A plain-language explanation of our verification methodology, risk assessment framework, and data handling practices — for dealers, brokers, and compliance officers.
PCMLTFR s.105(1)(a) — Single Document Method
The client uploads a government-issued photo ID (Canadian passport, provincial driver's licence, or permanent resident card) directly on their mobile device. The document is processed immediately and never stored on ClearKYC servers.
An AI-powered OCR engine extracts key fields from the document: full legal name, date of birth, document number, issue date, expiry date, and address (where present). Extracted data is cross-referenced against client-submitted information.
The client submits a real-time selfie. A biometric comparison engine matches the selfie against the document photo and returns a confidence score. A match confirms the person holding the ID is the same person in the document photo.
The selfie capture process includes passive liveness detection to confirm the image is of a live person and not a printed photograph or screen replay.
PCMLTFA s.9.3 — PEP/HIO Determination & Sanctions Screening
Every client is screened against the OpenSanctions global database, which consolidates over 320 international watchlists updated multiple times daily.
United Nations Security Council (UN SC)·Office of the Superintendent of Financial Institutions (OSFI)·U.S. Office of Foreign Assets Control (OFAC SDN)·European Union Financial Sanctions·Special Economic Measures Act (SEMA) Canada·Global PEP registries
A match is flagged only when the screening engine returns a confidence score above 0.70 from a confirmed sanctions or PEP dataset. Name-similarity matches below this threshold are not reported, to minimize false positives for clients with common names.
A Politically Exposed Person (PEP) flag is raised when a high-confidence match is found in a PEP dataset. The dealer is notified in the compliance report and must conduct Enhanced Due Diligence (EDD) before proceeding.
PCMLTFA s.9.6 — Risk-Based Approach
Each KYC submission is assigned a risk level of LOW, MEDIUM, or HIGH. The assessment is conducted by an AI compliance engine trained on Canadian regulatory standards.
The following factors are evaluated and combined to determine the final risk level:
| Risk Factor | Risk Level |
|---|---|
| No AML/PEP matches, standard transaction | LOW |
| PEP match identified (score > 0.70) | MEDIUM |
| Third party involvement declared | MEDIUM |
| Sanctions list match identified | HIGH |
| Real estate transaction value ≥ CAD $2,000,000 | HIGH |
| PEP match + high-value transaction | HIGH |
PCMLTFR s.155 — Record Retention
Upon completion of the KYC process, a 3-page PDF compliance report is generated and emailed directly to the dealer's registered address. The report is not stored on ClearKYC servers after delivery.
Identity Verification Record (PCMLTFR s.105)·Client Identification·Risk Assessment Summary·PEP/HIO & Sanctions Screening Results·Business Relationship Record·FINTRAC/CIRO Compliance Checklist·Dealer Certification & Sign-Off Section
Dealers are required to retain the compliance report for a minimum of 5 years from the date of the transaction or business relationship, in accordance with PCMLTFR s.155. ClearKYC does not retain copies of the report.
Zero Data Retention Architecture
ClearKYC stores only: client name, submission status, dealer ID, and submission timestamp. This minimal dataset supports the dealer dashboard and audit trail.
Passport or ID document images·Selfie photographs·Biometric data·Date of birth, address, or financial information·The compliance report PDF
By eliminating storage of sensitive personal data, ClearKYC minimizes breach risk at the application layer. Even in the unlikely event of a security incident, no client PII beyond name and submission date is accessible.
All data processing and storage occurs on Canadian servers (AWS ca-central-1, Montreal). No personal data is transferred outside Canada.
Applicable Legislation
Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA)·Proceeds of Crime Regulations (PCMLTFR s.105, s.155)·CIRO Rule 3200 — Know Your Client·NI 31-103 s.13.2 — Suitability
Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA)·Proceeds of Crime Regulations (PCMLTFR s.105, s.11, s.155)·Real Estate Council of Ontario (RECO)·Trust in Real Estate Services Act, 2002 (TRESA)
ClearKYC is a compliance technology tool. It does not constitute legal advice, and dealers remain responsible for their own compliance programs and ultimate KYC determinations. The dealer must review and sign off on each compliance report.
If a client believes they have been incorrectly flagged, or if you have questions about our methodology, please contact our compliance team. Dealers retain full discretion to override the AI risk assessment and must always apply their own professional judgment.
info@clearkyc.ca →