Regulation 19(4)(c) Assessment

    Technological Due Diligence

    This page summarises WhyAML's Technological Due Diligence - the document your firm places in its Practice-Wide Risk Assessment folder when adopting WhyAML.

    Under Regulation 19(4)(c) of the Money Laundering Regulations, your firm must assess the risks of adopting new verification technology. WhyAML provides the complete TDD pack for its verification method, the Witness Model. This summary covers the key elements.

    In your portal

    The full TDD document (v2.0) is available in your client portal after onboarding. It includes the complete risk assessment, regulatory mapping references, G-RADE engine specification, and audit trail field descriptions.

    How confidence accumulates

    The G-RADE™ confidence engine

    G-RADE is WhyAML's proprietary confidence accumulation engine. It does not make binary pass/fail decisions - it measures the cumulative weight of evidence across all proof elements and determines when the institutional connection confidence threshold has been reached.

    How G-RADE works

    Every proof element adds to the confidence score. No single element is load-bearing. A low G-RADE score requires more proof elements - it never rejects the individual. A high score allows a faster path. The threshold is fixed, documented, and auditable.

    Your firm sets its own minimum threshold through the security slider. This is recorded as part of your audit trail and PWRA documentation.

    See how the verification process works in our FAQ →
    Three independent layers

    Three proof levels

    Each level provides independent evidence. Together they form a composite proof significantly stronger than any single document-based check.

    1

    Self-Screener (Knowledge-Based)

    Dynamic knowledge-based authentication using OSINT identity triangulation, geographic cross-referencing, and 4-9 dynamically generated questions from the individual's own observable financial history. Questions are unique to the genuine account holder - they cannot be pre-set or guessed.

    2

    MCP-TLS Institutional Connection

    Live institutional account connection proof via MCP-TLS inside AWS Nitro Enclave - a hardware-isolated trusted execution environment. Demonstrates in real time that the individual controls access to their institutional account.

    3

    Transaction-Based Proof

    Historical KYC-threshold transaction to or from the regulated source institution within a three-year window, or a future natural transfer as real-time proof of account control. The institution has already performed enhanced due diligence on qualifying transactions.

    Risk-by-risk

    Risk assessment summary

    The TDD assesses each risk associated with adopting WhyAML, as required by Regulation 19(4)(c).

    Not a certified Digital Verification Service (DVS)

    WhyAML is not a DVS and creates no digital identity, so certification does not apply to it by category - it is not a 'non-certified DVS' either. Regulation 28 is technology-neutral: the regulated institution is the reliable, independent source. The 26 February 2026 HMT/DSIT guidance recognises certified DVS as one route, not a precondition. Adoption is recorded under Reg 19(4)(c) with full Technological Due Diligence documentation, and the company-level Regulatory Defence cover funds defence of the methodology if it is formally challenged.

    False positive (impersonation)

    Requires simultaneous compromise of dynamic knowledge questions, live MCP-TLS access, and financial transaction. Composite resistance exceeds 97%. Structurally stronger than document inspection against AI deepfakes.

    Provider ceases trading

    Compliance Token is on-chain and self-contained. Does not depend on platform access for evidentiary value. Blockchain record permanently accessible.

    Document-based is superior

    WhyAML is immune to deepfake documents, provides perpetual monitoring (not point-in-time), creates immutable blockchain audit trail, and detects fraud patterns document methods cannot identify.

    What lives where

    Data architecture

    WhyAML's architecture is designed to minimise data exposure. Your firm stores no PII through the WhyAML process.

    Data heldHeld by
    Name, address, wallet addressGo 2 Glory Ltd (data controller)
    Broker Compliance Certificate (no PII)Your firm
    Compliance Token (no PII, on-chain)Your client

    In the event of a data breach, the data at risk is limited to name, address, and wallet address - not the sensitive identity documents that constitute the highest-severity breach category.

    Read more about data handling in our FAQ →

    Full TDD document available in your portal

    The complete Technological Due Diligence pack - including the full risk assessment, G-RADE specification, audit trail field descriptions, and regulatory mapping cross-references - is available to clients in the WhyAML portal.

    This document is the risk assessment required by Regulation 19(4)(c). See it mapped provision by provision.