial Services Supervisory Agency (HR-CFSSA)</td></tr><tr><td> </td><td>Supreme Court of the Republic of Croatia (HR-SCRC)</td></tr><tr><td>Curacao</td><td>Central Bank of Curacao and Sint Maarten (CW-CBC-SM)</td></tr><tr><td>Cyprus</td><td>Central Bank of Cyprus (CY-CBC)</td></tr><tr><td> </td><td>Commission for the Protection of Competition (CY-COMPCO)</td></tr><tr><td> </td><td>Consumer Protection Service (CY-CPS)</td></tr><tr><td> </td><td>Cyprus Securities and Exchange Commission (CYSEC)</td></tr><tr><td> </td><td>Federal Police Most Wanted (CY-FPMW)</td></tr><tr><td> </td><td>National Betting Authority (CY-NBA)</td></tr><tr><td> </td><td>Supreme Court (CY-SC)</td></tr><tr><td>Czech Republic</td><td>Czech Environmental Inspectorate (CZ-CEI)</td></tr><tr><td> </td><td>Czech National Bank (CZ-CNB)</td></tr><tr><td> </td><td>Czech Office for the Protection of Competition (CZ-COPC)</td></tr><tr><td> </td><td>Czech Police - Most Wanted (CZ-MostW)</td></tr><tr><td> </td><td>Energy Regulatory Office - News (CZ-ERU)</td></tr><tr><td> </td><td>Financial Analytical Office (CZ-FAO-Enf)</td></tr><tr><td> </td><td>Ministry of Finance (CZ-MF)</td></tr><tr><td> </td><td>Ministry of Interior of the Czech Republic (CZ-MVCR)</td></tr><tr><td> </td><td>Most Wanted (CZ-MW)</td></tr><tr><td>Denmark</td><td>Finanstilsynet (Financial Supervisory Authority of Denmark) (DK-FSA-WA)</td></tr><tr><td> </td><td>The Danish Competition and Consumer Authority (DK-DCCA)</td></tr><tr><td> </td><td>The Danish Gambling Authority (DK - DGA)</td></tr><tr><td>Dominica</td><td>Financial Services Unit, Ministry of Finance &#x26; Planning of the Government of the Commonwealth of Dominica (CWDOM-FSU)</td></tr><tr><td>Dominican Republic</td><td>Dirección Central de Investigaciones Criminales (DO-DICRIM)</td></tr><tr><td> </td><td>Dirección Nacional de Control de Drogas (Dominican Republic) (DO-DNCD)</td></tr><tr><td> </td><td>Ministerio del Interior y Policía (DO-MIP)</td></tr><tr><td> </td><td>Poder Judicial (DO-SUPREMA)</td></tr><tr><td> </td><td>Policía Nacional Dominicana (DO-Policia)</td></tr><tr><td> </td><td>Procuraduría Fiscal del Distrito Nacional (DO-FISCAL)</td></tr><tr><td> </td><td>Procuraduría General de la República (DO-PGR)</td></tr><tr><td> </td><td>Superintendencia del Mercado de Valores de la República Dominicana (DO-SMV)</td></tr><tr><td>Ecuador</td><td>Fiscalia General del Estado de Ecuador (EC-FGEE)</td></tr><tr><td> </td><td>Policia Nacional del Ecuador (EC-PNE)</td></tr><tr><td> </td><td>Servicio Nacional de Aduana del Ecuador (EC-SNA)</td></tr><tr><td> </td><td>SRI-Ghost Companies (EC-SRIGC)</td></tr><tr><td> </td><td>Superintendencia de Bancos (EC-SB)</td></tr><tr><td> </td><td>Superintendencia de Compañias y Valores (EC-SCV)</td></tr><tr><td> </td><td>Superintendencia de Control del Poder de Mercado (EC-SCPM)</td></tr><tr><td>Egypt</td><td>Egyptian Financial Supervisory Authority (EG-FSA)</td></tr><tr><td> </td><td>Ministry of Interior (EG-MOI)</td></tr><tr><td> </td><td>Stock Exchange (EG-SE)</td></tr><tr><td>El Salvador</td><td>Fiscalía General de la República, El Salvador (SV-Fiscal)</td></tr><tr><td> </td><td>Ministerio de Gobernación, República de El Salvador (SV-GOV)</td></tr><tr><td> </td><td>Policía Nacional Civil de El Salvador (SV-PN)</td></tr><tr><td> </td><td>Sistema Electrónico de Compras Públicas de El Salvador (SV-SECP)</td></tr><tr><td> </td><td>Superintendencia del Sistema Financiero (SV-SSF)</td></tr><tr><td>Estonia</td><td>Estonia-Courts (EE-Court)</td></tr><tr><td> </td><td>Estonian Internal Security Service (EE-EISS)</td></tr><tr><td> </td><td>Estonian Police (EE-EP)</td></tr><tr><td> </td><td>Estonia State Gazette (EE-Gazette)</td></tr><tr><td> </td><td>Financial Intelligence Unit of Estonia (EE-FIU)</td></tr><tr><td> </td><td>Financial Supervision Authority of Estonia (EE-EE-FSAE)</td></tr><tr><td> </td><td>Prosecutor's Office (EE-PO)</td></tr><tr><td>Ethiopia</td><td>Ethiopia Revenues and Customs Authority (ET-ERCA)</td></tr><tr><td> </td><td>Federal Ethics and Anti-Corruption Commission of Ethiopia (ET-FEAC)</td></tr><tr><td> </td><td>National Intelligence and Security Services (ET-NISS)</td></tr><tr><td>Fiji</td><td>Fiji Financial Intelligence Unit (FJ-FinUnit)</td></tr><tr><td> </td><td>Fiji Independent Commission Against Corruption (FJ-ICAC)</td></tr><tr><td>Finland</td><td>Finanssivalvonta (Financial Supervisory Authority of Finland) (FIN-FSA)</td></tr><tr><td> </td><td>Prosecutor's Office (FI-PO)</td></tr><tr><td> </td><td>Supreme Court (FI-SC)</td></tr><tr><td>France</td><td>Anti-Corruption Agency (FR-ACA)</td></tr><tr><td> </td><td>Autorite de la Concurrence (FR-AC)</td></tr><tr><td> </td><td>Banque De France (FR-BF)</td></tr><tr><td> </td><td>Direction générale de la concurrence, de la consommation et de la répression des fraudes (DGCCRF) (FR-DGCCRF)</td></tr><tr><td> </td><td>Energy Regulatory Commission (FR-ERC)</td></tr><tr><td> </td><td>French Autorité des marchés financiers (FL-AMF)</td></tr><tr><td> </td><td>Judicial Public Interest Agreements List (FR-CJIP)</td></tr><tr><td> </td><td>MINEFE - Asset Freeze List (FR-ENF-MAF)</td></tr><tr><td> </td><td>Ministère de l'Economie - Regulation 2017/1509 (FR-MEF-NC)</td></tr><tr><td> </td><td>Ministre de l’Intérieur, Police nationale (France) (FR-POLICE)</td></tr><tr><td> </td><td>National Gambling Authority (FR-NGA)</td></tr><tr><td>French Polynesia</td><td>Polynesian Competition Authority (PF-PCA)</td></tr><tr><td>Georgia</td><td>Ministry of Internal Affairs of Georgia (GE-INTERI)</td></tr><tr><td> </td><td>Office of the Prosecutor General of Georgia (GE-POG)</td></tr><tr><td> </td><td>Otkhozoria - Tatunashvili List (GE-OTL)</td></tr><tr><td>Germany</td><td>Bafin Federal Financial Supervisory Authority (DE-BAFIN)</td></tr><tr><td> </td><td>Bundesanzeiger - courts' decisions (Germany) (DE-DE-BCD)</td></tr><tr><td> </td><td>Bundeskartellamt (Federal Cartel Office) (DE-FEDCO)</td></tr><tr><td> </td><td>Der Generalbundesanwalt beim Bundesgerichtshof (Attorney General of Germany) (DE-GBA)</td></tr><tr><td> </td><td>Der Polizeipräsident in Berlin (Germany) (Polizei BL)</td></tr><tr><td> </td><td>Federal Ministry for Finance - Unliscensed Company List (DE-BMF)</td></tr><tr><td> </td><td>Federal Ministry of the Interior (DE-FMI)</td></tr><tr><td> </td><td>Federal Office for Economic Affairs and Export Control (Bundesamt für Wirtschaft und Ausfuhrkontrolle)- BAFA (DE-BAFA)</td></tr><tr><td> </td><td>Federal Office for Protection of the Constitution (DE-FOPC)</td></tr><tr><td> </td><td>German Federal Criminal Police Office (DE-BKA)</td></tr><tr><td> </td><td>Hessische Polizei (Germany) (Polizei HS)</td></tr><tr><td> </td><td>Landeskriminalamt Thüringen (Germany) (Polizei TG)</td></tr><tr><td> </td><td>Landespolizei Schleswig-Holstein (Germany) (Polizei SH)</td></tr><tr><td> </td><td>Ministry of Justice-Federal Gazette (DE-GAZ)</td></tr><tr><td> </td><td>Polizei Baden Württemberg (Germany) (Polizei BW)</td></tr><tr><td> </td><td>Polizei Bayern (Germany) (PLZ Bayern)</td></tr><tr><td> </td><td>Polizei Brandenburg (Germany) (Polizei LB)</td></tr><tr><td> </td><td>Polizei Bremen (Germany) (Polizei BM)</td></tr><tr><td> </td><td>Polizei Hamburg (Germany) (Polizei HB)</td></tr><tr><td> </td><td>Polizei Mecklenburg Vorpommern (Germany) (Polizei MV)</td></tr><tr><td> </td><td>Polizei Niedersachsen (Germany) (Polizei NS)</td></tr><tr><td> </td><td>Polizei Nordrhein-Westfalen (Germany) (PolizeiNRW)</td></tr><tr><td> </td><td>Polizei Rheinland Pfalz (Germany) (Polizei RP)</td></tr><tr><td> </td><td>Polizei Saarland (Germany) (Polizei SL)</td></tr><tr><td> </td><td>Polizei Sachsen (Germany) (Polizei SC)</td></tr><tr><td> </td><td>Polizei Sachsen Anhalt (Germany) (Polizei SA)</td></tr><tr><td>Ghana</td><td>Bank of Ghana (GH-BOG)</td></tr><tr><td> </td><td>Economic and Organized Crime Office (GH-EOCO)</td></tr><tr><td> </td><td>Ghana Police Service (GH-GPS)</td></tr><tr><td> </td><td>Ghana Police Service - Most Wanted (GH-GPS-MW)</td></tr><tr><td> </td><td>Office of the Special Prosecutor (GH-OSP)</td></tr><tr><td> </td><td>Securities and Exchange Commission of Ghana (GH-SEC)</td></tr><tr><td>Gibraltar</td><td>Gibraltar Financial Services Commission (GI-FSC)</td></tr><tr><td>Greece</td><td>Hellenic Accounting and Auditing Standards Oversight Board (GR-HAASOB)</td></tr><tr><td> </td><td>Hellenic Competition Commission (GR-HCC)</td></tr><tr><td> </td><td>Hellenic Police (GR-HP)</td></tr><tr><td> </td><td>Hellenic Republic Capital Market Commission (GR-HRCMC)</td></tr><tr><td> </td><td>The Hellenic Gaming Commission (GR-HGC)</td></tr><tr><td> </td><td>The Hellenic Gaming Commission Blacklist (GR-HGCB)</td></tr><tr><td>Grenada</td><td>Royal Grenada Police Force (GD-RGPF)</td></tr><tr><td>Guatemala</td><td>Guatecompras - Sistema de Contrataciones y Adquisiciones (GT-GCSACGT)</td></tr><tr><td> </td><td>International Commission against Impunity in Guatemala (GT - CICIG)</td></tr><tr><td> </td><td>Ministerio de Gobernación de Guatemala (GT-MINGOB)</td></tr><tr><td> </td><td>Ministerio Público de Guatemala (GT-MinPub)</td></tr><tr><td> </td><td>Policia Nacional Civil de Guatemala (GT-PNC)</td></tr><tr><td> </td><td>La Dirección Normativa de Contrataciones y Adquisiciones del Estado (GT-DNCAE)</td></tr><tr><td>Guernsey</td><td>Guernsey Financial Investigation Unit (GG-FIU)</td></tr><tr><td> </td><td>Guernsey Financial Services Commission (Gsy-FSC)</td></tr><tr><td>Guyana</td><td>Customs Anti Narcotic Unit (GY-CANU)</td></tr><tr><td> </td><td>Guyana Police Force (GY-GPF)</td></tr><tr><td>Holy See</td><td>Financial Information Authority (VA-FIA)</td></tr><tr><td>Honduras</td><td>Ministerio Público de Honduras (HN-MPH)</td></tr><tr><td> </td><td>National Police of Honduras (HN-NPH)</td></tr><tr><td> </td><td>Poder Judicial de Honduras (HN-JBH)</td></tr><tr><td> </td><td>Secretaria de Defensa Nacional de Honduras (Ministry of Defense) (HN-MOD)</td></tr><tr><td>Hong Kong SAR</td><td>Anti-Deception Coordination Centre (HK-ADCC)</td></tr><tr><td> </td><td>Hong Kong Customs and Excise Department (HK-CED)</td></tr><tr><td> </td><td>Hong Kong Monetary Authority (HK-HKMA)</td></tr><tr><td> </td><td>Hong Kong Police (HK-POLICE)</td></tr><tr><td> </td><td>Independent Commission Against Corruption (Hong Kong) (HK-ICAC)</td></tr><tr><td> </td><td>Insider Dealing Tribunal (HK-IDT)</td></tr><tr><td> </td><td>Insurance Authority (HK-IA)</td></tr><tr><td> </td><td>Judiciary (HK-COURT)</td></tr><tr><td> </td><td>Market Misconduct Tribunal (HK-MMT)</td></tr><tr><td> </td><td>Securities and Futures Commission of Hong Kong (HK-HKSFC)</td></tr><tr><td> </td><td>Securities and Futures Exchanges (HK-EX)</td></tr><tr><td>Hungary</td><td>Competition Commission (HU-CC)</td></tr><tr><td> </td><td>Hungarian Courts (HU-HCourts)</td></tr><tr><td> </td><td>Hungarian Energy and Public Utility Regulatory Authority (HU-HEPURA)</td></tr><tr><td> </td><td>Hungarian Financial Supervisory Authority (PSZÁF) (HU-PSZÁF)</td></tr><tr><td> </td><td>Hungarian National Police (HU-POLICE)</td></tr><tr><td> </td><td>Supervisory Authority for Regulated Activities (HU-SZTFH)</td></tr><tr><td> </td><td>The Central Bank of Hungary (HU-CBH)</td></tr><tr><td>Iceland</td><td>Central Bank of Iceland (IS-ENF-CBI)</td></tr><tr><td> </td><td>Fjármálaeftirlitið, Financial Supervisory Authority, Iceland (FME) (IS-FME)</td></tr><tr><td>India</td><td>All India Council for Technical Education (IN-AICTE)</td></tr><tr><td> </td><td>Bombay Stock Exchange (IN-BSE)</td></tr><tr><td> </td><td>Central Board of Excise and Customs (IN-CBEC)</td></tr><tr><td> </td><td>Central Reserve Police Force (IN-CRPF)</td></tr><tr><td> </td><td>Central Vigilance Commission (IN-CVC)</td></tr><tr><td> </td><td>Competition Commission of India (IN-CCI)</td></tr><tr><td> </td><td>Delhi Police (IN-DP)</td></tr><tr><td> </td><td>Directorate of Revenue Intelligence (IN-DRI)</td></tr><tr><td> </td><td>Enforcement Directorate (IN-EDI)</td></tr><tr><td> </td><td>Financial Intelligence Unit - India (IN-FIU)</td></tr><tr><td> </td><td>Income Tax Department (IN-ITD)</td></tr><tr><td> </td><td>India Narcotics Control Bureau (IN-INCC)</td></tr><tr><td> </td><td>Indian Central Bureau of Investigation (IN-CBI)</td></tr><tr><td> </td><td>India Wildlife Crime Control Bureau (IN-IWCCB)</td></tr><tr><td> </td><td>Insurance Regulatory and Development Authority (IN-IRDA)</td></tr><tr><td> </td><td>Ministry of Corporate Affairs of India (IN-MCA)</td></tr><tr><td> </td><td>Ministry of Defense (IN-MOD)</td></tr><tr><td> </td><td>Ministry of Home Affairs - Gazette (IN-MHA-G)</td></tr><tr><td> </td><td>Ministry of Social Justice and Empowerment (IN-MOSJE)</td></tr><tr><td> </td><td>National Crime Records Bureau (IN-NCRB)</td></tr><tr><td> </td><td>National Financial Reporting Authority (IN-NFRA)</td></tr><tr><td> </td><td>National Housing Bank (IN-ENF-NHB)</td></tr><tr><td> </td><td>National Investigation Agency (IN-NIA)</td></tr><tr><td> </td><td>National Investigation Agency - Most Wanted (IN-NIAMW)</td></tr><tr><td> </td><td>National Securities Depository Limited (IN-NSDL)</td></tr><tr><td> </td><td>National Stock Exchange of India Ltd. (IN-NSE)</td></tr><tr><td> </td><td>Pension Fund Regulatory and Development Authority (IN-PFRDA)</td></tr><tr><td> </td><td>Press Information Bureau (IN-PIB)</td></tr><tr><td> </td><td>Reserve Bank of India (IN-RBI)</td></tr><tr><td> </td><td>Securities and Exchange Board of India (IN-SEBI)</td></tr><tr><td> </td><td>University Grants Commission (IN-UGC)</td></tr><tr><td>Indonesia</td><td>Attorney General of Indonesia (ID-AGIN)</td></tr><tr><td> </td><td>Bank Indonesia (ID-BI)</td></tr><tr><td> </td><td>Capital Market Supervisory Agency of Indonesia (ID-BAPEPAM)</td></tr><tr><td> </td><td>Commodity Futures Trading Regulatory Agency (Bappebti) (ID-CFTRA)</td></tr><tr><td> </td><td>Corruption Eradication Commission (ID-CEC)</td></tr><tr><td> </td><td>Criminal Investigation Police (ID-CIP)</td></tr><tr><td> </td><td>Deposit Insurance Agency (LPS) (ID-DIA)</td></tr><tr><td> </td><td>Indonesian Business Competition Supervisory Agency (KPPU) (ID-IBCS)</td></tr><tr><td> </td><td>Indonesian Financial Services Authority (ID-IFSA)</td></tr><tr><td> </td><td>Indonesian Financial Transaction Reports &#x26; Analysis Centre (ID-FTRAC)</td></tr><tr><td> </td><td>Institution for Procurement of Goods (ID-LKPP)</td></tr><tr><td> </td><td>National Police (ID-NP)</td></tr><tr><td> </td><td>Supreme Court (ID-SUPR)</td></tr><tr><td>International</td><td>Asian Development Bank (ASIAADB)</td></tr><tr><td> </td><td>Eastern Caribbean Supreme Court (EC-ECSC)</td></tr><tr><td> </td><td>Early Detection and Exclusion System List (EU-EDES)</td></tr><tr><td> </td><td>EDES Database (EU-EDES-DB)</td></tr><tr><td> </td><td>European Central Bank - Supervision (EU-ECB-S)</td></tr><tr><td> </td><td>European Commission (EU-EC)</td></tr><tr><td> </td><td>European Commission-High Risk Jurisdiction (EU-EC-HRJ)</td></tr><tr><td> </td><td>European Investment Bank - Exclusion List (EU-EIB-EL)</td></tr><tr><td> </td><td>European Securities and Markets Authority (EU-ESMA)</td></tr><tr><td> </td><td>European Union Banned Airlines (EU-BA)</td></tr><tr><td> </td><td>Europol (EU-Europol)</td></tr><tr><td> </td><td>Non-Cooperative Jurisdictions for Tax Purposes (EU-NCJTP)</td></tr><tr><td> </td><td>Nordic Investment Bank Debarments (EU-NIB-D)</td></tr><tr><td> </td><td>opean Bank for Reconstruction and Development (EBRD)</td></tr><tr><td> </td><td>ancial Action Task Force (FATF-GAFI)</td></tr><tr><td> </td><td>Asian Infrastructure Investment Bank (INT-AIIB)</td></tr><tr><td> </td><td>Inter-American Development Bank (IDB)</td></tr><tr><td> </td><td>International Criminal Court (INT-ICC)</td></tr><tr><td> </td><td>Interpol (Interpol)</td></tr><tr><td> </td><td>International Organization of Securities Commissions (INT-IOSCO)</td></tr><tr><td> </td><td>Mutual Legal Assistance (MLAT) (MLAT)</td></tr><tr><td> </td><td>United Nations Children and Armed Conflict - Persistent Violators (UN-CAC-PV)</td></tr><tr><td> </td><td>United Nations International Criminal Tribunal for the Former Yugoslavia (UN-ICTY)</td></tr><tr><td> </td><td>United Nations Development Programme (INT-UNDP)</td></tr><tr><td> </td><td>United Nations Office for Project Services (INT-UNOPS)</td></tr><tr><td> </td><td>World Bank Corporate Procurement Listing of Non-Responsible Vendors (WB-NRV)</td></tr><tr><td> </td><td>World Bank List of Debarred Firms (WBDL)</td></tr><tr><td>Iraq</td><td>Central Bank of Iraq-Fined Companies (IQ-CBI-FC)</td></tr><tr><td> </td><td>Central Bank of Iraq-Foreign Currency Ban List (IQ-CBI-FCB)</td></tr><tr><td> </td><td>Central Bank of Iraq-Punished Companies (IQ-CBI-PC)</td></tr><tr><td>Ireland</td><td>Central Bank of Ireland (IE-CBI)</td></tr><tr><td> </td><td>Enforcement Corporate Enforcement Authority (IE-ENF-CEA)</td></tr><tr><td> </td><td>Irish Financial Services Regulatory Authority (IE-IFSRA)</td></tr><tr><td> </td><td>Office of the Director of Corporate Enforcement (IE-ODCE)</td></tr><tr><td> </td><td>Revenue Commissioners - Irish Tax &#x26; Customs (IE-Revenue)</td></tr><tr><td>Isle of Man</td><td>Isle of Man Courts of Justice (IM-IMCOJ)</td></tr><tr><td> </td><td>Isle of Man Financial Supervision Commission (IoM-FSC)</td></tr><tr><td>Israel</td><td>Bank of Israel (IL-BI)</td></tr><tr><td> </td><td>Bank of Israel Sanctions Committee (IL-BOI-SC)</td></tr><tr><td> </td><td>Israel Antitrust Authority (IL-IAA)</td></tr><tr><td> </td><td>Israel Military Advocate General (IL-IMAG)</td></tr><tr><td> </td><td>Israel Ministry of Environmental Protection (IL-IMEP)</td></tr><tr><td> </td><td>Israel Police (IL-Police)</td></tr><tr><td> </td><td>Israel Securities Authority (ISA) (IL-ISA)</td></tr><tr><td> </td><td>Israel Security Agency (IL-Shabak)</td></tr><tr><td> </td><td>Israel Tax Authority (IL-ITA)</td></tr><tr><td> </td><td>Ministry of Communications (IL-MoC)</td></tr><tr><td> </td><td>Ministry of Foreign Affairs (IL-MFA)</td></tr><tr><td> </td><td>Ministry of Justice-Enforcement (IL-MJ-E)</td></tr><tr><td> </td><td>National Bureau for Counter Terror Financing (IL-NBCTF)</td></tr><tr><td>Italy</td><td>Autorita Garante Concorrenze Mercato (IT-AGCM)</td></tr><tr><td> </td><td>Banca d'Italia (IT-BDI)</td></tr><tr><td> </td><td>Guardia di Finanza (IT-GDF)</td></tr><tr><td> </td><td>Institute for Supervision of Insurance (IT - ISI)</td></tr><tr><td> </td><td>Italian Regulatory Authority for Energy, Networks and Environment (IT-ARERA)</td></tr><tr><td> </td><td>Italy Commissione Nazionale per le Società e la Borsa (IT-CONSOB)</td></tr><tr><td> </td><td>Ministero dell'Interno (Italy) (IT-Interno)</td></tr><tr><td> </td><td>Polizia di Stato (IT-PS)</td></tr><tr><td>Jamaica</td><td>Financial Investigations Division-News and Releases (JM-ENF-FID)</td></tr><tr><td> </td><td>Jamaica Constabulary Force (JM-JCF)</td></tr><tr><td> </td><td>Jamaica Financial Services Commission (Jam-FSC)</td></tr><tr><td> </td><td>Major Organised Crime and Anti Corruption Agency (JM-MOCA)</td></tr><tr><td>Japan</td><td>Aichi Prefectural Government (JP-ACPG)</td></tr><tr><td> </td><td>Aomori Prefectural Government (JP-AOPG)</td></tr><tr><td> </td><td>Chiba Prefectural Government (JP-CBPG)</td></tr><tr><td> </td><td>Chubu Regional Bureau of METI (JP-METI-CH)</td></tr><tr><td> </td><td>Chugoku Local Finance Bureau (JP-CULFB)</td></tr><tr><td> </td><td>Chugoku Regional Bureau of METI (JP-METI-CG)</td></tr><tr><td> </td><td>Consumer Affairs Agency (JP-CAA)</td></tr><tr><td> </td><td>Ehime Prefectural Government (JP-EHPG)</td></tr><tr><td> </td><td>Financial Services Agency Moneylenders (JP-FSA-ML)</td></tr><tr><td> </td><td>Financial Services Agency Unauthorized Companies (JP-FSA-UC)</td></tr><tr><td> </td><td>Fukui Prefectural Government (JP-YKPG)</td></tr><tr><td> </td><td>Fukuoka Local Finance Bureau (JP-FKLFB)</td></tr><tr><td> </td><td>Fukuoka Prefecture Police (JP-FPP)</td></tr><tr><td> </td><td>Fukuoka Prefecture (JP-FP)</td></tr><tr><td> </td><td>Fukushima Prefectural Government (JP-FUPG)</td></tr><tr><td> </td><td>Gifu Prefectural Government (JP-GFPG)</td></tr><tr><td> </td><td>Gunma Prefectural Government (JP-GMPG)</td></tr><tr><td> </td><td>Hiroshima Prefectural Government (JP-HSPG)</td></tr><tr><td> </td><td>Hokkaido Local Finance Bureau (JP-HKLFB)</td></tr><tr><td> </td><td>Hokkaido Prefectural Government (JP-HKPG)</td></tr><tr><td> </td><td>Hokkaido Prefecture Police (JP-HPP)</td></tr><tr><td> </td><td>Hokkaido Regional Bureau of METI (JP-METI-HO)</td></tr><tr><td> </td><td>Hokuriku Local Finance Bureau (JP-HOLFB)</td></tr><tr><td> </td><td>Hyogo Prefectural Government (JP-HYPG)</td></tr><tr><td> </td><td>Ibaraki Prefectural Government (JP-IBPG)</td></tr><tr><td> </td><td>Iwate Prefectural Government (JP-IWPG)</td></tr><tr><td> </td><td>Japan External Trade Organization (JP-JETRO)</td></tr><tr><td> </td><td>Japan Fair Trade Commission (JP-FTC)</td></tr><tr><td> </td><td>Japan Osaka Prefectural Government (JP-OPG)</td></tr><tr><td> </td><td>Japanese Financial Services Agency (JP-FSA)</td></tr><tr><td> </td><td>Japanese National Police Agency (JP-NPA)</td></tr><tr><td> </td><td>Kagawa Prefectural Government (JP-KGPG)</td></tr><tr><td> </td><td>Kagoshima Prefectural Government (JP-KSPG)</td></tr><tr><td> </td><td>Kanagawa Prefectural Government (JP-KNPG)</td></tr><tr><td> </td><td>Kansai Regional Bureau of METI (JP-METI-KN)</td></tr><tr><td> </td><td>Kanto Local Finance Bureau (JP-KLFB)</td></tr><tr><td> </td><td>Kanto Regional Bureau of METI (JP-METI-KA)</td></tr><tr><td> </td><td>Kinki Local Finance Bureau (JP-KNLFB)</td></tr><tr><td> </td><td>Kochi Prefectural Government (JP-KOPG)</td></tr><tr><td> </td><td>Kumamoto Prefectural Government (JP-KMPG)</td></tr><tr><td> </td><td>Kyoto Prefectural Government (JP-KYPG)</td></tr><tr><td> </td><td>Kyushu Local Finance Bureau (JP-KULFB)</td></tr><tr><td> </td><td>Kyushu Regional Bureau of METI (JP-METI-KY)</td></tr><tr><td> </td><td>Ministry of Defense (JP-MOD)</td></tr><tr><td> </td><td>Ministry of Economy, Trade and Industry (JP-METI)</td></tr><tr><td> </td><td>Ministry of Economy, Trade and Industry - Import Export Ban (JP-METI-IE)</td></tr><tr><td> </td><td>Ministry of Finance - Enforcement (JP-MOF-E)</td></tr><tr><td> </td><td>Ministry of Land, Infrastructure and Transport (JP-MLIT)</td></tr><tr><td> </td><td>Miyagi Prefectural Government (JP-MGPG)</td></tr><tr><td> </td><td>Miyazaki Prefectural Government (JP-MZPG)</td></tr><tr><td> </td><td>Nagano Prefectural Government (JP-NAPG)</td></tr><tr><td> </td><td>Nagasaki Prefectural Government (JP-NGPG)</td></tr><tr><td> </td><td>Nagoya Stock Exchange (JP-NSE)</td></tr><tr><td> </td><td>Nara Prefectural Government (JP-NRPG)</td></tr><tr><td> </td><td>National Public Safety Commission (JP-NPSC)</td></tr><tr><td> </td><td>Niigata Prefectural Government (JP-NIPG)</td></tr><tr><td> </td><td>Oita Prefectural Government (JP-OTPG)</td></tr><tr><td> </td><td>Okayama Prefectural Government (JP-OMPG)</td></tr><tr><td> </td><td>Okinawa Prefectural Government (JP-OWPG)</td></tr><tr><td> </td><td>Osaka Exchange (JP-OSE)</td></tr><tr><td> </td><td>Public Security Intelligence Agency (JP-PSIA)</td></tr><tr><td> </td><td>Saga Prefectural Government (JP-SGPG)</td></tr><tr><td> </td><td>Saitama Prefectural Government (JP-STPG)</td></tr><tr><td> </td><td>Securities and Exchange Surveillance Commission of Japan (JP-SESC)</td></tr><tr><td> </td><td>Shiga Prefectural Government (JP-SHPG)</td></tr><tr><td> </td><td>Shikoku Local Finance Bureau (JP-SILFB)</td></tr><tr><td> </td><td>Shikoku Regional Bureau of METI (JP-METI-SH)</td></tr><tr><td> </td><td>Shizuoka Prefectural Government (JP-SZPG)</td></tr><tr><td> </td><td>Tohoku Local Finance Bureau (JP-THLFB)</td></tr><tr><td> </td><td>Tohoku Regional Bureau of METI (JP-METI-TO)</td></tr><tr><td> </td><td>Tokai Local Finance Bureau (JP-TKLFB)</td></tr><tr><td> </td><td>Tokyo Metropolitan Government (JP-TKMG)</td></tr><tr><td> </td><td>Tokyo Stock Exchange (JP-TSX)</td></tr><tr><td> </td><td>Wakayama Prefectural Government (JP-WKPG)</td></tr><tr><td> </td><td>Yamagata Prefecture Government (JP-YAPG)</td></tr><tr><td> </td><td>Yamaguchi Prefectural Government (JP-YMGPG)</td></tr><tr><td> </td><td>Yamanashi Prefectural Government (JP-YMGPG)</td></tr><tr><td>Jersey</td><td>Courts (JE-CO)</td></tr><tr><td> </td><td>Jersey Financial Services Commission (Jers-FSC)</td></tr><tr><td> </td><td>Police (Jers-Pol)</td></tr><tr><td>Kazakhstan</td><td>Agency for Civil Service Affairs and Anti-Corruption (KZ-ACSA-AC)</td></tr><tr><td> </td><td>Agency on Regulation of Financial Markets and Organizations (KZ-ARSFM)</td></tr><tr><td> </td><td>Department of Internal Affairs of Akmola region (KZ-AKMOLA)</td></tr><tr><td> </td><td>Department of Internal Affairs of Aktobe region (KZ-AKTOBE)</td></tr><tr><td> </td><td>Department of Internal Affairs of Almaty (KZ-ALMA)</td></tr><tr><td> </td><td>Department of Internal Affairs of Almaty region (KZ-ALMATY)</td></tr><tr><td> </td><td>Department of Internal Affairs of Astana (KZ-ASTANA)</td></tr><tr><td> </td><td>Department of Internal Affairs of Atyrau region (KZ-ATYRAU)</td></tr><tr><td> </td><td>Department of Internal Affairs of Jambyl region (KZ-JAMBYL)</td></tr><tr><td> </td><td>Department of Internal Affairs of Karaganda region (KZ-KARAGA)</td></tr><tr><td> </td><td>Department of Internal Affairs of Kostanay region (KZ-KOSTNY)</td></tr><tr><td> </td><td>Department of Internal Affairs of Kyzylorda region (KZ-KYZYL)</td></tr><tr><td> </td><td>Department of Internal Affairs of Mangistau region (KZ-MANGIS)</td></tr><tr><td> </td><td>Department of Internal Affairs of North Kazakhstan region (KZ-NORTH)</td></tr><tr><td> </td><td>Department of Internal Affairs of Pavlodar region (KZ-PAVLO)</td></tr><tr><td> </td><td>Department of Internal Affairs of South-Kazakhstan region (KZ-SOUTH)</td></tr><tr><td> </td><td>Department of Internal Affairs of West Kazakhstan region (KZ-WEST)</td></tr><tr><td> </td><td>Financial Monitoring Agency (KZ-FMA)</td></tr><tr><td> </td><td>Financial Police of Kazakhstan (KZ-FINPOL)</td></tr><tr><td> </td><td>Financial Supervision of the National Bank of Kazakhstan (KZ-FSNB)</td></tr><tr><td> </td><td>General Prosecutor's Office (KZ-GENPRO)</td></tr><tr><td> </td><td>Ministry of Internal Affairs (KZ-MOIA)</td></tr><tr><td> </td><td>The Committee on Legal Statistics and Special Records of the General Prosecutor of the Republic of Kazakhstan (KZ-CLSSR)</td></tr><tr><td>Kenya</td><td>Capital Markets Authority (KE-CMA)</td></tr><tr><td> </td><td>Central Bank of Kenya (KE-CBK)</td></tr><tr><td> </td><td>Competition Authority of Kenya (KE-CAK)</td></tr><tr><td> </td><td>Kenya Anti Corruption Commission (KACC) (KE-KACC)</td></tr><tr><td> </td><td>Kenya Gazette Prevention of Terrorism Act (KE-KG-POTA)</td></tr><tr><td> </td><td>The Office of the Director of Public Prosecutions (KE-ODPP)</td></tr><tr><td>Korea</td><td>Financial Supervisory Service (KR-FSS)</td></tr><tr><td>Korea (Republic Of)</td><td>Financial Services Commission of Korea (KR-FSCKO)</td></tr><tr><td> </td><td>Korean National Police Agency (KNPA)</td></tr><tr><td> </td><td>Public Procurement Service (KR-PPS)</td></tr><tr><td>Kosovo</td><td>Central Bank of Kosovo (KS-BQK)</td></tr><tr><td> </td><td>State Prosecutor of the Republic of Kosovo (KS-SPRK)</td></tr><tr><td> </td><td>Kosovo Competition Authority (KS-KCA)</td></tr><tr><td> </td><td>Kosovo Police (XK-KP)</td></tr><tr><td> </td><td>Procurement Review Body (XK-PRB)</td></tr><tr><td>Kuwait</td><td>Capital Markets Authority (KW-CMA)</td></tr><tr><td>Kyrgyzstan</td><td>Financial Police (KG-FP)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Kyrgyzstan (KG-MIAK)</td></tr><tr><td> </td><td>National Bank of the Kyrgyz Republic (KG-NBKR)</td></tr><tr><td> </td><td>Prosecutor General of Kyrgyzskoy Republic (KG-PG)</td></tr><tr><td> </td><td>Service of the Execution of Sentence (KG-SES)</td></tr><tr><td> </td><td>State Committee for National Security (KG-SCNS)</td></tr><tr><td> </td><td>State Service for Combating Economic Crimes under the Government of Kyrgyz Republic (KG-SSCEC)</td></tr><tr><td> </td><td>The Supreme Court of Kyrgyzstan (KG-SC)</td></tr><tr><td>Latvia</td><td>Central Bank of Latvia (LV-CBL)</td></tr><tr><td> </td><td>Competition Council (LV-CC)</td></tr><tr><td> </td><td>Corruption Prevention and Combating Bureau (LV-KNAB)</td></tr><tr><td> </td><td>Financial and Capital Market Commission (LV-FCMC)</td></tr><tr><td> </td><td>General Prosecutors Office (LV-GPS)</td></tr><tr><td> </td><td>Latvia State Police (LV-SP)</td></tr><tr><td> </td><td>Security Police (LV-SecPol)</td></tr><tr><td> </td><td>State Border Guard (LV-SBG)</td></tr><tr><td> </td><td>State Revenue Service (LV-VID)</td></tr><tr><td> </td><td>Supreme Court (LV-SCOURT)</td></tr><tr><td>Lebanon</td><td>Internal Security Forces - Terrorist List (LB-ISF-TTF)</td></tr><tr><td> </td><td>Special Tribunal for Lebanon (LB-STN)</td></tr><tr><td>Libya</td><td>Central Bank of Libya (LY-CBL)</td></tr><tr><td>Liechtenstein</td><td>Finanzmarktaufsicht (LI-FMA)</td></tr><tr><td> </td><td>Liechtenstein National Police (LI-NP)</td></tr><tr><td>Lithuania</td><td>Central Bank of the Republic of Lithuania (LT-CBRL)</td></tr><tr><td> </td><td>Competition Council of Lithuania (LT-CCL)</td></tr><tr><td> </td><td>Customs of the Republic of Lithuania (LT-CRL)</td></tr><tr><td> </td><td>Financial Crime Investigation Service (LT-FCIS)</td></tr><tr><td> </td><td>Gaming Control Authority (LT-GCA)</td></tr><tr><td> </td><td>Lithuania General Prosecutor's Office (LT-LGPO)</td></tr><tr><td> </td><td>Lithuanian Courts (LT-CTS)</td></tr><tr><td> </td><td>Lithuanian Criminal Police Bureau (LT-LCPB)</td></tr><tr><td> </td><td>National Energy Regulatory Council (LT-NERC)</td></tr><tr><td> </td><td>Police department under the Interior Ministry (LT-PDIM)</td></tr><tr><td> </td><td>Special Investigation Service of the Republic of Lithuania (LT-SISRL)</td></tr><tr><td> </td><td>State Border Guard Service (LT-SBGS)</td></tr><tr><td> </td><td>State Security Department (LT-SSD)</td></tr><tr><td> </td><td>Supreme Court (LT-SC)</td></tr><tr><td>Luxembourg</td><td>Commission de Surveillance du Secteur Financial Anti Terrorist Financing Ministerial Regulations (LU-CSSFMR)</td></tr><tr><td> </td><td>Commission de Surveillance du Secteur Financier Luxembourg (Lux-CSSF)</td></tr><tr><td> </td><td>Office of the Insurance Commissioner (LU-OIC)</td></tr><tr><td>Macao SAR</td><td>Commission Against Corruption (MO-CCAC)</td></tr><tr><td> </td><td>Macao Asset Freezing Coordination Commission (MO-MAFCC)</td></tr><tr><td> </td><td>Macao Court (MO-MC)</td></tr><tr><td> </td><td>Macau Customs (MO-CUSTOM)</td></tr><tr><td> </td><td>Public Prosecutions Office (MO-PUBPRO)</td></tr><tr><td>Macedonia</td><td>Macedonian Commission for Protection of Competition (MK-MCPC)</td></tr><tr><td> </td><td>Macedonian Financial Police (MK-MFP)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of the Republic of Macedonia (MK-MIA)</td></tr><tr><td> </td><td>Primary Court Skopje (MK-PCS)</td></tr><tr><td> </td><td>Public Prosecutor's Office (MK-PPO)</td></tr><tr><td> </td><td>Securities and Exchange Commission of Macedonia (MK-SEC)</td></tr><tr><td> </td><td>Specialized Public Prosecutor's Office (MK-SPO)</td></tr><tr><td>Malawi</td><td>Malawi Anti Corruption Bureau (MW-ACB)</td></tr><tr><td> </td><td>Reserve Bank of Malawi - Press Releases (MW-RBM)</td></tr><tr><td>Malaysia</td><td>Anti-Corruption Commission (MY-ACC)</td></tr><tr><td> </td><td>Attorney General’s Chambers – Enforcement (MY-AGCEnf)</td></tr><tr><td> </td><td>Bank Negara Malaysia (MY-BNM)</td></tr><tr><td> </td><td>Bursa Malaysia (MY-KLE)</td></tr><tr><td> </td><td>Courts of Malaysia (Judgments list) (MY-CM)</td></tr><tr><td> </td><td>Federation of Investment Managers Malaysia (MY-FIMM)</td></tr><tr><td> </td><td>Immigration Department of Malaysia - Media Release (MY-IMI)</td></tr><tr><td> </td><td>Inland Revenue Board of Malaysia (MY-IRBM)</td></tr><tr><td> </td><td>Labuan Financial Services Authority (MY-Labuan)</td></tr><tr><td> </td><td>Malaysia Competition Commission (MY-MYCC)</td></tr><tr><td> </td><td>Malaysia Securities Commission (MY-SC)</td></tr><tr><td> </td><td>Ministry of Domestic Trade and Consumer Affairs - Offenders (MY-MDTCA)</td></tr><tr><td> </td><td>Ministry of International Trade and Industry (MY-MITI)</td></tr><tr><td> </td><td>Ministry of Tourism and Culture - Announcement (MY-MTC)</td></tr><tr><td> </td><td>Perbadanan Insurans Deposit Malaysia (MY-PIDM)</td></tr><tr><td> </td><td>Royal Malaysian Police Force (MY-RPOLICE)</td></tr><tr><td> </td><td>The Companies Commission of Malaysia (MY-CCM)</td></tr><tr><td>Maldives</td><td>Capital Market Development Authority (MV-CMDA)</td></tr><tr><td> </td><td>Maldives Inland Revenue Authority (MV-MIRA)</td></tr><tr><td> </td><td>Maldives Police Service (MV-MPS)</td></tr><tr><td>Malta</td><td>Ministry for Justice, Culture and Local Government (MT-JCLG)</td></tr><tr><td> </td><td>Asset Recovery Bureau (MT-AR)</td></tr><tr><td> </td><td>Central Bank of Malta (MT-CB)</td></tr><tr><td> </td><td>Financial Intelligence Analysis Unit (MT-FIAU)</td></tr><tr><td> </td><td>Malta Financial Services Authority (MA-FSA)</td></tr><tr><td> </td><td>Malta Gaming Authority (MT-MGA)</td></tr><tr><td> </td><td>Malta Ministry for Justice and Home Affairs (MT-LEGAL)</td></tr><tr><td>Mauritius</td><td>Independent Commission Against Corruption (MU-ICAC)</td></tr><tr><td> </td><td>Mauritius Courts (MU-MC)</td></tr><tr><td> </td><td>Mauritius Financial Services Commission (MU-MAUFSC)</td></tr><tr><td>Mexico</td><td>Catálogo de Datos Abiertos (MX-CDA)</td></tr><tr><td> </td><td>Central Bank of Mexico (MX-BANXICO)</td></tr><tr><td> </td><td>Comisión Nacional Bancaria y de Valores de Mexico (MX-CNBV)</td></tr><tr><td> </td><td>Comisión Nacional de Seguridad (MX-CNS)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a agentes de seguros y/o fianzas persona física (MX-CNSFSPF)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a agentes de seguros y/o fianzas persona moral (MX-CNSFSPM)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a instituciones de fianzas (MX-CNSFSIF)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a instituciones de seguros (MX-CNSFSIS)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a intermediarios de reaseguro (MX-CNSFSIR)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a oficinas de representación (MX-CNSFSOR)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a otros sujetos supervisados (MX-CNSFSSS)</td></tr><tr><td> </td><td>Comision Nacional de Seguros Y Fianzas - Sanciones a personas que intermediaron sin autorización (MX-CNSFSIA)</td></tr><tr><td> </td><td>CONDUSEF (MX-CONDUSE)</td></tr><tr><td> </td><td>Diario Oficial de la Federación (MX-DOF)</td></tr><tr><td> </td><td>Directorio de Proveedores y Contratistas Sancionados (MX-DPCS)</td></tr><tr><td> </td><td>Federal Commission of Economic Competition (COFECE) (MX-COFECE)</td></tr><tr><td> </td><td>Fiscalía General del Estado (MX-FGE)</td></tr><tr><td> </td><td>Judiciary Branch of Mexico (MX - CJF)</td></tr><tr><td> </td><td>Presidencia de la Républica (MX-Pres)</td></tr><tr><td> </td><td>Procuradoría General de Justicia (MX-PGJ)</td></tr><tr><td> </td><td>Procuraduría General de la República de Mexico (MX-PGRMX)</td></tr><tr><td> </td><td>Secretaría de Gobernación (MX-Sec-Gob)</td></tr><tr><td> </td><td>Secretaría De Hacienda Y Crédito Público (MX-SHCP)</td></tr><tr><td> </td><td>Secretaria de la Defensa Nacional (MX-SDN)</td></tr><tr><td> </td><td>Secretaria de Marina (MX-SDM)</td></tr><tr><td> </td><td>Secretaría de Seguridad Pública de Mexico (MX-SSP)</td></tr><tr><td> </td><td>Servicio de Administración Tributaria (MX-SAT)</td></tr><tr><td> </td><td>Servicio de Administración Tributaria - 69B Presuntos (MX-SAT69BP)</td></tr><tr><td>Moldova</td><td>Center for Combating Economic Crimes and Corruption (ML-CCECC)</td></tr><tr><td> </td><td>General Police Inspectorate (MD-GPI)</td></tr><tr><td> </td><td>Ministry of Internal Affairs (ML-MIA)</td></tr><tr><td> </td><td>Moldovan Department of Penitentiary Institutions (MD-MDPI)</td></tr><tr><td> </td><td>Office of the Prosecutor General of the Republic of Moldova (MD-PROGEN)</td></tr><tr><td> </td><td>Police Department of Gagauzia (MD-PDG)</td></tr><tr><td> </td><td>Supreme Court of Justice (MD-CSJ)</td></tr><tr><td>Mongolia</td><td>The Independent Authority Against Corruption of Mongolia (MN-IAAC)</td></tr><tr><td>Montenegro</td><td>Agency for Prevention of Corruption (ME-APC)</td></tr><tr><td> </td><td>Agency for Protection of Competition of Montenegro (ME-AFPC)</td></tr><tr><td> </td><td>Capital Market Authority (ME-CMA)</td></tr><tr><td> </td><td>Police Directorate of Montenegro (ME-PDM)</td></tr><tr><td> </td><td>Prosecutor's Office of Montenegro (ME-PROS)</td></tr><tr><td>Morocco</td><td>Moroccan Financial Markets Authority (MA-AMMC)</td></tr><tr><td>Mozambique</td><td>Banco de Moçambique (MZ-BDM)</td></tr><tr><td>Myanmar</td><td>Anti-Corruption Commission (MM-ACC)</td></tr><tr><td> </td><td>Myanmar Financial Intelligence Unit (MFIU) (MM-MFIU)</td></tr><tr><td> </td><td>Myanmar Police Force (MM-MPF)</td></tr><tr><td> </td><td>Myanmar President Office (MM-MPO)</td></tr><tr><td> </td><td>State Counsellor Office (MM-SCO)</td></tr><tr><td>Namibia</td><td>Anti Corruption Commission (NA-ACC)</td></tr><tr><td> </td><td>Bank of Namibia (NA-BON)</td></tr><tr><td> </td><td>Namibia Financial Institutions Supervisory Authority (NA-NAMFISA)</td></tr><tr><td> </td><td>Namibia Supreme Court (NA-SC)</td></tr><tr><td>Nepal</td><td>Commission for the Investigation of Abuse of Authority (NP-CIAA)</td></tr><tr><td> </td><td>Department of Foreign Employment (NP-DOFE)</td></tr><tr><td> </td><td>Narcotics Control Bureau (NP-NCB)</td></tr><tr><td> </td><td>Nepal Police Most Wanted List (NP-NPMWL)</td></tr><tr><td> </td><td>Nepal Rastra Bank (NP-NRB)</td></tr><tr><td> </td><td>Public Procurement Monitoring Office (NP-PPMO)</td></tr><tr><td> </td><td>Securities Board of Nepal (NP-SEBON)</td></tr><tr><td>Netherlands</td><td>De Nederlandsche Bank (DNB) (NL-DNB)</td></tr><tr><td> </td><td>Gaming Authority of the Netherlands (NL-GAN)</td></tr><tr><td> </td><td>Netherlands Authority for Consumers and Markets (NL-ACM)</td></tr><tr><td> </td><td>Netherlands Authority for the Financial Markets (NL-AFM)</td></tr><tr><td> </td><td>Netherlands Courts (NL-Courts)</td></tr><tr><td> </td><td>Netherlands Financial Intelligence Unit (NL-FIU)</td></tr><tr><td> </td><td>Politie (Netherlands Police) (NL-POLITIE)</td></tr><tr><td> </td><td>Public Prosecution Service (NL-PPS)</td></tr><tr><td> </td><td>Supreme Court of the Netherlands (NL-COURT)</td></tr><tr><td>Netherlands Antilles</td><td>Central Bank of the Netherlands Antilles (AN-BNA)</td></tr><tr><td>New Caledonia</td><td>New Caledonian Competition Authority (NC-ACNC)</td></tr><tr><td>New Zealand</td><td>Commerce Commission (NZ-CC)</td></tr><tr><td> </td><td>Department of Internal Affairs (NZ-DIA)</td></tr><tr><td> </td><td>Inland Revenue of New Zealand (NZ-INREV)</td></tr><tr><td> </td><td>New Zealand Companies Office (NZ-NZCO)</td></tr><tr><td> </td><td>New Zealand Customs Service (NZ-NCS)</td></tr><tr><td> </td><td>New Zealand Financial Markets Authority (NZ-FMA)</td></tr><tr><td> </td><td>New Zealand Police Wanted (NZ-NZPW)</td></tr><tr><td> </td><td>New Zealand Securities Commission (NZ-SC)</td></tr><tr><td> </td><td>New Zealand Serious Fraud Office (NZ-SFO)</td></tr><tr><td> </td><td>Reserve Bank (NZ--RB)</td></tr><tr><td>Nicaragua</td><td>Poder Judicial República de Nicaragua (PJN)</td></tr><tr><td> </td><td>Policía Nacional de Nicaragua (NI-POLICIA)</td></tr><tr><td> </td><td>Procuraduría General de la República de Nicaragua (NI-PGRN)</td></tr><tr><td> </td><td>Superintendencia de Bancos y otras Instituciones Financieras (NI-SBIF)</td></tr><tr><td>Nigeria</td><td>Central Bank of Nigeria (CBN) (NG-CBN)</td></tr><tr><td> </td><td>Economic and Financial Crimes Commission (EFCC) (NG-EFCC)</td></tr><tr><td> </td><td>Independent Corrupt Practices and Other Related Offences Commission (NG-ICPC)</td></tr><tr><td> </td><td>Independent Corrupt Practices and Other Related Offences Commission - Most Wanted (NG-ICPC-MW)</td></tr><tr><td> </td><td>National Insurance Commission (NG-NIC)</td></tr><tr><td> </td><td>Nigeria Deposit Insurance Corporation (NDIC) (NG-NDIC)</td></tr><tr><td> </td><td>Nigeria National Drug Law Enforcement Agency (NDLEA) (NG-NDLEA)</td></tr><tr><td> </td><td>Nigeria Police Force (NG-NPF)</td></tr><tr><td> </td><td>Nigerian Exchange (NG-NGX)</td></tr><tr><td> </td><td>Securities and Exchange Commission of Nigeria (SEC) (NG-SEC)</td></tr><tr><td>Norway</td><td>Authority for Investigation and Prosecution of Economic and Environmental Crime (NO-NAIPEE)</td></tr><tr><td> </td><td>Financial Supervisory Authority (NO-FSA-WA)</td></tr><tr><td> </td><td>Norges Bank Observation and Exclusion of Companies (NO-NBOEC)</td></tr><tr><td> </td><td>Norwegian Gaming Authority - Pyramid Schemes (NO-NGAPS)</td></tr><tr><td> </td><td>Norwegian Gaming Authority - Unlicensed Gambling Operators (NO-NGAU)</td></tr><tr><td> </td><td>Norwegian Gaming Authority - Decisions (NO-NGAD)</td></tr><tr><td>Oman</td><td>Capital Market Authority (OM-CMA_NW)</td></tr><tr><td>Pakistan</td><td>Anti Narcotics Force (ANF) (PK-ENF-ANF)</td></tr><tr><td> </td><td>Balochistan Police (PK-ENF-BP)</td></tr><tr><td> </td><td>Central Depository Company (PK-CDC)</td></tr><tr><td> </td><td>Competition Commission of Pakistan (PK-CCP)</td></tr><tr><td> </td><td>Federal Board of Revenue (PK-FBR)</td></tr><tr><td> </td><td>Federal Investigation Agency (FIA) - Govt. of Pakistan (PK-FIA)</td></tr><tr><td> </td><td>Islamabad Capital Territory Police (PK-ENF-ICP)</td></tr><tr><td> </td><td>Khyber Pakhtunkhwa Police (PK-ENF-KPP)</td></tr><tr><td> </td><td>Khyber Pakhtunkhwa Public Procurement Regulatory Authority (PK-KPPRA)</td></tr><tr><td> </td><td>National Counter Terrorism Authority Pakistan (PK-NACTA)</td></tr><tr><td> </td><td>Pakistan National Accountability Bureau (PK-NAB)</td></tr><tr><td> </td><td>Peshawar Police (PK-ENF-PP)</td></tr><tr><td> </td><td>Public Procurement Regulatory Authority (PK-PPRA)</td></tr><tr><td> </td><td>Punjab Police (Pakistan) (PK-Punjab)</td></tr><tr><td> </td><td>Punjab Procurement Regulatory Authority (PK-PJPRA)</td></tr><tr><td> </td><td>Securities and Exchange Commission of Pakistan (PK-SECP)</td></tr><tr><td> </td><td>Sindh Police (PK-ENF-SP)</td></tr><tr><td> </td><td>Sindh Public Procurement Regulatory Authority (PK-SPRA)</td></tr><tr><td> </td><td>State Bank of Pakistan (PK-ENF-SBP)</td></tr><tr><td>Palestine</td><td>Palestine Monetary Authority - Local Freezing List (PS-PMA-LFL)</td></tr><tr><td>Panama</td><td>Ministerio de Ambiente de Panama (PA-MA)</td></tr><tr><td> </td><td>Ministerio Publico de Panama - Comunicados (PA-MP-C)</td></tr><tr><td> </td><td>Organo Judicial de Panama (PA-OJP)</td></tr><tr><td> </td><td>PanamaCompra (PA-PANCOM)</td></tr><tr><td> </td><td>Panama Superintendency of Banks (PA-SBP)</td></tr><tr><td> </td><td>Policia Nacional de Panamá (PA-POLICE)</td></tr><tr><td> </td><td>Superintendence of Non-Financial Regulated Persons (PA-SNFRP)</td></tr><tr><td> </td><td>Superintendencia de Seguros y Reaseguros de Panamá (PA-Supsgre)</td></tr><tr><td> </td><td>Superintendencia del Mercado de Valores (PA-CNDV)</td></tr><tr><td>Paraguay</td><td>Aduanas (PY-DNA)</td></tr><tr><td> </td><td>Central Bank of Paraguay-Penalty Records (PY-BCP-PR)</td></tr><tr><td> </td><td>Dirección Nacional de Contrataciones Públicas (PY-DNCP)</td></tr><tr><td> </td><td>Ministerio del Interior (PY-MDI)</td></tr><tr><td> </td><td>Ministerio Público de Paraguay (PY-MINPUB)</td></tr><tr><td> </td><td>Policia Naciona (PY-PN)</td></tr><tr><td> </td><td>Secretaría Nacional Antidrogas (PY-SENAD)</td></tr><tr><td>Peru</td><td>Agencia Fiscal de Noticias (PE-AF)</td></tr><tr><td> </td><td>Contraloría General de la República (PE-CGR)</td></tr><tr><td> </td><td>Ministerio de Justicia del Perú deudores por delitos de Terrorismo (PE-DDT)</td></tr><tr><td> </td><td>Ministerio de Justicia del Perú deudores por delitos de Corrupcion (PE-MIN-DDT)</td></tr><tr><td> </td><td>Ministry of Justice List of Legal Persons under Investigation. Application of Law 30737, Category 3 (PE-MJC3)</td></tr><tr><td> </td><td>El Peruano Official Diario (PE-EP)</td></tr><tr><td> </td><td>Instituto Nacional de Defensa de la Competencia y de la Protección de la Propiedad Intelectual (PE-INDECOP)</td></tr><tr><td> </td><td>Ministerio de Justicia del Perú (PE-MINJUS)</td></tr><tr><td> </td><td>Ministerio del Interior de Perú (PE-MinInt)</td></tr><tr><td> </td><td>Ministerio Público, Fiscalia de la Nación (Perú) (PE-MPFN)</td></tr><tr><td> </td><td>Organismo Supervisor de las Contrataciones (PE-OSCE)</td></tr><tr><td> </td><td>Osinergmin (PE-Osinerg)</td></tr><tr><td> </td><td>Poder Judicial de Peru (PE-PJP)</td></tr><tr><td> </td><td>Policía Nacional del Perú (PNP)</td></tr><tr><td> </td><td>Superintendencia de Banca y Seguros del Perú (PE-SBS)</td></tr><tr><td> </td><td>Superintendencia de Mercado de Valores (PE-SMV)</td></tr><tr><td>Philippines</td><td>Anti-Money Laundering Council Enforcement (PH-AMLC-E)</td></tr><tr><td> </td><td>Bangko Sentral ng Pilipinas BSP (Philippines Central BankPhilippines) (PH-BSP)</td></tr><tr><td> </td><td>Criminal Investigation and Detection Group (PH-CIDG)</td></tr><tr><td> </td><td>Department of Environment and Natural Resources (PH-DENR)</td></tr><tr><td> </td><td>Department of Foreign Affairs (PH-DFA)</td></tr><tr><td> </td><td>Department of Justice (PH-DJ)</td></tr><tr><td> </td><td>Office of the Ombudsman (PH-OFO)</td></tr><tr><td> </td><td>Philippine Department of Finance (PH-DOF)</td></tr><tr><td> </td><td>Philippine Deposit Insurance Corporation (PH-PDIC)</td></tr><tr><td> </td><td>Philippine Drug Enforcement Agency (PH-PDEA)</td></tr><tr><td> </td><td>Philippine National Police (PH-PNP)</td></tr><tr><td> </td><td>Philippines Bureau of Internal Revenue (PH-PBIR)</td></tr><tr><td> </td><td>Philippines National Bureau of Investigation (PH-BURINV)</td></tr><tr><td> </td><td>Philippines Securities and Exchange Commission (PH-SEC)</td></tr><tr><td> </td><td>Supreme Court of the Philippines (PH-SCP)</td></tr><tr><td>Poland</td><td>Border Guard (PL-BG)</td></tr><tr><td> </td><td>Central Anti Corruption Bureau (PL-CACB)</td></tr><tr><td> </td><td>Illicit Gambling Services (PL-IGS)</td></tr><tr><td> </td><td>Ministry of Finance - Administrative Sanctions (PL-MF-AS)</td></tr><tr><td> </td><td>Most Wanted (PL-MW)</td></tr><tr><td> </td><td>Polish Financial Supervision Authority (PL-PFSA)</td></tr><tr><td> </td><td>Poland Police (PLP)</td></tr><tr><td> </td><td>Office of Competition and Consumer Protection (PL-UOCCP)</td></tr><tr><td>Portugal</td><td>Autoridade da Concorrencia (PT-ADC)</td></tr><tr><td> </td><td>Portuguese Comissão Do Mercado De Valores Mobiliários (PT-CMVM)</td></tr><tr><td>Puerto Rico</td><td>Departamento de Justicia (PR-DJ)</td></tr><tr><td> </td><td>Policia de Puerto Rico (PR-PPR)</td></tr><tr><td>Qatar</td><td>Qatar Financial Center (QA-QFC)</td></tr><tr><td> </td><td>Qatar Financial Centre Regulatory Authority (QA-QFC-RA)</td></tr><tr><td>Republika Srpska</td><td>District Prosecutor's Office in Banja Luka (RK-DPO-BL)</td></tr><tr><td> </td><td>Ministry of the Interior of the Republika Srpska (RK-MOI)</td></tr><tr><td> </td><td>Republic of Srpska Securities Commission (RK-SEC)</td></tr><tr><td>Romania</td><td>Competition Council (RO-CC)</td></tr><tr><td> </td><td>Directorate for Investigation of Organized Crime and Terrorism (DIICOT) (RO-DIICOT)</td></tr><tr><td> </td><td>High Court of Cassation and Justice of Romania (RO-HCCJR)</td></tr><tr><td> </td><td>Ministry of Justice of Romania (RO-MINJUS)</td></tr><tr><td> </td><td>National Anticorruption Directorate (DNA) (RO-DNA)</td></tr><tr><td> </td><td>National Gambling Office - Blacklist (RO-NGO-B)</td></tr><tr><td> </td><td>National Integrity Agency (RO-ANI)</td></tr><tr><td> </td><td>National Securities Commission (RO-CNVMR)</td></tr><tr><td> </td><td>Police (RO-PO)</td></tr><tr><td> </td><td>Public Ministry of Romania (RO-PMR)</td></tr><tr><td> </td><td>Romanian Financial Supervision Authority (RO-RFSA)</td></tr><tr><td> </td><td>Romanian National Bank (RO-ENF-BNR)</td></tr><tr><td> </td><td>Supreme Council of National Defense (RO-CSAT)</td></tr><tr><td>Russia</td><td>Federal Tax Service (RU-FTS)</td></tr><tr><td> </td><td>Office of the Prosecutor General of the Russian Federation - Illegal Remuneration (RU-OPGRFIR)</td></tr><tr><td> </td><td>Prosecutors Office of the Republic of Crimea (RU-PORC)</td></tr><tr><td>Russian Federation</td><td>Chief Military Prosecutor (RU-CMP)</td></tr><tr><td> </td><td>Courts (RU-LEGAL)</td></tr><tr><td> </td><td>Federal Antimonopoly Service of the Russian Federation (RU-FAS)</td></tr><tr><td> </td><td>Federal Drug Control Service (RU-FDCS)</td></tr><tr><td> </td><td>Federal Penitentiary Service (RU-FPS)</td></tr><tr><td> </td><td>Federal Security Service of the Russian Federation (FSB) (RU-FSB)</td></tr><tr><td> </td><td>Investigative Committee at the Public Prosecutor's Office of the Russian Federation (RU-SLEDCOM)</td></tr><tr><td> </td><td>Ministry of Internal Affairs of Buryatia Republic (MVD) (RU-MVDBR)</td></tr><tr><td> </td><td>Ministry of Justice (RU-MINJUS)</td></tr><tr><td> </td><td>Ministry of the Interior of the Russian Federation (RU-MVDRF)</td></tr><tr><td> </td><td>Office of the Prosecutor General of the Russian Federation (RU-GPO)</td></tr><tr><td> </td><td>Prosecutor's Office (RU-PROKUR)</td></tr><tr><td> </td><td>The Central Bank of the Russian Federation (RU-CBR)</td></tr><tr><td>Rwanda</td><td>International Criminal Tribunal for Rwanda) (RW-ICT)</td></tr><tr><td> </td><td>National Public Prosecution Authority (RW-NPPA)</td></tr><tr><td> </td><td>Office of the Ombudsman (RW-OO)</td></tr><tr><td> </td><td>Office of the Prosecutor General of the Republic of Rwanda (RW-PG)</td></tr><tr><td> </td><td>Rwanda National Police (RW-RNP)</td></tr><tr><td> </td><td>Rwanda Public Procurement Authority (RW-PUBLIC)</td></tr><tr><td>Samoa</td><td>Central Bank of Samoa (WS-CBS)</td></tr><tr><td>Saudi Arabia</td><td>Capital Market Authority (SA - CMA)</td></tr><tr><td> </td><td>Ministry of Interior (General Directorate of Investigation) (SA-MOI)</td></tr><tr><td> </td><td>Saudi Arabian Monetary Authority (SAMA) (SA-SAMA)</td></tr><tr><td>Serbia</td><td>Anti-Corruption Agency in Serbia (RS-ACAS)</td></tr><tr><td> </td><td>Belgrade Higher Court (RS-HCB)</td></tr><tr><td> </td><td>Commission for Protection of Competition (RS-CPC)</td></tr><tr><td> </td><td>Court of Appeal in Belgrade (RS-CAB)</td></tr><tr><td> </td><td>Court of Appeal in Novi Sad (RS-CA-NS)</td></tr><tr><td> </td><td>Ministry of Interior of the Republic of Serbia (RS-INTERS)</td></tr><tr><td> </td><td>Serbian Office of the War Crimes Prosecutor (RS-SOWCP)</td></tr><tr><td>Seychelles</td><td>Central Bank of Seychelles (SC-CBS)</td></tr><tr><td> </td><td>Financial Services Authority Seychelles (SC-FSAS)</td></tr><tr><td>Sierra Leone</td><td>Anti-Corruption Commission (SL-ACC)</td></tr><tr><td> </td><td>Special Court for Sierra Leone (SL-SCSL)</td></tr><tr><td>Singapore</td><td>Accounting and Corporate Regulatory Authority (SG-ACRA)</td></tr><tr><td> </td><td>Agri-Food &#x26; Veterinary Authority (SG-AVA)</td></tr><tr><td> </td><td>Attorney General’s Chambers (SG-AGC-E)</td></tr><tr><td> </td><td>Casino Regulatory Authority (SG-SRA)</td></tr><tr><td> </td><td>Central Narcotics Bureau, Singapore (SG-CNB)</td></tr><tr><td> </td><td>Charity Council (SG-CHCO)</td></tr><tr><td> </td><td>Competition Commission of Singapore (CCS) (SG-CCS)</td></tr><tr><td> </td><td>Corrupt Practices Investigation Bureau (SG-CPIB)</td></tr><tr><td> </td><td>Council for Estate Agencies (SG-CEA)</td></tr><tr><td> </td><td>Customs (SG-CU)</td></tr><tr><td> </td><td>Immigration and Checkpoints Authority (SG-ICA)</td></tr><tr><td> </td><td>Inland Revenue Authority (SG-IRA)</td></tr><tr><td> </td><td>Maritime and Port Authority (SG-MPA)</td></tr><tr><td> </td><td>Ministry of Home Affairs (SG-MHA)</td></tr><tr><td> </td><td>Ministry of Manpower (SG-MOM)</td></tr><tr><td> </td><td>Monetary Authority of Singapore (Sing-MAS)</td></tr><tr><td> </td><td>Police Force Case Studies (SG-PF-CS)</td></tr><tr><td> </td><td>Singapore, Commercial Affairs Department (SG-CAD)</td></tr><tr><td> </td><td>Singapore, Ministry of Law (SG-MinLaw)</td></tr><tr><td> </td><td>Singapore, Supreme Court (SG-SUP-CRT)</td></tr><tr><td> </td><td>Singapore Food Agency (SG-SFA)</td></tr><tr><td> </td><td>Singapore Stock Exchange (SG-SX)</td></tr><tr><td>Sint Maarten</td><td>Central Bank of Curacao and Sint Maarten (SX-CBC-SM)</td></tr><tr><td>Slovakia</td><td>Banska Bystrica Regional Police Directorate (SK-BBKRPZ)</td></tr><tr><td> </td><td>Gambling Regulatory Authority (SK-GRA)</td></tr><tr><td> </td><td>General Prosecutor's Office (SK-GPO)</td></tr><tr><td> </td><td>Kosice Regional Police Directorate (SK-KKRPZ)</td></tr><tr><td> </td><td>Ministry of Interior (Slovak Republic) (SK-MINV)</td></tr><tr><td> </td><td>National Bank of Slovakia (SK-NBank)</td></tr><tr><td> </td><td>Slovak Office for Public Procurement (SK-SOPP)</td></tr><tr><td> </td><td>Specialized Criminal Court (SK-SCC)</td></tr><tr><td> </td><td>The Antimonopoly Office of the Slovak Republic (SK-AOSR)</td></tr><tr><td>Slovenia</td><td>Bank of Slovenia (SI-BoS)</td></tr><tr><td> </td><td>Commission for the Prevention of Corruption (SI-CPC)</td></tr><tr><td> </td><td>Republic of Slovenia, Ministry of the Interior Police (SI-Police)</td></tr><tr><td> </td><td>Slovene Securities Market Agency (AGENCIJA)</td></tr><tr><td> </td><td>Slovenian Competition Protection Office (SI-SCPO)</td></tr><tr><td> </td><td>Supreme Court of Slovenia (SI-SC-SI)</td></tr><tr><td>South Africa</td><td>Competition Commission (ZA-CC)</td></tr><tr><td> </td><td>Competition Tribunal (ZA-CT)</td></tr><tr><td> </td><td>Financial Intelligence Centre (ZA-FIC)</td></tr><tr><td> </td><td>Financial Sector Conduct Authority (ZA-FSCA)</td></tr><tr><td> </td><td>National Prosecution Authority (ZA-NPA)</td></tr><tr><td> </td><td>South African Police Service (ZA-SAPS)</td></tr><tr><td> </td><td>South African Revenue Service (ZA-SARS)</td></tr><tr><td> </td><td>Special Investigating Unit (ZA-SIU)</td></tr><tr><td>South Korea</td><td>Fair Trade Commission (KR-FTC)</td></tr><tr><td> </td><td>Financial Services Commission (KR-FSC)</td></tr><tr><td> </td><td>Financial Supervisory Service (KR-FSS)</td></tr><tr><td> </td><td>Korea Customs Service (KR-KCS)</td></tr><tr><td> </td><td>Supreme Prosecutors' Office (KR-SPO)</td></tr><tr><td>Spain</td><td>Agencia Española de Protección de Datos (ES-AEPD)</td></tr><tr><td> </td><td>Bank of Spain (ES-BOS)</td></tr><tr><td> </td><td>Comisión Nacional de los Mercados y la Competencia (ES-CNMC)</td></tr><tr><td> </td><td>Comisión Nacional del Mercado de Valores (ES-CNMV)</td></tr><tr><td> </td><td>Dirección General de Seguros y Fondos de Pensiones (ES-DGSFP)</td></tr><tr><td> </td><td>Guardia Civil (ES-GC)</td></tr><tr><td> </td><td>Ministerio de Justicia (ES-MJ)</td></tr><tr><td> </td><td>National Police (ES-CNP)</td></tr><tr><td> </td><td>Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales (ES-SEPBLAC)</td></tr><tr><td>Sri Lanka</td><td>Central Bank of Sri Lanka (LK-CBSL)</td></tr><tr><td> </td><td>Commission to Investigate Allegations of Bribery or Corruption (LK-CIABOC)</td></tr><tr><td> </td><td>Financial Intelligence Unit of Sri Lanka (LK-FIU)</td></tr><tr><td> </td><td>Securities and Exchange Commission of Sri Lanka (LK-SEC)</td></tr><tr><td> </td><td>Sri Lanka Police (LK-POLICE)</td></tr><tr><td>St. Kitts and Nevis</td><td>Financial Services Regulatory Commission (KN-FSRC)</td></tr><tr><td> </td><td>Royal St. Christopher and Nevis Police Force (KN-RSCNPF)</td></tr><tr><td>St. Lucia</td><td>Financial Intelligence Authority (LC-FIA)</td></tr><tr><td> </td><td>Financial Services Regulatory Authority (LC-FSRA)</td></tr><tr><td> </td><td>Royal Saint Lucia Police Force (LC-RSLPF)</td></tr><tr><td>St. Vincent and The Grenadines</td><td>Financial ServicesAuthority (VC-FSA)</td></tr><tr><td> </td><td>Royal Saint Vincent and the Grenadines Police Force (VC-RSVGPF)</td></tr><tr><td>Swaziland</td><td>Central Bank of Swaziland (SZ-CBS)</td></tr><tr><td> </td><td>Financial Services Regulatory Authority (SZ-FSRA)</td></tr><tr><td>Sweden</td><td>Economic Crime Authority (SE-EBM)</td></tr><tr><td> </td><td>Finansinspektionen (Financial Supervisory Authority) (SE-FI)</td></tr><tr><td> </td><td>Swedish Competition Authority (SE-SCA)</td></tr><tr><td> </td><td>Swedish Police Authority (SE-POLICE)</td></tr><tr><td> </td><td>Swedish Prosecution Authority (SE-SPA)</td></tr><tr><td>Switzerland</td><td>Federal Department of Finance (CH-FDF)</td></tr><tr><td> </td><td>Federal Gaming Board (CH-ESBK)</td></tr><tr><td> </td><td>Financial Market Supervisory Authority (CH-FINMA)</td></tr><tr><td> </td><td>Office of the Attorney General of Switzerland (CH-OAG)</td></tr><tr><td> </td><td>Swiss Competition Commission (CH-WEKO)</td></tr><tr><td>Taiwan</td><td>Central Bank of the Republic of China (Taiwan) (TW-CBC)</td></tr><tr><td> </td><td>Financial Supervisory Commission (TW-FSC)</td></tr><tr><td> </td><td>Investigation Bureau, Ministry of Justice (TW-MJIB)</td></tr><tr><td> </td><td>Ministry of Justice (TW-MOJ)</td></tr><tr><td> </td><td>National Police Agency (TW-NPA)</td></tr><tr><td>Tajikistan</td><td>Agency for State Financial Control and Combating Corruption (TJ-ASFCC)</td></tr><tr><td> </td><td>Ministry of Internal Affairs (TJ-MIA)</td></tr><tr><td> </td><td>National Bank of Tajikistan (TJ-NBT)</td></tr><tr><td>Tanzania</td><td>Bank of Tanzania (TZ-BOT)</td></tr><tr><td> </td><td>Capital Markets and Securities Authority (TZ-CMSA)</td></tr><tr><td> </td><td>Prevention and Combating of Corruption Bureau (TZ-PCCB)</td></tr><tr><td>Thailand</td><td>Anti-Money Laundering Office (TH-AMLO)</td></tr><tr><td> </td><td>Bank of Thailand (TH-BOT)</td></tr><tr><td> </td><td>Department of Special Investigation (TH-DSI)</td></tr><tr><td> </td><td>Office of the National Anti-Corruption Commission (TH-NACC)</td></tr><tr><td> </td><td>Office of the Securities and Exchange Commission (TH-SEC)</td></tr><tr><td> </td><td>Royal Thai Police (TH-RTP)</td></tr><tr><td>Trinidad and Tobago</td><td>Central Bank of Trinidad and Tobago (TT-CBTT)</td></tr><tr><td> </td><td>Financial Intelligence Unit of Trinidad and Tobago (TT-FIU)</td></tr><tr><td> </td><td>Trinidad and Tobago Police Service (TT-TTPS)</td></tr><tr><td> </td><td>Trinidad and Tobago Securities and Exchange Commission (TT-SEC)</td></tr><tr><td>Turkey</td><td>Banking Regulation and Supervision Agency (TR-BRSA)</td></tr><tr><td> </td><td>Capital Markets Board of Turkey (TR-CMB)</td></tr><tr><td> </td><td>Competition Authority (TR-RK)</td></tr><tr><td> </td><td>Financial Crimes Investigation Board (TR-MASAK)</td></tr><tr><td> </td><td>Ministry of Interior (TR-MOI)</td></tr><tr><td>Turks and Caicos</td><td>Financial Services Commission (TC-FSC)</td></tr><tr><td> </td><td>Royal Turks and Caicos Islands Police Force (TC-RTCIPF)</td></tr><tr><td>Uganda</td><td>Bank of Uganda (UG-BOU)</td></tr><tr><td> </td><td>Capital Markets Authority (UG-CMA)</td></tr><tr><td> </td><td>Financial Intelligence Authority (UG-FIA)</td></tr><tr><td> </td><td>Inspectorate of Government (UG-IG)</td></tr><tr><td> </td><td>Uganda Police Force (UG-UPF)</td></tr><tr><td>Ukraine</td><td>Anti-Monopoly Committee of Ukraine (UA-AMCU)</td></tr><tr><td> </td><td>Ministry of Internal Affairs (UA-MIA)</td></tr><tr><td> </td><td>National Anti-Corruption Bureau of Ukraine (UA-NABU)</td></tr><tr><td> </td><td>National Bank of Ukraine (UA-NBU)</td></tr><tr><td> </td><td>National Commission on Securities and Stock Market (UA-NCSSM)</td></tr><tr><td> </td><td>National Police of Ukraine (UA-NPU)</td></tr><tr><td> </td><td>Prosecutor General's Office of Ukraine (UA-PGO)</td></tr><tr><td> </td><td>Security Service of Ukraine (UA-SSU)</td></tr><tr><td> </td><td>State Bureau of Investigations (UA-SBI)</td></tr><tr><td> </td><td>State Financial Monitoring Service (UA-SFMS)</td></tr><tr><td>United Arab Emirates</td><td>Central Bank of the UAE (AE-CBUAE)</td></tr><tr><td> </td><td>Dubai Financial Services Authority (AE-DFSA)</td></tr><tr><td> </td><td>Financial Services Regulatory Authority (AE-FSRA)</td></tr><tr><td> </td><td>Ministry of Interior (AE-MOI)</td></tr><tr><td> </td><td>Securities and Commodities Authority (AE-SCA)</td></tr><tr><td>United Kingdom</td><td>Attorney General's Office (UK-AGO)</td></tr><tr><td> </td><td>Bank of England News (UK-BE)</td></tr><tr><td> </td><td>Bar Standards Board (UK-BSB)</td></tr><tr><td> </td><td>Charity Commission for England and Wales (UK-CCEW)</td></tr><tr><td> </td><td>Civil Aviation Authority (CAA) (UK-CAA)</td></tr><tr><td> </td><td>Competition and Markets Authority (UK-CMA)</td></tr><tr><td> </td><td>Crimestoppers Trust (UK-Crime)</td></tr><tr><td> </td><td>Crown Office and Procurator Fiscal Service (UK-COPFS)</td></tr><tr><td> </td><td>Crown Prosecution Service (UK-CPS)</td></tr><tr><td> </td><td>Department of Trade and Industry (UK-DTI)</td></tr><tr><td> </td><td>Dept Business Innovation and Skill (UK BIS)</td></tr><tr><td> </td><td>Disqualified Directors (UK-DisqDir)</td></tr><tr><td> </td><td>Environment Agency (UK-EA)</td></tr><tr><td> </td><td>Financial Conduct Authority (UK-FCA)</td></tr><tr><td> </td><td>Financial Conduct Authority - Unauthorized Firms/ Individuals (UK-FCA-UFI)</td></tr><tr><td> </td><td>Financial Conduct Authority - Unauthorized Internet Banks (UK-FCA-UIB)</td></tr><tr><td> </td><td>Financial Conduct Authority - Unregistered Cryptoasset Businesses (UK-FCA-UCB)</td></tr><tr><td> </td><td>Financial Services Authority (UK-FSC)</td></tr><tr><td> </td><td>Financial Services Authority - Final Notice (UK-FSA)</td></tr><tr><td> </td><td>Financial Services Authority - Unauthorised Firms / Individuals (UK-FSA-UFI)</td></tr><tr><td> </td><td>Financial Services Authority - Unauthorised Overseas Firms (UK-FSA-UOF)</td></tr><tr><td> </td><td>Financial Services Authority - Unauthorized Internet Banks (UK-FSA-UIB)</td></tr><tr><td> </td><td>Gangmasters and Labour Abuse Authority (UK-GLAA)</td></tr><tr><td> </td><td>Government News Network (UK-GNN)</td></tr><tr><td> </td><td>Her Majesty's Courts Service (UK-HMCS)</td></tr><tr><td> </td><td>HM Revenue and Customs (UKRC)</td></tr><tr><td> </td><td>Home Office (UK-HOME)</td></tr><tr><td> </td><td>Immigration Enforcement (UK-IE)</td></tr><tr><td> </td><td>Judiciary of Scotland (UK-JS)</td></tr><tr><td> </td><td>Lloyd's of London (Partial list due to source availability)</td></tr><tr><td>United States</td><td>Dept. of Defense Procurement and Acquisition (US-DPAP)</td></tr><tr><td> </td><td>District of Columbia Attorney General (US-DC-AG)</td></tr><tr><td> </td><td>Equal Employment Opportunities Commission (US-EEOC)</td></tr><tr><td> </td><td>Federal Aviation Administration (US-FAA)</td></tr><tr><td> </td><td>Federal Communications Commission (US-FCC)</td></tr><tr><td> </td><td>Federal Election Commission (US-FEC)</td></tr><tr><td> </td><td>Federal Energy Regulatory Commission (US-FERC)</td></tr><tr><td> </td><td>Federal Housing Finance Agency (US-FHFA)</td></tr><tr><td> </td><td>Indiana Office of the Secretary of State Securities Division (US-IN-SOS)</td></tr><tr><td> </td><td>Intercontinental Futures Exchange (US-INT-EX)</td></tr><tr><td> </td><td>Investors Exchange - Disciplinary Actions (US-IEX-DA)</td></tr><tr><td> </td><td>Iowa Attorney General (US-IA-AG)</td></tr><tr><td> </td><td>Iowa Insurance Division (US-IA-IID)</td></tr><tr><td> </td><td>Iowa Public Employee Retirement System (US-IPERS)</td></tr><tr><td> </td><td>Kansas Attorney General (US-KS-AG)</td></tr><tr><td> </td><td>Kansas Bureau of Investigation (US-KBI)</td></tr><tr><td> </td><td>Kansas Securities Commission (US-KS-SC)</td></tr><tr><td> </td><td>Kentucky Attorney General (US-SAG-KY)</td></tr><tr><td> </td><td>Louisiana Department of Justice Office of the Attorney General (US-AG-LA)</td></tr><tr><td> </td><td>Maine Attorney General (US-ME-AG)</td></tr><tr><td> </td><td>Maine Bureau of Insurance (US-ME-INS)</td></tr><tr><td> </td><td>Maine Department of Professional and Financial Regulation (US-ME-DPFR)</td></tr><tr><td> </td><td>Maine Securities Division (US-NV-SSD)</td></tr><tr><td> </td><td>Maryland Attorney General (US-SAG-MD)</td></tr><tr><td> </td><td>Massachusetts Attorney General (US-MA-AG)</td></tr><tr><td> </td><td>Massachusetts Securities Division (US-MA-SD)</td></tr><tr><td> </td><td>Massachusetts Gaming Commission Exclusion List (US-MGC-EL)</td></tr><tr><td> </td><td>Miami International Securities Exchange - MIAX Options Disciplinary Actions (US-MIAX-OP)</td></tr><tr><td> </td><td>Miami International Securities Exchange - MIAX Pearl Disciplinary Actions (US-MIAX-PE)</td></tr><tr><td> </td><td>Michigan Attorney General (US-SAG-MI)</td></tr><tr><td> </td><td>Michigan Department of Insurance and Financial Services (US-MI-ISF)</td></tr><tr><td> </td><td>Michigan Gaming Control Board Exclusion List (US-MGCB-EL)</td></tr><tr><td> </td><td>Michigan Treasury (US-MITreas)</td></tr><tr><td> </td><td>Minnesota Attorney General (US-MN-AG)</td></tr><tr><td> </td><td>Minnesota Department of Commerce (US-MN-DC)</td></tr><tr><td> </td><td>Minnesota State Board of Investment (US-MSBI)</td></tr><tr><td> </td><td>Mississippi Attorney General (US-MS-AG)</td></tr><tr><td> </td><td>Mississippi Department of Public Safety (US-MDPS)</td></tr><tr><td> </td><td>Mississippi Gaming Commission Exclusion List (US-MSGC-EL)</td></tr><tr><td> </td><td>Mississippi Office of the State Auditor (US-MOSA)</td></tr><tr><td> </td><td>Mississippi Secretary of State (US-MS-SOS)</td></tr><tr><td> </td><td>Missouri Attorney General (US-MO-AG)</td></tr><tr><td> </td><td>Missouri Gaming Commission-Exclusion List (US-MOGC-EL)</td></tr><tr><td> </td><td>Missouri Secretary of State Securities Division (US-US-MSS)</td></tr><tr><td> </td><td>Montana Attorney General (US-MT-AG)</td></tr><tr><td> </td><td>Montana State Auditor’s Office (US-MT-SAO)</td></tr><tr><td> </td><td>Nebraska Attorney General (US-NE-AG)</td></tr><tr><td> </td><td>Nebraska Department of Banking and Finance (US-NE-DBF)</td></tr><tr><td> </td><td>Nevada Attorney General (US-NV-AG)</td></tr><tr><td> </td><td>Nevada Gaming Commission &#x26; State Gaming Control Board (US-NV-GCB)</td></tr><tr><td> </td><td>Nevada Secretary of State Securities Division (US-NV-SSSD)</td></tr><tr><td> </td><td>New Hampshire Department of Justice Office of the Attorney General (US-NH-DOJ)</td></tr><tr><td> </td><td>New Hampshire Secretary of State (US-NH-SOS)</td></tr><tr><td> </td><td>New Jersey Bureau of Securities (US-NJ-BOS)</td></tr><tr><td> </td><td>New Jersey Casino Control Commission (US-NJ-CCC)</td></tr><tr><td> </td><td>New Jersey Department of Banking &#x26; Insurance (US-DOB&#x26;I)</td></tr><tr><td> </td><td>New Jersey Office of the Attorney General and Department of Law &#x26; Public Safety (US-NJ-AG)</td></tr><tr><td> </td><td>New Mexico Attorney General (US-OAG-NM)</td></tr><tr><td> </td><td>New Mexico Gaming Control Board-Exclusion List (US-NMGB-EL)</td></tr><tr><td> </td><td>Rhode Island State Police (US-RISP)</td></tr><tr><td> </td><td>San Diego County Attorney General (US-SAND-AG)</td></tr><tr><td> </td><td>Special Inspector General for Afghanistan Reconstruction - Suspension and Debarment (US-SIGAR-S)</td></tr><tr><td> </td><td>Special Inspector General for Afghanistan Reconstruction (US-SIGAR)</td></tr><tr><td> </td><td>South Carolina Attorney General (US-SC-AG)</td></tr><tr><td> </td><td>South Dakota Attorney General (US-SD-AG)</td></tr><tr><td> </td><td>Tennessee Attorney General (US-TN-AG)</td></tr><tr><td> </td><td>Tennessee Bureau of Investigation (US-TN-TBI)</td></tr><tr><td> </td><td>Tennessee Department of Commerce and Insurance (US-TDCI)</td></tr><tr><td> </td><td>Tennessee Securities Division (US-TN-SD)</td></tr><tr><td> </td><td>Texas Department of Banking (US-TX-DOB)</td></tr><tr><td> </td><td>Texas Attorney General (US-TX-AG)</td></tr><tr><td> </td><td>Texas Department of Public Safety (US-TX-DPS)</td></tr><tr><td> </td><td>Texas State Securities Board (US-TX-SB)</td></tr><tr><td> </td><td>The Nevada Legislature (US-TNL)</td></tr><tr><td> </td><td>The System for Award Management (SAM) (US-SAM)</td></tr><tr><td> </td><td>The United States Attorney's Office Northern District of Mississippi (US-USAONDM)</td></tr><tr><td> </td><td>Tricare-DHHS (US-TRI)</td></tr><tr><td> </td><td>U.S. Air Force Office of Special Investigations (US-AFOSI)</td></tr><tr><td> </td><td>U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) (US-ATF)</td></tr><tr><td> </td><td>U.S. Bureau of Industry and Security (BIS)- Entity List (BIS-EL)</td></tr><tr><td> </td><td>U.S. Bureau of Industry and Security (BIS)- Unverified List (BIS-UL)</td></tr><tr><td> </td><td>U.S. Central Intelligence Agency (US-CIA)</td></tr><tr><td> </td><td>U.S. Commodity Futures Trading Commission (US-CFTC)</td></tr><tr><td> </td><td>U.S. Courts (US-COURT)</td></tr><tr><td> </td><td>U.S. Department of Defense Military Commission Proceedings at Guantanamo Bay (US-Defense)</td></tr><tr><td> </td><td>U.S. Department of Health &#x26; Human Services (US-HHS-EIE)</td></tr><tr><td> </td><td>U.S. Department of Homeland Security (US-DHS)</td></tr><tr><td> </td><td>U.S. Department of Housing and Urban Development (US-DHUD)</td></tr><tr><td> </td><td>U.S. Department of Justice (US-DOJ)</td></tr><tr><td> </td><td>U.S. Department of Justice - Tax Division (US-DOJ-TAX)</td></tr><tr><td> </td><td>U.S. Department of Labor Office of Inspector General (US-DOL-OIG)</td></tr><tr><td> </td><td>U.S. Department of State, Narcotics Rewards Program (US-NARC)</td></tr><tr><td> </td><td>U.S. Department of State - Section 231 of CAATSA (US-DOS231d)</td></tr><tr><td> </td><td>U.S. Department of Transportation - Office of Inspector General (US-DOT-OIG)</td></tr><tr><td> </td><td>U.S. Drug Enforcement Administration (US-DEA)</td></tr><tr><td> </td><td>U.S. Environmental Protection Agency (US-EPA)</td></tr><tr><td> </td><td>U.S. Excluded Parties List System (EPLS) (US-EPLS)</td></tr><tr><td> </td><td>U.S. FBI - Law Enforcement Assistance (US-FBI-LEA)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Bank Robbers (FBI-MW-BR)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Counter Intelligence (FBI-MW-CI)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Crimes Against Children (FBI-MW-CAC)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Criminal Enterprise Investigations (FBI-MW-CEI)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Cyber’s Most Wanted (FBI-MW-CMM)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Domestic Terrorism (FBI-MW-DT)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Human Trafficking (FBI-MW-HT)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Most Wanted Terrorists (FBI-MWT)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Murder (FBI-MW-M)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Parental Kidnappings (FBI-MW-PK)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Seeking Information (FBI-MW-SI)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Seeking Information - Terrorism (FBI-MW-SIT)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Violent Crimes (FBI-MW-VC)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - White Collar Crimes (FBI-MW-WCC)</td></tr><tr><td> </td><td>U.S. FBI Most Wanted - Top 10 Fugitives and Most Wanted Terrorists (FBI-MW)</td></tr><tr><td> </td><td>U.S. FDIC Denial of Section 19 Application (US-FDIC-L)</td></tr><tr><td> </td><td>U.S. FDIC Failed Bank (US-FDIC-fb)</td></tr><tr><td> </td><td>U.S. FDIC Order to Cease and Desist (US-FDIC-b)</td></tr><tr><td> </td><td>U.S. FDIC Removal and/or Prohibition Order (US-FDIC-e)</td></tr><tr><td> </td><td>U.S. FDIC Temporary Order to Cease and Desist (US-FDIC-cb)</td></tr><tr><td> </td><td>U.S. FDIC Temporary Suspension/ Prohibition Order for Indictment (US-FDIC-g)</td></tr><tr><td> </td><td>U.S. FDIC Termination of Deposit Insurance (US-FDIC-a)</td></tr><tr><td> </td><td>U.S. Federal Bureau of Investigation (FBI)</td></tr><tr><td> </td><td>U.S. Federal Deposit Insurance Corporation (US-FDIC)</td></tr><tr><td> </td><td>U.S. Federal Reserve Board (US-FED-BOA)</td></tr><tr><td> </td><td>U.S. Federal Reserve Board - Cease and Desist Order (US-FED-C&#x26;D)</td></tr><tr><td> </td><td>U.S. Federal Reserve Board - Modification and Termination (US-FED-M&#x26;T)</td></tr><tr><td> </td><td>U.S. Federal Reserve Board - Prohibition from Banking (US-FED)</td></tr><tr><td> </td><td>U.S. Federal Trade Commission (US-FTC)</td></tr><tr><td> </td><td>U.S. Financial Crimes Enforcement Network (US-FINCEN)</td></tr><tr><td> </td><td>U.S. Food and Drug Administration (US-FDA)</td></tr><tr><td> </td><td>U.S. Immigration and Customs Enforcement (ICE) (US-ICE)</td></tr><tr><td> </td><td>U.S. Internal Revenue Service (US-IRS)</td></tr><tr><td> </td><td>U.S. International Trade Commission (US-ITC)</td></tr><tr><td> </td><td>U.S. Marshalls (US Marsh)</td></tr><tr><td> </td><td>U.S. National Association of Securities Dealers (US-NASD)</td></tr><tr><td> </td><td>U.S. National Credit Union Administration (US-NCUA)</td></tr><tr><td> </td><td>U.S. National Futures Association (US-NFA)</td></tr><tr><td> </td><td>U.S. Naval Criminal Investigative Service (NCIS) (US-NCIS)</td></tr><tr><td> </td><td>U.S. OCC Banks Cease &#x26; Desist Orders (C&#x26;D) (US-OCC-C&#x26;D)</td></tr><tr><td> </td><td>U.S. OCC IAPs 1829 Removals (1829) (US-OCC1829)</td></tr><tr><td> </td><td>U.S. OCC IAPs Cease &#x26; Desist Orders against Individuals (PC&#x26;D) (US-OCC-PCD)</td></tr><tr><td> </td><td>U.S. OCC IAPs Removal/Prohibition Orders (REM) (US-OCC-REM)</td></tr><tr><td> </td><td>U.S. OCC Unauthorized Banks List (OCC)</td></tr><tr><td> </td><td>U.S. Office of Foreign Asset Control (OFAC) - Advisory to the Maritime Petroleum Shipping Community (US-AMPSC)</td></tr><tr><td> </td><td>U.S. Office of Foreign Asset Control (OFAC) - Enforcement Information (US-OFAC-EI)</td></tr><tr><td> </td><td>U.S. Office of the Comptroller of the Currency (US-OCC)</td></tr><tr><td> </td><td>U.S. Postal Inspection Service (US-USPIS)</td></tr><tr><td> </td><td>U.S. Secret Service (US-USSS)</td></tr><tr><td> </td><td>U.S. Securities and Exchange Commission (US-SEC)</td></tr><tr><td> </td><td>United States Attorney - Central District of California (US-AG-CDCA)</td></tr><tr><td> </td><td>United States Attorney - Central District of Illinois (US-AG-CDIL)</td></tr><tr><td> </td><td>United States Attorney - District of Alaska (US-AO-DAK)</td></tr><tr><td> </td><td>United States Attorney - District of Arizona (US-AO-DOAZ)</td></tr><tr><td> </td><td>United States Attorney - District of Colorado (US-AO-DCO)</td></tr><tr><td> </td><td>United States Attorney - District of Columbia (US-AO-DODC)</td></tr><tr><td> </td><td>United States Attorney - District of Connecticut (US-AO-DOCT)</td></tr><tr><td> </td><td>United States Attorney - District of Delaware (US-AO-DDE)</td></tr><tr><td> </td><td>United States Attorney - District of Hawaii (US-AO-DHI)</td></tr><tr><td> </td><td>United States Attorney - District of Idaho (US-AO-DID)</td></tr><tr><td> </td><td>United States Attorney - District of Kansas (US-AO-DKS)</td></tr><tr><td> </td><td>United States Attorney - District of Maine (US-AO-DME)</td></tr><tr><td> </td><td>United States Attorney - District of Maryland (US-AO-DMD)</td></tr><tr><td> </td><td>United States Attorney - District of Massachusetts (US-AO-DOMA)</td></tr><tr><td> </td><td>United States Attorney - District of Minnesota (US-AO-DMN)</td></tr><tr><td> </td><td>United States Attorney - District of Montana (US-AO-DMT)</td></tr><tr><td> </td><td>United States Attorney - District of Nebraska (US-AG-DNE)</td></tr><tr><td> </td><td>United States Attorney - District of Nevada (US-AG-DNV)</td></tr><tr><td> </td><td>United States Attorney - District of New Hampshire (US-AO-DNH)</td></tr><tr><td> </td><td>United States Attorney - District of New Jersey (US-AO-NJ)</td></tr><tr><td> </td><td>United States Attorney - District of New Mexico (US-AO-DNM)</td></tr><tr><td> </td><td>United States Attorney - District of North Dakota (US-AO-DND)</td></tr><tr><td> </td><td>United States Attorney - District of Oregon (US-AO-DOR)</td></tr><tr><td> </td><td>United States Attorney - District of Puerto Rico (US-AO-PR)</td></tr><tr><td> </td><td>United States Attorney - District of Rhode Island (US-AG-RI)</td></tr><tr><td> </td><td>United States Attorney - District of South Carolina (US-AO-DNC)</td></tr><tr><td> </td><td>United States Attorney - District of South Dakota (US-AO-DSD)</td></tr><tr><td> </td><td>United States Attorney - District of Utah (US-AO-DUT)</td></tr><tr><td> </td><td>United States Attorney - District of Vermont (US-AO-DVT)</td></tr><tr><td> </td><td>United States Attorney - District of Wyoming (US-AG-DOWY)</td></tr><tr><td> </td><td>United States Attorney - Districts of Guam &#x26; the Northern Mariana Islands (US-AO-GNM)</td></tr><tr><td>Uruguay</td><td>Banco Central del Uruguay (UY-BCU)</td></tr><tr><td> </td><td>Ministerio del Interior (UY-MI)</td></tr><tr><td> </td><td>Secretaría Nacional para la Lucha contra el Lavado de Activos y el Financiamiento del Terrorismo (UY-SENACLAFT)</td></tr><tr><td>Uzbekistan</td><td>Central Bank of Uzbekistan (UZ-CBU)</td></tr><tr><td> </td><td>Department for Combating Economic Crimes (UZ-DCEC)</td></tr><tr><td> </td><td>Ministry of Internal Affairs (UZ-MIA)</td></tr><tr><td> </td><td>Prosecutor General's Office (UZ-PGO)</td></tr><tr><td>Venezuela</td><td>Ministerio del Poder Popular para Relaciones Interiores, Justicia y Paz (VE-MPPRIJP)</td></tr><tr><td> </td><td>Superintendencia de las Instituciones del Sector Bancario (VE-SUDEBAN)</td></tr><tr><td> </td><td>Superintendencia Nacional de Valores (VE-SUNAVAL)</td></tr><tr><td> </td><td>Tribunal Supremo de Justicia (VE-TSJ)</td></tr><tr><td>Vietnam</td><td>Government Inspectorate of Vietnam (VN-GIV)</td></tr><tr><td> </td><td>Ministry of Public Security (VN-MPS)</td></tr><tr><td> </td><td>State Bank of Vietnam (VN-SBV)</td></tr><tr><td> </td><td>State Securities Commission (VN-SSC)</td></tr><tr><td>Virgin Islands (British)</td><td>British Virgin Islands Financial Services Commission (VG-FSC)</td></tr><tr><td> </td><td>Royal Virgin Islands Police Force (VG-RVIPF)</td></tr><tr><td>Virgin Islands (United States)</td><td>Virgin Islands Police Department (VI-VIPD)</td></tr><tr><td>Zambia</td><td>Anti-Corruption Commission (ZM-ACC)</td></tr><tr><td> </td><td>Bank of Zambia (ZM-BOZ)</td></tr><tr><td> </td><td>Drug Enforcement Commission (ZM-DEC)</td></tr><tr><td> </td><td>Financial Intelligence Centre (ZM-FIC)</td></tr><tr><td> </td><td>Zambia Police Service (ZM-ZPS)</td></tr><tr><td>Zimbabwe</td><td>Reserve Bank of Zimbabwe (ZW-RBZ)</td></tr><tr><td> </td><td>Securities and Exchanges Commission of Zimbabwe (ZW-SECZ)</td></tr><tr><td> </td><td>Zimbabwe Anti-Corruption Commission (ZW-ZACC)</td></tr><tr><td> </td><td>Zimbabwe Republic Police (ZW-ZRP)</td></tr><tr><td> </td><td>Zimbabwe Republic Police - Most Wanted (ZW-ZRP-MW)</td></tr></tbody></table>

