Swootle Book a demo

Guides / Swootle Research / 2026-07-18

A practical KYC software evaluation guide for regulated firms testing evidence collection, ownership, risk, exceptions, human approval, and refresh workflows.

KYC software: 7 tests for regulated onboarding

KYC software should connect customer intake to evidence, risk assessment, human review, approval, and the next action. For a regulated firm, the useful question is not whether a tool can collect a form. It is whether the tool can guide the right customer or entity through a configured process, show what is missing, route exceptions, and keep the decision context with the workflow record.

For the product-level view of that complete customer-acceptance path, explore regulated client onboarding software. This guide retains the educational and evaluation intent for KYC and KYB process design.

This is a commercial process guide, not a statement of universal legal requirements. KYC, KYB, customer due diligence, beneficial-ownership and ongoing-review duties vary by service, risk and jurisdiction. Use the current rules of the relevant regulator and qualified local advice when designing the control programme.

In this guide

What KYC and KYB onboarding software should do

KYC applies primarily to an individual. KYB applies to a company or other legal entity and usually requires information about ownership, control, authority and purpose. In practice, a single relationship can involve both: a company, its directors, its controllers, a corporate trustee, an intermediary and the person who is authorised to instruct the firm.

A useful onboarding system should let a team configure a path that:

  • identifies the customer type, service requested, jurisdiction and relationship purpose;
  • collects individual, entity and related-party information relevant to that path;
  • requests documents and other evidence with a clear reason and next action;
  • models the ownership and control relationships that the customer has supplied;
  • applies configured risk factors and sends higher-risk or incomplete cases to review;
  • records approval, return or rejection decisions with reviewer comments and context; and
  • starts a targeted refresh workflow when relevant information changes.

That is the difference between onboarding software and a digital form. The form is an input. The workflow is the controlled sequence from input to decision.

Regulatory context: use the right source for the right market

The FATF Recommendations provide an international reference point for risk-based customer due diligence, beneficial ownership and record-related controls. FATF guidance is not local law, but it is useful when defining the questions a process must answer.

For a UK programme, check the current Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 and the guidance relevant to the firm's sector. For an EU programme, the EU Anti-Money Laundering Regulation is a primary legal instrument to review alongside applicable supervisory material and the firm's services. Offshore firms should map the equivalent local legislation, rules and guidance rather than treating an international template as a complete answer.

The software consequence is practical: the process must be configurable. A vendor should not imply that one fixed KYC checklist, one global beneficial-owner definition or one risk score works for every firm.

The regulated KYC and KYB onboarding process

The following sequence is a useful design and buying framework. It is an operating model, not a substitute for the firm's approved policy.

Stage Questions to configure Useful workflow output
Scope and triage What service is requested, by whom, in which jurisdiction and for what purpose? The appropriate customer and evidence path.
Identity and authority Who is the individual or legal entity, and who may instruct the firm? Identity, registration and authority evidence linked to the relationship.
Ownership and control Which people and entities own, control or exercise relevant powers? A configured record of supplied relationships, roles and unresolved gaps.
Evidence What documents, declarations or explanations support the information? Requested, returned, missing and reviewed evidence.
Risk assessment Which customer, service, geography, structure and evidence factors affect risk? A configured risk outcome and the route it should take.
Review and decision Who can accept, return, reject or escalate the case, and why? Reviewer action, comments, approval conditions and decision context.
Refresh What change should cause information or evidence to be reviewed again? A targeted refresh path with new questions, evidence and review.
Seven-stage KYC and KYB onboarding workflow from scope to refresh.
A useful evaluation follows one representative file from initial scope through evidence, ownership, risk, human decision and refresh.

1. Start with service and customer context

Ask for the service before presenting a long generic questionnaire. A company formation matter, trust administration request, professional-services engagement and account-opening process can require different questions. Customer type, service, jurisdiction, expected activity and relationship purpose are useful early routing inputs.

