Compliance Pack · UK-regulated lenders + factors + credit insurers
Continuous KYB is no longer a choice.
Here’s how RecoupIQ closes the gap.
The FCA has moved on from annual KYB reviews. SYSC 6.3, the Financial Crime Guide Chapter 3, JMLSG Part I §5.3.13, and FATF Recommendation 10 all converge on the same requirement: perpetual, ongoing monitoring of every business relationship. This document maps every signal RecoupIQ surfaces to the specific guidance it satisfies, so a compliance officer can approve a pilot from this page alone.
1. What the regulators actually require
FCA SYSC 6.3.1R (Financial Crime). Authorised firms must take reasonable care to establish and maintain effective systems and controls for countering the risk that the firm might be used to further financial crime. Includes ongoing monitoring of business relationships.
FCA Financial Crime Guide, Chapter 3 (FCG 3). Customer due diligence is “not a one-off event”, firms must “keep their knowledge of customers up to date” throughout the business relationship. Annual reviews are explicitly named as insufficient where the customer’s risk profile or activity changes more frequently.
JMLSG Part I §5.3.13. Ongoing monitoring includes scrutiny of transactions AND keeping documents/data/information up to date. Trigger-based reviews are encouraged where new external information surfaces, exactly the signal-firehose model RecoupIQ delivers.
FATF Recommendation 10. Conducting ongoing due diligence on the business relationship and scrutiny of transactions throughout the course of that relationship.
2. The 21 RecoupIQ signals, mapped to FCA guidance
Every priced output carries a confidence block citing which signals contributed and their source tier. The table below maps each signal class to the FCA guidance it satisfies. Buyers should retain the per-counterparty priced_risk.provenanceblock as evidence of continuous monitoring.
| RecoupIQ signal | Source | FCA / JMLSG / FATF satisfies |
|---|---|---|
| OFSI sanctions hit | HM Treasury OFSI Consolidated List | SYSC 6.3 (financial crime), SAMLA 2018 strict-liability sections |
| FCA Warning List match | FCA published warning list | FCG 3, FSMA 2000 s.19 |
| Disqualified-officer cross-reference | CH Disqualifications Service | JMLSG §5.3.13 (data refresh), CDDA 1986 |
| Gazette insolvency notice | UK Gazette real-time feed | FCG 3 (trigger-based review), Insolvency Act 1986 |
| Companies Court winding-up petition | Companies Court cause list | FCG 3 (earliest leading indicator) |
| Recoverable-asset signal | HMLR CCOD / OCOD | FCG 3 (financial-circumstances change) |
| Offshore-control flag | HMLR OCOD ⋈ CH ROE | FATF Rec 10 (beneficial-owner refresh), ECTEA 2022 |
| ECCTA director-ID verification status | CH ECCTA 2023 register | FCG 3, ECCTA 2023 |
| HMRC defaulter list match | HMRC PDDD | FCG 3 (tax-compliance change) |
| Secured-creditor stack | CH Charges Register | FCG 3 (financial-circumstances change), CA 2006 Part 25 |
| Phoenix Six-Indicator | INSS published methodology | FCG 3, CDDA 1986 |
| SIC-code change | CH CS01 delta | FCG 3 (activity-profile change) |
| Filing-latency trajectory | CH filings cadence | JMLSG §5.3.13 (document refresh) |
| Logistic / boosted-tree PD | RecoupIQ model trained on outcomes | FCG 3 (risk-based approach) |
| Capital-bleed velocity | iXBRL YoY analysis | FCG 3 (financial-circumstances change) |
| iXBRL reconstruction-loss anomaly | iXBRL autoencoder | FCG 3, SYSC 6.3 (financial-statement red flag) |
| Director-network risk | CH officer graph | FATF Rec 10 (beneficial-owner network) |
| Group-structure stress | PSC chain propagation | JMLSG §5.3.13 (group-level data refresh) |
| News-distress signal | INSS RSS + UK press | FCG 3 (trigger-based review) |
| Sector stress (cluster momentum) | RecoupIQ sector cohort analysis | FCG 3 (sector-level risk-based approach) |
| Beneish M-Score | iXBRL 3-component variant | FCG 3 (earnings-manipulation red flag) |
3. How buyers retain the evidence
Every RecoupIQ API response includes a priced_risk.provenance block listing the exact components that contributed to the assessment, a methodology version stamp, a confidence grade (A regulator-primary → D rules-based heuristic), and a Right of Reply URL. The buyer’s compliance team retains this block alongside their KYB file as the auditable record of continuous monitoring.
For ECCTA s.199 Failure-to-Prevent-Fraud-covered buyers (UK organisations meeting two of: >£36m turnover, >£18m balance-sheet, >250 employees), the ECCTA Evidence Pack extends the same evidence trail to per-screening event level.
4. What this means in practice
For UK-regulated invoice-finance lenders, factors, asset-based lenders, and credit insurers, the FCA position now reads:
- Annual-only KYB is non-compliant where the borrower’s risk profile can change between reviews, which it always can for SME counterparties.
- Evidence of attempted monitoring is required, not just a clean-at-onboarding snapshot.
- Trigger-based scrutiny when new external information surfaces is the published expectation. RecoupIQ is the trigger feed.
For a 2,000-supplier book, a typical compliance team cannot manually monitor each counterparty in real time. The choice is: build the monitoring layer in-house (estimated 18-24 months + ~£2m fully-loaded), or integrate RecoupIQ’s API at /api/v1/risk-assess in a single sprint. The methodology is published at /methodology; the external audit invitation at /audit-our-numbers.
5. Next step for compliance approval
Email [email protected] with:
- Your firm name, FRN, and the relevant SYSC obligation.
- Whether you need a sandbox API key for compliance evaluation (free, rate-limited).
- Whether you also need a written response to specific FCA queries (we can produce one within 48 hours).
We will reply within one working day. Sandbox keys never carry production-metering charges; pilot deployments retain the full Right-of-Reply path.