</details>

## PEP Sources and Types

The individual is checked against various global sources to assess whether they are potentially a politically exposed person. Each PEP type helps categorise the type of PEP (e.g. HOS - Head of State).&#x20;

<details>

<summary>PEP Sources &#x26; Types</summary>

### PEP Sources

* CIA World Leaders
* CIA World Factbook
* Rulers articles and other databases continually monitored to additional information
* Gov’t/Official websites covering all levels of PEPs
* Other open sources. For example, those independent from the state control

### PEP Types

* **AMB** - Ambassadors and top diplomatic officials
* **ASC** - Family, close associates and advisors
* **CAB** - Cabinet officials
* **DIP** - Diplomats
* **FAM** - Family members
* **GCO** - Top executives/functionaries in state-controlled businesses
* **GOE** - Government Owned Enterprises (Organisation)
* **HOS** - Heads of state
* **INF** - Senior officials overseeing key infrastructure sectors.
* **INT** - Officer of Inter-Governmental Organisations
* **ISO** - International sporting officials
* **JUD** - Senior judicial officials
* **LEG** - Senior legislative branch&#x20;
* **MIL** - Senior military figures
* **MUN** - Municipal level officials
* **NIO** - Senior officials overseeing non-infrastructure sectors.
* **POL -** Political party figures
* **PRM** - Root Subjects
* **REG** - Regional officials

</details>

PEPs are categorised into tiers of risk. With Tier 1 being the highest potential risk, including heads of state and high-ranking government positions.

<details>

<summary>PEP Tiers</summary>

### Tier 1 - High Risk

* Heads of state and government (including Royal families).
* Members of government (ministers, deputies, state, and under-state secretaries) at national and sub-national levels in case of federal states (e.g., Florida in the US, Bavaria in Germany, Johor in Malaysia, Lagos in Nigeria, Goa in India etc) and provinces in China (e.g., Henan); President and College of Commissioner of the European Commission.
* Members of Parliament or similar legislative bodies (at national and sub-national level in case of federal states – same as above); Members of the European Parliament.
* Heads and top commanders of military and law enforcement and their deputies.
* Heads and members of supreme courts, of constitutional courts or of other high-level judicial bodies whose decisions are not subject to further appeal, except in exceptional cases, similar for EU Court of Justice.
* Heads and members of courts of auditors (including EU Court of Auditors) and of the boards of central banks (including the European Central Bank).
* Top ranking officials of mainstream political parties (e.g., party leaders and members of governing bodies) and only the heads/deputy heads of minor political parties (without representation in parliament).

### Tier 2 - Medium Risk

* Members of legislative (e.g., aldermen, councillors) and executive (e.g., prefects) bodies at regional, provincial, cantonal, or equivalent levels (below the level of states in case of federal jurisdiction).
* Judges, justices, magistrates, prosecutors, attorneys in courts with jurisdiction at regional, provincial or equivalent level.
* Ambassadors, general consuls, high commissioners, permanent representatives, head of missions and their deputies, charge d’affairs.
* Chairmen, secretary generals, directors, deputy directors and members of the board or equivalent function of international/regional organisations (e.g., UN, EU, World Bank, EBRD, OAS, Arab League, ASEAN, CARICOM etc).
* Presidents/Chairperson and board members of State-Owned Enterprises (SOEs), businesses and organisations.
* Senior officials of the military, judiciary, law enforcement agencies, central banks, and other state agencies, authorities and state bodies (e.g., high ranking civil servants, director generals, directors, heads of units, secretaries (permanent, principal, joint secretaries etc).
* Heads and senior members of mainstream religious groups (e.g., archbishop, patriarch, cardinal, bishop, imam, rabbi).
* Mayors of capital cities (e.g., London, New Delhi, Paris, New York, Rio de Janeiro) and Head of Cities which are directly appointed and answerable to the Chinese central government.

### PEP Tier 3 - Low Risk

* Advisers, heads of cabinet and similar roles of senior officials of the military, judiciary, law enforcement, central banks.
* And other state agencies, authorities, and state bodies (designation/level to be determined depending on country ML/TF and corruption risks profile and administration structure).
* Heads and board members / senior officials of Trade Unions. In case of Chambers of Commerce and Charities a risk- based approach is followed.
* Presidents, secretary generals, directors, deputy directors and members of the board or equivalent function of international NGOs (e.g., Oxfam, Amnesty, Transparency International etc).
* Middle ranking diplomats (minister-counsellors, councillors, 1st Secretaries and 2nd Secretaries).
* Alternate/deputy members of parliament/senate (not currently occupying seat).
* Mayors and members of local councils at municipal, town, village, or equivalent levels (i.e., below regional, provincial, cantonal, and other levels not captured elsewhere).
* Senior civil servants at regional/provincial or equivalent levels; senior officials of administrative bodies at local levels (directors/secretaries of city governments).

</details>

## PEPs by Association

Family members and personal and business associates of PEPs, typically individuals who are not PEPs in their own capacity but serve on a board of directors alongside PEPs. Based on FATF, Close Associates are considered to be: (known) (sexual) partners outside the family unit (e.g., girlfriends, boyfriends, mistresses); prominent members of the same political party, civil organisation, labour, or employee union as the PEP; business partners or associates, especially those that share (beneficial) ownership of legal entities with the PEP, or who are otherwise connected (e.g., through joint membership of a company board). In the case of personal relationships, the social, economic, and cultural context may also play a role in determining how close those relationships generally are (FATF Guidelines, 2013).

Should the individual have a potential match within the PEP & Sanctions sources they will be flagged up for review.


# Adverse Media Screening

The Adverse Media check offers a comprehensive screening against negative media sources to ascertain any potential risks associated with an individual. This feature conducts daily scans across a vast array of media outlets, including newspapers, magazines, TV/radio transcripts, and more, encompassing over 30,000 sources in 57 languages. With a formidable database established from screening over 2.5 billion media articles, it boasts an extensive collection of negative news, encompassing individuals ranging from terrorists and fraudsters to criminals and influencers.

The core of this feature lies in its ability to categorise Adverse Media Events based on their Risk Stage and Risk Type. The Risk Stage determines where an event is in its lifecycle, while the Risk Type provides insights into the nature of the event, such as abuse, arson, fraud, cybercrime, and more. These classifications work in tandem to decide if a particular Adverse Media Event should be included in the results, ensuring a thorough and precise assessment for every individual screened.

## Adverse Media Stages

The Risk Stage describes where in its lifecycle an Adverse Media Event is. Risk Stages are used in conjunction with Risk Types to determine if the Adverse Media Event is to be included in the results.

| Stage 1   | Stage 2         | Stage 3            | Stage 4              |
| --------- | --------------- | ------------------ | -------------------- |
| Accuse    | Arraign         | Appeal             | Acquit / Not Guilty  |
| Allege    | Arrest          | Confession         | Disciplinary         |
| Conspire  | Audit           | Plea               | Regulatory Action    |
| Probe     | Charged         | Settlement or Suit | Arbitration          |
| Suspected | Complaint Filed | Trial              | Associated           |
|           | Indict          |                    | Censure              |
|           | Lien            |                    | Convict              |
|           | Seizure         |                    | Deported             |
|           |                 |                    | Dismissed            |
|           |                 |                    | Expelled             |
|           |                 |                    | Fine (<$10K, >$10K)  |
|           |                 |                    | Govt Official        |
|           |                 |                    | Revoked Registration |
|           |                 |                    | Sanction             |
|           |                 |                    | Served Jail Time     |
|           |                 |                    | Suspended            |

## Risk types

The Risk Type describes the nature of the Adverse Media Event. Risk Types are used in conjunction with Risk Stage to determine if the Adverse Media Event is to be included in the results.

These include

* :red\_circle:**Critical** - Risk Stages 1, 2, 3 & 4
* :orange\_circle:**Valuable** - Risk Stages 2, 3 & 4
* :yellow\_circle:**Investigate** - Risk Stages 3 & 4
* :green\_circle: **Probative** - Risk Stages 4

<details>

<summary><span data-gb-custom-inline data-tag="emoji" data-code="1f534">🔴</span><strong>Critical Types</strong></summary>

* BRB - Bribery, Graft, Kickbacks, Political Corruption&#x20;
* BUS - Business Crimes (Antitrust, Bankruptcy, Price Fixing)&#x20;
* DEN - Denied Entity&#x20;
* FOF - Former OFAC List&#x20;
* FOS - Former Sanctions List&#x20;
* FRD - Fraud, Scams, Swindles&#x20;
* IRC - Iran Connect&#x20;
* MLA - Money Laundering&#x20;
* ORG - Organized Crime, Criminal Association, Racketeering&#x20;
* PEP - Person Political REG - Regulatory Action&#x20;
* SEC - SEC Violations (Insider Trading, Securities Fraud)&#x20;
* SNX - Sanctions Connect&#x20;
* TER - Terrorist Related&#x20;
* WLT - Watch List

</details>

<details>

<summary><span data-gb-custom-inline data-tag="emoji" data-code="1f7e0">🟠</span><strong>Valuable Types</strong></summary>

* CFT - Counterfeiting, Forgery&#x20;
* CYB - Computer Related, Cyber Crime&#x20;
* DTF - Trafficking or Distribution of Drug&#x20;
* FAR - Foreign Agent Registration Act&#x20;
* FUG - Fugitive, Escape&#x20;
* GAM - Illegal Gambling&#x20;
* HUM - Human Rights, Genocide, War Crimes&#x20;
* IMP - Identity Theft, Impersonation&#x20;
* KID - Kidnapping, Abduction, Held Against Will&#x20;
* LMD - Legal Marijuana Dispensary&#x20;
* LNS - Loan Sharking, Usury, Predatory Lending&#x20;
* MOR - Mortgage Related MSB - Money Services Business&#x20;
* MUR - Murder, Manslaughter (Committed, Planned or Attempted)&#x20;
* OBS - Obscenity Related, Child Pornography&#x20;
* PRJ - Perjury, Obstruction of Justice, False Filings, False Statements&#x20;
* RES - Real Estate Actions&#x20;
* SEX - Sex Offenses (Rape, Sodomy, Sexual Abuse, Paedophilia)&#x20;
* SMG - Smuggling (Does not include Drugs, Money, People or Guns&#x20;
* SPY - Spying (Treason, Espionage)&#x20;
* TAX - Tax Related Offenses&#x20;
* TFT - Theft (Larceny, Misappropriation, Embezzlement, Extortion)&#x20;
* TRF - People Trafficking, Organ Trafficking

</details>

<details>

<summary><span data-gb-custom-inline data-tag="emoji" data-code="1f7e1">🟡</span><strong>Investigate Types</strong></summary>

* ARS - Arson&#x20;
* AST - Assault, Battery&#x20;
* BUR - Burglary&#x20;
* CON - Conspiracy (no specific crime named)&#x20;
* DPS - Possession of Drugs or Drug Paraphernalia&#x20;
* FOR - Forfeiture IGN - Possession or Sale of Guns, Weapons and Explosives&#x20;
* PSP - Possession of Stolen Property&#x20;
* ROB - Robbery (Stealing by Threat, Use of Force)

</details>

<details>

<summary><span data-gb-custom-inline data-tag="emoji" data-code="1f7e2">🟢</span> <strong>Probative</strong></summary>

* ABU - Abuse (Domestic, Elder, Child)&#x20;
* CPR - Copyright Infringement (Intellectual Property, Electronic Piracy&#x20;
* ENV - Environmental Crimes (Poaching, Illegal Logging, Animal Cruelty)&#x20;
* IPR - Illegal Prostitution&#x20;
* MIS - Misconduct&#x20;
* NSC - Nonspecific Crimes

</details>

Should the individual have a potential match within adverse media sources they will be flagged up for review.


# Proof of Address Upload

The proof of residential address upload is designed to be used as a secondary form of proof for the individual’s current residential address of the user. This feature requires the user to send an image or PDF file of a selected qualifying document dated within the past three months. This individual can select from the following document types:

* Telephone bill
* Tax assessment notice
* Water bill
* Electricity or gas bill
* Credit card statement

This list is configurable. No electronic checks are performed against the document, it is simply uploaded as supplementary evidence. Users can view or download this document from the Verify Portal. It is also included within the individual’s PDF report if the POA is an image file.


# Geolocation Check

The geolocation check operates by cross-referencing the geographical GPS location data from the user's mobile device with the country of residence provided.

When the geolocation check is performed, the mobile device will prompt the user to grant permission to access their device's location data. Upon permission, real-time geolocation data is captured from the mobile device, including latitude and longitude coordinates.&#x20;

The coordinates are used to determine the country where the mobile device is currently located. The identified country is then compared with the user's confirmed country of residence. If the countries match, the check will pass. If there is a discrepancy or the location service permission is denied, the check will require review.

This check can be used as an additional layer of verification to help prevent fraudulent application from overseas.&#x20;


# Upload  Documents

Mobile users can now upload both extra documents and additional documents through the Verify Mobile app. These documents will be accessible to Portal users and they can easily view and download these extra documents and additional documents along with other uploaded documents by mobile users directly and can track the number of documents uploaded by them.

### **1. View Uploaded Documents on the Portal**&#x20;

To view uploaded documents in Verify, follow these steps:

1. Go to the application cards and click on the specific individual card.&#x20;
2. On the left-hand side of the screen, navigate to the "Progress" section where you will find information about the number of documents uploaded by the individual.
3. Click on "View Documents" to access the uploaded documents. You can download the documents directly from there.

<figure><img src="/files/fu4ER3kWEGTDbNviQVa0" alt="" width="375"><figcaption><p>Upload additional documents</p></figcaption></figure>

{% hint style="info" %}
No electronic checks are performed on these documents, but this flexibility enables you to gather comprehensive information quickly. This enhances your ability to effectively verify customer details by requesting a broader range of additional documents from them
{% endhint %}

### **2. Uploading Documents in the Verify Mobile App**

Mobile users can access the **"Documents"** section by clicking on the **Docs** tab in the app. Here, they can view the list of **requested additional documents** and **Proof of Address** documents that you have asked them to provide. They also have the option to upload **Extra Documents** if they wish to submit additional information.

Click for more details on[  **Proof of Address** ](/service-information/the-checks/proof-of-address-upload)and[ **Additional Documents**](broken://pages/C6vhy3FMstwgWZVnBqqr)

<figure><img src="/files/rzyT8dqyGPt2epDiQtej" alt="" width="375"><figcaption><p>Uploading Documents by App</p></figcaption></figure>

<details>

<summary><strong>Upload Extra Document</strong></summary>

* These are documents voluntarily uploaded by the mobile user without being specifically requested by you.
* Users have the flexibility to upload these documents **even after completing** their verification journey.
* This feature helps when additional details are needed, enabling **seamless collaboration** between you and the user without back-and-forth communication.
* If, during your review, you require **more information**, you can request the user to upload extra documents directly through the app.

</details>

<details>

<summary><strong>Additional Documents / Proof of Address</strong></summary>

* These are documents that you have **specifically requested** from the user as part of the verification process.
* Since these documents are **mandatory**, users must submit them for verification to be completed.

</details>


# Source of Funds

Our Source of Funds (SOF) feature allows you to collect and manage detailed information about the origin of funds from your customers for a transaction. This process is streamlined through mobile integration, allowing for a seamless experience. You can access and manage this information through the Verify portal and configure the SOF risk scoring levels according to your business's risk appetite.

### **Mobile App workflow**

If you have a Source of Funds associated with an application, then the mobile customers should follow a short workflow:

* 1\) Provide the transaction amount
* 2\) Select the source of funds type
* 3\) Provide details and upload documentation

<figure><img src="/files/Q45yIsG3EFut16dwIgGC" alt="" width="375"><figcaption><p><strong>Mobile App Workflow for SOF</strong></p></figcaption></figure>

**Step 1: Prompt to provide transaction amount**

* Request customers to provide details about the transaction amount through the Verify mobile app.
* If the customer knows the transaction amount, they should enter it. However, if they are unsure about the transaction amount, they can still proceed to the next stage.

**Step2: Select source types**

* Mobile customers select the most appropriate source type(s) for their specific transaction from the given list. Such as Income (Employment Income, Business Income, Rental Income), savings / ISA, gifts, and others.
* Mobile customers can select one or more SOF types from the given list.

**Step 3: Upload documentation**

* Mobile customers can upload documents to evidence each selected source type. This step is optional but recommended for thorough verification.

***

### **Portal Overview**

Once your customer has provided the source of funds information via the mobile app, you can view the information on their record through the Verify Portal. The information is divided into three sections:

<figure><img src="/files/1zyuU7im3xga1jP9nFM5" alt="" width="375"><figcaption><p>Portal overview</p></figcaption></figure>

**Section 1: Transaction overview**

* **Total transaction amount**: Displays the total transaction amount entered by the mobile customer.
* **Accumulative amounts**: Shows the cumulative amount for each source of funds if there are multiple sources associated with the transaction.

**Section 2: Source Types and Risk Levels**

* **Source Types**: Lists the types of sources selected by the mobile customer.
* **Risk Levels**: Displays the risk level (low, medium, or high) for each source type along with the associated amount.
* **Review Status**: Any source of funds type with a medium or high-risk level will be flagged for review, allowing you to investigate further based on your business risk appetite.

**Section 3: Source of Funds Details**

* **Details and Evidence**: Provides a detailed view of the sources of funds and the types of evidence submitted by the customer.
* **Document Download**:  Allows you to download and review the submitted documentation to ensure it is appropriate and accurate for the declared source of funds. No electronic checks are performed against the SOF document submitted by the user

***

### Source of Funds Risk Levels Configuration

You can also configure the Source of Funds as per your business requirements. This feature allows you to set risk levels and manage compliance effectively. For more information, please refer to the [SOF risk-scoring levels](broken://pages/90DN7yaDNnE67ZkSmqWc).


# UK Bank Account Check

Our UK Bank Account Check feature verifies the bank account details against the customer name and date of birth.&#x20;

The customer enters their UK bank account details (if they have one) within the mobile app. Once submitted, these details are securely processed through our verification service, confirming whether the account is valid, and belongs to the individual. The personal details are matched to the details held by the bank. The check will pass if they match.

Other attributes such, as matching address details, may also be included in the check but it is the name and date of birth that determines whether the check will pass.&#x20;

### Mobile App Workflow:

<details>

<summary><strong>Step 1: Select the UK bank account option</strong></summary>

* Select "I do not have a UK bank account" to proceed without verification.
* Provide UK bank account details for verification.

</details>

<details>

<summary><strong>Step 2: Enter  UK bank account details (If provided)</strong></summary>

If the user has their UK bank account, they must enter:

* Account Holder Name
* Sort Code
* Bank Account Number

</details>

<details>

<summary><strong>Step 3: Review bank details</strong></summary>

After entering the details, the system will display a summary of the bank account information for the user to review.

* The user can:
  * Click **"Continue"** if the details are correct.
  * Edit the information if any corrections are needed

</details>

<figure><img src="/files/5pJLVFCesxNYKfMdK7Cf" alt="" width="375"><figcaption><p>UK bank check </p></figcaption></figure>


# Income & Employment

The Income & Employment feature is designed to streamline and standardise the process of collecting detailed employment and income information from clients during onboarding. It provides a structured and intuitive method for capturing data related to multiple income sources and employment types, covering both current and previous years where applicable.

This feature enables you to gather comprehensive financial information in one centralised location. The Verify Portal automatically calculates the client’s total current income, supporting more accurate risk assessment and informed decision-making.

All data submitted by the client is securely stored in the backend, clearly presented within the Verify Portal, and included in downloadable PDF reports for use in administrative reviews and compliance audits.

<figure><img src="/files/v7qJTOGLk7Oy0Bi2NNYW" alt="" width="563"><figcaption><p>Verify Portal income &#x26; employment section</p></figcaption></figure>

***

### **Mobile App Workflow: Income & Employment Capture**

<details>

<summary>Step 1:  Access the Income &#x26; Employment Section</summary>

* Tap on the **Income & Employment** card in the mobile app to begin.

</details>

<details>

<summary>Step 2: Select Current Employment Type(s)</summary>

Choose your current employment type(s) from the predefined list:

* Employed
* Self-employed
* Unemployed
* Retired
* Student
* Other

</details>

<details>

<summary>Step 3: Provide Employment Details</summary>

Based on your selected employment type(s), the app will display a tailored set of questions in an intuitive interface. These questions are designed to collect relevant income and job-related details specific to each employment type.

</details>

<details>

<summary><strong>Step 4: Income Summary Calculation</strong></summary>

If you have selected multiple employment types, the system will calculate and display your **total annual income** by summing the values provided for each current employment entry. Only **current** employment income is included in this calculation.

</details>

<details>

<summary><strong>Step 5: Enter Previous Employment (If Required)</strong></summary>

If enabled by the admin, the app will also prompt you to provide details about your **previous employment history**, including income data for the specified number of years.

</details>

<details>

<summary><strong>Step 6: Review &#x26; Submit</strong></summary>

After completing the form, a **summary card** will be shown with all the income and employment information you have provided. Review the details carefully, then tap **“Confirm”** to submit.

Once submitted, your data is securely stored and made accessible to administrators in the Verify Portal for review, reporting, and compliance purposes.

</details>

<figure><img src="/files/GZPKR5qRyzaERPag8jUf" alt="" width="375"><figcaption><p>Mobile workflow</p></figcaption></figure>


# Data Collection and Storage

## Data Storage & Control

All data is stored encrypted in either our primary Microsoft Azure Datacentre in Dublin, Ireland or our secondary geo-redundant Microsoft Azure Datacentre in Amsterdam, Holland. No data is stored on the end-user mobile device.

All data either at rest or in transit is encrypted. At rest, data is encrypted using Transparent data encrypted (TDE) using key based AES 256 algorithm. In transit, all connection use Transport Layer Security (TLS v 1.2 or greater).

All data access is governed by role-based access control following our ‘Least Privilege’ Access Control governance policy.

Physical access control at Azure Datacentres meets or exceeds Tier 4 standards and meets all ISO 27001, HIPAA, FedRAMP, SOC 1, SOC 2, and UK G-Cloud standards.

All Tiller staff undertake full background check screening before employment and are required to undertake security awareness training every 6 months. Access Control policies are followed on any change of employment status to confirm, change, or revoke access rights.

Further information on data security can be found on our website: <https://www.tillertech.com/privacy-policy>.

## PDF Report

A customer report can be generated for all clients that have been processed. The PDF can be downloaded directly from the browser by an authorised user from the Verify by Tiller Portal. The PDF contains all information captured against the individuals and the detailed output for the verification checks performed.

## 3rd Party Services

Tiller Technologies shares individual data with 3rd party services to be able to perform verification checks. Agreements are in place with all service providers, and mutual due diligence has been completed. Each company using the Verify by Tiller services will be required to accept Terms and Conditions that stipulate how data is processed. Each end customer will need to accept an End User Terms to use the Verify by Tiller application.

## Security Testing

Security is continually tested using an in-house QA (quality assurance) team ensuring the alignment of the services to Tiller Technologies’ data security policies. A full penetration is conducted by [Pentest People](https://www.pentestpeople.com/) who are UK based cyber security company, part of the GRC Group. They are a CREST (Council of Registered Ethical Security Testers) accredited, a NCSC (National Cyber Security Centre) CHECK assured cyber service provider and a certified HM Government G-Cloud supplier. Full independent external testing is conducted at a minimum of once every 12 months.

Further information about data security is found in our Privacy Policy, Terms & Conditions and End User Terms. Tiller Technologies is a Data Processor and will conduct regular DPIAs (Data Protection Impact Assessments) for each new feature developed and deployed.


# Service Levels and Availability

## Approach

We operate the Verify by Tiller platform to be available 24/7, ensuring our service is always ready when you need it.

Our modern, cloud-native architecture provides a robust fault-tolerant platform leveraging all the benefits of a geo-redundant virtualise hosting.

The platforms design also allows us to perform updates and releases with little or no downtime scheduling or interruption to your production services. This approach of continuous deployment means the platform is constantly being improved and updated seamlessly.

We aim for and consistently exceed a 99.9% uptime availability, a testament to our commitment to reliability.

## Service Level Agreement (SLA)

Verify by Tillers Service Level Agreement, which would be included in your contract, outlines our commitment to responding to your support requests or issues. We prioritise incidents based on their impact on your operations, ensuring we address issues in the most appropriate order to get maximum benefit. The criteria being:

* **Priority 1 (Critical)**: For critical issues that severely impact your ability to use the platform, we guarantee a 2-hour response time during normal UK business hours (9 a.m. to 5 p.m.).
* **Priority 2 (High)**: For high-priority issues that cause a significant but not critical impact, we will respond within 8 hours during normal UK business hours.
* **Priority 3 (Medium)**: For medium-priority issues that have a moderate impact, our response time is 24 hours within normal UK business hours.
* **Priority 4 (Low)**: For minor issues or general inquiries, we commit to responding within 5 business days.

Please note that our defined "hours" for response times are based on our general support cover, which is from 9 a.m. to 5 p.m. UK weekday business days.

## Technical Reliability

Our system's architecture is built on a resilient, multi-region cloud infrastructure, designed to provide redundancy and failover capabilities. This ensures our platform remains robust and recoverable even in the event of regional outages. We also employ a support team that focuses on proactive monitoring, performance optimisation, and incident response, which allows us to quickly identify and resolve potential issues if they happen or even before they can impact service availability.

To achieve our high uptime, we leverage a robust DevOps culture. Our CI/CD (Continuous Integration/Continuous Deployment) pipelines allow us to deploy code changes rapidly and reliably with little manual intervention, which reduces the risk of human error and ensures a smooth, continuous flow of updates. We also utilize monitoring and alerting systems to track aspect of our platform's performance. This allows our support team to receive immediate notifications of any anomalies and take corrective action, often before a customer even notices an issue.

## Ensuring Data Integrity and Security

Beyond just availability, our commitment to reliability extends to the integrity and security of your data. The platform incorporates multiple layers of security, including encryption in transit and at rest, to protect sensitive information. We perform regular security audits, penetration testing, and vulnerability assessments to ensure our defences are robust and up to date. Our adherence to strict controls over data security, availability, processing integrity, and confidentiality. These measures provide a foundation of trust, giving you confidence not only in our uptime or recovery times but also in our ability to protect your most sensitive regulatory data.


# Security, business continuity and incident reporting

## Business Continuity

Tiller Technologies business continuity plan BCP plan exists to ensure the consistent and secure continued operation of the company in such an event. The execution of the plan be executed under our ‘Availability Management Policy’ and ‘Incident Response Procedure’. All business systems and services are cloud-based and are implemented to allow the safe and secure control access and continued operation from a remote location. This is continually evaluated and confirmed as remote working is an integral part of our business operating model.

## Incident reporting

Formal incident response policies, procedures and specific plans are in place to cover the following scenarios:

* Information Systems Service Incident
* Information Security Data Breach
* Ransomware Attack
* Virus or Malware Intrusion
* Denial of Service Incident

Incident Response plans follow the following 7-step methodology:

* Preparation
* Threat Detection
* Containment
* Investigation
* Eradication
* Recovery
* Follow-Up/Notification

All policies, procedures and plans are managed and assessed in-line with our ‘Procedure for Management Reviews’ with the objective to:

* Ensure that information security processes are conducted effectively, efficiently, and economically to the benefit of Tiller and its clients
* Identify compliance or any areas of non-compliance with the ISO/IEC 27001 standard
* Identify further opportunities for continual improvement, which may extend beyond the criteria set out in ISO/IEC 27001

Provide Tiller with internal assurance that Incident Response is effectively managed and risks to the business and its clients are minimised.

## Customer Notification

Formal incident response procedures and plans are in place to cover the following scenarios:

* Information Systems Service Incident
* Information Security Data Breach
* Ransomware Attack
* Virus or Malware Intrusion
* Denial of Service Incident

Tillers procedures and notification schedule is aligned to the requirement of the EU General Data Protection Regulation 2016 (GDPR) that incidents affecting personal data that are likely to result in a risk to the rights and freedoms of data subjects must be reported to the data protection supervisory authority by the controller without undue delay and where feasible, within 72 hours of becoming aware of it.

Any such notification would be directed to the client-nominated representative and would include the following information if known:

* The date and time that the breach was discovered
* The date and time that the breach is believed to have occurred
* The data items included e.g., name, address, bank details, biometrics etc.
* The volume of data involved
* The number of data subjects affected
* The nature of the breach e.g., theft, accidental destruction
* Whether the personal data was encrypted
* If encrypted, the strength of the encryption used
* The actions that have been taken to manage the impact of the breach
* Contact details of the person managing the breach within our organisation
* Any other factors that are deemed to be relevant


# Country Coverage Match Rates

In our address verification process, we use multiple service providers to check client address information across various countries. Each provider has a unique success rate based on the quality and availability of data sources within a specific country. Due to these differences, match rates can vary between countries and providers.

<figure><img src="/files/pXycX3hSUODGr7mY3IfP" alt="" width="188"><figcaption></figcaption></figure>

We categorise the anticipated match rate into the following bands:

<img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"> **+60% Anticipated match rate**

{% hint style="info" %}
**+60% (High Match Rate):** Countries where address verification sources are highly reliable and have comprehensive coverage.
{% endhint %}

<img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line">  **>40% Anticipated match rate**

{% hint style="info" %}
**40% - 60% (Moderate Match Rate):** Countries with fairly good coverage but may have some limitations.
{% endhint %}

<img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line">  **<40% Anticipated match rate**

{% hint style="info" %}
**<40% (Low Match Rate):** Countries with limited data sources or lower verification accuracy.
{% endhint %}

**\*** *Subject to conditions*

Please see below for the match rates per continent.