Progressive disclosure also improves the client experience. An individual should not see an entity ownership questionnaire. A company may need directors, controllers and constitutional evidence. A trust-related relationship may require role-specific questions about trustees, settlors, protectors, appointors or beneficiaries, depending on the firm's policy and the applicable rules.

2. Collect identity, entity and authority evidence

Identity checks are one input to due diligence, not the whole process. The workflow should request the evidence that the firm's policy requires, record which party it supports, and make the next step visible when the evidence is missing or returned.

For KYB, the path may include registration details, constitutional documents, directors, authorised representatives and the people who can instruct the firm. An intermediary may be the contact point without being the underlying customer. That distinction should be explicit in the data model and in the reviewer's view.

3. Model ownership and control without promising automatic resolution

Ownership and control can run through intermediate companies or legal arrangements. A good process collects the relevant relationships and supporting evidence so a reviewer can understand what has been supplied, what remains uncertain and what conclusion the firm has reached.

The FATF guidance on beneficial ownership transparency for legal arrangements is a useful source for thinking about trust-party roles and control questions. It does not create a universal data model for every jurisdiction.

Do not confuse relationship modelling with automated ownership resolution. Swootle can collect and relate configured people, entities, ownership edges and roles in a workflow. It does not claim to automatically resolve every beneficial owner or complex global ownership chain.

4. Tie evidence and returned information to the path

The request should explain what is needed and what happens next. Useful states include requested, received, returned for action, reviewed and accepted for the current decision. If an alternative document is accepted or an information gap remains, the reviewer should be able to record the rationale and route the case appropriately.

Swootle's customer portal supports a guided path through configured questions, documents and follow-up requests. The product proof is narrower than a document-management-system claim: the workflow can request and retain configured evidence within the workflow record, but it does not verify every document or replace a firm's wider records and retention arrangements.

5. Apply risk factors and route human review

Risk assessment should reflect the firm's approved methodology. Possible inputs include customer and service type, jurisdictions, ownership complexity, missing evidence, returned provider results and other factors selected by the firm. The important control is the route: what happens when the result is higher risk, incomplete or disputed?

With risk and review workflows, teams can apply configured risk factors and route outcomes for human review. That does not produce a regulator-approved rating or remove reviewer judgement. Higher-risk cases may need additional evidence, questions, approvals or specialist advice under the firm's policy.

Swootle can carry a configured enhanced-review pattern, but it does not claim to provide standalone EDD as a universal domain or to perform legally sufficient EDD by itself.

6. Treat external checks as inputs, not conclusions

Some firms use identity, entity, PEP, sanctions or adverse-media providers as part of their control environment. The buyer should ask which provider arrangement is available, what result is returned, how a possible match is routed, and who makes the decision.

Swootle supports configured identity or entity checks through supported provider arrangements and can route returned results for review. It does not claim native PEP, sanctions or adverse-media execution. A provider result is not automatically a legal conclusion, and a workflow should not present it as one.

KYC exception routing from a representative file to standard review, targeted follow-up, or escalation.
The same case record should retain evidence, ownership and rationale whether it proceeds, loops back for information or escalates.

7. Plan refresh without overstating monitoring

Approval is a point in the relationship, not a reason to lose the record. A director change, ownership change, new service, jurisdictional change, expired evidence or new risk indicator may require a targeted review under the firm's policy.

Swootle supports configurable refresh and ongoing review workflows through the ongoing review workflow surface. It does not claim a native periodic scheduler or continuous monitoring execution. Confirm whether a proposed design uses a manual start, an external event, a provider result or another configured trigger.

How to evaluate KYC onboarding software

Ask each vendor to demonstrate one representative file rather than a perfect individual pass. Include:

  1. an individual who needs identity and authority evidence;
  2. a company with an intermediate entity in its ownership chain;
  3. a trust or other legal arrangement with role-specific questions;
  4. a missing document and a returned request for more information;
  5. a provider result that requires analyst review;
  6. a configured risk route that requires human approval; and
  7. a changed director or ownership relationship that starts a refresh.

