Guides / Swootle Research / 2026-07-18
What TCSP software must handle across service triage, layered entities, trusts, ownership and control, evidence, configured risk review, approvals, and lifecycle change.
AML software for trust and company service providers: a buyer guide
AML software for trust and company service providers should make the operating model inspectable. It needs to connect the service being provided to the legal customer, the people who can instruct, the entities and legal arrangements behind the relationship, the evidence collected, the risk path, the human decision, and the next review action.
This is a buying guide, not a global statement of legal obligation. TCSP scope, beneficial-ownership definitions, record requirements, review expectations, and regulator terminology vary by jurisdiction and service. Use current primary sources and qualified local advice to decide what your programme must do.
Where a TCSP serves clients or structures across jurisdictions, the international financial centre AML workflow hub provides broader context for configuring the workflow.
What this market's software must handle
Start with service triage rather than a customer name. Formation, registered-office services, director or secretary services, nominee arrangements, trust administration, company administration, and changes to an existing structure can require different questions and evidence.
The software should be able to represent or connect:
- the legal customer and the service or matter requested;
- directors, shareholders, trustees, settlors, protectors, appointors, beneficiaries, authorised persons, representatives, and intermediaries where relevant;
- ownership and control relationships, including intermediate companies and ownership edges;
- authority to instruct and the reason the service is needed;
- requested documents, declarations, returned check context, reviewer tasks, approval outcomes, and follow-up;
- the change or refresh path after onboarding.
The exact role taxonomy is not universal. A useful platform lets the firm configure the questions and evidence required by its programme instead of treating a generic UBO field as a complete answer.
Why point identity checks are insufficient
A point identity or entity check can answer part of an identity question. It does not, by itself, show how a company is owned through another company, who has authority under a trust arrangement, why a nominee service was requested, which document supports a control assertion, or why a reviewer accepted an unresolved gap.
Checks are therefore inputs to a wider workflow. The buyer should ask whether results can be linked to the relevant person or entity, whether a returned result can trigger a review or request for more information, and whether the reviewer can record the decision context. Do not treat a provider result as a legal conclusion or assume that software performs every form of screening.
Entity, trust, ownership, and control complexity
Legal ownership, beneficial enjoyment, practical control, and authority to instruct can sit with different people. A corporate trustee may have its own ownership chain. A protector or appointor may have powers that matter to the firm's assessment. A professional intermediary may be the contact point without being the underlying customer.
The FATF risk-based approach for trust and company service providers and FATF guidance on beneficial ownership transparency for legal arrangements are useful starting points for designing questions. They do not remove the need to check the rules and guidance that apply to the firm's services and jurisdictions.
Ask the vendor to demonstrate:
- how a company, trust, person, and ownership or control edge are represented;
- how roles can be labelled without implying that one global UBO definition applies everywhere;
- how the flow asks about authority, purpose, source explanations, and relevant parties;
- how the reviewer sees the structure and evidence together;
- how a changed role or relationship starts a new review path.
If the demonstration only shows a single customer record and a pass or fail result, it is not demonstrating the TCSP problem.
Evidence collection and missing information
Evidence requirements should follow the path. A TCSP may need a registry extract, constitutional documents, trust deed or relevant extracts, ownership information, authority evidence, identity evidence, source-of-wealth or source-of-funds material, service rationale, and information about expected activity. The right set depends on the firm's risk assessment and jurisdictional requirements.
The important software questions are practical:
- Can the customer upload the requested material through a controlled portal?
- Can the team set document requirements by service or structure?
- Does the process distinguish missing, returned, expired, and reviewed information?
- Can a reviewer reopen or hand off a submission without losing the earlier context?
- Can the reason for accepting an alternative document or an unresolved gap be recorded?
This is where workflow differs from a shared folder. The workflow gives the team a visible next action and a reason for the request. It does not make a missing document disappear.
Configured risk and human approval
Risk rules should be configurable to the firm's programme, with clear ownership of the method and thresholds. A vendor should show how structure, service, jurisdiction, missing evidence, returned check context, and other selected factors can route a case to the right review stage.
The decision still belongs to an appropriately authorised person. Look for named roles, checklists, comments, approval or return actions, conditions, and a place to connect the rationale to the evidence. Ask what happens when a reviewer disagrees with a configured route.
Do not accept broad claims that a workflow tool provides compliant enhanced due diligence by itself. A platform may carry your EDD questions, documents, reviewer work, and decisions, but your firm defines the procedure and remains responsible for the conclusion.
Lifecycle change and refresh
TCSP files can change when a director, shareholder, trustee, protector, appointor, authorised person, intermediary, service, jurisdiction, or expected activity changes. The buyer should ask how the existing relationship starts a targeted refresh, how new evidence is requested, and how the reviewer can compare the current decision with the earlier context.
