Use Cases
Customer Due Diligence (KYC)Company Verification (KYB & UBO)Screening (PEP, Sanctions, Adverse Media)Transaction Monitoring & SARsOngoing MonitoringClient OnboardingEnhanced Due DiligenceBy Industry
Banking & FinanceFintech & PaymentsCrypto & Digital AssetsWealth ManagementGambling & iGamingLegal & Professional ServicesLuxuryLearn
LearnPlain-English explainers on compliance and identity verificationVideosShort walkthroughs of Compliance Hub in actionBuild
DocumentationUser guides and API referenceMarketplace240+ connectors and providersPartner ProgramBecome a Zenoo partnerCompany
AboutOur story and missionThe Honesty BoxOur real delivery timelines, liveNewsroomPartnership announcements and company newsContact UsGet in touchIdentity verification gaps, agentic compliance workflows, and the FCA's Supercharged Sandbox move into sharper focus this week
A data point surfaced in this week's field material that is worth sitting with. A wealth management operation ran a retrospective review of 20 client screening cases where a primary identity verification tool returned partial matches and failed verification. In 13 of those 13 partial-match failures, a secondary data provider achieved the minimum two-match, two-source threshold required by their process. The average result was not marginal: 4.85 data matches from 4.54 sources, roughly 140 per cent above the stated floor.
That number matters for two reasons. First, it suggests that partial-match failures at the primary layer are not necessarily indicative of genuine verification problems; they may indicate coverage gaps specific to that tool. Second, it points to a design question that many teams avoid: if your waterfall configuration is correctly set up and you are still seeing systematic divergence between two providers on the same cases, the issue is almost certainly data source composition, not process failure.
The team in question has raised the divergence with their primary vendor and noted that the gap persisted even after a configuration update. That is not unusual. Identity data vendors update their source weighting and match logic on their own release cycles, and those changes are not always communicated in time for compliance teams to recalibrate thresholds.
The practical implication: any team relying on a single-layer identity check without a defined secondary fallback should review their partial-match failure rate against an alternative provider, even informally. The cost of a structured review is low. The cost of systematically over-declining verifiable customers is not.
FCA censures a firm for undisclosed commissions in financial promotions. The FCA censured a securities firm, Equity for Growth (Securities) Limited, this week for approving minibond promotions that failed to disclose high commission fees charged by appointed representatives and introducers, and did not state that those fees would be deducted from investor funds. The censure is a reminder that responsibility for promotion approval sits with the authorised principal, not the appointed representative. Compliance teams that approve third-party promotions should have documented confirmation that fee structures are disclosed in plain terms before sign-off.
Anthropic joins the FCA's Supercharged Sandbox. The FCA announced that Anthropic will provide Claude, including Claude Code, to participants in the second cohort of its Supercharged Sandbox. Use cases in scope include agent-led payments, fraud and economic crime detection, and AI governance. This is the most concrete signal yet that the FCA is willing to let firms test large language model capabilities in a supervised environment rather than simply issuing guidance about risks. It does not mean those capabilities are validated for production use; the sandbox is explicitly a controlled experiment. Compliance leaders evaluating AI tools should note what comes out of this cohort in late 2026, rather than drawing conclusions now.
FCA moves on operational resilience oversight. A blog post from the FCA this week reiterated the scope of its new oversight regime for critical technology and data providers operating behind the scenes in financial services. The framing is explicit: resilience failures by third-party providers are treated as system-level risks, not just vendor problems. Teams that have not yet mapped their critical third-party dependencies against the new regime should treat this as a prompt.
Consumer Duty outcomes monitoring. The FCA published a reminder this week that outcomes monitoring under Consumer Duty is expected to go beyond data collection. The emphasis was on firms identifying where customers are struggling and acting before harm occurs. For AML and onboarding teams, this reinforces the case for tracking decline rates and manual review queues by customer segment, not just in aggregate.
Transaction reporting harmonisation. The FCA and the Bank of England appointed members to a new taskforce on harmonising transaction and post-trade reporting across UK MiFIR, UK EMIR, and UK SFTR. Three working groups have been formed. This is early-stage policy work, but firms with reporting obligations across more than one regime should monitor it.
The field items, the sceptic's corner and this week's research read. One email, then a six-digit code.
This content is free, but you must be subscribed to the Zenoo Compliance Brief to continue reading.
Free · Curated by compliance practitioners · Zero spam
Already a subscriber?