Questions answered

    Frequently Asked Questions

    Everything you need to know about the stablecoin checkout, and about verifying clients without collecting a thing - for tax and accountancy practices and the obliged-entity sectors that follow.

    The Money Laundering Regulations apply identically to a sole practitioner and to a major bank.

    The same verification standard, regardless of size or budget. WhyAML gives smaller obliged businesses access to that standard without collecting or storing identity documents.

    Stablecoin Checkout

    Getting paid in stablecoin, and having the client verified in the same act.

    It is a payment link you paste into the invoice you already send. Your client settles it from an account they already hold at a regulated institution, and the act of paying is what verifies them. The wallet that pays is the wallet we verified.

    Ordinary crypto checkouts verify the business receiving the money and never check the person sending it. That is why a supervised firm cannot use one - value arrives from an address with no name attached, and there is nothing to put in front of a supervisor. Ours is the only stablecoin checkout on crypto rails that verifies the payer as well as the merchant.

    See the whole thing working

    USDC and EURC only. Both are issued by Circle, both are fully reserved, and both are pegged one to one against the dollar and the euro respectively.

    We do not accept Bitcoin, Ether, or any other cryptoasset. Those move in price between the moment your client sends and the moment you look at your balance, which is not a position a practice should be put in for settling a fee. A stablecoin does not do that, which is the entire reason we chose them.

    Because somebody has already done it. Your client holds an account at a regulated institution - an exchange or a bank - that verified them properly under its own legal obligations, and remains supervised on whether it did. That work is finished, it was expensive, and it was not yours to pay for.

    What we do is observe that relationship rather than rebuild it. Your client answers a small number of questions only they could answer, then connects the account the money will come from. Control of that account is witnessed as the payment moves. No passport, no selfie, no app to download, and nothing collected or stored at any point.

    The Witness Model, in full

    Minutes, and it is final when it lands. There is no settlement window, no overnight batch, and no waiting for a bank to open on Monday.

    Card money takes one to three days to reach you, and can still be pulled back weeks after the work is done while somebody argues about it. This arrives and it is yours.

    No. Once a same-chain stablecoin payment settles, it settles. There is no representment process, no chargeback exposure, and no reserve to hold against a dispute.

    That is a materially cleaner settlement position than card acceptance, where the money in your account is provisional for months. It also means you should be as careful about who you invoice as you always were - finality cuts both ways, and a payment taken in error has to be refunded deliberately rather than clawed back automatically.

    Yes. A client can settle part now and the balance later, on the same link, without losing the compliance evidence attached to it. Each payment is its own verification event, so the evidence in your file is from the day the money moved rather than from onboarding.

    A bank transfer moves the whole amount or none of it, which is why most practices never ask for anything up front. Being able to ask for a deposit commits the client before the work starts.

    The payment arrives already matched to the invoice and the client, with the day's conversion figure attached, and reconciles into Xero, QuickBooks or FreeAgent the same day.

    Pay.UK research puts manual reconciliation at 3.6 hours a week for a small business - roughly 166 hours a year that nobody bills for. Opening the bank, finding the payment, finding the invoice, ticking it off. That is the work this removes, because the payment and the record were never separate to begin with.

    One Single Portal Credit. That one flat credit covers every cost of accepting the payment in full - network fees, identity verification, sanctions and PEP screening, and the compliance certificate. No transaction fee is charged, and no card-processing fee of 1.5 up to 3.5 percent applies.

    Credits are bought in packs and stay valid for 24 months. There is no subscription, no minimum, and no contract, so a quiet quarter costs you nothing.

    The packs and what they cost

    Yes. Sanctions and Politically Exposed Person screening runs as part of onboarding a client, and the result is recorded on the compliance certificate next to the verification itself. Both carry the same timestamp, so the screening and the identity evidence sit in one document rather than two.

    The cost is inside the Single Portal Credit. It is not metered and it is not billed separately from the payment.

    We are not certified under the UK digital identity and attributes trust framework, and we are not seeking certification. Certification requires the check to be carried out from a document, and this method is built to avoid holding documents, so the two do not fit together. The screening a certified process would include is still performed.

    As with everything else here, this supports your own customer due diligence. It does not discharge your obligation, and the decision on whether to act for a client remains yours.

    What we hold about your clients

    Yes, and you already know this better than we do. Converting a cryptoasset into a stablecoin is a disposal for capital gains purposes in exactly the same way that converting it into sterling is. Paying you in stablecoin carries no tax advantage over paying you in pounds, and nothing about this product changes that.

    We mention it because it comes up, not because it is a feature. The tax position of your client's disposals is your professional judgement, on your file. We verify who paid you and we settle the invoice.

