Every EveryGuard AML product — AgentGuard, FirmGuard, PracticeGuard, ArtGuard — runs customer due diligence on the same engine: a link the customer opens on their own phone, an identity check that reads the document (or, on iPhone, the passport chip itself), a live sanctions & PEP screen, and a locked evidence pack the firm can hand a regulator. This page shows how it all fits together.
Every check follows the same six-step path, whichever Guard product sent it. Steps run mostly on the customer's device — the firm never has to be in the room.
The firm sends a one-time verify link by SMS or email — verify.agentguard.uk/{token} (or verify.everyguard.uk for the other verticals). Nothing to install to receive it.
The customer picks passport, UK driving licence or BRP and photographs it. On-device OCR reads it instantly; a Claude Vision fallback rescues a bad scan.
On iPhone, the customer can instead tap their ePassport's NFC chip via the AgentGuard Verify App Clip — a cryptographically state-signed read, no photo needed.
Premium · iPhoneA short liveness check (smile / hand gesture) confirms a live person, then the selfie is matched server-side against the document photo.
The name is checked against sanctions (OFSI/FCDO/OFAC/UN) and PEP lists, refreshed daily, with a freshness gate that escalates rather than clearing against a stale list.
The firm gets a clear verdict — clear, review or match — and a locked, audit-ready evidence pack retained for 5 years under MLR Reg 40.
No portal login, no PDF to print and scan back. Four moments from the same five-screen flow.
Every check screens the name against OFSI, FCDO, OFAC and UN sanctions data, Companies House disqualified directors, and a Politically Exposed Persons roster — refreshed daily.
If a binding source (OFSI/OFAC/UN) is behind on its refresh, a would-be "clear" verdict is escalated to "review" instead — staleness can only add caution, it can never remove it, and a genuine match is never downgraded.
Name matching combines fuzzy scoring with a surname-support check, so a customer who happens to share a first name with a sanctioned individual isn't wrongly flagged — while genuine matches, reordered names and typos still surface for review.
The live selfie taken during liveness is matched, server-side, against the portrait on the ID document — closing the gap a liveness challenge alone can't: proving the person holding the phone is the person on the document, not just that a live face was in frame.
Tapping the ePassport's NFC chip via the AgentGuard Verify App Clip reads a cryptographically signed identity record straight from the document — the strongest tier available, and the one competitors charge most for. Live on the App Store as a premium option; the equivalent Android build is still in progress.
Document image, selfie, face-match distance, the sanctions/PEP screening replay with the list version and fetch date used, and the full activity timeline — downloadable as PDF, or a ZIP of the whole pack. Not a badge for the customer to see; a private file the firm can hand a regulator.
Evidence is retained for 5 years per MLR Reg 40 with an application-level retention lock, and — where a dedicated evidence bucket is provisioned — S3 object-lock that even an administrator can't override early. Every view of a customer's ID imagery is itself logged.
A firm can opt a customer into monthly, quarterly or annual re-screening against fresh sanctions and PEP data — no re-contact needed — with a monitoring-run record written either way, because "no change" is itself evidence.
Build the identity-verification and screening engine once, point it at the next regulated profession. Each product adds its own onboarding, pricing and regulator-specific detail on top of the same verify flow, matcher and evidence pack.
The engine's original home — full CDD suite plus continuous AML compliance scanning against HMRC supervision and redress rules.
Client due diligence for SRA-regulated firms, alongside the SRA Transparency Rules scan and the Legal Sector Affinity Group policy pack.
Client due diligence with sanctions & PEP screening for HMRC-supervised accountancy practices.
Client & provenance due diligence for HMRC-supervised art-market participants under the Money Laundering Regulations.
The same verify flow also underpins right-to-work identity capture for care and visa-sponsor customers — same document read, same face match, a different purpose flag rather than a different codebase.
We'd rather tell you where the edges are than let a customer or a regulator find them first.
A random head or hand challenge on its own only proves a live person was in front of the camera — it doesn't prove that person is the document holder. That binding comes from the server-side face match (standard) or the passport-chip read (premium), not from liveness by itself.
The AgentGuard Verify App Clip is live on the App Store and reads the NFC chip in an ePassport. It's an iPhone-only, opt-in upgrade tier, not the default path — most checks complete on photo + face match. The Android equivalent is still being built.
A below-threshold face match, an unreadable document, or a stale sanctions list never silently clears a customer — each routes to a human review. A genuine sanctions or PEP match is never downgraded by anything downstream.
Enhanced due diligence on a PEP or review case is a human decision an operator records — there's no automated EDD workflow behind it yet. Ongoing monitoring is opt-in per customer, not switched on for everyone by default.
The engine described here is live in production on AgentGuard, FirmGuard, PracticeGuard and ArtGuard — not a roadmap.