KYCifi combines specialist AML, KYC and virtual asset compliance expertise with intelligent technology, so customer relationships are kept current and defensible through periodic and trigger-based reviews, distinct from onboarding CDD.
The workflow tools are client software, available to KYCifi clients and engagement partners. New to KYCifi? Book a consultation and we’ll set up your access.
Onboarding is a moment; risk is continuous. Between reviews, customers change, screening lists move and relationships drift from the picture on file.
Profiles captured at onboarding age quickly and drift from reality.
Ownership, activity and product use shift, often without notice.
PEPs, complex structures and high-risk profiles need closer, recurring scrutiny.
Sanctions, PEP and adverse media lists change; a clear customer may not stay clear.
Activity must be watched between reviews, with triggers acted on promptly.
Supervisors expect periodic and event-driven reviews, evidenced consistently.
Each review must be recorded to a standard that holds up later.
The full review history must be evidenced and retained for inspection.
Every periodic or event-driven review runs the same disciplined way, so customer risk stays current and defensible.
A periodic cycle or a trigger event opens a review of the relationship.
Periodic · triggerCustomer details and ownership are refreshed against the latest position.
RefreshRecords and evidence are checked for currency, completeness and gaps.
RecordsSanctions, PEP and adverse media re-screened, and new hits adjudicated.
Re-screenRisk is re-rated against the refreshed picture and any new findings.
Re-rateWhere risk rises, enhanced due diligence and investigation are applied.
EDDA documented decision to continue, restrict or exit, with senior referral where it matters.
DecisionKYCifi is, first, a specialist AML and KYC practice with deep virtual asset experience. A new screening hit, an ownership change or a shift in activity is investigated and judged by specialists, not just re-flagged on a schedule.
Our practitioners lead every review. LÆdar AI, our intelligence platform, does the legwork behind them, so judgement stays with the people, and the review file is built as they work.
Defensible, audit-ready outputs for every review, built to the standard supervisors expect.
A complete record of each periodic or trigger-based review and its outcome.
An updated, documented risk rating with a clear, per-factor rationale.
Enhanced due diligence with investigation for relationships that escalate.
Ongoing monitoring and trigger-review records across the relationship.
A complete review history and audit trail, ready for supervisory inspection.
From exchanges to the banks that serve them, KYCifi keeps customer risk current between onboardings.
See how KYCifi combines specialist compliance expertise and intelligent technology to support virtual asset businesses.
Questions? Contact contact@kycifi.com
Guided due diligence for banks onboarding Virtual Asset Service Providers under SBP BPRD Circular No.10 of 2026. Complete all six steps to produce a structured, audit-ready KYC record.
Record the reviewing bank's details and the VASP's registration information, PVARA NOC status, and operational profile. All required fields are marked with an asterisk.
Elevated Regulatory Risk. Under SBP BPRD Circular No.10 of 2026, banks should only provide services to VASPs that are registered or in the process of registering with PVARA. A VASP that has not applied for NOC presents elevated regulatory risk. Consider whether to proceed with this review.
Record all directors, beneficial owners, and key officers of the VASP. Complete PEP status and sanctions screening for each individual. Up to 5 individuals may be recorded.
PEP Identified. A Politically Exposed Person has been identified in the VASP ownership or management structure. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval is required before proceeding.
PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.
PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.
PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.
PEP Identified. Enhanced due diligence is mandatory under AMLA 2010. Senior management approval required.
Corporate UBO Tracing Required. Corporate UBOs require full ownership tracing to identify the ultimate natural person. Obtain a corporate structure chart and shareholder registers for all corporate entities in the ownership chain.
FATF Blacklisted Jurisdiction. A UBO is from a FATF blacklisted jurisdiction. Enhanced due diligence is mandatory under AMLA 2010. Consider whether to proceed with this onboarding.
Assess the virtual assets handled, customer base profile, geographic exposure, and technology controls. These factors feed directly into the risk score calculated in Step 6.
Privacy Coins -- Elevated ML/TF Risk. Privacy coins present elevated money laundering and terrorist financing risk due to enhanced anonymity features. Specific enhanced controls are required. Consider whether this is acceptable under your bank's risk appetite.
VASP-to-VASP Relationships. Relationships with other VASPs carry elevated risk under FATF Recommendation 16. Travel Rule compliance is mandatory for all transfers with counterpart VASPs. Verify that the VASP has adequate controls for these relationships.
No Blockchain Analytics Tool. This is a significant gap in the VASP's transaction monitoring capability. A blockchain analytics tool is essential for identifying high-risk transactions, sanctions exposure, and illicit fund flows.
No Automated Transaction Monitoring. Manual monitoring processes only present elevated money laundering risk. An automated transaction monitoring system is required for effective AML controls at any meaningful transaction volume.
Review the VASP's AML/CFT/CPF programme against PVARA NOC Regulations 2025 requirements. Each No answer is a mandatory compliance gap that must be resolved before account opening.
No Board-Approved AML/CFT/CPF Policy. This is a mandatory requirement under PVARA NOC Regulations 2025. This VASP does not meet the minimum compliance standard for onboarding.
Not Registered on goAML FMU Portal. goAML FMU registration is mandatory for all VASPs under PVARA NOC Regulations 2025. The VASP cannot file STRs without this registration.
No NACTA Screening. Screening against NACTA proscribed organisations and designated persons is mandatory under PVARA NOC Regulations 2025. Failure to screen constitutes a serious compliance breach.
No MLRO Appointed. Appointment of a qualified MLRO is mandatory under PVARA NOC Regulations 2025. This VASP does not meet the minimum compliance standard.
No Travel Rule Compliance Solution. Travel Rule compliance is required under FATF Recommendation 16 for VASPs conducting virtual asset transfers. The VASP must have a technical solution for transmitting originator and beneficiary data.
Verify each condition required under SBP BPRD Circular No.10 of 2026 before providing banking services to this VASP. All 15 conditions should be met for onboarding to proceed.
Review the auto-calculated composite risk score derived from all previous steps, record the onboarding decision, complete the analyst declaration, and generate the KYC review file.
A composite risk score of 9 or above requires referral to the bank's MLRO before an onboarding decision can be recorded. Complete the referral details below.
Generate a professional compliance narrative using LÆdar AI, KYCifi's regulatory AI. The output is fully editable before being included in the downloaded review file.
Download the complete KYC review file as a PDF. The file includes all answers, the risk score breakdown, the AI narrative (if generated), and the analyst declaration. Retain on file pursuant to SBP BPRD Circular No.10 of 2026.