Frequently Asked Questions
Everything you need to know about the stablecoin checkout, and about verifying clients without collecting a thing - for tax and accountancy practices and the obliged-entity sectors that follow.
The Money Laundering Regulations apply identically to a sole practitioner and to a major bank.
The same verification standard, regardless of size or budget. WhyAML gives smaller obliged businesses access to that standard without collecting or storing identity documents.
Stablecoin Checkout
Getting paid in stablecoin, and having the client verified in the same act.
It is a payment link you paste into the invoice you already send. Your client settles it from an account they already hold at a regulated institution, and the act of paying is what verifies them. The wallet that pays is the wallet we verified.
Ordinary crypto checkouts verify the business receiving the money and never check the person sending it. That is why a supervised firm cannot use one - value arrives from an address with no name attached, and there is nothing to put in front of a supervisor. Ours is the only stablecoin checkout on crypto rails that verifies the payer as well as the merchant.
See the whole thing workingUSDC and EURC only. Both are issued by Circle, both are fully reserved, and both are pegged one to one against the dollar and the euro respectively.
We do not accept Bitcoin, Ether, or any other cryptoasset. Those move in price between the moment your client sends and the moment you look at your balance, which is not a position a practice should be put in for settling a fee. A stablecoin does not do that, which is the entire reason we chose them.
Because somebody has already done it. Your client holds an account at a regulated institution - an exchange or a bank - that verified them properly under its own legal obligations, and remains supervised on whether it did. That work is finished, it was expensive, and it was not yours to pay for.
What we do is observe that relationship rather than rebuild it. Your client answers a small number of questions only they could answer, then connects the account the money will come from. Control of that account is witnessed as the payment moves. No passport, no selfie, no app to download, and nothing collected or stored at any point.
The Witness Model, in fullMinutes, and it is final when it lands. There is no settlement window, no overnight batch, and no waiting for a bank to open on Monday.
Card money takes one to three days to reach you, and can still be pulled back weeks after the work is done while somebody argues about it. This arrives and it is yours.
No. Once a same-chain stablecoin payment settles, it settles. There is no representment process, no chargeback exposure, and no reserve to hold against a dispute.
That is a materially cleaner settlement position than card acceptance, where the money in your account is provisional for months. It also means you should be as careful about who you invoice as you always were - finality cuts both ways, and a payment taken in error has to be refunded deliberately rather than clawed back automatically.
Yes. A client can settle part now and the balance later, on the same link, without losing the compliance evidence attached to it. Each payment is its own verification event, so the evidence in your file is from the day the money moved rather than from onboarding.
A bank transfer moves the whole amount or none of it, which is why most practices never ask for anything up front. Being able to ask for a deposit commits the client before the work starts.
The payment arrives already matched to the invoice and the client, with the day's conversion figure attached, and reconciles into Xero, QuickBooks or FreeAgent the same day.
Pay.UK research puts manual reconciliation at 3.6 hours a week for a small business - roughly 166 hours a year that nobody bills for. Opening the bank, finding the payment, finding the invoice, ticking it off. That is the work this removes, because the payment and the record were never separate to begin with.
One Single Portal Credit. That one flat credit covers every cost of accepting the payment in full - network fees, identity verification, sanctions and PEP screening, and the compliance certificate. No transaction fee is charged, and no card-processing fee of 1.5 up to 3.5 percent applies.
Credits are bought in packs and stay valid for 24 months. There is no subscription, no minimum, and no contract, so a quiet quarter costs you nothing.
The packs and what they costYes. Sanctions and Politically Exposed Person screening runs as part of onboarding a client, and the result is recorded on the compliance certificate next to the verification itself. Both carry the same timestamp, so the screening and the identity evidence sit in one document rather than two.
The cost is inside the Single Portal Credit. It is not metered and it is not billed separately from the payment.
We are not certified under the UK digital identity and attributes trust framework, and we are not seeking certification. Certification requires the check to be carried out from a document, and this method is built to avoid holding documents, so the two do not fit together. The screening a certified process would include is still performed.
As with everything else here, this supports your own customer due diligence. It does not discharge your obligation, and the decision on whether to act for a client remains yours.
