The questions you actually want to ask
The things that only surface half an hour into a demo, written down instead. Including the answers that are not in our favour.
I keep my files in Excel and Word today. What does software add?
A spreadsheet shows you what a file looks like today. Under review that is not the question. The question is what you knew on the day you took this client on, and what you based it on.
Cloudpliant records every investigation as a frozen report: the checks, the outcomes, the risk classification and the exact list version screened against, with the date and time. That report never changes afterwards. Screen the same client a year later and a new report appears beside it, so you can see immediately what moved.
You can imitate that in Excel with filenames and folders, and it works exactly as long as everybody sticks to the convention.
Legal basis: Wwft art. 33 en 34 (vastlegging en bewaartermijn van vijf jaar)
Am I even allowed to automate my client due diligence?
The law prescribes a result, not a method. You need to know who your client is, what the risk is and why you reached that conclusion, and you need to be able to show it. How you get to that knowledge is yours to arrange.
What you cannot outsource is the responsibility. That is why Cloudpliant makes no decision for you. The system gathers, screens, classifies by fixed rules and records. Accepting or declining is yours, with a motivation that lands in the file.
Software that promises to take over your client due diligence is promising something it cannot deliver.
Legal basis: Wwft art. 3 (het cliëntenonderzoek schrijft een resultaat voor, geen methode) · AMLR art. 76 lid 5 (betekenisvolle menselijke tussenkomst bij accepteren of weigeren, vanaf 10 juli 2027)
The system rates a client I have known for twenty years as high risk. Now what?
Look at which factor caused it, and override it if you disagree.
The classification comes from a fixed thirteen-factor point count. Per client you can see which factors counted and for how many points, so high risk is never a black box you simply have to accept.
If you disagree you set the level manually with a motivation. That override is not a way around the system: it is recorded with your name and the date, which makes it evidence in itself that you thought about it deliberately. That is exactly what a reviewer wants to see.
Legal basis: Wwft art. 8 (verscherpt cliëntenonderzoek bij hoger risico) · AMLR art. 76 lid 5 (recht op uitleg en betwisting van een geautomatiseerde beoordeling)
Do you use AI to determine the risk?
No, and that is deliberate.
Risk classification is a rule matrix: fixed factors, fixed points, fixed thresholds. Enter the same client again a year from now with the same details and you get the same answer. A language model does not give you that. It answers differently on Tuesday than on Monday, and cannot explain afterwards why.
You have to be able to explain to a supervisor how you arrived at a classification. That only works if the rules can be written down. Which is why the whole matrix is simply published on our site, rather than sitting inside a model we could not recount either.
Legal basis: AMLR art. 76 lid 5 (geautomatiseerde besluitvorming alleen met menselijke tussenkomst) · AMLR art. 76 lid 4 (verwerking voor commerciële doeleinden verboden, dus ook geen modeltraining)
What if a source is unreachable? Does my client come out clean?
No. That is possibly the most important rule in the entire system.
A check that did not run may never read as a clean client. If a lookup fails it is recorded as a failed check and the report comes out as incomplete, never as no findings. The client is not ticked off as screened, the existing risk classification is not overwritten, and the file stays open for another attempt.
The alternative is that an outage at a source presents itself as good news. That is the kind of mistake you discover years later, at the worst possible moment.
Legal basis: Wwft art. 5 (geen zakelijke relatie als het cliëntenonderzoek niet kan worden afgerond)
I already have a KvK integration. Is this not the same thing?
A KvK integration tells you who a company is: legal form, address, directors, activities. That is half the work, and Cloudpliant retrieves those details too.
The other half is whether something is wrong with the people behind it. Is a director on a sanctions list? Is the UBO politically exposed? Is there a bankruptcy running? The business register knows none of that, because it is not a risk register.
And then there is time. A KvK lookup is a snapshot. Cloudpliant keeps watching and tells you when something changes about a client you already took on.
