For regulated practices
Should KYC and AML live inside your case management system?
Your case management system should know the matter. Your onboarding software should collect the people, checks, funds, forms and decisions needed to make that matter ready for review. A microapp or API can connect the two without forcing the practice to replace either system.

This guide is general information for regulated practices. It does not replace current legislation, sector guidance, professional judgement or your practice's risk-based policies.
01
Start client onboarding from the matter
KYC and AML do not need to be built into a case management system to feel like part of it. They need the right matter context, a secure connection and a clear route back into the practice's record. That can come from an embedded microapp, a server-to-server API or a simpler link-based setup.
A disconnected identity check creates avoidable work. Someone opens a matter, signs into another product, types the client details again, sends a request, waits for a result and then moves the evidence back into the case management system. The check may be digital, but the process around it is still manual.
Starting from the matter removes that duplication. The matter reference, type, responsible person and parties can determine which onboarding work is needed. Progress can then return to the system where the practice manages the case.
- Create the onboarding record from the matter rather than rekeying it.
- Keep each person's role clear, including clients, directors, beneficial owners and giftors.
- Use matter type and risk decisions to assign the right work.
- Return useful progress and completion information to the case management system.
02
A KYC result is only one part of onboarding
Identity verification and AML screening matter, but they do not complete the file. A regulated practice may also need to understand the purpose of the work, beneficial ownership, Source of Funds, Source of Wealth, third-party contributions and the risks associated with the client or matter.
The client may need to complete forms, provide supporting documents, receive terms and sign a Client Care Letter. If a family member is providing a gift, the practice may need a separate explanation and evidence from that person. Treating these as unrelated requests puts the chasing back on the fee earner and makes the final review harder.
- Identity document and biometric checks.
- AML screening, including PEP and sanctions results where applicable.
- KYB, ownership and relevant people for business clients.
- Guided Source of Funds with evidence for each declared source.
- Giftor invitations for identity, AML and Source of Funds work.
- Matter forms, documents, terms and electronic signatures.
- A recorded risk assessment and the practice's final decision.
03
What matter-centred onboarding looks like
A useful workflow changes with the case. A conveyancing purchase may need property details, tenure, Source of Funds and giftor evidence. An accountancy instruction may need business verification, beneficial owners and different documents. The system should assign what applies rather than send every client the same checklist.
Clients then receive one secure, passwordless link. They can save their progress and return without creating an account. Smart reminders can focus on the work that is still outstanding, including partially completed steps, instead of sending the same generic chase to everyone.
As the information arrives, Verify Client organises it around the matter. Where applicable, it can prepare an editable risk assessment draft from the collected evidence. The practice remains responsible for reviewing the file, changing the assessment where needed and recording its decision.
- One client request shaped by matter type, party role and practice policy.
- Focused correction requests when a document or answer needs more work.
- Progress-aware reminders rather than repeated manual chasing.
- One review record that brings evidence, outcomes and decisions together.
04
Choose an embedded microapp or API integration
Different practices need different levels of connection. A launched MicroApp gives a firm user access to an approved specialist interface from the firm portal. Verify Client issues a short-lived, single-use launch token, which the MicroApp exchanges for an access token limited to that practice, app and user's permissions.
A server-to-server API integration works in the background. A case management system can create an onboarding matter, add parties, choose the primary client, generate the configured Client Care Letter and send invitations. It uses confidential credentials to request a short-lived system token, and each action needs an explicit scope enabled by the practice.
Status webhooks can tell the connected system when onboarding changes, while controlled read endpoints support reconciliation. This lets the case management system remain the operational record without forcing it to reproduce the detailed client experience or compliance workflow.
- Use a MicroApp when a person needs a specialist interface inside their working day.
- Use the API when another system should create or update onboarding in the background.
- Use both when staff need an embedded workspace and the systems also need automatic synchronisation.
- Start with secure links when a deeper connection would not remove meaningful work.
05
Build the integration around control and evidence
An integration should not receive broad access simply because it is convenient. Give each app only the actions it needs. Keep client secrets out of browser code, use short-lived access tokens and apply source restrictions where appropriate.
The record should also show whether an action came from a firm user, a launched app or a background integration. Automated collection can prepare the file, but it should not hide exceptions or present a provider result as the practice's final decision.
- Select the smallest practical set of API scopes.
- Store confidential credentials in a server-side secret manager.
- Keep app, practice and actor attribution in the audit record.
- Separate provider outcomes, client completion and practice review.
- Retain human control over risk and acceptance decisions.
06
Questions to ask before choosing an integration
A product can claim to integrate with case management while doing little more than copying an identity result into a document folder. Test the whole process with a real matter. Include more than one client, a failed document, a giftor, an incomplete Source of Funds declaration and a review exception.
Follow the matter from creation to final review. Count every manual login, copied field, downloaded file and chase email. Those steps reveal whether the integration removes work or merely moves it.
- Can the case management system create the matter and its parties without rekeying?
- Can workflows change by matter type, party role and assessed risk?
- Does Source of Funds collect explanations as well as documents?
- Can giftors or other third parties complete their own relevant work?
- Are forms, terms, documents and signatures part of the same request?
- Do reminders respond to what the client has already completed?
- Can staff request a focused correction without restarting onboarding?
- Does the practice receive a review-ready record with an audit history?
- Are API permissions narrow, visible and revocable?
- Can the practice keep its existing case management system?
Questions regulated practices ask
Does KYC need to be built into a case management system?
No. KYC can be connected securely through an embedded app or API. The important test is whether the matter starts the correct onboarding work and receives useful progress and completion information without staff rekeying data or moving evidence manually.
What is the difference between KYC integration and client onboarding integration?
A KYC integration usually starts an identity or screening check and returns its result. A client onboarding integration can also coordinate Source of Funds, KYB, giftors, forms, documents, terms, signatures, reminders, risk assessment and the final review record.
Can Verify Client work with an existing case management system?
Yes. A practice can start with secure links, launch an approved MicroApp for firm users or use a server-to-server API integration. The appropriate model depends on which work needs to happen automatically and which system should remain the operational record.
What can the Verify Client API automate?
A scoped API integration can create onboarding matters, add or update parties, choose the primary client, generate a configured Client Care Letter, send invitations and receive status updates. Available actions depend on the permissions enabled by the practice.
Does an automated risk assessment replace the practice's decision?
No. Where applicable, Verify Client can prepare an editable draft from the onboarding information and evidence. The practice reviews it, makes any necessary changes and records the final decision.

