The questions you actually want to ask

The things that only surface half an hour into a demo, written down instead. Including the answers that are not in our favour.

I keep my files in Excel and Word today. What does software add?

A spreadsheet shows you what a file looks like today. Under review that is not the question. The question is what you knew on the day you took this client on, and what you based it on.

Cloudpliant records every investigation as a frozen report: the checks, the outcomes, the risk classification and the exact list version screened against, with the date and time. That report never changes afterwards. Screen the same client a year later and a new report appears beside it, so you can see immediately what moved.

You can imitate that in Excel with filenames and folders, and it works exactly as long as everybody sticks to the convention.

Am I even allowed to automate my client due diligence?

The law prescribes a result, not a method. You need to know who your client is, what the risk is and why you reached that conclusion, and you need to be able to show it. How you get to that knowledge is yours to arrange.

What you cannot outsource is the responsibility. Not to us, and not to an AI either: “the model said so” is no answer in a review, because you have to be able to retell the reasoning. That is why there is no model in the classification and Cloudpliant makes no decision for you. The system gathers, screens, classifies by fixed rules and records. Accepting or declining is yours, with a motivation that lands in the file.

Software that promises to take over your client due diligence is promising something it cannot deliver.

The system rates a client I have known for twenty years as high risk. Now what?

Look at which factor caused it, and override it if you disagree.

The classification comes from a fixed thirteen-factor point count. Per client you can see which factors counted and for how many points, so high risk is never a black box you simply have to accept.

If you disagree you set the level manually with a motivation. That override is not a way around the system: it is recorded with your name and the date, which makes it evidence in itself that you thought about it deliberately. That is exactly what a reviewer wants to see.

See the full risk matrix

Do you use AI to determine the risk?

No, and that is deliberate.

Risk classification is a rule matrix: fixed factors, fixed points, fixed thresholds. Enter the same client again a year from now with the same details and you get the same answer. A language model does not give you that. It answers differently on Tuesday than on Monday, and cannot explain afterwards why.

You have to be able to explain to a supervisor how you arrived at a classification. That only works if the rules can be written down. Which is why the whole matrix is simply published on our site, rather than sitting inside a model we could not recount either.

Does that mean no model is ever involved anywhere? We are not promising that forever. It is quite possible that one day a model saves you retyping a KvK extract or an identity document, or notices that a name does not match what you entered. Even then it makes a proposal you confirm, the matrix determines the risk, and a person takes the decision. That distinction is the promise, not the absence of technology.

What we do and do not do with AI

What if a source is unreachable? Does my client come out clean?

No. That is possibly the most important rule in the entire system.

A check that did not run may never read as a clean client. If a lookup fails it is recorded as a failed check and the report comes out as incomplete, never as no findings. The client is not ticked off as screened, the existing risk classification is not overwritten, and the file stays open for another attempt.

The alternative is that an outage at a source presents itself as good news. That is the kind of mistake you discover years later, at the worst possible moment.

I already have a KvK integration. Is this not the same thing?

A KvK integration tells you who a company is: legal form, address, directors, activities. That is half the work, and Cloudpliant retrieves those details too.

The other half is whether something is wrong with the people behind it. Is a director on a sanctions list? Is the UBO politically exposed? Is there a bankruptcy running? The business register knows none of that, because it is not a risk register.

And then there is time. A KvK lookup is a snapshot. Cloudpliant keeps watching and tells you when something changes about a client you already took on.

Where is my client data stored?

In one place, and that is a choice. Your client files, the documents and every screening result sit on Hetzner servers in Falkenstein, Germany, in ISO 27001-certified data centres. One party, one country, one legal system for the data that matters.

A data processing agreement comes with it on every plan, the free account included. And you can always get it out: every report as PDF and as JSON, or all of them at once over the API.

Outside those servers at most one thing is involved per step, and we track per vendor where they sit and under which law. If you use identity verification, the vendor you picked does that one step on its own infrastructure. Our error reporting goes to an external service, but without client data: no names, no documents, no outcomes, no signed-in user. That is configuration rather than a promise, in all four processes that can report an error, and there is a test on it.

We pick vendors deliberately, and European where we can. Your data sits with a German host, the sanctions and PEP lists come out of Berlin, and the commercial register and the insolvency register are Dutch public bodies. For every vendor we record who they are, where they sit, which law they answer to and what data they see. That is more precise than one reassuring sentence, and you can read it back.

And no decision about your client comes out of an AI model: the risk classification is a rule matrix, and accepting or declining is yours.

How we secure your data

How much work is switching?

If you work in Exact Online, Nmbrs Accounting or HubSpot you connect it once and your relations are pulled in. From then on every new or changed relation is screened automatically and the report lands back in the system you already work in.

If you use something else you add clients manually or through the API. You do not have to retype your existing files first. Start with the clients due for review now and pick up the rest as their moment arrives.

And if you get stuck, we will help you move. Mail support@cloudpliant.com with how things are set up today and we will look at it with you. Before you are a customer, too.

See the integrations

Who is liable if something goes wrong anyway?

You are. That is not small print, it is how the system works: the obligation sits with the firm and you cannot pass it to a supplier.

What software can do is make the difference between 'we thought it was fine' and 'here is what we checked, when, against which source and against which version of it'. Under review only the second one counts.

A supplier telling you they take on the liability is mostly selling you a feeling.

Why are your prices simply on the site?

Because you should be able to compare without having to sit through a call first.

In this market 'price on request' is the norm. That is a choice and not a necessity: it puts a sales call in front of the answer to what something costs. We would rather do it the other way round.

