# Zyphe: full content map for LLMs This file is the full machine-readable content of zyphe.com, intended for AI crawlers and large language models that ground answers in source content. Zyphe is the AI agents platform for compliance. We build audit-ready AI agents that work inside the compliance systems regulated companies already use. Our agents reason, take action, and complete cases across KYC, KYB, AML, sanctions, transaction monitoring, EDD, ongoing monitoring, and audit preparation, on a privacy-first substrate that never stores customer PII centrally. --- ## Hero positioning The AI agents platform for compliance. KYC, KYB, and AML decisions, made without ever holding your customers' PII. Trusted by EU, UK, and US compliance teams at fintechs and exchanges. --- ## Capabilities ### Agents act inside your stack Zyphe agents log into your existing case management, KYC/KYB, AML, and ticketing tools. They reason over data, take action, and complete reviews, replicating the workflows of your best analysts. ### Leading risk reasoning models Agents leverage state of the art reasoning models tuned for compliance workloads: KYC verification, UBO mapping, sanctions screening, transaction monitoring, and EDD. ### Privacy-first audit substrate Decentralised PII storage means there is no central honeypot to breach. Every decision carries a documented rationale and audit trail compliance officers can defend to regulators. --- ## Services in detail ### KYC verification Customer identity verification with document, biometric, and NFC chip read on a privacy-first substrate. ### KYB and periodic reviews Entity formation checks, registry lookups, UBO mapping, and periodic refresh on schedule or on trigger events. ### Anti-money laundering investigations Triage L1 alerts and complete L2 cases faster with Zyphe AI agents. ### Sanctions, PEP and adverse media Resolve hits against watchlists and providers you already use, with false-positive disposition and escalation drafting. ### Transaction monitoring Disposition TM alerts, surface typology patterns, draft SAR/STR narratives inside your existing TM platform. ### Enhanced due diligence Complete consumer and business EDD processes that used to take hours in minutes. ### Ongoing monitoring Periodic KYC refresh, dynamic risk reassessment, trigger-event handling. ### Audit preparation Cleaned-up case files, structured sampling, narrative consistency review, regulator-ready evidence packs. ### Document review IDs, proof of address, corporate documents, source of funds documents reviewed against your acceptance matrix. ### Case management Agents work inside your case manager (Unit21, Hummingbird, Sumsub, Sift, Alloy, Persona, or in-house). ### Custom agents Forward Deployed Engineering helps build novel agents for your unique business model on top of our privacy-first substrate. --- ## Operated review desks (compliance as a service) Zyphe also runs compliance operations work as operated desks rather than as software the customer runs. Agents work an agreed queue against the customer’s own policy and produce a decision-ready file with a written rationale; the customer approves. The following decisions are never taken by Zyphe, because Article 18(3) of Regulation (EU) 2024/1624 provides that they shall not be outsourced under any circumstances: - The proposal and approval of your business-wide risk assessment - The approval of your internal policies, procedures and controls - The decision on the risk profile attributed to a customer - The decision to enter into a business relationship or carry out an occasional transaction - Reporting suspicious activity, or threshold-based reports, to your FIU - The approval of the criteria used to detect suspicious or unusual transactions Two qualifications belong with that list. Article 18(3)(e) permits FIU reporting to be outsourced to another obliged entity in the same group and established in the same Member State. Article 18(7) lets a collective investment undertaking without legal personality outsource points (c), (d) and (e) to one of its service providers, once it has notified its supervisor and the supervisor has approved. Neither reaches a typical bank, payment institution, electronic money institution or crypto-asset service provider. Approving an individual alert disposition is not itself an Article 18(3) requirement. The Regulation governs the decisions listed above; how much of the rest your team reviews is set by your own policy. Zyphe returns every case for approval because that is the service boundary we sell, not because a regulation compels it case by case. Article 18(1) of the same Regulation permits outsourcing of other tasks provided the supervisor is notified before the service provider starts. Article 18(2) treats the provider as part of the obliged entity, leaves the obliged entity fully liable, and requires it to be able to demonstrate to its supervisor that it understands the rationale behind the provider’s activities. The Regulation applies from 10 July 2027. ### Sanctions and PEP alert review Sanctions and PEP alert review is the work of deciding whether each screening hit is a true match to a designated person or entity, or a false positive to be discounted. Zyphe runs it as an operated desk: agents pull the customer record and the list entry, compare names, dates and identifiers against your matching policy, and produce a written disposition for every alert. Your analysts approve. The decisions EU law reserves for the obliged entity, including the customer risk profile and whether to enter a business relationship, stay with your team. **URL**: https://www.zyphe.com/agents/sanctions-pep-alert-review **How the desk works** - Pull the whole picture: The agent retrieves the customer record you hold, the list entry that triggered the alert, and every previous disposition on the same customer, so a hit discounted last quarter is not investigated from a blank page. - Compare against your policy: Names, dates and places of birth, nationality