Protecting the Art of the Deal Through Trust.

Verifying a client is a delicate moment in any sale. Our infrastructure makes your KYC and AML process seamless, secure, and fully compliant. Explore how our secure operating system simplifies your client's compliance journey below.

KYCProtect compliance platform 2026

Sensitive AML Data Deserves Purpose-Built Protection

Art market compliance records contains passports, identity documents, addresses, corporate ownership details, source-of-funds evidence, transaction context, risk decisions, and internal compliance notes. KYCProtect treats this information as sensitive from the moment it enters the workflow. The platform is designed to support secure collection, review, storage, and release of AML evidence while giving teams the visibility they need to make proportionate, risk-based decisions.

  • Identity verification records
  • Sanctions, PEP, and adverse media screening outcomes
  • Beneficial ownership and corporate buyer information
  • Source-of-funds and source-of-wealth evidence
  • Linked transaction and high-value sale records
  • Internal risk decisions, reviewer notes, and audit history

Security Controls Built Around AML Workflows

KYCProtect is designed around controlled access, secure evidence handling, and defensible record-keeping. Instead of passing sensitive files through inboxes or shared folders, teams can manage client due diligence inside a structured compliance workflow.

Role-based access

Limit what sales, operations, and compliance users can see or do.

Audit-ready activity history

Keep a record of key actions, decisions, and review status.

Secure document handling

Reduce reliance on email attachments and unmanaged file storage.

Encrypted connections

Protect data in transit between users and the platform.

Controlled review status

Let commercial teams see whether a client is cleared, pending, escalated, or blocked without exposing unnecessary personal data.

Retention-aware workflows

Support organised record-keeping for AML files and review evidence.

Four Steps to an Audit-Ready Compliance File

KYCProtect organises client due diligence into four connected steps — from identity verification to continuous monitoring. Select any step below to explore how each part of the workflow operates.

Step 1

Identity Verification

Secure document authentication via Didit

Step 2

Automated Screening

Sanctions, PEP, watchlists, adverse media

Step 3

Risk Scoring

Based on FATF-aligned typologies

Step 4

Continuous Monitoring

Alerts on changes, new risks, or media exposure

Identity Verification

Powered by Didit

KYCProtect is powered by Didit: the licensed verification source mandated for regulatory-compliant processing of all government-issued documents.

Automated Screening

Our automated screening system stays up to date by linking directly to governments and international organizations

Sanctions Screening

Coverage of all major international sanctions regimes

  • OFAC (US)
  • EU Consolidated Sanctions
  • UN Security Council
  • HM Treasury (UK)
  • Regional sanctions lists

PEP & Political Exposure

Identification of politically exposed persons and close associates

  • Government registers
  • International leadership databases
  • State-owned enterprise records
  • Relatives and close associates (RCA)

Adverse Media Monitoring

Continuous screening across 235,000+ news sources

  • Financial crime
  • Corruption & bribery
  • Regulatory violations
  • Terrorism & organised crime

Powered by automated adverse media screening via regulated data providers

Risk Scoring

Automated risk scoring informed by FATF guidance and internationally recognised typologies

Match Analysis

Evaluates the severity and credibility of sanctions, PEP, and adverse media hits

FATF Alignment

Risk levels calibrated against Financial Action Task Force typologies and red flags

Profile & Jurisdiction

Evaluates client industry, purpose of relationship, expected transaction volume, nationality, and country of residence

Deterministic Scoring

Rule-based engine producing a 0–100 score. The same inputs always produce the same result — fully explainable and audit-ready

Risk Level Framework

Low Risk (Verified & Clear)

Status: Identity confirmed. Automated screening is clear with no watchlist matches (Sanctions/PEP), and the identity document is valid and matches the profile perfectly.

Required Action: Clear. Recommended for standard onboarding.

Medium Risk (Verification Pending)

Status: Pending clarification. Screening is clear, but minor discrepancies—such as a name variation, an expired document, or a high-audit jurisdiction—require additional context.

Required Action: Request Proof of Address (POA). Collect secondary documentation to resolve data conflicts and finalize residency verification.

High Risk (Enhanced Due Diligence)

Status: Manual review required. The profile contains significant red flags, such as Adverse Media, "Soft Matches" on PEP registries, or persistent address mismatches across documents.

Required Action: Start Enhanced Due Diligence (EDD). Activates a workflow to help you collect and log additional documents like Proof of Funds or ownership context.

Critical Risk (Immediate Escalation)

Status: Compliance block. A direct match on Global Sanctions Lists has been confirmed, or there is evidence of fraudulent documentation and financial crime.

Required Action: Account blocked. Pause transaction and review internally for reporting to the Financial Intelligence Unit (FIU).

Remote KYC email workflow for art dealers

Privacy-First by Design

KYCProtect does not exist to monetise personal data. Information processed through the platform is used to support AML, KYC, sanctions screening, risk review, and compliance record-keeping for your business. For art businesses, privacy is not just a legal issue. It is commercial. Collectors, consignors, artists, intermediaries, and institutional buyers expect discretion. KYCProtect helps you request only the evidence needed for a proportionate compliance decision and keep that evidence within a controlled workflow.

Where required, KYCProtect can support GDPR-aligned processing, data access controls, and documented compliance workflows. For detailed data processing terms, request our security and data protection information.

