Compliance evidence

    Regulatory compliance mapping

    How WhyAML's verification methodology maps against each applicable provision of the UK AML regulatory framework.

    Each regulation is assessed with the specific WhyAML mechanism that addresses it. The standard applied is adversarial - each entry is written to withstand challenge.

    In your portal

    The full Regulatory Compliance Mapping document - with complete evidence tables, known limitations analysis, and gap assessment - is available in your client portal after onboarding.

    Part A

    Money Laundering Regulations 2017

    Regulation 28

    Customer Due Diligence - Identity Verification

    Strong

    Requirement: Verify identity from a reliable source independent of the person.

    How WhyAML satisfies: WhyAML's Witness Model - a confidence accumulation stack of self-screener, DKIM institutional connection, and KYC-threshold transaction evidence - constitutes a reliable and independent source. Each channel is structurally independent of the individual's self-report.

    HMT/DSIT Guidance (Feb 2026)

    Digital Verification Services - Not a DVS

    Strong with caveat

    Requirement: Approved guidance recognises certified DVS as a reliable source and cautions that non-certified DVS are unsuitable for MLR identity verification.

    How WhyAML satisfies: The Witness Model is not a DVS. It creates no digital identity - it proofs no documents or biometrics against identity repositories - it witnesses a customer's control of a regulated institutional relationship. The position is categorical: the guidance governs certified digital-identity providers and is not directed at this method, which performs the firm's own CDD under Regulation 28's method-neutral standard with the Source Institution as the reliable, independent source.

    Regulation 14B(2)

    Custodian Wallet Provider - Not In Scope

    Not in scope

    The test: Safeguarding, or safeguarding and administering, cryptoassets or private cryptographic keys on behalf of customers.

    Our position: WhyAML holds no keys, safeguards nothing and administers nothing. The customer signs from a wallet they alone control; no private key, seed phrase, or signing authority passes to WhyAML or to the merchant at any point in the flow.

    Regulation 14A(1)

    Cryptoasset Exchange Provider - Not In Scope

    Not in scope

    The test: Exchanging, or arranging to exchange, cryptoassets for money or another cryptoasset.

    Our position: Settlement is same-chain - the customer sends a stablecoin and the merchant receives the same stablecoin on the same network. Nothing is exchanged for anything. Any conversion between money and cryptoassets happens before WhyAML is involved, at the customer's own FCA-registered venue. With no exchange occurring in the flow, the arranging limb has nothing to attach to.

    Regulation 19(4)(c)

    Risk Assessment - New Technologies

    Strong

    Requirement: Assess risks of new technologies adopted for AML prevention.

    How WhyAML satisfies: The TDD document constitutes that assessment. G-RADE™'s tiered proof architecture operationalises proportionate scrutiny - higher-risk individuals go through more proof elements.

    Regulation 27

    Timing of Verification

    Strong with caveat

    Requirement: Verification must be completed before the business relationship is established.

    How WhyAML satisfies: Compliance Token and Compliance Certification issued only on full completion. Near-Approved Status is a commercial communication only - firms must not treat it as completed verification.

    Regulation 33

    Enhanced Customer Due Diligence

    Strong

    Requirement: Apply enhanced measures to higher-risk clients.

    How WhyAML satisfies: G-RADE™'s low-confidence path maps directly to Regulation 33. Individuals whose score indicates elevated risk are automatically routed through additional proof elements.

    Regulation 39

    Reliance on Third Parties

    Strong

    Requirement: Formal written agreement required for third-party reliance.

    How WhyAML satisfies: WhyAML does not constitute reliance under Regulation 39. The firm is performing its own CDD using WhyAML as a technology tool, not delegating CDD to a third party. No written reliance agreement is required or claimed.

    Regulation 40

    Record Keeping

    Strong

    Requirement: Retain CDD evidence for 5 years.

    How WhyAML satisfies: Satisfied automatically and permanently by the on-chain Compliance Token. The blockchain record is independently verifiable by any regulator without depending on the firm's record-keeping.

    Regulation 28(11)

    Ongoing Monitoring

    Strong

    Requirement: Keep verification information up to date throughout the business relationship.

    How WhyAML satisfies: Perpetual KYC (pKYC) provides continuous post-onboarding wallet monitoring. Detects sanctions interactions, behavioural anomalies, geographic shifts, and network association changes. Alerts the firm in real time.

    Part B

    Data (Use and Access) Act 2025

    DUAA 2025

    Data Minimisation Mandate

    Strong

    Requirement: Collect only the minimum data necessary.

    How WhyAML satisfies: WhyAML holds name, address, and wallet address only. No identity documents, no biometrics, no financial account details. Structurally aligned with data minimisation.

    DUAA 2025

    Individual Rights - Subject Access and Erasure

    Strong

    Requirement: Individuals can access and request deletion of their data.

    How WhyAML satisfies: SARs directed to Go 2 Glory Ltd as data controller. The firm holds no personal data to disclose. Compliance Token on-chain is not personal data.

    Part C

    Crypto-Asset Framework & GDPR

    CARF (Jan 2026)

    Crypto-Asset Reporting Framework

    Adequate

    Requirement: Report crypto-linked tax residency.

    How WhyAML satisfies: WhyAML's behavioural geolocation and institutional connection verification assist with tax residency determination.

    FCA Travel Rule

    Originator and Beneficiary Information

    Strong

    Requirement: Identify originator/beneficiary for crypto transfers.

    How WhyAML satisfies: The institutional proxy link satisfies originator identification requirements.

    UK GDPR Article 22

    Automated Decision-Making

    Strong

    Requirement: Individuals have rights regarding automated decisions.

    How WhyAML satisfies: G-RADE™ determines the proof path, never the outcome. No individual is rejected - more evidence is required for lower-confidence profiles. Pre-emptively addresses automated decision-making concerns.

    Full compliance mapping in your portal

    The complete document - with full evidence tables, known limitations, gap analysis, and document control - is available to clients in the WhyAML portal.