and any document identifiers are compared using your matching rules and thresholds, not a generic default the vendor prefers. - Write the disposition: Each alert gets a plain-language rationale: which fields matched, which did not, which sources were checked, and why the conclusion follows from them. - Escalate what is not clear: Genuine identity overlap, a weak but plausible match, or a designation that has changed in substance goes to your analyst with the evidence already assembled and the open question stated. - Hand over a file, not a verdict: Every alert leaves the desk with its evidence and reasoning attached, in a form your case management system and your audit trail can both accept. **What this desk will not do** - Set or tune your matching thresholds - Decide a customer's risk rating - Approve or reject an onboarding - File a suspicious activity report on your behalf - Change your screening policy ### Adverse media review Adverse media review, also called negative news screening, is the work of checking whether press coverage and public records about a customer indicate financial crime risk. Most of what a screening tool surfaces is noise: a namesake, a story where your customer is the victim rather than the subject, or an article too old to bear on today's risk. Zyphe runs the review as an operated desk. Agents read the underlying sources, resolve whether the coverage is genuinely about your customer, classify it against your risk taxonomy, and produce a cited summary. Your analysts decide what it means for the relationship. **URL**: https://www.zyphe.com/agents/adverse-media-review **How the desk works** - Read the source, not the headline: Aggregated snippets routinely drop the qualifier that changes the meaning: charges dropped, a person named as a witness, an allegation attributed to a party rather than established. The agent opens the underlying item and works from its text. - Resolve the entity: The agent establishes whether the person or company in the coverage is actually your customer, using date of birth, location, employer, corporate identifiers and the surrounding detail, and records what the resolution rests on. - Classify against your taxonomy: Each relevant item is placed against your own categories: predicate offence type, the customer's role in the story, the date, and the credibility of the outlet. Your taxonomy, not a generic risk label. - Summarise with citations: The customer gets one summary that a reviewer can act on, with every assertion linked to the item it came from, so nothing rests on the agent's paraphrase alone. - Escalate the material findings: Anything that plausibly changes the risk picture goes to your analyst with the reading already done and the open question stated plainly. **What this desk will not do** - Define your adverse media taxonomy or lookback period - Decide what is material to your risk appetite - Exit or restrict a customer relationship - File a suspicious activity report on your behalf - Treat an unverified allegation as an established fact ### UBO and EDD review Enhanced due diligence is the deeper investigation a regulated firm runs on higher-risk customers, and beneficial ownership resolution is the part of it that traces who ultimately owns or controls a company. Zyphe runs both as an operated desk: agents map the corporate structure, walk each layer through the registries until they reach natural persons, screen those people against sanctions, PEP and adverse media sources, and assemble the file with the gaps stated rather than glossed. Your team sets the customer's risk profile and decides on the relationship, both of which AMLR Article 18(3) reserves to your firm. **URL**: https://www.zyphe.com/agents/ubo-edd-review **How the desk works** - Map the structure: The agent establishes the immediate corporate picture from the registry of incorporation: entity status, directors, filed shareholders, and the identifiers that let the next layer be traced. - Walk the chain to natural persons: Each corporate shareholder is followed through its own registry, layer by layer, until the chain reaches natural persons or reaches something that cannot be resolved. Zyphe runs registry checks against 240+ corporate registries worldwide. - Apply your ownership threshold: Zyphe defaults to a 25% beneficial ownership threshold, configurable per risk tier, and records control exercised by other means where the shareholding alone does not capture it. - Screen everyone the chain produces: Every natural person identified is screened against sanctions, PEP and adverse media sources, and the results are attached to the position they hold in the structure rather than to a flat list of names. - Document what did not resolve: Opaque layers, nominee arrangements, registries with no public filing and contradictions between sources are written into the file as open items. A gap recorded is defensible at audit. A gap smoothed over is not. **What this desk will not do** - Set your beneficial ownership threshold or EDD triggers - Decide the corporate customer's risk rating - Approve or reject an onboarding - Declare an unresolved chain resolved - File a suspicious activity report on your behalf ### Transaction monitoring alert triage Transaction monitoring alert triage is the work of deciding which rule-triggered alerts reflect genuine suspicion and which are ordinary account behaviour. Zyphe runs it as an operated desk: agents reconstruct the transaction history behind each alert, test it against that customer's own established pattern and against your typology library, and produce a written disposition, with a draft narrative where escalation is warranted. Your investigators approve. The decision to report to the FIU never leaves your firm, because AMLR Article 18(3)(e) does not allow it to. **URL**: https://www.zyphe.com/agents/transaction-monitoring-alert-triage **How the desk works** - Reconstruct the account picture: The agent pulls the transaction history around the alert, every prior alert