AML compliance that shows its work
DueCheck screens your clients against sanctions and PEP lists, scores their risk, keeps them monitored, and hands an auditor a file that explains every decision. Built for accountants, auditors, lawyers and corporate service providers in Cyprus and the EU
Every client, the same five questions
Who are they, who owns them, are they on a list, how risky are they, and has anything changed since you last looked. Most firms answer with a spreadsheet, a few browser tabs and a folder of PDFs, then rebuild the whole story the week the regulator asks for it. DueCheck keeps the story as it happens
Every hit explains itself
A reviewer should never have to take the software's word for it. DueCheck shows the score behind every match, factor by factor
- Five sources, kept current. The UN consolidated list, the EU financial sanctions files, OFAC SDN and consolidated, the UK OFSI list, and OpenSanctions sanctions and PEP data, refreshed on each publisher's own schedule
- Matching a compliance officer would recognise. Greek to Latin transliteration under ELOT 743 and BGN/PCGN, spelling variants, initials, reordered names, and identifiers such as a passport or registration number that settle a match on their own
- Decisions stick to the pair. A false positive cleared once stays cleared on every later screening of the same person
- An optional AI note. It summarises a hit for the reviewer. It writes a note, it never takes the decision
Follow the shares to the people
DueCheck records directors, shareholders, beneficial owners and signatories, then walks the chain across companies to find the natural persons behind them
- Ten levels deep, with exact percentages. Effective holdings are carried down the chain, so a 60 percent parent of a wholly owned subsidiary reads as 60 percent
- Dead ends are shown, not hidden. Circular ownership, unreachable owners and chains that go quiet are flagged for a person to resolve
- Everyone found gets screened. Each natural person the walk reaches goes through the same sanctions and PEP checks as the client
Your policy, applied the same way every time
Each client is scored on client type, country, sector, products, delivery channel, ownership and screening results, with the worst factor in each category driving the category
- Country risk that stays current. The EU high-risk third country list, the FATF lists and the EU tax list, updated by the product and confirmed by a person before they take effect
- Thresholds, weights and floors are yours. Every field carries an explanation of what it does and what the default is
- Overrides are recorded. Who, when and why, carried forward until somebody changes them
Country weight overridden to 1.4 by L. Moreau on 08 Sep, reason recorded
The person who prepares cannot approve
Eight case kinds, from onboarding to suspicious activity, each with tasks, evidence, comments, checklists and enhanced due diligence templates
- Four eyes where a decision matters. Preparation and approval are separate roles, and DueCheck holds the case until a second person rules
- Evidence is frozen when it is captured. Each snapshot is encrypted at rest and hashed, so what the reviewer saw is what the auditor sees
- Ask the client without an account. Send a secure link by email. They upload documents and answer a questionnaire with no password to create
Onboarding is the beginning, not the file
Every client is re-screened on a schedule set by their risk band, and again the moment a sanctions list changes
- Alerts that stay readable. New hits, list changes, expiring identity documents, overdue reviews and adverse media, rolled up so the desk shows one line per firm
- Alerts open cases on their own. Under the same four-eyes rules as everything else
- Adverse media in English and Greek. Names and aliases across sanctions, crime, fraud, corruption, terrorism, litigation, regulatory and insolvency vocabularies. An AI classifier reads each page, judges whether it is about the same party, and summarises it. A person confirms or dismisses, and nothing changes a client's status until a person rules
- A registry of public sources. From OLAF and CySEC to the Registrar of Companies and the Gazette, read on a schedule and kept as evidence
A file the auditor can verify
Every action is written to a hash-chained log that nobody can edit or delete. Each entry carries the hash of the one before it, so the chain proves itself
Change any line and every hash below it stops matching. The nightly check reports it. Print a case file or export it as JSON for the regulator
Four steps, then it keeps going
Hosted and operated by IXXO in the EU
Your firm is an organisation of its own inside the service. Your users, policies, records, usage and secure links stay yours, and no other firm can reach them
Planned, and not yet released
Everything above is in the installed product today. Everything below is on the roadmap and carries this label until the release is live
Firms that have to prove they did the work
Obliged entities under the Cyprus AML law and the EU directives, where the file has to hold up long after the decision was taken
See it on your own clients
Book a thirty-minute walkthrough. Bring three client names and we will screen them live
Talk to the team that built it
Tell us about your firm and what you have to evidence. Write to info@ixxo.com or use the form
IXXO, Cyprus. Hosted and operated in the EU