What we hold about your clientsYes, and you already know this better than we do. Converting a cryptoasset into a stablecoin is a disposal for capital gains purposes in exactly the same way that converting it into sterling is. Paying you in stablecoin carries no tax advantage over paying you in pounds, and nothing about this product changes that.
We mention it because it comes up, not because it is a feature. The tax position of your client's disposals is your professional judgement, on your file. We verify who paid you and we settle the invoice.
If a check fails on our side, you keep the credit. You are not charged for our problem.
If the check completes and returns a result you are not comfortable with, that is a different thing. The evidence goes in your file and the decision on whether to act for that client remains yours - as it always was. We supply evidence that supports your verification and your documented procedure. It does not discharge your obligation, and no product can.
You need a wallet for the stablecoin to arrive into, and that is the extent of it. The payment is wallet to wallet. We never hold your money and we never hold your client's money, so there is no client money to account for and no capital to hold against it.
There is nothing to install, nothing to migrate, and no IT project. Bank transfer still works, cards still work if you take them, and this sits alongside for the clients and the invoices where it fits.
Around six million UK adults hold crypto, and some of them are already your clients or would like to be. They hold value they cannot easily spend with you, and they struggle to find an adviser who understands disposals, staking and the rest of it. Accepting stablecoin is the loudest available signal that you do.
The rest is operational. Money that arrives in minutes and cannot be reversed, deposits you can actually ask for, and a Friday afternoon you get back.
Want to see it end to end? The stablecoin checkout, explained →
The Basics
Understanding what WhyAML is and why it exists.
WhyAML is a assemble-free identity-verification platform built for businesses with anti-money-laundering obligations. It lets you verify that your clients are who they say they are - in line with UK AML rules - without ever handling a single identity document.
The platform is operated by Go 2 Glory Ltd. The consumer-facing verification product carries the brand name WhyAML, because AML is the experience your client has.
Why AML, and why this wayAs an estate agent, tax accountant, solicitor, lender, or other regulated business, you are classified as an 'obliged entity' under the UK Money Laundering Regulations 2017. Parliament has given you a specific responsibility to check who your clients are before working with them. It is not optional, and it applies to every business in your sector regardless of size.
The rules apply identically to you and to a major bank. The difference is that the bank has a dedicated compliance team and infrastructure built over decades, and you do not. WhyAML closes that gap by giving you access to the same standard of verification the large institutions use, at a price that fits a smaller business.
Identity checks are a standard obligation for every firm in your sector - HMRC supervises estate agents and accountants, the SRA supervises solicitors, the FCA supervises others. What good standing looks like in practice is a consistent, documented process applied to every client, every time. That is exactly what WhyAML gives you: the same check, the same record, on every file - so when your supervisor looks, the work is already there and organised.
See what the rules actually requireThose are the three sectors WhyAML is launching for first, because they share a particularly clear version of the same problem: a full AML obligation, without the compliance infrastructure of a large institution. The Witness Model itself is general - it applies to any obliged entity under MLR 2017 that isn't a Tier 1 bank with its own verification stack. If your firm is supervised for AML and you're not a major institution, it's built for you.
Still getting the gist of what WhyAML does? See the whole idea in one place →
How WhyAML Works
A plain-English explanation of the verification process.
It doesn't inspect anything your client sends. It observes something that already exists: their authenticated relationship with a regulated institution that has already verified them and keeps monitoring that relationship under supervision. The institution did the identity work, and continues to. WhyAML confirms your client genuinely controls that relationship - and hands you the compliance record. Nothing is collected from your client, because the proof isn't a document they produce; it's a relationship they already hold.
See how the verification actually worksToday, FCA-registered crypto-asset firms such as Coinbase and Kraken - registered with the FCA for anti-money-laundering purposes under the MLRs. These firms perform contemporary KYC on their account holders and are supervised for it.
From Phase 1, WhyAML will also verify through FCA- and PRA-regulated UK banks via read-only Open Banking, under WhyAML's RAISP registration. The principle holds in both cases: the reliable, independent source is the regulated institution itself - not a document about your client.
They answer a short set of questions only they could answer, confirm a connection to an institutional account they control, and supply a recent email from that institution which the platform cryptographically verifies. They never upload an identity document, take a selfie, or install an app. What they're doing is proving control of something already theirs - not assembling a new file about themselves for you to hold.