on the same customer, how each was dispositioned, and what the customer declared about expected activity at onboarding. - Test against that customer's baseline: An alert only means something relative to what is normal for this customer. Seasonal trade, a funding round, a payroll cycle and a genuine structuring pattern all breach the same threshold and read completely differently against the customer's own history. - Apply your typologies: Your rules, your thresholds, your typology library. The desk applies the detection criteria you approved rather than importing a generic pattern set and calling it best practice. - Draft the disposition or the narrative: Alerts that resolve get a reasoned close. Alerts that do not get a narrative drafted in your house format, with the supporting facts assembled, for your investigator to amend, approve and file. - Write it back where you work: The disposition and its evidence return to your monitoring or case management platform, in the structure your audit trail already expects. **What this desk will not do** - Write or tune your detection rules and thresholds - Close an alert without your approval - Decide a customer's risk rating - File a suspicious activity report on your behalf - Decide whether to exit a relationship ### KYC periodic review and refresh KYC periodic review, also called ongoing due diligence or KYC refresh, is the work of re-verifying existing customers on a schedule or when something changes. Zyphe runs it as an operated desk: agents pull the file you already hold, re-run the checks your policy requires for that risk tier, and compare the result against what was decided last time. The output is a diff, not a fresh dossier, so your reviewer reads what actually changed. Your team approves the refreshed risk profile, which AMLR Article 18(3)(c) reserves to your firm. **URL**: https://www.zyphe.com/agents/kyc-periodic-review-refresh **How the desk works** - Pull the file you already hold: The agent starts from what was decided at onboarding or at the last review, and on what evidence, so the review measures change rather than starting from a blank page. - Re-run what your policy requires: Identity, address, corporate registry, ownership and screening checks are re-run to the depth your policy sets for that risk tier, not to a single depth applied to everybody. - Diff against the file: The output is the delta. Unchanged items are marked unchanged and take none of your reviewer's attention. This is the step that turns a periodic review from a re-read into a decision. - Flag what actually matters: A new beneficial owner, a designation on a related party, an expired identity document, a registry filing that contradicts what you hold, or activity outside the declared profile. - Prepare the refreshed file: Findings, evidence and dates are assembled into a file your reviewer can approve, with any exception listed explicitly rather than left as a silent gap. **What this desk will not do** - Set your review cycles or trigger definitions - Decide the refreshed risk rating - Waive a missing document or an unmet standard - Offboard a customer - Mark a file complete when evidence is missing --- ## Industries ### KYC for Fintech **Summary**: Reusable identity for neobanks, BaaS providers, payment companies, and lenders. Stop re-verifying the same customer across products and partners. **URL**: https://www.zyphe.com/industry/kyc-for-fintech ### KYC for Casino **Summary**: Age verification, source of funds, GAMSTOP, and EDD across MGA, UKGC, AGCO, and ADM. Players bring a portable credential; operators stop losing the deposit at document upload. **URL**: https://www.zyphe.com/industry/kyc-for-casino ### KYC for iGaming **Summary**: KYC for iGaming across sportsbook, DFS, casino, and lottery on one player base. Multi-state US ready, GeoComply-compatible, perpetual monitoring built in. **URL**: https://www.zyphe.com/industry/kyc-for-igaming ### KYC for Crypto **Summary**: MiCA-aligned KYC for crypto exchanges, wallets, on-ramps, and DeFi platforms. Verify users in 190+ countries, reuse credentials across products, store zero PII. **URL**: https://www.zyphe.com/industry/kyc-for-crypto ### KYC for DAOs **Summary**: Credential-gated identity for token-voting governance, multisig signer screening, treasury KYB, and grant disbursement under FATF VASP and Ooki DAO precedent. **URL**: https://www.zyphe.com/industry/kyc-for-dao ### KYC for Government **Summary**: Citizen identity for benefits, permits, and voting under eIDAS 2.0 EU Digital Identity Wallet, Login.gov, FedRAMP/StateRAMP, with sovereign data residency. **URL**: https://www.zyphe.com/industry/kyc-for-government ### KYC for Healthcare **Summary**: Prescriber identity (NPI/DEA), EPCS two-factor, patient identity matching across HIE, age verification for restricted services, HIPAA-aligned audit, no PHI honeypot. **URL**: https://www.zyphe.com/industry/kyc-for-healthcare ### KYC for Neobanks **Summary**: Reusable identity for retail neobanks running multiple products on a single customer base. Multi-jurisdictional KYC, perpetual CDD, EMI/banking licence audit-ready. **URL**: https://www.zyphe.com/industry/kyc-for-neobanks ### KYC for Banking **Summary**: Retail and commercial banking onboarding, UBO verification, correspondent-banking due diligence, perpetual CDD under FFIEC, OCC, FCA SYSC, AMLD6. **URL**: https://www.zyphe.com/industry/kyc-for-banking ### KYC for Transport **Summary**: Driver onboarding (TLC, PHV, CDL, Driver CPC), continuous background-check monitoring, Platform Workers Directive disclosures, age verification for car-sharing. **URL**: https://www.zyphe.com/industry/kyc-for-transport ### KYC for Ecommerce **Summary**: Age-gated SKUs, high-value purchase fraud, returning-customer one-tap reuse. UK Online Safety Act, US INFORM Consumers Act, GDPR Article 6 lawful basis. **URL**: https://www.zyphe.com/industry/kyc-for-ecommerce ### KYC for Marketplaces **Summary**: Two-sided platform identity under DSA Article 30 and INFORM Consumers Act, payments-aggregator KYB pass-through, P2P fraud controls without bank-grade PII retention. **URL**: https://www.zyphe.com/industry/kyc-for-marketplace ### KYC for Adult Platforms **Summary**: Age-assurance under UK Online Safety Act, Texas HB 1181, EU DSA, France ARCOM. 