    If a check fails on our side, you keep the credit. You are not charged for our problem.

    If the check completes and returns a result you are not comfortable with, that is a different thing. The evidence goes in your file and the decision on whether to act for that client remains yours - as it always was. We supply evidence that supports your verification and your documented procedure. It does not discharge your obligation, and no product can.

    You need a wallet for the stablecoin to arrive into, and that is the extent of it. The payment is wallet to wallet. We never hold your money and we never hold your client's money, so there is no client money to account for and no capital to hold against it.

    There is nothing to install, nothing to migrate, and no IT project. Bank transfer still works, cards still work if you take them, and this sits alongside for the clients and the invoices where it fits.

    Around six million UK adults hold crypto, and some of them are already your clients or would like to be. They hold value they cannot easily spend with you, and they struggle to find an adviser who understands disposals, staking and the rest of it. Accepting stablecoin is the loudest available signal that you do.

    The rest is operational. Money that arrives in minutes and cannot be reversed, deposits you can actually ask for, and a Friday afternoon you get back.

    Want to see it end to end? The stablecoin checkout, explained →

    The Basics

    Understanding what WhyAML is and why it exists.

    WhyAML is a assemble-free identity-verification platform built for businesses with anti-money-laundering obligations. It lets you verify that your clients are who they say they are - in line with UK AML rules - without ever handling a single identity document.

    The platform is operated by Go 2 Glory Ltd. The consumer-facing verification product carries the brand name WhyAML, because AML is the experience your client has.

    Why AML, and why this way

    As an estate agent, tax accountant, solicitor, lender, or other regulated business, you are classified as an 'obliged entity' under the UK Money Laundering Regulations 2017. Parliament has given you a specific responsibility to check who your clients are before working with them. It is not optional, and it applies to every business in your sector regardless of size.

    The rules apply identically to you and to a major bank. The difference is that the bank has a dedicated compliance team and infrastructure built over decades, and you do not. WhyAML closes that gap by giving you access to the same standard of verification the large institutions use, at a price that fits a smaller business.

    Identity checks are a standard obligation for every firm in your sector - HMRC supervises estate agents and accountants, the SRA supervises solicitors, the FCA supervises others. What good standing looks like in practice is a consistent, documented process applied to every client, every time. That is exactly what WhyAML gives you: the same check, the same record, on every file - so when your supervisor looks, the work is already there and organised.

    See what the rules actually require

    Those are the three sectors WhyAML is launching for first, because they share a particularly clear version of the same problem: a full AML obligation, without the compliance infrastructure of a large institution. The Witness Model itself is general - it applies to any obliged entity under MLR 2017 that isn't a Tier 1 bank with its own verification stack. If your firm is supervised for AML and you're not a major institution, it's built for you.

    Still getting the gist of what WhyAML does? See the whole idea in one place →

    How WhyAML Works

    A plain-English explanation of the verification process.

    It doesn't inspect anything your client sends. It observes something that already exists: their authenticated relationship with a regulated institution that has already verified them and keeps monitoring that relationship under supervision. The institution did the identity work, and continues to. WhyAML confirms your client genuinely controls that relationship - and hands you the compliance record. Nothing is collected from your client, because the proof isn't a document they produce; it's a relationship they already hold.

    See how the verification actually works

    Today, FCA-registered crypto-asset firms such as Coinbase and Kraken - registered with the FCA for anti-money-laundering purposes under the MLRs. These firms perform contemporary KYC on their account holders and are supervised for it.

    From Phase 1, WhyAML will also verify through FCA- and PRA-regulated UK banks via read-only Open Banking, under WhyAML's RAISP registration. The principle holds in both cases: the reliable, independent source is the regulated institution itself - not a document about your client.

    They answer a short set of questions only they could answer, confirm a connection to an institutional account they control, and supply a recent email from that institution which the platform cryptographically verifies. They never upload an identity document, take a selfie, or install an app. What they're doing is proving control of something already theirs - not assembling a new file about themselves for you to hold.

    Real exchange emails carry an invisible cryptographic signature called DKIM, which proves the email genuinely came from the institution's domain and was not altered in transit. By verifying that signature, WhyAML confirms your client's institutional relationship is real - without ever contacting the institution or needing its cooperation.

    The email is read inside a sealed, hardware-isolated environment. No member of WhyAML staff ever sees its contents, and the file itself is never retained - only the result of the check is recorded.

    No - and that is deliberate. G-RADE™ (confidence scoring) reads each client's institutional history and asks for exactly as much proof as their profile warrants. A strong, recent regulated relationship clears on fewer signals; a more complex profile is asked for more, until the same confidence is reached. This is the risk-based approach the Regulations describe, turned into evidence - not one blanket check applied to everyone regardless.