Real exchange emails carry an invisible cryptographic signature called DKIM, which proves the email genuinely came from the institution's domain and was not altered in transit. By verifying that signature, WhyAML confirms your client's institutional relationship is real - without ever contacting the institution or needing its cooperation.
The email is read inside a sealed, hardware-isolated environment. No member of WhyAML staff ever sees its contents, and the file itself is never retained - only the result of the check is recorded.
No - and that is deliberate. G-RADE™ (confidence scoring) reads each client's institutional history and asks for exactly as much proof as their profile warrants. A strong, recent regulated relationship clears on fewer signals; a more complex profile is asked for more, until the same confidence is reached. This is the risk-based approach the Regulations describe, turned into evidence - not one blanket check applied to everyone regardless.
Near-approved status means the verification is materially complete and awaiting one final confirmation - usually a routine transaction your client was going to make anyway. You can continue your working relationship during this time, but the formal certificate is only issued once the process is fully complete. Do not treat near-approved status as a finished verification for the purpose of starting a regulated business relationship.
None of them. The verification works by witnessing your client's authenticated relationship with a regulated institution, so there is no selfie, no liveness scan, no biometric captured, and nothing to install. That is not a convenience feature bolted on - it is a consequence of the method. A check built on observing a real relationship has no need for a photo of a face, which is also why it cannot be defeated by a synthetic one.
No selfie, no app - why it worksWant to know why this method holds up? Read the architectural brief →
Your Clients' Data
Why WhyAML is safer - for you and for them.
The platform holds only the minimum necessary: your client's name, address, and wallet address. The exchange connection used to confirm control of the account is read inside a sealed, hardware-isolated environment; only the result of the check is recorded, and the email itself is never stored.
No passport copies. No bank statements. No utility bills. The sensitive documents that traditionally sit in filing cabinets and shared drives - the ones that make small businesses targets for identity theft - are never collected in the first place.
How this meets UK GDPROperational data is held in encrypted, secure cloud infrastructure based in the EU, subject to UK data protection law. An independent technology audit covers how data is handled at every stage. The architecture is designed so that the personal information held about your client is genuinely minimal - data minimisation in fact, not just in policy.
When verification is complete, your client receives an encoded record on the blockchain called a Compliance Token. It contains no personal information - no name, no address, nothing readable. It is an anti-fraud signal of verification, written as a native part of how the system works.
Your client holds it in their own wallet. Under the Data (Use and Access) Act 2025 and UK GDPR Article 20, the verified-status record is theirs to hold and to port - they can use it in a future verification or keep it private, and the protection works either way.
You receive a Broker Compliance Certificate - a clean, downloadable record confirming the verification was completed, the confidence band achieved, the timestamped flow of each step, and the regulations satisfied. The Technological Due Diligence assessment and the Certificate Terms of Use are appended in full.
This is your evidence of compliance. You store it, and if a regulator examines your process, this is what you show them. The underlying personal data never enters your systems.
UK law requires AML verification records to be kept for five years, and WhyAML meets this automatically. Your Broker Compliance Certificates are stored in your portal. Your client's on-chain record is permanent and independently verifiable - it cannot be lost, altered, or deleted.
Most of the cyber risk a smaller firm carries on AML comes from one place: holding identity documents it doesn't have institutional infrastructure to protect. The regime asks you to perform an institutional security function on a non-institutional budget. WhyAML's answer isn't tighter security around the documents - it's not collecting them. There is no filing cabinet, no shared drive, no inbox folder of passports. What can't be lost is what was never gathered.
Want the legal backing behind all this? See every regulation we satisfy →
The Architecture
Why this approach exists, and why it works.
A passport is a piece of paper. The institution behind your client - the bank or regulated exchange they actually use - has already verified their identity to a far higher standard than any single document could provide, and continues to monitor the relationship under statutory obligations. Checking the passport gives you a copy of a document; checking the institutional relationship gives you the supervised, ongoing verification the institution maintains.
In a world where AI-generated passports are increasingly difficult to detect - a 311% increase in synthetic identity documents between Q1 2024 and Q1 2025 - the document-centric model has a structural weakness. The Witness Model does not.