2257 record-keeping for performers via threshold-encrypted vaults, no PII honeypot. **URL**: https://www.zyphe.com/industry/kyc-for-adult ### KYC for Enterprise **Summary**: Unified identity across employee, customer, and supplier with SSO/IdP federation, B2B counterparty KYB, supplier due diligence, SOC 2 / ISO 27001 audit alignment. **URL**: https://www.zyphe.com/industry/kyc-for-enterprise --- ## Security and assurance - Decentralised PII storage (no central honeypot) - NFC chip read + two-step liveness - SOC 2 Type II audited - ISO/IEC 27001 certified - GDPR + AMLA compliant - Virtual private clouds - Independent model validation - Per-decision audit trail --- ## Frequently asked questions ### What is Zyphe? Zyphe is the AI agents platform for compliance. Our agents replicate the workflows of your best analysts across KYC, KYB, AML, sanctions, transaction monitoring, and EDD, inside the tools you already use, on a privacy-first substrate that means we never hold your customers PII. ### Do you replace our compliance team? No. Zyphe extends your team. Your MLRO, Head of Compliance, and internal analysts remain accountable. Agents handle the heavy data work; your team makes the final risk decisions. ### How do agents work inside our existing tools? Agents log into internal and external sources, analyse data, and take action within your existing case management, KYC/KYB, AML, CRM, and ticketing tools. ### What does "privacy-first substrate" mean? Zyphe verifies customer identity using NFC chip reads, two-step liveness, and decentralised PII storage. Personal data never sits in a Zyphe-owned database. ### Is the platform audit-ready? Yes. Every action carries a documented rationale and audit trail. Decisions are auditable per-customer, per-case, per-regulator. ### How do you ensure model and decision quality? Independent model validation, layered QA, documented review playbooks, escalation rules, and full audit trails on every case. ### Is our data secure? Decentralised PII storage, virtual private cloud deployment, SOC 2 Type II audited, ISO/IEC 27001 certified, GDPR + AMLA compliant. ### Do you support multilingual review? Yes. Agents cover English, Spanish, Portuguese, French, German, Italian, Dutch, Polish, and additional languages on request. ### How fast can we start? Most teams can begin scoping immediately, with deployment depending on tools, access, training, and risk requirements. ### Do you provide legal advice? No. Zyphe provides compliance operations automation, not legal advice. --- ## Recent blog posts - [KYB Providers in 2026: How to Compare Them After the Beneficial Ownership Shift](https://www.zyphe.com/resources/blog/kyb-providers): KYB providers verify business customers and their owners. Compare registry access, UBO depth and coverage in 2026, after the US beneficial ownership shift. - [How to Reduce KYC Drop-off: A Conversion Playbook](https://www.zyphe.com/resources/blog/how-to-reduce-kyc-drop-off-conversion-playbook): KYC drop-off quietly kills onboarding conversion. Here's a practical, step-by-step playbook to reduce KYC drop-off without ever weakening your compliance. - [KYC for Neobanks: Perpetual Customer Due Diligence on a Single Customer Base](https://www.zyphe.com/resources/blog/kyc-for-neobanks-perpetual-cdd): One customer, several products, one audit trail. See how neobanks run perpetual CDD under FFIEC and EU AML rules, and who owns liability in a BaaS stack. - [KYC for Healthcare: NPI, DEA, EPCS Two-Factor and HIPAA-Aligned Identity in 2026](https://www.zyphe.com/resources/blog/kyc-for-healthcare-2026): Healthcare identity spans prescriber, patient and age-gated users. See how NPI/DEA checks, EPCS two-factor, and HIPAA-aligned handling fit a 2026 playbook. - [Decentralized PII Storage: How Sharded Identity Architecture Removes the Honeypot](https://www.zyphe.com/resources/blog/decentralized-pii-storage): Centralized identity databases are breach honeypots. See how decentralized PII storage shards encrypted data so no single node ever holds a full record. - [KYC for DAOs After Ooki: Staying Compliant Under FATF VASP Rules in 2026](https://www.zyphe.com/resources/blog/kyc-for-daos-after-ooki): Ooki DAO set the precedent that token holders can be personally liable. Here's what FATF, the CFTC and MiCA require from DAO governance, treasury and grants. - [KYC for Online Casinos in 2026: MGA, UKGC, AGCO and ADM Requirements Compared](https://www.zyphe.com/resources/blog/kyc-for-online-casinos-2026): Online casino KYC across MGA, UKGC, AGCO and ADM sets four different bars. See what each regulator requires and where operators lose deposits at onboarding. - [KYC Without Storing Passports: Is It Possible?](https://www.zyphe.com/resources/blog/kyc-without-storing-passports): Can you run KYC without storing passports? Yes. Here's the difference between keeping a passport scan and keeping verification evidence, and how to do it. - [Sanctions Screening False Positives: The 60% Budget Drain You Can Actually Fix](https://www.zyphe.com/resources/blog/sanctions-screening-false-positives): Most of a sanctions screening budget clears noise. See where false positives originate, why name-match tuning is the wrong fix, and what OFAC expects. - [UBO Mapping With AI: Resolving Four-Tier Beneficial Ownership Chains in Under 60 Seconds](https://www.zyphe.com/resources/blog/ubo-mapping-with-ai): Beneficial ownership chains took days. See how AI UBO mapping resolves four-tier graphs across registries, scores confidence per edge, and meets FATF Rec 24. - [The TD Bank $3 Billion Lesson: What 92% Unmonitored Volume Actually Means](https://www.zyphe.com/resources/blog/td-bank-3-billion-aml-lesson): TD Bank paid about $3 billion in 2024 for AML