Regulatory compliance mapping
How WhyAML's verification methodology maps against each applicable provision of the UK AML regulatory framework.
Each regulation is assessed with the specific WhyAML mechanism that addresses it. The standard applied is adversarial - each entry is written to withstand challenge.
The full Regulatory Compliance Mapping document - with complete evidence tables, known limitations analysis, and gap assessment - is available in your client portal after onboarding.
Money Laundering Regulations 2017
Customer Due Diligence - Identity Verification
Requirement: Verify identity from a reliable source independent of the person.
How WhyAML satisfies: WhyAML's Witness Model - a confidence accumulation stack of self-screener, DKIM institutional connection, and KYC-threshold transaction evidence - constitutes a reliable and independent source. Each channel is structurally independent of the individual's self-report.
Digital Verification Services - Not a DVS
Requirement: Approved guidance recognises certified DVS as a reliable source and cautions that non-certified DVS are unsuitable for MLR identity verification.
How WhyAML satisfies: The Witness Model is not a DVS. It creates no digital identity - it proofs no documents or biometrics against identity repositories - it witnesses a customer's control of a regulated institutional relationship. The position is categorical: the guidance governs certified digital-identity providers and is not directed at this method, which performs the firm's own CDD under Regulation 28's method-neutral standard with the Source Institution as the reliable, independent source.
Custodian Wallet Provider - Not In Scope
The test: Safeguarding, or safeguarding and administering, cryptoassets or private cryptographic keys on behalf of customers.
Our position: WhyAML holds no keys, safeguards nothing and administers nothing. The customer signs from a wallet they alone control; no private key, seed phrase, or signing authority passes to WhyAML or to the merchant at any point in the flow.
Cryptoasset Exchange Provider - Not In Scope
The test: Exchanging, or arranging to exchange, cryptoassets for money or another cryptoasset.
Our position: Settlement is same-chain - the customer sends a stablecoin and the merchant receives the same stablecoin on the same network. Nothing is exchanged for anything. Any conversion between money and cryptoassets happens before WhyAML is involved, at the customer's own FCA-registered venue. With no exchange occurring in the flow, the arranging limb has nothing to attach to.
Risk Assessment - New Technologies
Requirement: Assess risks of new technologies adopted for AML prevention.
How WhyAML satisfies: The TDD document constitutes that assessment. G-RADE™'s tiered proof architecture operationalises proportionate scrutiny - higher-risk individuals go through more proof elements.
Timing of Verification
Requirement: Verification must be completed before the business relationship is established.
How WhyAML satisfies: Compliance Token and Compliance Certification issued only on full completion. Near-Approved Status is a commercial communication only - firms must not treat it as completed verification.
Enhanced Customer Due Diligence
Requirement: Apply enhanced measures to higher-risk clients.
How WhyAML satisfies: G-RADE™'s low-confidence path maps directly to Regulation 33. Individuals whose score indicates elevated risk are automatically routed through additional proof elements.
Reliance on Third Parties
Requirement: Formal written agreement required for third-party reliance.
How WhyAML satisfies: WhyAML does not constitute reliance under Regulation 39. The firm is performing its own CDD using WhyAML as a technology tool, not delegating CDD to a third party. No written reliance agreement is required or claimed.
Record Keeping
Requirement: Retain CDD evidence for 5 years.
How WhyAML satisfies: Satisfied automatically and permanently by the on-chain Compliance Token. The blockchain record is independently verifiable by any regulator without depending on the firm's record-keeping.
Ongoing Monitoring
Requirement: Keep verification information up to date throughout the business relationship.
How WhyAML satisfies: Perpetual KYC (pKYC) provides continuous post-onboarding wallet monitoring. Detects sanctions interactions, behavioural anomalies, geographic shifts, and network association changes. Alerts the firm in real time.
Data (Use and Access) Act 2025
Data Minimisation Mandate
Requirement: Collect only the minimum data necessary.
How WhyAML satisfies: WhyAML holds name, address, and wallet address only. No identity documents, no biometrics, no financial account details. Structurally aligned with data minimisation.
Individual Rights - Subject Access and Erasure
Requirement: Individuals can access and request deletion of their data.
How WhyAML satisfies: SARs directed to Go 2 Glory Ltd as data controller. The firm holds no personal data to disclose. Compliance Token on-chain is not personal data.
Crypto-Asset Framework & GDPR
Crypto-Asset Reporting Framework
Requirement: Report crypto-linked tax residency.
How WhyAML satisfies: WhyAML's behavioural geolocation and institutional connection verification assist with tax residency determination.
Originator and Beneficiary Information
Requirement: Identify originator/beneficiary for crypto transfers.
How WhyAML satisfies: The institutional proxy link satisfies originator identification requirements.
Automated Decision-Making
Requirement: Individuals have rights regarding automated decisions.
How WhyAML satisfies: G-RADE™ determines the proof path, never the outcome. No individual is rejected - more evidence is required for lower-confidence profiles. Pre-emptively addresses automated decision-making concerns.
Full compliance mapping in your portal
The complete document - with full evidence tables, known limitations, gap analysis, and document control - is available to clients in the WhyAML portal.