Legal basis: Wwft art. 3 lid 2 sub b (de uiteindelijk belanghebbende identificeren en de eigendoms- en zeggenschapsstructuur doorgronden)
Where is my client data stored?
The application, the database, the documents and the stored screening results all run on Hetzner servers in Falkenstein, Germany.
We name the asterisk straight away, because everything stays in Europe is a claim you should be able to check. Our error reporting runs through a service with a European processing region but a US parent company. If you use identity verification, the vendor you choose processes that step on its own infrastructure. We track per vendor where they sit and which law they answer to, and that is exactly why we do not claim a hundred percent.
What definitely does not happen: no client data goes to an AI model.
Legal basis: Wwft art. 34a lid 1 (alleen verwerken met het oog op witwassen en terrorismefinanciering, nooit commercieel) · AMLR art. 76 lid 4 (zelfde verbod, vanaf 10 juli 2027)
How much work is switching?
If you work in Exact Online or HubSpot you connect it once and your relations are pulled in. From then on every new or changed relation is screened automatically and the report lands back in the system you already work in.
If you use something else you add clients manually or through the API. You do not have to retype your existing files first. Start with the clients due for review now and pick up the rest as their moment arrives.
Who is liable if something goes wrong anyway?
You are. That is not small print, it is how the system works: the obligation sits with the firm and you cannot pass it to a supplier.
What software can do is make the difference between we thought it was fine and here is what we checked, when, against which source and against which version of it. Under review only the second one counts.
A supplier telling you they take on the liability is mostly selling you a feeling.
Legal basis: Wwft art. 1a (de verplichting rust op de instelling zelf)
Why are your prices simply on the site?
Because you should be able to compare without having to sit through a call first.
You see what it costs before you speak to anyone, and you see where the cost comes from. Screenings against sanctions and PEP lists are billed per lookup by our provider, so those costs are real and we do not pretend they are zero.
It is also why re-screening a client within a day is free: that question has already been asked and already been paid for, so we do not charge it twice.
Do you screen continuously, or only when I take a client on?
Continuously, and the pace follows the risk. A low-risk file comes round every ninety days, neutral every month, high every week and unacceptable every day.
On top of that the system checks each night whether the sanctions lists themselves moved. If they did not, there is nothing to re-screen and it costs nothing. If they did, the files go past the lists again and you hear about it when something changed about your client.
Legal basis: Wwft art. 3 lid 2 sub d (voortdurende controle op de zakelijke relatie)
I only have thirty clients. Is this not overkill for a small firm?
The obligation does not look at your size. Thirty files have to be as complete as three hundred, except you have no compliance department for it. That does not make a small firm less obliged, it makes it more exposed to the handwork.
You do not pay per user here. Your whole firm is included on every plan, so you never have to choose who gets access. The integrations and the API are in from the free plan, not held back for a business tier.
Up to ten files it costs nothing. Above that it starts at a hundred euro a month for a hundred files.
Legal basis: Wwft art. 1a (wie instelling is, hangt af van de dienst en niet van de omvang)
How do I know a hit is really my client and not someone with the same name?
You do not know for certain, and the system does not pretend otherwise. A hit on a list is a candidate, not a conclusion.
Every candidate comes with a match score and with the elements it was compared on: name, date of birth, country. You can see per element whether it lines up or contradicts, so you can judge for yourself whether this could be the same person.
If it is a namesake you dismiss the hit with a short note. That judgement is recorded with your name and the date, stops counting towards the score from then on, and does not come back at the next screening as if nothing happened. The judgement itself stays in the file, because the fact that you looked is evidence too.
Legal basis: AMLR art. 76 lid 2 (gegevens uit betrouwbare bron, juist en actueel, geen vertekende of discriminerende uitkomsten) · AMLR art. 76 lid 3 sub b (onderscheid tussen beschuldiging, onderzoek, procedure en veroordeling)
Do I have to bother my clients with this?
Usually not. Screening against sanctions lists, PEP registers, the business register and the court registers happens without your client noticing anything.