failures, with most volume unmonitored. Here's the scope gap, and what every bank should audit this quarter. - [Building an Audit-Ready Compliance Stack: From Onboarding to SAR Filing](https://www.zyphe.com/resources/blog/audit-ready-compliance-stack): Most compliance stacks are six vendors and a diagram. Here's how to build an audit-ready compliance stack from onboarding through to SAR filing, end to end. - [KYC for iGaming in 2026: Multi-State US Compliance from Day One](https://www.zyphe.com/resources/blog/kyc-for-igaming-multi-state-us-2026): Launching across US states? iGaming KYC diverges by regulator. Here's the playbook for one customer base, 21-plus age, geolocation and multi-state onboarding. - [The Binance $4.3B Settlement: Five Compliance Architecture Lessons for VASPs](https://www.zyphe.com/resources/blog/binance-4-3-billion-settlement-lessons): Binance paid over $4.3B in 2023 and its CEO pleaded guilty. Here are five compliance architecture lessons every crypto exchange and VASP should act on now. - [AMLD6 and the AMLA Regulation: What Actually Changed for Your Compliance](https://www.zyphe.com/resources/blog/amld6-amla-2026): The EU's 2024 AML package reshapes compliance with a single rulebook and a new authority. Here's what AMLD6, the AML Regulation and AMLA require, and when. - [Zero-Knowledge KYC and Regulators: MiCA, FATF and AMLA](https://www.zyphe.com/resources/blog/zero-knowledge-kyc-regulators-mica-fatf-amla): Does zero-knowledge KYC satisfy MiCA, FATF and AMLA? An evenhanded look at where ZK proofs fit, where retention duties remain, and what actually works today. - [Correspondent Banking Due Diligence in 2026: AMLD6, FFIEC and the Nordea Lesson](https://www.zyphe.com/resources/blog/correspondent-banking-due-diligence-2026): NYDFS fined Nordea $35M in 2024 for correspondent-banking AML failures. See what FATF, FFIEC and Wolfsberg's CBDDQ require, and the gaps Nordea exposed. - [Source of Funds Verification: What the FCA, FinCEN and FATF Actually Require](https://www.zyphe.com/resources/blog/source-of-funds-verification-2026): Source of funds and source of wealth differ, and regulators treat them differently. Here's what the FCA, FinCEN and FATF require, and what documentation counts. - [The Bank Secrecy Act (BSA) Explained: Requirements, Reporting Thresholds and Compliance in 2026](https://www.zyphe.com/resources/blog/bank-secrecy-act-bsa-explained): Bank Secrecy Act reporting thresholds for 2026: the CTR and SAR dollar triggers, filing deadlines, the five pillars, who must comply, and BSA penalties. - [Persona Alternatives: Zyphe vs Persona Compared for 2026](https://www.zyphe.com/resources/blog/zyphe-vs-persona): Weighing Persona alternatives? See how Zyphe vs Persona compares on data storage, reusable credentials, pricing and configurability, and which fits best. - [Age Verification Under the UK Online Safety Act: An Operator Playbook](https://www.zyphe.com/resources/blog/age-verification-uk-online-safety-act): The UK Online Safety Act's age-check duties are live and Ofcom-enforced. Here's who must comply and what highly effective age assurance really means now. - [Crypto Compliance Software: A 2026 Comparison](https://www.zyphe.com/resources/blog/crypto-compliance-software-2026-comparison): Comparing crypto compliance software? See how on-chain analytics (Chainalysis, Elliptic, TRM Labs) and KYC layers (Sumsub, Zyphe) fit a 2026 compliance stack. - [The US Corporate Transparency Act in 2026: What FinCEN Now Requires](https://www.zyphe.com/resources/blog/corporate-transparency-act-2026): The Corporate Transparency Act changed dramatically in 2025. See who must report beneficial ownership to FinCEN now, after domestic companies were exempted. - [Best KYC Software 2026: 10 Vendors Compared](https://www.zyphe.com/resources/blog/best-kyc-software-2026): The best KYC software of 2026, ranked. Compare Sumsub, Persona, Veriff, Zyphe and 6 more on pricing, coverage, and data privacy — then pick by use case. - [AU10TIX Alternatives: Privacy-First Identity Verification Options for 2026](https://www.zyphe.com/resources/blog/au10tix-alternatives): The best AU10TIX alternatives in 2026, compared on data architecture, reusable credentials and migration effort, plus a five-step playbook for switching. - [Fourthline Alternatives: The 2026 Guide for European Compliance Teams](https://www.zyphe.com/resources/blog/fourthline-alternatives): Compare the best Fourthline alternatives for 2026: why European teams switch, how Zyphe, Sumsub, Onfido, Veriff and Jumio stack up, plus a migration plan. - [iDenfy Alternatives: Privacy-First Options for Growing Compliance Teams in 2026](https://www.zyphe.com/resources/blog/idenfy-alternatives): iDenfy is an SMB favourite for accessible KYC, but applicant documents still sit in a vendor cloud. Compare the best iDenfy alternatives for 2026, honestly. - [IDnow Alternatives in 2026: Privacy-First Options Beyond VideoIdent](https://www.zyphe.com/resources/blog/idnow-alternatives): Compare the best IDnow alternatives for 2026: why teams move beyond VideoIdent, how Zyphe removes the vendor-held PII store, and how to migrate without risk. - [Incode Alternatives in 2026: Privacy-First Options for Biometric Verification](https://www.zyphe.com/resources/blog/incode-alternatives): Why teams look beyond Incode's biometrics-led platform in 2026: the best Incode alternatives compared, plus a five-step migration playbook without disruption. - [Ondato Alternatives (2026): Privacy-First KYC Platforms Compared](https://www.zyphe.com/resources/blog/ondato-alternatives): Comparing Ondato alternatives in 2026? See how Zyphe, Sumsub, Veriff and Onfido differ on data architecture and GDPR exposure, plus a five-step migration plan. ## News - [SAR confidentiality: regulators say banks can tell customers why an account closed](https://www.zyphe.com/resources/news/sar-confidentiality-joint-statement-september-2026): FinCEN and four federal regulators clarified SAR confidentiality on 2 September 2026. What banks may