Conformia Compliance platform

Compliance that stops slowing you down

The compliance platform for regulated professions.

  • SHA-256 Audit chain no UPDATE or DELETE on that table, by design
  • 4+ Sanctions lists OFAC, UN, EU, UK, the Monaco asset-freeze list and the Journal de Monaco
    60 to 80% STRIX pre-filled from the dossiers and screening you already hold
  • 235,000+ News sources screened adverse media in near real time, each match classified by category
    On-premise Deployment or in the cloud you choose, air-gapped included
  • 5 Risk dimensions weighted to exactly 100, then classified without a human pass

How it works

A dossier goes in. A decision comes out, and the log wrote itself.

Identity papers, sanctions lists, the PEP database and your own client register on one side. On the other, a screening decision a person signs off and an audit entry nobody can rewrite afterwards. Pick a profession and a step below.

Request access

Reads from

ID documents
Company registry
Sanctions lists
PEP database
Client register
Source of funds
Audit log
STRIX templates

Does

Proves

  • Fields extracted from passports and IDs
  • Ownership tree for legal entities, down to the beneficial owner
  • Checklists configured per regulated profession
  • Completeness scored, so the gap is visible

The cycle

From an empty dossier to one the regulator can check

Five steps, and each one hands the next what it needs. That is why the questionnaire at the end is already mostly filled, and why the audit log wrote itself while you worked.

KYC Dossier Management

A dossier is the pieces, not a form: the identity documents, the beneficial-owner declarations, the source-of-funds file and the checklist your profession is held to, each with its own status. The screen shows a typical individual file, six document types tracked, and a completeness score computed from what the checklist requires rather than from what happened to be uploaded.

Operations

The dossier is your work. The watch is the platform’s.

Most of what a compliance platform owes you happens when nobody is looking at it: overnight, on a Saturday, or the week a list changes. Here is what runs on its own, and what you can take out of it.

  • Continuous re-screening

    When a sanctions or PEP list is updated, the clients already in your register are screened again automatically. You are told about a new match because the world changed, not because someone opened the file.

  • Alert triage

    Every hit follows the same path: open, under review, then true match or false positive, then closed. Nothing is dismissed silently, and the reason a match was closed stays attached to it.

    Open Under review True match or false positive Closed
  • Four-eyes approval

    A risk decision is written to the record only once a second person has validated it. High and critical cases trigger enhanced due diligence on their own rather than waiting to be noticed.

  • Integrity verification

    The hash chain is verified automatically every week. A single altered record breaks the chain, and the check fails rather than passing quietly.

Reported on

  • Inspection pack the full evidence set, exported for regulator submission
  • STRIX export the annual questionnaire in the regulator-ready format
  • Screening outcomes every alert, its sources and why it was closed
  • Audit log hash-chained, with the decision and the person behind each write
  • Dossier state completeness, risk level and what is still missing, per client

Who it is for

The same obligations, never the same dossier

A yacht broker and a corporate service provider answer to the same regulator and never assemble the same file. The checklists follow the profession, not the other way round.

  • Financial intermediaries

    AML compliance without the overhead

    Manage all KYC dossiers for clients and UBOs from intake to ongoing monitoring. Automated screening, STRIX questionnaire auto-fill, and STR workflow reduce the compliance team's administrative burden by over 60%.

    • KYC lifecycle automation
    • STRIX auto-fill from existing data
    • STR workflow with audit trail
  • Real estate & yachting

    Transaction-level compliance documentation

    Each high-value transaction triggers a KYC check automatically. Dossiers capture source-of-funds, UBO structures, and property/vessel details with sector-specific checklists. All decisions are auditable on demand.

    • Transaction-triggered KYC
    • Sector-specific checklists
    • Source-of-funds documentation
  • Corporate service providers

    Portfolio-wide risk visibility

    Manage dossiers across an entire client portfolio from one workspace. Risk dashboard shows portfolio-level exposure. Continuous re-screening catches sanction updates immediately without manual checks.

    • Portfolio-level risk dashboard
    • Continuous re-screening
    • Multi-client workspace

Where to start

Start on one profession. The audit trail starts with it.

Nobody moves a whole compliance operation in one weekend, and the regulator does not accept a gap while you do. Each step below opens the same platform wider.

  • Pilot

    One profession, one dossier type, from intake to decision.

    • The checklist configured for your sector, not a generic one
    • Screening on OFAC, UN, EU, UK, the Monaco asset-freeze list and the press
    • The hash-chained log running from the very first dossier
    Scope a pilot
  • Operate

    The whole cycle, for the whole compliance team.

    • Risk scored on five weighted dimensions, EDD triggered on its own
    • Four-eyes approval before a decision is written to the record
    • Re-screening fires when a list changes, not when someone remembers
    • STRIX prepared from what the platform already holds
    Talk to an engineer
  • Sovereign

    On your own servers, and nothing leaves them.

    • Parametric on-premise installer, deployed in a single command
    • LDAP or Active Directory federation, S3 or SFTP backup targets
    • Offline Docker delivery for fully air-gapped environments
    Plan a deployment

Widening is never a migration. The audit trail that starts on your first pilot dossier is the one a regulator reads three years later, unbroken.

Questions

What a compliance officer asks before signing

Conformia is designed for any organisation with AML/KYC obligations: financial intermediaries, real estate agencies, family offices, law firms, notaries, corporate service providers, yachting brokers, and other regulated professionals. The compliance workflows and checklists are configurable per regulated sector.
Conformia runs parallel screening against multiple sources, including OFAC, UN, EU, and national sanctions lists, as well as PEP (politically exposed person) databases. Fuzzy matching with configurable thresholds handles name variations. Alerts are generated automatically and follow a structured workflow: Open → Under Review → True Match or False Positive → Closed.
The STRIX module manages the annual questionnaire mandated by Monaco's AMSF regulator for all regulated sectors. Conformia auto-fills 60, 80% of STRIX responses from existing platform data: dossiers, screening results, risk scores, and decision records. All five STRIX sections are covered, with sector-specific modules per the official templates.
The audit log uses SHA-256 hash chaining, each record cryptographically links to the previous one. The underlying database role has no UPDATE or DELETE permissions on the audit table, making retrospective modification impossible. Integrity is verified automatically on a weekly schedule, and full inspection packs can be exported for regulator submission.
Yes. Conformia includes a parametric on-premise installer with scripted deployment in a single command. It supports Let's Encrypt, client-supplied certificates, or no-TLS modes; LDAP/Active Directory federation; S3-compatible or SFTP backup destinations; and offline Docker image delivery for air-gapped environments. Rollback to prior versions is supported.
The Conformia AI layer uses compliance-specific skills (screening analysis, EDD drafting, risk explanation, document analysis, STRIX assistance). All AI calls pass through a PII redaction proxy before reaching any language model. Sensitive STR (suspicious transaction report) files are never accessible to the AI without explicit MLRO authorisation. Three data tiers are supported: full on-premise, EU-sovereign partners, and cloud-global, with on-premise as the secure default.

Next

Tell us which dossier takes you the longest

Conformia is built for regulated professionals in Monaco and neighbouring jurisdictions, and access is by request. Tell us which dossier takes you the longest, and we walk you through it on cases like yours.