<details>

<summary>Africa</summary>

| Country                 | Country code | Expected  address match rate                                    |
| ----------------------- | ------------ | --------------------------------------------------------------- |
| Ghan&#x61;**\***        | GHA          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| Keny&#x61;**\***        | KEN          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| Nigeri&#x61;**\***      | NGA          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| South Afric&#x61;**\*** | ZAF          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |

</details>

<details>

<summary>Asia &#x26; Pacific</summary>

| Country                                                                                   | Country code | Expected  address match rate                                    |
| ----------------------------------------------------------------------------------------- | ------------ | --------------------------------------------------------------- |
| <img src="/files/Cc0iNoSgUL89b7b22tPG" alt="" data-size="line">   Armeni&#x61;**\***      | ARM          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/odWjUzeT0aJsDQEPAGlB" alt="" data-size="line">   Australia               | AUS          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/dFHMsn8a2WaICTWPN8qg" alt="" data-size="line">   China                   | CHN          | <img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"> |
| <img src="/files/5e58CsrrjtfuZVzh4qgx" alt="" data-size="line">   Hong Kong               | HKG          | <img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"> |
| <img src="/files/fDnSzfywFEgmiOw5lO28" alt="" data-size="line">   Indi&#x61;**\***        | IND          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/MWYgJ5bzQIhGyZ43ScIo" alt="" data-size="line">   Indonesi&#x61;**\***    | IDN          | <img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"> |
| <img src="/files/yQlMhxlu5uzA7vw8JVKJ" alt="" data-size="line">   Japa&#x6E;**\***        | JPN          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/mZzG3aAN0lCeOyGPIdcx" alt="" data-size="line">   Malaysi&#x61;**\***     | MYS          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/bvi0Bx5wK9VFxSTTbGFb" alt="" data-size="line">   New Zealand             | NZL          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/B46YaeLieFytUBT9cFXw" alt="" data-size="line">   Philippine&#x73;**\***  | PHL          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/A4M9gFzgGAfX5lkx5D0F" alt="" data-size="line">   Saudi Arabi&#x61;**\*** | SAU          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/rcRnjx5dJDTfmijWiuHV" alt="" data-size="line">   Singapore               | SGP          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/T3rhBWZGNGIaqAoaIAMQ" alt="" data-size="line">   Thailan&#x64;**\***     | THA          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/CQBWytIsCEjh2MpL3b7E" alt="" data-size="line">   Vietna&#x6D;**\***      | VNM          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |

</details>

<details>

<summary><strong>Europe</strong></summary>

<table><thead><tr><th width="246">Country </th><th width="136">Country code</th><th width="251">Expected  address match rate</th></tr></thead><tbody><tr><td><img src="/files/1SQzMYHnr8CsBIbQpvOl" alt="" data-size="line">   Austria<strong>*</strong></td><td>AUT</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line">  </td></tr><tr><td><img src="/files/NjYsUVl6s6W00pawRtdX" alt="" data-size="line">   Belgium<strong>*</strong></td><td>BEL</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/gg1SnMJia902SNiXhYrg" alt="" data-size="line">   Czech Republic<strong>*</strong></td><td>CZE</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/FXTNBfuknPsspdkNacKf" alt="" data-size="line">   Denmark<strong>*</strong></td><td>DNK</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/gE2IwnYcirnw39pLdkqI" alt="" data-size="line">   Finland<strong>*</strong></td><td>FIN</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/SWdtTntSnT5G9sRMxVAv" alt="" data-size="line">   France</td><td>FRA</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/8Blf5r0IKX6QPpAzVsBt" alt="" data-size="line">   Germany</td><td>DEU</td><td><img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"></td></tr><tr><td><img src="/files/klE8WqzJMsQdTBEHnrVB" alt="" data-size="line">   Gibraltar<strong>*</strong></td><td>GIB</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/FR8TSmJHiQ6dOKUMJaE0" alt="" data-size="line">   Greece<strong>*</strong></td><td>GRC</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/RjYKzUj5PUweMxKsXTAA" alt="" data-size="line">   Guernsey</td><td>GGY</td><td><img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"></td></tr><tr><td><img src="/files/4XKt4peZlRRohIsBw6ZZ" alt="" data-size="line">   Hungary<strong>*</strong></td><td>HUN</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/YW3k76JxL38Oz2BPQvk0" alt="" data-size="line">   Ireland<strong>*</strong></td><td>IRL</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/zCeFcGdHH9UYUDR9fgfD" alt="" data-size="line">   Isle of Man</td><td>IMN</td><td><img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"></td></tr><tr><td><img src="/files/5NHh51g4aUpm3PqHvPl0" alt="" data-size="line">   Italy</td><td>ITA</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/CamvLW8ce61namCfzU5h" alt="" data-size="line">   Jersey</td><td>JEY</td><td><img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"></td></tr><tr><td><img src="/files/BQn3KmJq5gA8BZX87epC" alt="" data-size="line">   Luxembourg<strong>*</strong></td><td>LUX</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/f9BnLiCJBBYsqLKAov0t" alt="" data-size="line">   Malta<strong>*</strong></td><td>MLT</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/crEEixiNgDOS6Kbfwijl" alt="" data-size="line">   Netherlands<strong>*</strong></td><td>NLD</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/mFVRmHxmU3ZjwwH6ILqo" alt="" data-size="line">   Norway</td><td>NOR</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/msbL0FuSLz9dZ9VS9dbb" alt="" data-size="line">   Poland<strong>*</strong></td><td>POL</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/UOX6kRK2NizMp548Pe3h" alt="" data-size="line">   Portugal<strong>*</strong></td><td>PRT</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/W6M2gHkEeujYHg7qs1yi" alt="" data-size="line">   Romania<strong>*</strong></td><td>ROU</td><td><img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"></td></tr><tr><td><img src="/files/5b17Bj1tGiogNVcM3LQy" alt="" data-size="line">   Slovakia<strong>*</strong></td><td>SVK</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/oO06LslKW1aQjeIDZCTG" alt="" data-size="line">   Spain<strong>*</strong></td><td>ESP</td><td><img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"></td></tr><tr><td><img src="/files/f3dhXbA1LVz3Vgg9PoNO" alt="" data-size="line">   Sweden</td><td>SWE</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/L7ozJkUrcDwpn7NqOEx3" alt="" data-size="line">   Switzerland</td><td>CHE</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/nBDYDszISMqbnPVVLclq" alt="" data-size="line">   Turkey<strong>*</strong></td><td>TUR</td><td><img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"></td></tr><tr><td><img src="/files/b5JW8DYC9uERU2Wy3zkY" alt="" data-size="line">   United Kingdom</td><td>GBR</td><td><img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"></td></tr></tbody></table>

</details>

<details>

<summary>North &#x26; South/Latin America</summary>

| Country                                                                                | Country code | Expected  address match rate                                    |
| -------------------------------------------------------------------------------------- | ------------ | --------------------------------------------------------------- |
| <img src="/files/nxpMwmdfOKpHi65ApjeY" alt="" data-size="line">   Argentin&#x61;**\*** | ARG          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/i4qse7ju0oAhJCW8u9po" alt="" data-size="line">   Brazi&#x6C;**\***    | BRA          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/3LcO1TNoFMP1VSRKpRUT" alt="" data-size="line">   Canada               | CAN          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/EetbU9uTOhk6TQwn4okP" alt="" data-size="line">   Chil&#x65;**\***     | CHL          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/boGqa4HeLv5CDKHjMcXN" alt="" data-size="line">   Colombi&#x61;**\***  | COL          | <img src="/files/YpxHmQkJakUH8WVaS1dR" alt="" data-size="line"> |
| <img src="/files/wsqBkO4Q9OiW0ex9BzwB" alt="" data-size="line">   Mexic&#x6F;**\***    | MEX          | <img src="/files/4JkOLfuITkBRxB0hnLCm" alt="" data-size="line"> |
| <img src="/files/AVTiu1rrcrn2XEgO7jhh" alt="" data-size="line">   United States        | USA          | <img src="/files/bITQXgFV063mKUEgtQrz" alt="" data-size="line"> |

</details>


# FAQS

## **Welcome to the Verify by Tiller Frequently Asked Questions (FAQs)**

Whether you are new to Verify by Tiller or looking for a deeper understanding of our platform, our FAQ section is here to provide you with quick answers to your questions.

**How to Use This FAQ**

To make navigation easier, we've categorised the questions into key areas: [General Information](/help-and-support/faqs/general-information), [Using Verify by Tiller](/help-and-support/faqs/using-verify-by-tiller), [Data Security and Privacy](/help-and-support/faqs/data-security-and-privacy) and [Billing and Account Management](/help-and-support/faqs/billing-and-account-management).

For detailed guidance, refer to our [Service Information](/service-information/what-is-verify-by-tiller) and [Guides](broken://pages/ESwIgABucUGZ3i5VC9QL) , which offer comprehensive insights into every aspect of Verify by Tiller. And if you don't find the answer you're looking for here, our dedicated support team is always ready to assist you further.

{% content-ref url="/pages/TBg1V0DCEUVXo09EBp6y" %}
[General Information](/help-and-support/faqs/general-information)
{% endcontent-ref %}

{% content-ref url="/pages/dgQQrKTILUyUXw5TAIvD" %}
[Using Verify by Tiller](/help-and-support/faqs/using-verify-by-tiller)
{% endcontent-ref %}

{% content-ref url="/pages/6cjJ7It39eHTJPKyr0oO" %}
[Data Security and Privacy](/help-and-support/faqs/data-security-and-privacy)
{% endcontent-ref %}

{% content-ref url="/pages/bwS00ztRltLOEznUvZL8" %}
[Billing and Account Management](/help-and-support/faqs/billing-and-account-management)
{% endcontent-ref %}


# General Information

<details>

<summary>What is Verify by Tiller?</summary>

Verify by Tiller is a comprehensive Know Your Customer (KYC) solution designed to simplify the identity verification, risk assessment, and compliance management processes for regulated and supervised businesses worldwide.&#x20;

Our service leverages cutting-edge technology to provide an efficient and secure way for organizations to meet their KYC, AML (Anti-Money Laundering), and CDD (Customer Due Diligence) obligations.

</details>

<details>

<summary>Who can use Verify by Tiller?</summary>

Verify by Tiller is built for regulated and supervised businesses across various industries, including finance, real estate, legal, and healthcare sectors that require stringent identity verification and compliance checks. Our platform is suitable for organisations of all sizes, from small businesses to large enterprises, looking to streamline their KYC processes.

</details>

<details>

<summary>In which countries is Verify by Tiller available?</summary>

Verify by Tiller offers its services globally. While our core services are available in multiple countries, the availability of specific checks and features may vary based on local regulations and data sources. For detailed information on country-specific services, please refer to our [Documents and materials](/help-and-support/documents-and-materials) area or contact our support team.

</details>

<details>

<summary>How does Verify by Tiller integrate with existing systems?</summary>

Verify by Tiller is designed for seamless integration with your existing systems via a robust set of APIs. This enables a straightforward setup process and allows for the automation of KYC checks within your current operational workflows. Detailed documentation and support are available to assist with integration, ensuring a smooth adoption of Verify by Tiller into your services. Please see our [API Documentation](https://verify-doc.tiller-verify.com/verify-by-tiller-api-documentation).

</details>

<details>

<summary>What makes Verify by Tiller different from other KYC solutions?</summary>

Verify by Tiller stands out due to its comprehensive suite of checks, ease of use, and commitment to security and privacy. Our platform combines identity document verification, biometric and liveness checks, international address verification, and more, all within an intuitive user interface.&#x20;

For more information, please contact a member of our team at <info@tilletech.com>.&#x20;

</details>

<details>

<summary>Has there been any independent review or due diligence conducted of your service?</summary>

Yes, following an extensive due diligence process, Verify by Tiller was granted accreditation by the ICAEW (the Institute of Accountants for England and Wales) in 2023 for providing electronic identification services for their member accountancy firms. The due diligence report is available on request from us, or from the ICAEW. \
\
In addition, BDO Jersey has conducted a review of our service in relation to the requirements of the Jersey Financial Services Commission (JFSC) regulatory handbook. This report can be viewed here [BDO23-EIDV Summary ](/help-and-support/documents-and-materials)

</details>

<details>

<summary>Can Verify by Tiller be customised to meet specific business needs?</summary>

Verify by Tiller offers some customisable elements to meet the specific needs of your business. From selecting specific verification checks to customising some of the branding within the mobile app, our platform can be tailored meet a broad range of requirements. Our team is available to discuss customisation options and help you configure the best solution for your business.

</details>

<details>

<summary>How do I get started with Verify by Tiller?</summary>

Getting started with Verify by Tiller is straightforward. You can sign up through our website, where you'll be guided through the process of setting up your account and starting your first verification checks. For detailed instructions and tips for getting started, please refer to our [Getting Started](broken://pages/IyrAgD840oYzJy6bihZd) guide or contact our team at <info@tillertech.com>.

</details>

<details>

<summary>What devices does the Verify app work on?</summary>

The Verify app by Tiller is accessible on both iOS and Android devices, offering users flexibility and convenience across various platforms. Please ensure that your devices are compatible

1. **iOS Devices:**

   Compatible with iOS 15.8 or later versions, users can download the Verify app from the Apple App Store to experience its features seamlessly on their Apple devices. To access our app on the App Store, please [**click here**](https://apps.apple.com/gb/app/verify-by-tiller/id1645063264).
2. **Android Devices**

   The Verify app is fully supported on Android 11 and above. While it may function on older Android versions, we recommend upgrading to Android 11 or higher for optimal performance and security. To access our app on the Google Play, please [**click here**.](https://play.google.com/store/apps/details?id=com.tiller.wealthxcel.verify\&hl=en\&gl=US)

These versions are selected because they receive regular security updates from Google and iOS, guaranteeing the safety of your data and providing a secure and reliable user experience. Please note that tablet devices are not currently supported.

</details>

<details>

<summary>Does every passport have NFC technology?</summary>

NFC (Near Field Communication) technology is not available on every passport. NFC-enabled passports, also known as biometric passports or ePassports, are a newer type of passport that contains an embedded chip with the passport holder's personal information. While many countries have adopted ePassports, not all passports are ePassports, and even in countries that issue ePassports, not all passport holders may have one. You can normally tell if your passport is an ePassport if you are able to use an E-gate at an airport, or you can see the metallic embedded chip in the pages.

</details>

<details>

<summary>Why I can't scan my NFC chip?</summary>

If you are having issues scanning your passport's NFC chip through your mobile phone, please ensure that there are no physical barriers to prevent a successful scan. Please remove your mobile's cover or anything that would interfere with the magnetic field required to activate the chip and enable it to send the required information.

</details>

<details>

<summary>Can I leave the app part-way through the checks, and continue at a later time?</summary>

Yes, you can leave the app the app at any time and complete your checks at a later time. As long as you have your access code or request a new code to be sent by e-mail, you can use that to pick up where you left off. Just simply type that code onto the app and you will be able to complete any outstanding checks for as long as these are retained.

</details>

<details>

<summary>What is KYC?</summary>

Know Your Customer ('KYC') processes are designed to protect financial and other institutions against fraud, corruption, money laundering and terrorist financing. For companies in regulated, supervised, or high-value industries, KYC is a legal requirement as part of working with a new or existing client.

</details>

<details>

<summary>What is a PEP?</summary>

A 'PEP' is a politically exposed person. They are usually an individual who holds a prominent public position or role in a government body or international organisation. Many PEPs hold positions that can be abused for the purpose of laundering illicit funds or other offences such as corruption or bribery and are therefore considered to represent a higher compliance risk. As a result, businesses must perform enhanced due diligence when dealing with PEPs to prevent the misuse of their services for illegal activities.

</details>

<details>

<summary>What is the purpose of the NFC chip in passports?</summary>

NFC-enabled passports are also known as ePassports or biometric passports, and they typically contain a digital photo of the passport holder as well as other biometric data such as fingerprints or facial recognition data. This information is securely stored on the NFC chip and can be accessed by authorised parties using NFC technology, which provides a secure and convenient way to verify the identity of the passport holder.

</details>

<details>

<summary>What is a liveness test check?</summary>

A liveness test check is a security feature used to confirm that the individual being verified is physically present and not a fraudster using a photo or video to impersonate the person.

A liveness test check can be conducted using various methods, such as asking the individual to blink or move their head, or perform a certain facial expression. The goal is to ensure that the individual is a real person and that the verification process is not being bypassed by someone attempting to use fake images

Liveness test checks are commonly used in identity verification processes, particularly in higher-value industries, to prevent fraud and identity theft.

</details>

<details>

<summary>Does the electronic address verification service work internationally?</summary>

Yes, in addition to comprehensive UK population coverage, we also cover many of the other developed countries, as part of the service. For country coverage, please see our[ **country coverage documents**](/help-and-support/documents-and-materials#country-coverage-and-address-coverage-match-rate)**.**

</details>

<details>

<summary>How does the electronic address verification service work?</summary>

In our international address verifications, we verify the customer's current residential address by cross-checking it against multiple reliable international data sources to ensure that they are a genuine resident at that address.

There are two parts to this function.&#x20;

1. **Step 1:** In the Verify by Tiller mobile app, customers choose their country of residence and input the first line of their address or postal/ZIP code. They then select their address from a list of properties to confirm its existence.
2. **Step 2:** Once the property's existence is confirmed, we use the customer's name and address to search 'regulatory-quality' databases. These databases include utilities (excluding mobile phones), credit reference agencies, and government sources. Verify by Tiller conducts searches across up to independent data sources and provides the results of each search through the Verify Admin Portal.

</details>

<details>

<summary>What type of address verification documents are acceptable by Verify by tiller?</summary>

Verify allows you to upload a range of proof of address documents that typically range from Telephone Bills, Water Bills, Electric and/or Gas Bills, Tax Assessment Notices and Credit Card/Bank Statements. However, to ascertain any specific requirements, you should inquire with the company you're dealing with and Verify will accommodate for those documents to be uploaded.

</details>

<details>

<summary>Geolocation - Why must I share my location?</summary>

Geolocation is a term defining the process or technique of identifying the geographical location of a person or device by means of digital information processed via the Internet. This will enable us to clearly ascertain the place an individual accesses their application through their smart device. Please ensure that you disable any V.P.N.s on your smart device so Verify may do this accurately.

</details>

<details>

<summary>How can I use the Verify app if I don't have a smart phone</summary>

You can use any compatible mobile device to complete your actions - even if it belongs to a friend, relation, or business. No data is stored locally on the device and all your information is sent securely one way to us. Once you have completed inputting your details and it is sent to us, all information is automatically deleted from the phone. This ensures that you can use another person's phone while keeping your data safe.

</details>

<details>

<summary>What is KYC and why is it important?</summary>

KYC is a regulatory requirement for financial institutions and other businesses to verify the identity of their customers. The objective of KYC is to prevent identity theft, fraud, money laundering, and terrorist financing. KYC involves collecting personal information and documents from your customer to verify their identity and assess their risk profile. The KYC process helps businesses to identify and manage potential risks associated with their customers, comply with legal and regulatory requirements, and protect their reputation. Failure to comply with KYC requirements can result in fines, legal action, and damage to the business's reputation.

</details>


# Using Verify by Tiller

<details>

<summary>How do I navigate the Verify Portal?</summary>

The Verify Portal is your central hub for managing customer verifications. It features an intuitive interface with sections for Applications, Application View, Participant View, My Profile, and Settings.&#x20;

You can start new applications, view ongoing checks, manage your profile, and customise settings. Navigation is straightforward, with each section accessible from the main dashboard. For a detailed walkthrough, refer to our [Navigating the Portal](broken://pages/0fdXn8YooIJ4Gx14ov05) guide.

</details>

<details>

<summary>What checks can Verify by Tiller perform?</summary>

Verify by Tiller conducts a wide range of checks to ensure comprehensive KYC compliance, including:

* Identity document verification
* Biometric face match and liveness check
* International address verification
* PEP (Politically Exposed Person) & sanctions screening
* Adverse media screening
* Secure proof of address upload
* Geolocation check&#x20;

These checks are designed to provide a thorough assessment of an individual's identity and risk profile, adhering to global compliance standards. For details information on the checks performed please see [The Checks](/service-information/the-checks) section of the service information.

</details>

<details>

<summary>How does the whole process work?</summary>

* **Step 1:** The first step is to invite your customers to start their KYC checks from within the Verify Admin Portal. Use the 'New Application' button to create a new application - there are then 2 small forms to complete on your customer. When you are ready, you can then use the system to send an email invitation to your customer.&#x20;
* **Step 2:** Verify by Tiller will then send an automatic email containing a one-time-use input code to your customer, inviting them to download the Verify by Tiller mobile app enabling them to begin their KYC journey on their mobile device.&#x20;
* **Step 3:** Having downloaded the relevant mobile app, the customer is provided with a guided journey to enable them to provide and complete their required KYC tasks.&#x20;
* **Step 4:**  All information and verifications from your customer's checks are fed back into the Verify Admin Portal for your staff to review.&#x20;
* **Step 5:**  When you have completed your review of the information provided, you can download the full report on your customer to retain for your records.

For a detailed walkthrough, refer to our [**What is Verify by Tiller** ](/service-information/what-is-verify-by-tiller)guide.

</details>

<details>

<summary>How does the mobile app work for end-customers?</summary>

The Verify by Tiller Mobile App streamlines the verification process for end-customers. Upon receiving an invitation, customers download the app and enter their unique code. They are then guided through a series of steps to provide the necessary information and complete required actions, such as capturing ID documents and performing biometric checks. The app is designed to be user-friendly and secure, ensuring customers can easily and safely complete their verifications. Please see [The Verification Journey](broken://pages/gAPX8iRYPzrl4TywuRw8) guide.&#x20;

</details>

<details>

<summary>Can I use Verify Portal on my tablet?</summary>

Regrettably, our Verify Portal is incompatible with tablets, and certain features may not work correctly. We recommend accessing the portal from a laptop or computer using any compatible web browser for optimal performance.

</details>

<details>

<summary>What is the process for verifying identity and other credentials?</summary>

The verification process begins when a business initiates an application through the Verify Portal. Each participant (end-customer) receives an email invitation to download the Verify by Tiller Mobile App and complete their part of the verification process. This includes capturing ID documents, performing biometric checks, and providing any additional required information.&#x20;

Once all participants have completed their tasks, the business user can review the results in the Verify Portal and make informed decisions based on the comprehensive reports generated by the system. A PDF report can be downloaded and stored against your client record.

</details>

<details>

<summary>How long does a typical verification take?</summary>

The duration of a verification process can vary depending on the number of checks required. However, most verifications are completed within 5-10 minutes by the end customer. Once they have provided all necessary information through the mobile app, the results will be made available, and the user will receive an email notification.

</details>

<details>

<summary>Can I track the progress of verifications?</summary>

Yes, the Verify Portal allows you to track the progress of each verification in real-time. You can see which stage of the process an application is in, whether actions have been completed by the participants, and the status of each check.&#x20;

This visibility ensures you are always informed about the status of your verifications and can take action as needed. Please see the [Review Individuals](broken://pages/N2jZNeJHMxvWBHpwGSTQ) guide for more details.

</details>

<details>

<summary>What happens if a verification fails?</summary>

If a verification fails or requires further review, the Verify Portal will provide detailed information on the specific checks that did not pass and the reasons behind it. Businesses can then decide on the next steps, which may include requesting additional information from the participant or rejecting the application based on the risk assessment. Support is available to guide through any necessary follow-up actions but it can depend on your business process.

</details>

<details>

<summary>What type of identification document is acceptable by Verify by tiller</summary>

We accept ID documents from approximately 150 countries. At present, we accept a passport, driving licence, or national identity card as forms of identification. However, a passport is the preferred option as we can access the embedded information in the passport's 'NFC chip' which yields more accurate results.

</details>

<details>

<summary>Which browsers does Verify Portal support?</summary>

The Verify Portal supports all the main browsers such as Google Chrome, Mozilla Firefox, Microsoft Edge, and Safari. It's important to note that different features and functionalities may work differently on different browsers, so it's always recommended to use the latest versions of supported browsers for optimal performance and security.

</details>

<details>

<summary>Why do my clients need to complete these actions on their mobile devices?</summary>

Clients are required to complete actions on their mobile devices through our Verify by Tiller app to facilitate Know Your Customer (KYC) checks on behalf of your organisations or businesses. These actions typically involve providing personal details, address information, identity documents, and proof of address. By completing these actions, we can conduct necessary checks and generate comprehensive reports for your organization or business, ensuring compliance and security.

</details>

<details>

<summary>Why do my clients need to complete their personal details again on their mobile devices?</summary>

Your client's personal details are key to a number of the checks that we perform on behalf of the organisation or business. We also want to check that they have the correct details on your record and the ID document they have submitted.

</details>

<details>

<summary>Will the checks performed by Verify by Tiller will affect my customer credit score?</summary>

No, whilst we may access information held on you by credit reference agencies as proof of address source, this does not affect your credit score.

</details>

<details>

<summary>How can I optimise the Verify by Tiller mobile app to capture my clients' details effectively?</summary>

As part of verifying your client's identity, they will be given a set of instructions to take a photograph of their identity document. They need to follow the instructions within the app, to maximise the clarity and accuracy of this photograph. Please therefore avoid using the app under direct overhead lights, as this can cause glare. Please refer for more detail

</details>

<details>

<summary>How many individuals or participants can I add under one 'reference'?</summary>

You have the flexibility to add as many individuals or participants as you wish under a single common reference. This allows joint accounts or groups of customers to be processed together under the same reference, without any restrictions on the number of participants. To add individuals, click on the "+ Add Individual" button and input their information. However, if you prefer each customer to have their own personal reference, ensure that each customer invite is sent separately under a new reference, rather than grouped under one application reference.

</details>

<details>

<summary>How can I modify the information of an individual in the application before sending them an invite?</summary>

Currently, If you wish to modify any details on a newly created application such as the title, reference, consultants, or personal information of an individual before sending them an invitation, you will need to remove the existing participant and add a new one with the accurate details.

</details>

<details>

<summary>How long does it take for my customer to get the email invite from Verify by Tiller</summary>

When you send the invitation from the Verify Portal, your customer will receive the welcome email within a few seconds.

</details>

<details>

<summary>Can I edit my applicant information after sending the invite?</summary>

Currently, once you have sent the invite, it is not possible to edit the application. However, you can delete the existing application and create a new one if necessary.

</details>

<details>

<summary>How to create a new application?</summary>

If you already have the client's personal details to hand, you can create an application within minutes by following the simple steps.

* Click on the "New Application" icon to begin the process.
* Fill out the application type to specify the purpose and requirements of the new application.&#x20;
* You'll then be prompted to add individuals to the application. Enter the personal details of your customers or other relevant parties.&#x20;
* If you don't need to add more individuals to the same application, click "Next."
* &#x20;Finally, click on "Save & Send Invite" to complete the process.&#x20;

Your client will receive a welcome email with instructions on how to download the app and perform any required checks. For a detailed walkthrough, refer to our [**Creating a New Applications** ](broken://pages/5IkDGSVJVIaKW2k93pQa)guide.

</details>

<details>

<summary>How can I delete an individual from an application with multiple persons?</summary>

You can delete individuals at any status in the application process. However, if they have already begun the verification process, you may be charged for that part of the check. Please follow the following steps.

* Click on the relevant application.&#x20;
* Select the individual you wish to delete. It will prompt you to the individual page.&#x20;
* Click on the "..." icon displayed vertically on the top right-hand side of the screen. It will prompt you to the individual page.
* Select the "Delete" option which is highlighted in red.&#x20;

Before deleting the individual, make sure that you have confirmed your decision, as this is an irreversible action and all information about the individual will be permanently removed.

</details>

<details>

<summary>How do I archive an application?</summary>

* When an application is in the "New" stage, it can only be deleted, not archived.
* Once it progresses to the "In progress" stage or beyond, you can archive it by accessing the application and clicking the "Archive" button, located within the "..." menu displayed vertically on the right-hand side next to the Userr drop-down menu. This button is highlighted in red for easy identification.

<img src="/files/528VmzlJYRbAymQSJ5a8" alt="" data-size="original">

* Archived applications remain accessible for viewing but are filtered out of the normal list of applications by default.
* It's important to note that once an application is archived, it cannot be restored. Once it's in the Archive, it will remain there permanently.

</details>

<details>

<summary>For how long are applications retained in the archive?</summary>

The maximum amount of time that an application can exist in the Verify portal is 8 weeks, irrespective of status. Any application created 6 or more weeks ago, regardless of its status will automatically be moved to Archive, where it will be retained for a further 2 weeks before auto-deletion. However, if the application was manually archived, then it is retained for a maximum of 8 weeks (in total), before being automatically deleted from the system. Please ensure that you always download the customer report to your records so that you have a permanent record for your customer file.

</details>

<details>

<summary>How do I add more users to my Verify Admin Portal?</summary>

You can add users by accessing the "Settings" button (cogwheel icon) and selecting the "Users" tab. Click "Invite user" to send an invitation. For more details, visit the [**Managing Users** ](broken://pages/vElAWuJIPz41rl3KbvsR)guide.

</details>

<details>

<summary>Why do I need to set up 'consultants' within the Verify Admin Portal?</summary>

We think of 'consultants' as the customer-facing persons within your firm (e.g. sales salespeople, law partners, accountants etc) who are actually dealing with the customer. Adding their names into the system, then allows you to 'link' their name to an application and filter for any applications associated with that person for easy reference

</details>

<details>

<summary>How many consultants can I add into the system?</summary>

You can add as many consultants as you like. To do so, simply click the "Add a new consultant" on the "Select consultant" drop-down menu within a new application and fill out their information.

</details>

<details>

<summary>If I accidentally delete an application, is there a way to retrieve it?</summary>

No, once an application is deleted, it cannot be recovered.

</details>

<details>

<summary>Why do I need to take a picture or upload an image of a proof of address document</summary>

In addition to using digital technologies to confirm whether you live at your stated address, we also want to capture an image of a utility bill, or similar, in order to further prove that you live at your stated address.

</details>


# Data Security and Privacy

<details>

<summary>How does Verify by Tiller ensure data security?</summary>

Verify by Tiller prioritises data security through multiple layers of protection. All data, both at rest and in transit, is encrypted using advanced encryption standards, including AES 256 for data at rest and TLS v1.2 or greater for data in transit.&#x20;

Our infrastructure is hosted in secure data centers with strict access controls. Regular security testing, including penetration testing, is conducted to ensure ongoing resilience against threats. Please see more information in the [Security, business continuity and incident reporting](/service-information/security-business-continuity-and-incident-reporting) section within service information.

</details>

<details>

<summary>What data is collected by Verify by Tiller, and how is it used?</summary>

Verify by Tiller collects data necessary to perform KYC, AML, and CDD checks. This includes personal identification information (PII) such as full name, date of birth, residential address, email address, ID document images, biometric data (for liveness and face match checks), and geolocation data.&#x20;

This data is used solely for the purpose of verifying the identity of individuals and assessing related risks as part of the compliance process. Data usage is in strict adherence to our [privacy policy](https://www.tiller-verify.com/verify-privacy-policy) and applicable laws.

</details>

<details>

<summary>How long does Verify by Tiller store data?</summary>

Verify by Tiller stores customer data for a period necessary to fulfill the KYC checks, after which the data is securely deleted. Typically, customer data is automatically deleted from our systems 8 weeks after the completion of the verification process, ensuring that sensitive information is not retained longer than necessary. This retention policy is designed to balance regulatory requirements with privacy considerations.

</details>

<details>

<summary>Does Verify by Tiller share data with third parties?</summary>

Verify by Tiller shares data with third-party services only to the extent necessary to perform the required verification checks. All third-party service providers are rigorously vetted and bound by strict data processing agreements that ensure compliance with data protection laws and the security of the data being processed. Our commitment to user privacy prohibits the sale of data to third parties for marketing or any non-essential purposes.

</details>

<details>

<summary>What measures are in place to protect user privacy?</summary>

Verify by Tiller employs a comprehensive set of privacy measures, including data minimisation and strict access controls. We adhere to the principles of GDPR and other data protection regulations, ensuring that users have control over their personal information. Users can request access to, correction of, or deletion of their personal data as per applicable laws.

</details>

<details>

<summary>How can users ensure their data is being handled securely?</summary>

Users are encouraged to review Verify by Tiller's [privacy policy](https://www.tiller-verify.com/verify-privacy-policy) for detailed information. Additionally, users should secure their accounts using strong, unique passwords and remain vigilant against phishing and other types of online fraud. For any concerns or questions about data security and privacy, our support team is available to assist.

</details>

<details>

<summary>What happens in the event of a data breach?</summary>

In the event of a data breach, Verify by Tiller has established incident response procedures to quickly address and mitigate any potential impact. Affected users will be notified without undue delay, along with relevant authorities as required by law, providing details of the breach and the measures taken to address it. Continuous monitoring and improvement of our security practices ensure the highest level of data protection.

For more information on this process, please see the [Security, business continuity and incident ](/service-information/security-business-continuity-and-incident-reporting)reporting section of the service information.

</details>


# Billing and Account Management

<details>

<summary>How is Verify by Tiller priced?</summary>

Verify by Tiller employs a transparent pricing model based on the volume of checks and the specific services used. Pricing can vary depending on the types of verification checks required, the volume of verifications, and any custom features or integrations needed.&#x20;

For detailed pricing information, please contact our sales team on <info@tillertech.com> for a quote.&#x20;

</details>

<details>

<summary>How are payments processed, and which payment methods are accepted?</summary>

Currently, you will receive an invoice each month based on the usage. Some agreements may pay a fixed monthly or annual rate depending on the agreement with the user.&#x20;

Payments are currently made by bank transfers but we are currently implementing a payment gateway.

</details>

<details>

<summary>Who can I contact for billing issues?</summary>

For any billing issues, our dedicated support team is here to help. You can reach out via email on <support@tillertech.com> or phone on 020 3196 0365 for assistance.

</details>

<details>

<summary>Will I be charged if I have deleted the individual?</summary>

It depends. If you have instructed Verify by Tiller to send the invite out to your customer and he/she has already completed their checks, then unfortunately you will be charged. If the check have not been completed, then you can delete the customer and there will be no charge.

</details>

<details>

<summary>Is there any charge for adding more users, and is there a maximum number allowed?</summary>

Adding users to the system is free of charge, and there is no maximum limit on the number of users.

</details>


# Support & Training

**Business Hours:**  Monday to Friday, 9:00 am – 5:00 pm.&#x20;

**Number:** 020 3196 0365

**Support email:** <support@tillertech.com>

**Please feel free to book a training session with one of our team:**

{% embed url="<https://meetings.hubspot.com/jonathan-ripper/verify-training-session>" %}


# Documents and materials

## BDO Guidance Note&#x20;

{% file src="/files/eZQPe5D75oEjZdx6FH6d" %}
BDO Guidance Note for the registered persons who are considering the use of electronic methods of identification and verification in their business.
{% endfile %}

***

## Country Coverage and Address Coverage Match rate&#x20;

{% file src="/files/Sv2pdvU7b5P7YCyahcwH" %}
Country coverage match rate
{% endfile %}

{% file src="/files/7r8Hy5R5O7uYHi9GeW1f" %}
Address verification country coverage
{% endfile %}

{% file src="/files/VDC59gbwnCLX309YEDP0" %}
ID Verification Supported document type&#x20;
{% endfile %}

***

## User Guidance Document&#x20;

{% file src="/files/jGAYoJF0h7b1GOCEe4aW" %}
User guidance (Portal and app)
{% endfile %}

{% file src="/files/F2jbIO6HuORDWVRRmnWz" %}
How to read your PDF report
{% endfile %}


# Release Notes

## Current release

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 2.8.5  (20 July 2026)</strong></em></summary>

### Overview

Verify v2.8.5 is all about making what you already use work better. Version 2.8 brought a lot of new capability, so this release focuses on fixing and polishing it. We have resolved 106 issues across forms, company information, and Profile records, and the Verify Portal now has a cleaner, more consistent look. The mobile app and ID document scanning have both been improved, and address verification now covers 69 countries. You do not need to do anything to get any of this.

### Features

#### A Refreshed Verify Portal

The Verify Portal has a cleaner, more consistent look. Only the appearance has changed, so everything works exactly as it did before. It should simply be easier on the eye when you are working through a long list of records or reviewing a case.

What's new:

**Consistent status badges** The status shown against an application now looks the same wherever you see it, whether on a list, a detail page, or a Profile.

**Clearer person and company icons** The icons that tell you whether a record is a person or a company now appear in the same place and style throughout, so you can see at a glance what you are looking at.

**Tidier tables and tabs** Lists and tabbed pages have been cleaned up so they are easier to read and you can see more at once.

**Small fixes** The "Date Created" column no longer overlaps the user drop-down in list view, and pop-up messages now close when you click elsewhere on the screen.

#### Editing Previous Names and Nature of Business in the Portal

You can now add and edit previous names and nature of business directly on a Profile record in the Verify Portal.

Until now, this information could only be collected by asking the company contact to submit it through the Entity Portal. That meant even a small correction needed a new request sending out. Your team can now make those changes themselves.

You can add, edit, and remove previous names on a Profile, including the ceased and change dates. You can add, edit, and remove nature of business entries, including the industry and sector choices and the written description. Every change is recorded in the Profile's history.

Nothing changes in the Entity Portal, so company contacts can still submit this information the way they do today

#### Coming Next: A New View of Screening Data

We are building a new way of showing screening data in the Verify Portal, so your reviewers can see more clearly what a match contains and the detail behind it. The preparation work for this is included in v2.8.5, and the new view itself will arrive in the next release. Nothing changes about your screening results or how you work with them in the meantime.

### Enhancements

#### Mobile App Improvements

The Verify mobile app has a set of screen improvements and fixes covering the steps your applicants work through when submitting their verification. Each step is now clearer, and we have dealt with a number of issues people told us about. The updates will arrive shortly through the App Store and Google Play, so there is nothing for you or your applicants to do.

#### Better ID Document Scanning

We have improved ID document scanning in two ways. The mobile app now gives applicants clearer guidance while they are photographing their document, and we have improved how well documents are recognised and read once photographed.

This should mean more of your applicants get a good scan on the first attempt, and fewer documents need to be checked by hand because the photo was not clear enough. The ID documents we accept are unchanged, as is the way you review the results.

#### Wider Address Verification Coverage

Address verification now covers 69 countries. Addresses in the newly added countries are checked in the same way as everywhere else and reviewed exactly as they are today. There are no settings to change and nothing you need to do.

#### Fixes and Stability Improvements

This release includes a wide range of refinements and resolved minor issues across Verify.

What you need to know:

**Forms** are more reliable. **Company information** now saves and displays correctly, including nature of business, previous names, entity details, and company adverse media results

**Profile records** have had a number of corrections, covering external references, previous name dates, and the details shown on the Profile summary

**The Entity Portal** now fills in address details automatically where they are already held on the Profile, and we have fixed several smaller issues in the Add Parties and document request steps

All of these apply automatically. There is nothing you need to do, and nothing changes about the way you use Verify.

</details>

***

## Previous releases

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 2.8  (15 June 2026)</strong></em></summary>

### Overview <a href="#overview" id="overview"></a>

Verify v2.8 delivers a significant step forward for both the KYB process and on our monitoring service in response to client feedback. The release also includes clearer address verification wording, ongoing security work, and a platform upgrade.

### Features <a href="#features" id="features"></a>

#### KYB Entity Verification Checks <a href="#kyb-entity-verification-checks" id="kyb-entity-verification-checks"></a>

As part of our phased rollout of the KYB module, refinements have been added to teh compliance checks for entity applications. When an entity completes the Entity Portal, the following checks are produced automatically.

**Entity Details Update** compares the entity details captured on the application against the details submitted by the entity contact in the Entity Portal. Any differences (entity name, registration number, date of incorporation, country, or entity type) are flagged for review, with the option to update the linked Profile on acceptance.

**Previous Names** captures any previous trading or registered names declared by the entity and can runs PEP, Sanctions, and Adverse Media screening on each one, surfacing any matches for review before acceptance.

**Nature of Business Risk** assesses the entity's declared industries and sectors against the risk levels you have configured in Settings, alongside the nature of business narrative. Medium and high-risk selections are flagged for review.

**Address Update** compares the addresses submitted by the entity against the addresses held on the Profile. Any changes or new addresses are flagged for review, with the Profile updated on acceptance.

**Associated Parties** takes a point-in-time snapshot of all associated parties (individuals and entities) and assesses risk based on both the **entity type** and the **relationship type** for each party, against your configured risk levels.

Each check provides a clear set of details, an Accept or Reject with reason decision, and a full audit trail. The KYB module remains on phased rollout working jointly with clients. Please speak to your account manager for access or a demonstration.

#### Link Existing Records to a KYB Profile <a href="#link-existing-records-to-a-kyb-profile" id="link-existing-records-to-a-kyb-profile"></a>

You can now link existing Application, Screening, and Monitoring records to an Individual or Entity Profile from within the Verify Portal, where the record is not already linked to one.

From within an Application, Screening, or Monitoring record, you can now link it to an existing Profile. Once linked, the record will be visible from the Profile alongside any other records associated with it.

This makes it possible to see and manage all of a Profile's underlying records in one place, an important capability as the KYB module continues to roll out. The linking option is shown only where the record is not already linked to a Profile.

#### Monitoring Improvements <a href="#monitoring-improvements" id="monitoring-improvements"></a>

A focused set of improvements to the monitoring service, addressing the most common feedback from clients using the service.

**Monitoring alert emails are now more targeted.** Notifications are only sent when a monitoring event actually changes the record's status (from Active to Review). Alerts in which the result is excluded (and therefore does not change the record) no longer generate an email, reducing unnecessary noise.

**Alert emails now include the external reference for the monitoring record**, and a **direct link** that takes you straight to the relevant monitoring record in the Verify Portal rather than the Portal home.

**Alerts contain only the new activity for the event**, rather than restating the full alert content. This addresses commonly-reported duplication and makes it easier and faster to action each event.

**External reference on monitoring records.** You can now add and see an external reference within a monitoring record in the Verify Portal, and use it to filter the monitoring list. This makes it easier to align monitoring records with your own systems and references.

There is no action required to take advantage of these improvements - they apply to your existing monitoring records and notifications automatically.

### Enhancements <a href="#enhancements" id="enhancements"></a>

#### Clearer Address Verification Wording <a href="#clearer-address-verification-wording" id="clearer-address-verification-wording"></a>

We updated the wording shown in the Verify Portal from some of our source providers to be clearer and more user-friendly. The address check outcomes you see during review will now be easier to interpret, with less ambiguity around what each result means.

#### Platform Security & Maintenance Updates <a href="#platform-security--maintenance-updates" id="platform-security--maintenance-updates"></a>

This release also includes a range of behind-the-scenes improvements to our platform.

We completed our annual external penetration test as part of our ongoing security assurance programme.&#x20;

We have also upgraded the technology stack underpinning our verification service to keep it current, secure, and well supported.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 2.7  (11 May 2026)</strong></em></summary>

### Overview <a href="#overview" id="overview"></a>

Verify v2.7 focuses on giving your compliance team richer detail and a clearer view when reviewing screening and address verification results. This release surfaces more of the underlying screening data, improves how that information is presented, and makes it easier to review South African addresses manually where needed.

### Features <a href="#features" id="features"></a>

#### Richer Screening Results <a href="#richer-screening-results" id="richer-screening-results"></a>

We have enhanced how PEP, Sanctions, and Adverse Media screening results are presented, giving your reviewers more detail and a clearer view when completing due diligence.

A new **Record Sources** tab shows the original sources behind each matched profile, so you can verify information directly from the authoritative source. A warning is shown before you leave Verify for any external site.

**More detailed PEP information** is now displayed, including status, type, country, role, governing institution, and relevant dates. PEP results are presented in an easy-to-read card layout rather than a dense table.

**Adverse media is now better formatted**, making large blocks of text far easier to scan and review, with longer entries neatly summarised and expandable.

These improvements appear automatically in your screening results and are also included in the PDF report. There are no changes to your existing workflows.

#### South African Address Review in the Portal <a href="#south-african-address-review-in-the-portal" id="south-african-address-review-in-the-portal"></a>

When verifying South African addresses, the Verify Portal now displays the address details returned by the data source directly within the result.

You can now see the personal and residential address details found in the source, as well as the credit sources the address has been checked against. The address entered can be reviewed side by side with the source addresses.

This means that even where an electronic match is not possible, your team can review the information and reach a decision manually, rather than the check being inconclusive.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 2.6  (13 April 2026)</strong></em></summary>

### Overview <a href="#overview" id="overview"></a>

Verify v2.6 strengthens our fraud detection, expands our external API, and adds new self-service controls to the Verify Portal. This release focuses on closing fraud gaps in identity checks, giving you more flexibility when integrating Verify with your own systems, and improving the day-to-day verification workflow for your team and your customers.

### Features <a href="#features" id="features"></a>

#### South African Address Verification in Screening <a href="#south-african-address-verification-in-screening" id="south-african-address-verification-in-screening"></a>

Building on our South African address verification service, the Verify Portal's Screening module now captures the information needed to verify South African addresses directly.

When South Africa is selected during a screening with address verification, the portal will request a National ID number

This additional information enables more accurate address verification using our South African data source. The National ID is handled in full compliance with POPIA regulations, with encryption at rest and in transit.

#### Proof of Address Reset <a href="#proof-of-address-reset" id="proof-of-address-reset"></a>

Portal users can now reset the **Proof of Address** capture for an individual, making it easy to request a new document when the one provided is unsuitable, for example if it is out of date, illegible, or the wrong type of document.

When reset, the check returns to Pending, the individual's application returns to In Progress, and the previous document is removed. The individual automatically receives an email with their invitation code and a link to complete the check again, eliminating the need to restart the entire application.

#### Extended Invite Code Validity <a href="#extended-invite-code-validity" id="extended-invite-code-validity"></a>

We have extended how long invite codes remain valid, giving your customers more time to complete their verification.

Newly issued invite codes are now valid for 21 days, increased from 7 days. This applies to all new codes, including initial invites, resends, and resets.

Customer emails have been updated to reflect the new 21-day validity period. This gives recipients a more realistic timeframe to complete their verification and reduces the need to reissue expired codes.

### Enhancements <a href="#enhancements" id="enhancements"></a>

#### ID Document Recapture Detection in the Report <a href="#id-document-recapture-detection-in-the-report" id="id-document-recapture-detection-in-the-report"></a>

The recapture detection check, which identifies images that have been recaptured rather than captured directly, such as a photo taken of a screen, now appears explicitly in the identity check report.

The recapture detection result is now shown clearly as part of the ID and liveness check. Where a recaptured image is detected, there is now a specific check result that is flagged for review. This applies to both the front and back of documents where both are captured

#### Monitoring & Webhook API Improvements <a href="#monitoring--webhook-api-improvements" id="monitoring--webhook-api-improvements"></a>

For clients integrating Verify with their own systems, we have enahnced our external API to support separate ongoing monitoring webhooks.

Webhook payload versioning, so future changes will not disrupt your existing integrations.&#x20;

Multiple webhook subscriptions per organisation, each with its own endpoint. Event filtering, so you can choose to receive only the events relevant to you, including new monitoring events.

#### KYB Org Chart Relationships <a href="#kyb-org-chart-relationships" id="kyb-org-chart-relationships"></a>

As we continue to roll out our KYB (Know Your Business) capability, you can now add relationships within the Org Chart in the Verify Portal.

Refinements include easier linked of profile (entities and individuals) to help represent ownership mapping. This is part of our continued KYB enhancements.

#### Platform Performance & Security Updates <a href="#platform-performance--security-updates" id="platform-performance--security-updates"></a>

We have carried out a round of behind-the-scenes updates to the technology underpinning the Verify Portal, keeping our platform secure, stable, and up to date. There is no action required and no change to the way you use Verify.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 2.5  (2</strong></em><strong>3 February 2</strong><em><strong>026)</strong></em></summary>

## Overview:

Verify v2.5 introduces significant enhancements to our screening capabilities, mobile experience, and platform configuration options. This release focuses on improving verification accuracy, expanding device support, and giving administrators greater control over their Verify setup.

## Features:

#### Enhanced PEP, Sanctions & Adverse Media Screening <a href="#enhanced-pep-sanctions--adverse-media-screening" id="enhanced-pep-sanctions--adverse-media-screening"></a>

We have upgraded our PEP (Politically Exposed Persons), Sanctions, and Adverse Media screening capabilities to provide more comprehensive global coverage and improved match quality.

**Key improvements include:**

* Access to more comprehensive global screening databases
* Improved match accuracy with reduced false positives
* Enhanced data fields and risk indicators
* Superior coverage across key jurisdictions

This enhancement applies across all modules: Applications, Screening, and Monitoring. There are no changes to your existing workflows, you will automatically benefit from improved screening results.

#### South African Address Verification <a href="#south-african-address-verification" id="south-african-address-verification"></a>

We have introduced an enhanced address verification service for South Africa, providing superior coverage for South African addresses.

**What you need to know:**

* When verifying South African addresses, the mobile app will now request a National ID number
* This additional information enables more accurate address verification
* The National ID is handled in full compliance with POPIA regulations, with encryption at rest and in transit

This feature will appear automatically when South Africa is selected as the country during address verification.

#### Tablet Support <a href="#tablet-support" id="tablet-support"></a>

The Verify mobile app now better supports tablet devices, providing an optimised experience for iPad and Android tablets.

**Benefits include:**

* Improved layouts designed for larger screens
* Enhanced usability for verification workflows
* Full feature parity with phone experience

Users can download the latest app version from the App Store or Google Play to access tablet support.

#### Configurable Address History Requirements <a href="#configurable-address-history-requirements" id="configurable-address-history-requirements"></a>

Administrators can now configure the number of years of address history required during individual verification workflows.

**How to configure:**

* Navigate to **Settings > Application**
* Locate the new **Address History** section
* Select the required number of years (1-10 years)

This replaces the previous fixed 3-year requirement, allowing you to tailor address history collection to your specific compliance requirements.

#### Forms Condition Configuration <a href="#forms-condition-configuration" id="forms-condition-configuration"></a>

Administrators can now configure conditional logic on form sections directly within the Verify Portal, without requiring support assistance.

**Key capabilities:**

* Access the new configuration interface via **Settings > Forms**
* Define visibility rules for form sections based on previous responses
* Preview conditional behaviour before publishing
* Make changes immediately without backend intervention

This self-service capability gives you greater control over your form workflows and reduces the time to implement form logic changes.

#### Two-Factor Authentication Status <a href="#two-factor-authentication-status" id="two-factor-authentication-status"></a>

A new 2FA status indicator has been added to help administrators manage security compliance across their user base.

**How to use:**

* Navigate to **Settings > Users**
* View the 2FA status for each user at a glance
* Filter the user list to identify users without 2FA enabled

This feature supports your security compliance efforts by making it easy to identify and follow up with users who have not yet enabled two-factor authentication.

## Enhancements:

#### Improved Email Communications <a href="#improved-email-communications" id="improved-email-communications"></a>

All Verify email communications have been enhanced with improved formatting and functionality.

**Improvements include:**

* Deep links that take you directly to the relevant application or record
* Improved rendering across major email clients (Outlook, Gmail, Apple Mail)
* More consistent styling across all email templates

#### Module Access Management <a href="#module-access-management" id="module-access-management"></a>

We have introduced more granular access controls for Verify modules, allowing for flexible configuration of which modules are available to your organisation.

If you have questions about your module access configuration, please contact your account manager or our support team.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 2.4  (18 November 2025)</strong></em></summary>

## Features:

**Return URL Persistence:** A new authentication flow has been implemented that maintains URL persistence across the login process. This enables users from integrated systems to navigate directly to a specific individual or application record after authentication, eliminating the need to re-locate records post-login. This feature is particularly useful for clients using Verify alongside third-party platforms, as it allows seamless handoff directly into the relevant application or individual record in the Verify Portal.

**Conditional Logic in Forms:** Forms now support conditional logic, enabling dynamic question visibility based on previous responses. Questions can be shown or hidden based on user inputs, reducing form completion time by displaying only relevant questions.

**Mock Location and Developer Mode Detection:** The Verify mobile app now includes detection capabilities for mock location services and developer mode as part of the geolocation verification process. This security enhancement helps ensure accurate and trustworthy location verification during identity checks by detecting:

* Mock location applications or settings enabled on the device
* Developer mode enabled on Android and iOS devices

This information is transmitted to the Verify service as part of Geolocation check. Portal display of this information is planned for a future release..

## Enhancements:

**PDF Report Improvements:** PDF verification reports have been restructured to improve clarity and organisation. The Forms section now appears earlier in PDF reports, immediately after customer information. This repositioning prioritises customer-provided information (including form responses) before verification check results, providing a more logical flow of information for report readers. Additional refinements have been made to better accommodate and display information from all verification services.

**Data Retention Configuration:** A new tenant-level configuration feature has been introduced to manage data retention settings. Administrators can now configure data retention policies, including enabling or disabling retention policies and setting configurable retention periods. This capability supports compliance with data protection regulations and provides greater control over how long customer information is stored within Verify.<br>

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 2.3  (17 July 2025)</strong></em></summary>

## Features:

**Company Monitoring functionality:** Verify now supports ongoing monitoring for both individuals and companies within a single streamlined workflow. The Monitoring feature includes an enhanced dashboard with full check history and filtering options, as well as a dedicated Company Monitoring screen for managing records. This update enables clients to perform Sanctions and Adverse Media checks on companies directly in the Verify Portal, improving compliance and oversight.  For any inquiries regarding the Monitoring feature, please contact our support desk.

## Enhancement:

**Add forms to completed applications:** The Verify Portal user can assign new forms to an individual even after their application has been marked as completed. This feature removes the limitation of manual follow-ups when additional information is needed and improves the flexibility and efficiency of post-submission workflows.

**Add additional documents to completed Applications:** The Verify Portal user can now request additional documents from an individual even after they have completed the verification process in the mobile app. A new “Request Now” button in the Verify  Portal makes it easy to send requests for further documentation when needed.

**New question types in forms:** The Verify mobile app now supports additional structured question types, allowing users to provide more accurate and validated information during form completion

**New Supported Input Types:**

1. **Phone Number:** Users can select their country code and enter a numeric-only phone number.
2. **Email Address**: Captures email input with standard format validation.&#x20;
3. **Website Address:** Requires links to begin with http\:// or https\:// and disallows unsupported characters.
4. **Currency & Amount:** Users can select a currency type and input a numeric amount.
5. **File Upload:** Users can upload documents or images directly from their mobile device. Supported file types include JPEG, PNG, and PDF.
6. **Addresses:** The user can provide their address in a structured format.
7. **Country**: choose from a predefined country list for standardised input

**Dynamic currency selection for SOF:** To further enhance the white-label flexibility of the Verify mobile app, we have introduced currency selection for Source of Funds (SoF) transactions. Previously, the app defaulted to GBP for all transactions. With this update, mobile users can now select their preferred currency when entering SoF transaction amounts. This allows for a more customised and regionally appropriate solution to white-label requirements.<br>

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 2.2  (30 May 2025)</strong></em></summary>

## Features:

**Reset Identity & Liveness (ID\&V) Check:** We have introduced a new feature in the Verify Portal that allows you to reset the Identity & Liveness (ID\&V) check individually when its status is *In Review*. With this new feature, you no longer need to reset the entire application to resolve ID\&V issues. A new “Reset ID\&V” button now appears in the Individual **I**dentity & Liveness (ID\&V)  Check Overview page, enabling you to trigger the reset directly and request a new ID document submission from the applicant.

**Custom Email Templates and Domain Support:** Verify user can now configure their own custom HTML email templates for system-generated communications, and you can also send emails from your own domain, ensuring a consistent and professional experience for your users. This update offers more flexibility, improves brand alignment, and supports better compliance with your organisation’s communication policies. For more details, please contact our **Support** or **Sales team**

## Enhancement:

**Back-side ID Document Capture:** We have introduced the Back-side ID document capture feature in the mobile app for the identity & liveness check process. This enhancement enables users to capture the back side of ID documents, such as driver's license cards, ensuring that both the front and back images are captured for a more comprehensive identity review. The captured images are securely stored, made available in the Verify Portal for you to review, and included in client PDF reports for auditing and record-keeping.

**Passive Liveness check:** The Verify app now uses passive liveness technology, replacing the previous active liveness process. With passive liveness for identity & liveness check, the system verifies whether a user is real without requiring active gestures such as head tilting or smiling.&#x20;

**Deep linking service for invite email:** We have made slight but important updates to several email templates to support deep linking and improve user clarity. These changes ensure that users can seamlessly access the Verify mobile app via deep links embedded directly in the emails.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 2.15  (29 April 2025)</strong></em></summary>

## Features:

**Consultant configuration:** This update introduces a new Consultant configuration feature within the Settings area of the Verify Portal. With this enhancement, Admin users can now more efficiently manage consultant profiles, including the ability to edit, disable, or remove consultants directly through the Verify portal.

## Enhancement:

**Banner:** We have enhanced the communication banner on the Verify Portal. Previously limited to a single static message, the banner has been upgraded to a carousel-style format, allowing multiple messages or updates to be displayed for improved communication with users.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 2.1  (19 March 2025)</strong></em></summary>

## Features:

**Company Screening:** We are excited to announce a key milestone in the Verify portal with the launch of Company Screening, introduced as part of the Verify V2.1 release.

Up until now, our previous releases have focused primarily on individual KYC checks and related features. With this release, we’re taking an important first step towards offering Know Your Business (KYB) solutions. This new functionality expands the capabilities of the Verify portal, enabling our clients to conduct screening checks not only on individuals but also on business entities.

The Company Screening feature allows clients to perform Sanctions and Adverse Media checks on companies directly within the Verify portal. egic roadmap towards full KYB services.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 2.07  (04 March 2025)</strong></em></summary>

## Features:

**UK Bank Check:** We are pleased to introduce the UK Bank Check feature in the Verify by Tiller process. This feature allows users to provide their UK bank account details within the mobile app, if requested, as part of their mobile action journey.

Once submitted, these details will be securely verified through our Bank Check verification service to determine if the account is valid, and belongs to the individual. The results will be visible on the portal and included in the PDF report.&#x20;

## Enhancement:

**PEP result:**  We have enhanced the PEP results in the Portal by incorporating new attributes to provide greater clarity and deeper insights. The newly added attributes, including "Positions," "Relations," and "Aliases," will assist you in conducting more thorough investigations, particularly during PEP reviews.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 2.06  (28 January 2025)</strong></em></summary>

## Features:

1. **2FA configuration feature in Verify Portal:** We are excited to announce the rollout of Two-Factor Authentication (2FA) as a new feature within the Verify Portal. This enhancement is designed to strengthen account security and give users greater control over their authentication preferences.  2FA has been implemented for both the existing and the new users. All users can manage their 2FA settings through the My Profile section of the Verify Portal.

## Enhancement:

1. **Additional documents delete function:** We have introduced the delete functionality for additional documents, allowing users to easily delete additional documents they no longer require directly from the Verify Portal settings area.
2. **Splash screen customisation:** Several enhancements have been made to the splash screen for the Verify portal to provide users with greater customisation options. Such as:
   1. The users now have the ability to show or hide specific splash screen elements, *(such as the logo, welcome message, and additional information, according to their business needs)*
   2. The welcome message UI has been updated with improved wording making it easier for user to create personalised and user-friendly messages for their end users.
   3. Now users can add additional information and link to their splash screen.
   4. Users can now choose to display or hide their Terms & Conditions section.&#x20;

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 2.05  (18 December 2024)</strong></em></summary>

## Features:

1. **Customisable Form feature in Verify Portal:** We are excited to introduce the Customisable Form feature in the Verify Portal, allowing clients to design tailored forms to collect specific information from their customers during the KYC process. This feature provides flexibility with the ability to create multiple forms, each containing up to 5 sections and 10 questions per section, catering to various business requirements. Forms can be easily assigned to specific application types, ensuring they are completed as part of the verification process.  Additionally, when an application requires a form, customers will see a "form card" in the mobile app. This card allows them to complete and submit their responses directly from their mobile device.
2. **Data retention settings:** We have introduced the Data retention settings feature, designed to give portal admin users greater control over the retention, archiving, and deletion of client data while ensuring compliance with business and regulatory requirements.

## Enhancement:

1. **About section for individual view page:** The "About" section on the Individual View pages has undergone a comprehensive redesign to improve usability and provide a more organised layout. Relevant information is now displayed in clearly defined sections, making it easier for users to locate and understand the details without feeling overwhelmed by excessive data.
2. **New application type screen:** As part of the introduction of the forms feature, the Application Type page on the Verify Portal has been updated with a newly designed user interface (UI). This updated UI allows users to select a form when choosing an application type. With this enhancement, users can seamlessly add forms along with additional documents while creating an application type, streamlining the process and improving functionality.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 2.0  (21 October 2024)</strong></em></summary>

## Features:

1. **Monitoring feature:** We are pleased to announce the release of our "Monitoring feature", which enhances the Verify portal with new functionalities aimed at streamlining the monitoring process. This update includes a dedicated monitoring section for viewing and adding monitoring records, an intuitive monitoring dashboard that offers an overview of each individual's monitoring status, activation date, and latest activity, as well as advanced filters to refine searches by status and date range. For any inquiries regarding the Monitoring feature, please contact our support desk.
2. **Malware scanning for uploaded documents:** We have implemented a multi-cloud security solution to scan all uploaded documents for malware before they are accessible in the Verify Portal. After scanning, only malware-free documents are made available to users, enhancing the security of our document-handling processes.
3. **Additional document feature:** Admin can request additional documents from clients through the Verify Mobile App using an additional document feature within the Verify portal. This functionality has been integrated into both the application setup process and the settings area for configuration.

***

## Enhancement:

1. **SOF evidence required a toggler feature:** We have added an "Evidence required" toggler to the settings area of the Source of Funds risk level configuration. This feature allows users to easily enable or disable the document requirement for SOF type to align with their business needs.
2. **Uploaded documents enhancement:** The 'Uploaded Documents' section has been upgraded to showcase all documents collected during the mobile journey. Verify portal users can now easily view, and download submitted documents, all in one place. Each document is categorised by type and a filter option is available for quickly locating specific documents.
3. **Feature descriptions and user guidance links in the settings:** We have added brief descriptions for each key feature in the settings area. A "Learn More" button is also available, linking to user guidance pages where users can find detailed instructions on how to use each feature.
4. **New application type screen:** As part of our transition to a subscription model, the application type page on the Verify Portal has been updated to reflect the new subscription tiers. A new user interface (UI) has been designed, revamping the application type creation page with a multi-step process to enhance user experience. This update allows users to easily add additional documents alongside checks when creating an application type.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.6  (04 September 2024)</strong></em></summary>

## Features:

**Screening** The new "Screening" tool,  empowers businesses to conduct PEP & Sanctions, Adverse Media and Address checks on individuals without the need the customer involvement with the Verify Mobile app. A "Screening check" can be seamlessly converted into an application. This allows the user to initiate an application for the same individual reducing duplication.

**Key Features of the "Check" Function:**

1. **Dedicated "Screening" section:** A new "Screening" section has been added to the Verify portal interface.
2. **Intuitive dashboard:** Users will have access to a "Screening" dashboard that displays a summary of the individuals for whom the checks were conducted.
3. **Data entry forms**: The Verify portal now includes forms for the "Screening" feature, where you can enter client details and address information. These forms feature validations to ensure all required fields are filled out correctly before initiating the check
4. **Real-time results:** The system provides real-time results within seconds when a check is run on a client. It cross references the input data with multiple sources to verify the client's address and other critical details, which can be viewed directly on the portal.
5. **Downloadable PDF reports:** Upon completing a check, users can download a detailed PDF report
6. **Seamless conversion to application:** Based on your business requirements and risk appetite, the "Screening check" can be converted into an "Application" within the Verify portal. This allows the user to initiate an application for the same individual. Reducing duplication.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.5.3  (30 July 2024)</strong></em></summary>

## Features:

1. **Branding screen:** On the Verify Portal, admin users can now easily set up and customise the brand screen for the Verify mobile app according to their brand image directly from the settings area. This allows them to customise the company logos, text colours, and background colours, to align with their brand identity. Additionally, admins can provide a link to their company’s Terms and Conditions and Privacy Policy
2. **Previous Address:** Companies can now request previous addresses be captured as part of the add address action within the mobile app. If the customer has lived at their address for less than three years, they will be asked to provide a set of previous addresses until at least three years of address history have been added. Previous addresses are viewable within the Verify Portal and recorded in the Customer PDF Report. It should be noted that previous addresses will not be verified against the address verification service.

***

## Enhancement:

1. **Enhancements to the PEP check results table in the portal and PDF report:** We have updated the PEP checks result UI design to incorporate additional attributes in the PEP results and excluded results tables, including Country, Matching Entity, Date of Birth, and Gender, when available. Additionally, the PDF report template has been modified to include these new attributes under the PEP & Sanctions check section.
2. **Personal Details Match:** With this release, users can now view the information provided by mobile users alongside their ID document details directly on the portal and in PDF reports in the ID & Liveness section under personal details match. If there is a discrepancy, the "Personal Details Match" section will flag the personal information for review, indicating that it does not match the ID document.
3. **Enhancement in PDF report:** We have made several enhancements to the PDF report to improve clarity and detail

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.5.2  (02 July 2024)</strong></em></summary>

## Features:

1. **Source of funds:** We are thrilled to introduce the "Source of Funds (SOF)" feature in this release. This update allows clients to request and manage information about the origin of funds directly from their customers via the Verify mobile app. In the Verify portal, clients can easily view the SOF information provided by their customers and download the evidence for each SOF if provided.&#x20;
2. **Source of funds risk levels settings:** In the Verify Portal setting area, we have added a feature that allows admin users to configure risk levels for different sources of funds types. Admins are presented with a comprehensive list of Source of Funds (SOF) types and their respective risk levels, which they can adjust according to specific business requirements.
3. **New feature banner:** We have introduced new banner functionality to enhance client communication and engagement. This feature will be prominently displayed on the Verify portal to announce new releases, important updates, and critical notifications. This banner functionality, Verify v1.5.2 improves the overall user experience by delivering relevant information directly within the Verify portal.

***

## Enhancement:

1. **Proof of address file upload:** We are pleased to announce an enhancement to our Proof of Address (POA) feature by introducing the proof of address file upload. This new addition allows users to conveniently upload PDF files (in addition to images) when submitting their proof of address documents.
2. **Ul design improvement for POA:** In this update, we have enhanced the UI design features for both the portal and PDF reports, specifically focusing on the Proof of Address (POA) section within individual view pages. A key improvement includes implementing distinct designs based on the type of file uploaded, whether PDF or image.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line"> <em><strong>Version V 1.5.1  (18 June 2024)</strong></em></summary>

## Features:

1. **Document Upload:** Individuals can now upload extra documents through the Verify Mobile app, which will be accessible to Verify Portal users. This enhancement allows companies using Verify to request a broader range of documents from their customers. Additional documents can be uploaded as images or files, making the process more flexible and convenient. Verify Portal users can view and download these documents directly from the portal.
2. **Reminder Email:** We have introduced a new feature within the **‘Application Type’** settings that allows admin users to control "**auto-email reminders"** sent to mobile users who have not completed the required actions. Verify will send email reminders for up to six days if this functionality is enabled by the user for the application.
3. **Help & Support Page:**  A new Help & Support page has been added to the Verify Portal, featuring resource links (Website, Training Hub, API documentation, FAQs) and an embedded form for creating support tickets. The form enables users to quickly submit a request for help or support from our team.&#x20;
4. **PEP & Sanctions Filtering Configuration:** We are pleased to introduce new filters for our  Verify product. This update enhances the Verify Portal, allowing clients to customise and manage verification filters directly within their settings area. Users can now specify which filters to apply for PEP, Sanction, and Adverse Media checks. More detail can be viewed in PEP & Sanctions Filtering Configuration.
5. **Archive and Deletion Notifications:**  We have activated our archive and delete functionality in line with our data retention policy. Automated email reminders will notify Verify Portal users three days before their applications are archived or deleted, ensuring users are aware of impending actions and can take necessary steps if required.

***

## Enhancement:

1. **Validity Period of Invite Codes**: The expiry of invite codes has been extended to 7 days, up from the previous 24 hours. This change ensures that invite codes remain valid long enough for end customers to complete their checks.
2. **App Version Display**: The app version is now visible on the initial invite screen of the mobile app. This enhancement helps end customers identify the app version they are using, aiding in technical support queries.
3. **Settings Area Improvements**: Navigation within the settings area has been improved to enhance user experience and make the settings area more extendable for future releases, allowing for greater account customization.
4. **Individual Page Improvements**: Several enhancements have been made to the individual view page in the Verify Portal, including:
   1. **Manual/Approve Comments**: Comments from manual approvals or rejections are now displayed with timestamps, providing a clear audit trail and the reasons for these decisions, similar to the PDF report format.
   2. **Face Match Results Streamlined**: The ID Scan face match results page has been simplified with more descriptive labels. Detailed information is provided only if a result requires review, improving clarity and usability.

* **API Enhancements**: Various enhancements have been made to the API, providing more detailed information in the API documentation.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.5  (22 February 2024)</strong></em></summary>

## Features:

1. **Self-Service Application Type Management:** This update empowers clients to directly manage their application types, transitioning from a manual, backend process to a self-service model. Admin users can tailor application types to specific business needs, enhancing flexibility and efficiency. Users are automatically associated with the default Core Identity application type upon registration.