now tell customers about fraud and account closures. - [The new matters requiring attention rule: what changes for BSA findings](https://www.zyphe.com/resources/news/occ-fdic-matters-requiring-attention-rule-september-2026): The OCC and FDIC final rule on matters requiring attention lands in the Federal Register. What it changes for BSA, sanctions and AML examination findings. - [Australia's IDLock will let customers switch off their own Document Verification Service checks](https://www.zyphe.com/resources/news/australia-idlock-document-verification-service-september-2026): Australia's IDLock will let people block their own documents in the Document Verification Service. What it changes for KYC onboarding and CDD obligations. - [Court blocks bulk transfer of driver's license data to federal agencies](https://www.zyphe.com/resources/news/cdlis-driver-license-data-transfer-blocked-august-2026): A US court blocked a federal demand for driver's license data from a database of 17 million commercial drivers. What it changes for KYC, privacy and vendors. - [Syria sanctions relief is not AML clearance: what the SST rescission changes](https://www.zyphe.com/resources/news/syria-sst-rescission-sanctions-relief-august-2026): Washington rescinded Syria's State Sponsor of Terrorism designation on 24 August 2026. The EU, the UK and the FATF did not follow, so due diligence stands. - [Meta age assurance settlement: certified accuracy targets and a delete-by-default rule](https://www.zyphe.com/resources/news/meta-age-assurance-settlement-august-2026): Meta's age assurance settlement sets certified false positive caps, ISO 27566 testing and a delete-by-default data rule. What compliance teams should read now. - [The DVS trust framework 1.0 reaches its earliest start date, and MLR reliance gets sharper edges](https://www.zyphe.com/resources/news/uk-dvs-trust-framework-1-0-september-2026): The UK DVS trust framework 1.0 reached its earliest start date on 1 September 2026. What certification, the CertifID mark and MLR reliance now mean for firms. - [The Missouri age verification law now in force: section 407.3405 bans the verifier from keeping anything](https://www.zyphe.com/resources/news/missouri-age-verification-law-407-3405-august-2026): Missouri's age verification law took effect on 28 August 2026. Section 407.3405 makes operators use a third party and bars that verifier from keeping data. - [FinCEN special measure would cut Banque Misr UAE off from US correspondent banking](https://www.zyphe.com/resources/news/fincen-special-measure-banque-misr-uae-august-2026): FinCEN proposed a section 311 special measure against Banque Misr UAE on 28 August 2026. What 103 suspected front companies mean for correspondent duties. - [FinCEN ends beneficial ownership reporting for US companies](https://www.zyphe.com/resources/news/fincen-ends-beneficial-ownership-reporting-august-2026): FinCEN's final rule permanently ends beneficial ownership reporting for US companies. What it changes for CDD, KYB checks, and the data already on file. - [AUSTRAC mortgage fraud findings: Operation Claw puts lenders on notice](https://www.zyphe.com/resources/news/austrac-operation-claw-mortgage-fraud-august-2026): AUSTRAC's Operation Claw found suspected mortgage fraud across 10 major Australian banks. What the findings mean for lender due diligence and SMR duties. - [QuinnBet to pay £609,104 after the Gambling Commission found its AML controls failed](https://www.zyphe.com/resources/news/quinnbet-gambling-commission-aml-controls-settlement-august-2026): QuinnBet will pay £609,104 after the Gambling Commission found its AML controls failed for 29 months. What the source of funds and SAR findings mean for firms. - [Treasury's GENIUS Act rule would make exchanges vet foreign stablecoin issuers](https://www.zyphe.com/resources/news/treasury-genius-act-foreign-stablecoin-issuers-august-2026): Treasury's GENIUS Act proposal would make crypto exchanges run due diligence on foreign stablecoin issuers before listing. Deadlines, duties and open risks. - [Foreign subsidiary sanctions liability: OFAC settles with Rice Lake over Iran diversion](https://www.zyphe.com/resources/news/ofac-rice-lake-foreign-subsidiary-sanctions-august-2026): OFAC settled with Rice Lake for 60,764 dollars after its Italian subsidiary shipped goods to Iran through a UAE distributor. What it changes for controls. - [Identity fraud drives 59% of UK fraud risk cases in Cifas H1 2026 data](https://www.zyphe.com/resources/news/cifas-identity-fraud-uk-half-year-2026): Cifas members filed over 220,000 UK fraud risk cases in the first half of 2026. Identity fraud hit 59% of them, SIM swap filings rose 402% and muling rose 69%. ## Guides - [The Payment Scam Liability: The $8 Million Cost Hidden In Your Onboarding Process](https://www.zyphe.com/guide/the-payment-scam-liability): UK PSR's 50/50 liability split makes mule accounts a direct P&L cost. What the $8M onboarding risk means for your compliance strategy in 2025 ## Glossary - [AML vs CFT](https://www.zyphe.com/resources/glossary/aml-vs-cft): AML CFT explained: what each term means, how they differ, how FATF frames AML/CFT/CPF, and why the distinction changes how your compliance program runs. - [AMLID](https://www.zyphe.com/resources/glossary/amlid): AMLID stands for the Anti-Money Laundering International Database, a secure information platform developed by the United Nations. - [Account Takeover (ATO) fraud](https://www.zyphe.com/resources/glossary/account-takeover-ato): Account Takeover (ATO) is fraud where attackers gain unauthorized access to legitimate users' online accounts, compromising personal data. - [Anti-Money Laundering (AML)](https://www.zyphe.com/resources/glossary/what-is-anti-money-laundering): Anti-money laundering is the framework of laws and controls that stops criminals disguising illicit funds. See what AML covers, the key rules, and how it works. - [Bank Account Verification & Validation Service](https://www.zyphe.com/resources/glossary/bank-account-validation-service): A