Connect your compliance workflows, keep your authorisation.
The compliance module connects KYC, KYB, sanctions, wallet screening, transaction monitoring, and Travel Rule workflows through configurable integrations. You select the vendors from each category and operate them under your own authorisation. Your policy defines thresholds and tolerances. OVAAL orchestrates the workflows and records the evidence. Everything is instrumented, logged, and exportable for your auditor or regulator.
The compliance surface.
Categories you connect, not vendors we lock you into.
| Workflow | What it does | Provider category |
|---|---|---|
| KYC / KYB | Identity and business verification feeding the account record | KYC/KYB providers (partner-chosen) |
| Travel Rule messaging | Originator and beneficiary data exchange on qualifying transfers | Travel Rule providers (partner-chosen) |
| Transaction monitoring | Ongoing monitoring, sanctions, and risk-category scoring | AML screening vendors (partner-chosen) |
| Wallet & address screening | Pre-transfer destination checks against sanctions and high-risk clusters | AML screening vendors (partner-chosen) |
| Settlement rails | Payout and settlement to regulated rails | EMI / SEPA rails partners (partner-chosen) |
| Audit-log export | Signed JSON or CSV, queryable by transaction, user, rule, or time | OVAAL-native |
| Incident response | Joint runbook per partner | OVAAL + partner on-call |
Specific vendor names within each category are disclosed in the gated compliance pack, where contractually allowed, not on this page. That keeps the integration provider-neutral and your options open.
Who owns what.
Where your license meets OVAAL's orchestration.
| Responsibility | Partner | OVAAL |
|---|---|---|
| Regulated license (CASP / EMI / VARA / CBB) | Holds the license | Technology role unless expressly authorised |
| End-user KYC and KYB | Policy owner | Workflow orchestration |
| Source-of-funds policy | Defines | Orchestrates against the partner's policy |
| Transaction monitoring and sanctions | Sets thresholds | Connected vendor executes; OVAAL records |
| Travel Rule messaging | Policy per jurisdiction | Integration handles the exchange |
| Custody of end-user funds | Partner or authorised provider | Non-custodial |
| Breach notification to regulators | Primary | Supports with incident data |
OVAAL is designed to support deployments by authorised firms operating in regulated markets. It is not itself a bank, EMI, or CASP, and does not provide the regulated service. The partner's authorisation owns those obligations; OVAAL orchestrates against the partner's policy.
Compliance is one module across the OVAAL platform; settlement rails are connected from money movement. For the full customer, OVAAL, and authorised-provider split, see the compliance responsibility model.
Built for the auditor in the room.
Pick your vendor in each category; swap without re-architecting
Every check, exception, and decision logged against the instruction
Signed audit logs for your auditor or regulator on demand
Partner compliance pack on request.
DPA template, sub-processor list, the named vendors per category where contractually allowed, security posture, an audit-log export sample, a joint incident playbook, and the MSA template.