    Near-approved status means the verification is materially complete and awaiting one final confirmation - usually a routine transaction your client was going to make anyway. You can continue your working relationship during this time, but the formal certificate is only issued once the process is fully complete. Do not treat near-approved status as a finished verification for the purpose of starting a regulated business relationship.

    None of them. The verification works by witnessing your client's authenticated relationship with a regulated institution, so there is no selfie, no liveness scan, no biometric captured, and nothing to install. That is not a convenience feature bolted on - it is a consequence of the method. A check built on observing a real relationship has no need for a photo of a face, which is also why it cannot be defeated by a synthetic one.

    No selfie, no app - why it works

    Want to know why this method holds up? Read the architectural brief →

    Your Clients' Data

    Why WhyAML is safer - for you and for them.

    The platform holds only the minimum necessary: your client's name, address, and wallet address. The exchange connection used to confirm control of the account is read inside a sealed, hardware-isolated environment; only the result of the check is recorded, and the email itself is never stored.

    No passport copies. No bank statements. No utility bills. The sensitive documents that traditionally sit in filing cabinets and shared drives - the ones that make small businesses targets for identity theft - are never collected in the first place.

    How this meets UK GDPR

    Operational data is held in encrypted, secure cloud infrastructure based in the EU, subject to UK data protection law. An independent technology audit covers how data is handled at every stage. The architecture is designed so that the personal information held about your client is genuinely minimal - data minimisation in fact, not just in policy.

    When verification is complete, your client receives an encoded record on the blockchain called a Compliance Token. It contains no personal information - no name, no address, nothing readable. It is an anti-fraud signal of verification, written as a native part of how the system works.

    Your client holds it in their own wallet. Under the Data (Use and Access) Act 2025 and UK GDPR Article 20, the verified-status record is theirs to hold and to port - they can use it in a future verification or keep it private, and the protection works either way.

    You receive a Broker Compliance Certificate - a clean, downloadable record confirming the verification was completed, the confidence band achieved, the timestamped flow of each step, and the regulations satisfied. The Technological Due Diligence assessment and the Certificate Terms of Use are appended in full.

    This is your evidence of compliance. You store it, and if a regulator examines your process, this is what you show them. The underlying personal data never enters your systems.

    UK law requires AML verification records to be kept for five years, and WhyAML meets this automatically. Your Broker Compliance Certificates are stored in your portal. Your client's on-chain record is permanent and independently verifiable - it cannot be lost, altered, or deleted.

    Most of the cyber risk a smaller firm carries on AML comes from one place: holding identity documents it doesn't have institutional infrastructure to protect. The regime asks you to perform an institutional security function on a non-institutional budget. WhyAML's answer isn't tighter security around the documents - it's not collecting them. There is no filing cabinet, no shared drive, no inbox folder of passports. What can't be lost is what was never gathered.

    Want the legal backing behind all this? See every regulation we satisfy →

    The Architecture

    Why this approach exists, and why it works.

    A passport is a piece of paper. The institution behind your client - the bank or regulated exchange they actually use - has already verified their identity to a far higher standard than any single document could provide, and continues to monitor the relationship under statutory obligations. Checking the passport gives you a copy of a document; checking the institutional relationship gives you the supervised, ongoing verification the institution maintains.

    In a world where AI-generated passports are increasingly difficult to detect - a 311% increase in synthetic identity documents between Q1 2024 and Q1 2025 - the document-centric model has a structural weakness. The Witness Model does not.

    Read the architectural brief

    Under the document-centric model, your client's identity documents end up in every database they applied to - including every deal that never completed. Most people have no idea how many copies of their passport and bank statements sit in the systems of firms they never did business with.

    Under the WhyAML model this doesn't happen. The verification is recorded once, and your client controls who has access. If a deal doesn't complete, no identity documents were ever collected - the honeypot doesn't exist because the documents were never gathered.

    Read the architectural brief

    No. The architecture is rail-agnostic - it observes the user's authenticated relationship with a regulated institution, whatever rails that institution operates on. Today the platform observes on-chain activity at FCA-registered crypto-asset firms. From Phase 1 it will observe read-only Open Banking signals at FCA- and PRA-regulated UK banks, under WhyAML's RAISP registration.

    The principle does not change between phases: the institution did the identity work, the client's ongoing economic activity is the proof, and WhyAML witnesses the result. Your client doesn't need to be a crypto specialist - they need a real, authenticated relationship with a regulated institution.

    Read the architectural brief

    AML exists to enable financial investigation. Under the document-centric model, if fraud is discovered after the verification, the trail ends at the document accepted at onboarding - and if that document was synthetic, there is nothing for an investigator to follow.