Score the demonstration against five buyer questions:

  • Can the team change the path without rebuilding the whole process?
  • Can a customer see what is outstanding and why?
  • Can a reviewer see evidence, risk inputs and the decision context together?
  • Can the workflow preserve human accountability at exceptions and approvals?
  • Can the vendor explain the boundary between its product, external providers and the firm's legal responsibility?

A 10-point KYC software scorecard

Score each test 0, 1 or 2 while the vendor works through the representative file: 0 if the capability is not shown, 1 if it depends on an unexplained workaround or manual hand-off, and 2 if the capability is visible, configurable and retained in the case record. This is a procurement aid, not a compliance rating.

Test 0 points 1 point 2 points
Path configuration Fixed happy path only Change needs vendor or code work Team can show a controlled configuration change
Customer clarity Status and next action are unclear Staff explain gaps outside the portal Customer sees the request, reason and next action
Reviewer context Evidence and decisions sit apart Context is assembled manually Evidence, risk inputs and rationale appear together
Exception control Gap leaves the demonstrated flow Manual hand-off exists but is not traceable Return, escalation and approval routes are visible
System boundaries Provider or automation claims stay vague Boundary is described but not demonstrated Product, provider and human responsibilities are explicit
Ten-point KYC software scorecard showing five evaluation tests and the scoring rule.
Use the same representative file and the same five tests across every shortlisted vendor.

Treat 8–10 as a reason to advance to detailed controls and implementation due diligence, 5–7 as a gap-closure conversation, and 0–4 as evidence that the demonstrated workflow does not yet meet the operating need. A high score does not establish legal sufficiency, information-security suitability, data protection compliance or production readiness; those require their own review.

For regional planning, compare the UK and EU AML workflow approach with the offshore AML workflow approach. These pages are starting points for configuring a jurisdiction-aware process, not substitutes for local regulatory review.

What Swootle can and cannot be the answer to

Swootle provides configurable workflow infrastructure through workflow orchestration, including reusable templates, questions, evidence requests, branches, review steps, versioning and publishing. It also provides a guided customer portal, configured risk rules and human approval paths.

The boundaries matter when comparing products. Swootle does not claim:

  • native PEP, sanctions or adverse-media execution;
  • automated resolution of every ownership chain or beneficial owner;
  • standalone EDD as a complete compliance service;
  • a native scheduler or continuous monitoring execution;
  • a separately verified audit-history retrieval interface; or
  • broad named integrations based only on a generic API or HTTP handoff.

Decision context can be retained with the workflow record, but firms should verify how reviewers retrieve and use that context in the specific workspace. Generic HTTP automation can support an implementation handoff, but it is not evidence of broad native integration coverage.

Frequently asked questions

What is KYC onboarding software?

KYC onboarding software guides the collection and review of customer information, identity evidence, risk inputs and approval decisions before a relationship begins. For KYB, it also needs to support entity, ownership, control and authority information.

Does KYC software perform sanctions and PEP screening?

Some products connect to external screening providers. The buyer should confirm the exact provider arrangement and workflow. Swootle does not claim native PEP, sanctions or adverse-media execution, but can route supported provider results for review when configured.

Can KYC onboarding software resolve beneficial ownership automatically?

Do not assume so. A workflow can collect ownership and control relationships and request evidence, while the firm or an external service performs the relevant analysis. Swootle does not claim automatic resolution of every beneficial owner or complex ownership chain.

Is KYC onboarding finished when the customer is approved?

No. The firm should define how relevant changes trigger a refresh under its policy. Swootle supports configurable refresh workflows, but does not claim a native scheduler or continuous monitoring execution.

For a review of a representative KYC and KYB process, book a workflow review.

This guide was materially updated on 4 September 2026. Its original publication date remains 18 July 2026.

Put the guide into practice

Book a KYC and KYB workflow review

Bring one anonymised representative case. We will map the customer request, evidence, exceptions and accountable decision, then identify whether Swootle fits the operating model.

Book a workflow review

Review enterprise pricing