Skip to content

The Wwft check?
The register knows.

Your client files sit in folders. A folder cannot tell you what is valid, what expires when, or who still owes you a document — a register can. Evidence belongs in an evidence store, so it goes into the vault one document at a time.

What the folder knows

  • paspoort_scan.pdf
  • KvK-uittreksel-2023.pdf
  • beschikking_30procent.pdf
  • opdrachtbevestiging.pdf

Four files. No status, no dates, no evidence — and no way to see that a fifth document was never collected at all. To answer “do we hold a valid passport copy for this client?” somebody opens the folder and reads.

What the register knows

Client score62
DocumentStatusExpires
Passport / ID copyWwft-mandatoryPresent12 FEB 2027
KvK extractWwft-mandatoryExpiring04 NOV 2026
30% ruling decisionExpiring30 JUN 2027
Engagement letterPresent
UBO register extractWwft-mandatoryMissing

One missing Wwft-mandatory record forces the client red, whatever the score would otherwise be.

The same five documents, as records. Completeness is a number, expiry is a date, and a missing Wwft-mandatory item is impossible to miss.

Demonstration data — not a real client

What the Wwft actually asks of you

If your firm keeps books, files tax returns, runs payroll or provides corporate services, you are an institution under the Wwft and BFT supervises you. Three obligations drive the whole register.

Wwft art. 3

Know the client, and the people behind it

Identity established and verified, legal form and registration for entities, every ultimate beneficial owner identified and verified, the purpose and intended nature of the relationship, and a risk classification you can explain.

Wwft art. 33

Be able to show what you did

The data and the verification evidence are recorded and retrievable. Completeness you cannot demonstrate is completeness you do not have.

Wwft art. 33/34

Keep it five years, then destroy it

Five years after the relationship ends the file must still be there — and then the personal data has to go, because the GDPR takes over where the retention duty stops.

Ongoing monitoring is the part that catches firms out: the file has to stay current, not just be correct on the day it was opened.

How it works

Five moving parts. One of them does ask you to move something — the evidence, deliberately, and only the evidence.

  1. 01

    Evidence belongs in an evidence store

    Your working folders stay yours. What the file has to prove goes into a separate vault in the EU — uploaded deliberately, one document at a time, because an automated sweep files an email as a passport. Nothing is migrated in bulk.

  2. 02

    The checklist builds itself

    Legal form and the services you provide decide which documents apply. A B.V. gets the corporate set; a private client gets the expat set. Nobody maintains a spreadsheet of who needs what.

  3. 03

    Completeness becomes a number

    Wwft-mandatory items weigh triple, service-specific double, good-to-have single. Valid scores full, expiring scores half, missing scores nothing — and any missing mandatory item forces red regardless.

  4. 04

    Expiry stops being a surprise

    Every date is watched. A passport, a KvK extract going stale, a 30% ruling running out — each one crosses its thresholds long before it becomes your problem.

  5. 05

    You set how often it re-checks

    The register verifies itself — that the vault still holds every document the file claims — as often as you choose, at no cost per run, and once a day it reads files back out of the vault byte for byte, because metadata alone proves nothing. Re-verifying against an outside source is priced per check: a Handelsregister lookup, a sanctions and PEP screening. You pick the cadence and you can see what it costs, instead of buying a subscription that decides for you.

What is live, what is next

KYC Vault runs a real firm's Wwft files every day. It is not a finished product for sale to everyone yet, so here is the honest split.

Live

  • Client register with weighted completeness scoring
  • Wwft checklist per legal form and service mix
  • Document vault in the EU, uploaded document by document
  • ID copies read automatically, then masked by hand
  • Sanctions, PEP and adverse-media screening — run when you ask, and re-screened at least every six months, enforced by the register
  • Screening of the client entity as well as its people
  • Every question as a report: on screen, as a spreadsheet, or as a letterhead PDF — including one client's entire file as a single hand-over document
  • Expiry reminders and a weekly digest to the firm, sent automatically
  • Client portal in EN and NL: a one-time sign-in link, a plain-language list of what is still needed, and never a document
  • Self-check that the vault still holds what the file claims — read back for real, daily
  • Backups restored and verified by drill on a fresh server, not assumed — last drill 23 August 2026
  • Handelsregister verification, and onboarding from a KvK number
  • Retention queue, and destruction across both stores with evidence
  • Two-factor sign-in enforced, and a read-only auditor role
  • Audit log on every record change; EU hosting, row-level access

Next

  • Reminder mail to the client as well
  • Continuous AML monitoring between screenings (a deeper provider integration — until then the six-month re-screen rhythm above carries the duty)

The next twelve months

The one thing a folder can never do is look forward. The register knows what expires before it expires.

Expiries per month34
  • AUG 262
  • SEP 260
  • OCT 265
  • NOV 263
  • DEC 261
  • JAN 277
  • FEB 274
  • MAR 270
  • APR 272
  • MAY 276
  • JUN 273
  • JUL 271

Illustrative distribution, not a customer's data.

Where the data lives

Hosted in the EU

The app and the document vault live in Frankfurt, Germany; error monitoring runs in an Amsterdam datacenter. All of it inside the EU.

ID copies masked, originals destroyed

Once an ID document has been read, the copy kept in the vault is masked by hand and the unmasked original destroyed. Stricter than the law strictly requires — a chosen position, and one that is explicable at an inspection.

BSN isolated, administrators only

The BSN sits in its own table that only administrators can reach, is stripped out of the audit log, and never appears in a report or an email.

Access takes two factors

Every staff sign-in needs a password and an authenticator code, and the database itself refuses to answer without both — it is not just a login screen. An auditor can be given a read-only role: every record visible, none of them changeable.

Early access

We are opening KYC Vault to a small number of Dutch firms. Leave an address and we will get in touch before it opens up.

We use this only to contact you about KYC Vault. No list, no newsletter.