***

## Enhancement:

1. **Introducing Logout Functionality for Verify App Mobile:** In this update, we have improved the user experience by introducing a logout functionality within the Verify Mobile app for both iOS and Android platforms.&#x20;
2. **Data Deletion Request Feature Implemented on  Verify Mobile App:** Customers on mobile platforms can now request to delete their data directly from the app. Upon initiating the deletion request, an email will be automatically sent to the Business user associated with the account.&#x20;

***

## Resolved issues <a href="#resolved-issues-2" id="resolved-issues-2"></a>

1. We addressed a minor issue where some iOS devices experienced challenges uploading documents due to the new iOS software release.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.4  (24 October 2023)</strong></em></summary>

## Features:

1. **Adverse Media Check Type:** Introducing an additional Adverse Media check type, broadening the range of features available in Verify. This optional check can be added to application types at an additional cost.
2. **Manual Approval of Check Records:** We're introducing a manual review and approval process for check records, ensuring a streamlined operational flow and a robust audit trail for our clients.&#x20;

***

## Enhancement:

1. **Enhanced PEP & Sanctions:** We have enhanced the accuracy and depth of our Politically Exposed Person (PEP) and Sanctions checks! With these improvements, users will receive more detailed return data, ensuring a thorough verification process.
2. **New Individual Check Screen:** A revamped interface for individual checks, designed to enhance user navigation and provide comprehensive information. All data available in the PDF will now also be displayed on the screen within the Verify Portal. The redesigned interface aims to make reviewing and processing an application more streamlined.
3. **Database Query Optimisation:** App service upgrades and optimisations have been made to deliver a more responsive service.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.3  (24 August 2023)</strong></em></summary>

## Features:

1. **Former Names Capture**:  The system can now record any previous names a person might have used – beneficial for those who've legally changed names or used different names in various contexts. This feature adheres to JSFC KYC requirements
2. **Nationality Capture:** We can now capture and record an individual’s nationality or multiple nationalities, aligning with JSFC KYC guidelines.
3. **Place of Birth Recording**: This new feature allows the system to note an individual's birthplace, a vital component for KYC processes as mandated by JSFC KYC guidelines.
4. **New address verification source:** A new address verification source will be launched and available to Verify as part of this release. This will provide coverage to Austria, Czech Republic and Finland. It will also be used as an additional data source for another 35 countries.
5. **External API improvements:** The external APIs have been adapted to be more versatile. This is to include a smoother experience for external parties, allowing for integrations that are more tailored to their needs

***

## Enhancement:

1. **Application Overview in Table View:**  We've introduced a 'Table View' for a more streamlined look at applications, replacing the old 'Card View'. This new view simplifies management and searching for various applications. Users can filter applications based on their mandate status to swiftly identify applications requiring action.
2. **Refined Application View Page:** The application view page has been revamped for enhanced clarity and user experience.
3. **Updated Mobile SDK for  IDScan:** The mobile SDK (software development kit) has been updated, to ensure it runs smoothly and is fully compatible with the most recent version of the service provider  IDScan technology.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.2  (28 June 2023)</strong></em></summary>

## Features:

1. **UAT Environment Implementation:** Establishing a User Acceptance Testing environment to enhance release stability and ensure quality control before production deployment. This will help improve our release cycles and allow a more defined set of features per production release. The UAT environment may also be used as a test environment for third parties. This could be especially useful for our external API integration initiatives.
2. **External Facing APIs for Third-Party Integrations:** Introduction of external APIs to facilitate integration with third-party services. These services are primarily focused to be used by third-party partners but can be utilised by any tenant with an ‘external’ permission user. API documentation will be made available to parties using the APIs. This should open further opportunities for both partnership agreements and direct integrations.

***

## Enhancement:

1. **Improved Company Sign-Up:** Further information is gathered as part of the sign-up process. This includes capturing billing details, MLRO details, and expected countries of operation. This is to reduce the company set-up time, provide the accounts team with invoicing details and allow internal MI around where country expectations are.
2. **PDF Report Improvements:** Enhancements to PDF, improving the readability of the report as well as the results passed to the services. The readability of the PDF has been a common user feedback critique. We will continue to make improvements in further deployments.
3. **Improved Mobile Action Card:** The IOS mobile action card has been redesigned and reduced in size. More action cards are now viewable on the mobile home screen at one time. The action card icons have also been improved.

***

## Resolved issues <a href="#resolved-issues-2" id="resolved-issues-2"></a>

1. Our PDF reports and services are now more readable with improved results.

</details>

<details>

<summary><img src="/files/sp2XAcQijpau99pDmgT6" alt="" data-size="line">  <em><strong>Version V 1.1  (08 May 2023)</strong></em></summary>

## Features:

1. **GPS Geolocation:** A new feature that enables the collection of GPS location data from mobile users. This feature will gather the GPS location of the mobile user, store it against the individual's record, and perform a check to see if the GPS location matches the country of residential address input provided by the user.

***

## Enhancement:&#x20;

1. **No Country Coverage:** Our Verify Portal and mobile app now feature functionality that alerts clients and mobile users if the selected country is not covered by our services
2. **Optional Date of birth:** We have removed the need for the customer’s date of birth when adding them to an application. The DOB field is no longer mandatory and will only be checked against the customer if inputted.
3. **Paper Trail Logging**: Our back-end services now feature enhanced logging through paper trail logging to improve our visibility on user interactions and any errors that may arise.
4. **Email Template:** Following customer feedback, we have revised our email templates, making necessary amendments to improve user experience.
5. **Mobile app improvements:** General improvements have been made to the mobile application to enhance user experience. E.g. a new date picker has been added to our latest update enabling users to easily select a date on the app.

***

## Resolved issues <a href="#resolved-issues-2" id="resolved-issues-2"></a>

1. We have made improvements to the PDF report feature. Users can now make parallel requests for each individual PDF report in the application. Ensuring that PDF reports can be downloaded without any issues.&#x20;
2. With our latest release, the "PEP & Sanction Screening" section header icon will now display according to the result received from the service provider. This improvement allows for more accurate and efficient reporting, providing our users with a better understanding of the information presented in the PDF report.&#x20;
3. &#x20;We improved the user interface by adding the ability to select the document type and move to the next page.
4. &#x20;With our mobile app, we improved navigation on the 'Company Information' screen so users can return to the home screen easily after viewing the details.
5. The wording in the PDF report's "address verification" section has been updated based on the check results.

</details>


# Welcome to the Training Hub

At Tiller, we understand the complexities and evolving nature of Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations. That's why we've curated a range of guides to walk you through the verification journey and show you how to get the most from the Verify by Tiller's services.

{% hint style="info" %}
**Verify by Tiller:** A robust digital solution that provides high-quality customer ID verification and customer due diligence (CDD) for regulated and supervised businesses. The cutting-edge technology that powers this solution, coupled with the highest quality data sources, ensures a service of the highest regulatory standards.
{% endhint %}

{% embed url="<https://vimeo.com/868287110?share=copy>" %}
Verify by Tiller - KYC checks made simple
{% endembed %}

***

## Learn how Verify works

We've put together some helpful information to help you get the most out of the service.

{% content-ref url="/pages/gAPX8iRYPzrl4TywuRw8" %}
[The Verification Journey](/training-hub/the-verification-journey)
{% endcontent-ref %}

{% content-ref url="/pages/ESwIgABucUGZ3i5VC9QL" %}
[User Guides](/training-hub/user-guides/getting-started)
{% endcontent-ref %}


# The Verification Journey

The Verify Mobile Journey has been developed to meet the needs of businesses in various industries that require a secure and efficient way to verify the identities of their customers. This section will take you through the steps required for your customers to complete the verification process using our mobile app.

<figure><img src="/files/Z0qoxicBufvlqVyytJ11" alt=""><figcaption></figcaption></figure>

**i)  Create application and send invites:**

Create an application within the Verify Portal and add individuals. Then send the invites to these individuals. This will put the application into an 'In Progress' status.

**ii)  Invitation:**

The customer receives an email invitation with a unique invite code and instructions to download the app. The invite code is used to access the mobile app and link the customer with their application.

**iii)  Download Verify App:**

Once Verify app is downloaded from either the iOS App Store or Google Play Store, the client uses the invite code to access the app. This links them back to the application.

**iv)  Accept End User Terms:**

Before any information is captured, the customer will be asked to accept the end-user terms. These terms can be found on our website: <https://www.tiller-verify.com/end-user-terms>.

**iv)  Mobile actions:**

The customer completes the required actions on the mobile. These actions will depend on the applications checks. For example:

* Adding personal details
* Accepting location services
* Adding residential checks
* ID & Liveness capture
* Uploading proof of address

Once all actions are complete the customer will be notified. The user attached to the application will also receive an email confirming.&#x20;

**vi)  Checks run:**

Once all mobile actions have been completed, the checks will run. The application will move from 'In Progress' to either 'In Review' (one or more checks need to be reviewed) or 'Completed' (all checks passed).&#x20;

**vii) View results:**

The check results will now be available for review in the Verify Portal. You can view the application details and select an individual to view. Each check will have results that are viewable from within the portal. Please see [managing applications](/training-hub/user-guides/applications/managing-applications) and [reviewing individuals](/training-hub/user-guides/applications/reviewing-individuals) for more details.

**viii)  Download report:**

The PDF customer report will be available. This will contain the customers' provided information and check results. This should be saved back to your customers' records.&#x20;

&#x20;


# Getting Started

How to set up your Verify by Tiller account.

Get started by signing up within the Verify Portal: <https://app.tiller-verify.com/sign-up>

For more information, please follow these 4 steps:

<details>

<summary>Step 1: Set up your account</summary>

To begin, sign up for Verify by Tiller by visiting the following link: [Sign Up](https://app.tiller-verify.com/sign-up)

Fill out your user and company information. After successful registration, Tiller will then activate your account and send you a welcome email.

You will then be able to log in: [Login](https://app.tiller-verify.com/login)

If you have any question during your account set up please contact our customer support team: <support@tillertech.com>

</details>

<details>

<summary>Step 2: Invite team members</summary>

Admin users can invite team members through the settings area: <img src="/files/OGbPhjuTfUGdjaD0VF12" alt="setting cog icon" data-size="line">

Within the setting area click on the 'Users' tab:

&#x20;<img src="/files/WxeKUfzBfHA96bfQx1eN" alt="settings - user tab" data-size="original">

From here you can manage and invite new users:

&#x20;<img src="/files/9IBtuH416xD5HQguwHn4" alt="invite user button" data-size="original">

Please complete the form by adding their name, email, job title and permissions.&#x20;

* Admin - Has access to the settings areas. Can manage company and user information.
* Staff - Do not have access to the settings area.

Once complete, click the 'Send Invite' button. The user will receive an email asking them to set up their password to access the Verify Portal.

</details>

<details>

<summary>Step 3: Create your first application</summary>

You can create your first application from the applications overview screen: <img src="/files/aAeWSUc1SdM2C2Op9eM8" alt="" data-size="line">

Create a new application by clicking on this button:&#x20;

![](/files/qCphJR7YOfdhLe9S17vM)

You will then need to complete a short workflow: **Create application** >> **Add Individuals** >> **Send Invites.**

**Create application:**

Create a new application by adding an application reference, selecting the application type and adding a consultant.

* *Application reference*: This is your reference to identify and search for this application.
* *Application type*: This will determine which checks will be performed against the individuals.&#x20;
* *Consultant*: The details of the professional or consultant, this is usually the person with the relationship with the customer. This is different to the Verify Portal user.

**Add individuals:**

Add one or more individuals to the application. They will all be grouped under this application. We need some basic information to set up their record:

* Title
* Gender - Use 'Other' if unknown or unspecified.&#x20;
* First name
* Middle name(s) - Optional
* Last name
* Date of birth - Optional
* Email address - For sending the invite. Try to use a unique email for each person.&#x20;

This will create a record for each individual under this application. If you stop the process here, the application will be in a 'New' status, and you can add more individuals and send invites later.&#x20;

**Send invite(s)**

Once you have added all the individuals, you can send the invitations. ![Save and send invite button](/files/RZO0Lg0loiZB7gnIT1DT)

Each individual will receive an email asking them to complete the process using the Verify mobile app.

Once the invites are sent, the application will have an 'In progress' status. The application will move to the 'Review' or 'Complete' state once all individuals have completed the process on the mobile app.&#x20;

</details>

<details>

<summary>Step 4: Managing your applications</summary>

**Applications Overview**

Manage the progress of your applications from the applications screen: <img src="/files/aAeWSUc1SdM2C2Op9eM8" alt="" data-size="line">

The applications can be viewed in either a card or table view:

![](/files/Tkk3bQPVmkR46dN7NDK8)

Within these views, each application will have a status.

New >> In Progress >> In Review >> Completed / Rejected

* :white\_circle:**New** - The application has been created, but invites to individuals have not been sent.
* :blue\_circle:**In progress** - The email invites have been sent to participants but not everyone has completed their mobile app actions.
* :orange\_circle:**In review** - All individuals have completed the Verify App process, but at least one check needs to be reviewed.&#x20;
* :green\_circle:**Completed** - All checks have been successful, or an 'In review' application has been manually completed.&#x20;
* :red\_circle:**Rejected** - The user has rejected an 'In review' application. This status is to help manage applications that have been unsuccessful.&#x20;

The application card has some key information:&#x20;

<img src="/files/7YTVUY5SRTS8Gxev2Xdj" alt="" data-size="original">

You can search and filter the applications.&#x20;

* **Search**: The application can be searched using the reference, ID and participants’ names.
* **Filter**: The applications can be filtered by user, consultant, created date, application type and whether the application has been archived.

Select an application you wish to view from this page.

**View application**

The application view page shows key information about the application and participants associated with it. This includes general details about the application, the count of checks and their status, and the participants associated with it. ‘In review’ applications can be 'completed' or 'rejected'.&#x20;

The application view page shows key information about the application and participants associated with it. This includes general details about the application, the count of checks and their status, and the participants associated with it. ‘In review’ application can be completed or rejected from this view.

* ***Application Details*****:**  In this section, you will discover comprehensive details about the application type, its creation date, the unique ID specific to this application, and the assigned consultant. Furthermore, a deletion date is included in accordance with our data retention policy, serving as a reminder that this application is scheduled for automatic removal on that particular date.
* ***Checks In Review / Passed / Pending*****:** This displays the total number of checks for each participant in the application and their status.
* ***Participant Details*****:** Each participant will have a card where the user can view some information of each participant, including their name, actions completed, checks passed, and checks in review. Click on the participants’ cards to view their verification results.

The application view page contains actions the user can perform to manage the application:

* ***Choose Participant to View*****:** Users can select a specific participant to view their progress and the results of their checks in more detail.
* ***Add Participants (In progress status only)*****:** While an application is in progress, users can add additional participants and send them an invite.
* ***Complete/Reject Application (In review status only)*****:** Once an application is in review, users can mark it as complete or reject it based on the results of the checks and any additional information gathered. Completing or rejecting the application will change its status.
* ***Update User*****:** The user assigned to the application can be updated.
* ***Update Consultant*****:** Users can assign or change the consultant responsible for managing the clients.
* ***Archive Application*****:** Users can archive an application to remove it from the active list, while retaining the information for future reference it will no longer appear within the applications page without filtering for archived applications.
* ***Delete Application*****:** Users can permanently delete an application and all associated application and participant data, ensuring that sensitive information is permanently removed.
* ***Comment*****:** Users can add comments to an application.

You can view each individual from this application by selecting their card.

**View Participant**&#x20;

The participant page provides an in-depth view of individual information, progress tracking, and the outcomes of their checks. You can delve into the specifics of check status and review the result information.&#x20;

Checks in ‘Review’ can be manually accepted or rejected of checks as part of the review process.

On the participant page, users can access the following information:

* **Progress Section**: The customer's progress can be monitored from this section. You can&#x20;
  * View uploaded documents and request new additional document uploads.
  * Track invite status, including the invite email address and time sent.
  * Resend the invitation if required.
  * Monitor action progress (e.g. Accept Terms, Add Personal Details, Perform ID Check, etc.). Once all actions are marked as completed, checks will begin processing.
* **About Section**

  The **About** tab in the centre panel provides a comprehensive view of the participant’s information, organised into several sub-tabs:

  * **Invite Tab**: Displays the initial details entered when creating the participant's application, such as title, name, and gender.
  * **Personal Information Tab**: Shows the personal details submitted by the client via the mobile application. This includes information such as full name, nationality, and place of birth.
  * **Address Tab**: Displays the current and previous addresses, along with geolocation data, as provided by the client through the app.
  * **Financials Tab**: If applicable to the application type, this section presents financial information such as bank account details, source of funds, employment status, and income.
  * **Forms Tab**: Lists any forms completed by the client, including the questions asked and their responses. You can also request a new form if additional information is needed.

To view all information in one place, click the **"All Details"** button. This will display a consolidated view of the information from all the sub-tabs, including Invite, Personal, Address, Financials, and Forms, in a single screen for easier review.

**Check Information**

Checks are divided into three distinct stages: "Pending," "Reviewed," and "Completed," providing you with a more comprehensive understanding of their statuses.

Each check is presented in a card format, containing key information and icons that convey the status and result of the check. To access more detailed information, users can click on the "View" option on the card. This action will display detailed check information. It's important to note that this "View" option is available only for checks that have been completed and are presently under review.

**Manual Accept/ Reject Check**

Users can manually accept or reject checks in the 'review' status. When users choose to manually reject or accept checks, these actions will be stored against the check details. Users will be prompted to leave a comment explaining the reason for this decision. This note will be included in the Customer PDF Report for audit purposes.

**Further actions**

Users can also complete the following actions against the participant:

* **Reset Individual**: Reset the participant's progress. This will remove all collected details and check results on the customer, enabling them to start the verification process from the beginning.
* **Delete Individual**: Permanently remove the participant and all their associated personal and verification data.
* **Add Comment**: Add notes or comments about the participant, fostering communication and collaboration among team members.
* **Download Customer Report PDF**: When the customer has completed their mobile actions and their checks have been performed, a comprehensive PDF report of the participant's KYC checks which can be downloaded and saved for record-keeping purposes.

**Post-Completion Actions**

This section outlines the available post-completion controls for Portal users within the Verify platform.

Once a mobile user has completed their verification journey, Portal users can still take further actions if needed. These include:

* **Requesting Additional Information**: You can request new forms or upload additional documents, even after the application is marked as complete. This is useful when further clarification or supporting evidence is required.
* **Resetting Identity & Liveness Checks**: If the **Identity & Liveness** check is in **"In Review"** status and needs to be redone (e.g. due to image quality issues or mismatched data), you can reset this specific check without affecting the rest of the application. This allows the user to resubmit their identity verification through the mobile app.

These tools provide flexibility and ensure that applications can still be updated or corrected after initial submission.

</details>


# Reviewing results

Results can be reviewed from the Verify Portal or by downloading the customer PDF.

<table data-card-size="large" data-view="cards"><thead><tr><th align="center"></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Participant View</strong></td><td><ol><li>View check details directly from the Verify Portal.</li><li>Each check result is displayed with the result details.</li><li>Users have the option to manually approve or reject checks that are under review. They are required to leave a comment.</li></ol><p></p><p>Detailed information can be found in the <a href="/pages/N2jZNeJHMxvWBHpwGSTQ"><strong>Review Individuals.</strong></a></p></td><td></td><td><a href="/pages/N2jZNeJHMxvWBHpwGSTQ">/pages/N2jZNeJHMxvWBHpwGSTQ</a></td></tr><tr><td align="center"><strong>PDF record</strong></td><td><ol><li>Users can download a PDF from the Verify Portal.</li><li>The results are presented in one place for easy review. </li><li>The PDF record should be stored with the customer record.</li></ol><p></p></td><td>Users can gain a comprehensive understanding of the customer report by reviewing the <a href="/pages/o2lvKPAVZ2ovJGz4wTIX"><strong>Understanding the customer report</strong></a> .</td><td></td></tr></tbody></table>


# Applications

The application view page shows key information about the application and participants associated with it. ‘In review’ applications can be 'completed' or 'rejected'.

* ***Application Details*****:**  In this section, you will find details about the application, its creation date, the references, and the assigned consultant. Furthermore, a deletion date is included in accordance with our data retention policy, serving as a reminder that this application is scheduled for automatic removal on that particular date.
* ***Checks Completed/ Passed / Pending***: This displays the total number of checks for each participant in the application and their status.

The application view page contains actions the user can perform to manage the application:

* ***Choose Participant to View*****:** Users can select a specific participant to view their progress and the results of their checks in more detail.
* ***Add Participants (In progress only)*****:** While an application is in progress, users can add additional participants and send them an invite.

You can view each individual from this application by selecting their card.

<div align="right"><figure><img src="/files/vqenTkZShWLmmCQ0zuMB" alt=""><figcaption><p>Application View Page</p></figcaption></figure></div>


# Creating a New Applications

{% embed url="<https://vimeo.com/919616628>" %}
Adding a participant to an application
{% endembed %}

### New application

You can create an application in just a few steps:

Start a new application by clicking on the “+ New application” button, then follow a short workflow:

* **1)** Create an application type&#x20;
* **(2/3)** Add individuals
* **(4)** Send Invites

<figure><img src="/files/xigj0SZlZYCH1SuVH8d2" alt="" width="563"><figcaption><p>New application flow</p></figcaption></figure>

**Step 1:** Create a new application

Start a new application by clicking on the **“+ New application”** button

<img src="/files/qCphJR7YOfdhLe9S17vM" alt="" data-size="original">

**Step 2: Add application type**

Fill out the application type to specify the purpose and requirements of the new application.

* **Application Reference:** This is the reference you will use to identify a particular set of requests. Depending on your line of business, this may be a case number, matter reference, application reference, client name, or number.&#x20;
* **Application type:** Select the application type. This will determine the checks performed against the individual.&#x20;

**Step 3: Add individuals**

You'll then be prompted to add individuals to the application. Enter the personal details of your customers.

More than one individual can be applied to an application. The allocation can be cancelled at any time. If an application is created and exited before the invites have been sent, it will remain in the ‘New’ status. Clicking on a new application will route the user back to the new application workflow.

**Step 4: Send Invite**

* If you don't need to add more individuals to the same application, click "**Next."**
* Finally, click on **"Save & Send Invite"** to complete the process. Your client will receive a welcome email with instructions on how to download the app and perform any required checks.&#x20;


# Managing Applications

## Application Views

Manage the progress of your applications from the applications screen: <img src="/files/aAeWSUc1SdM2C2Op9eM8" alt="" data-size="line">

{% embed url="<https://vimeo.com/919616679>" fullWidth="true" %}
Application overview
{% endembed %}

The applications can be viewed in either a card or table view:

<img src="/files/Tkk3bQPVmkR46dN7NDK8" alt="" data-size="original">

Within these views, each application will have a status.

New >> In Progress >> In Review >> Completed / Rejected

<table><thead><tr><th width="192">Application Status</th><th>Description</th></tr></thead><tbody><tr><td><span data-gb-custom-inline data-tag="emoji" data-code="26aa">⚪</span> <strong>New</strong> </td><td>The application has been created, but invites to individuals have not been sent.</td></tr><tr><td><span data-gb-custom-inline data-tag="emoji" data-code="1f535">🔵</span> <strong>In progress</strong></td><td>The email invites have been sent to participants but not everyone has completed their mobile app actions.</td></tr><tr><td><span data-gb-custom-inline data-tag="emoji" data-code="1f7e0">🟠</span> <strong>In review</strong></td><td>All individuals have completed their Verify App process and at least one check needs to be reviewed. </td></tr><tr><td><span data-gb-custom-inline data-tag="emoji" data-code="1f7e2">🟢</span> <strong>Completed</strong></td><td>All checks have been successful, or an 'In review' application has been manually completed. </td></tr><tr><td><span data-gb-custom-inline data-tag="emoji" data-code="1f534">🔴</span> <strong>Rejected</strong></td><td>The user has rejected an 'In review' application. This status is to help manage applications that have been unsuccessful. </td></tr></tbody></table>

## Application Cards

On the overview screen, each application has a card that provides a quick overview of its progress.

&#x20;

<figure><img src="/files/7YTVUY5SRTS8Gxev2Xdj" alt=""><figcaption><p>Application card detail</p></figcaption></figure>

* **Mobile Actions:** The mobile actions that your customers needs to perform.
* **Application Reference:** What the user named the application when it was created. This should be something meaningful, like an internal reference for the client or case that you use on other systems.
* **Application ID:** The application ID is a unique ID that we create. This allows you to quickly find an application by searching for the ID and helps us find an application if you need support.&#x20;
* **Date Created:** The date the application was first created.&#x20;
* **Complete participants:** The total number of participants associated with your application and how many are complete.
* **User:** Each application can have a user associated with it. This helps manage and find applications that are a particular staff member's responsibility. Initially, this will be the user that created the application, but can be updated from that applications page.

***

## View, Search and Filter

Users can view, search, and filter applications.&#x20;

* **View:** Click on a card or row of an application to navigate to the application view.
* **Search**: The application can be searched using the reference, ID and participants’ names.
* **Filter**: The applications can be filtered by allocated user, consultant, created date, application type and whether the application has been archived.

***


# Reviewing Individuals

The participant page provides a detailed view of individual information, progress tracking, and the check results. This page equips the users with the tools to oversee, review, and take action for each participant. Checks in ‘Review’ can be manually accepted or rejected  checks as part of the review process.

***

## Participant Progress

The **Progress** panel on the left side of the dashboard provides a clear overview of the participant's verification journey. You can:

* View uploaded documents and request new additional document uploads.
* Track invite status, including the invite email address and time sent.
* Resend the invitation if required.
* Monitor action progress (e.g. Accept Terms, Add Personal Details, Perform ID Check, etc.). Once all actions are marked as completed, checks will begin processing. The Action Check section shows how many actions have been completed by the mobile user. If any actions are still pending in the mobile app, they will be displayed here with a pending icon. You can then follow up with the client and ask them to complete those actions.

This section ensures real-time tracking of both user-submitted actions and system processing steps.

<figure><img src="/files/HU29cI9M7wV17ztCy5u6" alt="" width="375"><figcaption><p>Participant progress section</p></figcaption></figure>

***

#### **About Section**

The **About** tab in the centre panel provides a comprehensive view of the participant’s information, organised into several sub-tabs:

* **Invite Tab**: Displays the initial details entered when creating the participant's application, such as title, name, and gender.
* **Personal Information Tab**: Shows the personal details submitted by the client via the mobile application. This includes information such as full name, nationality, and place of birth.
* **Address Tab**: Displays the current and previous addresses, along with geolocation data, as provided by the client through the app.
* **Financials Tab**: If applicable to the application type, this section presents financial information such as bank account details, source of funds, employment and income status.
* **Forms Tab**: Lists any forms completed by the client, including the questions asked and their responses. You can also request a new form if additional information is needed

<figure><img src="/files/RwMzS7MsM3kZ2Ecvyna9" alt="" width="563"><figcaption><p>Participant about section</p></figcaption></figure>

To view all information in one place, click the **"All Details"** button. This will display a consolidated view of the information from all the sub-tabs, including Invite, Personal, Address, Financials, and Forms, in a single screen for easier review.

***

## **Checks**

Checks are divided into three distinct stages: "Pending," "Reviewed," and "Completed," providing you with a more comprehensive understanding of their statuses.

Each check is presented in a card format, containing key information and icons that convey the status and result of the check. To access more detailed information, users can click on the "View" option on the card. This action will display detailed check information. It's important to note that this "View" option is available only for checks that have been completed and are presently under review.

**Manual Accept/ Reject Check**

Users can manually accept or reject checks that are in the 'review' status. When users choose to manually reject or accept checks, these actions will be stored against the check details. Users will be prompted to leave a comment explaining the reason for this decision. This note will be included in the Customer PDF Report for audit purposes.

***

## **Further actions**

Users can also complete the following actions against the participant:

* **Reset Individual**: Reset the participant's progress, this will remove all collected details and check results on the customer, enabling them to start the verification process from the beginning.

{% embed url="<https://vimeo.com/919616576>" %}
Resetting an individual
{% endembed %}

* **Delete Individual**: Permanently remove the participant and all their associated personal and verification data.

<figure><img src="/files/RGCMavYGG3CAhqe5cCZE" alt="" width="563"><figcaption><p> Participant View page </p></figcaption></figure>

* **Download Customer Report PDF:** When the customer has completed their mobile actions and their checks have been performed, a comprehensive PDF report of the participant's KYC checks can be downloaded and saved for record-keeping purposes.
* **Making comments:** Comments can be made against the individual during their application. It provides a useful way to record actions, notes or useful information. A key feature of the comment is that when users choose to accept or reject actions manually, they must provide a reason for their decision, which will be stored with the check details. Users will be prompted to leave a comment explaining the rationale behind their decision. These comments will be included in the Customer Report for audit purposes, ensuring transparency and accountability in decision-making.

***

## Post-completion actions

This section outlines the available post-completion controls for Portal users within the Verify platform.

Once a mobile user has completed their verification journey, Portal users can still take further actions if needed. These include:

* **Requesting Additional Information**: You can request new forms or upload additional documents, even after the application is marked as complete. This is useful when further clarification or supporting evidence is required.
* **Resetting Identity & Liveness Checks**: If the **Identity & Liveness** check is in **"In Review"** status and needs to be redone (e.g. due to image quality issues or mismatched data), you can reset this specific check without affecting the rest of the application. This allows the user to resubmit their identity verification through the mobile app.

These tools provide flexibility and ensure that applications can still be updated or corrected after initial submission.

<figure><img src="/files/SxyV45THVMK0oEClpEVX" alt="" width="375"><figcaption><p>Request new forms</p></figcaption></figure>


# Post-Completion Actions

Even after a mobile user has completed their verification journey, Verify Portal users can continue to take further actions within the Verify platform. This includes requesting additional information, such as new forms or uploading additional documents, when further clarification is required from the client. You can also reset the Identity & Liveness check if it remains in **"In Review"** status, allowing the client to resubmit their verification through the mobile app.

These features allow you to manage the process efficiently within a single platform, avoiding the need for back-and-forth communication via email. All updates and requests are captured within the same record, ensuring consistency and ease of access.

***

### Reset Identity & Liveness (ID\&V) Check:

The **Reset Identity & Liveness Check** feature allows Portal users to selectively reset the ID\&V process for individual applicants directly within the Verify Portal. This is especially useful when an ID\&V check is in **"In Review"** status due to issues such as:

* Blurry or poor-quality ID photos
* Incomplete or mismatched identity data
* Failed liveness or facial recognition checks

Rather than restarting the entire application or communicating with the client via email, this feature enables you to manage the process within the platform. It ensures a smooth and auditable workflow while maintaining a single record of all client verification actions.

**Step-by-Step: How to Reset the ID\&V Check**

<details>

<summary>Step 1: Access the Individual Application</summary>

* Go to the **Verify Portal** and open the relevant participant’s application.
* Navigate to the **Individual Check Overview** card.

</details>

<details>

<summary>Step 2: Go to the ID&#x26;V Check Card</summary>

* Go to the **Identity & Liveness Result** card and click the **View** link.
* If the check status is **"In Review"**, a **"Reset ID\&V"** button will appear next to it.

</details>

<details>

<summary>Step 3: Click the "Reset ID&#x26;V" Button</summary>

* Click the button to start the reset process. A confirmation pop-up will appear with the message: "*Are you sure you want to reset this client's Identity & Liveness check?”*
* Click **Continue t**o proceed.
* The  Identity & Liveness card will reflect the reset status (e.g. with a pending or reset icon). Verify system will send an automatic email to the client with the new invite code and instructions to re-complete the ID\&V step via the mobile app.

</details>

<figure><img src="/files/xSzYQvmznx3yIUGEicna" alt=""><figcaption><p><strong>Reset the ID&#x26;V Check</strong></p></figcaption></figure>

***

### Request Additional Documents Post-Completion

Even after a mobile user has completed their initial verification journey,  Verify Portal users can request additional documents as needed directly from within the Verify platform. This feature is useful when further supporting evidence is required,  for example, proof of wealth or other documents relevant to the application type.

The process ensures that all requests and uploads are stored in a centralised location, eliminating the need for external communication and maintaining a complete record within the platform.

**Step-by-Step: How to Request Additional Documents**

<details>

<summary>Step 1: Navigate to the Individual Application</summary>

* Open the relevant application in the Verify Portal and go to the “Progress” section.
* Under the uploaded Documents section, click the “Request new” button.

</details>

<details>

<summary>Step 2: Select Documents</summary>

* A list of available additional documents will appear.
* The screen shows two sections:
  * **Existing Additional Documents**: Already assigned to the application.
  * **Add New Additional Documents**: A list of additional documents available for assignment.
* Toggle the switches for the documents you wish to request
* Click “Add”, then “Confirm” to proceed.

</details>

<details>

<summary>Step 3: Automatic Notification &#x26; Status Update</summary>

* The selected document requests are sent to the mobile user with their invite code and instructions.
* The new document status appears as "Pending" in the Portal action section.

</details>

<figure><img src="/files/sokqMRvkRgRZrMpXCNWq" alt=""><figcaption><p><strong>Request Additional Documents</strong></p></figcaption></figure>

{% hint style="info" %}
When the mobile user reopens the mobile app and enters their invite code, they will see the pending document requests.

After uploading, the document status updates to “Completed” and can be downloaded in the Portal.
{% endhint %}

***

### Request Additional Forms Post-Completion

The Verify platform now supports assigning **additional forms** to applicants **even after** they have completed their initial journey. This allows you to collect any extra details directly through the app, keeping the process streamlined and all records centralised within the platform.

**Step-by-Step: How to Request Additional Forms**

<details>

<summary>Step 1: Navigate to the Forms Tab</summary>

1. Open the relevant application in the Verify Portal and go to the **"About"** section. Click on the **"Forms"** tab, where all form-related actions are managed.

</details>

<details>

<summary>Step 2: Click "Request Now"</summary>

* A new **"Request Now"** button is available within the Forms tab. Click it to open the **Form Assignment** screen.
* The screen shows two sections:
  * **Existing Forms**: Already assigned to the application.
  * **Add New Forms**: A list of additional forms available for assignment.
* Use the toggle switches to select the forms you want to send.
* Click “Add”, then “Confirm” to proceed.

</details>

<details>

<summary>Step 3:  Automatic Notification &#x26; Status Update</summary>

* The selected forms are added to the user’s application.
* An **email notification** is automatically sent to the user with instructions.
* A new form action is created in the progress action section, with each form's status marked as **"Pending.**

</details>

<figure><img src="/files/IzvtS20MesPPiFWXAlkn" alt=""><figcaption><p><strong>Request Additional Forms</strong></p></figcaption></figure>


# Understanding Customer Reports

The Customer Report is an essential tool for maintaining accurate records of your customer interactions and verifying their identity. This report serves as a comprehensive record of the detailed information gathered about your customers, as well as the verification checks conducted to ensure compliance with regulatory requirements. By downloading and saving this report, you can demonstrate that your organization has fulfilled its obligations regarding customer due diligence. By doing so, you establish a robust audit trail, demonstrating to regulators and stakeholders that your organization has conducted thorough due diligence on its customers.

To offer a comprehensive understanding of the checks conducted on the customer and the resulting outcomes, the PDF report is segmented into various sections. Each section contains comprehensive details with key points underlined for clarity. Access these sections below by clicking on each tab, accompanied by example information for better understanding.

## 1.   About the PDF

The Customer Report provides a record of the detailed information collected about your customer and the verification checks performed against that individual. The report should be downloaded and saved against your customer records to prove that you have completed customer due diligence.

The following Core Identity (including Address) Check are:·     &#x20;

* ID & Liveness
* PEP & Sanctions
* Address Verification &#x20;
* Geolocation
* Proof of Address

For each verification check we use information captured in the mobile app and each check will have a result of either **‘Passed’,** **‘Review required’,** **‘Failed’, ‘Manually accepted’, or ‘Manually rejected’,**  &#x20;

<table><thead><tr><th width="275">Result</th><th>Description</th></tr></thead><tbody><tr><td><img src="/files/Gu7LxhVntjNpaw0NaJXc" alt="" data-size="line">  <strong>PASSED</strong></td><td>The customer has met the criteria to pass the check.</td></tr><tr><td><img src="/files/El1zbCbyMXPeputqHUUO" alt="" data-size="line">  <strong>REVIEW REQUIRED</strong></td><td>The customer did not pass the check and it needs to be reviewed.</td></tr><tr><td><img src="/files/UPuvsTvdKb37AdjePDiu" alt="" data-size="line">  <strong>FAILED</strong> </td><td>The check was unable to be performed.</td></tr><tr><td><img src="/files/MDqWMPPLZ6qgjaVe57H7" alt="" data-size="line">  <strong>MANUALLY  ACCEPTED</strong></td><td>The user has manually accepted the check that is in review status  </td></tr><tr><td><img src="/files/qbqs4l3VdSqetijGC07v" alt="" data-size="line">  <strong>MANUALLY  REJECTED</strong></td><td>The user has manually rejected the check that is in review status  </td></tr></tbody></table>

{% hint style="info" %}
**IMPORTANT NOTE:** The report will only be available when the customer has completed all the actions in the mobile app.
{% endhint %}

## 2.   Customer Information

{% hint style="info" %}
Verify captures information about your customers when they use the mobile app. This includes personal details, biometric information, their residential address, contact information, and device geolocation. This information is used when performing the checks.
{% endhint %}

<figure><img src="/files/588qOfGgZTKrMbreaQQY" alt="" width="375"><figcaption><p>Customer information section on PDF report</p></figcaption></figure>

* **Personal details:**&#x20;

The individual's name, date of birth, and sex are captured during the mobile journey. This is compared with the invite information as well as used for the verification checks.

* **Current residential address:**&#x20;

Your Customer starts by searching for their address on ‘international look-up’ or can complete the address form within the mobile app. The individuals address is captured in a structured format. This is used for various checks but predominantly for our AML residential address verification.&#x20;

* **Contact information:**&#x20;

This section shows the individual’s email address used for the invite. We will be capturing more contact details in future updates.&#x20;

* **Geolocation check:**&#x20;

The country of residential address and device location are compared. If they match, the check passes. The customer must give permission for us to capture these coordinates through their mobile device location setting.

* &#x20;**Agreement to terms:**&#x20;

When the customer first accesses the mobile app we ask them to confirm our End User Terms and Privacy Policy. This is stored and provided on the Customer Report as a record that Tiller has been given permission to process the individual’s data.

## 3.   ID & Liveness

{% hint style="info" %}
The Identity Document scan and biometric liveness test are performed for this check. It ensures the authenticity of the customer's identification documents (passport, driver's licence, or national ID card), and it validates that the person providing the ID is the same one in the document photo (i.e., the person is 'alive' and not a photo or a video recording).

The following needs to be successful for this check to pass: document verified, liveness test, and biometric face match.
{% endhint %}

### &#x20;3.1 - Document information

The customer selects one of the following identity documents:

* **Passport,**&#x20;
* **Drivers Licence, or**&#x20;
* **National Identity Card.**

Verify by Tiller supports 1,335 document types across 176 different countries. More detailed information can be viewed on {{link to country document placeholder}}

<figure><img src="/files/ir2wT5yJdEogB3VUvIYU" alt="" width="375"><figcaption><p>The document name and country of origin will be determined if recognised. </p></figcaption></figure>

Verify will scan the document and extract the information through OCR (optical character recognition) and NFC (near field communication - passport only). The document image, information, and portrait are used to perform the verifications. All the details captured are available in the customer report.

<figure><img src="/files/UIBAVPoASFuI5S91cvTI" alt=""><figcaption></figcaption></figure>

> **OCR -** Technology used to convert printed text into machine-readable text.
>
> **NFC -** Wireless communication to extract information and images from the embedded passport chip. This method is highly accurate and adds an additional layer of security. Passport NFC capture is always the preferred way of getting the customers ID information.

***

### 3.2 - Verified document

The recognised document is checked for its authenticity, and personal detail accuracy and validates its information. If any of the results require review it will state the reason.

<figure><img src="/files/I3H5mxuxnUflHmUlOV8w" alt="" width="356"><figcaption><p>Verified document information</p></figcaption></figure>

**Details**

<table><thead><tr><th width="190">Type</th><th>Description</th></tr></thead><tbody><tr><td><strong>Document front side check</strong></td><td>The front of the document checked against official templates to ensure its authenticity.</td></tr><tr><td><strong>Underage rule</strong></td><td>The individual must be over the age of 18.</td></tr><tr><td><strong>Document blocking policy</strong></td><td>None of the document images or information has been blocked or is unable to be read as a valid document.</td></tr><tr><td><strong>Document support</strong></td><td>The document type must be supported by our services. Our service supports over 1,300 document types across 173 countries.</td></tr><tr><td><strong>Document validation</strong></td><td><p>A number of checks are made to ensure the integrity of the document. This is designed to detect signs of tampering, defacement, and other issues. Factors include </p><ul><li>Lighting - Poor lighting or overexposure can prevent the document validation. </li><li>Obstructions - If the document has been obstructed in any way which might prevent a validation.</li><li>Glare - Significant glare on the document surface may impact the quality of the capture.</li></ul><p>Should the integrity not be successfully validated for any reason this check will not be successful.</p></td></tr></tbody></table>

### 3.3 -  Liveness

The **Liveness Check** is a security measure designed to confirm that the individual completing the identity verification is physically present at the time of submission. In the **Verify platform**, we use a **passive liveness check**.

With passive liveness, the user is prompted to **manually capture a live image of themselves** during the identity verification process. This image is then analysed for subtle cues that indicate it was taken in real-time by a live person, such as lighting consistency, facial depth, and image integrity.

<figure><img src="/files/jipdD32sXkX6ZBkEhORX" alt="" width="188"><figcaption><p>Passive liveness check</p></figcaption></figure>

> * **‘Pasive’ liveness:**  Passive liveness uses to verify that a person is real without requiring them to perform any actions such as blinking or turning their head. It runs seamlessly in the background, analysing subtle visual cues such as skin texture, natural light reflections, and micro-movements. This prevents the use of static photos, masks, or pre-recorded videos, providing strong security while keeping the user experience simple and frictionless.
> * **Liveness overall failure reason:** The overriding reason for failure is shown in this section. This is ‘None’ when the check has passed.

***

### 3.4 - Verify face match

Our Face Match service uses advanced biometric technology to ensure the person undergoing the identity check is the same as the one pictured in the provided identification document.

{% hint style="success" %}
**The confidence score:**

68 facial features between the live facial image captured and the reference photo on the presented identity document are analysed to determine the confidence score. The higher the score, the stronger the match.
{% endhint %}

<figure><img src="/files/UqgesgtKXsriVz1EcbaP" alt="" width="563"><figcaption><p>The confidence score must be over 60% for the result to pass</p></figcaption></figure>

**ID Photo and Chip Photo**

* ***Selfie Photo -*** The selfie photo is a live image captured directly from the user during the identity verification process. It serves as the primary reference for comparing against the ID portrait and, if available, the NFC chip photo. This image helps confirm that the person submitting the application is the same individual shown in the ID document.&#x20;
* ***ID Photo -*** The ID portrait photo is extracted from the ID document. This is the default method of retrieving the reference photo for the supported photo ID.
* **Chip Photo -** Modern passports contain an NFC chip, which holds biometric data and the passport image. If available, the NFC image and data are compared with the captured live facial image. This NFC image will provide an extra layer of verification with a high rate of accuracy.

## 4.   PEP & Sanctions

If a match is identified the check will be unsuccessful and require further review. We'll also explain why the individual was flagged as a Politically Exposed Person (PEP)

{% hint style="info" %}
The PEP and Sanctions screening service detects individuals who are considered Politically Exposed Persons (PEPs) and those listed in international sanctions databases. Through third-party verification, the service continuously checks against major sanctions lists like the United Nations (UN), European Union (EU), Office of Foreign Assets Control (OFAC), and Office of Financial Sanctions Implementation (OFSI) for any new updates.

For PEP data, information is sourced from multiple reliable sources, including CIA World Leaders, CIA World Factbook, Rulers articles and other databases continually monitored to additional information, Gov’t/Official websites covering all levels of PEPs, Other useful open sources. For example, those independent from the state control, and selected media websites for regular (daily) media checks.

The sanctions screening monitors internationally recognised (e.g. OFSI, OFAC, US State Department, UK & EU Sanctions) and locally enforcement sanctions lists to ensure compliance with regulations, regardless of your geographical location.

It helps you identify potential reputational and operational risks as well as adherence to anti-money laundering (AML) & countering the financing of terrorism (CFT) and sanctions regulations and due process.
{% endhint %}

### 4.1 PEP Check

## 4.   PEP & Sanctions

If a match is identified the check will be unsuccessful and require further review. We'll also explain why the individual was flagged as a Politically Exposed Person (PEP)

{% hint style="info" %}
The PEP and Sanctions screening service detects individuals who are considered Politically Exposed Persons (PEPs) and those listed in international sanctions databases. Through third-party verification, the service continuously checks against major sanctions lists like the United Nations (UN), European Union (EU), Office of Foreign Assets Control (OFAC), and Office of Financial Sanctions Implementation (OFSI) for any new updates.

For PEP data, information is sourced from multiple reliable sources, including CIA World Leaders, CIA World Factbook, Rulers articles and other databases continually monitored to additional information, Gov’t/Official websites covering all levels of PEPs, Other useful open sources. For example, those independent from the state control, and selected media websites for regular (daily) media checks.

The sanctions screening monitors internationally recognised (e.g. OFSI, OFAC, US State Department, UK & EU Sanctions) and locally enforcement sanctions lists to ensure compliance with regulations, regardless of your geographical location.

It helps you identify potential reputational and operational risks as well as adherence to anti-money laundering (AML) & countering the financing of terrorism (CFT) and sanctions regulations and due process.
{% endhint %}

### 4.1 PEP Check

In the PEP & Sanctions database check, a multi-layered approach is used to identify potential matches. The individuals personal details are cross-referenced against the individuals on the available lists. The check will pass if no match is found.

<figure><img src="/files/veIElMrsYZMKCED65Zdx" alt="" width="563"><figcaption><p>PEP check result example</p></figcaption></figure>

### 4.2 Sanctions Check

For the Sanctions database check, we employ a multi-layered approach to detect potential matches by cross-referencing individuals against available lists. If a check is under review, we furnish comprehensive details regarding the list where the individual appears, including the source, original name, title, date, and URL link for further investigation.

<figure><img src="/files/HLfVHj9FhpFAq8CjPyvz" alt="" width="563"><figcaption></figcaption></figure>

## 5.   Address Verification

{% hint style="info" %}
Our international address verification process leverages multiple third-party regulatory-quality data sources to verify the address information provided by your customers. These sources differ depending on the country, but commonly include credit agency records, voter & other government databases, utility companies, landline telephone companies, citizen card information, and more. We specifically exclude lower-quality sources such as marketing databases, as they are not typically deemed to be sufficiently reliable for regulatory purposes.

During the address capture within the mobile app, the user searches for their address using an international address lookup. The address is structured to provide the highest match rate from our sources. The country is identified and up to three sources with the highest available match rates are checked against the individuals address and personal details for a match. If a match is found, the Address Verification check will pass.
{% endhint %}

### 5.1  Address verification example

The address verification service will check up to three separate sources, depending on country availability. Should a sufficient match be found the check will pass. Each source can have different underlying results in the details table. Therefore results types will differ depending on the source. The source will pass provided that that at least the minimum required underlying results have passed.

<figure><img src="/files/LsVjOjuB4xvcnCxB0X83" alt="" width="563"><figcaption><p>This source has passed due to enough successful results to determine a match.</p></figcaption></figure>

Below is an example of a UK address source:

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Registry of death</strong></td><td>We checked the provided full name against the Registry of Deaths, which keeps records of people who have passed away. We check to ensure the data subject has not been recorded on the death register.</td><td></td></tr><tr><td><strong>Name, address and date of birth</strong></td><td>The customer's name, address, and date of birth have been matched on one or multiple underlying sources. The distinct count and sum of the data sources matches are also assessed to contribute to the result.</td><td></td></tr><tr><td><strong>Name and address (ID Authenticate)</strong></td><td>In some instances, an additional check using the national ID number is performed. In this case a national ID number was not available, therefore the result was unsuccessful. The overall address verification has still passed as sufficient other results have been matched.</td><td></td></tr></tbody></table>

## 6.   Proof of Address

{% hint style="info" %}
The Proof of Address upload can be used as a secondary method of address verification should the our international address verification service be unsuccessful. The customer must select from a configurable list of acceptable document types. These currently include:

* Telephone bill&#x20;
* Tax assessment notice&#x20;
* Water bill&#x20;
* Electricity or gas bill&#x20;
* Credit card statement

The customer must also confirm the issue date of the document. This must be at least within the last three months.
{% endhint %}

### 6.1  Proof of address document

The captured proof of address document is available to view on the PDF. It should be noted that no digital checks are performed on the document. It is for supplementary evidence only.

* **Document type:** The customer selects the document type from the list above. This list is configurable and additional document types can be added if required.
* **Issue date:** The issue date confirmed by the customer is shown on the PDF. This must be within the previous three months for the user to be able to proceed.

<figure><img src="/files/fFGtex0NDaxzj4p8gPox" alt="" width="563"><figcaption></figcaption></figure>

## 7.  **Comments**

**Making comments**

Comments can be made against the individual during their application. It provides a useful way to record actions or notes. These comments may contain various elements observed throughout the verification process or additional contextual information relevant to the individual’s profile. They can be valuable to supplement the results of each check.

Any comments made against the individual will appear on the customer report. Each comment has a time stamp and record of the user that submitted it.

<figure><img src="/files/r0Rem6jVrxYFSKs1Sh7A" alt="" width="375"><figcaption></figcaption></figure>


# Screening

<img src="/files/NgVu7l2QxeG1KY2CHnPm" alt="" data-size="line"> The Screening service in the Verify Portal enables businesses to conduct pre-assessment checks on both new and existing clients. Clients can be either individuals or companies/entities.

With this screening functionality, you can perform checks without requiring customer contact, getting results back immediately.

#### **Available Screening Checks**

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>For Individuals Screening:</strong></td><td><ul><li>Address verification checks </li><li>PEP &#x26; Sanctions  checks </li><li>Adverse Media checks</li></ul></td></tr><tr><td><strong>For  Companies Screening:</strong></td><td><ul><li>Sanctions checks</li><li>Adverse Media checks</li></ul></td></tr></tbody></table>

This feature supports **PEP & Sanctions, Adverse Media, and Address verification**, ensuring businesses can perform essential compliance and risk assessments effectively.

## Managing Screening Check History Screen

The '**Screening'** module provides a comprehensive overview of all checks performed on both individuals and companies.&#x20;

<figure><img src="/files/YfvcuAND5L6PrWYxtBGQ" alt=""><figcaption><p>Check History screen</p></figcaption></figure>

**Key components of the check history screen table:**

* **Individual name:** This column displays the names of the individuals and companies for whom checks have been performed. Each entry corresponds to a specific individual or company whose details have been reviewed or are pending review.
* **Reference:** The "Reference "column provides a unique identifier for each check performed by the system. This reference number allows for easy tracking and management of both individual and company checks.
* **Checks:** The "Checks" column indicates the types of checks that have been run. Icons are used to represent different categories of checks, such as address verification, PEP & Sanction, Adverse Media etc.

<figure><img src="/files/Q2oNiCZDYAhQnnMmBRqW" alt="" width="361"><figcaption><p>Check type</p></figcaption></figure>

* **Result:** The "Result" column summarises the outcome of the checks. Different icons are used to indicate the status:

  * **Green checkmark:** Number of successful checks completed with no issues on the record.
  * **Yellow icons:** The number of checks that come in review on the record that need future reviewing from your team.&#x20;
  * **Pending icons:** The pending icons indicate the number of currently pending checks. This status can occur in two scenarios:

    * **Incomplete record details:** A check may be marked as pending if you have added the record's details but have not yet run the check.
    * **System processing:** A check can also be pending when the system is in the process of running the check on the records. Once the system completes the check, the status will be updated accordingly.

    The numbers next to these icons represent the count of each result type (e.g., how many checks passed, how many checks in review, etc.)

  <figure><img src="/files/d75sCPBwV2DjCVcLEYzn" alt="" width="341"><figcaption><p>Result</p></figcaption></figure>
* **View:** The "View" option allows users to access the detailed results of each check. By clicking "View," users can review the overall findings and take any necessary actions based on the results.

***

## Search and Filter

Users can search, and filter the checks.

* **Search**: The check can be searched using the name and reference.
* **Filter**: The check can be filtered by the date started and check type.&#x20;


# Creating Individual Check

To create a new screening record, start by navigating to the check history screen. Once there, click on the **"+ New Check"** button, select individual check and follow the brief workflow:

1. Select the checks you need.
2. Add individual details.
3. Enter the individual’s address.
4. Run the check.

<figure><img src="/files/vFRi34ZF3HCi88T9yg6D" alt="" width="563"><figcaption><p>Individual Check Flow </p></figcaption></figure>

**Step 1. Create a new check:**

To start a new check, click on the **"+ New Check"** button. You will then be provided with the option to select either an **Individual** check or a **Company** check.

![](/files/gJ4okqK8bIYnEggN4tu5)

To proceed with an individual check, click on **"Individual"**

**Step 2. Select the checks:**

* After clicking **"+ New Check,"** you'll be taken to a screen where you can select the types of checks you want to perform on the individual.
* You must select at least one check before proceeding. Once you've made your selection, click **"Next."**

**Step 3. Add individual details:**

* You will then be prompted to enter the personal details of the individual you are checking.
* The only mandatory fields are the first name and last name, but if you have the date of birth, it’s highly recommended to include it, as it enhances the accuracy of the results.

**Step 4. Add the individual address:**

* Provide the individual’s address and country details. Address information is required to run the check, as it allows the system to cross-reference records in different databases.
* You can manually enter the address or use a postcode/zip code. After entering the address, click **"Next."**

**Step 5. Run the check:**

* Before running the check, you will see a summary screen that includes the individual's name, address, and the checks that will be performed.
* Review the summary, then click **"Run"** to submit the check. The system will process the check within a few seconds.  In the meantime, you can choose to create a new check for another individual or close the workflow to return to the Check history screen.

By following these steps, you can efficiently create and run checks on your clients, ensuring their information is accurate and up to date.


# Reviewing Individuals Check

The **"Reviewing Individuals' Check"** page offers a detailed overview of the checks conducted on an individual, including the results, and takes action based on those results. For checks marked as 'Reviewed,' you can manually accept or reject the results as part of your business risk appetite. You have the option to download a PDF report summarising all the checks you have performed.

The check can easily be converted into an application if additional information is required, or if further verification is needed.

<figure><img src="/files/c16clD62aWIsoUcaTcoo" alt="" width="563"><figcaption><p>Reviewing individual check</p></figcaption></figure>

## **Details section**

It contains detailed information regarding individuals and the ability to convert them into applications.

### **1. Convert to application:**

A **"Check"** can be seamlessly converted into an **"Application,"** enabling the user to start an application for the same individual without duplicating efforts.

<figure><img src="/files/tattqBUZ7XBbwdlCs4dZ" alt="" width="375"><figcaption><p>Convert check into application</p></figcaption></figure>

To convert a check into an application, simply click the "Convert to Application" button in the check details section. This action will automatically transfer the relevant information into an application form.  You will need to select the type of application you wish to proceed for this individual. After providing the application information, enter the user's email address to send a verification request.

For more details on the application process, you can find information  on[ "Application"](/training-hub/user-guides/applications)

### 2. Individual detail:

In this section, you will find key information about the individual, such as a unique reference number that helps in tracking the check and, it also displays the date when the checks were completed, along with the individual's personal details and address. Additionally, a Delete Date" is specified, which indicates when the checks will be automatically removed in accordance with the data retention policy.

***

## **Check section**

### **1. Check Type:**&#x20;

This section lists the different types of checks performed on the individual. Currently, you can conduct PEP & Sanctions, Adverse Media and Address checks on individuals without the need the customer involvement with the Verify Mobile app.

### **2. Result Status:**

* **Review:** Indicates that the check requires further review.
* **Accepted:** Shows that the check has passed without issues.
* **View:** A link to view detailed results of each specific check, allowing the user to dive deeper into any findings.

***

## Check Details

Displays the overall results of the specific check, showing whether the individual check was passed or in review.

**Manual accept/ reject check**

You can manually accept or reject checks that are in the 'review' status. When users choose to manually reject or accept checks, these actions will be stored against the check details. You will be prompted to leave a comment explaining the reason for this decision. This note will be included in the Customer PDF Report for audit purposes.

***

## **Download PDF report:**

&#x20;Located at the top-right of the screen, this button allows the user to download a comprehensive PDF report of all the checks performed on the individual. The PDF includes all the details and results from the checks, making it easy to store, share, or reference later for compliance and audit purposes.&#x20;

## **Making comments:**&#x20;

Comments can be made against the individual during their check. It provides a useful way to record actions, notes or useful information.


# Creating Company Check

To create a new screening record, start by navigating to the check history screen. Once there, click on the **"+ New Check"** button, select company check and follow the brief workflow:

1. Select the checks you need.
2. Add company details.
3. Enter the company-registered address (optional).
4. Run the check.

<figure><img src="/files/UTxNWIvVREtsWwk7vtGi" alt="" width="563"><figcaption><p>Company Check Flow </p></figcaption></figure>

**Step 1. Create a new check:**

To start a new check, click on the **"+ New Check"** button. You will then be provided with the option to select either an **Individual** check or a **Company** check.

![](/files/aVXDtK3sITUQhyzvqDoo)

To proceed with an individual check, click on **"Company"**

**Step 2. Select the checks:**

* After selecting **"Company,"** you'll be taken to a screen where you can select the types of checks you want to perform on the individual.
* You must select at least one check before proceeding. Once you've made your selection, click **"Next."**

**Step 3. Add company details:**

* You will then be prompted to enter the details of the company you are checking.
* The only mandatory fields are **Company Name** and **Country**. However, if you have additional details such as the **Registration Number** or **Date of Incorporation**, providing them can help improve the accuracy of the search result

**Step 4. Add the company registered address:**

* Provide the company’s registered address and country details. The address information is optional, so if you do not know the company’s registered address, you can skip this step and click **"Next."**

**Step 5. Run the check:**

* Before running the check, you will see a summary screen that includes the company details and the checks that will be performed.
* Review the summary, then click **"Run"** to submit the check. The system will process the check within a few seconds.  In the meantime, you can choose to create a new check for another company or close the workflow to return to the Check history screen.

By following these steps, you can efficiently create and run checks on your clients, ensuring their information is accurate and up to date.


# Reviewing Company Check

The **"Reviewing Company Check"** page offers a detailed overview of the checks conducted on a company, including the results, and takes action based on those results. For checks marked as 'Reviewed,' you can manually accept or reject the results as part of your business risk appetite. You have the option to download a PDF report summarising all the checks you have performed.

<figure><img src="/files/Qd32NsVUgjVYAHBwrenr" alt=""><figcaption><p>Reviewing company check</p></figcaption></figure>

## **Details section**

In this section, you will find key information about the company such as a unique reference number that helps in tracking the check and, it also displays the date when the checks were completed, along with the company details and address. Additionally, a Delete Date" is specified, which indicates when the checks will be automatically removed in accordance with the data retention policy.

***

## **Check section**

### **1. Check Type:**&#x20;

This section lists the different types of checks performed on the company. Currently, you can conduct Sanctions,  and Adverse Media checks on companies.&#x20;

### **2. Result Status:**

* **Review:** Indicates that the check requires further review.
* **Accepted:** Shows that the check has passed without issues.
* **View:** A link to view detailed results of each specific check, allowing the user to dive deeper into any findings.

***

## Check Details

Displays the overall results of the specific check, showing whether the individual check was passed or in review.

**Manual accept/ reject check**

You can manually accept or reject checks that are in the 'review' status. When users choose to manually reject or accept checks, these actions will be stored against the check details. You will be prompted to leave a comment explaining the reason for this decision. This note will be included in the Customer PDF Report for audit purposes.

***

## **Download PDF report:**

&#x20;Located at the top-right of the screen, this button allows the user to download a comprehensive PDF report of all the checks performed on the company. The PDF includes all the details and results from the checks, making it easy to store, share, or reference later for compliance and audit purposes.&#x20;

## **Making comments:**&#x20;

Comments can be made against the company record during their check. It provides a useful way to record actions, notes or useful information.


# Monitoring

<img src="/files/Y73XFsCC1iXRhmdCL7YJ" alt="" data-size="line"> Verify Portal Monitoring service allows you to continuously monitor individuals and companies you add to your monitoring list, keeping you informed of potential risks.&#x20;

If the system detects any new PEP & Sanctions, or Adverse Media related to a monitored individual or companies, it will promptly send you a notification. In this way, you can take immediate action and review the individual's and the company's status in real time. Additionally, the service generates detailed PDF reports for each instance of suspicious activity detected.

#### **Available** Monitoring **Checks**

<table data-view="cards"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>For Individuals Monitoring:</strong></td><td><p> </p><ul><li>PEP &#x26; Sanctions  checks </li><li>Adverse Media checks</li></ul></td></tr><tr><td><strong>For  Companies Monitoring:</strong></td><td><ul><li>Sanctions checks</li><li>Adverse Media checks</li></ul></td></tr></tbody></table>

This feature supports **PEP, Sanctions, and  Adverse Media**, ensuring businesses can perform essential compliance and risk assessments effectively.

***

### Managing the Monitoring Dashboard

The Monitoring Dashboard is designed to help users effectively track and manage individuals or companies under monitoring. It provides a clear, real-time view of each monitoring status, including the latest activity detected on their records.

Below is a detailed explanation of how to navigate through the dashboard.

<figure><img src="/files/uXX8wsqf1cnC0yyZai0K" alt=""><figcaption><p>Monitoring dashboard overview</p></figcaption></figure>

### **Key Features:**

1. **Name**: Displays the name of the individual or company being monitored. This list includes all individuals and companies whose monitoring records have been added to the Verify system.
2. **Status:** Displays the current monitoring status of the individual or companies, which can be one of three states:
   1. **Pending:** The individual's or company's details have been added, but no monitoring record has been created yet.
   2. **Active**: Monitoring is currently ongoing for these records.&#x20;
   3. **Requires Review:** A new activity has been found for this record that requires your attention for review. Once reviewed, the status can be updated.
3. **ID:** A unique identification number assigned to each individual or company, making it easier to identify.
4. **Date started**: This shows the date when monitoring was started or when they were first added to the list.
5. **Last activity**: Displays the latest date of any new record or activity found for these records. If any new information is recorded, this date will automatically update to reflect the latest data.
6. **View**: Clicking the "View" button next to each record allows you to see more detailed information and monitoring records associated with the individual or companies.

***

### Searching and Filtering:

* **Search**: You can use the search bar at the top to search for a specific individual or companies by name or ID.
* **Filter By**: The filter button allows you to organise the records by either the **Date started** or the **Last activity**, helping you prioritise or focus on specific individuals or companies based on their monitoring history.


# Creating Individual Monitoring Records

To create a new monitoring record for an individual, start by navigating to the Monitoring Dashboard. Once there, click on the **+ New Monitoring Record** button. Follow the simple workflow to:

1. Enter the individual's details.
2. Select the activities you want to monitor.
3. Confirm the details.

The system will then run the selected activities on the individual and create an ongoing monitoring record.

<figure><img src="/files/9FRgkp9OzJlgBR4vIyue" alt="" width="563"><figcaption><p>Creating a Monitoring Records</p></figcaption></figure>

**Step 1. Create a monitoring record:**

Begin by navigating to the Monitoring Dashboard. Click on the "+ Monitoring Record" button to start a new monitoring check for an individual.

&#x20;![](/files/3vqDQQmS6XkvNXYS6Ljz)

&#x20;**Step 2. Add individual details:**

You will be prompted to enter the personal details of the individual you wish to monitor. The only mandatory fields are first name and last name, but providing additional information, such as date of birth, is highly recommended for more accurate results.

**Step 3. Select monitoring activities:**

Next, choose the activities you want to monitor for the individual. There are two key monitoring activities to select from:

* PEP & Sanctions monitoring&#x20;
* Adverse Media monitoring

Choose Yes or No. Selecting "Yes" means the system will continuously monitor the individual against the activities database. If new records appear, the system will notify you with an updated status.

#### Step 4. Confirm and complete the monitoring setup

Before running the monitoring check, you will see a summary screen displaying the individual's details and the selected monitoring activities. Review the information to ensure accuracy. Once confirmed, the system will begin monitoring the individual, and a monitoring record will be created. You will receive notifications for any relevant updates or changes in the individual's status.


# Reviewing Individuals' Monitoring Records

The "Individual monitoring detail page" offers a detailed and organised view of an individual’s monitoring record, including their activity status, and any actions required for review.

<figure><img src="/files/vpMqOGmAuTOz7RDF7sbP" alt=""><figcaption><p>Individual monitoring records</p></figcaption></figure>

1. **Details section:** The "Details section" provides a summary of the individual’s essential information, including their unique monitoring reference ID, start date, and last recorded activity.
2. **About section:** The **"**&#x41;bout section" provides an overview of the activity types being monitored for the individual, including details on when monitoring began and the dates of the most recent activities found.
3. **Activity section:** The "Activity section" serves as the event log for monitoring activities, detailing specific events related to the individual’s monitoring record. If any activity is incomplete or requires action, the monitoring record will be marked as requiring "Review". Each event is shown with its current status and creation date. If the status is Review, you can manually accept or reject the event by clicking the View button next to it for further details.
4. **Download PDF:** This allows users to download the individual’s monitoring record as a PDF file, providing a summary of the monitoring details for offline use or reporting purposes.


# Creating Company Monitoring Records

To create a new monitoring record for a company, start by navigating to the Monitoring Dashboard. Once there, click on the **+ New Monitoring Record** button. Follow the simple workflow to:

1. Enter the company details.
2. Select the activities you want to monitor.
3. Confirm the details.

The system will then run the selected activities on the individual and create an ongoing monitoring record.

<figure><img src="/files/BEIeKRPURUB8Qw0bV34V" alt="" width="563"><figcaption><p>Creating a Monitoring Records</p></figcaption></figure>

**Step 1. Create a monitoring record:**

Begin by navigating to the Monitoring Dashboard. Click on the "+ Monitoring Record" button to start a new monitoring check for a company.

&#x20;![](/files/3vqDQQmS6XkvNXYS6Ljz)

&#x20;**Step 2. Add company details:**

You will be prompted to enter the details of the company you wish to monitor. The only mandatory fields are company name and Country of incorporation, but providing additional information, such as registration number, is highly recommended for more accurate results.

**Step 3. Select monitoring activities:**

Next, choose the activities you want to monitor for the company. There are two key monitoring activities to select from:

* Sanctions monitoring&#x20;
* Adverse Media monitoring

Choose Yes or No. Selecting "Yes" means the system will continuously monitor the company against the activities database. If new records appear, the system will notify you with an updated status.

#### Step 4. Confirm and complete the monitoring setup

Before running the monitoring check, you will see a summary screen displaying the company details and the selected monitoring activities. Review the information to ensure accuracy. Once confirmed, the system will begin monitoring the company, and a monitoring record will be created. You will receive notifications for any relevant updates or changes in the company's status.