Read the architectural briefUnder the document-centric model, your client's identity documents end up in every database they applied to - including every deal that never completed. Most people have no idea how many copies of their passport and bank statements sit in the systems of firms they never did business with.
Under the WhyAML model this doesn't happen. The verification is recorded once, and your client controls who has access. If a deal doesn't complete, no identity documents were ever collected - the honeypot doesn't exist because the documents were never gathered.
Read the architectural briefNo. The architecture is rail-agnostic - it observes the user's authenticated relationship with a regulated institution, whatever rails that institution operates on. Today the platform observes on-chain activity at FCA-registered crypto-asset firms. From Phase 1 it will observe read-only Open Banking signals at FCA- and PRA-regulated UK banks, under WhyAML's RAISP registration.
The principle does not change between phases: the institution did the identity work, the client's ongoing economic activity is the proof, and WhyAML witnesses the result. Your client doesn't need to be a crypto specialist - they need a real, authenticated relationship with a regulated institution.
Read the architectural briefAML exists to enable financial investigation. Under the document-centric model, if fraud is discovered after the verification, the trail ends at the document accepted at onboarding - and if that document was synthetic, there is nothing for an investigator to follow.
Under the Witness Model, the trail leads upstream into the regulated institution's own records, its ongoing monitoring, and its supervisory oversight. An investigator reaches the institution that actually performed and maintains the underlying verification - not a piece of paper that may or may not be real.
Read the architectural briefCurious why the document model breaks down? Read The AML Paradox →
Your Legal Obligations
What the rules actually require - and how WhyAML addresses them.
Regulation 28 of the Money Laundering Regulations 2017 requires that identity be verified from a reliable, independent source. The Regulations do not prescribe a method; they require reliability and independence. A regulated institution that has performed and maintains comprehensive KYC under its own statutory obligations is a reliable and independent source, and WhyAML witnesses your client's authenticated connection to that source. You meet your Regulation 28 obligation using that evidence; WhyAML does not meet it for you.
Adoption of the methodology is recorded under Regulation 19(4)(c) as a risk-based approach. WhyAML provides a full Technological Due Diligence assessment, appended to every Broker Compliance Certificate, that forms part of your Practice-Wide Risk Assessment.
The full regulatory mappingNo, and it does not claim to be. The HM Treasury and DSIT Joint Guidance of 26 February 2026 confirmed that DIATF-certified Digital Verification Services are one recognised route to satisfying Regulation 28. WhyAML takes a different route: it is not a DVS and does not create a digital identity. Regulation 28 is technology-neutral - it requires identity to be verified from a reliable source independent of the person, without prescribing a single method. WhyAML witnesses your client's authenticated relationship with a regulated institution that has already performed statutory KYC; that institution is the reliable, independent source. The same guidance directs firms to sector guidance from HMRC and the JMLSG, which accommodates electronic verification on its merits - reinforcing that WhyAML sits outside the digital-identity-service category the guidance addresses, rather than inside it as a non-certified one. Adoption of this methodology is recorded under Regulation 19(4)(c) as a documented risk-based approach, supported by the Technological Due Diligence pack appended to every Broker Compliance Certificate.
Yes - that obligation sits with you as the regulated business. WhyAML provides the documentation to support it, including a Technological Due Diligence assessment that covers the platform's methodology and is signed off by your MLRO before first use.
You show them your Broker Compliance Certificates and the appended Technological Due Diligence assessment. WhyAML's deeper documentation - the provision-by-provision Regulatory Compliance Mapping that defends each requirement in detail - is available to your counsel on request. Every verification leaves a clear, auditable, timestamped record, so if a regulator examines your process, it is all there and organised.
Your existing verification records remain valid for the period they were conducted. WhyAML is for new verifications and for periodic re-verification where your obligations require it.
CARF - the Crypto-Asset Reporting Framework - adds requirements to identify and report clients with crypto-asset positions. Its due-diligence obligations are already live, in force since January 2026, with the first report to HMRC due in May 2027. If any of your clients hold or trade digital assets, it already shapes how you must identify and document them.
WhyAML verifies those clients through the regulated institutions they already use, and supplies economic-residency evidence to support the tax-residency determination you have to make - which remains yours. The evidence comes from real, authenticated activity, not a self-declaration.
