| Instrument31 CFR 1020.220 — Customer Identification Program | What it governsVerification of identity within a reasonable time using documentary or non-documentary methods, on a risk basis. | How this service meets itSupplies the documentary-method analysis and the written record of what was examined and why it was sufficient. |
| InstrumentFFIEC BSA/AML Examination Manual | What it governsExaminer expectations for customer due diligence, enhanced due diligence and documented rationale. | How this service meets itDeterminations are written in the structure an examiner reads: evidence, method, conclusion, limitation. |
| InstrumentFATF Recommendation 10 | What it governsIdentification and verification using reliable, independent source documents, data or information. | How this service meets itAddresses the case the recommendation anticipates but most stacks do not handle: reliable documents from a jurisdiction with no queryable source. |
| InstrumentNIST SP 800-63A-4 (July 2025) | What it governsIdentity evidence strength and validation of evidence against the issuing or an authoritative source. | How this service meets itProvides the reasoned assessment where validation against the issuing source is unavailable, and states plainly what that limits. |
| InstrumentICAO Doc 9303 | What it governsMachine-readable travel document specification, including machine-readable zone structure and transliteration of Arabic-script names. | How this service meets itPassport review follows the specification; the name graph uses its transliteration as one of its standards. |
| InstrumentUNSC Resolution 1988 list · OFAC SDN | What it governsName screening obligations against lists whose Afghan entries carry original-script names, approximate dates of birth and absent identification numbers. | How this service meets itScreening notes work the original script, not a single romanisation, and record the discriminators used. |
| InstrumentRegulation (EU) 2024/1624 (AMLR) and AMLA | What it governsHarmonised customer due diligence across the European Union, with reliance and record-keeping rules. | How this service meets itEvidence files are produced in a form a relying institution can hold and an authority can inspect. |
| InstrumenteIDAS 2.0 and the EU Digital Identity Wallet | What it governsPerson identification data and electronic attestation of attributes as Member State wallets come into service. | How this service meets itAttribute-level output is structured for attestation flows, not only for a human file. |
| InstrumentGDPR Articles 9 and 35 · UK GDPR | What it governsSpecial category data and data protection impact assessment for high-risk processing. | How this service meets itMinimum-necessary intake, defined retention, named custodian, and impact assessment support for the client's own record. |
| InstrumentEU AI Act | What it governsObligations attaching to automated systems used in identity and access decisions, including human oversight and accuracy. | How this service meets itProvides the qualified human review and the documented reasoning that an automated decision cannot produce on its own. |