# Reviewing company's Monitoring Records

The "Company monitoring detail page" offers a detailed and organised view of a company monitoring record, including their activity status and any actions required for review.

<figure><img src="/files/9Myv8lCR2H4qTVwGUaqS" alt=""><figcaption><p>Company monitoring records</p></figcaption></figure>

1. **Details section:** The "Details section" provides a summary of the company's essential information, including its unique monitoring reference ID, start date, and last recorded activity.
2. **About section:** The **"**&#x41;bout section" provides an overview of the activity types being monitored for the company, including details on when monitoring began and the dates of the most recent activities found.
3. **Activity section:** The "Activity section" serves as the event log for monitoring activities, detailing specific events related to the company monitoring record. If any activity is incomplete or requires action, the monitoring record will be marked as requiring "Review". Each event is shown with its current status and creation date. If the status is Review, you can manually accept or reject the event by clicking the View button next to it for further details.
4. **Download PDF:** This allows users to download the company monitoring record as a PDF file, providing a summary of the monitoring details for offline use or reporting purposes.


# Account Settings

<img src="/files/OGbPhjuTfUGdjaD0VF12" alt="" data-size="line"> The Settings section, accessible exclusively to admin users, serves as a centralised hub for managing your account. This section includes both General and Application areas, which provide detailed information about the company and allow for the configuration of accounts to meet your specific needs. In the Application area, you can configure specific application types and PEP & Sanctions Filtering functionalities to align with your business workflow and requirements.

Admin users have the capability to perform actions such as adding, modifying, or removing user accounts, thereby maintaining control over access and permissions within the system.

The following section can be accessed in the settings area.

<table data-card-size="large" data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/PiCFqsR7aOgv32tjnA4O">/pages/PiCFqsR7aOgv32tjnA4O</a></td><td></td></tr><tr><td><a href="/pages/nRfG01xgNiV6GpgVGgZc">/pages/nRfG01xgNiV6GpgVGgZc</a></td><td></td></tr></tbody></table>


# General

In the General Information section, you will find a summary of the information collected during the sign-up process about your company. This feature aims to provide Admin users with easy access to their company information for review and updates as needed. This not only saves time and effort but also ensures that the information remains accurate and up-to-date.

The following section can be accessed in the general settings area.

<table data-card-size="large" data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/IBAi61GnkbMPZfJfgvz9">/pages/IBAi61GnkbMPZfJfgvz9</a></td><td><a href="/pages/IBAi61GnkbMPZfJfgvz9">/pages/IBAi61GnkbMPZfJfgvz9</a></td></tr><tr><td><a href="/pages/W9f8r1W5O0Gqdosei3vn">/pages/W9f8r1W5O0Gqdosei3vn</a></td><td></td></tr><tr><td><a href="/pages/vElAWuJIPz41rl3KbvsR">/pages/vElAWuJIPz41rl3KbvsR</a></td><td></td></tr><tr><td><a href="/pages/jJ0ReNHDnCedGTRvbH8e">/pages/jJ0ReNHDnCedGTRvbH8e</a></td><td></td></tr><tr><td><a href="/pages/vSHRAtQ2OR0O9bKji2Kr">/pages/vSHRAtQ2OR0O9bKji2Kr</a></td><td></td></tr><tr><td><a href="/pages/0kgBajQRU4EkvddvqZOF">/pages/0kgBajQRU4EkvddvqZOF</a></td><td></td></tr></tbody></table>


# Company Details

The Company Details section provides essential information about your company. This includes the company's name, logo, address, phone number, website, support contact information, and display name. This feature ensures that users have easy access to their company information for review and updates as needed

1. **Access:** Users with admin rights can access the Account Information section. This ensures that only authorised personnel can view and modify account details.
2. **Viewing Company Information:** Users can view comprehensive company information in this section, including the company logo, business profile information, address, phone number, and support email address. Additionally, this section allows an admin user to set their display name. If they prefer to use an abbreviated version of the company's name on the mobile app, they can save it as the display name. This will be displayed accordingly.
3. **Uploading company logo**: In case discrepancies or updates are required, admin users have the option to update relevant areas. For example, if there is a discrepancy in the company logo, users can simply upload the updated logo here.
4. **Updating Account Details:** Users can update account details such as company address, phone number, and email address as necessary. This ensures that account information remains accurate and up-to-date.

{% embed url="<https://vimeo.com/919616602>" %}
Adding a company logo
{% endembed %}


# Branding

On the Verify Portal, admin users can now easily set up and customise the brand screen for the Verify mobile app to align with their brand image. This can be done directly from the settings area, where admins have the ability to:

* Customise company logos
* Add a customise welcome message to align with their brand image
* Add additional information with links
* Adjust text colours for the branding screen
* Select background colours  for the branding screen
* Provide links to the company’s Terms and Conditions and Privacy Policy

All configurations are securely stored on the backend for each company account, ensuring that branding elements are consistently applied whenever invite codes are sent to mobile users.

<div data-full-width="true"><figure><img src="/files/3ouB3ypmOsS8eRuaWag9" alt="" width="563"><figcaption><p>Splash screen configuration</p></figcaption></figure></div>

For mobile users, the splash screen feature enhances their journey by providing a seamless sequence that starts with the invite code screen, followed by a custom branded screen configured by the Verify portal admin, and then the Verify terms and conditions. Each user will see a company-branded splash screen prompting them to perform the KYC check, creating a strong first impression of trustworthiness and reassuring users of the app's legitimacy, thereby making them more comfortable sharing their personal information.

#### Toggle Option for Splash Screen

A toggle option is available for admins to enable or disable the branding splash screen features to meet their business needs. Admins can adjust visibility for the following elements by using the toggle options:

1. **Display splash screen**: Admins can enable or disable the branding splash screen. If disabled, the splash screen will not appear after the invite code screen.
2. **Use company display name**: Admins can choose whether to display the company name on the splash screen. The display name can be a short name, abbreviation, or brand name that users recognise and associate with the business, ensuring familiarity and trust.
3. **Additional information/links section**: Admins can enable the section to display additional information and links to provide further context or resources to users. You can add multiple links with customisable text and URL links to guide mobile users to external resources or other important sections.
4. **Terms & Conditions**: The option to display or hide the Terms & Conditions section is available, giving admins flexibility in how they present legal and policy details.

If a toggle option is disabled, the corresponding information will not appear on the branding splash screen in the mobile app after the invite code screen. This functionality gives admins the flexibility to customise the splash screen display according to their specific requirements and preferences.


# Managing Users

{% embed url="<https://vimeo.com/919616657>" %}
Adding a user to your account
{% endembed %}

## Permission levels

There are two types of permission levels in the product.

<table><thead><tr><th width="180">Role</th><th>Capabilities</th></tr></thead><tbody><tr><td>Admin</td><td>The  Admin user possesses full administrative privileges, granting access to the settings area for making various changes. This includes updating company records as needed, inviting teams to use the  Verify by Tiller portal, and creating mandate types.</td></tr><tr><td>Staff</td><td>Staff users are exclusively authorised to conduct KYC checks on the clients and do not possess access to the settings area.</td></tr></tbody></table>


# Billing Details

In the billing section, you will find the billing officer information provided during the initial stages of your engagement. This information is essential for us and you to ensure timely invoicing is sent according to your contract. If there are any changes to the billing officer's details, you have the option to update the details directly within your account, eliminating the need to contact us for the update. The billing information will be promptly updated accordingly.


# Consultants

Consultant information can be included when creating an application, especially if you are completing checks on behalf of another company representative. This could include a team member in your office who is handling client interactions. These consultants can be assigned to specific applications, and their profiles are manageable from the Settings area.

You can easily manage consultant profiles by adding new consultants, editing their details, deactivating them, or removing them entirely from your verify setting area.

<figure><img src="/files/P0l2TZjKksgZlZMM7DMc" alt=""><figcaption><p>Consultants Configuration </p></figcaption></figure>

<details>

<summary>Creating a New Consultant</summary>

* Click the **“+ Create Consultant”** button.

<figure><img src="/files/NuhmBkolboLykW9nEgo6" alt="" width="188"><figcaption></figcaption></figure>

* Enter the consultant's full name and email address.
* Confirm to add them to the Verify portal, they will now appear in the dropdown when assigning consultants to applications.

</details>

<details>

<summary>Editing a Consultant</summary>

* Click the **Edit pencil icon** next to a consultant’s name.
* Update their details in the modal that appears.
* Confirm to save the changes.

<figure><img src="/files/uIxTLayMHrRIjOi2BzOR" alt="" width="375"><figcaption><p>Edit Consultants</p></figcaption></figure>

</details>

<details>

<summary>Enabling/Disabling a Consultant</summary>

* Use the **Active toggle** to turn a consultant on or off.
* If disabled, the consultant will not be selectable when creating new applications.
* You can re-enable them anytime by toggling them back on.

</details>

<details>

<summary>Deleting a Consultant</summary>

* Click the **Delete icon** to remove a consultant from the Verify Portal
* A confirmation message will appear. Once confirmed, the consultant will be permanently deleted.

</details>


# Data Retention

## Dpo Details

The DPO officer information provided during the initial stages of your engagement can be found in the DPO section. In the event that any changes need to be made to the DPO officer's details, you can update the details directly within your account, avoiding the need to contact us.

## Data Retention

The **Data retention settings** enable administrators to control how long client data is retained and determine when it will be archived or permanently deleted. By default, client data is retained for **8 weeks**. During this period:

* **Auto-Archiving**: Applications are automatically archived after **6 weeks** (42 days).
* **Permanent Deletion**: Archived data is permanently deleted after an additional **2 weeks** (56 days total).

These settings are essential to ensure your platform complies with data protection regulations while securely managing sensitive client information. You can configure the data retention settings according to your business requirements.

<figure><img src="/files/ikqD62oe5vSwQ1V5UAVA" alt="" width="375"><figcaption><p>Configure the data retention settings </p></figcaption></figure>

**Steps to configure data retention settings**

1. **Delete date:**  As an admin, you can define the period for which the data will be retained. You can choose a retention period anywhere between **56 days (8 weeks)** and **90 days**. This determines how long data associated with applications will be stored before it is eligible for deletion.
2. **Automatic archive:** You have the option to enable automatic archiving of applications. When this option is selected, all applications will be archived **14 days before the deletion date**. Archiving allows you to retain a record of the data without keeping it in the active system.
3. **Delete and archive email:** With this setting enabled, users assigned to applications or check records will receive an email notification **three days prior to the archive or delete action**. This helps ensure that user is informed before data is archived or deleted, giving them the opportunity to take action if necessary.


# Application

In the application section, you can configure and manage your account to align with your business requirements and customise it to meet your specific needs. This customised approach ensures a personalised experience that matches your unique operational needs. It gives you more control over your account, making it easier to manage application types and filter results for PEPs and sanctions.

The following section can be accessed in the application settings area.

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/yMumCu2TS818vGtOHP7i">Managing Application Types</a></td><td><a href="/pages/yMumCu2TS818vGtOHP7i">/pages/yMumCu2TS818vGtOHP7i</a></td></tr><tr><td><a href="/pages/pH71oYvjP5d3mAW2Sigh">PEP &#x26; Sanctions Filtering</a></td><td></td></tr><tr><td><a href="/pages/90DN7yaDNnE67ZkSmqWc">SOF Risk Scoring Levels</a></td><td></td></tr><tr><td>Additional documents</td><td></td></tr><tr><td>Forms</td><td></td></tr></tbody></table>


# Managing Application Types

Under this section, admin users have the capability to manage their application types, tailoring them to specific business needs. Upon signing up, each user account is automatically associated with the default Core Identity (including Address Check) application type functionality.

When the user clicks on any application type, it will take them to the corresponding application type view page. Where admin users can access the following information:

<figure><img src="/files/Sj6PZcTEHUAOnSCb2VBV" alt="" width="563"><figcaption><p>Application type view page </p></figcaption></figure>

<details>

<summary>Overview of the application type view page</summary>

* **Application Type details:**  The application details will provide a brief overview of the application type. The application name type field makes it easy for the user to select the application, and a description of the application type will be displayed when the user chooses a particular application type. You can easily edit the name and description by using the edit functionality.
* **Associated individuals info:** The total count of individuals linked to the application type will be presented here. It's important to note that if any individual is associated with the application type, the deletion of the application type is restricted.
* **Auto-email reminders:** The status of the auto-email reminder for each mandate type can be viewed to determine if it is inactive or active. By default, the auto-email reminders are inactive for Core Identity (including Address Check)
* **Checks info:** The user can be able to see concise details regarding the checks linked to the application type, encompassing both the basic checks and any additional checks, if applicable.
* **Additional documents:** The user can view any additional documents that have been attached to the application type.
* **Enable/ functionality:** It is possible to toggle between active and inactive application types, with built-in enabled functionality.
* **Edit/ functionality:** Users have the ability to edit the name, description, additional documents, and auto-email reminders of an application type. However, once the application type is created, changes to checks are restricted
* **Delete/ functionality:** Users can only delete an application type if it is not associated with any individuals. If the application type is linked with active applications or individuals, the system will provide a warning message.

</details>

**New application Type:** To adapt application types to suit your business requirements, admin users can create custom variations by following these simple steps.

<details>

<summary>Step 1: Create a new application type</summary>

* Start a new application by clicking on the **“+ New application Type”** button&#x20;

  <figure><img src="/files/r5qCya0tRJ1o2aCswWqJ" alt="" width="375"><figcaption><p>Add new application type</p></figcaption></figure>

</details>

<details>

<summary>Step 2:  Provide details for the application type</summary>

* Provide a name and description for the application type.&#x20;

The application type name can be customised with a maximum of 50 characters and visible to all users during the application creation process, allowing them to select this specific application type. When users select this application type on their application, a description will appear explaining the type of application and the necessary actions to be taken on the mobile App by the client.

* For each application type, you can toggle automated email reminders on or off.&#x20;

  <figure><img src="/files/L5T5JHmxa8KgZRB12O6P" alt="" width="375"><figcaption><p>Auto-email reminder</p></figcaption></figure>

When this feature is active, Verify will automatically send email reminders for up to six days to mobile customers who have not completed the required mobile actions.

</details>

<details>

<summary>Step 3: Add checks</summary>

You now have the option to select both basic and additional checks from the provided list, based on your subscription plan. These checks define the specific actions users must complete within the mobile app, ensuring the necessary checks are performed.

</details>

<details>

<summary>Step 4: Add forms</summary>

You can add forms to this application. These forms will need to be completed by your customer as part of the verification process. To add a form, simply click +Include Forms. This will display a list of forms you’ve created to meet your business requirements. Select the relevant forms you want to include in the application, and they will be added seamlessly.

</details>

<details>

<summary>Step 5: Add additional documents</summary>

After selecting the check, you have the option to add additional documents if needed. You can choose a document from the pre-configured default list, which includes commonly used documents. If the document you require is not listed, you can add a new one by clicking the "**+** **Additional Document"** button.

<img src="/files/ysTndoKGFF3qz7vfPSX4" alt="" data-size="original">

The form will appear, prompting you to enter the **Document Name**, **Document Type**, and **Description** for the new document you would like to add to the application type.

This step is optional. If you prefer not to add any additional documents to the application type, simply click finish to complete the application creation process.

</details>

<figure><img src="/files/CjphZ8K24dqeI2Rb8bbZ" alt=""><figcaption><p>A  workflow for creating  a new Application-type </p></figcaption></figure>


# Screening Preferences

To improve the accuracy of our PEP & Sanctions and Adverse Media service, we have included filter options in the Verify Portal. These filters enable admin users to customise and manage their PEP and Sanctions settings based on their business requirements for their  Verify Portal account. Users can now specify which filters to apply for PEP, Sanction, and Adverse Media checks.&#x20;

These filters include:

## 1. Date of birth filters

{% hint style="info" %}
**Purpose:** To narrow down potential matches by comparing the date of birth provided with the dates of birth listed in multiple reliable resources for PEPs.

**Function:** The Verify system cross-references the date of birth provided by the user against the multiple reliable database of PEPs. This ensures that the person being checked has the same or a very similar date of birth as a listed PEP.
{% endhint %}

Here is how the date of birth filters work, including examples for each scenario:

### 1.1 Include all results:

This filter will return all potential matches from the database, even if the date of birth is not provided or does not match the one being checked.

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td>If you are checking John Snow born on 1st January 1980, and the database has multiple John Snow with various birth dates or no birth dates at all, all these entries will be included in your results.</td><td>John Snow - 01/01/1980<br>John Snow - 07/05/1980<br>John Snow - 01/01/1981<br>John Snow - (not available)</td></tr></tbody></table>

### 1.2 Exclude if the date of birth unknown:

This filter excludes results where the date of birth is not available from reliable sources. Its function is to eliminate any potential matches that do not have a date of birth listed in the database. The results that are filtered out are still available to view within an expandable element within the Portal.

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td>If you are checking John Snow born on 1st January 1980, and the database includes John Snowy without birth dates, those entries will be excluded. Only John Snowy with a known birth date will be considered.</td><td><p>John Snow - 01/01/1980<br>John Snowy - 01/01/1981</p><p><strong>Excluded result:</strong></p><p>John Snowy -(not available)<br>John Smith Snow -(not available)</p></td></tr></tbody></table>

### **1.3 Match the exact date of birth:**

To include only results where the date of birth exactly matches the provided date of birth, if the date of birth is available in the source, this filter will return only those entries where the date of birth exactly matches the one you are checking. The results that are filtered out are still available to view within an expandable element within the Portal.

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td>If you are checking Michael Johnson born on 1st January 1985, and the database has several Michael Johnsons with different birth dates, only the Michael Johnson with the exact birth date of 10th October 1975 will be included in the results.</td><td><p>Michael Johnson  - 01/01/1985<br>Michae Johnsons - 01/01/1985</p><p><strong>Excluded result:</strong></p><p>Michael Johnson - 05/09/1985 <br>Michael Johnson -(not available)</p></td></tr></tbody></table>

## 2. Name match filters

{% hint style="info" %}
**Purpose:** To identify potential matches based on names. These filters are used to verify the identity of users or to identify similar-sounding names listed in multiple reliable sources for PEPs.

**Function:** The Verify system uses algorithms to match the names provided against the names of PEPs. This includes exact matches and fuzzy matches (accounting for slight variations or misspellings). By considering these factors, the algorithms can accurately identify potential matches even in cases of minor discrepancies in spelling.
{% endhint %}

Here is how the name match filters work, including examples for each scenario:

### 2.1 Exact name required

This filter ensures that only entries with an exact match of both first and last names are included in the results, which is particularly useful if identification accuracy is key and slight variations in first and last names are unacceptable. The filter compares the provided name with entries in the database, returning only those entries in which the first name and the last name match exactly. The results that are filtered out are still available to view within an expandable element within the Portal.

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td>Suppose you are searching for "John Smith" in a database. The filter will only include entries that are an exact match, such as "John Smith" or "John A Smith". Entries like "John Smyth," and "Jon Smith," will be excluded because they do not exactly match the provided first and last names.</td><td><p>John Smith  - 01/01/1985<br>John A Smith - 01/01/1985</p><p><strong>Excluded result:</strong></p><p>John Smyth - 01/01/1985<br>Jon Smith - 01/01/1985</p></td></tr></tbody></table>

### 2.2 Surname only (fuzzy match on surname only):

The purpose of this filter is to include results that match the provided surname, allowing for slight variations in spelling or phonetic differences. This is particularly useful in cases where the surname might be commonly misspelt or where variations are common due to transliterations or typographical errors.

This filter works by performing a fuzzy match on the surname, which means it will return entries that are similar to the provided surname within a specified tolerance level. The default tolerance is set at 95%, meaning the surnames need to be 95% similar to be considered a match. The minimum tolerance can be set as low as 80%, allowing for even greater variations, and can go up to 100% for better matches. The results that are filtered out are still available to view within an expandable element within the Portal.

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td><p>If you are searching for "Johnson," the filter will include entries like "Johnston," "Jonson," and "Johnsen" if they fall within the specified tolerance level. Therefore, if the database contains:</p><ul><li>Johnson</li><li>Johnston</li><li>Jonson</li><li>Johnsen</li><li>Jansen</li></ul></td><td><p><strong>At a 95% tolerance level:</strong> the filter will likely include </p><ul><li>Johnson </li><li>Johnston</li><li>Johnsen</li></ul><p><strong>At an 80% tolerance level:</strong> the filter will likely include.</p><ul><li>Jonson</li><li>Jansen</li><li>Johnson </li><li>Johnston</li><li>Johnsen</li></ul></td></tr></tbody></table>

## 3. Gender match filters

{% hint style="info" %}
**Purpose:** The purpose of the gender filter is to refine search results by ensuring that only entries matching the specified gender are included.

**Function:** This filter works by comparing the gender of each entry in the database with the provided gender. Only those entries where the gender matches exactly will be included in the results. This helps in narrowing down the list of potential matches to those that are gender-appropriate, thereby increasing the accuracy of the search.
{% endhint %}

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td>In the case of searching for Alex Smith with the specified gender as Female, the filter narrows down the database to only include entries that identify Alex Smith as female. For example, among the database entries including Alex Smith, Male and Alex Smith, Female, only Alex Smith (Female) will be included in the filtered results.</td><td><p>Alex Smith, Female  - 01/01/1985<br></p><p><strong>Excluded result:</strong></p><p>Alex Smith, Male - 01/01/1985<br></p></td></tr></tbody></table>

## **4. PEP type filters**

{% hint style="info" %}
**Purpose**:  PEP Type Filters categorise and filter Politically Exposed Persons (PEPs) based on specific types or classifications to distinguish between different categories of PEPs. These categories include domestic PEPs, foreign PEPs, family members, or close associates, allowing users to tailor the level of scrutiny and risk assessment. You can view these PEP Types on the [PEP and Sanctions screening page ](broken://pages/rEdFylM2iHlDDuWeXY60)under the ["PEP Source and Type"](broken://pages/rEdFylM2iHlDDuWeXY60#pep-sources-and-types) section.

**Function:** The Verify system allows users to apply PEP Type Filters to specify the types of PEPs they want to include or exclude from their searches and verifications. This functionality helps in focusing on particular subsets of PEPs that are relevant to the user's risk management policies and compliance requirements
{% endhint %}

Here is how the PEP type filters work, including examples for each scenario:

### 4.1 Include all PEP types:

This filter will return results for all individuals classified as PEPs, regardless of whether they are PEPs by their own position or by association with another PEP.

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td><p>If you are searching for "John Snow" within a database that includes entries such as:</p><ol><li>John Snow, a government official (PEP by position)</li><li>Jane Snow, John Snow's spouse (PEP by family association) and </li><li>John Snow, an executive at a state-owned enterprise (PEP by position)</li></ol><p>All three entries will be included in the result. This means the search results encompass all individuals named "John Snow," irrespective of their PEP classification, whether they hold a position that qualifies them as a Politically Exposed Person (PEP) or are associated with a PEP through family ties.</p></td><td>John Snow, government official (PEP by position)<br>Jane Snow, (PEP by family association) <br>John Snow, an executive at a state-owned enterprise (PEP by position)<br></td></tr></tbody></table>

### 4.2 Exclude PEP by family association:

This filter works by excluding entries where an individual's PEP status is solely attributed to their familial relationship with another PEP. Only direct PEPs (due to their own positions) will be included.

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td><p>If you are searching for "John Snow" within a database that includes entries such as:</p><ol><li>John Snow, a government official (PEP by position)</li><li>Jane Snow, John Snow's spouse (PEP by family association) and </li><li>John Snow, an executive at a state-owned enterprise (PEP by position)</li></ol><p>only "John Snow, a government official (PEP by position) and John Snow, an executive at a state-owned enterprise (PEP by position) will be included, while Jane Snow will be excluded</p></td><td><p>John Snow, government official (PEP by position)<br>John Snow, an executive at a state-owned enterprise (PEP by position)</p><p></p><p><strong>Excluded result:</strong><br>Jane Snow, (PEP by family association) </p></td></tr></tbody></table>

## &#x20;**Adverse Media filters**

{% hint style="info" %}
**Purpose:**  The adverse media filter is to detect and highlight individuals mentioned in negative news or media reports.&#x20;

**Function:** The filter works by searching through various sources such as news outlets, media platforms, and public records to find mentions of the person under investigation. It specifically identifies instances where their full name, or something similar, has come up in relation to controversies, scandals, legal issues, or other negative events.&#x20;
{% endhint %}

In an adverse media filter, you can select specific adverse media types such as BRB (Bribery, Graft, Kickbacks, Political Corruption), BUS (Business Crimes like Antitrust, Bankruptcy, and Price Fixing), DEN (Denied Entity), and FOF (Former OFAC List). Depending on the screening process requirements, these types can be enabled or disabled. more information about adverse media types can be viewed in the [Adverse media screening](broken://pages/xIxElj6kMSGvOyGZ2Wtn)

<table data-full-width="false"><thead><tr><th width="452">Example</th><th>Result return</th></tr></thead><tbody><tr><td><p>Suppose you are conducting a screening on John Snow using an adverse media filter and you want to include reports related to bribery and business crimes while excluding other adverse media types. In the adverse media results, you find the following:</p><ol><li>John Snow (Involved in bribery to a high state officer)</li><li> John Snow (Conspiracy to plot a scam in the housing industry) </li><li>John Snow (Tax avoidance scheme) </li><li>John Snow (Possession of drugs) </li></ol><p>In this scenario, only the reports related to bribery and business crimes (the first three entries) will be included in the results, while the report related to possession of drugs will be excluded based on the specified filter settings.</p></td><td><p></p><p>John Snow (Involved in bribery to a high state officer)</p><p>John Snow (Conspiracy to plot a scam in the housing industry) </p><p>John Snow (Tax avoidance scheme) </p><p></p><p><strong>Excluded result:</strong><br>John Snow (Possession of drugs) </p></td></tr></tbody></table>


# Source of funds

We provide our clients with the flexibility to customise risk scoring levels for Source of Funds (SOF) types to meet their specific needs. This customisation ensures that your risk management approach remains robust and compliant over time.

Initially, our system assigns a default risk level (low, medium, or high) to each source of funds type. However, recognising the diversity in compliance needs across businesses and industries, we offer the ability to customise these risk levels to match your operational context through our Verify Portal.&#x20;

<figure><img src="/files/FNAozjT5rvIQ2vbqauIl" alt=""><figcaption><p>SOF risk scoring configuration</p></figcaption></figure>

As an admin user, you have the flexibility to configure the risk scoring levels for each Source of Funds SOF type to match your business's risk appetite. Follow these steps to manage your SOF settings:

1. **Risk Level Configuration:**

   You can set the risk level for each SOF type to low, medium, or high according to your business requirements. This ensures that your risk management approach is tailored to your specific needs.
2. **Evidence Required:**&#x20;

   With the evidence required toggler, you can easily decide if submitting an SOF document is mandatory or optional for mobile users. When the toggler is switched on, mobile users are required to upload the document for the SOF type to proceed further. If the toggler is off, submission is optional, allowing users to complete their SOF type without providing the document.
3. **Enable/Disable SOF Types:**

   You can enable or disable specific SOF types from being displayed on the mobile app using the active toggler option. For example, if you do not want the "Savings /ISA" SOF type to appear on the mobile app, you can deactivate it by toggling the switch off.
4. **Reset to Default Settings**

   If needed, you can reset all configurations to our global default settings by  selecting "Reset All." This will restore the default SOF risk scoring levels initially provided.


# Additional document

The Additional Documents feature in the Verify portal allows you to request extra documents from your clients through the Verify Mobile App. This functionality is integrated into both the application setup process and the settings area, enabling you to configure document requirements based on your business needs.

In the settings area, admins users can customise additional document requests to meet their business requirements. They can view the predefined list of additional document types or create and configure their own. Document types can also be edited as needed.

<figure><img src="/files/zE00RqSsrJaLCn9jrvUT" alt=""><figcaption><p>Manage additional documnets request</p></figcaption></figure>

### Customising "Additional Document" requests:

**Adding a new  "Additional Document":**

* To create a new additional document request, click the **"Add Additional Document"** button. <img src="/files/1uC3kfp9nfzyubJACSIe" alt="" data-size="original">
* A pop-up screen will open, where you can:
  * **Document Name**: Specify the name of the document you need your clients to submit.
  * **Document Type**: Choose the required format (PDF, image, or both).
  * **Description**: Provide a clear description to help your clients understand the purpose of the document.

**Editing existing "Additional** **Document"**:

You can easily edit the name, type, or description of any existing document by clicking the **pencil icon** next to it. This will allow you to update the information as needed.


# Forms

Our Form Feature empowers businesses to create and manage custom forms to collect additional client information during the KYC process. These forms enable you to ask specific, business-relevant questions, ensuring all necessary data is gathered and stored in one place. You can create multiple forms tailored to application types, providing flexibility to meet your requirements.

Once forms are created, they can be easily linked to application types. This allows your customers to complete the required forms seamlessly while undergoing KYC checks through their app. All collected information is stored in one place, streamlining the onboarding process and reducing the need for back-and-forth communication.

<figure><img src="/files/PrEKcioGmigviujyAP0T" alt="" width="563"><figcaption><p>Forms</p></figcaption></figure>

Start a new form by clicking the **“+ New Form”** button and follow these simple steps:

* **Step 1:** Create a Form
* **Step 2:** Add Sections to the Form
* **Step 3:** Add Questions to Each Section
* **Step4:** Review and Submit the Form

<figure><img src="/files/hF6mknxIDqUhtBIphI2b" alt="" width="563"><figcaption><p>Create a new forms</p></figcaption></figure>

**Step 1: Create a new Forms**

Start a new form by clicking on the **“+ New form”** button&#x20;

<figure><img src="/files/AszzLTFWYnbgMGUSsNmu" alt="" width="156"><figcaption></figcaption></figure>

Provide a name and description for your form. The **Form name** and **Description** are essential components that define the purpose and content of your form.

* **Form name:**  The form name should clearly reflect its purpose, making it easy for users to understand its intent. It can align with similar forms used during customer onboarding. A well-defined name helps users quickly identify and distinguish between different types of forms, especially when managing multiple forms.
* **Form description:** The description provides a brief overview of the form’s purpose and the type of information it collects. It ensures users understand why the form is being used and what they need to complete it.

{% hint style="success" %}
**Example:**&#x20;

**Form name:** *Business registration form*&#x20;

**Form description:** *This form gathers essential business details from customers, such as company name, registration number, and payment information.*
{% endhint %}

**Step 2: Add sections to the form**

Organising your form into sections helps improve its structure, usability, and logical flow, making it easier for users to complete.

* Divide the form into distinct sections based on the type of information you need to collect.
* You can include up to 5 sections in one form, each with a clear section title and description.

{% hint style="success" %}
**Example:**&#x20;

**Section 1:**

**Title**: *Business Details*

**Description:**  *Provide the basic details about your business, such as name and registration number.*

***

**Section 2:**

**Title**: *Contact Information*

**Description:**  *Enter contact details for your business, including the primary contact person.*
{% endhint %}

#### Step 3: Adding questions to your section

Once you have defined the section titles and descriptions, you can add up to 10 questions per section based on your business requirements. These questions should be tailored to gather the specific information you need from your clients.&#x20;

You can easily rearrange the order of questions within each section to maintain a logical flow. Simply drag and drop the questions up or down to adjust their placement.

Below are the available answer types that mobile users can provide in response to your questions:

* **Short text:**

&#x20;*A simple text field where users can input brief answers. Ideal for short pieces of information like names or small details.*&#x20;

{% hint style="success" %}
***Example**:* *What is your full name?*
{% endhint %}

* **Long text:**

*A larger text field for longer, detailed responses. Perfect for questions that require more explanation.*&#x20;

{% hint style="success" %}
***Example:*** *Please describe the nature of your business.*
{% endhint %}

* **Number**:&#x20;

A *numeric input field for numbers only makes it easy for users to enter things like registration numbers, amounts, or quantities.*&#x20;

{% hint style="success" %}
***Example**: What is your company registration number?*
{% endhint %}

* **Date:**

&#x20;*A date picker that allows users to select a date easily. This is great for questions involving specific dates like birthdates or company founding dates.*&#x20;

{% hint style="success" %}
***Example**: What is your company's founding date?*
{% endhint %}

* **Multiple select:**

*Allows users to select more than one option from a list. Ideal for questions where more than one answer may apply.*

{% hint style="success" %}
&#x20;***Example**: Which of the following services does your business provide?*&#x20;

*(Select all that apply) Options:*&#x20;

* *Consulting*

* *Development*

* *Marketing, Design*
  {% endhint %}

* **Choice (single select)**

Users can select only one option from a list. This is used for questions where only one answer is appropriate.

{% hint style="success" %}
**Example**:

*What type of business structure do you have?*&#x20;

* **Options 1:** *Sole Proprietor*

* **Options 2:** *Partnership*

* **Options 3:** *Corporation*
  {% endhint %}

* **Phone Number**

Allows users to enter their phone number with the country code. Input is restricted to numeric values

{% hint style="success" %}
**Example**:

*What is your contact number?* (Enter phone number with country code)
{% endhint %}

* **Email Address**

Captures a valid email address from the user. Includes built-in format validation to avoid incorrect entries.

{% hint style="success" %}
**Example**:

What is your email address?
{% endhint %}

* **Website Address**

Requires users to provide a valid website URL. The input must start with `http://` or `https://` and avoid special characters.

{% hint style="success" %}
**Example**:

Enter your business website:
{% endhint %}

* **Currency**

Users can select a currency and input a numerical amount to represent income, fees, or other financial data.

{% hint style="success" %}
**Example**:

How much is your monthly income?
{% endhint %}

**File Upload:**

Users can upload required documents or images directly via mobile. Supports image or PDF formats.

{% hint style="success" %}
**Example**:

Please upload your proof of identity.
{% endhint %}

**Address:**

Allows users to enter structured address details, including street, city, state, and postal code.

{% hint style="success" %}
**Example**:

What is your current address?
{% endhint %}

**Country:**

Users can select a country from a predefined list

{% hint style="success" %}
**Example**:

Which country do you currently reside in?
{% endhint %}

By choosing the right answer types, you ensure that your mobile users have a smooth experience while submitting their information.

<figure><img src="/files/s7tgZdHOq6LVueqRIymM" alt="" width="563"><figcaption><p>Added question to sections</p></figcaption></figure>

**Step 4:** **Review and submit the form**

Once you have added sections and questions to the form, you can easily review it. If needed, you can make edits to the questions or sections, or delete them. Once you are satisfied with the structure, simply click **"Finish"** to create the form. Your form is now ready, and you can easily add it when creating an application type.


# Income & employment configuration

The Previous Employment and Income History Configuration allows you to capture your user's historical income records based on your business requirements. This setting is managed through a toggle switch in the Verify Portal. When enabled, it prompts the mobile user to provide details of their previous employment and income. You can also define a custom time range from 1 to 10 years to determine how far back the mobile user history should be collected. This ensures that only relevant financial data is gathered in line with your application needs.

<figure><img src="/files/wvQfoup9LM023y7WfWqA" alt=""><figcaption><p> Income &#x26; employment configuration</p></figcaption></figure>


# My Profile

<img src="/files/svcXL4WoNB8ioMJcpLwz" alt="" data-size="line"> At the bottom of the left-hand side menu on the Verify Portal, you will see your initials displayed above the Logout button. Clicking on your initials will take you directly to the My Profile area.

The **My Profile** area is designed to give users control over their personal information, password management, and Two-Factor Authentication (2FA) settings. This area is divided into three sections:

1. **My Info**
2. **Change password**
3. #### 2 Factor Authentication

<figure><img src="/files/K4SWLx5B3YwIx4RwPZCI" alt="" width="375"><figcaption><p>My Profile </p></figcaption></figure>

### **My Info:**

In this section, you can view  the personal information associated with your account:

* **Name**: Your full name.
* **Job Title**: Your role or designation in the company.
* **Email Address**: The email address linked to your account.

This information reflects the details provided during account creation.

***

### **Change password:**&#x20;

To update your password, simply enter your current password, followed by your desired new password, and confirm the new password to complete the process.

For enhanced security, please ensure that your new password meets the following requirements:

* A minimum of 12 characters in length.
* A combination of uppercase and lowercase letters.
* Include one or more numerical digits.
* Use of special characters such as! , @ ,# , & , $ ,%&#x20;

***

### 2 Factor Authentication:

For enhanced account security, you can enable, disable, or update your Two-Factor Authentication (2FA) settings from here:

* **Setting Up 2FA:** If you did not set up Two-Factor Authentication (2FA) during the onboarding process, you can easily do so later by clicking on the **Enable** button in the 2FA settings section. Follow the step-by-step instructions provided to complete the setup.

  * Scan the QR code displayed on the screen using a compatible authenticator app (e.g., Google Authenticator or Microsoft Authenticator).
  * Enter the verification code generated by the app into the designated field.
  * Confirm the setup to enable 2FA for your account

  <figure><img src="/files/g4tOixHqblbCXWiooLrL" alt="" width="375"><figcaption><p>Set up 2FA</p></figcaption></figure>
* **Recovery codes:** Once 2FA is set up, you will receive recovery codes. These codes are crucial if you lose access to your authenticator app. Please store them securely in a safe location.
* **Managing 2FA:** Once 2FA is enabled, the **Enable** button will change to a **Manage** button.
  * If you wish to disable 2FA, simply click on the **Manage** button. A confirmation pop-up will appear, allowing you to turn off 2FA. However, we highly recommend keeping 2FA enabled to ensure optimal security for your account.


# Help/ Support

In our Help and Support section, you will discover a wide range of resources to help you navigate and utilise our Verify Portal effectively. Whether you are updating your account, creating applications, troubleshooting issues, or exploring specific features, click on the button to be redirected to the relevant section. We ensure that you have accurate and consistent information about portal features and functionality all the time. This setup empowers you to find solutions independently, minimising search time.

<figure><img src="/files/ZMf3oar4R76rxxQPsRrj" alt="" width="563"><figcaption><p>Get in touch</p></figcaption></figure>

For additional support, you can easily get in touch with our support team directly from the portal by sending an email. This will provide you with a seamless experience for seeking guidance or assistance.

Here are a few examples of the buttons you can access in our Help Desk:

<table data-card-size="large" data-view="cards"><thead><tr><th data-type="content-ref"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/spaces/e9f96cZsZ1bEGJR6diKz/pages/H9xwW9WLCzi7ZntYrHCV">/spaces/e9f96cZsZ1bEGJR6diKz/pages/H9xwW9WLCzi7ZntYrHCV</a></td><td></td></tr><tr><td><a href="/spaces/e9f96cZsZ1bEGJR6diKz/pages/hVR8nyK8fvzLm6VduObh">/spaces/e9f96cZsZ1bEGJR6diKz/pages/hVR8nyK8fvzLm6VduObh</a></td><td></td></tr></tbody></table>


# Welcome to the Trust Centre

When it comes to digital client onboarding and Anti-Money Laundering (AML) checks, building trust is critical to everything we do. We understand that handling sensitive client data and ensuring regulatory compliance are paramount to your operations.

This trust centre is designed to provide you with complete transparency into our commitment to **security, privacy, and compliance**. Here, you'll find detailed information about our robust technical and organizational measures, our adherence to global data protection regulations, and the rigorous processes we have in place to safeguard your data, your client's data and ensure the integrity of our services.

Explore the sections below to learn more about how we build and maintain trust, empowering you to onboard clients confidently and securely.

***

## Due Diligence Pack

We recognize that onboarding a new technology partner requires rigorous assessment, particularly within the regulated sectors we serve. The Due Diligence Pack is designed to streamline your vendor verification process by providing centralized access to Tiller Technologies’ critical corporate and operational data. To accelerate your review, we have included a downloadable, **pre-completed Due Diligence Assessment Questionnaire**. This comprehensive document anticipates and answers standard regulatory, security, and governance queries, ensuring your risk and compliance teams have the detailed information they need immediately, without the wait.

{% content-ref url="/pages/at3IPF6h2ai0lRJZtSfi" %}
[Due Diligence Pack](/trust-centre/trust-centre/due-diligence-pack)
{% endcontent-ref %}

***

## Trust Components

Tiller Technologies has implemented the widely accepted Information Security Management System (ISMS), making it compliant with the internationally recognized ISO/IEC 27001:2022 standard. This framework is foundational to Tiller's operations, providing clear guidelines for the systematic management of information security, data governance and business compliance.

The ISMS framework helps Tiller ensure it can manage the confidentiality, integrity, and availability of all its information assets, including it SaaS[^1] platforms, networks, applications, and services. ISMS serves as a dynamic and systematic approach to identify and manage information security risks, fostering continuous improvement of Tiller's security controls to protect against evolving threats and uphold the trust placed in its operations.

<figure><img src="/files/43ZCz7TgCmM7vtNLOw07" alt="Information Security Management System Framework"><figcaption></figcaption></figure>

See below for detailed Information on our commitment to information **security, data protection, reliability, and compliance.**&#x20;

{% content-ref url="/pages/HGHvjApMbjKnKdm739gZ" %}
[Information Security](/trust-centre/trust-components/information-security)
{% endcontent-ref %}

{% content-ref url="/pages/4lYVm0HpwA9NhCaAdf9U" %}
[Data Protection](/trust-centre/trust-components/data-protection)
{% endcontent-ref %}

{% content-ref url="/pages/MoNZKrO1p4bxMeKb3KLu" %}
[Cloud & Reliability](/trust-centre/trust-components/cloud-and-reliability)
{% endcontent-ref %}

{% content-ref url="/pages/Vdm9XbV7xPsctb491A1y" %}
[Risk & Compliance](/trust-centre/trust-components/risk-and-compliance)
{% endcontent-ref %}

***

## Regulatory Compliance Performance

**Verify by Tiller** is purpose-built to satisfy complex AML, CFT, and CPF obligations for regulated businesses across the UK, the Crown Dependencies (Jersey, Guernsey, Isle of Man), and international financial centres. To demonstrate how our platform supports your specific regulatory commitments, we have provided helpful information on our alignment with key jurisdictional authorities below.

{% content-ref url="/pages/w28OjMz3Somn5RpMjUsV" %}
[Jersey Financial Services Commission](/trust-centre/regulatory-compliance/jersey-financial-services-commission)
{% endcontent-ref %}

{% content-ref url="/pages/N3dgJf2VaDdlD56Az24v" %}
[Guernsey Financial Services Commission](/trust-centre/regulatory-compliance/guernsey-financial-services-commission)
{% endcontent-ref %}

{% content-ref url="/pages/6Gog70DADG0wRXGX5SBs" %}
[Isle of Man Financial Services Authority](/trust-centre/regulatory-compliance/isle-of-man-financial-services-authority)
{% endcontent-ref %}

{% content-ref url="/pages/uJPdVGifyWmJX70M1nDH" %}
[Bermuda Proceeds of Crime Regulations & BMA Guidance](/trust-centre/regulatory-compliance/bermuda-proceeds-of-crime-regulations-and-bma-guidance)
{% endcontent-ref %}

[^1]: Software as a Service


# Due Diligence Pack

Welcome to the Tiller. As a trusted partner to regulated companies across the Channel Islands, UK, and beyond, we recognize that our clients entrust us with their most sensitive data—and their reputations. Our mission to streamline compliance onboarding is underpinned by an unwavering commitment to transparency and regulatory alignment.

This page provides standard information on the company and its product usually required during a due diligence assessment. In addition, from this page you can download a completed due diligence questionnaire on Tiller Technologies and its Verify by Tiller platform to simplify your assessment.

## Company Details

{% columns %}
{% column width="25%" %}
Legal Name
{% endcolumn %}

{% column %}
Tiller Technologies Limited
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Description
{% endcolumn %}

{% column %}
Headquartered in Jersey, Channel Islands, Tiller Technologies (‘Tiller’) is a multi-award-winning provider of cutting-edge customer onboarding technology.

We specialise in transforming how regulated & supervised professional & financial services businesses operate. Initially focused on creating bespoke solutions for financial services. Tiller expanded its capabilities with the launch of our SaaS Digital AML solution, **Verify by Tiller**, in January 2023.

Our in-house expertise, deep industry knowledge, and familiarity with stringent offshore regulatory frameworks enable us to deliver a high-quality, accessible AML solution.

At Tiller, we pride ourselves on offering a boutique customer experience, from implementation to ongoing support, ensuring our clients have the tools they need to thrive in a demanding regulatory landscape.
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Company Website
{% endcolumn %}

{% column %}
<https://www.tillertech.com/>
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Company Type
{% endcolumn %}

{% column %}
Registered Company Private
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Registration Date
{% endcolumn %}

{% column %}
15<sup>th</sup> May 2019
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Registration No:
{% endcolumn %}

{% column %}
[129056](https://www.jerseyfsc.org/registry/registry-entities/entity/313364)
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Company Registry
{% endcolumn %}

{% column %}
[Jersey Financial Services Commission Registry](https://www.jerseyfsc.org/registry/registry-entities/entity/313364)
{% endcolumn %}
{% endcolumns %}

## Parent Company Details

{% columns %}
{% column width="25%" %}
Parent Company
{% endcolumn %}

{% column %}
[Tiller Group Limited](https://www.jerseyfsc.org/registry/registry-entities/entity/300079)
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Company Type
{% endcolumn %}

{% column %}
Registered Company Public
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Registration Date
{% endcolumn %}

{% column %}
19<sup>th</sup> May 2014
{% endcolumn %}
{% endcolumns %}

***

## Platform Details

{% columns %}
{% column width="25%" %}
Platform Name
{% endcolumn %}

{% column %}
Verify by Tiller
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Description
{% endcolumn %}

{% column %}
Verify by Tiller is a secure digital platform designed to streamline Know Your Customer (KYC) and Anti-Money Laundering (AML) processes for regulated and supervised businesses globally. It offers a convenient and efficient way for individuals to prove their identity to businesses through a user-friendly mobile app. The platform collects data to support identity verification and performs background checks to satisfy risk management and regulatory obligations. The digital process replaces traditional, often paper-based, and time-consuming manual verification methods. The platform also provides client definable forms and document upload features to support Know Your Customer (KYC) requirements and your business operational needs.

The platform is built to meet stringent regulatory standards, leveraging cutting-edge technology and high-quality data sources to ensure robust and compliant customer identification. Verify by Tiller provides a solution for real-time remote identity verification, address checks, and bank account verification, enabling businesses to onboard clients securely from anywhere in the globe. It also automatically performs ongoing monitoring for PEP (Politically Exposed Person) & Sanctions screening and adverse media, helping businesses manage risks and maintain compliance throughout the customer lifecycle.
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Product Website
{% endcolumn %}

{% column %}
<https://www.tiller-verify.com/>
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Launch Date
{% endcolumn %}

{% column %}
January 2023
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="25%" %}
Host Data Centres
{% endcolumn %}

{% column %}

* [Azure Dublin, Ireland](https://www.datacenters.com/microsoft-azure-north-europe-ireland)
* [Azure Amsterdam, Netherlands](https://www.datacenters.com/microsoft-azure-west-europe-netherlands)
  {% endcolumn %}
  {% endcolumns %}

***

<div align="left"><figure><img src="/files/mj05adM7FJmf54rTdNmb" alt="Due Diligence Questionnaire"><figcaption></figcaption></figure></div>

To simplify your due diligence process we have prepared and made available to you an already completed due diligence questionnaire on Tiller and the Verify by Tiller platform. The questionnaire answers the typical questions ask and should satisfy most due diligence exercises.

To obtain the completed due diligence questionnaire simply complete the form below and a link to download the document will be sent to you.

### Completed Due Diligence Questionnaire Request Form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=due+diligence+questionnaire&resourcepath=support.tiller-verify.com/hubfs/Trust+Centre+-+Due+Diligence+Documents/Tiller+Technologies+Due+Diligence+Questionnaire.xlsx>" %}


# How we instil trust

Tiller Technologies has implemented the widely accepted Information Security Management System (ISMS), making it compliant with the internationally recognized ISO/IEC 27001:2022 standard. This framework is foundational to Tiller's operations, providing clear guidelines for the systematic management of information security, data governance and business compliance.

The ISMS framework helps Tiller ensure it can manage the confidentiality, integrity, and availability of all its information assets, including it SaaS[^1] platforms, networks, applications, and services. ISMS serves as a dynamic and systematic approach to identify and manage information security risks, fostering continuous improvement of Tiller's security controls to protect against evolving threats and uphold the trust placed in its operations.

<figure><img src="/files/43ZCz7TgCmM7vtNLOw07" alt="Information Security Management System Framework"><figcaption></figcaption></figure>

See below for detailed Information on our commitment to information **security, data protection, reliability, and compliance.**&#x20;

{% content-ref url="/pages/HGHvjApMbjKnKdm739gZ" %}
[Information Security](/trust-centre/trust-components/information-security)
{% endcontent-ref %}

{% content-ref url="/pages/4lYVm0HpwA9NhCaAdf9U" %}
[Data Protection](/trust-centre/trust-components/data-protection)
{% endcontent-ref %}

{% content-ref url="/pages/MoNZKrO1p4bxMeKb3KLu" %}
[Cloud & Reliability](/trust-centre/trust-components/cloud-and-reliability)
{% endcontent-ref %}

{% content-ref url="/pages/Vdm9XbV7xPsctb491A1y" %}
[Risk & Compliance](/trust-centre/trust-components/risk-and-compliance)
{% endcontent-ref %}

[^1]: Software as a Service


# Information Security

We understand that the security of your data is paramount. As a leading SaaS provider, we are committed to upholding the highest standards of information security, ensuring the confidentiality, integrity, and protection of you and client's valuable data within our platform.

This section of our Trust Centre provides an overview of our security posture, outlining the technical, administrative, and physical safeguards we have implemented.

<details>

<summary>What are Tiller's Technical &#x26; Organizational Measures (TOMs)?</summary>

Tiller Technologies implements robust Technical and Organizational Measures (TOMs) to ensure the secure operation of its systems and uphold data integrity. As a company utilizing managed cloud services for its IT infrastructure, our security posture is divided into the following four categories (*Physical, Logical, Network, Personnel/Organisational*):

**Physical Security:** Since Tiller utilizes managed cloud services (Microsoft Azure) for hosting its IT infrastructure, systems, and data, physical security is primarily maintained by our cloud provider. This ensures our infrastructure benefits from world-class data centre protections, though Tiller maintains oversight through its provider selection and management processes.

**Logical Security:** We employ a comprehensive set of technical safeguards to protect data and systems at the application and data layer:

* **Encryption**: Data is encrypted at rest using Blob Storage Account Encryption and SQL Database Transparent Data Encryption.
* **Access Control**: Access is meticulously managed through strict user identification and authentication. We enforce Role-Based Access Control (RBAC) for all Production systems.
* **Authentication**: We maintain stringent password policies—including requirements for length and character sets—for both user and non-user service accounts. Multi-Factor Authentication (MFA) is enforced on all user accounts.
* **Endpoint Protection**: Malware protection is enforced across all servers, desktops, and laptops, utilizing anti-virus, anti-malware, and ransomware screening at all levels.

**Network Security:** Our network security is layered and designed to protect data in transit and detect anomalies:

* **Encryption in Transit**: All data transmission is secured using SSL/TLS protocols and VPNs.
* **Monitoring**: We utilize Azure’s comprehensive suite of security tools to perform continuous threat detection and network monitoring.

**Personnel & Organizational Measures:** In parallel with technical controls, we maintain strong organizational measures to ensure our staff and processes support our security goals:

* **Training**: All staff undergo Cyber Security and Data Protection Awareness training upon hire, with mandatory refresher training performed every 6 months.
* **Risk & Incident Management**: We maintain a risk management policy for identifying and treating risks. This is supported by a structured incident management process with defined procedures for the detection, escalation, and resolution of security incidents (including specific workflows for data breaches, denial of service, and ransomware).
* **Change Management**: All modifications to systems, whether internal or third-party, undergo security risk assessments, formal testing, and approval.
* **Validation**: We engage independent external security specialists to perform specific penetration security testing to validate our defences.

</details>

<details>

<summary>How is access control managed?</summary>

Tiller Technologies prioritizes robust Access Control as a fundamental element of its defence-in-depth information security strategy, ensuring the confidentiality, integrity, and availability of classified data. This policy applies to all systems, people, and processes within Tiller's information systems. Tiller implements industry-standard best practices, including the principle of "Least Privilege," meaning that the default approach is to assume no access is granted unless explicitly justified by business needs and authorised. This is complemented by the "Need to Know" principle, where access is granted only when necessary to perform a role. This applies to both users and system components. User access management procedures are formally documented and cover the entire lifecycle, from initial registration to final de-registration, with regular reviews of user access rights to ensure their continued appropriateness.

* **Least Privilege**: the default approach taken must be to assume that access is not  \
  required, rather than to assume that it is
* **Need to Know**: access is only granted to the information required to perform a role or task,  \
  and no more
* **Need to Use**: users or systems will only be able to access physical and logical facilities required  \
  for their role

Tiller employs Role-Based Access Control (RBAC) to provision user access rights and permissions to computer systems and data, ensuring they are commensurate with the tasks users are expected to perform. Each user account is unique and associated with a specific individual, prohibiting generic or shared accounts. Privileged access rights, such as administrator-level accounts, are tightly controlled. Multi-factor authentication is also enforced on all access authentications. Furthermore, Tiller enforces a strong password policy. Regular access reviews are conducted by asset and system owners (at least annually) and by the Information Security Manager for privileged access accounts (quarterly), to identify and rectify any non-compliance with the access control policy.

<figure><img src="/files/PMtpt8xFXrz5Piv1JcT0" alt="Role Based Access Control"><figcaption></figcaption></figure>

</details>

<details>

<summary>How are session timeouts managed to prevent unauthorized access?</summary>

To minimize risk from unattended screens, the Verify platform operations portal enforces an automatic session timeout after a defined period of inactivity. Users must re-authenticate to regain access, ensuring that open sessions do not become a vulnerability.

</details>

<details>

<summary>Is sensitive data encrypted and what forms data encryption are used?</summary>

Tiller prioritizes the security of all client data and information assets through the rigorous application of data encryption. All customer data is encrypted while at rest using Transparent Data Encryption (TDE), ensuring that sensitive information is protected even when stored. Our commitment to data protection extends to backups, which are encrypted using [AES 256](#user-content-fn-1)[^1]. For data in transit, Tiller utilizes industry-standard protocols, encrypting all data exchanged using Transport Layer Security (TLS) v1.2 or v1.3, both externally and internally.

Our cryptographic policy, guided by ISO/IEC 27001:2022 standards, dictates our approach to the use and ongoing management of encryption techniques. Our encryption framework employs robust key management, where cryptographic keys are protected throughout their entire lifecycle—from generation, secure storage and use. Regular testing, including penetration tests, is conducted to identify any weaknesses and continuously enhance the security of our encryption measures

</details>

<details>

<summary>Is independent penetration testing performed on your platform and who by?</summary>

We maintain a proactive and robust security posture through regular and comprehensive penetration testing of our platforms. These security assessments are a critical component of our commitment to safeguarding information assets and ensuring the resilience of our systems. Our platforms undergo at a minimum annual penetration testing by an external security specialist organization ([Pentest People](https://www.pentestpeople.com/)). This ensures an independent and thorough evaluation of our defences against potential cyber threats.

Pentest People is a highly accredited firm, holding distinguished credentials:

* CREST[^2] Cyber Security Incident Response (CSIR)
* CREST OWASP Verification Standard (OVS) (Level 1 and Level 2)
* NCSC CHECK (National Cyber Security Centre) authorization to conduct IT Health Checks (ITHCs) for the government
* Approved HM Government G-Cloud Supplier
* ISO 27001:2022
* ISO 9001:2015
* Cyber Essentials Plus

The expertise of their team is further underscored by individual certifications:

* CISSP (Certified Information Systems Security Professional)
* CEH (Certified Ethical Hacker)
* CPSA (CREST Practitioner Security Analyst)
* CRT (CREST Registered Penetration Tester)
* OSCP (Offensive Security Certified Professional)

The findings from these penetration tests are formally reviewed, and lessons learned are applied to enhance our security measures, ensuring continuous improvement of our defensive capabilities

</details>

<details>

<summary>How does Tiller secure its <a data-footnote-ref href="#user-content-fn-3">API</a>s?</summary>

Tiller employs strict API security measures, including OAuth 2.0 for authentication and rate limiting to prevent abuse. All API traffic is encrypted via TLS 1.3, and we perform regular automated security scanning of our API endpoints to detect and remediate vulnerabilities such as injection attacks or broken object level authorization.

</details>

<details>

<summary>How are vulnerabilities managed?</summary>

Tiller Technologies maintains a comprehensive Technical Vulnerability Management Policy designed to identify, assess, and remediate technical vulnerabilities across all information systems, including network devices, servers, workstations, mobile devices, operating systems, databases, and applications. This proactive approach ensures the timely and effective mitigation of potential weaknesses that could be exploited by threats. Vulnerabilities are identified through a variety of sources, including regular internal and external vulnerability assessment scans and reports, vendor security advisories, security forums, and incident management processes.

Each identified vulnerability undergoes a thorough assessment to determine its risk level, considering the likelihood of exploitation and potential impact on Tiller’s operations and data. Once assessed, vulnerabilities are prioritized, and appropriate treatment options are applied, which include patching, reconfiguring systems, or hardening configurations by disabling unnecessary services to reduce the attack surface.

<figure><img src="/files/gERlZD1vGp1eyuPzlL7N" alt="Vulnerability Management Lifecycle"><figcaption><p>Vulnerability Management Lifecycle</p></figcaption></figure>

Identified issues that require corrective action are managed through a formal nonconformity process. Tiller also conducts continuous monitoring, measurement, analysis, and evaluation of security events and system logs to detect unusual activity that could indicate vulnerabilities or attacks. Furthermore, security awareness training is conducted for all employees every 6 months to enhance their ability to recognize and avoid vulnerabilities.

</details>

<details>

<summary>How are Incidents managed?</summary>

We maintain a robust Incident Management framework to effectively detect, respond to, and recover from information security events and incidents, ensuring the protection of information assets and service continuity. Tiller has established a clear Information Security Event Assessment Procedure to distinguish between routine events and those that require escalation to incidents based on criteria such as evidence of malicious intent, high classification level of involved information, or a clear breach of policy. Once an incident is identified, the Information Security Incident Response Procedure is activated, guiding a structured response through stages of detection, detailed analysis, containment to prevent further damage, eradication of the root cause, and recovery to restore normal operations. All actions and decisions are logged throughout this process.

<figure><img src="/files/xS1BlUnGJ20rMochJUlj" alt="Incident Response Process"><figcaption></figcaption></figure>

Furthermore, Tiller has developed specialized incident response plans tailored to specific threats, including dedicated procedures for Ransomware, Denial of Service (DoS) attacks, and broader Data Breaches. In the event of a personal data breach, a specific notification procedure is followed to ensure timely communication with relevant supervisory authorities and affected data subjects, in compliance with regulatory requirements such as GDPR[^4]. Following the resolution of any incident, a formal post-incident review is conducted to identify lessons learned, implement corrective actions, and continuously enhance Tiller's security controls and incident response capabilities, thereby strengthening our resilience against future threats.

</details>

<details>

<summary>How do you ensure staff are aware of security policies and threats?</summary>

Tiller takes staff training on security matters extremely seriously. Our staff are an important part of the company's overall 'security in depth' approach to cyber threats.

All new staff as part of their induction and on a 6 monthly basis, thereafter, are required to complete full Cyber Security and Data Protection training. In conjunction with the training, staff are also tested on their understanding and ability to detect cyber threats and how to mitigate them.

Staff completion of the training and the results of the tests are tracked and monitored to ensure all staff are full up to date with their training and can apply it effectively.

</details>

<details>

<summary>How is security integrated into your software development lifecycle (<a data-footnote-ref href="#user-content-fn-5">SDLC</a>)?</summary>

Security is not an afterthought at Tiller; it is embedded into every stage of our development process, often referred to as "SecDevOps." Our secure development lifecycle ensures that security best practices are applied from the initial design phase through to deployment.

* **Design**: We conduct security architecture reviews and threat modelling during the design phase to identify potential risks before a single line of code is written.
* **Development**: Our engineers follow secure coding standards (based on OWASP[^6] guidelines) to prevent common vulnerabilities. We perform security reviews at each stage of the development lifecycle.
* **Testing**: Before any update is released, it undergoes rigorous peer review and dynamic analysis. We also perform regular vulnerability scanning and dependency checks to ensure code is secure.
* **Deployment**: We use automated deployment pipelines that enforce security gates, ensuring that code cannot be pushed to production if it fails checks.

This proactive approach ensures that the Verify by Tiller platform remains resilient against evolving threats by building security into the DNA of our application.

</details>

<details>

<summary>How does Tiller protect against malware and malicious code across its environments?</summary>

Tiller configures environments with security software to monitor, detect, and prevent malicious code. This includes ensuring all computers have up-to-date anti-virus/malware/ransomware software that updates definitions hourly, scans usage continually and performs scheduled daily. Staff are also trained to be diligent in detecting unusual events and to report them immediately.

Furthermore, Tiller employs a "defence in depth" approach, recognizing that no single control is sufficient, and includes Intrusion Detection/Prevention Systems (IDS/IPS) deployed on platform environments to monitor for malicious activity or policy violations, with alerts reported to administrators.

</details>

<details>

<summary>Does Tiller use AI in its security stack?</summary>

Yes, we leverage the advanced AI and Machine Learning capabilities within Microsoft Azure’s security suite to detect anomalous behaviour and potential zero-day threats in real-time, allowing for a proactive response to security incidents before they impact our platform.

</details>

<details>

<summary>How does Tiller secure its mobile application against tampering or reverse engineering?</summary>

The Verify by Tiller mobile app is built with hardened security measures, including code obfuscation and runtime application self-protection (RASP[^7]) mechanisms. These detect if the app is running on a jailbroken or rooted device and prevent it from launching to ensure the integrity of the data capture process.

</details>

<details>

<summary>How does Tiller ensure physical security measures are in place for third-party managed data centre?</summary>

Tiller's Logical & Physical Access Control policy outlines that suitable security controls are required to prevent unauthorized access to information assets, including physical access controls. For those reasons, Tiller's IT infrastructure is hosted at Microsoft Azure Data Centres in Dublin and Amsterdam. Microsoft Azure data centres implement a comprehensive security framework that includes both logical and physical access controls.

Logical controls involve Role-Based Access Control (RBAC), Azure Active Directory (now Microsoft Entra ID) for identity management, multi-factor authentication (MFA), and a just-in-time (JIT) access model that provides temporary, audited access to customer data on a need-to-know basis.

Physical security includes multi-layered defences like biometric scanners, video surveillance, and highly trained security personnel to protect the facilities. Access to the physical data centre is strictly restricted and audited, with all visitors and personnel undergoing rigorous checks. These controls are independently audited to meet numerous global, regional, and industry-specific compliance standards, including ISO/IEC 27001:2022, SOC 1, 2, and 3 reports, and industry-specific standards like PCI DSS for payment card data and FedRAMP for U.S. government services.

</details>

<details>

<summary>How do you manage third-party vendor risk?</summary>

We do not view our vendors in isolation. Tiller conducts rigorous due diligence before onboarding any third-party supplier, assessing their security posture, GDPR compliance, and financial stability. Critical vendors are reviewed annually to ensure they continue to meet our security standards (ISO 27001:2022 alignment) and service level agreements.

</details>

***

### Available Supporting Security Documents

The following security related supporting documentation is available via the request form below

* TTL - ISMS-DOC-05-4 Information Security Policy
* TTL - ISMS-DOC-08-1 Supplier Information Security Evaluation Process
* TTL - ISMS-DOC-A07-1 Employee Screening Procedure
* TTL - ISMS-DOC-A09-1 Access Control Policy
* TTL - ISMS-DOC-A09-2 User Access Management Process
* TTL - ISMS-DOC-A10-1 Cryptographic Policy
* TTL - ISMS-DOC-A12-4 Anti-Malware Policy
* TTL - ISMS-DOC-A12-8 Technical Vulnerability Management Policy
* TTL - ISMS-DOC-A12-9 Technical Vulnerability Assessment Procedure
* TTL - ISMS-DOC-A13-1 Network Security Policy
* TTL - ISMS-DOC-A13-5 Electronic Messaging Policy
* TTL - ISMS-DOC-A16-1 Information Security Event Assessment Procedure
* TTL - ISMS-DOC-A16-2 Information Security Incident Response Procedure
* TTL - ISMS-DOC-A16-4 Incident Response Plan Ransomware

***

### Security Documentation Request Form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=security+documentation&resourcepath=support.tiller-verify.com/hubfs/Trust+Centre+-+Due+Diligence+Documents/Tiller+Technologies+-+Security.zip>" %}

[^1]: A strong symmetric encryption algorithm utilizes a 256-bit key

[^2]: Council of Registered Ethical Security Testers

[^3]: Application Programming Interface

[^4]: General Data Protection Regulation

[^5]: Software Development LifeCycle

[^6]: Open Worldwide Application Security Project

[^7]: Runtime Application Self-Protection


# Data Protection

At Tiller Technologies, we are deeply committed to protecting the privacy of your clients Personal Identifiable Information (PII) as they use our Verify platform. We understand the sensitive nature of the data entrusted to us, and our data privacy practices are built on principles of transparency, accountability, and user control, aligning with stringent global regulations such as the UK General Data Protection Regulation (UK GDPR), UK Data Protection Act 2018 and Jersey's Data Protection Law 2018.&#x20;

This section of our Trust Portal details how we collect, use, store, and safeguard all data including PII data.

<details>

<summary>What is Tiller's approach to Data Privacy?</summary>

Tiller Technologies is deeply committed to safeguarding user privacy and personal data, a commitment detailed in our Privacy Policy, available at '[Tiller Technologies Privacy Policy](https://www.tiller-verify.com/privacy-policy)'. This policy transparently outlines how Tiller collects, uses, shares, retains, and secures personal data across various interactions, whether users are browsing marketing websites, engaging directly, or utilizing the 'Verify by Tiller' service. Data collection in relation to our website is limited to basic usage information (via IP addresses analysis and cookies) Within our Verify by Tiller platform more extensive information may be captured including, identity verification details, such as full names, addresses, identity documents, facial images, and financial information, but only collected after explicit user consent is obtained. This data is primarily utilized for identity verification, fraud prevention, and financial crime prevention as part of our clients onboarding regulatory obligations.

Tiller makes a clear distinction between its roles as a data processor (for data collected via 'Verify by Tiller' service, where the requesting organization is the controller) and as data controller (for employees of clients, website visitors, and direct contacts). Personal data is shared only with selected, trusted third parties necessary for service delivery, such as identity processing service providers and sanction screening agencies, and may be shared with government bodies or law enforcement when legally required. The company enforces robust security controls and policies, requiring appropriate measures from all third-party contractors. Data is only retained for the legitimate or lawful needs of its own operation and that of its clients. Tiller upholds all user rights under GDPR, including the rights to access, rectification, erasure, restriction of processing, data portability, and objection to processing, ensuring individuals maintain control over their personal information.