bank account verification and validation service confirms an account exists, is open, and belongs to the claimed owner before money moves, cutting failed payments and fraud. - [Bank Secrecy Act (BSA)](https://www.zyphe.com/resources/glossary/bank-secrecy-act-bsa): The Bank Secrecy Act (BSA) requires financial institutions to report and track transactions to detect and prevent money laundering and terrorist financing. - [Bot protection](https://www.zyphe.com/resources/glossary/bot-protection): Understand Bot Protection, its meaning, benefits, and how it helps safeguard your website and apps from harmful automated bot traffic and attacks. - [Business lien](https://www.zyphe.com/resources/glossary/business-lien): Understand what a business lien is—a legal claim by creditors on company assets like property, receivables, or equipment used to secure debts owed. - [California Consumer Privacy Act (CCPA)](https://www.zyphe.com/resources/glossary/california-consumer-privacy-act-ccpa): Explore the California Consumer Privacy Act (CCPA), a law granting California residents enhanced rights over personal data collection, privacy, and use. - [Children’s Online Privacy Protection Act (COPPA)](https://www.zyphe.com/resources/glossary/childrens-online-privacy-protection-act-coppa): Understand the Children's Online Privacy Protection Act (COPPA), a U.S. law protecting data privacy for children under 13 on websites, apps, and services. - [Clarity Act](https://www.zyphe.com/resources/glossary/clarity-act): The Clarity Act (2025) defines U.S. crypto rules, splitting oversight between the SEC and CFTC to reduce uncertainty and protect investors. Read More. - [Combating the Financing of Terrorism (CFT)](https://www.zyphe.com/resources/glossary/combating-the-financing-of-terrorism-cft): Learn about Combating the Financing of Terrorism (CFT), laws and policies aimed at detecting and stopping funds flowing to terrorist organizations. - [Compliance as a Service (CaaS)](https://www.zyphe.com/resources/glossary/compliance-as-a-service-caas): Compliance as a Service (CaaS), a cloud-based solution helping businesses meet regulatory requirements efficiently, reduce costs, and manage risks. - [Customer Due Diligence (CDD)](https://www.zyphe.com/resources/glossary/customer-due-diligence-cdd): Understand Customer Due Diligence (CDD): how FinCEN’s rule helps financial institutions verify identities, assess risk & prevent financial crime. - [Customer Identification Program (CIP)](https://www.zyphe.com/resources/glossary/customer-identification-program-cip): Learn about Customer Identification Program (CIP): FinCEN’s rule for verifying customer identities, assessing risk & preventing money laundering. - [Data Subject Access Request (DSAR)](https://www.zyphe.com/resources/glossary/dsar-subject-access-request): A subject access request (DSAR) lets a person obtain the personal data an organisation holds on them. Here's what it covers, the timeline, and how to respond. - [Data breach](https://www.zyphe.com/resources/glossary/data-breach): Discover what a data breach is, how unauthorized access to sensitive data occurs, its potential impact, and best practices for prevention and response. - [Deepfake](https://www.zyphe.com/resources/glossary/deepfake): Learn about deepfakes: AI-generated synthetic media that convincingly mimics real people, explores risks, ethics & detection methods. - [Document check](https://www.zyphe.com/resources/glossary/document-check): Explore Document Check in KYC: verifying customer identity documents for authenticity and compliance to prevent fraud and financial crime. - [Domestic PEPs](https://www.zyphe.com/resources/glossary/domestic-peps): Domestic PEPs hold prominent public roles in their own country. See how domestic PEPs differ from foreign PEPs, their risk, and the due diligence that applies. - [Enhanced due diligence (EDD)](https://www.zyphe.com/resources/glossary/enhanced-due-diligence-edd): Understand Enhanced Due Diligence (EDD): in-depth risk assessments, increased customer scrutiny & compliance measures combating high-risk financial crime. - [False negative](https://www.zyphe.com/resources/glossary/false-negative): Learn what a false negative is: when a detection system fails to flag real threats, risks in compliance, and strategies to reduce missed cases. - [False positive](https://www.zyphe.com/resources/glossary/false-positive): Learn what a false positive is: when a detection system wrongly flags legitimate activity as a threat, its impacts, and methods to reduce such errors. - [FedNow Service](https://www.zyphe.com/resources/glossary/fednow-service): FedNow Service: Real-time payment platform for U.S. banks. Glossary definition for instant payments and financial infrastructure. - [Federal Trade Commission (FTC)](https://www.zyphe.com/resources/glossary/federal-trade-commission-ftc): The Federal Trade Commission (FTC) protects consumers and promotes competition by enforcing antitrust, privacy, and consumer protection laws. - [Federated identity management (FIM)](https://www.zyphe.com/resources/glossary/federated-identity-management-fim): Federated identity management (FIM): Secure, unified access across organizations. Key term for enterprise security and compliance glossary pages. - [Financial Crimes Enforcement Network (FinCEN)](https://www.zyphe.com/resources/glossary/financial-crimes-enforcement-network-fincen): Financial Crimes Enforcement Network (FinCEN): U.S. bureau for AML and financial crime prevention. Glossary entry for compliance terms. - [Financial Industry Regulatory Authority (FINRA)](https://www.zyphe.com/resources/glossary/financial-industry-regulatory-authority-finra): Financial Industry Regulatory Authority (FINRA): U.S. self-regulatory body for broker-dealers. Glossary term for financial compliance. - [First-party fraud](https://www.zyphe.com/resources/glossary/first-party-fraud): First-party fraud: Fraud using one’s own identity for gain. Key glossary term for financial risk