Compliance Documentation

How ClearKYC Verifies Identities

A plain-language explanation of our verification methodology, risk assessment framework, and data handling practices — for dealers, brokers, and compliance officers.

FINTRACPCMLTFACIRO Rule 3200PCMLTFR s.105RECO
1
Client uploads ID + selfie
2
AI verifies document & face
3
AML/PEP screening
4
Report emailed to dealer
01

Identity Verification

PCMLTFR s.105(1)(a) — Single Document Method

Document Collection

The client uploads a government-issued photo ID (Canadian passport, provincial driver's licence, or permanent resident card) directly on their mobile device. The document is processed immediately and never stored on ClearKYC servers.

Optical Character Recognition

An AI-powered OCR engine extracts key fields from the document: full legal name, date of birth, document number, issue date, expiry date, and address (where present). Extracted data is cross-referenced against client-submitted information.

Face Match

The client submits a real-time selfie. A biometric comparison engine matches the selfie against the document photo and returns a confidence score. A match confirms the person holding the ID is the same person in the document photo.

Liveness Detection

The selfie capture process includes passive liveness detection to confirm the image is of a live person and not a printed photograph or screen replay.

02

AML & Sanctions Screening

PCMLTFA s.9.3 — PEP/HIO Determination & Sanctions Screening

Screening Engine

Every client is screened against the OpenSanctions global database, which consolidates over 320 international watchlists updated multiple times daily.

Sanctions Lists Covered

United Nations Security Council (UN SC)·Office of the Superintendent of Financial Institutions (OSFI)·U.S. Office of Foreign Assets Control (OFAC SDN)·European Union Financial Sanctions·Special Economic Measures Act (SEMA) Canada·Global PEP registries

Match Confidence Threshold

A match is flagged only when the screening engine returns a confidence score above 0.70 from a confirmed sanctions or PEP dataset. Name-similarity matches below this threshold are not reported, to minimize false positives for clients with common names.

PEP Determination

A Politically Exposed Person (PEP) flag is raised when a high-confidence match is found in a PEP dataset. The dealer is notified in the compliance report and must conduct Enhanced Due Diligence (EDD) before proceeding.

03

Risk Assessment

PCMLTFA s.9.6 — Risk-Based Approach

Risk Levels

Each KYC submission is assigned a risk level of LOW, MEDIUM, or HIGH. The assessment is conducted by an AI compliance engine trained on Canadian regulatory standards.

Risk Factors

The following factors are evaluated and combined to determine the final risk level:

Risk FactorRisk Level
No AML/PEP matches, standard transactionLOW
PEP match identified (score > 0.70)MEDIUM
Third party involvement declaredMEDIUM
Sanctions list match identifiedHIGH
Real estate transaction value ≥ CAD $2,000,000HIGH
PEP match + high-value transactionHIGH
04

Compliance Report

PCMLTFR s.155 — Record Retention

Report Delivery

Upon completion of the KYC process, a 3-page PDF compliance report is generated and emailed directly to the dealer's registered address. The report is not stored on ClearKYC servers after delivery.

Report Contents

Identity Verification Record (PCMLTFR s.105)·Client Identification·Risk Assessment Summary·PEP/HIO & Sanctions Screening Results·Business Relationship Record·FINTRAC/CIRO Compliance Checklist·Dealer Certification & Sign-Off Section

Record Retention

Dealers are required to retain the compliance report for a minimum of 5 years from the date of the transaction or business relationship, in accordance with PCMLTFR s.155. ClearKYC does not retain copies of the report.

05

Data Retention Policy

Zero Data Retention Architecture

What We Store

ClearKYC stores only: client name, submission status, dealer ID, and submission timestamp. This minimal dataset supports the dealer dashboard and audit trail.

What We Never Store

Passport or ID document images·Selfie photographs·Biometric data·Date of birth, address, or financial information·The compliance report PDF

Why This Matters

By eliminating storage of sensitive personal data, ClearKYC minimizes breach risk at the application layer. Even in the unlikely event of a security incident, no client PII beyond name and submission date is accessible.

Server Location

All data processing and storage occurs on Canadian servers (AWS ca-central-1, Montreal). No personal data is transferred outside Canada.

06

Regulatory Coverage

Applicable Legislation

Securities Channel

Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA)·Proceeds of Crime Regulations (PCMLTFR s.105, s.155)·CIRO Rule 3200 — Know Your Client·NI 31-103 s.13.2 — Suitability

Real Estate Channel

Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA)·Proceeds of Crime Regulations (PCMLTFR s.105, s.11, s.155)·Real Estate Council of Ontario (RECO)·Trust in Real Estate Services Act, 2002 (TRESA)

Limitations

ClearKYC is a compliance technology tool. It does not constitute legal advice, and dealers remain responsible for their own compliance programs and ultimate KYC determinations. The dealer must review and sign off on each compliance report.

Questions or Concerns?

If a client believes they have been incorrectly flagged, or if you have questions about our methodology, please contact our compliance team. Dealers retain full discretion to override the AI risk assessment and must always apply their own professional judgment.

info@clearkyc.ca →