</details>

<details>

<summary>Is Tiller GDPR Compliant?</summary>

Tiller Technologies is committed to data privacy and protection, adhering to a robust framework of global and regional regulations. Our data protection obligations are governed primarily by the Data Protection (Jersey) Law 2018 (DPJL), which underpins our Data Processor Agreement, and, in respect of our UK-related processing, by UK GDPR and the Data Protection Act 2018 (DPA 2018) as amended by the Data (Use and Access) Act 2025 (DUAA). These frameworks are built on the same core data protection principles set out in our Privacy and Personal Data Protection Policy. Where Tiller processes personal data of individuals in the EU/EEA, the EU General Data Protection Regulation (EU) 2016/679 also applies under its extraterritorial scope (Article 3(2)). These legal frameworks guide every aspect of our data handling, from collection and processing to storage and disclosure, ensuring the highest standards of data integrity and confidentiality.

<figure><img src="/files/InzAwh9zkDysuyaSAA92" alt="GDPR 7 Principles"><figcaption><p>GDPR 7 Principles</p></figcaption></figure>

<figure><img src="/files/SJz72xlIVe45f9rNUt0X" alt="GDPR 8 Data Subject Rights"><figcaption><p>GDPR 8 Data Subject Rights</p></figcaption></figure>

Beyond these foundational regulations, Tiller Technologies continuously monitors and integrates other relevant regional or industry-specific privacy laws and best practices, such as those recommended by ISO/IEC 27018 for personally identifiable information (PII) in cloud environments. Tiller Technologies Privacy Policy '[Tiller Technologies Privacy Policy](https://www.tiller-verify.com/privacy-policy)' further details how we manage personal data, uphold individual rights (including access, rectification, and erasure), and employ stringent security measures to protect your information. Through this multi-layered compliance strategy, Tiller Technologies actively builds and maintains trust, ensuring that our data processing activities not only meet but often exceed regulatory requirements, providing our clients and their customers with confidence in our secure and privacy-conscious operations.

</details>

<details>

<summary>How does Verify by Tiller ensure compliance with data minimisation principles under GDPR</summary>

Tiller’s Privacy and Personal Data Protection Policy explicitly states its adherence to GDPR principles, including "data minimisation," which emphasizes the need to collect only the minimum data required for a stated purpose.

Tiller ensures that personal data processed is **adequate, relevant, and limited to what is necessary for that purpose.** Tiller's Data Processor Agreement also confirms that Tiller only performs processing activities that are necessary and relevant to provide its services.

As for additional information captured via Verify by Tillers custom forms, the client themselves as Data Controllers must ensure they too are only requesting data which is **adequate, relevant, and limited to what is necessary for their purpose.**

</details>

<details>

<summary>How does Tiller ensure data is processed in accordance with expectations?</summary>

Tiller Technologies formalizes its commitment to data protection through a comprehensive Data Processor Agreement (DPA) that governs the processing of personal data on behalf of its clients. This DPA is included in all contracts with Tiller and in summary sets out the following. As the designated "Processor," Tiller adheres strictly to applicable data protection and privacy legislation, notably the Data Protection (Jersey) Law 2018, ensuring that all processing activities are conducted lawfully and responsibly. The primary purpose of this processing is to deliver Tiller Technologies' services, encompassing various categories of personal data as defined by the DPA, to facilitate the functionality and security of its platform. This agreement meticulously outlines Tiller's obligations, reinforcing that all personal data is handled under the strict written instructions of the client, who acts as the "Controller". Finally, Tiller also includes GDPR Standard Contractual Clauses (SCC) in its applicable contracts.

The DPA also establishes clear protocols for managing data subject rights and breach notifications. Tiller is mandated to promptly notify its clients (Controllers) of any complaints, notices, or communications related to data processing, as well as any requests received from data subjects regarding their personal data or other rights. Furthermore, Tiller provides full cooperation and assistance to clients in responding to such inquiries.&#x20;

To support its service delivery, Tiller utilizes a limited number of approved sub-processors all operating under the stringent terms set forth in the DPA to maintain the highest standards of data security and privacy:

**Cloud Hosting**

* Microsoft Ireland Operations Limited
* Microsoft Datacenter Netherlands B.V.

**Digital Identity Orchestration**

* GB Group plc

**KYC/KYB/AML Due Diligence Intelligence**

* Experian Limited
* LexisNexis® Risk Solutions
* IDMerit LLC
* Datanamix (Pty) Ltd

</details>

<details>

<summary>Who acts as the Data Controller, Data Processor, and Data Owner when using Verify by Tiller?</summary>

Understanding the specific roles in our data relationship is vital for compliance. In the context of the Verify by Tiller service, the roles are defined as follows:

* **The Data Owner (Data Subject)**: This is the individual (your customer) whose identity is being verified. They own their personal data and rights.
* **The Data Controller**: This is You (our Client). You determine the "purpose and means" of the processing. You decide to request a verification check to satisfy your own regulatory or business requirements, and you control how long that data is retained. The Data Controller is sometimes referred to as the "**Organisation**" in data privacy regulations such as [**PIPA**](#user-content-fn-1)[^1].
* **The Data Processor**: This is Tiller Technologies. We process the data solely on your behalf and in accordance with your written instructions (as defined in our Data Processing Agreement) to deliver the verification service.

</details>

<details>

<summary>What classifications of personal data does Tiller and its sub-processors process?</summary>

Under General Data Protections Regulations there are 3 classifications of personal data.

**General Personal Data**

Any information relating to an identified or identifiable natural person (data subject) such as full legal name, residential address, date of birth, place of birth, nationality, Passport number, National Identity Card number, Social Security number, Tax Identification Number, IP Address, bank account numbers and source of funds information etc. which do not fall into the other two categories.

**Special Category Data:**

Any data that is deemed inherently sensitive and poses a higher risk to the data subject's fundamental rights and freedoms. The only Special Category Data which Tiller or its sub-processors may process are the selfie image (Biometric data) used as part of the ID Verification process and some information revealed during PEP screening. For example, a data subjects active membership in a political party or senior role in a government.

**Criminal Conviction and Offence Data:**

Any data relating to criminal convictions, offences, or related security measures regarding the data subject. Such data may be processed when retrieved as part of Adverse Media and Enforcement Screening and Sanctions Screening. For example, a news article reporting that the data subject has been arrested or charged with fraud.

</details>

<details>

<summary>How is biometric data (e.g., facial scans) handled and stored?</summary>

Biometric data is treated as Special Category Data under GDPR. It is encrypted at rest and in transit and is strictly used only for the purpose of identity verification (comparing the selfie to the ID document). We do not build persistent biometric databases of your clients for other purposes, and this data is deleted in accordance with our retention policies.

</details>

<details>

<summary>Is your digital verification process certified against UK Government’s Digital Identity and Attributes Trust Framework (DIATF)</summary>

Yes, as a platform built on uncompromising security and regulatory adherence, we utilize identity verification tools that are fully certified against the UK Government’s Digital Identity and Attributes Trust Framework (DIATF). This certification guarantees that our digital verification processes meet the highest national standards for accuracy, data privacy, and fraud prevention. By leveraging DIATF-certified providers, we ensure your KYC and AML workflows remain highly resilient and seamlessly compliant with both UK and broader offshore regulatory demands.

</details>

<details>

<summary>Is data transferred cross borders and is that transfer compliant with regulations?</summary>

Verify by Tiller processing and hosting is performed from a Dublin, Ireland based data centre with georedundant DR hosting from a centre in Amsterdam, Netherlands and therefore falls under EU commission regulations. Some aspects of our operations do require some limited PII data related to the individuals to be transferred to that person’s country of residency for the purposes of residential address verification. In all instances Transfer Impact Assessments (TIA) have been performed to assess any risk and ensure all parties meet EU GDPR standards and enforced by its Standard Contractual Clauses (SCC).

Some industries and jurisdictions may enforce additional restrictions such as those required by the Commission de Surveillance du Secteur Financier (CSSF), Luxembourg’s financial regulator requiring Binding Corporate Rules (BCRs) be pre-approved by the CSSF. In those situations, the client will need to determine if their operation and the services they are taking from Tiller meet the regulations they operate under. However, Tiller will always collaborate with its clients to help them meet and evidence their compliance wherever possible.

</details>

<details>

<summary>What measures are in place to ensure the integrity and confidentiality of personal data processed by Tiller?</summary>

Tiller's Privacy and Personal Data Protection Policy ensures processing is conducted in a manner that guarantees appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

We ensure all sensitive or confidential data at rest (files, databases, backups) are encrypted, regardless of the environment. Encryption keys are stored securely within key vaults with restricted access. In addition, transactions between individuals and our Verify by Tiller platform and within the platform itself are encrypted using TLS[^2], and customer data is encrypted at rest using keys managed by Tiller.

</details>

<details>

<summary>How does Tiller handle data subject access requests (DSARs) and ensure individuals can exercise their rights under data protection laws?</summary>

Tiller's Privacy and Personal Data Protection Policy acknowledges the **rights of data subjects under GDPR** (e.g., right to be informed, access, rectification, erasure, restriction of processing, data portability, objection, rights related to automated decision-making and profiling).&#x20;

In matters related to data held within the Verify by Tiller platform, If Tiller, as **Data Processor**, receives a request from a data subject (**Data Owner**) regarding their data, Tiller will immediately forward the request to the client company (**Data Controller**) who instructed us to capture and process their data and refrain from responding directly ourselves. Tiller will also assist the Data Controller by providing the necessary information and documentation for data subject requests upon the Data Controller's written request and consent.

Ultimately Tiller will do everything it can to respect the rights of the individual while ensuring our clients retail full control of the request.

</details>

<details>

<summary>Is production data ever used in development or testing environments?</summary>

No. Tiller strictly enforces environment segregation. Development and Testing environments utilize synthetic or anonymized dummy data. Live client PII which has not been fully anonymized is never copied into lower environments, eliminating the risk of accidental exposure during development cycles.

</details>

<details>

<summary>Can I customize how long my client data is retained?</summary>

Yes, you have full control over data retention. As the Data Controller, you can configure the Verify platform settings to match your specific compliance needs.

Our system operates on the following principles:

* Custom Configuration: You can set retention limits that align with your local laws and internal policies.
* Default Policy: In the absence of a custom setting, data is automatically deleted after 90 days or sooner if the record is flagged for deletion by you.
* Ongoing Monitoring: If you have enabled continuous monitoring (e.g., for AML purposes), data is retained for as long as that service is active.

</details>

<details>

<summary>What happens to user data if a verification check is abandoned mid-process?</summary>

Data captured during an incomplete or abandoned session is held temporarily to allow the user to resume. Once the client completes the capture journey or if the verification request is cancelled by the client, then the data is processed and deleted in accordance with our standard retention policies.

</details>

<details>

<summary>How does Tiller handle data breaches if one occurs?</summary>

We follow a strict 72-hour notification window. In the unlikely event of a personal data breach, Tiller will notify the Data Controller without undue delay after becoming aware of the breach. We provide a detailed report including the nature of the breach, the data categories involved, and the remedial actions taken, assisting you in your obligation to report to supervisory authorities.

</details>

<details>

<summary>Does Tiller apply "Privacy by Design" principles to its Verify by Tiller?</summary>

Tiller adopted and applied the principles of "Privacy by Design" from the very inception of Verify by Tiller. This means that the definition and planning of all features in the platform and any new or changed features, only collect or process personal data after taking into due consideration of privacy rights if the individual. We have completed privacy impact assessments (PIAs) for the platform and are committed to respecting individuals GDPR rights and privacy in everything we do.

</details>

***

### Tiller Technologies use of 3rd Party Sub-Processors

At Tiller, we engage a select ecosystem of industry-leading sub-processors—including Microsoft Azure for secure hosting, GB Group for identity verification, and partners like LexisNexis Risk Solutions, Experian and more for global screening. We manage these critical partnerships through a rigorous vendor risk management framework that mandates comprehensive initial due diligence and ongoing security reviews to ensure every partner maintains enterprise-grade standards.

All data sharing is strictly governed by robust Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs), ensuring that personal information is encrypted in transit and at rest, minimized to only what is strictly necessary for the specific verification function, and processed solely in accordance with our documented instructions to maintain the complete integrity and confidentiality of your client data.

#### 3rd Pary Sub-Processors

<details>

<summary>GB Group plc</summary>

GB Group plc is a UK-based global specialist in digital identity and location intelligence. Tiller has partnered with GBG for their assistance in image and identity processing services that power parts of Tiller’s client onboarding and verification solutions.

#### **Data Shared (ID Verification)**

**Special Category Data Shared**

* ID Document Image *(which will include an image of the individual)*
* Selfie Image *(taken as part of the liveliness test)*

**General Category Data Shared&#x20;*****(***[***OCR***](#user-content-fn-3)[^3]***'ed or extracted from the*** [***RFID***](#user-content-fn-4)[^4] ***chip)***

* Full Name
* Date of Birth
* Place of Birth
* Nationality
* Residential Address *(if present on ID Document)*
* Country and Place of Birth
* ID Document number *(Passport number/Driving Licence Number/ID Card Number)*

#### Data Retention Terms with GB Group plc

* **Maximum of 30 days**

</details>

<details>

<summary>LexisNexis Risk Solutions UK Limited</summary>

LexisNexis Risk Solutions is a world leader in data and analytics, providing specialized financial crime compliance tools. Tiller has partnered with LexisNexis Risk Solutions for Politically Exposed Persons (PEP), Sanctions, and Adverse Media screening because they maintain one of the world's most comprehensive risk databases, covering millions of profiles curated from thousands of global government, regulatory, and media sources.

#### **Data Shared (Individual - PEP, Sanction and Adverse Media Screening)**

**General Category Data Shared**

* Full Name
* Title (Mr, Mrs, Miss etc.)
* Current Residential Address
* Date of Birth
* Country and Place of Birth

#### **Data Shared (Corporate - Sanction and Adverse Media Screening)**

**General Category Data Shared**

* Company Name
* Company Type
* Registered Address
* Registration Number

#### Data Retention Terms with LexisNexis Risk Solutions

* **Maximum of 24 hours** (except where ongoing monitoring is in place when it is retained for the duration the individual is monitored)

</details>

<details>

<summary>Experian Limited</summary>

Experian is a global leader in information services, providing robust data quality. Tiller has partnered with Experian to access their comprehensive range of UK and international ePoA[^5] that leverages government, credit bureau and utility company data. We also utilise their UK bank sources for Bank Account verification.

#### **Data Shared (Residential Address Verification)**

**General Category Data Shared**

* Full Name
* Title (Mr, Mrs, Miss etc.)
* Current Residential Address
* Previous Residential Address *(if applicable)*
* Date of Birth
* ID Card Number *(if available)*
* Telephone
* Email

#### **Data Shared (Bank Account Verification)**

**General Category Data Shared**

* Full Name
* Title (Mr, Mrs, Miss etc.)
* Current Residential Address
* Bank Account/IBAN Number *(including Sort Code or SWIFT/BIC code)*

#### Data Retention Terms with Experian Limited

* **Contracted maximum 1 year** (However, only retains personal data for 7 days, the contracted requirement is to allow for the support of a claim)

</details>

<details>

<summary>IDMerit LLC</summary>

IDMERIT is a identity verification specialist that excels in coverage of "hard-to-verify" markets. Tillers long partnership with IDMerit give us access to regulatory quality data sources from a large array of countries providing real-time internation ePoA[^5].

#### **Data Shared (Residential Address Verification)**

**General Category Data Shared**

* Full Name
* Title (Mr, Mrs, Miss etc.)
* Current Residential Address
* Date of Birth
* ID Dard Number *(if available)*
* Telephone
* Email

#### Data Retention Terms with IDMerit LLC

* **Maximum of 72 hours**

</details>

<details>

<summary>Datanamix (Pty) Ltd</summary>

Datanamix is a South African information services leader specializing in data verification and risk management solutions. Our partnership with them gives us comprehensive access to data on South African residence from government and credit agency sources.

#### **Data Shared (Residential Address Verification)**

**General Category Data Shared**

* Full Name
* SA ID Number
* Title (Mr, Mrs, Miss etc.)
* Telephone
* Email

#### **Data Shared (Bank Account Verification)**

**General Category Data Shared**

* Full Name
* Title (Mr, Mrs, Miss etc.)
* SA ID Number
* Bank Account & Branch Code
* Account Type

#### **Data Shared (Company Search)**

**General Category Data Shared**

* Company Name
* Company Type
* Registration Number

#### Data Retention Terms with Datanamix (Pty) Ltd

* **Maximum of 72 hours**

</details>

<details>

<summary>Microsoft Ireland Operations Limited</summary>

Microsoft Ireland Operations Limited is the legal entity responsible for operating Microsoft’s cloud services and data centres within the region, acting as a primary hub for Azure’s European infrastructure. Tiller partners with Microsoft by hosting its entire infrastructure within Azure's "North Europe" region (located in Dublin) and "West Europe" region (located in Amsterdam) data centres. We leverage Azure's enterprise-grade security to ensure that your client data is stored with the highest levels of resilience and compliance available.

No data is shared with Microsoft as all data hosted in their virtualised infrastructure is encrypted both at rest and in transit.

</details>

#### Verify by Tiller Data Flow

<figure><img src="/files/BcXMX5dHoRBjoEjnKJL1" alt=""><figcaption><p>Verify by Tiller Data Flow</p></figcaption></figure>

***

### Available Supporting Data Privacy Documents

The following data privacy related supporting documentation is available via the request form below

* Verify by Tiller - Data Processor Agreement - June 2024 - v1.2
* TTL - ISMS-DOC-A08-2 Information Classification Procedure
* TTL - ISMS-DOC-A08-9 Procedure for the Disposal of Media
* TTL - ISMS-DOC-A16-1 Information Security Event Assessment Procedure
* TTL - ISMS-DOC-A16-2 Information Security Incident Response Procedure
* TTL - ISMS-DOC-A16-6 Incident Response Plan Data Breach
* TTL - ISMS-DOC-A18-5 Privacy and Personal Data Protection Policy

***

### Data Privacy Documentation Request Form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=data+privacy+documentation&resourcepath=support.tiller-verify.com/hubfs/Trust+Centre+-+Due+Diligence+Documents/Tiller+Technologies+-+Data+Privacy.zip>" %}

[^1]: Personal Information Protection Act 2016 (PIPA), Bermuda

[^2]: Transport Layer Security

[^3]: Optical Character Recognition

[^4]: ***Radio Frequency Identification***

[^5]: Electronic Proof of Address


# Cloud & Reliability

The robust and scalable infrastructure underpinning Tiller Technologies SaaS products is hosted entirely within Microsoft Azure, a leading global cloud platform. Our strategic choice allows us to leverage Azure's world-class security capabilities, unparalleled availability, and extensive global network to deliver a highly reliable and scalable service. This section provides information on our infrastructure architecture design and the operational controls implemented to ensure the continuous availability, resilience from data encryption to disaster recovery and monitoring.

<details>

<summary>How does Tiller host its platforms?</summary>

Tiller Technologies leverages the robust, virtualised infrastructure provided by Microsoft Azure data centres strategically located in Dublin, Ireland, and Amsterdam, Netherlands. This choice of infrastructure provides was based on the exceptional quality, security, and resilience provided by Azure, crucial for handling sensitive data and ensuring continuous service availability. Azure's state-of-the-art facilities are designed with multiple layers of physical and digital security, and geo-redundancy for disaster recovery, ensuring that data remains protected and services are resilient against disruptions. Tiller further enhances this by requiring confidential data stored in those data centres to be encrypted both at rest and in transit, and by maintaining comprehensive backup procedures for all cloud-stored data

<figure><img src="/files/O9uhsCFblzyHVsavGJEB" alt=""><figcaption></figcaption></figure>

Tiller Technologies' use of Azure data centres which are certified to the ISO/IEC 27001:2022 international standard for information security, with annual surveillance audits confirming ongoing compliance. Tillers own commitment to data and system integrity is underscored by our own adherence to the rigorous information security standards. We also align with the ISO/IEC 27017 code of practice for information security controls in the cloud and ISO/IEC 27018 for the protection of personally identifiable information (PII) in the cloud. This dedication, combined with our robust availability management policy and incident response plans, ensures that Tiller's infrastructure and services provide a secure, reliable, and highly available environment for our platforms and customer data.

</details>

<details>

<summary>How does Tiller ensure Verify by Tiller can maintain its performance under heavy load?</summary>

The Verify by Tiller platform has been specifically designed and developed to be scalable. All our services are hosted on virtualized infrastructure, a core component that enables rapid and dynamic scaling to meet demand. This virtualized infrastructure and architecture allows us to efficiently scale "up" by adding additional performance resources when needed and to scale "out" by expanding the number of concurrent operations, ensuring consistent high performance even during peak loads.

<figure><img src="/files/DmjEpFGcvFTQRq5I9uA1" alt="Scale Up and Scale Out" width="563"><figcaption></figcaption></figure>

To facilitate seamless and efficient communication across our distributed software services, Tiller Technologies employs an Enterprise Service Bus (ESB) as its middleware communication layer. The ESB is instrumental in enabling data communication in a decoupled, scalable, and reliable manner, preventing single points of failure and allowing individual services to evolve independently without impacting the overall platform.&#x20;

For database scalability, Azure SQL Server Elastic Pools utilising Database Transactional Unit (DTU) based configuration optimising the database storage, compute and IO usage.

</details>

<details>

<summary>What data loss prevention (DLP) strategies do you employ?</summary>

Tiller follows a standard 7 step strategy to appropriately manage the data it holds. This approach to DLP, is designed to prevent sensitive data from leaving our controlled environment without authorization. To do this we have implemented processes that identify, monitor, and protect data at rest, in motion, and in use across our systems.

Our strategy integrates seamlessly with Azure's native security capabilities, leveraging its advanced features to detect anomalous activities, and enforce granular access controls. We continuously refine our DLP measures based on ongoing threat intelligence and regular assessments, ensuring that our defences evolve to counter emerging risks and maintain the confidentiality and integrity of your data.

Our 7-step DLP strategy:

1. **Prioritise data** based on sensitivity, ownership, volatility
2. **Categorise data** based on type, location, storage, retention
3. **Risk classification** based on access, visibility, change control
4. **Review & monitor** based on priority, category & risk, review and ensure the data is under appropriate control and management. Establish a review frequency based on the priority & risk
5. **Effect a reporting structure** for key stakeholders to communicate current status, risk & incidents effectively
6. **Effect training** to both technical and administrative staff on the controls and monitoring procedures and policies
7. **Effect control steps** as part of the change and incident management processes, to ensure any changes or incidents are affected in line with the DLP strategy

</details>

<details>

<summary>How do you ensure compliance with the Data Protection Act in regard to information held on hosting platforms like Azure?</summary>

Tiller as part of its selection process for host provider took the Data Protection Act requirements into careful consideration. Microsoft has been a leader amongst providers, ensuring its Azure services and the contracts that govern them are fully compliant with UK and EU regulations. The Data Protection Act requires companies using cloud services and the cloud providers themselves, to mitigate for the following:

* **Implementing retention effectively in the cloud**. We ensure that PII data held is only retained in the cloud databases, backups etc. for the period required to perform our services and that data is deleted at the end of that period.
* **Cloud provider breach response and notification.** We have confirmed that our agreements with Microsoft Azure ensure their compliance with regulatory obligations for notification and mitigation support in the event of a breach.&#x20;
* **Processing of personal data outside the European Economic Area (EEA)**. Tiller only uses Azure resources and storage hosted and maintained within the EEA. We currently use Azure datacentres in Dublin & Amsterdam.
* **Data portability & data ownership**. Our Azure agreement (Microsoft Online Agreement Addendum Financial Services) explicitly ensures provision for data export and our services include export to machine readable formats. The addendum also ensures our compliance with the FCA's [FG 16/5 guidance](#user-content-fn-1)[^1] for firms outsourcing to the 'cloud' and other third-party IT services.
* **Risk management**. Our cloud provider, Microsoft Azure is subject to our Data Protection Impact Assessment process. Also, our agreement with Microsoft Azure ensures there is a right to access independent audit reports on their service available via their Service Trust Portal: <https://servicetrust.microsoft.com/ViewPage/PrivacyDataProtection>
* **Security of Privacy**. Azure was selected as our cloud provider as they meet all UK and international data protection and security standards, and those standards are regularly assessed and [PEN tested](#user-content-fn-2)[^2]. with the results accessible. <https://servicetrust.microsoft.com/viewpage/PenTest>

</details>

<details>

<summary>Is Tiller Technologies compliant with the EU Digital Operational Resilience Act (DORA)?</summary>

Yes, Tiller Technologies is fully aligned with the requirements of the Digital Operational Resilience Act (DORA). As an ICT Third-Party Service Provider to regulated financial entities, we have implemented the necessary governance, risk management, and operational frameworks to ensure we meet the rigorous standards mandated by the regulation. Although DORA does not currently offer a formal certification for third-party vendors, our platform, *Verify by Tiller*, is architected to ensure the highest levels of resilience, availability, and security, enabling our clients to seamlessly maintain their own compliance while using our services.

To evidence this compliance, we have updated our standard contractual frameworks to incorporate the mandatory provisions of Article 30, including clear commitments on data residency, audit rights, and service level agreements. We maintain robust Business Continuity and Disaster Recovery (BCDR) plans and strict incident management protocols that align with the reporting timelines required by EU regulators. Furthermore, we provide full transparency regarding our sub-outsourcing supply chain, allowing our clients to confidently rely on Tiller for their Critical or Important Functions (CIF).

</details>

<details>

<summary>How is tenant isolation handled in your cloud environment?</summary>

We utilize strict logical isolation to separate client data. While we leverage shared cloud resources for efficiency, every client's data is logically segregated at the database and application level using unique tenant identifiers, ensuring that no client can access another's data.

</details>

<details>

<summary>Describe Tiller's Disaster Recovery (DR) plan and its targeted <a data-footnote-ref href="#user-content-fn-3">RTO</a> and <a data-footnote-ref href="#user-content-fn-4">RPO</a> in case of a primary data centre failure.</summary>

Tiller's BCP (Client Product Services DR Plan) outlines contingency planning for the event of a loss of critical service from its Azure cloud hosting provider. For a standard DR situation involving a full failover of all Verify by Tiller services to its secondary data centre at Azure, which is hosted in a separate georedundant region, the target RTO is 24 hours (within 1 business day), and the target RPO is 4 hours. In all failover DR tests and simulated critical failure modes, Tiller achieved a significantly quicker RTO time.&#x20;

For non-critical issues, not requiring failover to an alternate data centre there would little if any disruption to services.

</details>

<details>

<summary>How often does Tiller test its data restoration capabilities?</summary>

While backups are automated daily, we perform a full Data Restoration Test at least every 6 months. This verifies not only the integrity of the backup files but also validates our Recovery Time Objectives (RTO) in a real-world scenario.

</details>

<details>

<summary>What is your target Service Level Agreement (SLA) for uptime?</summary>

Tiller targets a platform availability of 99.9% availability per month during business hours. We employ redundant systems and failover mechanisms to ensure availability. Real-time service status and historical uptime reports are available to clients upon request or via our status page.

</details>

<details>

<summary>What system capacity and life planning processes do Tiller follow?</summary>

Tiller regularly reviews system capacity and performs life planning to ensure consistent and reliable service availability. This involves active monitoring to manage of our systems performance, employing threshold alerts to identify unplanned spikes in usage of response times, and implement automatic scaling to manage those events.&#x20;

The planning also includes addressing security and maintenance patching, as well as end-of-life dates for operating systems and components that the system relies on. Managing the testing and deployment of the Maintenace patches and for end-of-life events managing the seamless transition over to alternative software or services.

</details>

<details>

<summary>What is the "Exit Plan" if we choose to leave Tiller?</summary>

We prevent vendor lock-in by ensuring you always own your data. Our Master Services Agreement outlines a clear Exit Strategy, including the provision of your data to be extracted in an industry-standard machine-readable format via our APIs. At the end of the "Exit Plan" your tenant and data is securely deleted from our platform.

</details>

<details>

<summary>How does Tiller ensure that its operating procedures and practices are documented, reviewed, and endorsed to maintain operational integrity?</summary>

Tiller has documented procedures and policies which cover all aspects of its operations and systems activity and environments. We have implemented the ISMS framework for operational and data governance, which is a its tailor-made framework for regulated and supervised businesses.

Tiller undertakes procedure for management reviews for all new documentation or where significant changes have been made. We employ a governance structure with clearly defines roles, responsibilities, and authorities for the management and review of changes. The IT and Operations Committee itself reports to and is answerable to our Executive Committee (Exco). The Exco is ultimately responsible for reviewing and approving all key policies and procedures, ensuring that approved changes are consistently reflected across the organisation and in line with company strategy.

All documentation pertaining to operational requirements is reviewed as part of the annual review process. This systematic approach ensures that operational processes are formalized, consistent, and regularly updated to reflect best practices and changes.

</details>

<details>

<summary>How sustainable is the infrastructure used to host Verify by Tiller?</summary>

Tiller Technologies is committed to minimizing its environmental impact by hosting our platform within Microsoft Azure's data centres in Dublin, which are at the forefront of green cloud computing.

Our infrastructure leverages Microsoft's advanced sustainability technologies, including:

* **Energy Efficiency**: The use of state-of-the-art adiabatic and evaporative cooling systems to significantly reduce energy consumption.
* **Renewable Energy**: Operations are supported by renewable energy sourcing through Power Purchase Agreements (PPAs) and innovative pilots like green hydrogen power.
* **Water & Waste Stewardship**: The facilities utilize rainwater harvesting and maintain zero-waste certifications to minimize their physical footprint.

By utilizing this infrastructure, Tiller aligns with Microsoft’s ambitious global goals to be carbon negative, water positive, and zero waste by 2030, ensuring that your use of our services supports a sustainable future.

</details>

***

### Available Supporting Infrastructure Documents

The following infrastructure related supporting documentation is available via the request form below

* TTL - ISMS-DOC-A05-3 Cloud Computing Policy
* TTL - ISMS-DOC-A05-4 Cloud Service Specifications
* TTL - ISMS-DOC-A08-2 Information Classification Procedure
* TTL - ISMS-DOC-A12-2 Change Management Process
* TTL - ISMS-DOC-A12-4 Anti-Malware Policy
* TTL - ISMS-DOC-A12-5 Backup Policy
* TTL - ISMS-DOC-A12-8 Technical Vulnerability Management Policy
* TTL - ISMS-DOC-A12-9 Technical Vulnerability Assessment Procedure
* TTL - ISMS-DOC-A17-2 BCP (Client Product Services DR Plan)
* TTL - ISMS-DOC-A17-6 Availability Management Policy

***

### Infrastructure Documentation Request Form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=infrastructure+documentation&resourcepath=support.tiller-verify.com/hubfs/Trust+Centre+-+Due+Diligence+Documents/Tiller+Technologies+-+Infrastructure.zip>" %}

[^1]: Guidance for firms outsourcing to    \
    the ‘cloud’ and other third-party IT services

[^2]: Penetration test, is a simulated cyberattack

[^3]: Recovery Time Objective

[^4]: Recovery Point Objective


# Risk & Compliance

Our commitment to your trust extends beyond technical security and data privacy to a robust framework of compliance and governance controls. We navigate the complex landscape of global regulations and industry standards to ensure the service offered provide will support your regulated business. This section outlines our adherence to relevant regulatory requirements, internal policies, and audit processes, demonstrating our dedication to transparency and responsible stewardship of your data.

<details>

<summary>How does Tiller maintain effective procedures and controls?</summary>

To ensure the continuous effectiveness of our Information Security Management System (ISMS), Tiller conducts regular internal assessments of our policies and procedures. With input from the information technology and business management teams, reviews are undertaken to ensure information security processes are efficient, economical, and in compliance with the ISO/IEC 27001:2022 standard. These assessments covering all aspects of our management system takes place continuously, allowing for at a minimum all processes being covered within a one-year timeframe. Findings from these assessments, including any nonconformities, are documented and communicated to the management team, with action plans agreed upon for addressing identified issues.

<figure><img src="/files/mHNuYggmVZem70R6rGda" alt=""><figcaption></figcaption></figure>

We distinguish between observations, minor nonconformities (single lapses), and major nonconformities (significant breakdowns of the management system). All nonconformities are recorded in a Nonconformity and Corrective Action Log, where they are evaluated to determine their underlying cause, potential impact, appropriate corrective actions and those actions tracked to completion. This rigorous approach to assessments ensures that our ISMS remains robust, effective, and continuously improved.

</details>

<details>

<summary>How are risks managed?</summary>

At Tiller Technologies, effective risk management is a key part of our Information Security Management System (ISMS) and a core component of our commitment to compliance. Our risk assessment and treatment process align with international standards such as ISO/IEC 27001:2022 and [ISO 31000](#user-content-fn-1)[^1], ensuring a consistent approach to identifying, analysing, and mitigating potential threats. We conduct risk assessments covering all information assets as part of our ISMS implementation and perform regular updates through our management review process, identifying changes to assets, threats, and vulnerabilities. This process is qualitative, classifying risks as high, medium, or low based on a calculated score derived from the likelihood and impact of an event.

<figure><img src="/files/RVmSnAJkn2rSxJDCrfAt" alt="Risk Management Process" width="563"><figcaption></figcaption></figure>

For risks deemed unacceptable, we explore various treatment options, including applying controls to lessen likelihood and/or impact, or avoiding the risk. As a cloud service provider, the continuous assessment of risks and the application of comprehensive controls are vital to maintaining the confidence of our customers and fulfilling our obligations to protect Personally Identifiable Information (PII). This approach ensures that the risks faced in the day-to-day operation of our business are effectively managed and controlled.

</details>

<details>

<summary>Describe Tiller Technologies governance framework</summary>

Robust internal governance is the fundamental to our compliance framework, ensuring that our operations align with the highest standards of information security and data protection. Day-to-day execution of our policies and procedures, including change control, risk and incident management is overseen by our IT and Operations Committee. Our governance structure clearly defines roles, responsibilities, and authorities of this committee and its members as well as the individual employees who execute the procedures. The IT and Operations Committee itself reports to and is answerable to our Executive Committee (Exco). The Exco is responsible for reviewing and approving all key policies and procedures, ensuring that approved changes are consistently reflected across the organisation and in line with company strategy. This includes our Legal, Regulatory, and Contractual Requirements which outlines how we identify, assess, and incorporate legal and regulatory obligations.

Furthermore, we maintain a stringent Risk and Issue Escalation Process to ensure that newly identified risks and unanticipated issues are managed correctly and is necessary escalated to the appropriate management levels, including the Executive Committee, for expedited review and resolution. Through this comprehensive approach to internal governance, we demonstrate our commitment to transparency, accountability, and the continuous improvement of our security posture and compliance adherence

</details>

<details>

<summary>How does Tiller handle any non-compliance or failures to meet required standards?</summary>

If deficiencies are identified as part of normal operations or as a result of a review, We will take appropriate action to remediate that deficiency as soon as practicable by following its procedure for the management of nonconformity. We will also where appropriate escalate the nonconformity to senior management and all relevant stakeholders via our Issue and Escalation Process.

For serious or material regulatory deficiencies, appropriate consideration would be given to notifying the Commission. Tiller's Issue and Escalation Process is designed to ensure unanticipated issues are tracked to resolution, and escalated when a resolution cannot be reached.&#x20;

</details>

<details>

<summary>How do you support a potential client's due diligence review of Tiller Technologies as a critical supplier?</summary>

We aim to streamline your vendor risk assessment process by providing complete transparency through our Trust Centre. Here, you can access detailed specifications regarding our Security, Data Privacy, Infrastructure, Compliance and Governance, along with [downloadable](https://verify-doc.tiller-verify.com/training-hub/trust-centre/compliance-and-governance#compliance-and-governance-documentation-request-form) copies of our core policies and procedures. To further assist, we provide a [Due Diligence Pack](/trust-centre/trust-centre/due-diligence-pack) which includes a pre-completed Due Diligence Questionnaire (DDQ) that addresses the most common regulatory and security enquiries, allowing you to complete your review efficiently.

</details>

<details>

<summary>How does Tiller manage changes to its sub-processors?</summary>

As part of Tiller's commitment to expanding its offering and improving its services, Tiller may occasionally need to add or remove sub-processors.

Tiller will notify clients of any planned changes to its sub-processor list at least 30 days before they take effect. Any new sub-processor will be required to meet or exceed the standards stipulated in Tiller's contractual obligations in its service agreement.

Should such a change in sub-processor cause your regulator to object to the use of the sub-processor as part of any outsourcing notification requirement, we will work with you to resolve the regulator objection and if unsuccessful allow you to terminate the agreement.

</details>

<details>

<summary>How do you track regulatory changes?</summary>

Tiller operates a continuous "Regulatory Horizon Scanning" process. Our team, supported by external legal counsel, monitors changes in global AML/KYC regulations and data privacy laws. This ensures our platform remains compliant not just today, but is future-proofed against upcoming legislative changes.

</details>

<details>

<summary>Is Tiller registered with the Information Commissioner’s Office (ICO) or the Jersey Office of the Information Commissioner (JOIC)?</summary>

Yes, as a controller of our own business data and a processor for your client data, Tiller is registered with both the Jersey Office of the Information Commissioner (JOIC) and UK Information Commissioner’s Office (ICO).

</details>

<details>

<summary>Is Verify by Tiller compliant with the new Cyber Security Law 202- in Jersey</summary>

Yes. Tiller already implements "appropriate and proportionate" security measures across its Verify by Tiller platform. These measures include active threat monitoring and alerting, to reduce incident risks, and ensure the continuity of the Verify platform.

Under Article 31 of the new Law, Operators of Essential Services must notify the JCSC within 24 hours of a significant cyber incident. We have already updated our incident response procedures to ensure the JCSC is looped into our communication flows within this required 24-hour window, keeping both our platform and our clients fully compliant.

</details>

<details>

<summary>How does Verify by Tiller comply with the EU AI Act regarding biometric face matching?</summary>

Under the EU AI Act (Regulation (EU) 2024/1689), AI systems used for remote biometric identification are classified as high-risk under Annex III(1)(a). The Act draws a specific distinction for systems used solely for biometric verification, that is, confirming that a person is who they claim to be, which are excluded from this high-risk category. The facial matching feature within Verify by Tiller performs this narrower, 1:1 verification function, comparing a live selfie to the photograph on a government-issued identity document, rather than identifying an unknown person from a wider population. Irrespective of its formal classification, Tiller applies a comprehensive control framework to this feature, addressing data quality, transparency, and accountability, in line with the high-risk requirements of the Act ahead of the 2 August 2026 application date.

To address data governance and prevent discriminatory bias, the platform's facial matching models are validated using datasets that are statistically representative. Tiller strictly does not use client data or customer biometric profiles to train or fine-tune models. Instead, our partner face matching module relies on fully anonymised, pre-trained models that are monitored to guarantee consistent matching accuracy across variations in age, gender, and ethnicity, minimizing the risk of automated biases in client onboarding.

Traceability and absolute security are maintained through real-time, tamper-resistant event logging embedded within the system architecture. The platform automatically logs system uptime, confidence thresholds, matching operations, and error states. Clear operational instructions are provided to client firms to ensure they fully understand the system's capabilities, parameters, and operational boundaries.

Crucially, Verify by Tiller operates on a strict "Human-in-the-Loop" architecture. The AI functions exclusively to flag anomalies or output confidence scores; it is structurally blocked from making independent, final onboarding rejections; it may only issue referrals. The user interface is built to ensure that any potential mismatch or identity alert must be reviewed, interpreted, and formally actioned by the clients qualified compliance officer.

</details>

<details>

<summary>Does Tiller have a policy on AI Ethics and Algorithmic Bias?</summary>

Yes. We are committed to Fair AI. We review our identity verification vendors and internal logic to ensure that our technology performs accurately across different demographics and ethnicities, minimizing the risk of algorithmic bias in the onboarding process.

</details>

<details>

<summary>Does Tiller have a Corporate Social Responsibility Policy?</summary>

Our comprehensive approach to ethical behaviour is encapsulated in our Corporate Social Responsibility Policy, which aligns with the United Nations Global Compact's 10 principles. This commitment includes upholding human rights, ensuring fair labour practices (such as eliminating forced or child labour and discrimination), and promoting environmental responsibility through initiatives and eco-friendly technologies. We actively invest in research and development and maintain an open stance to new ideas, continuously striving to improve our operational practices as a socially aware and responsible business.

#### Human Rights

* Principle 1: Businesses should support and respect the protection of internationally proclaimed human rights; and
* Principle 2: make sure that they are not complicit in human rights abuses.

#### Labour

* Principle 3: Businesses should uphold the freedom of association and the effective recognition of the right to collective bargaining;
* Principle 4: the elimination of all forms of forced and compulsory labour;
* Principle 5: the effective abolition of child labour; and
* Principle 6: the elimination of discrimination in respect of employment and occupation.

#### Environment

* Principle 7: Businesses should support a precautionary approach to environmental challenges;
* Principle 8: undertake initiatives to promote greater environmental responsibility; and
* Principle 9: encourage the development and diffusion of environmentally friendly technologies.

#### Anti-Corruption

* Principle 10: Businesses should work against corruption in all its forms, including extortion and bribery.

Further reinforcing our ethical framework, we maintain a stringent Anti-Bribery and Anti-Corruption Policy, strictly prohibiting any form of bribery or corrupt practices, and requiring due diligence with all business partners. Our Conflicts of Interest Policy ensures that employees and boards avoid situations where personal interests might conflict with company or client duties, with clear responsibilities assigned for policy implementation and enforcement. Additionally, our Whistleblowing Policy fosters a culture of openness, enabling employees to report suspected wrongdoing—including criminal acts, financial malpractice, or legal non-compliance without fear of retaliation.

Finally, our Privacy and Personal Data Protection Policy, outlines our commitment to safeguarding Personal Identifiable Information (PII), upholding customer data rights, and treating their data with respect. These policies collectively underscore our dedication to operating with the highest ethical standards across all facets of our business.

</details>

<details>

<summary>How does Tiller manage conflicts of interest and maintain its anti-bribery and anti-corruption policy across its business?</summary>

Tiller's Conflicts of Interest Policy mandates that staff act honestly and in good faith, prioritizing client interests, and not misusing their position or information for personal gain. Any conflicts are reported to Exco and recorded.

Controls in place include information barriers, personal account dealing disclosures, a Gifts and Hospitality Policy, client confidentiality restrictions, and restrictions on outside business interests.

Tiller has a strict Anti-Bribery and Anti-Corruption Policy that prohibits bribery and facilitation payments, applies to all employees and extends to business partners like agents, subcontractors, and joint venture partners, requiring due diligence on their integrity records. Tiller conducts regular audits to review corruption vulnerability.

</details>

***

### Available Supporting Compliance & Governance Documents

The following compliance and governance related supporting documentation is available via the request form below

* TTL - ISMS-DOC-05-4B Issue and Escalation Process Summary
* TTL - ISMS-DOC-06-2 Risk Assessment and Treatment Process
* TTL - ISMS-DOC-09-2 Procedure for Internal Audits
* TTL - ISMS-DOC-09-4 Procedure for Management Reviews
* TTL - ISMS-DOC-10-1 Procedure for the Management of Nonconformity
* TTL - ISMS-DOC-A05-6 Modern Slavery Policy
* TTL - ISMS-DOC-A07-10 Anti-Bribery and Anti-Corruption Policy
* TTL - ISMS-DOC-A07-11 Conflicts of Interest Policy
* TTL - ISMS-DOC-A07-12 Whistleblowing Policy
* TTL - ISMS-DOC-A07-X1 Corporate Social Responsibility Policy
* TTL - ISMS-DOC-A14-2 Secure Development Policy
* TTL - ISMS-DOC-A14-3 Principles for Engineering Secure Systems
* TTL - ISMS-DOC-A18-1 Legal, Regulatory and Contractual Requirements Procedure
* TTL - ISMS-DOC-A18-3 IP and Copyright Compliance Policy
* TTL - ISMS-DOC-A18-4 Records Management Policy

***

### Compliance and Governance Documentation Request Form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=compliance+and+governance+documentation&resourcepath=support.tiller-verify.com/hubfs/Trust+Centre+-+Due+Diligence+Documents/Tiller+Technologies+-+Compliance+and+Governance.zip>" %}

[^1]: Standard for Risk Management


# Verify's Regulatory Compliance

**Verify by Tiller** is purpose-built to satisfy complex AML, CFT, and CPF obligations for regulated businesses across the UK, the Crown Dependencies (Jersey, Guernsey, Isle of Man), and international financial centres. To demonstrate how our platform supports your specific regulatory commitments, we have provided helpful information on our alignment with key jurisdictional authorities below.

{% content-ref url="/pages/w28OjMz3Somn5RpMjUsV" %}
[Jersey Financial Services Commission](/trust-centre/regulatory-compliance/jersey-financial-services-commission)
{% endcontent-ref %}

{% content-ref url="/pages/N3dgJf2VaDdlD56Az24v" %}
[Guernsey Financial Services Commission](/trust-centre/regulatory-compliance/guernsey-financial-services-commission)
{% endcontent-ref %}

{% content-ref url="/pages/6Gog70DADG0wRXGX5SBs" %}
[Isle of Man Financial Services Authority](/trust-centre/regulatory-compliance/isle-of-man-financial-services-authority)
{% endcontent-ref %}

{% content-ref url="/pages/uJPdVGifyWmJX70M1nDH" %}
[Bermuda Proceeds of Crime Regulations & BMA Guidance](/trust-centre/regulatory-compliance/bermuda-proceeds-of-crime-regulations-and-bma-guidance)
{% endcontent-ref %}


# Jersey Financial Services Commission

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

As a Jersey-based company, we understand that firms regulated by the Jersey Financial Services Commission (JFSC) must carefully evaluate any third-party solution. The selection of an CDD and AML platform, such as Verify by Tiller, is subject to specific regulatory obligations. These include:

{% content-ref url="/pages/5osD2XTl7lOysfNyYG7m" %}
[Jersey AML/CFT/CPF Handbook](/trust-centre/regulatory-compliance/jersey-financial-services-commission/jersey-aml-cft-cpf-handbook)
{% endcontent-ref %}

{% content-ref url="/pages/VZAhQFVXdnnTTCUW6JY6" %}
[Outsourcing Policy (OSP)](/trust-centre/regulatory-compliance/jersey-financial-services-commission/outsourcing-policy-osp)
{% endcontent-ref %}

As the regulated entity, you retain ultimate responsibility for compliance. However, we at Tiller are committed to providing you with the necessary information and support to help you meet your regulatory obligations.

***


# Jersey AML/CFT/CPF Handbook

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

We developed our Verify by Tiller platform to provide regulated companies with the necessary information to meet the requirements of the [JFSC AML/CFT/CPF Handbook](https://www.jerseyfsc.org/industry/financial-crime/amlcftcpf-handbooks/) (30th June 2026).

To provide you with an additional layer of assurance, we engaged independent compliance experts, [BDO Group Jersey](https://www.bdo.je/en-gb/industries/financial-services), to review our Verify by Tiller platform's adherence to the handbook.

We're proud to confirm that BDO's review found no gaps in our compliance.

<p align="center"><strong>We are happy to make BDO's report available to you via the</strong> <a href="#bdo-report-on-verify-by-tiller-and-jfsc-outsourcing-notification-download-request-form"><strong>request form below</strong></a><strong>.</strong></p>

## Handbook Requirement Mapping

Below is a breakdown as to how Tiller performed against JFSC AML/CFT/CPF Handbook requirements when it was independently assessed by BDO Group Jersey.

<details>

<summary>Finding out identity</summary>

A Supervised Person may demonstrate that it has found out the identity of an individual where it collects all the following \[Article 3(2)(a) of the Money Laundering Order]

<table><thead><tr><th width="198.666748046875" valign="top">Handbook Requirement</th><th width="443.6666259765625" valign="top">How was it achieved</th><th data-type="checkbox"></th></tr></thead><tbody><tr><td valign="top">Legal Name &#x26; names currently used</td><td valign="top">Names are read from the ID Documents and checked against entered details</td><td>true</td></tr><tr><td valign="top">Former names</td><td valign="top">Application allows additional names to be captured and<br>for supporting documents to be uploaded</td><td>true</td></tr><tr><td valign="top">Principle residential Address</td><td valign="top">The residential address is checked against regulatory quality data sources such as government databases, credit agencies &#x26; utility companies to confirm its accurate and current</td><td>true</td></tr><tr><td valign="top">Date of Birth</td><td valign="top">Place of Birth is read from the ID document when present and checked against entered details</td><td>true</td></tr><tr><td valign="top">Nationality</td><td valign="top">Nationality is read from the ID documents and checked</td><td>true</td></tr><tr><td valign="top">Government Issued Identifier</td><td valign="top">Identification numbers are read from the ID document<br>which is itself verified</td><td>true</td></tr><tr><td valign="top">Gender Identity</td><td valign="top">Gender is read from the ID documents when present and checked against entered details</td><td>true</td></tr></tbody></table>

</details>

<details>

<summary>Obtaining evidence of identity </summary>

A supervised person may demonstrate that it has obtained two sources of evidence that cover the above collected identity data

<table><thead><tr><th width="198.666748046875">Handbook Requirement</th><th width="443.6666259765625">How was it achieved</th><th data-type="checkbox"></th></tr></thead><tbody><tr><td>A current passport, national identity card or driving licence</td><td>Names are read from the ID Documents<br>Names are checked vs electoral registers or similar</td><td>true</td></tr><tr><td>Correspondence from central or local government, bank statement, utility bill or tenancy contract / agreement</td><td>The residential address is checked against regulatory quality data sources such as government databases, credit agencies &#x26; utility companies to confirm its accurate and current. In addition to the electronic verification of address, a copy of correspondence from central or local government, bank statement, utility bill or tenancy contract / agreement is also requested for upload</td><td>true</td></tr></tbody></table>

**Obtaining Evidence of Identity – Independent Data Sources**\
The Guidance Notes in the AML/CFT Handbook \[section 4.3.4, 70] confirms that a supervised person may demonstrate that it is satisfied that data or information supplied by\
a data service provider is sufficiently extensive, reliable, and accurate under Article 3(2)(a) of the Money Laundering Order where the source, scope and quality of the data or information accessed are understood.

</details>

<details>

<summary>Additional measures for when the person is not physically present</summary>

The Guidance Notes specifically highlights features of E-ID applications that may be used to mitigate the risk that documents have been tampered with or forger may include:

<table><thead><tr><th width="198.666748046875" valign="top">Handbook Requirement</th><th width="443.6666259765625" valign="top">How was it achieved</th><th data-type="checkbox"></th></tr></thead><tbody><tr><td valign="top">The copy of the document is of a very high level of clarity and resolution</td><td valign="top">Images are captured by the user’s mobile device or<br>extracted from the document’s NFC chip. The images<br>are presented to the user as part of the in-app<br>operations process for approval.</td><td>true</td></tr><tr><td valign="top">The copy of the document is automatically matched to a pre-defined “template” for the given id document</td><td valign="top">The document image is compared to government<br>templates as part of the ID&#x26;V process</td><td>true</td></tr><tr><td valign="top">The data in the main body of the document is compared to biometric data stored in the document’s machine-readable zone code</td><td valign="top">Where the document type supports this capability (for<br>example, passport document switch NFC/RFID chips),<br>this check is undertaken</td><td>true</td></tr><tr><td valign="top">Data on the document is automatically examined for use of<br>unauthorised print fonts and unexpected character spacing</td><td valign="top">The ID document image is compared to government<br>templates as part of the ID&#x26;V process</td><td>true</td></tr><tr><td valign="top">The copy of the document is automatically examined to enable<br>detection of fraudulent documents on the basis of that documents’<br>security features and locations of its elements</td><td valign="top">The ID document image is compared to government<br>templates as part of the ID&#x26;V process.</td><td>true</td></tr><tr><td valign="top">The copy of the document is examined by individuals specifically training to detect tampering /<br>forgery (e.g. ex-border agents) or the E-ID application has been<br>designed with the characteristics of this training/expertise in mind.</td><td valign="top">The ID document image is compared to government<br>templates as part of the ID&#x26;V process.<br>Verify by Tiller has been built with this requirement in<br>mind and incorporates a range of tamper-detection<br>processes.</td><td>true</td></tr><tr><td valign="top">The E-ID application itself controls the process and allows no<br>opportunity to tamper with documents or photographs</td><td valign="top">Verify by Tiller controls the entire process. The user<br>has no opportunity to tamper with images</td><td>true</td></tr><tr><td valign="top">A highly secure connection is used to transmit copies of documents and photographs</td><td valign="top">The transmission method is highly secure and<br>undertaken by the application</td><td>true</td></tr><tr><td valign="top">The E-ID application’s security is regularly tested in order to guard<br>against hacking or other security breaches</td><td valign="top">Verify by Tiller undergoes regular, full, front-to-back<br>penetration test cycles. These tests are performed by<br>an independent third party.</td><td>true</td></tr><tr><td valign="top">A "selfie" photograph of the customer is taken and biometrically<br>compared/matched to the photograph on the identity document presented</td><td valign="top">A series of randomised, liveness tests are performed<br>during the ID&#x26;V process. These are checked to the<br>government issued ID document.</td><td>true</td></tr><tr><td valign="top">A video or a "micro-stream” of photographs is taken in order to identify facial movements, which may help to confirm that the<br>customer is present</td><td valign="top">A series of randomised, liveness tests are performed<br>during the ID&#x26;V process. These are checked to the<br>government issued ID document.</td><td>true</td></tr><tr><td valign="top">Use of anti-impersonation measures</td><td valign="top">A series of randomised, liveness tests are performed<br>during the ID&#x26;V process. These are checked to the<br>government issued ID document.</td><td>true</td></tr><tr><td valign="top">A code or password is sent to the customer who, immediately before the application</td><td valign="top">The user is provided with a unique activation link as<br>part of the ID&#x26;V process.</td><td>true</td></tr><tr><td valign="top">Use of location matching</td><td valign="top">GPS location is captured as part of the ID&#x26;V process</td><td>true</td></tr><tr><td valign="top">The requirement that any image taken is adequately illuminated<br>when using the E-ID solution</td><td valign="top">Images are captured by the user’s mobile device or<br>extracted from the document’s NFC chip. The images<br>are presented to the user as part of the in-app<br>operations process for approval.</td><td>true</td></tr><tr><td valign="top">Where a supervised person uses E-ID<br>applications, adequate records are required to be kept</td><td valign="top">A full report of the ID&#x26;V checks &#x26; finding is provided<br>to the Supervised Person on completion of the ID&#x26;V<br>process.</td><td>true</td></tr></tbody></table>

</details>

<details>

<summary>Record keeping requirements relevant to use of electronic id</summary>

<table><thead><tr><th width="198.666748046875" valign="top">Handbook Requirement</th><th width="443.6666259765625" valign="top">How was it achieved</th><th data-type="checkbox"></th></tr></thead><tbody><tr><td valign="top">Adequate records are required to be kept</td><td valign="top">Verify by Tiller provides the Supervised Person with a<br>pdf containing a full copy of all data, images and<br>findings conducted as part of the ID&#x26;V process. The<br>Supervised Person is subsequently responsible for<br>maintaining these records on an ongoing basis.</td><td>true</td></tr><tr><td valign="top">Details of the biometric checking undertaken</td><td valign="top">This varies by country and document type. Please refer<br>to Verify by Tiller’s service documents</td><td>true</td></tr><tr><td valign="top">Details of what third party data sources have been utilised to verify the customer (if any).</td><td valign="top">This varies by country and document type. Please refer<br>to Verify by Tiller’s service documents</td><td>true</td></tr><tr><td valign="top">Details of the audit trail, sign-off or additional steps which have been undertaken.</td><td valign="top">Verify provides a comprehensive .pdf document the<br>details all the steps and approvals undertaken whilst<br>using the service.</td><td>true</td></tr><tr><td valign="top">Adequate records are required to be kept</td><td valign="top">Verify by Tiller provides the Supervised Person with a<br>pdf containing a full copy of all data, images and<br>findings conducted as part of the ID&#x26;V process. The<br>Supervised Person is subsequently responsible for<br>maintaining these records on an ongoing basis.</td><td>true</td></tr><tr><td valign="top">Details of the biometric checking undertaken</td><td valign="top">This varies by country and document type. Please refer<br>to Verify by Tiller’s service documents</td><td>true</td></tr><tr><td valign="top">Details of what third party data sources have been utilised to verify the customer (if any).</td><td valign="top">This varies by country and document type. Please refer<br>to Verify by Tiller’s service documents</td><td>true</td></tr><tr><td valign="top">Details of the audit trail, sign-off or additional steps which have been undertaken.</td><td valign="top">Verify provides a comprehensive .pdf document the<br>details all the steps and approvals undertaken whilst<br>using the service</td><td>true</td></tr></tbody></table>

</details>

***

## The JFSC Handbook and Verify by Tiller: An Overview

<details>

<summary>Does Verify by Tiller provide the information required under Article 3(2)(a) of the Money Laundering Order to perform customer due diligence</summary>

Yes. Verify by Tiller captures and where information required to verify the identity of an individual and were possible independently verifies that information from regulatory quality 3rd part data sources and verified identity documents. For full details see the detail in the [Handbook Requirement Mapping](#finding-out-identity)

</details>

<details>

<summary>Is the use of independent data sources when obtaining evidence of identity acceptable</summary>

Whether they are acceptable is always subject to acceptance by the supervised person for their specific circumstances. However, the JFSC AML/CFT Handbook \[section 4.3.4, 72] confirms that a supervised person may demonstrate that it is satisfied that data or information supplied by a data service provider is sufficiently extensive, reliable, and accurate under Article 3(2)(a) of the Money Laundering Order. For full details see the detail in the [Handbook Requirement Mapping](#obtaining-evidence-of-identity)

</details>

<details>

<summary>Does Verify by Tiller apply additional eID measures to aid in the verifying the identity of a person remotely.</summary>

Yes, The JFSC AML/Guidance Notes specifically highlights features that eID applications may be used to mitigate the risk that documents have been tampered with or forged. Verify by Tiller employ numerous technologies to mitigate these risks including but not limited to:

* Where the document type supports this capability (for example, passport document & ID cards), use of tamper proof NFC/RFID chips
* Document tamper detection, verifying key documents markers against templated originals of that specific document and issue.
* Image tamper detection and liveliness tests which where the document supports it image verification back to encrypted digital comply of image on NFC/RFID chips.

For full details ee the detail in the [Handbook Requirement Mapping](#record-keeping-requirements-relevant-to-use-of-electronic-id)

</details>

<details>

<summary>How does Tiller help me meet the "E-ID" requirements in Section 4 of the Handbook?</summary>

Tiller aligns with the guidance in Section 4.3.5 (Electronic Identification) of the Handbook. We provide:

1. **Passive Liveness Detection**: To guard against impersonation fraud.
2. **Document Authenticity**: Forensic checks to ensure the ID is not forged.
3. **Audit Trail**: A full, unalterable log of the verification steps for your Compliance Unit testing.

Liveness Detection meets the following international standards:

* **ISO 30107-3:** This international standard is the foundational framework for testing and evaluating how effectively a liveness detection solution can detect and defend against presentation attacks (spoofing attempts like photos, videos, or masks).
* **iBeta Accreditation:** iBeta is an independent testing lab accredited to perform testing against the ISO 30107-3 standard.
  * **Level 1 PAD:** Confirms basic attack detection capabilities.
  * **Level 2 PAD:** A higher, more robust level of certification that involves more sophisticated attack scenarios, and is considered the gold standard for enterprise-grade solutions.

Document Authenticity is achieved using the following forensic techniques:

* **Visual & Data Integrity Checks (Optical)**

  Use of Optical Character Recognition (OCR) and template matching using the camera's high-resolution image.

  * **MRZ Checksum Validation:** For passports and ID cards with a Machine-Readable Zone (the code at the bottom), the software calculates the check digits (mathematical checksums) to ensure the data lines are valid and have not been generated by a random number generator.
  * **VIZ vs. MRZ Consistency:** It extracts data from the **Visual Inspection Zone (VIZ)**, the normal text fields like Name and Date of Birth using **OCR** and compares it against the data in the **MRZ**. Any mismatch (e.g., a name spelled differently or a date altered in one place but not the other) triggers a failure.
  * **Template Matching (Pattern Recognition):** The image is compared against GBG’s global library of document templates. The software verifies the precise location of logos, the font type and size, and the background "guilloche" patterns (fine wavy lines) to ensure they match the issuing authority's standards.
* **Physical Security & Tamper Detection**

  To detect forgeries or "presentation attacks" (spoofing), Verify analyses the physical properties of the document image.

  * **Photo Tampering Detection:** The algorithms analyse the pixel density and edges around the photo area to detect "paste-over" attacks (where a fraudster glues a new photo over a stolen ID) or digital manipulation.
  * **Material Presence (Liveness):** The SDK checks for artifacts that suggest the document is not real plastic or paper. This includes detecting **screen refresh rates** (moire patterns) if someone is holding a phone up to the camera, or **lack of depth** if they are presenting a printed paper photocopy of an ID,
* **Electronic Verification (NFC for Passports)**

  When a passport or e-ID is available and the phone is NFC-enabled, Verify performs the "Gold Standard" cryptographic checks. This is the most reliable way to verify integrity because the data is cryptographically signed by the issuing government.

  * **Chip Access (BAC/PACE):** The app reads the MRZ to generate a key (Basic Access Control or PACE) to unlock the RFID chip. If the chip cannot be unlocked using the printed MRZ data, it suggests the physical page does not belong to the chip (a cloned or altered page).
  * **Passive Authentication (Data Integrity):** The software validates the **Document Signer Certificate (DSC)** against the Country Signing Certificate Authority (CSCA). This confirms that the data on the chip was signed by the government and has not been altered by a single byte since issuance.
  * **Active Authentication (Cloning Detection):** The chip is sent a random "challenge" which it must sign with its private key. A cloned chip will not have the private key and will fail this test, proving the physical document is the original.

</details>

<details>

<summary>Does Verify by Tiller's screening/monitoring take into account the introduction of the <em>Sanctions and Asset-Freezing (Implementation of External Sanctions) (Jersey) Order 2021</em></summary>

The main purpose of the Order is to give legal effect in Jersey to sanctions imposed by the United Nations Security Council (UNSC) and the autonomous sanctions regimes of the UK. This was necessary after the UK's departure from the European Union, as Jersey could no longer rely on EU sanctions regulations. This legislation, along with the *Sanctions and Asset-Freezing (Jersey) Law 2019*, provides the legal foundation for Jersey to implement a wide range of sanctions measures.

Verify by Tiller automatically checks individuals against the relevant UK and UN sanctions lists required under this order so is compliant. However it remains the responsibility of the supervised person that all requirements under this order are satisfied.

</details>

<details>

<summary>Does Verify by Tiller assist in the record keeping requirements set out in the Handbook</summary>

Businesses are required to keep accurate, clear and up to date records to satisfy customer due diligence and mitigate ongoing risk.

Verify by Tiller provides all the information it has captured, the checks and results of those checks and any supporting evidence such as images in one clear, simple but comprehensive PDF report that can be downloaded and included in the business records on the individual. Verify also provides an API with access to all the same information both in PDF format and in machine readable JSON format, allowing the CDD process to be fully integrated with your existing CRM or CLM system. See the detail in the [Handbook Requirement Mapping](#record-keeping-requirements-relevant-to-use-of-electronic-id)

</details>

<details>

<summary>Does using Tiller constitute "Material Outsourcing" under the JFSC OSP?</summary>

Generally, yes. Because Verify by Tiller handles critical CDD[^1] data and functions that are fundamental to your AML compliance, most firms should treat this as a "Material" outsourcing arrangement. We have prepared a [*Material Outsourcing Assessment and Notification*](/trust-centre/regulatory-compliance/jersey-financial-services-commission/outsourcing-policy-osp#outsourcing-policy-osp-jfsc-outsourcing-notification) template you can use to document this decision and notify the JFSC.

</details>

<details>

<summary>Can I use Tiller's specific "Outsourcing Notification" text for my JFSC portal submission?</summary>

Yes. To save you time, we have drafted "[Outsourcing Notification](/trust-centre/regulatory-compliance/jersey-financial-services-commission/outsourcing-policy-osp#outsourcing-policy-osp-jfsc-outsourcing-notification)" describing the "Nature of the Outsourced Activity" and "Risk Mitigation Measures" that you can copy and paste directly into the JFSC portal when submitting your outsourcing notification.

{% hint style="warning" %}
**It should be noted that some of the questions can only be completed by your business and all answers, included those either fully or partially completed by Tiller Technologies must be reviewed thoroughly and accepted or if necessary, updated based on your outsourcing due diligence assessment and business regulatory obligations.**
{% endhint %}

</details>

<details>

<summary>How does Verify by Tiller address the <em>UK Global Irregular Migration and Trafficking in Persons (Sanctions) Regulations 2025</em>?</summary>

The *UK Global Irregular Migration and Trafficking in Persons (Sanctions) Regulations 2025* is a specific sanctions regime. It is the legislation that provides the legal authority to impose various sanctions, such as asset freezes, travel bans, and director disqualifications, on individuals and entities involved in people smuggling, human trafficking, or the instrumentalization of migration.

The names of people and entities designated as sanctioned under the *Global Irregular Migration and Trafficking in Persons* *regulations* will appear on the larger *HMT Financial Sanctions List*. This list, also known as the Consolidated List, is the list of people and entities who have been designated under various UK sanctions regimes including the *Global Irregular Migration and Trafficking in Persons* *regulations* as being sanctioned. This list is maintained by the Office of Financial Sanctions Implementation (OFSI) at HM Treasury.

The *HMT Financial Sanctions List* is one of the many sanction list that Verify by Tiller checks when performing individual or entity AML checks.

</details>

***

## BDO Report on Verify by Tiller download request form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=BDO+Report+and+Outsourcing+Notice&resourcepath=support.tiller-verify.com/hubfs/Trust+Centre+-+Due+Diligence+Documents/BDO+and+Verify+by+Tiller+and+Outsourcing+Notice.zip>" %}

[^1]: Customer Due Diligence


# Outsourcing Policy (OSP)

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

## Outsourcing Policy (OSP) - Guidance

The [JFSC Outsourcing Policy (OSP)](https://www.jerseyfsc.org/industry/guidance-and-policy/outsourcing-policy/) outlines seven core principles that regulated companies must adhere to when outsourcing material activities.