and fraud prevention. - [Form W-9](https://www.zyphe.com/resources/glossary/form-w-9): Form W-9: IRS form for collecting taxpayer identification. Glossary entry for U.S. business tax and compliance terms. - [Fraud investigations](https://www.zyphe.com/resources/glossary/fraud-investigations): Fraud investigations: Process of uncovering and analyzing fraud. Essential glossary term for enterprise risk management. - [Fullz](https://www.zyphe.com/resources/glossary/fullz): Fullz: Complete stolen personal data set for ID fraud. Glossary entry for cybersecurity and financial risk terms. - [General Data Protection Regulation (GDPR)](https://www.zyphe.com/resources/glossary/general-data-protection-regulation-gdpr): General Data Protection Regulation (GDPR): EU law on personal data protection. Key glossary entry for privacy and compliance. - [Generative AI fraud](https://www.zyphe.com/resources/glossary/generative-ai-fraud): Generative AI fraud: Use of AI to create deceptive content for fraud. Glossary entry for cybersecurity and risk management terms. - [Genius Act](https://www.zyphe.com/resources/glossary/genius-act): The Genius Act (2025) sets federal rules for stablecoins: full reserves, public audits, and legal protection for users if issuers fail. - [Governance, risk, and compliance (GRC)](https://www.zyphe.com/resources/glossary/governance-risk-and-compliance-grc): Governance, risk, and compliance (GRC): Framework aligning business goals with regulations. Key glossary term for enterprise compliance. - [Gramm-Leach-Bliley Act (GLBA)](https://www.zyphe.com/resources/glossary/gramm-leach-bliley-act-glba): Gramm-Leach-Bliley Act (GLBA): U.S. law for financial data privacy and security. Glossary entry for banking and compliance. - [Graph database](https://www.zyphe.com/resources/glossary/graph-database): Graph database: Database optimized for managing relationships. Glossary term for data analysis and fraud detection. - [Health Insurance Portability & Accountability Act (HIPAA)](https://www.zyphe.com/resources/glossary/health-insurance-portability-accountability-act-hipaa): Health Insurance Portability & Accountability Act (HIPAA): U.S. law for health data privacy. Glossary entry for compliance and healthcare. - [INFORM Consumers Act](https://www.zyphe.com/resources/glossary/inform-consumers-act): INFORM Consumers Act: U.S. law increasing transparency for online sellers. Glossary entry for marketplace compliance and risk. - [Identity Assurance Levels (IAL)](https://www.zyphe.com/resources/glossary/identity-assurance-levels-ial): Identity Assurance Levels (IAL): NIST-defined levels of identity proofing rigor. Glossary entry for digital identity and compliance. - [Identity and access management (IAM)](https://www.zyphe.com/resources/glossary/identity-and-access-management-iam): Identity and access management (IAM): Controls user access to systems and data. Key glossary term for enterprise security. - [Identity authentication](https://www.zyphe.com/resources/glossary/identity-authentication): Identity authentication: Verifying a user’s claimed identity. Glossary term for cybersecurity and access control. - [Identity graph](https://www.zyphe.com/resources/glossary/identity-graph): Identity graph: Database linking identifiers to a single user. Glossary entry for digital identity and fraud prevention. - [Identity proofing](https://www.zyphe.com/resources/glossary/identity-proofing): Identity proofing: Verifying a person’s real-world identity. Key glossary term for onboarding and compliance checks. - [Identity verification (IDV)](https://www.zyphe.com/resources/glossary/identity-verification-idv): Identity verification (IDV): Confirms a user’s identity at onboarding or transaction. Glossary term for fraud prevention and compliance. - [Inherent risk](https://www.zyphe.com/resources/glossary/inherent-risk): Inherent risk: Risk level before controls are applied. Glossary term for enterprise risk management and assessment. - [KYB (Know Your Business)](https://www.zyphe.com/resources/glossary/what-is-kyb): KYB, or Know Your Business, verifies that a company is real, legally registered and safe to deal with. See what a KYB check covers and how it differs from KYC. - [KYC (Know Your Customer)](https://www.zyphe.com/resources/glossary/what-is-kyc): KYC, or Know Your Customer, is how firms verify who their customers are. See what the KYC process involves, why it matters, and how it differs from AML. - [Know Your Employee (KYE)](https://www.zyphe.com/resources/glossary/know-your-employee-kye): Know Your Employee (KYE): Due diligence to verify employee identity and background. Glossary entry for internal risk management. ## Webinars - [Your ID Documents Are About to Be Everywhere. That Should Terrify You.](https://www.zyphe.com/resources/webinar/why-decentralized-kyc-is-important-interview): ID laws mean your personal documents may be at risk. See how Zyphe lets you control your data and protect your identity online. - [Turning Compliance Into User Empowerment: Charlene Wang on The Crypto Megan Podcast](https://www.zyphe.com/resources/webinar/turning-compliance-into-user-empowerment-crypto-megan-podcast): Decentralized KYC and KYB that boost compliance and user trust — Charlene Wang on the Crypto Megan podcast. Listen now. - [Deepfakes, AI, & Data Breaches - The Latest Onboarding Trends](https://www.zyphe.com/resources/webinar/deepfakes-ai-data-breaches): Stop deepfake and AI-driven KYC fraud. Privacy-first identity verification with NachoNacho × Zyphe — free webinar, watch now. --- ## Contact - **Book a demo**: https://www.zyphe.com/contact - **Email**: hello@zyphe.com - **Coverage**: United States, United Kingdom, European Union - **Locations**: New York, London, Milan --- ## Legal scope Zyphe provides compliance operations automation, not legal advice. We do not replace your regulated compliance obligations, your MLRO, or your legal counsel. --- This file follows the llms-full.txt convention. For a condensed index see https://www.zyphe.com/llms.txt.