Some products use “continuous monitoring” as a broad label. Confirm whether that means a native scheduled service, an external provider result, an event-triggered workflow, or a manually started review. Swootle supports configurable refresh and ongoing review workflows. A native scheduler and continuous monitoring execution are not product claims to assume without confirmation.
Workflow software versus case management
AML case management software versus workflow software explains the distinction. Case management may organise work, notes, and status. Workflow software should also make the sequence, conditions, evidence requirements, returns, review stages, approvals, and next actions explicit.
For a TCSP, the useful question is not which label a vendor uses. Ask to see how a complex structure moves through intake, missing information, risk review, approval, and refresh without copying context between tools.
Integration questions
Ask for specific answers about:
- available API, webhook, or generic HTTP function options;
- what provider results can be returned and how they are linked to a person or entity;
- document storage, access controls, retention settings, and export behaviour;
- versioning, publishing, environment separation, and rollback;
- user roles, reviewer assignment, comments, and approval controls;
- what is configurable by your team and what requires vendor work.
Do not infer a native integration from an API endpoint or a marketing reference to “integrations”. Confirm the exact provider, data flow, error handling, ownership, and support arrangement.
Buying criteria
Use a demonstration file with:
- a company owned through another entity;
- a corporate trustee and a trust with role-specific questions;
- an intermediary who can instruct but is not the underlying relationship;
- a missing ownership document and a returned request for more information;
- a configured risk route that requires human approval;
- a changed director or trust role that starts a refresh.
Score whether the product can:
- carry the structure and service context;
- request and connect evidence;
- show the reason for a return or escalation;
- route to the right reviewer;
- keep decision context attached;
- publish a changed workflow safely;
- explain the boundary between product support and legal responsibility.
Implementation questions
Before signing, agree the first workflow scope, the initial customer and structure types, the evidence catalogue, the reviewer roles, the risk inputs, the return paths, and the refresh scenarios. Decide who owns the content and who can publish a new version.
Run synthetic cases and a small controlled pilot. Include incomplete documents, contradictory instructions, a complex trust, an intermediary, and a changed ownership relationship. Record what the workflow cannot answer and where a human or external provider is required.
Read the customer portal overview, risk and review overview, and ongoing review workflow overview as product-specific follow-up.
Red flags
- A single identity pass is presented as the entire customer due diligence process.
- “UBO” is treated as a universal field without configurable roles or jurisdictional context.
- The vendor cannot show a complex entity or trust structure.
- Missing information is handled by email with no linked decision context.
- A risk score is presented as a regulatory method or legal conclusion.
- Human approval is described as an exception to the product rather than part of the process.
- “Continuous monitoring” is not defined in terms of triggers, timing, provider, and ownership.
- The vendor claims broad native screening, EDD, or named-system integrations without an implementation demonstration.
- Audit-ready outcomes are promised without showing how reviewers retrieve and use the relevant history.
Truthful Swootle boundaries
Swootle provides configurable workflow infrastructure: templates, steps, versioning and publishing; customer portal and intake; company, person, and ownership-edge modelling; document requirements and upload; configurable risk rules and routing; and human review, approval, roles, checklists, comments, and decision context.
Check implementation details for the specific workspace and provider arrangement. Returned identity and entity check results can be used as workflow inputs where configured, but Swootle does not claim native PEP, sanctions, or adverse-media execution. It does not automatically resolve ownership, provide a universal beneficial-ownership interpretation, or replace the firm's judgement.
Swootle can carry your review questions and evidence, but it does not claim to provide compliant EDD as a standalone domain. It supports refresh workflow design, but does not claim a native periodic scheduler or continuous monitoring execution. Retain decision context in the workflow, but do not assume a separately verified audit-history retrieval interface. Generic HTTP automation is not the same as broad native integration coverage.
For a focused conversation, book a TCSP workflow review, review pricing, or start with the TCSP workflow pillar.
Primary sources and jurisdiction notes
- FATF's TCSP risk-based guidance is an international reference point, not a substitute for local law.
- FATF's legal-arrangements guidance helps explain why trust roles and control questions need care.
- The Jersey Trust Company Business Code of Practice is relevant to Jersey-regulated businesses and should not be generalised globally.
- The BVI TCSP AML/CFT guidance is a BVI source and should be checked against current local requirements.
Confirm applicable scope and duties with the relevant regulator or qualified adviser before publishing a customer workflow. The FATF TCSP RBA and FATF legal-arrangements guidance are useful source material for that review.
This guide was materially updated on 4 August 2026. Its original publication date remains 18 July 2026.
Put the guide into practice
Book a TCSP workflow review
Bring one anonymised representative case. We will map the customer request, evidence, exceptions and accountable decision, then identify whether Swootle fits the operating model.