To assist you with your outsourcing assessment, Tiller has provided a concise response to the relevant sections under each of these principles:

<details>

<summary><mark style="color:red;"><strong>Core Principle 1:</strong></mark> A Business is responsible for and accountable to the JFSC for any Outsourced Activity</summary>

***(3.1.3) Does our business retain responsible for the outsourced activity?***

> Yes, Tiller Technologies is defined as a [**Data Processor** ](#user-content-fn-1)[^1]within the Data Processing Agreement (DPA), which is part of our service agreement with you. This means we only process data based on your instructions as the [**Data Controller**](#user-content-fn-2)[^2]. The DPA confirms that Tiller cannot be delegated the responsibility for compliance decisions under regulatory law. For example, the decision to onboard a customer can only rest with you, while Verify by Tiller will provide the necessary information and check results to support that decision.

</details>

<details>

<summary><mark style="color:red;"><strong>Core Principle 2:</strong></mark> A Business must ensure that any Service Provider performing Outsourced Activity is Fit and Proper</summary>

***(3.2.1) How can our business conduct suitable and proportionate due diligence on Tiller?***

> Our [Trust Centre](/trust-centre) is designed to provide all the information your business needs to complete a thorough due diligence assessment on Tiller Technologies. Should you require any additional information not available there, please feel free to contact us.

***(3.2.3) How does choosing Tiller Technologies help reduce "material risk"?***

> As a [Jersey-registered company](https://www.jerseyfsc.org/registry/registry-entities/entity/313364) with all operational and managerial functions based on the island, Tiller Technologies is well-positioned to minimize any jurisdictional and regulatory risks. Our heritage in financial services gives us deep insight into the needs of regulated companies, but our primary focus is as a RegTech[^3] firm. We prioritize robust cybersecurity and sound data protection policies, and you can find a detailed overview of these measures in the [security section](/trust-centre/trust-components/information-security) of our Trust Centre.

***(3.2.4.2) Does Tiller have adequate capacity and resources to perform the Outsourced Activity?***

> Tiller has implemented with the use of the ISMS[^4] framework a complete suite of policies and procedures backed up by a robust governance and oversight structure. This is applied across the company and full details a provided, including supporting document in our [Trust Centre](/trust-centre#trust-components).

***(3.2.4.3) Does Tiller have adequate capacity and resources to perform the Outsourced Activity?***

> Tiller Technologies Limited operates as a wholly owned subsidiary of Tiller Group Limited. The group is in a sound financial position, with its most recent annual accounts publicly available via the [company registry](https://www.jerseyfsc.org/registry/registry-entities/entity/313364). We also maintain all necessary and appropriate insurance policies.

***(3.2.5.2) As a cloud services provider, does Tiller adhere to all industry good practices for data security and cyber risks?***

> Tiller has implemented with the use of the ISMS[^4] framework a complete suite of policies and procedures backed up by a robust governance and oversight structure. Security to Tiller is paramount. As a leading SaaS[^5] provider, we are committed to upholding the highest standards of information security, ensuring the confidentiality, integrity, and protection of you and client's valuable data within our platforms. Full details are provided in the [security](/trust-centre/trust-components/information-security) section of the Trust Portal, including supporting documentation.

***(3.2.5.3) Does Tiller adhere to international standards?***

> Tiller Technologies has implemented the widely accepted Information Security Management System (ISMS), aligning with the internationally recognized ISO/IEC 27001:2022 standard. This framework is foundational to Tiller's operations, providing clear guidelines for the systematic management of information security, data governance and business compliance.
>
> The ISMS framework helps Tiller ensure it can manage the confidentiality, integrity, and availability of all its information assets, including it SaaS[^5] platforms, networks, applications, and services. ISMS serves as a dynamic and systematic approach to identify and manage information security risks, fostering continuous improvement of Tiller's security controls to protect against evolving threats and uphold the trust placed in its operations.
>
> The Verify by Tiller platform is hosted in Azure data centres in Dublin, Ireland and Amsterdam, Netherlands. Both operate within the laws and regulations of the European Economic Area (EEA).

</details>

<details>

<summary><mark style="color:red;"><strong>Core Principle 3:</strong></mark> A Business must put in place an Outsourcing Agreement with the Service Provider before the start of the Outsourced Activity</summary>

***(3.3.1) Does Tillers service agreement include enforcement of the provisions set out in section 3.3.1 of the JFSC Outsourcing Policy (OSP)***

> All ten terms (3.3.1.1 to 3.3.1.10) under core principle 3 are fully addressed in the Tiller Technologies Service Agreement, Terms and Conditions, and the incorporated Data Processing Agreement. A copy of these documents is provided for your review as part of the quotation process.

***(3.3.2) How does Tillers service agreement meet the provisions set out in section 3.3.2 of the JFSC Outsourcing Policy (OSP)***

> All ten terms (3.3.2.1 to 3.3.2.10) under core principle 3 are fully addressed in the Tiller Technologies Service Agreement, Terms and Conditions, and the incorporated Data Processing Agreement. A copy of these documents is provided for your review as part of the quotation process.

</details>

<details>

<summary><mark style="color:red;"><strong>Core Principle 4:</strong></mark> A Business must maintain adequate capacity and resources to implement all necessary policies and procedures to ensure that a Service Provider continues to be Fit and Proper</summary>

*(**3.4.5.3) How does Tiller oversee and test the Outsourced Activity and to identify, monitor and mitigate against all associated risks?***

> Tiller has implemented with the use of the ISMS[^4] framework a comprehension suite of [Vulnerability](/trust-centre/trust-components/information-security#how-are-vulnerabilities-managed), [Incident](/trust-centre/trust-components/information-security#how-are-incidents-managed) and [Risk Management](/trust-centre/trust-components/risk-and-compliance#how-are-risks-managed) policies and procedures. These are designed to identify, Prioritise, Mitigate, Verify and Report and Monitor any occurrence of a vulnerability or incident or identified risk. Information on these processes and the supporting documentation is available in our [Trust Centre](/trust-centre#trust-components).

</details>

<details>

<summary><mark style="color:red;"><strong>Core Principle 5:</strong></mark> A Business must maintain suitable contingency plans in case a Service Provider’s performance suffers a material disruption, or ends unexpectedly, for any reason.</summary>

*(**3.5.5) What provisions exist in Tillers agreement terms and conditions to minimise the impact of voluntary or involuntarily termination of its services?***

> Tiller Technolgies as part of the termination clauses in the Data Processing Agreement which forms part of the overall Service Agreement, makes provision that if the service expires or terminates, the businesses data is made available for download and safe keeping by the business, after which the data will be deleted, except to the extent Tiller is required by applicable law to retain some of the data.

</details>

<details>

<summary><mark style="color:red;"><strong>Core Principle 6:</strong></mark> Except for where the OSP specifically provides otherwise, a Business must complete and upload an Outsourcing Notification before they appoint a Service Provider; the Service Provider must not start performing the Outsourced Activity until the Business receives a No Objection, and we must be notified of any subsequent material change to the Outsourced Activity as soon as the Business becomes aware</summary>

***(3.6.1 )  Do I need to notify the JFSC of our businesses use of Verify by Tiller?***

> Your business must make that determination based on the nature of your business, operational reliance on our services and specific circumstances. We cannot make that determination for you.
>
> Saying that, for Jersey regulated companies the answer is probably **yes** because of paragraph (3.6.5). You may still be required to notify the JFSC, but you may not have to wait for a 'No Objection'. Tiller has provided via the [request form below](#bdo-report-on-verify-by-tiller-and-jfsc-outsourcing-notification-download-request-form) an almost completed JFSC Outsourcing Notification form. Tiller has provided answers to the form's questions; however, **it is the sole responsibility of your business** to review those answers, ensure you agree with them based on your own due diligence assessments and that they are correct for your company's business operation.

</details>

<details>

<summary><mark style="color:red;"><strong>Core Principle 7:</strong></mark> A Business must ensure that there is nothing in the Service Provider’s performance of the Outsourced Activity that would prevent or restrict our regulatory powers in respect of the Business, or the Outsourced Activity</summary>

***(3.7.2) Does Tiller have provision in its agreements to ensure, where the JFSC require access to information to effectively supervise the outsourcing it can?***

> Tiller Technologies is a Jersey Registered company and although not licenced by the regulators, is still subject to all Jerseys laws. Tiller operates its Verify by Tiller platform from data centres in Ireland and the Netherlands and uses the services of other companies outside of Jersey. Tillers agreements with those companies all include provisions to ensure access to data required by law, by any court of competent jurisdiction or by **any regulatory or administrative body** is assured.

***(3.7.3) Does Tiller have provision in its agreements to ensure other jurisdictions secrecy laws does not impede the JFSC require access to information to effectively supervise the outsourcing?***

> Tiller does operate its Verify by Tiller platform from data centres in Ireland and the Netherlands. Tillers agreements with their hosting provider includes provisions to ensure access to data required by law, by any court of competent jurisdiction or by **any regulatory or administrative body** is assured.

</details>

### Treatment of Standardised Cloud Services

**Classification of Verify by Tiller**: Under the JFSC Outsourcing Policy (OSP) and its accompanying Guidance Notes, the Commission acknowledges the specific nature of "Standardised Cloud Services" (SaaS), where services are provided to multiple clients on a shared infrastructure with standard terms of business.

**Verify by Tiller is classified as a Standardised Cloud Service**.

**Impact on Your Due Diligence (Fit & Proper):** The JFSC recognizes that for standardised services, it is not always practical for a Supervised Person (the Client) to negotiate bespoke contractual terms or conduct physical onsite audits to assess the Service Provider.

To resolve this, and to simplify your "Fit and Proper" assessment burden, Tiller Technologies substitutes the need for bespoke investigation with enhanced transparency:

* **Audit & Assurance**: Instead of onsite visits, we provide access to our key policies, procedures, and other supporting detailed security documentation via this Trust Centre.
* **Contractual Terms**: While our Master Services Agreement (MSA) is a standard contract to ensure scalability, it has been specifically drafted to incorporate the Core Principles of the OSP, ensuring that despite being "standard," it is compliant with Jersey regulatory requirements.

**Conclusion for your Risk Assessment**: When completing your internal Outsourcing Notification or Risk Assessment, you may document that Verify by Tiller is a Standardised Cloud Service. You can evidence your oversight through the review of the standardized compliance and security artifacts provided in this Trust Centre.

***

## Outsourcing Policy (OSP) - JFSC Outsourcing Notification

The JFSC Outsourcing Policy may require your business to submit a completed Outsourcing Notification for digital services. You need to determine yourselves based on your business operating model and how you intend to use our services as to whether you just need to notify or if you require 'No Objection'. Typically:

* **If you are a Bank/Deposit Taker**: You likely require a 'No Objection' from the JFSC.
* **If you are a** [**DNFBP**](#user-content-fn-6)[^6]: You likely are only required to notification JFSC.

A **Designated Non-Financial Business and Profession** typically include:

* **Trust and Company Service Providers (TCSPs)**: Firms that set up and manage companies and trusts (the backbone of Jersey's finance industry).
* **Lawyers & Notaries**: specifically, when they are handling client transactions (e.g., buying property or managing client accounts).
* **Accountants**: When preparing transactions for clients.
* **Estate Agents**: When involved in transactions for buying/selling real estate.
* **Casinos/Gambling**: (Not a huge sector in Jersey but globally included).
* **High-Value Dealers**: Businesses dealing in precious metals, stones, or art.

To assist you with this notification process, we have provided a partially completed Outsourcing Notification form containing the information you need from us for your review, completion and submission.

<p align="center"><strong>We are happy to make this partially completed outsourcing notification form available to you via the</strong> <a href="#bdo-report-on-verify-by-tiller-and-jfsc-outsourcing-notification-download-request-form"><strong>request form below</strong></a><strong>.</strong></p>

{% hint style="warning" %}
**It should be noted that some of the questions can only be completed by your business and all answers, included those either fully or partially completed by Tiller Technologies must be reviewed thoroughly and accepted or if necessary, updated based on your outsourcing due diligence assessment and business regulatory obligations.**
{% endhint %}

***

## JFSC Outsourcing Notification download Request Form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=BDO+Report+and+Outsourcing+Notice&resourcepath=support.tiller-verify.com/hubfs/Trust+Centre+-+Due+Diligence+Documents/BDO+and+Verify+by+Tiller+and+Outsourcing+Notice.zip>" %}

[^1]: A Data Processor is an entity that handles personal data on behalf of a Data Controller. They process data based on the Data Controller's instructions

[^2]: A Data Controller is the entity that determines the purposes and means of processing personal data. The Data Controller is responsible for ensuring the processing complies with data protection laws

[^3]: Regulatory Technology

[^4]: Information Security Management System

[^5]: Software as a Service

[^6]: Designated Non-Financial Business and Profession


# Guernsey Financial Services Commission

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

As a Crown Dependency based company, we understand that firms regulated by the Guernsey Financial Services Commission (GFSC) must carefully evaluate any third-party solution. The selection of an CDD and AML platform, such as Verify by Tiller, is subject to specific regulatory obligations. These include:

{% content-ref url="/pages/Ya29kYWg6ALR7T6EoSE1" %}
[Guernsey AML/CFT/CPF Handbook](/trust-centre/regulatory-compliance/guernsey-financial-services-commission/guernsey-aml-cft-cpf-handbook)
{% endcontent-ref %}

{% content-ref url="/pages/0zh1P3LDHjZeMgA16pFg" %}
[Outsourcing Principles](/trust-centre/regulatory-compliance/guernsey-financial-services-commission/outsourcing-principles)
{% endcontent-ref %}

As the regulated entity, you retain ultimate responsibility for compliance. However, we at Tiller are committed to providing you with the necessary information and support to help you meet your regulatory obligations.

***


# Guernsey AML/CFT/CPF Handbook

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

As a Crown Dependency based company, we are uniquely aware of the needs of Guernsey regulated companies and developed our Verify by Tiller platform to ensure it meets or exceeds the requirements of the [GFSC AML/CFT/CPF Handbook](https://www.gfsc.gg/commission/financial-crime/handbook-on-countering-financial-crime-AML/CFT/CPF).

To provide you with an additional layer of assurance, we engaged the compliance experts, [Horsepool Group](https://horsepool.gg/), to review our Verify by Tiller platform's adherence to the handbook.

We're proud to confirm that the review found no gaps in our compliance.

<p align="center"><strong>We are happy to make the report available to you via the</strong> <a href="https://app.gitbook.com/o/lfRPWklrEZmas88PpVBX/s/gjPhZgVBq9D8qENoFca9/~/edit/~/changes/187/trust-centre/guernsey-financial-services-commission/guernsey-aml-cft-cpf-handbook#horsepool-group-report-on-verify-by-tiller-download-request-form"><strong>request form below</strong></a><strong>.</strong></p>

## Handbook Requirement Mapping

Below is a breakdown as to how Tiller performed against GFSC AML/CFT/CPF Handbook requirements when it was independently assessed by Horsepool Group.

<details>

<summary>Use of electronic solutions for identification and verification</summary>

**Requirement:** Electronic identification and verification systems can be used, provided they are sufficiently robust to mitigate the risk of false positives and negatives. Chapter 5, Section 5.40

* **How Tiller Satisfies This:**
  * The Product employs a range of independent sources for identity verification, including government databases and official records.
  * The use of diverse data sources provides a robust system designed to minimise false positives and negatives.

**Requirement:** Systems must use multiple data sources to confirm identity and verify&#x20;information independently. Chapter 5, Section 5.41

* **How Tiller Satisfies This:**
  * The Product sources data from a comprehensive network, including    &#x20;government and regulatory databases, to verify information    &#x20;independently, which aligns with the Handbook's requirements

**Requirement:** Firms must ensure electronic solutions are reliable and capable of&#x20;verifying identification documents and details effectively. Chapter 5, Section 5.42

* **How Tiller Satisfies This:**
  * The Product uses a web-platform and user app which guides verification    &#x20;subjects through the provision of appropriate documentation, such as    &#x20;passports, national identity cards, driver’s licenses and proof of address    &#x20;documentation.
  * Where a verification subject provides documentation other than a    &#x20;passport with an NFC-enabled chip, the Product uses Optical Character    &#x20;Recognition to obtain the relevant data from the document.
  * Where a verification subject provides a passport with an NFC-enabled    &#x20;chip, the Product uses NFC-technology to import the passport details from    &#x20;the data held on the chip.
  * Address verification is performed using a series of data sources checked    &#x20;against public registers available from governments and related agencies,    &#x20;however, will have some limitations in certain countries. Manual    &#x20;intervention overcomes this limitation.

**Requirement:** The system must include measures for detecting fraud, document\
tampering, and impersonation attempts. Chapter 5, Section 5.43

* **How Tiller Satisfies This:**
  * The Product employs the use of a ‘liveness check’ which is designed to make use of the verification subject’s camera on their device when    &#x20;uploading their documentation and information to the associated app.
  * The ‘liveness’ check requires the subject to perform four movements which are captured on camera. The subject’s image is compared to their    &#x20;passport and other verification data and any anomalies are flagged to the    &#x20;user for investigation.
    * *NB: This has now been replaced with an even more advanced 'Passive Liveness' test which is easier for the client and add enhanced reliability, security and is certified as meeting the **ISO 30107-3 iBeta Accreditation Level 2 PAD**:*
      * ***ISO 30107-3:** This international standard is the foundational framework for testing and evaluating how effectively a liveness detection solution can detect and defend against presentation attacks (spoofing attempts like photos, videos, or masks).*
      * ***iBeta Accreditation:** iBeta is an independent testing lab accredited to perform testing against the ISO 30107-3 standard.*
        * ***Level 1 PAD:** Confirms basic attack detection capabilities.*
        * ***Level 2 PAD:** A higher, more robust level of certification that involves more sophisticated attack scenarios and is considered the gold standard for enterprise-grade solutions.*
  * Document tampering is largely mitigated by the use of independent    &#x20;source checks such as with address verification as described above.

**Requirement:** Firms using electronic identification must regularly review and monitor the\
solution’s effectiveness in line with the firm’s risk appetite. Chapter 5, Section 5.44

* **How Tiller Satisfies This:**
  * This is an obligation on the firm which wishes to make use of the Product and therefore is not relevant to the assessment of the suitability of the    &#x20;Product.

</details>

<details>

<summary>Identification and verification of Natural Persons</summary>

**Requirement:** Identification and verification of natural persons must include obtaining documentation which confirms the person’s full name, date of birth,&#x20;nationality, residential address, and any former names. Chapter 5, Section 5.5

* **How Tiller Satisfies This:**
  * The Product collects all key identification data such as names, date of birth, nationality, and residential address based on:
    * (i) input from the      &#x20;verification subject and
    * (ii) verification against independent data sources.
  * The Product allows a firm to setup modular templates for different types    &#x20;of verification, based on the assumed risk profile of an individual.

**Requirement:** Verification must be based on reliable, independent source documents, data, or information. This includes official documents like passports,&#x20;national identity cards, or driver’s licenses. Chapter 5, Section 5.6

* **How Tiller Satisfies This:**
  * The Product uses a web-platform and user app which guides verification subjects through the provision of appropriate documentation, such as passports, national identity cards, driver’s licenses and proof of address    &#x20;documentation.
  * Address verification is performed using a series of data sources checked against public registers available from governments and related agencies, however, will have some limitations in certain countries. Manual    &#x20;intervention overcomes this limitation.
  * The Product sources data from a comprehensive network, including government and regulatory databases, to verify information    &#x20;independently

**Requirement:** In cases where electronic solutions are used, verification must involve&#x20;data obtained from multiple independent and reliable sources. Chapter 5, Section 5.41

* **How Tiller Satisfies This:**
  * The Product sources data from a comprehensive network, including government and regulatory databases, to verify information    &#x20;independently, which aligns with the Handbook's requirements.

**Requirement:** For higher-risk individuals, firms must take additional steps to verify identity, including obtaining certified copies of documents or conducting enhanced due diligence. Chapter 8, Section 8.4

* **How Tiller Satisfies This:**
  * The Product allows a firm to setup modular templates for different types of verification, based on the assumed risk profile of an individual. Certification of documents is replaced through the independent verification of the documentation employed by the Product.

**Requirement:** Verification records must be kept for the required retention period, typically five years, to facilitate future due diligence and transaction&#x20;monitoring. Chapter 16, Section 16.2

* **How Tiller Satisfies This:**
  * The Product will automatically delete reports on verification subjects after a minimum period (e.g. 8 weeks) and it is incumbent on firms to ensure that the reports are downloaded and stored to their own systems, and    &#x20;retained for the required period.

</details>

<details>

<summary>Source of Wealth and Source of Funds</summary>

**Requirement:** Firms must obtain information on the source of wealth and source of funds as part of the customer due diligence process, particularly for high-risk&#x20;clients. Chapter 4, Section 4.9

* **How Tiller Satisfies This:**
  * The Product allows users to request source of wealth and source of funds information from verification subjects.
  * Verification subjects are required to articulate their source of wealth and source of funds, and upload corresponding proof or evidence which is    &#x20;reviewed by the user.

**Requirement:** Information on the source of funds must include the origin of the funds \
used in transactions or business relationships, requiring evidence such&#x20;as bank statements, salary details, or sale of assets. Chapter 5, Section 5.17

* **How Tiller Satisfies This:**
  * The Product allows users to request source of wealth and source of funds information from verification subjects.
  * Verification subjects are required to articulate their source of wealth and source of funds, and upload corresponding proof or evidence which is    &#x20;reviewed by the user.

**Requirement:** For source of wealth, firms should gather information about how a customer acquired their total wealth, using evidence such as business&#x20;ownership, investments, or inheritance documents. Chapter 5, Section 5.18

* **How Tiller Satisfies This:**
  * The Product allows users to request source of wealth and source of funds information from verification subjects.
  * Verification subjects are required to articulate their source of wealth and source of funds, and upload corresponding proof or evidence which is    &#x20;reviewed by the user.

**Requirement:** Firms must assess the plausibility of the information provided and corroborate it with documentation, especially in cases involving higher risk customers or transactions. Chapter 8, Section 8.5

* **How Tiller Satisfies This:**
  * The Product does not make any automated or assumed calculation of plausibility and is reliant on the firm and its users to make such    &#x20;assessment.

**Requirement:** Enhanced due diligence measures, including obtaining more detailed information and additional verification, must be applied when dealing with&#x20;politically exposed persons (PEPs) or high-risk jurisdictions. Chapter 8, Section 8.4 - 8.7

* **How Tiller Satisfies This:**
  * The Product is designed as an E-ID Solution and forms part of an overall customer relationship risk assessment which must be designed and implemented by a firm. The firm is responsible for applying relevant ECDD    &#x20;measures based on the findings presented by the Product

</details>

<details>

<summary>Adverse Media, Sanctions, and PEP Screening Requirements</summary>

**Requirement:** Firms must conduct regular screening against applicable sanctions lists (e.g., UN, UK, EU) to ensure they do not engage in business with&#x20;sanctioned individuals or entities. Chapter 12, Section 12.5

* **How Tiller Satisfies This:**
  * The Product makes use of numerous global sanctions lists to perform initial screening at the point of take-on which includes appropriate sources    &#x20;which are linked to applicable sanctions lists.
  * The Product has a separate module called “Check” which is designed to allow independent screening without sending a request to a verification    &#x20;subject (such as when performing pre-engagement screening).

**Requirement:** PEP screening must include identifying customers and beneficial owners who are politically exposed persons and applying enhanced due&#x20;diligence. Chapter 8, Section 8.16 - 8.20

* **How Tiller Satisfies This:**
  * The Products includes comprehensive PEP screening, leveraging a wide range of international sources and forms part of an overall customer relationship risk assessment which must be designed and implemented by a firm. The firm is responsible for applying relevant ECDD measures    &#x20;based on the findings presented by the Product.

**Requirement:** Adverse media checks must be conducted to identify negative information associated with customers that could indicate a higher risk of money&#x20;laundering or terrorism financing. Chapter 5, Section 5.22

* **How Tiller Satisfies This:**
  * The Product scans over 120,000 sources for adverse media, indicating a robust process for identifying negative information and any findings are flagged to users which can be accepted or rejected, and the appropriate rationale is recorded.

**Requirement:** Firms must monitor transactions and customer activity for any matches against sanctions, adverse media, or PEP lists and take appropriate action (e.g., blocking transactions, filing suspicious activity reports) when&#x20;a match is found. Chapter 11, Section 11.10 - 11.15

* **How Tiller Satisfies This:**
  * The Product is designed as an E-ID Solution and forms part of overall customer relationship risk assessment which must be designed and implemented by a firm. The firm is responsible for performing monitoring    &#x20;of transactions which is not the purpose of the Product.

**Requirement:** Records of sanctions and PEP screenings, including any actions taken as a result of a match, must be retained and documented for future reference. Chapter 16, Section 16.4

* **How Tiller Satisfies This:**
  * The Product will automatically delete reports on verification subjects after a minimum period (e.g. 90 days) and it is incumbent on firms to ensure that details of any matches and action taken are stored to their own    &#x20;systems, and retained for the required period.

</details>

***

## The GFSC Handbook and Verify by Tiller: An Overview

<details>

<summary>Does the GFSC Handbook allow us to outsource our CDD and screening functions to a SaaS provider like Verify by Tiller?</summary>

**Yes**. The Handbook explicitly permits the outsourcing of functions relevant to compliance, including the gathering of identification data and screening. However, under **Commission Rule 2.42**, the Board remains ultimately responsible for compliance and cannot contract out of its statutory liability.

**How Verify by Tiller Addresses This**:

* Verify by Tiller acts as an outsourced service provider. While your Board retains liability, Tiller mitigates your vendor risk by providing a platform specifically "mapped" to the GFSC Handbook. It provides the rigorous audit trails and "meaningful, accurate and complete information" required by **Commission Rule 2.48(c)** to allow you to monitor the outsourced activity effectively.

</details>

<details>

<summary>Can we use electronic verification (E-ID) instead of traditional "wet ink" certified copies for non-face-to-face customers?</summary>

**Yes.** The Handbook adopts a "technology neutral" stance. **Chapter 5 (Section 5.6/5.7)** and **Chapter 6 (Section 6.5)** permit the use of electronic systems to verify identity. In fact, **Commission Rule 6.23** acknowledges that electronic controls can provide "an equally robust confirmation of a natural person's identity" compared to physical certification.

**How Verify by Tiller Addresses This:**&#x20;

* Verify by Tiller utilises advanced E-ID technology that satisfies the criteria for "Electronic System Certifiers" in **Section 6.5**. It employs biometric facial matching and NFC chip reading of passports to confirm the document's authenticity and the individual's presence (liveness), replacing the need for a lawyer or accountant to certify a copy physically.

</details>

<details>

<summary>What are the specific requirements for an electronic system to be accepted as a "certifier" under Chapter 6?</summary>

To replace a natural person certifier, the electronic system must integrate robust validation controls. **Commission Rule 6.24** lists specific examples, including:

1. Capturing photographs of the ID and the person.
2. Liveness checks (anti-impersonation measures).
3. Corroboration of biometric data (e.g., NFC chip).
4. Independent verification of the document against missing/stolen lists.

**How Verify by Tiller Addresses This:**

* Verify by Tiller meets these specific technical standards by incorporating NFC chip reading (authenticating the government-issued e-Passport), biometric liveness checks (preventing spoofing), and document validation against global databases. Tillers 'Passive Liveness test is certified as meeting the highest **ISO 30107-3 iBeta Accreditation Level 2 PAD** standard:

  * **ISO 30107-3:** This international standard is the foundational framework for testing and evaluating how effectively a liveness detection solution can detect and defend against presentation attacks (spoofing attempts like photos, videos, or masks).
  * **iBeta Accreditation:** iBeta is an independent testing lab accredited to perform testing against the ISO 30107-3 standard.
    * **Level 1 PAD:** Confirms basic attack detection capabilities.
    * **Level 2 PAD:** A higher, more robust level of certification that involves more sophisticated attack scenarios, and is considered the gold standard for enterprise-grade solutions.

  This fulfils the "triple-lock" of security implied by the Handbook's guidance on electronic certification.

</details>

<details>

<summary>Do we need to conduct a risk assessment before using Verify by Tiller?</summary>

**Yes**. **Commission Rule 2.46** mandates that *prior* to establishing an outsourcing arrangement, you must assess the risk of potential exposure to ML/TF/PF. Additionally, **Commission Rule 3.67** requires a specific business risk assessment (BRA) update before adopting "new technologies" for CDD.

**How Verify by Tiller Addresses This:**&#x20;

* Tiller assists in this process by providing transparency on its data sources and security protocols. They also provide a full due diligence pack which include an already completed due diligence assessment questionnaire to support and expedite the process. Implementing Tiller would constitute a "new business practice" or "new technology," and their system provides the granular reporting on their own controls necessary for your Board to approve the risk assessment as required by **Commission Rule 3.71.**

</details>

<details>

<summary>How does using a SaaS provider affect our obligation to screen for PEPs and Sanctions?</summary>

The obligation to screen remains absolute. **Commission Rule 12.42** requires firms to ensure they are not dealing with sanctioned entities. **Chapter 8** requires the identification of PEPs. Using an automated tool is highly recommended for ongoing accuracy.

**How Verify by Tiller Addresses This:**

* Verify by Tiller integrates real-time screening against global sanctions lists (UN, UK, OFAC) and PEP databases. Crucially, it addresses **Commission Rule 8.2.1** (Enhanced Due Diligence) by enabling "more frequent and more extensive ongoing monitoring". Tiller’s "Monitoring" module provides daily alerts on changes to a client's status, ensuring you are immediately aware if a client becomes a PEP or is sanctioned *after* onboarding.

</details>

<details>

<summary>Can Verify by Tiller help us meet the "reasonable measures" test for verifying address?</summary>

**Yes**. **Section 5.4** of the Handbook requires verification of the principal residential address. **Section 5.5** permits the use of "electronic statements" (e.g., utility bills delivered by email, or digital sources) provided the firm is satisfied with their veracity.

**How Verify by Tiller Addresses This**:

* Tiller allows for the secure upload and capture of address documents. It also performs direct verification of the residential address against government, credit agency and utility company databases. Furthermore, it can enhance "reasonable measures" by using **geolocation capture** (GPS data) at the time of onboarding to corroborate that the user is physically present at the claimed location, adding a layer of assurance beyond a simple PDF upload.

</details>

<details>

<summary>What are the record-keeping requirements if we use a digital platform?</summary>

**Commission Rule 16.14** requires that records are "readily retrievable" and kept for at least five years. You must be able to provide these to the Commission or FIU promptly.

**How Verify by Tiller Addresses This:**

* Verify by Tiller creates a comprehensive digital audit trail. For every check, it generates a **detailed PDF report** that includes timestamps, the specific data sources checked, and the outcomes of biometric matching. This ensures that even if you change providers later, you have a permanent, exportable record of the due diligence performed, satisfying **Chapter 16** requirements.

</details>

<details>

<summary>Does Verify by Tiller cover "Adverse Media" checks as recommended in the Handbook?</summary>

**Yes.** While not always a strict rule for *low* risk clients, **Section 3.17.1 (Customer Risk Factors)** indicates that firms must consider "adverse media reports" when assessing customer reputation. For high-risk clients, EDD measures often require open-source intelligence searches.

**How Verify by Tiller Addresses This**:

* Tiller includes an **Adverse Media screening** module that scans thousands of global news sources. This automates the "negative press" check, helping you build a robust risk profile as required by **Chapter 3**, without your analysts having to manually trawl search engines.

</details>

<details>

<summary>We rely on "Introducers" (Chapter 10). Can Tiller help with this?</summary>

**Yes**. **Chapter 10** allows firms to rely on an "Introducer" (Appendix C business) but requires the firm to "immediately upon request" obtain identification data. The risk often lies in the delay of receiving this data.

**How Verify by Tiller Addresses This:**

* Tiller can be used to facilitate **Introduced Business**. The Introducer can use Tiller to perform the check and instantly share the secure digital ID pack with your firm. This ensures you meet the "immediately upon request" test by effectively having the data available in real-time, reducing the reliance risk described in **Section 10.2.**

</details>

<details>

<summary>How do we handle "High Risk" customers using an automated tool?</summary>

For **High-Risk** relationships (e.g., Foreign PEPs), **Commission Rule 8.6** mandates **Enhanced Due Diligence (EDD)**. Automation alone is rarely sufficient; senior management approval is required.

**How Verify by Tiller Addresses This:**

* Tiller supports a **Risk-Based Approach**. You can configure workflows so that if a "hit" (PEP match or high-risk country) occurs, the file is flagged for manual review. Tiller provides the raw data (source of wealth docs, screening hits) to enable your MLRO/Senior Management to make the informed decision required by **Chapter 8**, but it does not auto-approve high-risk cases, ensuring compliant human oversight.

</details>

<details>

<summary>Does Tiller help with the "Source of Funds" (SoF) requirements?</summary>

**Section 8.3** requires taking reasonable measures to establish source of funds and wealth for high-risk customers.

**How Verify by Tiller Addresses This:**

* The platform allows for the **secure upload of supporting documentation** (bank statements, investment portfolios, sale agreements) directly from the client during the onboarding flow. This ensures SoF evidence is collected and linked directly to the client's digital profile, facilitating the "corroboration" required by **Commission Rule 8.25**.

</details>

<details>

<summary>Is "selfie" verification sufficient for liveness detection under the Handbook?</summary>

The Handbook requires measures to prevent "impersonation or identity fraud". A simple static selfie can be spoofed. **Section 6.5(b)** suggests "anti-impersonation measures" such as repeating words or movements.

**How Verify by Tiller Addresses This:** Verify by Tiller uses passive liveness checks rather than just a static photo. Tillers advanced passive liveness technology is certified as meeting the highest international standard of **ISO 30107-3 iBeta Accreditation Level 2 PAD**:

* **ISO 30107-3:** This international standard is the foundational framework for testing and evaluating how effectively a liveness detection solution can detect and defend against presentation attacks (spoofing attempts like photos, videos, or masks).
* **iBeta Accreditation:** iBeta is an independent testing lab accredited to perform testing against the ISO 30107-3 standard.
  * **Level 1 PAD:** Confirms basic attack detection capabilities.
  * **Level 2 PAD:** A higher, more robust level of certification that involves more sophisticated attack scenarios, and is considered the gold standard for enterprise-grade solutions.

This technology fully satisfies the robust anti-impersonation requirements of **Chapter 6**.

</details>

<details>

<summary>Does Tiller work for corporate customers (Legal Persons)?</summary>

**Chapter 7** requires understanding the ownership and control structure of legal persons and identifying Ultimate Beneficial Owners (UBOs).

**How Verify by Tiller Addresses This:**

* While E-ID is primarily for natural persons, Tiller will soon release a new KYB module which will allow you to build **corporate structures** within the platform, identifying UBOs. You can then trigger the individual E-ID checks for each identified UBO and Director. This "unwrapping" of the corporate structure aligns with **Section 7.3 (Beneficial Ownership)**.

</details>

<details>

<summary>What happens if Tiller identifies a "false positive" on a sanction match?</summary>

The Handbook requires you to resolve potential matches. **Section 12.9** emphasizes that firms must have procedures to handle sanction alerts.

**How Verify by Tiller Addresses This:**

* Tiller provides detailed match data (e.g., match percentage, specific alias matched). It allows your compliance team to review the potential match, add commentary/rationale for discounting it (if it is a false positive), and mark it as "Resolved." This creates the **audit trail of the decision-making process** required for regulatory defence.

</details>

***

## Horsepool Group Report on Verify by Tiller download request form

{% embed url="<https://share.hsforms.com/1aolwbtHkQjCTbiK3fd6Pfg4boxz?resourcename=Horsepool+Group+Report&resourcepath=7264007.fs1.hubspotusercontent-na1.net/hubfs/7264007/Trust+Centre+-+Due+Diligence+Documents/Tiller+Verify+Suitability+Assessment+-+Horsepool.zip>" %}


# Outsourcing Principles

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

## Outsourcing Principles

The GFSC has adopted a **principle-based** approach within the Handbook when it comes to outsourcing, supplemented by Guidance Notes. They focus on your company performing a risk assessment and having effective oversight when selecting an outsource provider.

When engaging a SaaS company like Tiller Technologies to perform functions relevant to Schedule 3 (e.g., electronic verification, screening), this constitutes a material outsourcing arrangement. Therefore, it is advised that you notify the GFSC of the arrangement.

To assist you with your outsourcing assessment and to provide supporting information for your notification to the GFSC, Tiller has provided a concise response to the relevant sections of the handbook:

<details>

<summary><strong>Due Diligence on the Provider (Handbook Ch 2, Para 2.48)</strong></summary>

Firms must as part of their vendor assurance, ensure the outsourced provider has "appropriate knowledge, skill, and experience" and applies policies and controls to an equivalent standard.

**How Tiller Satisfies This:**

* **Local Regulatory Alignment**: Unlike other providers, Verify by Tiller has been explicitly mapped to the GFSC Handbook. We collaborated with Guernsey compliance specialists Horsepool to ensure our workflows align with local Schedule 3 requirements.
* **Security Standards**: Tiller Technologies demonstrates that its [information security](/trust-centre/trust-components/information-security), [data protection](/trust-centre/trust-components/data-protection), personnel skills, and [operational controls](/trust-centre/trust-components/risk-and-compliance) meet the highest international standard for information security management.
* **Proven Track Record**: Tiller are the chosen partner for regulated entities across the Channel Islands and globally, including banks, wealth managers, and trust companies.

</details>

<details>

<summary><strong>Technology Risk &#x26; Data Sovereignty (Handbook Ch 3 &#x26; Para 3.86)</strong></summary>

Firms must assess the ML/TF/PF risks and vulnerabilities (cyber risks) associated with "New Technology" before adoption.

**How Tiller Satisfies This:**

* **Data Residency**: Your client data is hosted in Microsoft Azure data centres (based in Europe), ensuring alignment with GDPR and data sovereignty requirements. Tiller and its [sub-processors](https://verify-doc.tiller-verify.com/training-hub/trust-centre/data-privacy#tiller-technologies-use-of-3rd-party-sub-processors) strictly manage and are transparent about how data is managed and were required to perform the function instructed by you, shared.&#x20;
* **GFSC Right of Access**: Our contract with the client and our contracts with our sub-processors include clauses to ensure the regulator (GFSC) is explicitly granted right to access the data if needed.
* **Encryption Standards**: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), mitigating the risk of data interception or leakage. We employ a security in depth design approach to ensure data is always secure.
* **Penetration Testing**: We undergo regular independent penetration testing (annual or major release) to validate the resilience of our platform against cyber threats. We also continually test and monitor our platforms security state and resilience posture.&#x20;

</details>

<details>

<summary><strong>Electronic Identification (E-ID) "Triple Check" (Handbook Ch 5, Para 5.30)</strong></summary>

Electronic verification must act as a "triple check," verifying:

1. **Authenticity**: The document is genuine.
2. **Liveness**: The person presenting it is real and present.
3. **Linkage**: The person is linked to the identity and address.

**How Tiller Satisfies This:**

* **Authenticity (NFC Verification)**: Verify by Tiller utilizes NFC chip reading to cryptographically validate e-Passports. This accesses the government-signed digital data directly, preventing tampering and "photoshop" fraud which optical-only checks might miss. In addition, we apply rigorous templated, tamper and authenticity detection techniques to verify all forms or presented id documents.
* **Liveness (ISO 30107-3 Level 2)**: We utilize Passive Liveness detection certified to ISO 30107-3 Level 2. This detects deepfakes, masks, and screen spoofs instantly without complex user instructions.
* **Linkage (Geo & Residential Address)**: We verify the individual's residential address against international regulatory quality databases (50+ countries) and can capture geo-location data during the check to confirm the user is physically located where they claim to be.

</details>

<details>

<summary><strong>Oversight, Audit Trail &#x26; Monitoring (Handbook Ch 2, Para 2.49)</strong></summary>

The firm must "monitor the outsourced activity" and maintain a retrievable audit trail. Relying solely on a third party without oversight is not permitted.

**How Tiller Satisfies This:**

* **Immutable Audit Logs**: client acceptance of terms, documents uploaded, and check performed etc., all generate a timestamped digital record.
* **The "Compliance Pack" (PDF)**: For every client screened, Tiller generates a comprehensive PDF report detailing the information captured from the client, checks performed, the results (Pass/Fail), notes and the specific risk flags. This document can be downloaded manually or automatically via the API to your internal Document Management System (DMS) to satisfy record-keeping rules (Regulation 14).
* **Administrative Annotations**: The Tiller Portal allows your internal compliance team to add "Administrative Notes" to a client profile. This is critical for recording your *human* decision-making rationale (e.g., "Accepted risk based on additional evidence Y"), proving that you retain final responsibility.

</details>

<details>

<summary><strong>Reporting Suspicion &#x26; Exception Management (Handbook Ch 13)</strong></summary>

The agreement must ensure the provider reports any knowledge or suspicion of ML/TF to the firm's MLRO.

**How Tiller Satisfies This:**

* **Automated Flagging**: Verify by Tiller does not "hide" results. If a check fails (e.g., a sanction match, a liveness failure, or a document expiry), the system triggers a "Red Flag" or "Refer" status on the dashboard, ensuring the appropriate review and informed action can be taken.
* **Escalation Workflow**: These flags act as the trigger for your internal team to investigate. While Tiller does not file the SAR with the Financial Intelligence Unit (FIU), our clear "Exception Reporting" ensures your MLRO has the immediate intelligence needed to form a suspicion and report if necessary.

</details>

***

### Treatment of Standardised Cloud Services

While the Guernsey Financial Services Commission (GFSC) does not currently have a single, standalone "**Cloud Policy**", it has established definitive requirements for SaaS and Cloud services through three converging regulatory pillars:

1. **The Cyber Security Rules and Guidance, 2021** (The primary regulation for Cloud/SaaS).
2. **The Guidance Note on Outsourcing** (The general governance framework).
3. **The Handbook on Countering Financial Crime** (Specific to "New Technologies" used for AML).

#### Core Regulatory Pillars for SaaS/Cloud

To use a SaaS provider like Tiller Technologies compliantly, a Guernsey firm must adhere to the following specific standards:

<details>

<summary><strong>The Cyber Security Rules and Guidance, 2021</strong></summary>

This is the most critical document for SaaS engagements. The GFSC explicitly recognizes Cloud services as an "asset" that must be risk managed.

* **Cloud as Outsourcing**: The Guidance states: *"The Commission recognises that a Firm may hold assets using cloud services or similar outsourced service. It is the expectation that a Firm would identify these assets held in this manner in the same way they would any other outsourced provider."*
* **Board Accountability**: The Board remains accountable, and they must verify that the SaaS provider has appropriate controls (Identify, Protect, Detect, Respond, Recover).
* **Standardised Services**: The Commission acknowledges that for large, standardised providers (like Microsoft Azure or SaaS platforms), a bespoke contract may not be possible. In these cases, the Board must:
  * Review the provider's standard terms.
  * Assess if those terms meet the firm's minimum-security requirements.
  * Accept the residual risk formally in the Board minutes.

**How Tiller Satisfies This:**

* **Extensive Information Available**: Through this Trust Portal we provide full access to our governance policies and procedures providing you with the confidence that Tiller has appropriate controls in place to (Identify, Protect, Detect, Respond, Recover).
* **Contractual Terms**: Our contract with you is already designed to ensure it allows you to adhere to all the requirements set out by the GFSC without the need for any additional special terms, security requirements or other provisions. The contract has been reviewed and accepted by many companies operating in Guernsey and the Crown Dependencies and is proven to meet legal needs of those companies. Should however you have any unique requirements in excess of those mandated by the regulators our sales staff will be happy to discuss your specific requirements.&#x20;

</details>

<details>

<summary><strong>The Guidance Note on Outsourcing</strong></summary>

This applies to *all* licensees (Investment, Fiduciary, Insurance, Banking) and sets the governance standard.

* **Due Diligence**: You must conduct (and document) technical due diligence *before* signing. For a SaaS provider.
* **Business Continuity (BCP)**: You must have a "Exit Plan." If Tiller (the SaaS) goes offline or goes bust, how do you continue to screen clients?
  * *Standard:* You must be able to switch to an alternative provider or revert to manual checks without significant disruption.
* **Data Sovereignty**: While Guernsey has no hard "data residency" law preventing data leaving the island (unlike some jurisdictions), you must ensure compliance with the Data Protection (Bailiwick of Guernsey) Law, 2017.
  * *Requirement:* The SaaS provider must host data in an "Adequacy" jurisdiction (e.g., UK, EU/EEA) or have Standard Contractual Clauses (SCCs) in place.

**How Tiller Satisfies This:**

* **Due Diligence**: Through this Trust Portal and the support provided by our own onboarding process we provide all the information you require to perform a detailed due diligence assessment on Tiller and its platform. We even provide a completed due diligence assessment form which you can download plus all the supporting documentation.
* **Contractual Terms**: Backed into our contractual terms are exit clauses which ensures you can evidence an exit plan should you need to switch to an alternative provider. All your data is available to you to download and extract via our API.
* **Data Sovereignty**: Your client data is hosted in Microsoft Azure data centres (based in Europe), ensuring alignment with GDPR and data sovereignty requirements. Tiller and it's [sub-processors](https://verify-doc.tiller-verify.com/training-hub/trust-centre/data-privacy#tiller-technologies-use-of-3rd-party-sub-processors) strictly manage and are transparent about how data is managed and were required to perform the function instructed by you, shared.  &#x20;

</details>

<details>

<summary><strong>The AML/CFT Handbook (Chapter 3: New Technologies)</strong></summary>

When a SaaS company is used for CDD, it is "New Technology."

* **Risk Assessment**: Regulation 3(3)(c) mandates a specific risk assessment to identify *"money laundering and terrorist financing risks"* arising from the technology.
  * *Example: Does the system allow for "spoofing"? Is the database update frequency sufficient?*
* **Board Approval**: This specific assessment must be discussed and approved by the Board.

**How Tiller Satisfies This:**

* **Up to Data Sources**: Verify by Tiller only uses regulatory quality data sources which are updated daily when performing its check. Our technology, such as the use of NFC chips and templated anti-tamper checks of id documentation ensures we meet the highest verification standards.
* **Extensive Information to support assessment**: Through this Trust Portal and the support provided by our own onboarding process we provide all the information you require to perform a detailed risk assessment on Tiller and its platform. We even provide a completed due diligence assessment form which you can download. &#x20;

</details>


# Isle of Man Financial Services Authority

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

In the Isle of Man’s premier financial ecosystem, compliance with the [Anti-Money Laundering and Countering the Financing of Terrorism Code 2019](https://legislation.gov.im/cms/images/LEGISLATION/SUBORDINATE/2019/2019-0202/2019-0202_1.pdf) and the [IOMFSA AML/CFT Handbook](https://www.iomfsa.im/amlcft/amlcft-requirements-and-guidance/) is not merely a legal requirement, it is the bedrock of your license to operate.

The Authority’s regulatory framework demands a demonstrable, risk-based approach to preventing financial crime, placing a heavy onus on firms to conduct rigorous Customer Due Diligence (CDD), maintain dynamic Business and Customer Risk Assessments, and perform relentless ongoing monitoring. For Boards and MLROs, the challenge lies in operationalising these complex statutory obligations to a forensic standard without stifling commercial activity or creating unmanageable administrative burdens.

We understand that firms regulated by the Isle of Man Financial Services Authority (IOMFSA) must carefully evaluate any third-party solution. The selection of an CDD and AML platform, such as Verify by Tiller, is subject to specific regulatory obligations. These include:

{% content-ref url="/pages/UKqZUlVQL1EubolunTnD" %}
[IOMFSA AML/CFT Handbook](/trust-centre/regulatory-compliance/isle-of-man-financial-services-authority/iomfsa-aml-cft-handbook)
{% endcontent-ref %}

As the regulated entity, you retain ultimate responsibility for compliance. However, we at Tiller are committed to providing you with the necessary information and support to help you meet your regulatory obligations.

***


# IOMFSA AML/CFT Handbook

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

**Tiller Technologies** understands the unique jurisdictional pressures as mandated in the IOMFSA AML/CFT Handbook. We designed **Verify by Tiller** to bridge the gap between the Handbook’s granular guidance and practical operational reality. By automating critical compliance workflows, from biometric identity verification and multi-jurisdictional screening to client report generation and perpetual monitoring, Verify provides a robust digital framework that aligns directly with the Isle of Man’s regulatory expectations. Our platform ensures that every relevant client lifecycle event is assessed, verified, and recorded with an immutable audit trail, empowering your firm to demonstrate definitive compliance and navigate regulatory scrutiny with confidence.

## Handbook Requirement Mapping

Below is a breakdown of how Tiller can help your company satisfy the Isle of Man Financial Services Authority AML/CFT Handbook requirements by category. It includes a detailed review of each regulation and how Verify by Tiller addresses it:

#### Risk-Based Approach (RBA) & Risk Assessments

The Code mandates that all AML/CFT procedures must be risk-based, requiring documented assessments of business, customer, and technology risks.

<details>

<summary><strong>Business Risk Assessment (BRA) [Code Para 5; Handbook 2.2.8]</strong></summary>

**Requirement:**

* Firms must estimate the ML/FT risk posed by their business and customers, considering factors like customer complexity, geography, and delivery channels.

**How Tiller Satisfies This:**

* Meeting the requirement to estimate ML/FT risk requires more than just checking boxes; it requires a accurate view of your portfolio. Verify by Tiller ensures your compliance data across all client entities is up to date, mapping high-risk factors such as jurisdictional exposure and PEP factors. This allows your firm to construct an accurate, cumulative risk profile, ensuring your Business Risk Assessment accurately reflects the reality of your customer base rather than a theoretical estimate.

</details>

<details>

<summary><strong>Customer Risk Assessment (CRA) [Code Para 6; Handbook 2.2.9]</strong></summary>

**Requirement:**

* A CRA must be undertaken *prior* to establishing a relationship. It must consider nature, scale, complexity, and location of the customer, and be recorded to demonstrate its basis.

**How Tiller Satisfies This:**

* Verify allows you to automatically capture, and verify all the information such as client inputs, screening results, and geographic data, required to accurately and effectively determine the risk profile of the client ensuring a consistent and documented CRA for every profile

</details>

<details>

<summary><strong>Technology Risk Assessment (TRA) [Code Para 7; Handbook 2.2.11]</strong></summary>

**Requirement:**

* Firms must assess ML/FT risks posed by any technology used, including digital ID systems, ensuring robustness and data security.

**How Tiller Satisfies This:**

* Verify acts as a risk-mitigating technology with robust security protocols, data encryption, and immutable audit trails, directly supporting the "robustness" and "data security" requirements of your TRA. The information to support this is available in the [Trust Components](https://verify-doc.tiller-verify.com/training-hub/trust-centre/welcome-to-trust-centre#trust-components) section of this Trust Site.&#x20;

</details>

<details>

<summary><strong>Technology Risk Assessment (TRA) [Code Para 7; Handbook 2.2.11]</strong></summary>

**Requirement:**

* You must ensure "business continuity" in the event of system failure.

**How Tiller Satisfies This:**

* SLA & Redundancy: Tiller operates with high-availability server redundancy and a documented Disaster Recovery Plan, ensuring minimal downtime and continuous access to your compliance data.
* Tiller targets a platform availability of 99.9% availability per month during business hours. We employ redundant systems and failover mechanisms to ensure availability. Real-time service status and historical uptime reports are available to clients upon request or via our status page.
* Our BCP (Client Product Services DR Plan) outlines contingency planning for the event of a loss of critical service from its Azure cloud hosting provider. For a standard DR situation involving a full failover of all Verify by Tiller services to its secondary data centre at Azure, which is hosted in a separate georedundant region, the target RTO is 24 hours (within 1 business day), and the target RPO is 4 hours. In all failover DR tests and simulated critical failure modes, Tiller achieved a significantly quicker RTO time.&#x20;

  For non-critical issues, not requiring failover to an alternate data centre there would little if any disruption to services.

</details>

#### Customer Due Diligence (CDD) & Identification

The core of AML compliance is knowing your customer through independent verification and identifying beneficial owners.

<details>

<summary><strong>Identification &#x26; Verification (ID&#x26;V) [Code Para 8; Handbook 3.2.1.2]</strong></summary>

**Requirement:**

* You must identify and verify the customer using reliable, independent source documents, data, or information.

**How Tiller Satisfies This:**

* **Electronic IDV (eIDV)**: Verify integrates with global data bureaus and biometric providers to perform real-time identity checks, verifying name, address, and date of birth against independent sources.
* **Global Document Forensics**: Our platform checks government-issued IDs against a global database of document templates, analysing security features (holograms, fonts, MRZ codes) to detect forgeries that the human eye might miss.

</details>

<details>

<summary><strong>Beneficial Ownership [Code Para 12; Handbook 3.4.5]</strong></summary>

**Requirement:**

* You must identify the beneficial owner (UBO) and take reasonable measures to verify their identity.

**How Tiller Satisfies This:**

* **UBO Unwrapping**: Although at this time, Verify cannot allow for the mapping of complex corporate structures, or recording UBO details (This is coming soon in our KYB module), Verify does enabling you to perform on the identified individuals the required screening and verification.

</details>

<details>

<summary><strong>Electronic Methods [Handbook 3.3.4.5]</strong></summary>

**Requirement:**

* When using electronic verification, firms must ensure the system is robust, secure, and protects against fraud (e.g., liveness checks).

**How Tiller Satisfies This:**

* **Biometric Liveness Detection**: Verify utilises advanced biometric matching (selfie-to-ID) with passive liveness detection certified to the highest **ISO 30107-3 iBeta Accreditation Level 2 PAD** standard, to prevent spoofing and impersonation fraud, satisfying the Handbook’s guidance on digital identity.

</details>

#### Screening: PEPs, Sanctions & Adverse Media

Screening is critical for identifying high-risk exposures and preventing financial crime.

<details>

<summary><strong>Sanctions Compliance [Code Para 4(1)(a)(ii); Handbook 3.3.8]</strong></summary>

**Requirement:**

* Procedures must determine whether a customer is on a sanctions list. Screening must be done at the outset and on an ongoing basis.

**How Tiller Satisfies This:**

* **Global Watchlist Screening:** Verify screens individuals and entities against all major global sanctions lists (UN, UK, EU, OFAC) in real-time, providing immediate alerts if a client is listed.

</details>

<details>

<summary><strong>Politically Exposed Persons (PEPs) [Code Para 14; Handbook 3.8.8]</strong></summary>

**Requirement:**

* Firms must determine if a customer or UBO is a PEP. This requires proactive steps like database screening.

**How Tiller Satisfies This:**

* **PEP Identification**: The platform screens against extensive global PEP databases, identifying not just the PEP but also close associates and family members (RCAs), enabling you to apply Enhanced Due Diligence (EDD) where required.

</details>

<details>

<summary><strong>Adverse Media (Reputation) [Code Para 15(5)(b); Handbook 2.2.9.2]</strong></summary>

**Requirement:**

* A customer subject to regulatory warnings or adverse media regarding criminality must be treated as higher risk.

**How Tiller Satisfies This:**

* **Negative News Screening**: Verify scans thousands of global news sources daily for adverse media, helping you identify reputational risks that standard identity checks might miss.

</details>

#### Enhanced Due Diligence (EDD) & High Risk

Higher risk relationships require additional measures and senior management approval.

<details>

<summary><strong>Enhanced Due Diligence (EDD) [Code Para 15; Handbook 3.4.7]</strong></summary>

**Requirement:**

* EDD is required for high-risk customers, including obtaining source of wealth (SoW) and senior management approval.

**How Tiller Satisfies This:**

* **Workflow Management (Custom Forms)**: Verify allows you to flag high-risk profiles for "Enhanced" review workflows, mandating the collection of additional documents (SoW evidence) ensuring all additional information is captured and reviewed for Senior Management approval.&#x20;

</details>

<details>

<summary><strong>Source of Wealth (SoW) [Code Para 8/15; Handbook 3.8.5]</strong></summary>

**Requirement:**

* For high-risk relationships, you must take reasonable measures to establish the source of wealth.

**How Tiller Satisfies This:**

* **Document Repository**: The platform provides a secure repository to upload and categorise SoW evidence (e.g., property sales, dividend statements), linking them directly to the client profile for audit purposes.

</details>

#### Ongoing Monitoring

Compliance is not a one-time event; it is a continuous lifecycle.

<details>

<summary><strong>Ongoing Monitoring [Code Para 13; Handbook 3.4.6]</strong></summary>

**Requirement:**

* Firms must perform ongoing monitoring of the business relationship, including scrutiny of transactions and ensuring CDD documents are up to date.

**How Tiller Satisfies This:**

* **Perpetual KYC (pKYC)**: Verify supports daily automated re-screening of your client base. If a client is added to a sanctions list or becomes a PEP post-onboarding, the system triggers an immediate alert for remediation.

</details>

<details>

<summary><strong>Review of Information [Code Para 13(1)(a); Handbook 3.4.6.1]</strong></summary>

**Requirement:**

* Documents must be kept up-to-date and accurate, particularly for higher risk relationships.

**How Tiller Satisfies This:**

* **Expiry Management**: The platform tracks document expiry dates (e.g., passports) and can trigger notifications when updated CDD is required, ensuring your files never become stale.

</details>

#### Outsourcing & Third-Party Reliability

<details>

<summary><strong>Ultimate responsibility [Code Para 4(3)]</strong></summary>

**Requirement:**

* Ultimate responsibility remains with the relevant person. You must retain decision-making powers.

**How Tiller Satisfies This:**

* **Decision Engine**: Verify is a *tool* to support your decision, not a replacement. You configure what to check and what not to check and the thresholds to apply. The platform flags findings (e.g., "PEP Match") and give the information needed to help make a decision, but your compliance team makes the final "Approve/Reject" decision within the portal.

</details>

<details>

<summary><strong>Supplier maturity and geographic risks [Handbook 2.2.11.2]</strong></summary>

**Requirement:**

* You must consider "supplier maturity" and "geographic risks" of the vendor.

**How Tiller Satisfies This:**

* **Decision Engine**: UK/IoM Centric: Tiller Technologies is a mature, Jersey-based technology provider. We host data in secure, compliant jurisdictions within the EU that align with Isle of Man "adequacy" standards for data protection.

</details>

#### Record Keeping & Audit Trails

The ability to reconstruct the CDD process for regulators is mandatory.

<details>

<summary><strong>Record Keeping [Code Para 33; Handbook 6.4]</strong></summary>

**Requirement:**

* Firms must keep copies of all CDD documents, risk assessments, and results of analysis for at least 5 years.

**How Tiller Satisfies This:**

* **Client Report**: Verify generates a time-stamped, immutable client report of all information captured, screening results, actions taken, documents uploaded, and user approvals, ensuring you are always "audit-ready" for the IOMFSA.&#x20;

</details>

<details>

<summary><strong>Retrieval of Records [Code Para 34; Handbook 6.4]</strong></summary>

**Requirement:**

* Records must be retrievable within a reasonable timeframe to satisfy competent authority enquiries.

**How Tiller Satisfies This:**

* **Instant Retrieval:** All client profiles and associated history are stored digitally allowing you to either manually download and index the in the client file or automatically via the APi inject them into your CRM and/or document storage system. All the information is then instantly ready for regulatory inspections or internal audits.

</details>

***

## The IOMFSA Handbook and Verify by Tiller: FAQ

<details>

<summary>Does using Verify by Tiller satisfy the IOMFSA requirement for a Customer Risk Assessment (CRA)?</summary>

Under Paragraph 6(1) of the Code, a relevant person *must* carry out an assessment that estimates the ML/FT/PF risk posed by the customer. This is not optional; it must be undertaken *prior* to the establishment of a business relationship. The Handbook emphasizes that the CRA allows you to determine the extent of CDD to apply and whether enhanced measures are necessary. It must consider specific risk factors, including the nature, scale, complexity, and location of the customer’s activities.

**How Verify by Tiller Addresses This**:

* Verify allows you to configure a digital risk assessment model that mirrors your firm’s specific risk appetite. Tou can map your risk factors, such as country risk, client PEP status etc. Verify automates the collection of the information and its verification for every client. This ensures that every CRA is recorded and consistently applied, providing the "demonstrable basis" for your risk rating required by the Code.

</details>

<details>

<summary>Can I rely solely on Verify for "meeting" the customer?</summary>

The Code lists "circumstances in which the relevant persons and the customer have not met" as a risk factor that *may* pose a higher risk. However, the Handbook clarifies that in the digital age, "being physically present is not necessarily the only method of meeting a customer". The Handbook allows for the use of electronic methods if the system is sufficiently robust, secure, and protects against fraud.

**How Verify by Tiller Addresses This**:

* Verify utilizes advanced biometric electronic verification (eIDV). It captures a live video or "selfie" of the customer and matches it biometrically to the photograph on their government-issued ID. This process includes passive liveness detection certified to the highest **ISO 30107-3 iBeta Accreditation Level 2 PAD** standard to prevent "spoofing" (e.g., holding up a photo or using a deepfake), aligning with Handbook guidance on using technology to mitigate the risks of non-face-to-face identification.

</details>

<details>

<summary>How often does Verify screen for Sanctions?</summary>

Paragraph 13(1)(c) of the Code mandates that firms must perform ongoing monitoring to determine whether a customer is listed on a sanctions list. The Handbook explicitly warns that "periodic or trigger event customer reviews may not be adequate to detect such listings in a timely manner". You must ensure you do not breach sanctions requirements by dealing with a listed entity.

**How Verify by Tiller Addresses This**:

* Verify is configured for daily automated ongoing monitoring. It screens your entire client base against the latest UN, UK (OFSI), EU, and OFAC sanctions lists every 24 hours. If a client is added to a list, the system generates an immediate alert for your compliance team to investigate, ensuring you meet the requirement to detect listings in a "timely manner".

</details>

<details>

<summary>Does the platform handle the "Source of Wealth" requirement?</summary>

For high-risk customers, Paragraph 15(2)(c) of the Code requires you to take reasonable measures to establish the customer's Source of Wealth (SoW). The Handbook distinguishes SoW from Source of Funds; SoW refers to the origin of the customer's *entire* body of wealth. Failing to gather this information for high-risk clients is a direct breach of the Code.

**How Verify by Tiller Addresses This**:

* Verify provides a structured workflow for Enhanced Due Diligence (EDD). It allows you to mandatorily request SoW declarations and supporting evidence (e.g., property sale contracts, probate documents, audited accounts) for high-risk profiles. These documents are securely stored against the client record, creating an audit trail that demonstrates you have taken "reasonable measures" to establish SoW.

</details>

<details>

<summary>What happens if Verify identifies a PEP?</summary>

Paragraph 14 of the Code requires you to have procedures to determine if a customer is a Politically Exposed Person (PEP). If a customer is a foreign PEP (or a higher-risk domestic PEP), you *must* obtain Senior Management approval to continue the relationship and perform enhanced ongoing monitoring.

**How Verify by Tiller Addresses This**:

* Verify screens against global PEP databases (including relatives and close associates). If a match is found, the profile is flagged. The platform's workflow ensures the flagged match is reviewed and either confirmed or rejected as a false positive with supporting notes. Your procedures can therefore enforce "Senior Management approval" requirement and creating an immutable record of that decision.

</details>

<details>

<summary>Can Verify help with the "Technology Risk Assessment" (TRA)?</summary>

Paragraph 7 of the Code requires all relevant persons to carry out a TRA to estimate the ML/FT risks posed by *any* technology used in their business. The Handbook notes that while technology can improve efficiency, it can also weaken measures if applied without understanding. You must assess the robustness of the technology and its ability to withstand cyber-attacks.

**How Verify by Tiller Addresses This**:

* Verify supports your TRA by providing full details of all the components required to verify the platforms suitability (including [Information Security](/trust-centre/trust-components/information-security), [Data Protection](/trust-centre/trust-components/data-protection), [Cloud & Reliability](/trust-centre/trust-components/cloud-and-reliability), and [Risk & Compliance policies and procedures](/trust-centre/trust-components/risk-and-compliance)). Tiller also provides a full [Due Diligence Pack](/trust-centre/trust-centre/due-diligence-pack) including a completed Due Diligence Questionnaire for you to use. We provide detailed documentation on our policies and procedures to help you complete your  your TRA. Using a reputable third-party provider like Verify can mitigate the risks associated with "home-grown" or unmaintained technology solutions or providers which are not familiar with the Isle of Man's particular needs.

</details>

<details>

<summary>Is Verify compliant with IOM Data Protection requirements?</summary>

The Handbook states that relevant persons must comply with AML/CFT requirements having regard to their obligations under data protection legislation (GDPR as applied in IoM). Specifically, the TRA must consider the adequacy of controls to ensure compliance with data protection and privacy.

**How Verify by Tiller Addresses This**:

* Verify is built with Privacy by Design principles. It ensures data is stored securely, encrypted at rest and in transit, and allows for the granular management of the data held. Tiller's data protection obligations in respect of Isle of Man clients are governed primarily by the Isle of Man's Data Protection (Application of GDPR) Order 2018 (including its "Adequacy" Update (2024) and Amendment to Regulations 2025 (SD 2025/0115)) and the Isle of Man's Data Protection Act 2018 (DPA 2018), together with the Data Protection (Jersey) Law 2018 (DPJL) as the law governing Tiller's own operations as a Jersey company. These frameworks are built on the same core data protection principles set out in our Privacy and Personal Data Protection Policy. Where Tiller processes personal data of individuals in the EU/EEA, the EU General Data Protection Regulation (EU) 2016/679 also applies under its extraterritorial scope (Article 3(2)). These legal frameworks guide every aspect of our data handling, from collection and processing to storage and disclosure, ensuring the highest standards of data integrity and confidentiality.

</details>

<details>

<summary>Does the platform support "Certified Copies" of documents?</summary>

While electronic verification is encouraged, the Handbook still permits the use of hard copy documents. However, these must be certified by a "suitable certifier" to establish their reliability. The Handbook requires you to assess the reliability of the certifier and ensure the copy is of good quality.

**How Verify by Tiller Addresses This**:

* Verify allows for the upload and storage of traditional certified documents alongside electronic checks. You can upload the certified copy and tag the document type. This supports a "hybrid" approach where you may use eIDV for some clients and manual certification for others, keeping all records in one central digital repository. The responsibility however is on the client to ensure the uploaded certified copy is genuine and acceptable.

</details>

<details>

<summary>Can I use Verify for "Simplified Due Diligence" (SDD)?</summary>

The Code provides for exemptions and simplified measures (often called SDD) in lower-risk scenarios, such as listed companies or certain collective investment schemes. However, the Handbook explicitly states that "simplified measures must be risk sensitive" and you must keep a record of what concessions are used.

**How Verify by Tiller Addresses This**:

* Verify allows you to configure dynamic workflows. If your initial risk assessment scores a client as "Low Risk" (e.g., a PLC), you can use a simplified workflow that requests fewer documents or performs lighter-touch verification, consistent with the Code's concessions. Crucially, it records *why* SDD was applied, satisfying the audit trail requirement. If your initial risk assessment scores a client as a higher risk, you can use a more complicated workflow that requests more information and supporting documents and performs more verifications.