The full CARF guideSatisfied it stands up? Create an account → No card and no credit purchase - sign-up just lets you look around.
What Makes WhyAML Different
Why this is not just another compliance tool.
You end up in the same place on your file - a verified client - but you get there without ever taking custody of their documents. A passport copy in your inbox is a liability you are then responsible for protecting, indefinitely, and it is your problem if it leaks. WhyAML verifies the same identity without that document ever existing in your systems. Nothing collected is nothing to lose.
On the one thing that has to be true for your file, WhyAML gives you exactly what they do: a regulator-ready compliance record. Everything else is different. Other digital services - selfies, document scans, liveness checks - still inspect a document; they have simply moved the inspection on-screen. WhyAML inspects no document at all. It observes that your client already holds a verified relationship with a regulated institution, and reports the result.
As far as we are aware, it is the only AML verification service in the UK that collects no identity document from the client at any stage. That is not a faster way of doing the usual thing - it is a different thing.
See the difference, side by sideNo. WhyAML does not contact the institution, request anything from them, or require their participation. The verification is based entirely on evidence your client generates themselves through their own financial activity. Nothing is asked of the institution - only its existing, externally verifiable evidence of your client's authenticated relationship is observed.
WhyAML's verification engine - including the G-RADE™ (confidence scoring) system and the multi-level proof architecture - is Patent Protected. The approach is a new verification standard rather than a faster version of document checking.
Most are, and many prefer it. Sending a passport copy to a firm over email is something clients have quietly learned to be uneasy about, even when they go through with it. Verifying through a regulated relationship they already hold asks them to do less, not more, and leaves no document in your systems for them to worry about afterwards. It is a different experience on their side - not just a different mechanism on yours.
Seen enough to judge it for yourself? Open an account → Signing up is separate from buying credits, so there is nothing to commit to yet.
Getting Started
What you need to do to get up and running.
Complete the WhyAML onboarding process: accept the Client Terms of Service, review and sign off the Technological Due Diligence assessment (which becomes part of your Practice-Wide Risk Assessment file), and integrate the platform into your client onboarding workflow.
WhyAML lets you set your minimum confidence threshold during onboarding. A higher setting means more verification steps for your clients and greater evidential certainty for you; a lower setting asks fewer steps of straightforward clients. Your setting should reflect the risk profile of your typical client and is documented in your Practice-Wide Risk Assessment.
It depends on the client's institutional history, because the process asks for proportionate proof - a straightforward profile clears on fewer steps than a complex one. For some clients the final confirmation completes when they next make a routine transaction they were going to make anyway. You and your client always see exactly where they are in the process, so there is never a black box.
The platform will indicate clearly that an alternative verification method is needed. Traditional document-based verification remains available for those cases - but for any client with an authenticated relationship at an FCA-registered institution, the Witness Model is the better path.
WhyAML provides onboarding support, a knowledge base, and direct access to our team for queries about the platform and its use. For questions about your specific legal obligations, we recommend speaking with your professional body or a specialist adviser - our job is to give you the best possible tool, not to replace professional advice.
The Regulations don't require a UK address or a utility bill - they require a reliable, independent source. For an expat, a recent arrival, an international tenant, or any client without standard UK paperwork, WhyAML verifies through their existing FCA-registered exchange (with UK banks via read-only Open Banking coming in Phase 1), regardless of address history. The client who is hardest to verify on documents is often the most straightforward to verify on a relationship.
Verifying a client with no UK addressYes. Pricing is per check, with no monthly minimum and no contract - you pay for the checks you do and nothing else. Making institutional-grade verification reach a single-partner firm is the whole point, not an afterthought.
See pricingReady when you are. Create your account → - separate from buying credits - then see pricing whenever you want to top up.
The same standard - without collection, downloads, or biometrics.
Every WhyAML verification meets the reliable-and-independent-source requirement of Regulation 28 while collecting no identity documents from your client. The sensitive data that document-based checks accumulate is never gathered by you or us.
Your records are auditable and timestamped, and your client keeps a portable record of their own verified status.
WhyAML is the only AML verification service operating in the UK that doesn't assemble or collect identity document from the customer at any stage.
Read how the Confidence Architecture works