Only when you need something from the client do you send one link. It opens in the browser, in Dutch, with no account and no app. Your client supplies the document or identifies themselves, and the result lands in the file as recorded evidence.
That is the difference with a passport scan by email: you do not have to assess it yourself and it does not sit around in your archive.
Legal basis: Wwft art. 11 (verificatie aan de hand van documenten of gegevens uit betrouwbare en onafhankelijke bron)
The AMLR arrives in 2027. Should I not just wait?
The AMLR applies from 10 July 2027 and will replace a large part of what the Wwft says today. Until that day the Wwft applies in full, so waiting means two years of building files you already know are not complete.
The direction is no surprise either. In places it gets stricter rather than looser: the UBO threshold moves from more than 25 percent to 25 percent or more, which can be exactly one client per firm that you do not count as a UBO today.
We keep the date-dependent rules current in the software, so you do not have to pick a moment to switch everything over yourself.
Legal basis: AMLR art. 90 (van toepassing vanaf 10 juli 2027) · Uitvoeringsbesluit Wwft 2018 art. 3 (nu: meer dan 25 procent) tegenover AMLR art. 52 lid 1 (straks: 25 procent of meer)
Who inside my firm can see which files?
Your firm is one walled-off environment. Every read and write is bound to it, so another firm cannot reach your files, not even by accident.
You invite colleagues as members. There is an owner who administers and members who do the work. Who did what stays visible: every screening, every judgement on a hit and every acceptance carries the name of the person who made it. That is not just tidiness, it is exactly what a file has to be able to show.
If you want it stricter you require two-factor authentication for the whole firm. That requirement then applies everywhere someone comes in, not only at the login screen.
You are a small company yourselves. What if you go under?
A fair question, and the honest answer is not that it cannot happen.
What protects you is that your files stay yours and are not in a format only we can read. Every report can be pulled as a PDF and as JSON, and the API lets you fetch them programmatically. Your retention duty runs for five more years after a relationship ends, so that has to be possible anyway.
And we do not lock you in with an integration that holds your data hostage. The client data you started with is still sitting in your own accounting package.
Legal basis: Wwft art. 33 en 34 (bewaartermijn van vijf jaar na het einde van de relatie) · AMLR art. 77 lid 3 (vijf jaar, ook na een weigering)
What if a client objects to the screening, or asks me to erase their data?
Then two regimes run through each other, which is exactly why we have a separate page about it.
The short version: you are not screening out of curiosity but because the law obliges you to, and that obligation is also the basis for the processing. An erasure request does not set aside your retention duty while it runs. It cuts the other way just as sharply: once the term has passed you really do have to delete, and you may not use the data for anything else.
Two things that often go wrong. You have to tell your client that you process this data before the relationship starts, not when you open the file. And if you report to the FIU you may say nothing about it: on an access request you may withhold that part, but not the file as a whole.
Legal basis: Wwft art. 34a lid 2 (de cliënt informeren alvorens de zakelijke relatie aan te gaan) · Wwft art. 34a lid 3 (onmiddellijk vernietigen na het verstrijken van de termijn) · Wwft art. 23 lid 3 (het inzagerecht van AVG art. 15 mag opzij voor de geheimhouding rond een melding)
What if I leave? Can I still get to my files?
Yes, and not as a favour: your retention duty runs for five more years after a relationship ends, so you have to be able to reach them.
Every report can be downloaded as a PDF and retrieved as JSON, and the API lets you pull them programmatically. They are your files, and they are not behind a lock only we hold the key to.
Legal basis: Wwft art. 33 en 34 (bewaartermijn van vijf jaar)
Each answer then shows the article it rests on. Stays on while you browse the site.
Get started with Cloudpliant today
It's time to take control of your compliance. Cloudpliant provides one streamlined way to meet your WWFT, AML and KYC obligations, without the hassle.
The demo takes 30 minutes. Free account, no credit card needed.