You see what it costs before you speak to anyone, and you see where the cost comes from. Screenings against sanctions and PEP lists are billed per lookup by our provider, so those costs are real and we do not pretend they are zero.

It is also why re-screening a client within a day is free: that question has already been asked and already been paid for, so we do not charge it twice.

See the pricing

Do you screen continuously, or only when I take a client on?

Continuously, and the pace follows the risk. A low-risk file comes round every ninety days, neutral every month, high every week and unacceptable every day.

On top of that the system checks once each night whether the sanctions lists themselves moved. If they did not, those lists are not queried again and that night costs you nothing. If they did, the files that are due at that moment go past the lists again, and you hear about it when something changed about your client.

I only have thirty clients. Is this not overkill for a small firm?

The obligation does not look at your size. Thirty files have to be as complete as three hundred, except you have no compliance department for it. That does not make a small firm less obliged, it makes it more exposed to the handwork.

You do not pay per user here. Your whole firm is included on every plan, so you never have to choose who gets access. The integrations and the API are in from the free plan, not held back for a business tier.

Up to ten files it costs nothing. Above that it starts at a hundred euro a month for a hundred files.

See the plans

How do I know a hit is really my client and not someone with the same name?

You do not know for certain, and the system does not pretend otherwise. A hit on a list is a candidate, not a conclusion.

Every candidate comes with a match score and with the elements it was compared on: name, date of birth, country. You can see per element whether it lines up or contradicts, so you can judge for yourself whether this could be the same person.

If it is a namesake you dismiss the hit with a short note. That judgement is recorded with your name and the date, stops counting towards the score from then on, and does not come back at the next screening as if nothing happened. The judgement itself stays in the file, because the fact that you looked is evidence too.

Do I have to bother my clients with this?

Usually not. Screening against sanctions lists, PEP registers, the business register and the court registers happens without your client noticing anything.

Only when you need something from the client do you send one link. It opens in the browser, in Dutch, with no account and no app. Your client supplies the document or identifies themselves, and the result lands in the file as recorded evidence.

That is the difference with a passport scan by email: you do not have to assess it yourself and it does not sit around in your archive.

The AMLR arrives in 2027. Should I not just wait?

The AMLR applies from 10 July 2027 and will replace a large part of what the Wwft says today. Until that day the Wwft applies in full, so waiting means two years of building files you already know are not complete.

The direction is no surprise either. In places it gets stricter rather than looser: the UBO threshold moves from more than 25 percent to 25 percent or more, which can be exactly one client per firm that you do not count as a UBO today.

We keep the date-dependent rules current in the software, so you do not have to pick a moment to switch everything over yourself.

What changes in 2027

Who inside my firm can see which files?

Your firm is one walled-off environment. Every read and write is bound to it, so another firm cannot reach your files, not even by accident.

You invite colleagues as members. There is an owner who administers and members who do the work. Who did what stays visible: every screening, every judgement on a hit and every acceptance carries the name of the person who made it. That is not just tidiness, it is exactly what a file has to be able to show.

If you want it stricter you require two-factor authentication for the whole firm. That requirement then applies everywhere someone comes in, not only at the login screen.

What if I want to leave, or you can no longer deliver?

Then you take your files with you. Every report downloads as PDF and fetches as JSON, and the API hands you all of them at once, programmatically. They are your files and they are not in a format only we can read.

That is not a favour and not a contingency plan: your retention duty runs for five years after a client relationship ends, so you have to be able to reach them in five years anyway. You can try it today, on the free account, before you decide anything.

And a connector does not hold your data hostage. The client data you started with is still sitting in your own accounting package. On Exact Online the report also goes back into the administration, as a document and a task on the relation, so your evidence sits there as well and not only with us. We do not do that on Nmbrs Accounting and HubSpot yet: those fetch relations but do not write the report back.

None of this depends on how big a vendor is. Large parties get acquired, change direction or pull a product too. The question that counts is whether you can get out, and that is something you can check rather than believe.

Do I have to train my employees on the Wwft?

Yes. Art. 35 requires periodic training for your staff and for the people running the firm day to day, so they recognise an unusual transaction and can carry out client due diligence properly and completely. The act prescribes no form, so how you arrange it is up to you.

From 10 July 2027 the AMLR also requires the training to be documented. Today that is not yet a duty, but it is the kind of thing you would rather not reconstruct after the fact.

We made a free one for it: short videos adding up to about ten minutes, no account needed, and yours to use as you like. They carry no PE credits, so they sit alongside your professional body's course rather than instead of it.

See the free Wwft training

What if a client objects to the screening, or asks me to erase their data?

Then two regimes run through each other, which is exactly why we have a separate page about it.

The short version: you are not screening out of curiosity but because the law obliges you to, and that obligation is also the basis for the processing. An erasure request does not set aside your retention duty while it runs. It cuts the other way just as sharply: once the term has passed you really do have to delete, and you may not use the data for anything else.

Two things that often go wrong. You have to tell your client that you process this data before the relationship starts, not when you open the file. And if you report to the FIU you may say nothing about it: on an access request you may withhold that part, but not the file as a whole.

How the GDPR and the Wwft interact

Each answer then shows the article it rests on. Stays on while you browse the site.

This page explains how we apply the rules and is not legal advice. Each answer shows what it rests on, so you can read it yourself. Law as it stood in August 2026.

Get started with Cloudpliant today

10 client files free, the whole product. Connect Exact Online, or add a client by hand.

No credit card needed. The demo takes 30 minutes, online, no obligation.