Module 5: Risk & Compliance Orchestration Available

Connect your compliance workflows, keep your authorisation.

The compliance module connects KYC, KYB, sanctions, wallet screening, transaction monitoring, and Travel Rule workflows through configurable integrations. You select the vendors from each category and operate them under your own authorisation. Your policy defines thresholds and tolerances. OVAAL orchestrates the workflows and records the evidence. Everything is instrumented, logged, and exportable for your auditor or regulator.

The compliance surface.

Categories you connect, not vendors we lock you into.

WorkflowWhat it doesProvider category
KYC / KYBIdentity and business verification feeding the account recordKYC/KYB providers (partner-chosen)
Travel Rule messagingOriginator and beneficiary data exchange on qualifying transfersTravel Rule providers (partner-chosen)
Transaction monitoringOngoing monitoring, sanctions, and risk-category scoringAML screening vendors (partner-chosen)
Wallet & address screeningPre-transfer destination checks against sanctions and high-risk clustersAML screening vendors (partner-chosen)
Settlement railsPayout and settlement to regulated railsEMI / SEPA rails partners (partner-chosen)
Audit-log exportSigned JSON or CSV, queryable by transaction, user, rule, or timeOVAAL-native
Incident responseJoint runbook per partnerOVAAL + partner on-call

Specific vendor names within each category are disclosed in the gated compliance pack, where contractually allowed, not on this page. That keeps the integration provider-neutral and your options open.

Who owns what.

Where your license meets OVAAL's orchestration.

ResponsibilityPartnerOVAAL
Regulated license (CASP / EMI / VARA / CBB)Holds the licenseTechnology role unless expressly authorised
End-user KYC and KYBPolicy ownerWorkflow orchestration
Source-of-funds policyDefinesOrchestrates against the partner's policy
Transaction monitoring and sanctionsSets thresholdsConnected vendor executes; OVAAL records
Travel Rule messagingPolicy per jurisdictionIntegration handles the exchange
Custody of end-user fundsPartner or authorised providerNon-custodial
Breach notification to regulatorsPrimarySupports with incident data

OVAAL is designed to support deployments by authorised firms operating in regulated markets. It is not itself a bank, EMI, or CASP, and does not provide the regulated service. The partner's authorisation owns those obligations; OVAAL orchestrates against the partner's policy.

Compliance is one module across the OVAAL platform; settlement rails are connected from money movement. For the full customer, OVAAL, and authorised-provider split, see the compliance responsibility model.

Built for the auditor in the room.

Configurable

Pick your vendor in each category; swap without re-architecting

Recorded

Every check, exception, and decision logged against the instruction

Exportable

Signed audit logs for your auditor or regulator on demand

Independent security review Access controls & audit logging NDA materials on request Non-custodial architecture

Partner compliance pack on request.

DPA template, sub-processor list, the named vendors per category where contractually allowed, security posture, an audit-log export sample, a joint incident playbook, and the MSA template.