HomeInsightsRethinking KYC onboarding
RegTech · KYC / Onboarding
Rethinking KYC onboarding: from paperwork to risk-based decisions in minutes
Digital ID, sanctions screening, hybrid AI risk scoring, beneficial ownership capture — and the audit trail regulators expect, by default.
Published 22 April 2026 · 7 min read
Most Mauritius firms still onboard clients the way they did in 2015 — PDFs emailed back and forth, a risk score typed into a spreadsheet, sanctions screening done in a separate tool, and Enhanced Due Diligence triggered by whoever happens to remember. The result: weeks to onboard a simple corporate, and audit trails no MLRO wants to defend.
The regulator has moved. The FIAML Regulations 2018 require a risk-based approach with documented rationale. The FCC Guidelines on Legal Persons (2023) raise the bar on beneficial ownership. And inspectors now expect to see, on screen, the decision trail for a specific client file — not a reconstruction from three different systems. It is time to rethink the onboarding stack.
Why the old stack breaks
A traditional onboarding setup typically comprises:
- A PDF client application form.
- Scanned ID documents emailed to the compliance team.
- A separate sanctions/PEP screening tool — or worse, a free web search.
- A spreadsheet for risk scoring.
- Word documents for EDD memos.
- A shared drive for archiving the whole thing.
Each handoff introduces delay, error and inconsistency. When an inspector asks why a high-risk client received a medium rating, three staff members must piece together the answer from three systems. Nobody has a single, defensible audit trail.
What a modern stack looks like
Sherlock Onboarding was designed to replace that entire stack with a single, regulator-aware workflow. The core capabilities:
Digital identity verification
Mobile-first document capture, liveness detection, document authenticity checks. The client never has to print, sign and scan — and you get a time-stamped, tamper-evident record of the verification event.
Continuous sanctions, PEP and adverse media screening
Screening against UN, EU, OFAC, HMT and other consolidated lists, updated in near-real-time. PEP status and adverse media are screened at onboarding and monitored on an ongoing basis — so a client who becomes a PEP, or is newly sanctioned, surfaces on your MLRO dashboard without manual intervention.
Hybrid AI risk scoring
This is where Sherlock differs from most onboarding tools on the market. Risk scoring is hybrid: deterministic rules (geography, industry, product, PEP status, beneficial ownership opacity) carry full weight, and AI-generated insights from open-source research carry 50% weight. The MLRO keeps final control. No black-box AI decision. No "the algorithm said so".
Enhanced Due Diligence workflows
When a rule-based trigger or AI insight raises the risk profile, the EDD workflow opens automatically, with the right fields pre-populated, the right source-of-funds questions, and a structured memo template. The MLRO’s decision — approve, decline, escalate — is captured with reasoning.
Beneficial ownership capture
Beneficial ownership is captured per the FCC Guidelines on Legal Persons — ultimate natural person owners identified, thresholds applied, corroborating evidence uploaded, and chain-of-ownership diagrams generated where applicable.
Built-in transaction monitoring
Critically, Sherlock Onboarding does not end at onboarding. The same platform runs post-onboarding transaction monitoring against the risk profile you captured at day one. No handoff to a second platform. No reconciliation between two risk systems. One defensible record per client, from onboarding through ongoing monitoring through offboarding.
The evidence trail, by default
Under FIAMLA and the FIAML Regulations 2018, you must evidence that your onboarding was risk-based, documented, and proportionate. Sherlock generates that evidence as a by-product of how the platform works — not as a separate exercise at audit time:
- Every decision logged with timestamp, user, rationale.
- Every screening hit saved with full record of the review.
- Every escalation traceable from trigger to outcome.
- Full export, per client, on demand.
What changes operationally
Clients notice the change immediately: a corporate onboarding that used to take 10 working days now completes in 2–3. The compliance team notices something different: instead of spending time collecting evidence, they spend it reviewing it — which is what a skilled MLRO function is actually for.
And when the FSC or FIU arrives on inspection, the answer to "show me how you onboarded this client" is no longer a half-day scramble. It is a single export, signed off by the MLRO, matched to the underlying regulation.
See Sherlock Onboarding in action
Book a 30-minute demo. We’ll walk through the onboarding flow, the hybrid risk scoring, and the MLRO dashboard — using your own example profiles if you prefer.
Related
RegTech · DNFBP · Real Estate
Real-time transaction screening for Mauritius real estate agents and notaries
How Sherlock Transactions screens in real time for sanctions, PEPs, adverse media and ML typologies — built for the DNFBP reality.
Read article →AML/CFT · CDD & EDD
Enhanced Due Diligence: when, how and what to evidence
When EDD is triggered, what it must cover, the evidence pack regulators expect, and the six failures cited most often in audit reports.
Read article →AML/CFT · Audit
Is your AML/CFT framework ready for an independent audit?
What regulators actually expect from an independent AML/CFT audit, how to scope it, and the common gaps we see across Mauritius licensees.
Read article →