</details>

<details>

<summary>How does Verify handle "Adverse Media"?</summary>

Paragraph 15(5)(b) of the Code states that a customer subject to a "warning in relation to AML/CFT matters" is a matter posing a higher risk. The Handbook advises that you should consider "adverse media reports" or "reliable and credible allegations of criminality" as part of the customer's reputation profile.

**How Verify by Tiller Addresses This**:

* Verify integrates negative news screening into the onboarding process. It scans thousands of global news sources for adverse media regarding your client. If a "hit" is found (e.g., allegations of fraud or corruption), it is presented to the compliance officer for review. This enables you to factor reputational risk into your CRA, even if the client has no criminal conviction.

</details>

<details>

<summary>Does Verify replace the need for an MLRO?</summary>

Paragraph 23 of the Code requires the appointment of a Money Laundering Reporting Officer (MLRO) who must be sufficiently senior and have authority. The Handbook clarifies that while you can use technology, "it is not possible to outsource responsibility for compliance". The MLRO must retain responsibility for external disclosures.

**How Verify by Tiller Addresses This**:

* **No**. Verify is a *tool* to assist the MLRO and your onboarding team, not a replacement. It empowers the MLRO by providing organized data, automated alerts, and comprehensive reports. It frees up the MLRO and onboarding team from manual administrative tasks so they can focus on the high-value judgement calls—such as reviewing suspicious activity and submitting SARs—which are duties that cannot be delegated.

</details>

<details>

<summary>How long does Verify keep my records?</summary>

Paragraph 33 of the Code requires relevant persons to keep copies of all CDD documents and risk assessments. Paragraph 34 mandates that these records must be retained for at least 5 years from the end of the business relationship or the date of the occasional transaction. Records must be retrievable within a reasonable timeframe.

**How Verify by Tiller Addresses This**:

* Verify retains all client data, documents, check findings, and documents in a secure digital archive for you to download from manually or using API's inject directly into your existing CRM or Document Storage System for permanent or long term storage. The duration of data retention within Verify is set by the retention policy settings. Verify is not designed to be your permanent archive. This ensures you are not "locked In" to using Verify and retain you required data independence.

</details>

<details>

<summary>Can Verify help with "De-risking"?</summary>

"De-risking" is the termination of relationships to avoid risk rather than managing it. The Handbook encourages firms to avoid wholesale de-risking and instead apply a risk-based approach to manage risks on a "case-by-case basis". De-risking can increase financial exclusion and drive funds underground

**How Verify by Tiller Addresses This**:

* Verify provides granular risk data. Instead of a binary "yes/no" to a client, Verify allows you to see *specifically* where the risk lies (e.g., a specific high-risk jurisdiction or a specific adverse media article). This allows you to apply targeted Enhanced Due Diligence (EDD) to *manage* that specific risk rather than simply exiting the relationship, aligning with the Handbook’s guidance to avoid unnecessary de-risking.

</details>

<details>

<summary>Does the platform generate Suspicious Activity Reports (SARs)?</summary>

Paragraph 27 of the Code requires the MLRO to make an external disclosure (SAR) to the Financial Intelligence Unit (FIU) if they know or suspect ML/FT. This must be done via "Themis," the IOMFIU’s secure online reporting system.

**How Verify by Tiller Addresses This**:

* Verify does not submit SARs to the FIU (only the MLRO can do this via Themis). However, Verify facilitates the *Internal Disclosure* process required by Paragraph 26. Staff can flag suspicious findings found by Verify and alert the MLRO. The platform then provides the MLRO with all the necessary CDD data required to populate the SAR on Themis effectively.

</details>

<details>

<summary>Is Verify suitable for "Designated Businesses" (DNFBPs)?</summary>

The Handbook applies not just to financial institutions but also to "Designated Businesses" under the *Designated Businesses (Registration and Oversight) Act 2015*. This includes accountants, estate agents, tax advisers, and others. These businesses have the same requirement to conduct risk assessments and CDD.

**How Verify by Tiller Addresses This**:

* Yes. Verify’s flexible workflow engine is ideal for Designated Businesses. Whether you are an estate agent needing to screen a buyer or an accountant performing KYC on a director, the platform can be scaled to fit. It supports specific data capture requirements by allowing you to tailor custom forms specific to the nature of the service you provide.

</details>


# Bermuda Proceeds of Crime Regulations & BMA Guidance

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

Regulated entities in Bermuda operate within a rigorous framework governed by the Proceeds of Crime Regulations 2008 (POCR) and the 2023 BMA Guidance Notes. Achieving compliance requires a precise balance: satisfying the supervisory standards of the Bermuda Monetary Authority (BMA) and the reporting mandates of the Financial Intelligence Agency (FIA), while strictly adhering to the Personal Information Protection Act (PIPA) under the oversight of the Privacy Commissioner.

For Bermuda firms, selecting a RegTech partner is a material compliance decision. Verify by Tiller is engineered to navigate these complexities, offering an automated CDD and AML solution designed to meet Bermuda’s specific regulatory requirements for electronic verification, data sovereignty, and third-party outsourcing.

To support you Tiller has supplied the following information:

{% content-ref url="/pages/6s8trWVgPI8Mt68Ud5Sk" %}
[Monetary Authority & Regulatory Framework](/trust-centre/regulatory-compliance/bermuda-proceeds-of-crime-regulations-and-bma-guidance/monetary-authority-and-regulatory-framework)
{% endcontent-ref %}

{% content-ref url="/pages/H9ItLX2aeum0dDHrG5zY" %}
[Managing Technology & Outsourced Providers](/trust-centre/regulatory-compliance/bermuda-proceeds-of-crime-regulations-and-bma-guidance/managing-technology-and-outsourced-providers)
{% endcontent-ref %}

As the regulated entity, you retain ultimate responsibility for compliance. However, we at Tiller are committed to providing you with the necessary information and support to help you meet your regulatory obligations.

***


# Monetary Authority & Regulatory Framework

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

The Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 (POCR) form the statutory backbone of the compliance framework. For regulated entities in Bermuda, you are not merely required to "collect information and documents"; you are legally obligated to know your clients and maintain an active, risk-sensitive defence against financial crime.

We developed our Verify by Tiller platform to provide regulated companies with the necessary ability to capture, verify and assess the information needed to meet your legal obligations.

## Core Statutory Obligations (POCR 2008)

The POCR imposes five "Pillars of Compliance" that are non-negotiable. Failure to evidence any of these is a breach of the Regulations. How does Verify by Tiller help you meeting those obligations:

<details>

<summary>The Business Risk Assessment (Regulation 16)</summary>

You cannot treat all clients equally. You must perform a comprehensive Business Risk Assessment (BRA) to identify where your specific business is vulnerable to money laundering.

* **Requirement:** you must document your inherent risks (Geographic, Product, Customer, Delivery Channel) and assess the effectiveness of you controls to determine our *residual risk*
* **Support**: Verify by Tiller allows you to put in place a robust, effective and repeatable customer onboarding process. The digital onboarding process provided by Verify by Tiller allows you to understand and control your risk exposure and easily document and manage that risk&#x20;

</details>

<details>

<summary>Customer Due Diligence (CDD) (Regulations 5–9)</summary>

You must verify the identity of your customers *before* a business relationship is established.

* **Requirement:** Identify the identity of customers and understand *who* you are dealing with and the *nature* of the business they intend to conduct.
* **Screening**: Verify by Tiller performs comprehensive screening against international sanction lists, PEP databases, enforcement databases and adverse Media sources, helping you build an accurate risk profile for your client
* **Ongoing Monitoring**: CDD is not a one-off event. You must monitor your client's behaviour throughout the relationship to ensure they match the client profile establish during onboarding. Verify will rescreen all your clients daily and provide the tools to automatically perform periodic reviews and update expired documentation.

</details>

<details>

<summary>Enhanced Due Diligence (EDD) (Regulation 11)</summary>

For high-risk scenarios, standard checks are insufficient.

* **Requirement**: For Politically Exposed Persons (PEPs), clients from "High-Risk Third Countries," or complex/unusual activities, you must establish their Source of Wealth (SoW), verifying how the client acquired their total net worth, not just the funds in the current transaction.
* **Solution**: Verify by Tiller will help you identify high-risk scenarios by capturing and verifying country of residence and even geolocation of the individual. It will also fully screen them to identify PEPs from an array of global sources or individuals with adverse media indicating a high-risk profile. The platform also provides customisable digital client forms to aid in the capture of Source of Wealth information and also the upload of required supporting documentary evidence by the client. This allows you to quickly and efficiently perform the more complex checks and record keeping required for EDD.

</details>

<details>

<summary>Record Keeping (Regulation 15) </summary>

The regulation imposes a strict statutory duty to retain documents for a specific period to ensure they are available for use in any financial crime investigation.

* **Requirement**: All CDD documents, risk assessments, and transaction records must be retrievable without delay and must be kept for 5 years.
* **Support**: Verify by Tiller generates a comprehensive Client Report in PDF format at the end of the onboarding. It contains all information captured during the onboarding including identity documents and selfie images used to verify the person resenting the id document. It also contains the results of all checks performed and the findings as well as the actions taken in response to those findings. This report is clear evidence of the compliance process followed, and it allows you to easily store it for immediate retrieval at any time in the future. The same information can be easily exported via our AOI for inclusion into any of your existing systems to automatically aid in the centralisation of all your records

</details>

<details>

<summary>Internal Controls &#x26; Reporting (Regulation 16–18)</summary>

* **Requirement**: Your MLRO[^1] must establish a process to receive internal suspicious activity reports (SARs) and, where appropriate, file them with the **Financial Intelligence Agency (FIA)**.
* **Support:** The Verify by Tiller platform make it significantly easier for your MLRO to be made aware of exceptions during the onboarding process or arising out of ongoing monitoring. It provides all the evidence derived from the information provided by the client and the check and findings that were automatically performed. This makes it easier to collate the supporting information for the SARs report and providing the audit history which may be needed for any follow-up activities.&#x20;

</details>

***

### Other Typical Questions

**Section 1: Customer Due Diligence (Regs 5, 6 & 8)**

<details>

<summary>Regulation 6(2) requires verification using data from a "reliable and independent source." Does a digital solution satisfy this legal standard?</summary>

Yes, provided the source is authoritative. Verify by Tiller satisfies Regulation 6(2) by prioritizing NFC chip extraction from e-Passports. This data is cryptographically signed by the issuing government, making it the most "independent" and "reliable" source available, far exceeding the evidentiary value of a photocopied passport delivered by email.

</details>

<details>

<summary>Regulation 8 mandates verifying identity <em>before</em> the business relationship is established. How does Tiller ensure we don't accidentally onboard someone too early?</summary>

POCR imposes a strict chronological order. Verify by Tiller enforces this via "Referal Alerts" in the workflow. You can configure your process so that a client account cannot be opened (or a risk rating finalized) until the ID verification and screening steps are marked as "Complete" or "Accepted". This prevents the operational error of trading with an unverified entity, which is a direct breach of Regulation 8.

</details>

<details>

<summary>We have a lot of non-face-to-face clients. Does POCR Regulation 11 require us to treat them all as high risk?</summary>

Historically, yes, but modern technology mitigates this. While Regulation 11(1)(a) requires EDD where the customer is not physically present, Verify by Tiller uses biometric liveness detection to replicate the security of a face-to-face meeting. This allows you to justify treating standard non-face-to-face applicants as "Standard Risk" rather than "High Risk" in your Business Risk Assessment.

</details>

<details>

<summary>Regulation 5 requires us to identify the "Beneficial Owner." Can Tiller handle complex corporate structures?</summary>

Although at present Verify by Tiller cannot identify the Beneficial Owner behind a complex corporate structure (however the feature is coming soon in our KYB module), Verify can send individual digital verification links to each UBO already known (e.g., shareholders >10% or 25%), ensuring every controlling individual is verified to the same standard as a retail client.

</details>

**Section 2: Enhanced Due Diligence & PEPs (Reg 11)**

<details>

<summary>Regulation 11(4) imposes specific duties regarding Politically Exposed Persons (PEPs). How does Tiller prevent us from missing a PEP?</summary>

The regulation requires "risk management procedures" to determine if a customer is a PEP. Verify by Tiller screens every applicant against global PEP lists (Tier 1-4) automatically. If a match is found, the system flags the profile for manual review. This ensures you never inadvertently onboard a PEP without the "Senior Management Approval" mandated by law.

</details>

<details>

<summary>POCR requires us to take "adequate measures" to establish Source of Wealth (SoW) for PEPs. How does the platform support this?</summary>

For high-risk or PEP clients, Verify by Tiller allows the use of custom digital forms to capture "Source of Wealth" in the onboarding journey. It compels the user to declare the origin of their funds and upload supporting evidence (e.g., sale of shares, inheritance letters) before the application can proceed, ensuring you have the evidence required by Regulation 11(4)(b).

</details>

<details>

<summary>Regulation 11 requires EDD for "complex or unusually large transactions." Can Tiller help if we only use it for onboarding?</summary>

While Tiller is an onboarding tool, it sets the baseline for this monitoring. By establishing a robust "Client Profile" (expected activity, turnover, source of funds) at the start, Verify by Tiller provides the benchmark against which your transaction monitoring team can judge if a future transaction is "unusual," as required by Regulation 11(2).

</details>

**Section 3: Ongoing Monitoring (Reg 12)**

<details>

<summary>Regulation 12(1)(b) requires that documents and data be kept "up to date and relevant." Does Tiller automate this?</summary>

Yes. Manual files often go stale. Verify by Tiller has a "expiry management" feature. It tracks the expiry dates of passports or ID cards and can automatically prompt the customer (or your team) to provide a new document before the old one expires, ensuring you remain compliant with Regulation 12 continuously.

</details>

<details>

<summary>Regulation 12A enforces strict compliance with International Sanctions. How often does Tiller screen?</summary>

To meet the strict liability of Sanctions laws, Verify by Tiller performs Daily Delta Screening. It can re-screens your entire client base every 24 hours against the latest UK Consolidated List and over 100 other sanction lists and information sourced from over 1,600 official government websites. This ensures that if a client is designated overnight, you know about it immediately, satisfying the requirement to stop dealing with them.

</details>

<details>

<summary>If a client's risk profile changes (e.g., they become a PEP later), does Tiller notify us?</summary>

Yes. This is a critical component of Regulation 12 "Ongoing Monitoring." Because Tiller re-screens daily, if an existing client is elected to office or appears in adverse media, the system generates an alert. This allows you to move the client from "Standard" to "High Risk" and apply the necessary EDD retroactively.

</details>

**Section 4: Record Keeping (Reg 15)**

<details>

<summary>Regulation 15(3) requires records to be "retrievable without undue delay." Can Tiller help with a BMA request?</summary>

Absolutely. Digging through paper files or disparate drives causes delays. Verify by Tiller consolidates all ID data, screening results, and risk decisions into a single digital profile. You can export a "Client Report" in seconds, satisfying the "without undue delay" requirement during an FIA investigation or BMA audit. The same information is also made available instantly via our API to any of your other systems

</details>

<details>

<summary>Regulation 15(1) mandates a 5-year retention period. What happens if we delete the app?</summary>

Your data obligations persist. Verify by Tiller allows for the secure export/archiving of data to your own servers to meet the 5-year rule post-relationship. The same information is also made available via our API to allow all data to be archived in your core systems.

</details>

**Section 5: Systems, Controls & Risk Assessment (Reg 16)**

<details>

<summary>Regulation 16 requires us to establish "policies and procedures" for risk assessment. Does Tiller dictate our risk policy?</summary>

No, Regulation 16 says *you* must establish the policy. Verify by Tiller is the *engine* that executes it. The platform is configurable, allowing you to map your specific Risk Appetite Statement (e.g., "We need to capture SoW[^2]") into the workflow logic, ensuring your operational reality matches your written manual.

</details>

<details>

<summary>Regulation 17 covers "Reliance" on third parties. Is using Tiller considered "Reliance"?</summary>

No, using Tiller is Outsourcing, not Reliance (which refers to relying on another *regulated* firm like a bank). Under POCR, you retain responsibility. Verify by Tiller supports this by giving you full visibility and control. It doesn't make the decision for you; it presents the data (matches, ID validity) so your Compliance Officer can make the final decision, keeping you on the right side of the law.

</details>

<details>

<summary>Regulation 18 requires employee training. Does Tiller help with staff competence?</summary>

Indirectly, yes. Regulation 18 requires staff to be aware of the laws and procedures. Verify by Tiller helps you standardizes your procedures. By guiding staff through a mandatory, linear workflow (Upload > Screen > Review > Approve), it ensures that even junior staff follow the correct compliant process every time, reducing the risk of human error or "shortcut taking."

</details>

[^1]: Money Laundering Reporting Officer

[^2]: Source of Wealth


# Managing Technology & Outsourced Providers

{% hint style="info" %}
**The information provided here is for general informational purposes only and is not intended to constitute legal or professional advice. It is provided 'as is' and should not be considered a substitute for a comprehensive review against the relevant laws and regulations as they apply to your company.**
{% endhint %}

## Bermuda Monetary Authority (BMA) Guidance Notes 2023

As companies in Bermuda increasingly rely on RegTech outsource providers for automated screening and E-ID verification tools, we understand that it puts you under the scrutiny from the BMA to ensure those outsource providers are fit for purpose.

The 2023 Guidance Notes (specifically Chapter 4 on Customer Due Diligence and the Outsourcing Guidance) place strict liability on regulated companies when using RegTech. The use of services like Verify by Tiller is considered outsourcing and therefore, we understand all the requirements set out in the BMA Guidance Notes 2023 that you must ensure we meet or exceed.&#x20;

### Outsourcing Assessment

To assist you with your outsourcing assessment, Tiller has provided a concise response to the relevant parts of the Guidance Notes:

<details>

<summary><strong>Electronic Verification &#x26; Independent Data</strong> (Chapter 4, Section 4.26)</summary>

The BMA stipulates that when verifying identity electronically, you must rely on "**reliable, independent source documents, data, or information.**" You are explicitly prohibited from relying on simple copies or data provided solely by the customer without independent validation.

**How Verify by Tiller Exceeds This:**

* **NFC Chip Authentication**: Tiller does not just "look" at a photo of a passport (which can be Photoshopped). It uses Near Field Communication (NFC) to cryptographically unlock the biometric chip inside the e-Passport. This gives you access to the verified and unchangeable document information including the original digital image of the individual.
  * ***Compliance Value**:* This accesses the data source of origin (the issuing government), meeting the highest standard of "independence" under the Guidance Notes.
* **Document Verification**: Verify by Tiller can validate over 3000 types of identity documents issued from over 180 different countries to check for authenticity and tampering. This satisfies the requirement for "verification" of presented forms of identification.
* **Residential Address Verification**: Verify by Tiller can validate residential addresses in 50 different countries using electoral rolls, credit bureaus or utility company sources. This satisfies the requirement for "multi-source independent verification" of key information.

</details>

<details>

<summary><strong>Digital ID &#x26; Liveness Detection</strong> (Chapter 4 - Alignment with FATF Digital ID Guidance)</summary>

The Guidance accepts non-face-to-face onboarding only if the process can mitigate the risk of impersonation. You must ensure the person presenting the ID is the person to whom it belongs (i.e., you must prevent "spoofing" with AI, static photos or video recordings).

**How Verify by Tiller Exceeds This:**

* **Biometric Liveness Checks**: Tiller utilizes advanced passive liveness detection and analysis to confirm the user is a live human being and not a screen, mask, or deepfake. The system is ISO/IEC 30107-3 Level 2 (Presentation Attack Detection) certified by the iBeta Quality Assurance testing body.
* **1:1 Facial Matching**: The platform algorithmically compares the "Live" selfie against the "Trusted" high-resolution image extracted from the government ID chip when available or from the surface of the verified document.
  * ***Compliance Value**:* This provides a mathematical match score, removing the subjectivity of human review and providing the "audit trail of decision making" required by the BMA.

</details>

<details>

<summary><strong>The Risk-Based Approach</strong> (Chapter 4, Section 4.59 - Enhanced Due Diligence)</summary>

The BMA mandates that CDD cannot be "one size fits all." You must apply **Enhanced Due Diligence (EDD)** to higher-risk clients (e.g., non-residents, PEPs). A system that runs the same check on everyone is non-compliant.

**How Verify by Tiller Exceeds This:**

* **Configurable Workflows**: Tiller allows us to build distinct "Risk Journeys." We can configure a "Low Risk" journey where applicable and a separate "High Risk" journey for example additional proof of address or Source of Funds prompts are required.
  * ***Compliance Value**:* This demonstrates to the regulator that you are actively applying the **Risk-Based Approach** at the point of onboarding, rather than as an afterthought.

</details>

<details>

<summary><strong>Outsourcing &#x26; Governance</strong> (BMA Outsourcing Guidance Notes / POCR Regulation 19)</summary>

When outsourcing a "Material Function" (like KYC), you must retain ultimate responsibility. You must have "unrestricted access" to the data and ensure the vendor meets our security standards.

**How Verify by Tiller Exceeds This:**

* **Highest Security Standards**: Tiller meets or exceeds industry standards for information security. All the information to evidence this is available in our [Trust Centre security documentation](/trust-centre/trust-components/information-security) which is freely available to you for review as part of your "Vendor Due Diligence".
* **Data Sovereignty & Portability**: The platform allows for the export of fully compiled "KYC Client Report" as a PDF document including all information and images captured and the results of screening and validation checks. Any additional documents uploaded by the customer can also be downloaded. In addition, all this information in also available via our API for digital retrieval and injection into your CRM[^1] platform or other systems.
  * ***Compliance Value**:* If you ever leave Tiller, you retain the data. This prevents "Vendor Lock-in" risks, which is a key concern in the BMA’s Operational Resilience consultation.
* **Audit Trail**: Every action (document upload, verification check, or approval click) is recorded and tracked. This allows the MLRO to reconstruct the entire onboarding event at any time later during an audit.

</details>

<details>

<summary><strong>Ongoing Monitoring of Sanctions &#x26; PEPs</strong> (Chapter 9 / Regulation 12)</summary>

Screening is not a one-off event. You must screen your customer base daily against updates to the UK Consolidated List (Sanctions) and changes in PEP status.

**How Verify by Tiller Exceeds This:**

* **Daily "Delta" Screening**: Tiller can automatically re-screens your entire book of business every night. We screen against not just the UK Consolidated List (Sanctions) but against hundreds of sanction lists, PEP data sources, and enforcement data sources along with Adverse Media if required.
* **False Positive Reduction**: The system uses "fuzzy logic" which we can tune to match your match confidence level to filter out irrelevant noise.
  * ***Compliance Value**:* This ensures you exceed the strict liability standard of the **International Sanctions Regulations 2013** without needing to hire an army of analysts to manually check names every morning.

</details>

### Other Typical Questions

**Category 1: Electronic Identification (E-ID) & Verification**

<details>

<summary>The BMA Guidance Notes (Chapter 4) state we must use "reliable, independent source documents." How does Tiller meet this without seeing the physical passport?</summary>

The BMA requires that data comes from a source that cannot be easily forged. Verify by Tiller uses NFC (Near Field Communication) technology to access the cryptographic chip embedded in e-Passports. This data is digitally signed by the issuing government (the "Country Signing Certificate Authority"). By validating this digital signature, Tiller accesses the most independent and reliable source possible—the government itself—exceeding the reliability of a human looking at a physical page.

</details>

<details>

<summary>We are concerned about "spoofing" in non-face-to-face onboarding. What does the BMA require regarding "Liveness"?</summary>

The 2023 Guidance aligns with FATF standards, requiring mechanisms to ensure the person is "live" and not using a presentation attack (masks, photos of screens). Verify by Tiller utilizes advanced biometric liveness detection. Its passive liveness detection and analysis of micro-movements confirm they are a live human and not a screen, mask, or deepfake at the moment of capture, directly satisfying the BMA’s anti-impersonation requirements. The system is ISO/IEC 30107-3 Level 2 (Presentation Attack Detection) certified by the iBeta Quality Assurance testing body.

</details>

<details>

<summary>Can we rely on Tiller’s results, or do we still need to collect "Certified Copies" of documents?</summary>

Under the 2023 Guidance, if an E-ID system meets the criteria for independence and security (which Tiller does via NFC and Biometrics), it effectively replaces the need for traditional "Certified Copies" for standard risk clients. Tiller creates a digital audit trail that serves as the "certification" of the data's authenticity, streamlining the customer experience without compromising regulatory standards.

</details>

**Category 2: Screening (Sanctions, PEPs, Adverse Media)**

<details>

<summary>The BMA requires us to screen against the UK Consolidated List. Which lists does Tiller check?</summary>

Verify by Tiller aggregates data from major global watchlists, including the UK OFSI Consolidated List (mandatory in Bermuda), the UN Security Council list, EU lists, and US OFAC lists. This ensures that a Bermuda entity is compliant with both local Overseas Territories Orders and international best practices.

</details>

<details>

<summary>How does Tiller handle the "Ongoing Monitoring" requirement (Chapter 9) for Sanctions?</summary>

A one-time check at onboarding is insufficient. Verify by Tiller performs automated daily monitoring (delta screening). If a client you onboarded three years ago is added to a sanctions list tonight, Tiller will flag this alert the next morning, allowing your MLRO to freeze assets immediately and report to the Financial Intelligence Agency (FIA) as required by law.

</details>

<details>

<summary>Does Tiller help us distinguish between a "Foreign PEP" and a "Domestic PEP" as per BMA definitions?</summary>

Yes. The screening database categorizes Politically Exposed Persons (PEPs) by jurisdiction and role. This allows you to apply the correct level of Enhanced Due Diligence (EDD). For example, you can implement the procedure to manage a "Foreign PEP" for Senior Management Approval, a specific requirement under Regulation 11 of the POCR.

</details>

<details>

<summary>The BMA warns against relying on "fuzzy matching" that creates too many false negatives. Can we tune Tiller?</summary>

Absolutely. "Black box" screening is a regulatory risk. Verify by Tiller allows you to configure the "Fuzzy Logic" matching or switch it off completely. This allows your firm to define its own risk appetite and justify to the BMA why specific parameters were chosen to balance false positives against missed matches.

</details>

**Category 3: Risk Assessment & Governance**

<details>

<summary>Can Tiller automate our "Customer Risk Assessment" required by Regulation 16?</summary>

While the final decision rests with the firm, Verify by Tiller facilitates the assessment. Shortly a Risk Engine will be added to the platform which will allow you to build complex "Risk Scoring" that score clients based on various factors (e.g., Nationality, Region, SoW[^2], SoF[^3] etc.). The system can suggest a risk rating based on your pre-configured rules, ensuring consistency across your entire client base—a key factor BMA auditors look for.

</details>

<details>

<summary>How does Tiller support our obligation to understand the "Source of Wealth"?</summary>

For some clients, simply knowing the "Source of Funds" is not enough. Verify by Tiller includes dynamic questionnaires that can specifically ask for SoW details and prompting the upload of evidence (e.g., share certificates, sale of property deeds) directly within the secure onboarding flow.

</details>

<details>

<summary>The BMA Outsourcing Guidance requires us to have an "Exit Strategy." What happens to our data if we leave Tiller?</summary>

You are never locked in. Verify by Tiller allows you to export your data and compliance reports. This "Data Portability" ensures you meet the BMA’s Operational Resilience standards, proving you can retrieve your regulatory records even if you switch providers.

</details>

**Category 4: Record Keeping & Data Privacy (PIPA)**

<details>

<summary>Under PIPA and POCR Regulation 15, we must keep records for 5 years. Does Tiller store this?</summary>

Although Verify by Tiller should not be considered you digital archive as that should exist in your CRM or Client Lifecycle platform, Verify provides all identification data, screening results, and decisions in a form (full "KYC Pack") that can be stored by you for the 5 years required ready for a BMA Onsite Inspection or an FIA information request.

</details>

<details>

<summary>Is Tiller compliant with the Personal Information Protection Act (PIPA) 2016?</summary>

Yes. Verify by Tiller is built with "Privacy by Design." Data is encrypted at rest and in transit. The platform supports your PIPA obligations by providing tools to manage Subjects rights and ensuring data is only accessible to authorized compliance staff (Access Control), mitigating the risk of internal data breaches.

Tiller also correctly takes into account the differences between GDPR and PIPA when it comes to the classification of "Sensitive Personal Information. Information such as,

* Place of Birth (Place of Origin)
* Nationality (Place of Origin)
* Marital Status

which are treated as Standard Data by GDPR are recognised by Tiller as Sensitive Personal Data under PIPA and managed accordingly. It should be noted that a passport reveals a person's "Place of Birth" and "Nationality." In Bermuda, holding a copy of a passport means holding "Sensitive Personal Information" because it reveals the "Place of origin.". Verify already treats Passport data as Sensitive Personal Data anyway.

</details>

<details>

<summary>How does Tiller help us demonstrate "Senior Management Oversight" to the BMA?</summary>

The platform provides high-level dashboards and reporting metrics. You can view real-time data on onboarding status, the number of referrals, and pending PEP approvals. This empowers Management to make data-driven decisions and proves they are actively overseeing the compliance function, not just rubber-stamping it.

</details>

<details>

<summary>Does the system provide an audit trail for the MLRO's decisions?</summary>

Yes. This is important for BMA audits. Every uploaded document, dismissing a false positive sanction match, or approving a PEP is logged. This prevents the "he said, she said" problem and proves exactly *who* made a compliance decision and *when*.

</details>

[^1]: Client Relationship Management

[^2]: Source of Wealth

[^3]: Source of Funds


# Welcome to the Verify API

The Verify by Tiller API documentation is a comprehensive guide to the powerful API driving the Know Your Customer (KYC) solution developed by Tiller Technologies Limited. This API is designed to streamline the complex processes of identity verification, risk assessment, and compliance management for regulated and supervised businesses across the globe. Our API enables seamless integration, offering a secure, efficient, and user-friendly platform to meet your organisation's KYC obligations.

The Tiller Verify API is built on HTTP. Our API is RESTful. It has predictable resource URLs. It returns HTTP response codes to indicate status and or errors. It accepts and returns JSON in the HTTP body. You can use your favourite HTTP/REST library for your programming language to use Tiller Verify API.

For more information, please visit [www.tiller-verify.com](http://www.tiller-verify.com).

## Purpose of this API

The Verify by Tiller API provides programmable access to our customer KYC/AML services. It caters to a range of regulated business needs. By leveraging our API, you can integrate our verification process with your application.

Through a simple integration, you can create applications, send invites to customers and receive verification results. Checks include:

* Personal details and address capture
* Identity document verification.
* Biometric face match and liveness check.
* International address verification.
* PEP & sanctions screening.
* Adverse media screening
* Secure proof of address upload.
* Geolocation checks
* Nationality capture
* Place of birth capture
* UK Bank Ownership check (coming soon)
* Source of Funds capture (coming soon)

Tiller will continue to build out additional check and modules.

## The Verification Process

Verify by Tiller streamlines your onboarding process by providing a digital process for completing verification checks through the Verify by Tiller app.&#x20;

<figure><img src="/files/mIyTTsK0xg9meUPwGju7" alt=""><figcaption><p>Verification Process Using API</p></figcaption></figure>

For each application, follow these steps:

1\) Send an application request with one or more individuals.

2\) Customer(s) download the Verify by Tiller app and complete their checks.&#x20;

3\) Results are sent to your Webhook subscription or can be retrieved.

4\) For each completed customer, download the PDF report, documents and images.&#x20;

## Global Reach and Security

We understand the importance of global access combined with uncompromised security. Verify by Tiller API offers:

* **Worldwide Accessibility:** Our services are available across various geographical locations, adhering to international compliance standards. For information on our global coverage please contact us at <info@tillertech.com>.
* **Data Privacy and Security:** We prioritise the confidentiality and integrity of your data with state-of-the-art security measures. Find out more within the [Data Security](/verify-api/getting-started/data-security) section.

## Getting Started

Ready to integrate Verify by Tiller into your workflow? Head to our [Quick Start Guide](/verify-api/getting-started/quick-start-guide) for step-by-step instructions on using our API.

We are excited to partner with you and look forward to supporting your business's KYC needs. Should you have any questions or require assistance, our support team is available to ensure a smooth integration experience.


# Quick Start Guide

Getting straight to it with this quick start guide.

This section will guide you through the initial steps to integrate and use our services. Whether you are new to APIs or an experienced developer, we've designed this process to be straightforward.

### Step 1: Register for API Access

Before you can start using the API, you'll need to register and obtain your unique API credentials. These credentials are essential for authenticating and sending your API requests.

1\)      **Sign Up:** Visit our [sign up page](https://app.tiller-verify.com/sign-up) and create an account for your company. This will not be instant as we need to set up your company before we can give you access to our services.&#x20;

2\)      **API Permission:** Once your account is set up, please contact us at <support@tillertech.com> to request API permission on your user credentials.

### Step 2: Install Required Tools

To make API requests, you'll need a tool that can send HTTP requests. You can use tools like [Postman](https://www.postman.com/) , [cURL](https://curl.se/), or write your code in a language that supports HTTP requests, such as Python, JavaScript, etc.

We can provide you with a Postman collection if required. Please contact **<support@tillertech.com>**.

### Step 3: Authenticate Your API Request

All API requests to Verify by Tiller require authentication. An access token can be retrieved through the [Authentication](/verify-api/endpoints/api-reference/authentication) method. Please see below some examples code.&#x20;

URL:  "<https://api.tiller-verify.com/api/v1/ext/authentications/token>"

Code example:

{% tabs %}
{% tab title="Python" %}

```python
import requests

def get_auth_token(username, password):
    url = "https://api.tiller-verify.com/api/v1/ext/authentications/token"
    payload = {
        "username": username,
        "password": password,
        "grant_type": "password"
    }
    headers = {
        "Content-Type": "application/x-www-form-urlencoded"
    }
    response = requests.post(url, data=payload, headers=headers)
    if response.status_code == 200:
        return response.json().get("access_token")
    else:
        print(f"Error: {response.status_code}, Message: {response.text}")
        return None

# Replace with your username and password
token = get_auth_token("your_username", "your_password")
```

{% endtab %}

{% tab title="JavaScript" %}

```javascript
const axios = require('axios');

async function getAuthToken(username, password) {
    const url = "https://api.tiller-verify.com/api/v1/ext/authentications/token";
    const payload = {
        username: username,
        password: password,
        grant_type: "password"
    };
    try {
        const response = await axios.post(url, payload, {
            headers: {
                'Content-Type': 'application/json',
                'Accept': 'application/json'
            }
        });
        return response.data.access_token;
    } catch (error) {
        console.error(`Error: ${error.response.status}, Message: ${error.response.data}`);
        return null;
    }
}

// Replace with your username and password
getAuthToken('your_username', 'your_password').then(token => {
    console.log(token);
});
```

{% endtab %}

{% tab title="cURL" %}

```
curl -X POST https://api.tiller-verify.com/api/v1/ext/authentications/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "username=your_username&password=your_password&grant_type=password"
```

{% endtab %}
{% endtabs %}

:exclamation:For "grant\_type" we only support either "client\_credentials" or "password". This will usually be "password".

Authentication will provide a bearer token to include in the header of your subsequent API requests. Please ensure this token is passed into the Authorization header on subsequent requests.

### Step 4: Making Your First API Calls

Once you're authenticated, you can start making API calls. Here are some initial requests to get you started (subscribe, references and application).

### **- Post Subscription:**&#x20;

The subscribe endpoint provides a URL to send the customer verification results to your system via a Webhook.&#x20;

Example code:

{% tabs %}
{% tab title="Python" %}

```python
import requests

def subscribe_to_webhook(token, callback_url):
    url = "https://api.tiller-verify.com/api/v1/ext/webhooks/subscribe"
    headers = {
        "Authorization": f"Bearer {token}",
        "Content-Type": "application/json"
    }
    payload = {
        "callback_url": callback_url
    }
    response = requests.post(url, headers=headers, json=payload)
    if response.status_code == 200:
        return response.json()
    else:
        print(f"Error: {response.status_code}, Message: {response.text}")
        return None

# Example usage
token = "your_auth_token"  # Replace with your actual token
callback_url = "https://your.callback.url" # Replace with your URL
subscription = subscribe_to_webhook(token, callback_url)
print(subscription)
```

{% endtab %}

{% tab title="JavaScript" %}

```javascript
const axios = require('axios');

async function subscribeToWebhook(token, callbackUrl) {
    const url = "https://api.tiller-verify.com/api/v1/ext/webhooks/subscribe";
    const headers = {
        Authorization: `Bearer ${token}`,
        'Content-Type': 'application/json'
    };
    const payload = {
        callback_url: callbackUrl
    };

    try {
        const response = await axios.post(url, payload, { headers: headers });
        return response.data;
    } catch (error) {
        console.error(`Error: ${error.response.status}, Message: ${error.response.statusText}`);
        return null;
    }
}

// Example usage
const token = 'your_auth_token'; // Replace with your actual token
const callbackUrl = 'https://your.callback.url'; // Replace with your url

subscribeToWebhook(token, callbackUrl)
    .then(subscription => console.log(subscription))
    .catch(error => console.error(error));
```

{% endtab %}

{% tab title="cURL" %}

```
curl -X POST "https://api.tiller-verify.com/api/v1/ext/webhooks/subscribe" \
     -H "Authorization: Bearer your_auth_token" \
     -H "Content-Type: application/json" \
     -d '{"callback_url": "https://your.callback.url"}'
```

{% endtab %}
{% endtabs %}

You can specify a dynamic URL, such as an application ID. For example:

```
https://api.tiller-verify.com/api/v1/ext/webhooks/subscribe/{application_reference}
```

This allows for greater flexibility and specificity in handling webhook notifications.

### **- Get References:**&#x20;

This endpoint provide the ID references to commonly needed items such as your mandate type IDs and status IDs.&#x20;

{% tabs %}
{% tab title="Python" %}

```python
import requests

def get_references(token):
    url = "https://api.tiller-verify.com/api/v1/ext/references"
    headers = {"Authorization": f"Bearer {token}"}
    response = requests.get(url, headers=headers)
    if response.status_code == 200:
        return response.json()
    else:
        print(f"Error: {response.status_code}, Message: {response.text}")
        return None

# Example usage
token = "your_auth_token"  # Replace with your actual token
references = get_references(token)
print(references)
```

{% endtab %}

{% tab title="JavaScript" %}

```javascript
const axios = require('axios');

async function getReferences(token) {
    const url = "https://api.tiller-verify.com/api/v1/ext/references";
    const headers = {
        Authorization: `Bearer ${token}`
    };

    try {
        const response = await axios.get(url, { headers });
        return response.data;
    } catch (error) {
        console.error(`Error: ${error.response.status}, Message: ${error.response.statusText}`);
        return null;
    }
}

// Example usage
const token = "your_auth_token"; // Replace with your actual token
getReferences(token).then(references => {
    console.log(references);
});
```

{% endtab %}

{% tab title="cURL" %}

```
curl -X GET "https://api.tiller-verify.com/api/v1/ext/references" \
     -H "Authorization: Bearer your_auth_token"
```

{% endtab %}
{% endtabs %}

It is useful to organise the references into categories.

{% tabs %}
{% tab title="Python" %}

```python
import json
from collections import defaultdict

def organise_by_category(data):
    categories = defaultdict(list)
    for item in data:
        category = item['category']
        categories[category].append(item)
    
    # Optionally, sort each category by name or reference_id
    for category in categories:
        categories[category].sort(key=lambda x: (x['reference_id'] is None, x['reference_id']))

    return categories

# JSON payload
data = get_references(token)

# Organise data
organised_data = organise_by_category(data)

# To print the organized data
for category, items in organised_data.items():
    print(f"Category: {category}")
    for item in items:
        print(f"  {item}")
    print("\n")

# Optionally, convert it back to JSON
json_output = json.dumps(organized_data, indent=4)
print(json_output)
```

{% endtab %}

{% tab title="JavaScript" %}

```javascript
const data = references

function organiseByCategory(data) {
    const categories = {};

    data.forEach(item => {
        const category = item.category;
        if (!categories[category]) {
            categories[category] = [];
        }
        categories[category].push(item);
    });

    // Optionally, sort each category by name or reference_id
    for (const category in categories) {
        categories[category].sort((a, b) => {
            // Sorting by reference_id with null values last
            return (a.reference_id === null) - (b.reference_id === null) || 
                   (a.reference_id || 0) - (b.reference_id || 0);
        });
    }

    return categories;
}

const organisedData = organiseByCategory(data);

// To print the organized data
for (const category in organisedData) {
    console.log(`Category: ${category}`);
    organisedData[category].forEach(item => console.log(`  ${JSON.stringify(item)}`));
    console.log('\n');
}

// Optionally, convert it back to JSON
const jsonOutput = JSON.stringify(organisedData, null, 4);
console.log(jsonOutput);
```

{% endtab %}
{% endtabs %}

:exclamation:It is important that you retrieve your mandate type ID(s) to be able to start creating applications. These mandate types will determine the checks made against the individual. You should have at least one mandate type available upon set-up.

### **- Create Application**

You can create an application for one or more individuals. This will send each individual an email inviting them to download the Verify by Tiller app and complete their checks. For more information please see the [Applications](/verify-api/endpoints/api-reference/applications) section.

{% tabs %}
{% tab title="Python" %}

```python
import requests

def create_application(token, application_data):
    url = "https://api.tiller-verify.com/api/v1/ext/applications"
    headers = {
        "Authorization": f"Bearer {token}",
        "Content-Type": "application/json"
    }
    response = requests.post(url, headers=headers, json=application_data)
    if response.status_code == 200:
        return response.json()
    else:
        print(f"Error: {response.status_code}, Message: {response.text}")
        return None

# Example usage
token = "your_auth_token"  # Replace with your actual token
application_data = {
        "name": "YOUR_APPLICATION_NAME", # A meaningful application name for the customer
        "reference": "MANDATE_REFERENCE", # A unique mandate referece
        "mandate_type": 1, # Update from references list
        "individuals": [
            {
                "email": "CUSTOMER_EMAIL",
                "title": "Mr",
                "first_name": "FIRST_NAME",
                "middle_name": "", #Optional
                "last_name": "LAST_NAME",
                "date_of_birth": "1980-12-31", #Optional
                "gender": "male",
                "reference": "REFERENCE001" # Your unique reference
            } 
            # Additional individuals can be added to this list.
        ]
    }
new_application = create_application(token, application_data)
print(new_application)
```

{% endtab %}

{% tab title="JavaScript" %}

```javascript
const axios = require('axios');

async function createApplication(token, applicationData) {
    const url = "https://api.tiller-verify.com/api/v1/ext/applications";
    const headers = {
        Authorization: `Bearer ${token}`,
        'Content-Type': 'application/json'
    };

    try {
        const response = await axios.post(url, applicationData, { headers });
        return response.data;
    } catch (error) {
        console.error(`Error: ${error.response.status}, Message: ${error.response.data}`);
        return null;
    }
}

// Example usage
const token = "your_auth_token"; // Replace with your actual token
const applicationData = {
    name: "YOUR_APPLICATION_NAME", // A meaningful application name for the customer
    reference: "MANDATE_REFERENCE", // A unique mandate reference
    mandate_type: 1, // Update from references list
    individuals: [
        {
            email: "CUSTOMER_EMAIL",
            title: "Mr",
            first_name: "FIRST_NAME",
            middle_name: "", // Optional
            last_name: "LAST_NAME",
            date_of_birth: "1980-12-31", // Optional
            gender: "male",
            reference: "REFERENCE001" // Your unique reference
        }
        // Additional individuals can be added to this list.
    ]
};

createApplication(token, applicationData)
    .then(newApplication => console.log(newApplication))
    .catch(error => console.error(error));
```

{% endtab %}

{% tab title="cURL" %}

```
curl -X POST "https://api.tiller-verify.com/api/v1/ext/applications" \
     -H "Authorization: Bearer your_auth_token" \
     -H "Content-Type: application/json" \
     -d '{
            "name": "YOUR_APPLICATION_NAME",
            "reference": "MANDATE_REFERENCE",
            "mandate_type": 1,
            "individuals": [
                {
                    "email": "CUSTOMER_EMAIL",
                    "title": "Mr",
                    "first_name": "FIRST_NAME",
                    "middle_name": "",
                    "last_name": "LAST_NAME",
                    "date_of_birth": "1980-12-31",
                    "gender": "male",
                    "reference": "REFERENCE001"
                }
                // Additional individuals can be added here.
            ]
         }'
```

{% endtab %}
{% endtabs %}

Once an individual has completed their checks on the Verify by Tiller mobile app, the results will be sent to the URL provided through the subscription endpoint. You can also retrieve the information directly using the [Applications](/verify-api/endpoints/api-reference/applications) endpoint.&#x20;

Further information about all the endpoint can be found in the [API Reference](/verify-api/endpoints/api-reference) section.

### Step 5: Your Results

Each time an individual completes their checks within the Verify by Tiller app, you will receive a response to the URL you have posted to the subscription endpoint. Each webhook will contain the mandate/application details and all the details about the individuals.&#x20;

:exclamation:When all individuals have completed their checks, the mandate (application) will move from an 'in progress' :blue\_circle: status to either a 'in review' :yellow\_circle: or 'complete' :green\_circle: status.&#x20;

&#x20;**General structure:**

* **ID and Reference**: Unique identifiers for the application or the mandate.
* **Mandate Type**: Describes the type of application and what checks are included.
* **Status**: Overall status of the application, which is 'in progress' >> 'in review'/'complete'.

**Individual details:**

* **Name, Date of Birth, Email, Gender**: Basic personal information.
* **Terms Accepted**: Indicates whether the terms and conditions were accepted.
* **Completed Actions**: Lists completed steps in the mobile app to complete their check, like accepting terms and conditions, adding personal details, etc.
* **Checks**: Each check completed (e.g. address\_verification\_check) will have a set of result data, including:
  * Title - The type of check made
  * Status - Indicates the result of the check type, such as "pending", "review", or "accepted".
  * Check field results - Any underlying verifications made to determine the overall check status.
  * Images - Any associated images that are related to the check. This can include the ID document image for the Identity and Liveliness Checks.

### Handling Errors

Each API request will return a response. A successful request will typically return a 200 OK status code along with any requested data. Errors or issues with your request will return different status codes (e.g., 400 Bad Request, 401 Unauthorized) and an error message explaining what went wrong.

Error handling for all API methods must adhere to the RFC7807 standard, ensuring standardized and informative error responses for clients. Please see <https://www.rfc-editor.org/rfc/rfc7807>. Please see more information within the [Error Handling](/verify-api/endpoints/error-handling) section.

### Need Help?

If you encounter any issues or have questions, our support team is here to help. Please contact us at <support@tillertech.com>


# Data Security

This page contains information about how data is transferred and stored.

## Data storage & controls

All data is stored encrypted in either our primary Microsoft Azure Datacentre in Dublin, Ireland or our secondary geo-redundant Microsoft Azure Datacentre in Amsterdam, Holland. No data is stored on the end-user mobile device.

All data either at rest or in transit is encrypted. At rest, data is encrypted using Transparent data encrypted (TDE) using key based AES 256 algorithm. In transit, all connection use Transport Layer Security (TLS v 1.2 or greater).

All data access is governed by role-based access control following our ‘Least Privilege’ Access Control governance policy.

Physical access control at Azure Datacentres meets or exceeds Tier 4 standards and meets all ISO 27001, HIPAA, FedRAMP, SOC 1, SOC 2, and UK G-Cloud standards.

All Tiller staff undertake full background check screening before employment and are required to undertake security awareness training every 6 months. Access Control policies are followed on any change of employment status to confirm, change, or revoke access rights.

Further information on data security can be found on our website: <https://www.tillertech.com/privacy-policy>.

## PDF Report

A customer report can be generated for all clients that have been processed. The PDF can be downloaded directly from the browser by an authorised user from the Verify by Tiller Portal. The PDF contains all information captured against the individuals and the detailed output for the verification checks performed.

## Third Party Services

Tiller Technologies shares individual data with 3rd party services to be able to perform verification checks. Agreements are in place with all service providers, and mutual due diligence has been completed. Each company using the Verify by Tiller services will be required to accept Terms and Conditions that stipulate how data is processed. Each end customer will need to accept an End User Terms to use the Verify by Tiller application.

## Security testing

Security is continually tested using an in-house QA (quality assurance) team ensuring the alignment of the services to Tiller Technologies’ data security policies. A full penetration test will be conducted by NCC Group prior to the production launch of the services. This will be conducted at a minimum of once every 12 months.

Further information about data security is found in our Privacy Policy, Terms & Conditions and End User Terms. Tiller Technologies is a Data Processor and will conduct regular DPIAs (Data Protection Impact Assessments) for each new feature developed and deployed.


# API Reference

An overview of the endpoints and their structure.

The API provides a suite of endpoints designed to facilitate various operations related to customer identity verification and application processing. These endpoints are structured to offer a straightforward, RESTful interface, allowing for easy integration into diverse systems. Below is an overview of the required headers and key endpoints available:

## Request Headers

Proper implementation of these headers is essential for secure and effective communication between the client and server. Below details the specific headers required and secure API interactions.

1. **Content-Type**: Most endpoints' content type is set to `application/json`, indicating that the request body is formatted as JSON. However, for the authentication token request, this header should be set to `x-www-form-urlencoded`, indicating that the request's body is a URL-encoded form.
2. **Accept**: This header is used in the request header to indicate to the server what content types are acceptable for the response. For the this is typically set to `application/json`, which tells the server that the client is expecting a JSON-formatted response.
3. **Authorization**: This header is crucial for APIs that require authentication. The `Authorization` header is used to pass the bearer token which is a form of security token. The format generally is `Bearer <access_token>`, where `<access_token>` is a placeholder for the actual token the server provides upon authentication. This token is used by the server to verify that the request is coming from an authenticated and authorized source.

## Request Paths

1. [Authentication](/verify-api/endpoints/api-reference/authentication)

   * **Get Access and Refresh Tokens** (`POST /ext/authentications/token`): Acquire an access token for API authentication.

2. [Applications](/verify-api/endpoints/api-reference/applications)

   * **Create Application** (`POST /ext/applications`): Establish a new application, providing application type, reference and customer details. This will create an application and send an email invite to each customer.
   * **Retrieve Application** (`GET /ext/applications/{id}`): Fetch detailed information about a specific application using its unique ID. Useful for tracking and managing ongoing applications with direct callss
   * **Delete Application** (`DELETE /ext/applications/{id}`): Permanently remove an application from the system. This will permanently delete the application, customer associated and any underlying check data.
   * **Archive Application** (`PATCH /ext/applications/{id}/archive`): Archive an existing application for future reference without deleting it. Helps in maintaining application views without having to delete them.

3. [Individuals](/verify-api/endpoints/api-reference/individuals)

   * **Retrieve Individual** (`GET /ext/individuals/{id}`): Obtain detailed information on an individual associated with an application.
   * **Resend Invites** (`POST /ext/individuals/{id}/invites/resend`): Resend email invitation with new invite code to an individual. The email contains links to the Verify by Tiller app.
   * **Reset Individual** (`POST /ext/individuals/{id}/reset`): Reset an individual's information and check details within an application. Useful for restarting the process for your customer and sending them a new email with code.&#x20;
   * **Get Individual Report** (`GET /ext/individuals/{id}/report`): Download a comprehensive report about an individual's verification data.This is only available to individuals that have completed their checks.

4. [References](/verify-api/endpoints/api-reference/references)

   * **Retrieve References** (`GET /ext/references`): Access reference ID data like country codes, document types, and mandate/application types.

5. [Webhooks](/verify-api/endpoints/api-reference/webhooks)
   * **Subscribe to Webhook** (`POST /ext/webhooks/subscribe`): Enable webhook subscriptions for receiving real-time updates related to applications. Facilitates immediate response of application data when a customer has completed their verification process.&#x20;
   * **Retrieve Webhook** (`GET /ext/webhooks/retrieve/{application_id}`): Fetch webhook details for a particular application. Useful for debugging and monitoring webhook interactions.

Each endpoint plays a role in the operation of the identity verification process, offering a suite of tools for application management and system integration.


# Authentication

The Verify by Tiller API employs a secure authentication mechanism to ensure that only authorised users can access the API. This section covers everything you need to know about obtaining and using authentication tokens to interact with the Verify by Tiller API.

## Obtaining your Token

To obtain an authentication token, you will need to make a POST request to our authentication endpoint with your user credentials.&#x20;

:exclamation:It is important that the user credentials have been given the correct permissions. Please contact <support@tillertech.com> to request the API permissions be added to the user profile.

Here's a step-by-step guide:

1\) Ensure that your user credentials have API permissions. If you are unsure, contact <support@tillertech.com>.

2\) Send a POST request with your user credentials in the request body. Use 'password' in the grant type.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/authentications/token" method="post" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

After successfully authenticating, you will receive a JSON response containing your '*access\_token'*. This token must be included in the Authorization header of your subsequent API requests. It should be included as a Bearer token.


# Applications

This page contains information about managing applications/mandates.

## Overview

The Applications API is designed to facilitate the management of Verify by Tiller applications and the individuals associated. It offers the following functionality:

* Create an application.
* Retrieve application details.
* Delete the application (and all associated individuals and check data).
* Archive the application (to help with record keeping).&#x20;

:exclamation:The words 'application' and 'mandate' are used interchangeably.

## Create application

The Application POST endpoint (`/ext/applications`) is designed for creating new verification applications. This endpoint initiates the verification process by creating an application and sending email invites to the individuals.&#x20;

It requires application details, mandate type id (see [References](/verify-api/endpoints/api-reference/references) section), and information about the individuals. The endpoint ensures that each application is uniquely identified and processed, facilitating a structured and efficient verification workflow.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/applications" method="post" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

Example request data:

```json
application_data = {
        "name": "YOUR_APPLICATION_NAME", # A meaningful application name for your business
        "reference": "MANDATE_REFERENCE", # A unique mandate reference
        "mandate_type": 1, # Update ID from references list for your mandate type
        "individuals": [
            {
                "email": "CUSTOMER_EMAIL",
                "title": "Mr", # See references for full list
                "first_name": "FIRST_NAME",
                "middle_name": "", #Optional
                "last_name": "LAST_NAME",
                "date_of_birth": "1980-12-31", #Optional
                "gender": "male",
                "reference": "REFERENCE001" # A unique reference from your system
            } 
            # Additional individuals can be added to this list.
        ]
    }
```

## Retrieve application

The Retrieve Application Endpoint (`/ext/applications/{id}`) allows you to fetch detailed information about a specific Verify by Tiller application using its unique identifier. This endpoint is useful in actively in monitoring the progress and status of an application, providing comprehensive insights into the progress of the mobile actions, individual checks, status updates, and other relevant data.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/applications/{id}" method="get" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

## Complete application

The **Complete Application** endpoint (`/ext/applications/{app_id}/complete`) transitions an application from the "in review" status to "completed." This endpoint is used when the verification process for an application has been fully reviewed, or when it is determined that no further action is needed. Once an application is marked as completed it signifies that the verification process has reached its conclusion.

## Reject application

The **Reject Application** endpoint (`/ext/applications/{app_id}/reject`) is used to reject an application that is currently "in review." This endpoint plays a crucial role when it is determined that the application does not meet the required standards or the associated checks have failed. By rejecting an application, the system ensures that no further processing occurs and that the application is marked as invalid. This also allows tracking of rejected applications for auditing or reporting purposes.

## Delete application

The Delete Application Endpoint (`/ext/applications/{id}`), accessible via an HTTP DELETE request, enables clients to permanently remove an application using its unique identifier.&#x20;

This will delete the application and all individual data associated with that application. It ensures clients can efficiently manage their application records, removing those no longer needed or relevant. All applications are automatically deleted after eight weeks as per our privacy policy.&#x20;

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/applications/{id}" method="delete" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

## Archive application

The Archive Application Endpoint (`/ext/applications/{id}/archive`), which is accessed through an HTTP PATCH request, provides a facility to archive an existing application by its unique identifier.&#x20;

Archiving an application is a prudent way to manage no longer current records but might be needed for future reference. This functionality helps keep the active application pool manageable and relevant while ensuring that historical data is preserved. Archiving differs from deletion in that it preserves the data rather than removing it, allowing for retrieval and review as usual through the retrieve application endpoint.&#x20;

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/applications/{id}/archive" method="patch" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

An archived application will have the following attribute:

```json
"archived": True
```

## Accept check

The **Accept Check** endpoint (`/check/{check_id}/accept`) allows the manual acceptance of a verification check. This endpoint is used when a check needs to be marked as `manually_accepted`. This might occur in situations where the system requires human review before finalising the status of a check. Once a check is accepted, its status is updated, and the relevant data is persisted in the system. The process helps ensure that the system can account for exceptions where automated checks may not fully suffice.

The following body is required in the request:

```json
payload = {
    "comment": "This is a comment for the approval of this check",
    "comment_for": "IndividualCheck",
    "reference": 123456
}
```

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/check/{check\_id}/accept" method="patch" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

## Reject check

The **Reject Check** endpoint (`/check/{check_id}/reject`) provides the ability to reject a verification check manually. When a check fails or does not meet the required criteria, it can be flagged as `manually_rejected` through this endpoint. This ensures that the system maintains an accurate log of rejected checks and can trigger any necessary follow-up actions or notifications. By rejecting a check, administrators can control the verification process and ensure that unsuitable individuals are not processed further.

The following body is required in the request:

```json
payload = {
    "comment": "This is a comment for the rejection of this check",
    "comment_for": "IndividualCheck",
    "reference": 123456
}
```

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/check/{check\_id}/reject" method="patch" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}


# Individuals

This page contains information about managing the participants of the applications.

## Overview

The individual APIs focus on managing individual customers associated with an the applications.

The endpoints include:

* **Retrieving individual details:** Access the data related to a specific individual associated with an application, including personal details, completed mobile actions, and check details.
* **Resending invites:** Reissue an invitation by generating a new code and sending an email.
* **Resetting individual data:** Provides the ability to reset an individual. All information provided by the individual and check information will reset, and a new invite will be emailed.
* **Generating individual reports:** Retrieves the individual's PDF report that contains their information and check data in a structured format. This PDF should be stored on your system as a durable record of the verification results.

These information captured by the individual and the checks performed are determined by the application type they have been added to.

:exclamation:Please note that the terms individuals and customer are used interchangeably.

## Retrieve Individual

The Retrieve Individual endpoint is primarily used for fetching data about an individual, including personal information, their current status in the application process, the results of any checks conducted, and a record of their accepted terms and conditions.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/individuals/{id}/report" method="get" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

## Reset Individual

The Reset Individual endpoint will delete all information captured from the customer and all check data. The customer will also receive an email to confirming the reset with a new invite code.

This endpoint is useful when there is a need to clear previously submitted data for an individual, allowing them to restart or re-engage with the application process from a specific point.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/individuals/{id}/reset" method="post" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

## Retrieve Report

The Retrieve Report endpoint retrieves a detailed PDF report of the individual's application. These reports include the captured personal information, the verification status, the check results and comments collected against the individual. These reports should be downloaded and stored on your system.&#x20;

:exclamation:A report can only be retrieved for an individual that have completed their verification process and are in the 'completed' state.&#x20;

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/individuals/{id}/report" method="get" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

## Resend Invite

The Resend Invite endpoint resends invitation emails to individuals who have not yet completed their required mobile actions in the verification process. It serves as a tool for prompting and reminding individuals to complete the required mobile app steps.

Customers can also request a new invite code themselves through the mobile app.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/individuals/{id}/invites/resend" method="post" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}


# References

This page contains information about retrieving a set of references and their ID's.

The References API serves as a central repository for various reference data types for verification. This API provides access to reference information, which are organised into categories. These include:&#x20;

* **Country:** A list of countries and their ISO codes.&#x20;
* **Document types:** These are the available document types that the customer can select as part of the proof of address upload.
* **Industry:** A list of selectable industries for your account settings.
* **Individual check field status:** Each check can have a set of underlying results. These are represented by the check field results and can have the following status; 'pending', 'accepted', 'rejected'. These underlying results are what determines whether the check has passed or needs to be reviewed.
* **Individual check status:** Each check can have the following status; 'pending', 'review', 'accepted', 'manually\_accepted' or 'manually\_rejected'.
* **Individual status:** The progress of the customer completing their mobile app actions. They can be 'pending' or 'completed'. Only 'completed' individuals will have a customer report.&#x20;
* **Mandate status:** The progress of the application. This can be 'new', 'in progress', 'in review', 'completed' or 'rejected'.&#x20;
* **Mandate type:** A list of mandate/application types available. The information gathered and checks completed for the individuals associated with the mandate.
* **Title:** The acceptable titles for submitting the customers details as part of the create application process.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/references" method="get" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}


# Webhooks

This page describes the subscription process and managing the Webhooks.

Webhooks offer a way to receive real-time notifications about various events within the system. These webhooks are designed to keep your application in sync with changes in applications or individual statuses without continuously polling the API for updates.

When an event occurs (such as an update to an application's status or individual an individual completing their checks), Tiller sends an HTTP POST request with detailed event data to a subscription URL - the webhook endpoint set up in your system. This mechanism ensures your application can react promptly to changes, facilitating workflows and more immediate responses.

Key functionalities enabled by webhooks include:

* **Real-Time Notifications**: Instantly receive updates about important events, reducing the delay in processing or acting upon these changes.
* **Customised URL Pattern**: Choose the URL pattern for the POST request with the ability to have dynamic references in the URL.&#x20;
* **Security**: Provide Tiller with credentials to make an authenticated request to your webhook URL for increased security.

This real-time, event-driven approach is crucial for applications requiring immediate reaction to status changes in the verification process, ensuring that your integration remains up-to-date with the least amount of resource usage.

## Subscribe

The Subscribe endpoint registers a webhook subscription for receiving real-time notifications. This endpoint can be dynamically set with a webhook URL tailored to specific applications or events.

When you subscribe using this endpoint, you have the option to specify a dynamic URL that includes references, such as an application ID. For example:

```
https://api.tiller-verify.com/api/v1/ext/webhooks/subscribe/{application_reference}
```

The dynamic element needs to be an attribute of the application data. This dynamic URL structure allows for greater flexibility and specificity in handling webhook notifications. By using this dynamic URL, you can create highly responsive and tailored workflows that react promptly to relevant API events.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/webhooks/subscribe" method="post" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}

## Retrieve Webhook

The Retrieve Webhook endpoint serves as a tool for querying the expected webhook request data of an existing application. This endpoint can help with understanding and querying the expected response from the webhook for a particular application.

{% openapi src="/files/d3yB4cFl16j0xlR4QP71" path="/ext/webhooks/retrieve/{application\_id}" method="get" %}
[TillerTechnologies-verify-api-v1-oas3.json](https://content.gitbook.com/content/0zS5rWXn6QhdPJuSHu9k/blobs/QIqANJoV2sVgHqFFWsfb/TillerTechnologies-verify-api-v1-oas3.json)
{% endopenapi %}


# Error Handling

What error codes are there and how to handle errors.

## Success and Error codes

Each API request will return a response. A successful request will typically return a 200 OK status code along with any requested data. Errors or issues with your request will return different status codes (e.g., 400 Bad Request, 401 Unauthorized) and an error message explaining what went wrong.

### Success Codes

<table><thead><tr><th width="132">Code</th><th>Description</th></tr></thead><tbody><tr><td>200</td><td>OK - The request has succeeded.</td></tr><tr><td>201</td><td>Created - The request has been fulfilled and has resulted in one or more new resources being created.</td></tr><tr><td>202</td><td>Accepted - The request has been accepted for processing, but the processing has not been completed.</td></tr><tr><td>204</td><td>No Content - The server successfully processed the request, but is not returning any content.</td></tr></tbody></table>

### Error codes

<table><thead><tr><th width="132">Code</th><th>Description</th></tr></thead><tbody><tr><td>400</td><td>Bad Request - The server cannot process the request due to a client error (e.g., malformed request syntax).</td></tr><tr><td>401</td><td>Unauthorised - The request lacks valid authentication credentials for the target resource.</td></tr><tr><td>404</td><td>Not Found - The server can't find the requested resource.</td></tr><tr><td>500</td><td>Internal Server Error - The server encountered an unexpected condition that prevented it from fulfilling the request.</td></tr></tbody></table>

## Error Message Standard

Error handling for all API methods must adhere to the RFC7807 standard, ensuring standardized and informative error responses for clients. Please see <https://www.rfc-editor.org/rfc/rfc7807>.&#x20;

Please see below of a standard example.&#x20;

{% code overflow="wrap" %}

```json
{
   "type":"",
   "title":"Your request parameter didn't validate.",
   "exception":{
      "reference":[
         "Mandate with the reference already exists."
      ],
      "individuals":[
         {
            "reference":[
               "Individual with the reference already exists."
            ]
         },
         {
            "reference":[
               "Individual with the reference already exists."
            ]
         }
      ]
   },
   "status":"400"
}
```

{% endcode %}

**RFC7807: Problem Details for HTTP APIs**

RFC7807 is a standard for providing machine-readable error details in HTTP API responses. It was designed to offer a consistent way for servers to return error information in a structured format, making it easier for clients to understand and react to issues.

#### Key Features of RFC7807

1. **Structured Error Responses**: RFC7807 proposes a standard format for error messages, including fields like `type`, `title`, `status`, `detail`, and `instance`. This structure ensures that error information is conveyed in a predictable and easily parsable manner.
2. **Extensibility**: The standard allows for custom properties to be added to the error response. This means that while there's a common base of error information, additional details specific to an application or domain can be included.
3. **Machine-Readable and Human-Friendly**: The error responses are designed to be both machine-readable (easy for software to parse) and human-friendly (easy for developers to understand and debug).
4. **Uniform Handling of Errors Across APIs**: By adhering to a standard, it simplifies the client's task in handling errors because the format remains consistent across different APIs.


# Changelog and Versioning

The Verify by Tiller API is continuously evolving, with new features and updates being added to enhance functionality and user experience. This section provides information about our versioning policy and a changelog that details the historical and recent changes to the API.

## Versioning Policy

Our API versioning is designed to ensure backward compatibility and minimise disruptions to your integration.

* **Version Format:** We use a simple versioning, vX, where X is the major version.&#x20;
* **Major Versions:** Changes in the major version indicate significant updates that may not be backwards compatible. These changes could include modifications to existing endpoint functionality or removing endpoints. This will alter the API base URL.&#x20;

```url
https://api.tiller-verify.com/api/{version}/ext/{endpoint}
```

* **Minor Changes:** Minor version updates involve backward-compatible additions or enhancements, such as adding or extending new endpoints. These will not change the base URL.