Built for Regulator, Bank, and Internal Review

AML compliance is not complete when a passport is collected. A defensible file needs to show what was checked, why it was checked, who reviewed it, what risk indicators were considered, and how the final decision was reached. KYCProtect helps convert scattered compliance evidence into a structured case file that can support internal review, bank queries, supervisory checks, and future audits.

  • Documented customer due diligence
  • Risk-based review logic
  • Sanctions and PEP screening evidence
  • Source-of-funds reasoning
  • Corporate and beneficial ownership records
  • Reviewer notes and escalation status
  • Transaction-linked compliance context
KYCProtect mobile compliance dashboard

Designed for Galleries, Dealers, and Auction Houses

Generic KYC tools often assume a standard financial onboarding flow. Art market compliance is different. A single transaction may involve a buyer, payer, intermediary, advisor, shipping destination, corporate vehicle, beneficial owner, and artwork-specific context. KYCProtect is built around the realities of high-value art transactions: discreet collector relationships, linked transactions, fair sales, consignments, corporate buyers, repeat collectors, private placements, and cross-border AML obligations.

AML compliance workflow for an art gallery

Screening That Supports Human Compliance Judgment

KYCProtect supports sanctions, PEP, adverse media, and risk screening as part of a broader due diligence workflow. Screening results should not sit in isolation. They need to be connected to identity information, transaction context, jurisdiction, ownership structure, and reviewer judgment. The platform helps compliance teams move from a simple 'match/no match' mindset to a documented risk-based decision that can be explained later.

SubjectSCREENINGSanctionsPEP StatusAdverse MediaClearNo match!ReviewMatch foundReviewer documents decision

Security Awareness for Your Team

KYCProtect will never ask users to share passwords by email or phone. If your team receives a suspicious message claiming to be from KYCProtect, do not open links or attachments until the message has been verified. We recommend that art businesses train staff to recognise phishing attempts, domain spoofing, suspicious payment instructions, and unusual document requests, especially during high-value sales and art fair periods.

!!Suspicious messageVerifiedSafe to open

Trust FAQ

No. KYCProtect is built to support AML and KYC workflows, not to monetise personal data.
Yes. KYCProtect can support a status-based workflow where commercial users see the compliance state without unnecessary access to passports, ownership records, or source-of-funds evidence.
Yes. The platform is designed to keep AML evidence, risk decisions, and review notes organised so your team can respond with a structured file rather than reconstructing records from email and PDFs.
Yes. The platform is designed for galleries, dealers, and auction houses managing buyers, sellers, intermediaries, and transactions across jurisdictions.
Yes. Please use the buttons below to request security information or book a compliance demo.

Need to review security before starting?

If your team needs to assess data handling, access controls, AML workflow design, or security posture before using KYCProtect, we can walk you through the platform and provide additional security and data protection information.

KYCProtect is built on the principle that compliance infrastructure for the art market must meet the same standards of security and reliability as the financial institutions that AML regulation was originally designed for. The art world handles high-value, often cross-border transactions involving individuals of significant wealth and public prominence. The data collected during KYC and AML checks — identity documents, proof of address, source of funds information — is highly sensitive. Protecting it is not optional. It is a legal and ethical obligation.

All data processed through KYCProtect is encrypted in transit using TLS and at rest using AES-256 encryption. Client files, identity documents, and screening records are stored on secure, access-controlled cloud infrastructure, with strict role-based permissions ensuring that only authorised team members can view or export sensitive case data. Our architecture is designed to prevent unauthorised access and to support the data minimisation and purpose limitation principles required under GDPR.

Our sanctions and PEP screening data is sourced from authoritative, institutionally-recognised databases including OFAC (US Treasury Office of Foreign Assets Control), EU sanctions registers, FATF (Financial Action Task Force) lists, Interpol notices, FBI and DEA watchlists, and a continuously updated global adverse media index covering over 235,000 news sources in multiple languages. These sources are updated daily, ensuring screening results reflect the most current available data.

For Art Market Participants operating under 5AMLD, 6AMLD, EU Regulation 2024/1624, and the UK Money Laundering Regulations, KYCProtect provides the structured documentation trail that regulators require. Every check is timestamped and recorded in an immutable audit log. Every decision — whether to approve, escalate, or request Enhanced Due Diligence — is captured with full traceability. Case files can be exported as audit-ready PDF reports at any time, ready for submission to HMRC, national supervisory authorities, or other regulatory bodies.

Identity verification is performed using biometric liveness detection and AI-powered document analysis, comparing presented identity documents against global identity databases to confirm authenticity. This approach meets the requirements of remote Customer Due Diligence under current AML frameworks, and supports both simplified and enhanced verification workflows depending on the risk profile of each client.

KYCProtect operates under a data processor agreement with all clients, clearly defining responsibilities under GDPR Article 28. We do not share client data with third parties for commercial purposes. Data is retained only for as long as required by applicable AML regulations — typically five years from the end of the business relationship — and is securely deleted thereafter.

For art market businesses, trust in your compliance infrastructure is not a nice-to-have — it is essential. KYCProtect is designed so you can rely completely on the data you collect, the checks you run, and the records you keep. We do not cut corners on the tools that underpin your regulatory obligations.

Built for Compliance. Designed for Trust.

KYCProtect combines official global data, automated screening, and continuous monitoring to help businesses meet AML obligations while preserving customer trust and operational efficiency.

5-step AML Compliance Guide cover

Download your 5-step guide to AML Compliance

A clear, practical guide to the five key steps any art business needs to take to meet EU anti-money laundering requirements and build lasting client trust.