Every broker says it takes compliance seriously. The test is not the policy document — it is the Tuesday afternoon reality: where exactly does a client's passport photo live? Who saw it? When a reviewer rejects a proof of address, is the reason recorded anywhere a regulator could read it two years later? Firms fail compliance reviews not because they lacked a policy, but because their daily workflow could not produce evidence of the policy being followed.
That is why KYC and AML belong inside the CRM — the system where clients, money and staff already live — rather than in a shared drive and a spreadsheet beside it. Here is what the workflow looks like when it is built in.
Verification at the Front Door
The pipeline starts before any document: clients sign in with a code by email — passwordless, so there is no credential database to breach — with optional two-factor security, and their email is verified by construction. Identity verification then runs whichever way your compliance model prefers: automated through Sumsub, Onfido, Veriff or virtually any identity provider (each wired in via a one-click API integration), or manual document review by your own compliance team — many firms run automated checks with manual review as the escalation path. The CRM doesn't impose a vendor; it imposes a discipline: nobody withdraws a cent until verification is approved. The provider trade-offs are compared in KYC providers compared.
Documents: Private by Architecture
Identity documents are the most sensitive data a broker holds, and the standard failure is storage that was never designed for them — attachments in email threads, files in cloud folders with shareable links, images pasted into ticket systems. In the Singuard Broker CRM, documents are private by architecture: never on a public link, accessible only through the authenticated portal to exactly the roles that need them. A support agent answering tickets does not see passports; the compliance role does, because document review is its job — the role scoping enforced by the ops desk itself. Under it all, secrets and keys are encrypted at rest with AES-256-GCM, and the same private-by-default handling applies to everything a client uploads.
The per-Document Review Queue
Real clients are not "verified" in one binary step — they submit an ID, a proof of address, sometimes a source-of-funds document, and each has its own quality problems. So the review unit is the document, not the client. Each document lands in the compliance queue individually, where a reviewer approves or rejects it with a recorded reason. The mechanics matter more than they look:
- Precise client communication. "Your proof of address was rejected: document older than 90 days" resolves in one resubmission; "your verification failed" generates a support ticket and a churn risk.
- Reviewable decisions. Every approve/reject carries its reviewer and reason, so a second pair of eyes — or an auditor — can reconstruct the judgment, not just the outcome.
- Queue visibility. Managers see depth and throughput, catching a verification backlog before it becomes a stalled-deposits problem.
AML Posture: The Controls Around the Documents
KYC establishes who the client is; AML is the ongoing discipline around what they do. Inside the CRM that means: identity gating on money movement (no verified ID, no payout — enforced structurally, as covered in the withdrawals article); deposits and withdrawals that are counted exactly once and attributed to a verified identity, so the money trail is clean by construction; account controls for the moment something looks wrong — suspend, ban, revoke sessions; and the ability to answer "show me everything this client did, and everything we did about it" in minutes. This article is general information, not legal advice — your AML program, thresholds and reporting obligations are defined by your licence and your counsel (see AML basics for trading firms) — but whatever the program says, the CRM is what makes it executable daily.
Records That Cannot Be Quietly Edited
The last piece is the one regulators and payment partners weigh most: permanence. Every verification decision, document action, payout approval and account control in the CRM is written to a permanent record that no one can quietly edit — who did it, what, when. Not a log file someone rotates; a tamper-evident history that is part of the system of record. The practical consequences: disputes end quickly (the record answers), audits are cheap (evidence is a query, not an archaeology project), and internal misuse is deterred because everyone knows the history is unerasable. When a bank or PSP performs due diligence on your firm, this is the difference between "we have a policy" and "here is every decision we made under it."
Compliance, operationalized: private storage, per-document decisions with reasons, identity-gated money and an uneditable history. If your current stack cannot produce all four on demand, it is running on trust — and trust is not evidence.
Ready on Day One
None of this requires a compliance-technology project. The workflow above ships inside the Broker CRM as part of the bundle — KYC tools, queues, records and role scoping wired in from kickoff, with your preferred identity provider connected in one click — so a firm launching on the 24-hour plan starts its first client's verification with the same discipline it will have at ten thousand clients. Walk through the queue yourself in the live demo.
"KYC belongs inside the CRM, not bolted beside it. When verification, deposits and withdrawals share one record, compliance stops slowing operations."
— Roman Onta, Executive Director, Broker CRM & UI/UX
Key Takeaways
- Compliance lives or dies in workflow: documents, decisions and records — inside the CRM, not beside it.
- Identity documents must be private by architecture — never on a public link, visible only to the compliance role.
- Per-document review with recorded reasons resolves clients faster and makes every decision reconstructable.
- Permanent, uneditable records are what convert "we have a policy" into evidence a bank or auditor accepts.
Frequently Asked Questions
Can I Use My Own KYC Provider with the Broker CRM?
Yes — Sumsub, Onfido, Veriff or virtually any identity provider connects via a one-click API integration, and manual document review by your own team is always available alongside or instead. The workflow, queues and records are the same whichever you choose.
Who Inside My Firm Can See Client Identity Documents?
Only the roles you scope to it — by default the compliance function, through the authenticated ops desk. Documents are never exposed on public links, support agents work without seeing them, and every access path is governed by the same role model that runs the rest of the back office.
What Happens When a Client's Document Is Rejected?
The rejection reason recorded by the reviewer flows back to the client with clarity about what to fix, and the resubmission enters the same queue. Meanwhile the gate holds: an unverified client can explore the portal but cannot withdraw — the system, not staff vigilance, enforces it.