Overview
Risk Rules let your firm apply its own risk policy to every client automatically. This guide lists the rules you can set up, grouped by what they look at, and what each one can trigger. Your rules are built from your risk policy and signed off by your compliance stakeholder, so you choose which of these apply and what they do.
What a rule can do
When a rule is met, it can take one of the following actions. The actions available depend on the type of check.
Flag it for review: the result is marked for consider so your team takes a look.
Mark it as clear: the result passes automatically.
Ask the client to put something right: for example provide the correct identity document, a signed passport, two forms of identity, a different Proof of Address, or an additional Proof of Address.
Any client
Available actions: flag for review, or mark as clear.
Rule | What it checks | What it can trigger |
Client's country | The country the client is based in. | Flag for review or clear based on the country. |
Client's age | The client's age, worked out from their date of birth. | Flag for review (for example, under 18). |
Client location
Available actions: flag for review, mark as clear, or request an additional Proof of Address.
Rule | What it checks | What it can trigger |
International client | The client's country is different from your firm's country. | Flag for review, or request an additional Proof of Address. |
High-risk country | The client is in a country on the platform's high-risk list. | Flag for review, or request an additional Proof of Address. |
Identity documents
Available actions: flag for review, mark as clear, request the correct identity document, request a signed passport, or require two forms of identity.
Rule | What it checks | What it can trigger |
Driving licence type | Whether a UK or US driving licence is full, provisional, or under 21. | Flag for review, or request the correct document. |
Type of ID document | Which document was provided, such as a passport, driving licence, or identity card. | Request the correct document if it is not one you accept. |
Expired passport | The passport is out of date. | Request the correct document. |
Unsigned passport | The passport has not been signed. | Request a signed passport. |
Out-of-date document | Any identity document flagged as expired. | Request the correct document. |
Wrong document uploaded | The upload is not a supported identity document, for example a utility bill. | Request the correct document. |
Details do not match the document | A mismatch between the details entered and the document, such as a typo. | Flag for review, or request the correct document. |
How recently the document was issued | The number of days since a passport or driving licence was issued. | Flag for review (for example, issued very recently). |
Foreign driving licence | A driving licence issued outside your firm's country. | Flag for review. |
Number of ID documents provided | How many identity documents were captured. | Require two forms of identity. |
Date of birth matches the ID | The client's date of birth matches every document provided. | Flag for review if it does not match. |
Name matches the ID | The client's name matches every document (catches maiden versus married name). | Flag for review if it does not match. |
Recently verified elsewhere | The number of days since the client last passed identity verification on another request. | Mark as clear within a reliance window, for example 12 months. |
Proof of Address
Available actions: flag for review, mark as clear, request a different Proof of Address, or request an additional Proof of Address.
Rule | What it checks | What it can trigger |
Number of Proof of Address documents | How many Proof of Address documents were provided. | Request an additional Proof of Address, for example two for international clients. |
Name matches the ID | The Proof of Address name matches the client's identity document. | Flag for review, or request a different Proof of Address. |
Same document used for ID | The Proof of Address is the same document already used as identity. | Request a different Proof of Address. |
Age of the document | How old the Proof of Address is. | Request a different Proof of Address, for example older than 90 days. |
Type of document | Which Proof of Address was provided, such as a bank statement, utility bill, or council tax bill. | Request a different Proof of Address if it is not one you accept. |
Unsupported document | The Proof of Address is not a supported document type. | Request a different Proof of Address. |
Watchlist screening (PEPs and sanctions)
Available actions: flag for review, or mark as clear.
Rule | What it checks | What it can trigger |
Confirmed PEP (UK firms) | A confirmed politically exposed person match where your firm is UK-based. | Flag for review. |
Confirmed PEP | A confirmed politically exposed person match. | Flag for review, often combined with the international client rule. |
Confirmed sanctions match | A confirmed sanctions hit. | Flag for review. |
Confirmed sanctions match (individual) | A confirmed sanctions hit that is an individual person. | Flag for review. |
Identity fraud screening
Available actions: flag for review, or mark as clear.
Rule | What it checks | What it can trigger |
Known fraud match | The client matches a known-fraud database, such as a lost or stolen document register or an impersonation record. | Flag for review. This cannot be fixed by the client and is passed to your team for review. |
Source of Funds
Available actions: flag for review, or mark as clear.
Rule | What it checks | What it can trigger |
Gift included | The declared source of funds includes a monetary gift. | Flag for review, as a gift may need due diligence on the person giving it. |
Gift from overseas | A declared gift includes funds from overseas. | Flag for review. |
Enhanced CDD (NFC)
Available actions: flag for review, or mark as clear.
Rule | What it checks | What it can trigger |
Insufficient evidence | The Enhanced CDD (NFC) step is missing some or all of the required documents. | Flag for review. |
Risk Assessments
Available actions: flag for review, or mark as clear.
Rule | What it checks | What it can trigger |
Stayed high risk on update | An updated Risk Assessment was high risk before and is still high risk. | Flag for review. |
Important information
You choose which rules apply and what they do, based on your firm's risk policy.
Rules are set up firm-wide, so they apply consistently across your onboarding.
The set of available rules grows over time. If there is a rule your firm needs that is not listed here, let us know.
If you need more help
If you have a question about the Risk Rules you can set up, contact our Support team.
