TrustVerify is a technology provider, not an FCA-authorised firm. This page sets out the regulatory and compliance framework we build and operate to, so that regulated customers can evidence their own obligations from the checks they run with us.
Regulatory status
Magnificentech Solution Ltd, trading as TrustVerify, supplies identity, business and AML screening technology. It is not authorised or regulated by the Financial Conduct Authority and does not carry on any regulated activity. Our one registration in place today is with the Information Commissioner's Office (ZB962144) under the UK GDPR and the Data Protection Act 2018; Cyber Essentials Plus is in progress, and SOC 2 Type II and ISO/IEC 27001 are 2027 targets, not certifications we hold.
Where this page refers to the FCA Handbook, the Money Laundering Regulations or the FATF Recommendations, it describes the obligations our customers are subject to and that our product is designed to help them evidence — the regulatory responsibility remains theirs. This document is intended for partners, procurement and vendor due diligence.
TrustVerify is directly subject to, and operates under:
- UK GDPR and the Data Protection Act 2018 (ICO registration ZB962144)
- The Privacy and Electronic Communications Regulations (PECR)
The product is built to help customers evidence their own obligations under:
- UK Money Laundering Regulations 2017 (as amended)
- The FCA Handbook — SYSC and the FCA Consumer Duty, as they apply to our regulated customers
- JMLSG guidance on electronic identity verification
- FATF Recommendations
- CCPA principles (where applicable)
Card payments are handled entirely by FCA-authorised processors; TrustVerify is not in scope for PCI DSS itself because it never receives or stores cardholder data.
Payment Processing
Payment processing is conducted through FCA-authorised third-party providers. TrustVerify does not directly hold or process payment data but maintains contractual obligations aligned with PCI DSS requirements.
What the platform does today, so you can evidence your own AML/CTF obligations:
- Risk-based customer due diligence (CDD) workflows
- Enhanced Due Diligence (EDD) triggers for high-risk subjects and PEPs
- Point-in-time sanctions, PEP and adverse-media screening via OpenSanctions, which consolidates the OFAC, UN, EU and UK HMT lists among others
- SAR drafting from screening signals — produced as a draft for your MLRO to review, approve and submit to the NCA; TrustVerify never files on your behalf
- An immutable check record and downloadable report for every screening run
Not yet available
Ongoing/perpetual AML monitoring — scheduled re-screening of a saved subject list with alerts on new hits — is not live. Screening is point-in-time: you re-run a check when you need a fresh result. The API endpoint for ongoing monitoring returns 501 rather than reporting a monitor that would never re-screen.
Identity and business verification is conducted through:
- Document verification with liveness detection
- Biometric face match against the submitted document
- Company registry checks via Companies House (UK), GLEIF LEI records and HMRC VAT validation
- UBO and PSC identification and beneficial ownership mapping
- Re-verification on demand: you re-run a check when your periodic review falls due — TrustVerify does not currently re-verify subjects automatically
TrustVerify's data protection practices comply with UK GDPR and the Data Protection Act 2018:
- Lawful basis for all personal data processing
- Data minimisation and purpose limitation principles
- Subject access request procedures
- Data retention and deletion policies
- Privacy by design in product development
- Data breach notification procedures (72-hour reporting)
Chief Compliance Officer
Email: compliance@trustverify.co.uk
AML/Financial Crime Officer
Email: aml@trustverify.co.uk
Data Protection Officer
Email: dpo@trustverify.co.uk
Regulatory Affairs
Email: regulatory@trustverify.co.uk