    Under the Witness Model, the trail leads upstream into the regulated institution's own records, its ongoing monitoring, and its supervisory oversight. An investigator reaches the institution that actually performed and maintains the underlying verification - not a piece of paper that may or may not be real.

    Read the architectural brief

    Curious why the document model breaks down? Read The AML Paradox →

    What Makes WhyAML Different

    Why this is not just another compliance tool.

    You end up in the same place on your file - a verified client - but you get there without ever taking custody of their documents. A passport copy in your inbox is a liability you are then responsible for protecting, indefinitely, and it is your problem if it leaks. WhyAML verifies the same identity without that document ever existing in your systems. Nothing collected is nothing to lose.

    On the one thing that has to be true for your file, WhyAML gives you exactly what they do: a regulator-ready compliance record. Everything else is different. Other digital services - selfies, document scans, liveness checks - still inspect a document; they have simply moved the inspection on-screen. WhyAML inspects no document at all. It observes that your client already holds a verified relationship with a regulated institution, and reports the result.

    As far as we are aware, it is the only AML verification service in the UK that collects no identity document from the client at any stage. That is not a faster way of doing the usual thing - it is a different thing.

    See the difference, side by side

    No. WhyAML does not contact the institution, request anything from them, or require their participation. The verification is based entirely on evidence your client generates themselves through their own financial activity. Nothing is asked of the institution - only its existing, externally verifiable evidence of your client's authenticated relationship is observed.

    WhyAML's verification engine - including the G-RADE™ (confidence scoring) system and the multi-level proof architecture - is Patent Protected. The approach is a new verification standard rather than a faster version of document checking.

    Most are, and many prefer it. Sending a passport copy to a firm over email is something clients have quietly learned to be uneasy about, even when they go through with it. Verifying through a regulated relationship they already hold asks them to do less, not more, and leaves no document in your systems for them to worry about afterwards. It is a different experience on their side - not just a different mechanism on yours.

    Seen enough to judge it for yourself? Open an account → Signing up is separate from buying credits, so there is nothing to commit to yet.

    Getting Started

    What you need to do to get up and running.

    Complete the WhyAML onboarding process: accept the Client Terms of Service, review and sign off the Technological Due Diligence assessment (which becomes part of your Practice-Wide Risk Assessment file), and integrate the platform into your client onboarding workflow.

    WhyAML lets you set your minimum confidence threshold during onboarding. A higher setting means more verification steps for your clients and greater evidential certainty for you; a lower setting asks fewer steps of straightforward clients. Your setting should reflect the risk profile of your typical client and is documented in your Practice-Wide Risk Assessment.

    It depends on the client's institutional history, because the process asks for proportionate proof - a straightforward profile clears on fewer steps than a complex one. For some clients the final confirmation completes when they next make a routine transaction they were going to make anyway. You and your client always see exactly where they are in the process, so there is never a black box.

    The platform will indicate clearly that an alternative verification method is needed. Traditional document-based verification remains available for those cases - but for any client with an authenticated relationship at an FCA-registered institution, the Witness Model is the better path.

    WhyAML provides onboarding support, a knowledge base, and direct access to our team for queries about the platform and its use. For questions about your specific legal obligations, we recommend speaking with your professional body or a specialist adviser - our job is to give you the best possible tool, not to replace professional advice.

    The Regulations don't require a UK address or a utility bill - they require a reliable, independent source. For an expat, a recent arrival, an international tenant, or any client without standard UK paperwork, WhyAML verifies through their existing FCA-registered exchange (with UK banks via read-only Open Banking coming in Phase 1), regardless of address history. The client who is hardest to verify on documents is often the most straightforward to verify on a relationship.

    Verifying a client with no UK address

    Yes. Pricing is per check, with no monthly minimum and no contract - you pay for the checks you do and nothing else. Making institutional-grade verification reach a single-partner firm is the whole point, not an afterthought.

    See pricing

    Ready when you are. Create your account → - separate from buying credits - then see pricing whenever you want to top up.

    In short

    The same standard - without collection, downloads, or biometrics.

    Every WhyAML verification meets the reliable-and-independent-source requirement of Regulation 28 while collecting no identity documents from your client. The sensitive data that document-based checks accumulate is never gathered by you or us.

    Your records are auditable and timestamped, and your client keeps a portable record of their own verified status.

    WhyAML is the only AML verification service operating in the UK that doesn't assemble or collect identity document from the customer at any stage.

    Read how the Confidence Architecture works

    Ready to get started?

    See how WhyAML fits your client-onboarding workflow.