Full-stack · RegTech · Swiss AML/KYC

ComplySwiss — compliance operations, built into one system.

ComplySwiss is a Swiss-focused AML/KYC and GwG compliance SaaS platform I am designing and building end-to-end. The goal is to give compliance teams a structured operating system for customer due diligence, risk assessment, PEP and sanctions screening, evidence, transactions, alerts, cases and auditability — without stitching together disconnected spreadsheets and tools.

Role
Founder / product builder
Market
Switzerland / GwG
Architecture
Multi-tenant SaaS
Stack
PHP · MySQL · JS
The problem

AML work is not one screen. It is a chain of evidence and decisions.

Customer onboarding, KYC reviews, beneficial ownership, screening, transaction monitoring, alerts and investigations all create information that must remain connected and explainable. ComplySwiss is designed around that lifecycle rather than around isolated forms.

01 · Customer due diligence

One AML dossier per customer

Identity and company data, addresses, KYC status, beneficial owners, Source of Funds, Source of Wealth, documents, periodic review and risk history are brought together in a single dossier.

02 · Screening

PEP and sanctions controls

Customer and beneficial-owner screening integrates with OpenSanctions, records candidate matches, preserves the analyst conclusion and tracks when screening becomes due again.

03 · Evidence

SoF / SoW and document lifecycle

Supporting evidence can be uploaded, verified or rejected with review notes. Document status, expiry and replacement history remain visible for follow-up and audit preparation.

04 · Monitoring

Transactions → rules → alerts → cases

The operating model connects customer activity to transaction monitoring, configurable rules, AML alerts, compliance cases, case notes, evidence and approvals.

Operating model

A traceable workflow from firm to audit.

The product architecture follows the real compliance process, with organisation-level segregation and role-based access around the entire flow.

Firm / Organisation
Customer & UBO
Transactions & Rules
Alerts & Cases
Audit trail / export
What I built

Product, data model, workflows and delivery.

Multi-tenant foundation

  • Firm / organisation segregation
  • Users, roles and permissions
  • TOTP two-factor authentication
  • Security-conscious session and audit patterns

AML/KYC operations

  • Customer and company KYC profiles
  • Beneficial owners and control persons
  • Periodic KYC reviews
  • Explainable inherent AML risk scoring

Case management

  • AML alerts and compliance cases
  • Assignment, notes, evidence and status workflow
  • Approval and segregation-of-duties patterns
  • SRO-oriented audit exports

Engineering & deployment

  • PHP application architecture
  • MySQL relational schema
  • Responsive HTML/CSS/JavaScript UI
  • GitHub PR workflow and automated PHP syntax checks
Design decisions

Compliance completeness is separated from inherent AML risk.

A missing document or incomplete onboarding step should create a compliance action, but it should not automatically make a customer inherently high-risk. The product therefore tracks completeness, evidence quality and inherent risk as related but distinct dimensions.

Explainability first

Risk factors, screening outcomes, analyst conclusions and changes are recorded so a reviewer can understand not only the current status, but how it was reached.

Swiss context

The product is being shaped around Swiss GwG workflows and the needs of smaller and mid-sized compliance teams, with German as the default backend language and English retained for international use.

Live project

Explore ComplySwiss.

The platform is under active development. The public project site presents the product direction while the application continues to evolve through staged releases.