Broker compliance software that runs your regulator’s rules.
Compliance is TradeCore's regulatory module for FX/CFD brokers: jurisdiction rules, KYC verification, document evidence and client consent on one client record. 19 regulatory regimes ship pre-loaded, and every rule in them is yours to override per brand.
100+ brokerages run on TradeCore, including MultiBank Group, AvaTrade, IC Markets, FP Markets and Trade Nation.
Where does compliance sit in a brokerage platform?
The CRM core holds the client. Compliance decides what that client is allowed to do, and keeps the proof. BrokerIQ is TradeCore's modular CRM and back-office product line for FX/CFD brokers. Compliance runs natively on the BrokerIQ CRM core, or standalone on your existing CRM, sending your systems a webhook at every compliance stage.
The compliance layer
One rulebook, read by every surface above it
Signup
Only licensed countries
The country list a client picks from is generated from the brand's licences, and the client's declared country resolves to a jurisdiction before the account exists.
Licence go-live
Gaps must close first
A licence cannot be activated while a mandatory KYC document category is uncollectable or a mandatory risk warning is missing or unpublished.
Trading accounts
Leverage and platform
Account creation rejects a leverage above the regime cap, a leverage outside the permitted menu, or a trading platform the regime does not allow.
How do brokers run different rules for different regulators?
TradeCore ships 19 regulatory regimes — ten onshore, eight offshore and a rest-of-world fallback — each carrying 26 rules, from the leverage cap to the complaint-response deadline. Every rule is a default your compliance officer can override per brand.
The seeded rules, by regime
United Kingdom — FCA — Financial Conduct Authority (Onshore)
- Trading: Maximum leverage
- 30:1
- Trading: Permitted platforms
- MT5
- Trading: Negative balance protection
- Required
- Onboarding & classification: Cooling-off
- 1 day before first trade
- Onboarding & classification: Vulnerable customer flag
- Required
- Marketing & disclosure: Marketing approval
- Required
- Reporting & disputes: Suspicious activity reports
- NCA
- Reporting & disputes: Complaint response deadline
- 56 days
Maximum leverage is a seeded default for FCA, not a floor — any brand can override it, and all 26 rules, in its own licence.
Seeded from: FCA Handbook COBS 22.5, FCA Handbook DISP 1.6
Cyprus — CySEC / MiFID II — Cyprus Securities and Exchange Commission (Onshore)
- Trading: Maximum leverage
- 30:1
- Trading: Negative balance protection
- Required
- Routing: Passporting
- Across the EEA
- Onboarding & classification: Professional thresholds
- Income, portfolio, experience
- Marketing & disclosure: Risk warning template
- Required at signup
- Reporting & disputes: Suspicious activity reports
- MOKAS
- Reporting & disputes: Complaint response deadline
- 30 days
Maximum leverage is a seeded default for CYSEC, not a floor — any brand can override it, and all 26 rules, in its own licence.
Seeded from: CySEC Policy Statement PS-01-2019 (CyNPIMs)
Australia — ASIC — Australian Securities and Investments Commission (Onshore)
- Trading: Maximum leverage
- 30:1
- Trading: Permitted platforms
- MT4, MT5, cTrader
- Trading: Negative balance protection
- Required
- Marketing & disclosure: Pre-contact opt-in
- Required
- Reporting & disputes: Suspicious activity reports
- AUSTRAC
- Reporting & disputes: Threshold transaction report
- AUD 10,000
- Reporting & disputes: Complaint response deadline
- 45 days
- Reporting & disputes: Target market determination
- Required
Permitted platforms is a seeded default for ASIC, not a floor — any brand can override it, and all 26 rules, in its own licence.
Seeded from: ASIC 20-254MR CFD product intervention order, AUSTRAC threshold transaction reports
Singapore — MAS — Monetary Authority of Singapore (Onshore)
- Trading: Maximum leverage
- 20:1
- Trading: Permitted leverage menu
- 1, 5, 10, 20
- Marketing & disclosure: Pre-contact opt-in
- Required
- Reporting & disputes: Suspicious activity reports
- STRO
- Reporting & disputes: Threshold transaction report
- SGD 20,000
- Reporting & disputes: Complaint response deadline
- 30 days
Maximum leverage is a seeded default for MAS, not a floor — any brand can override it, and all 26 rules, in its own licence.
Vanuatu — VFSC — Vanuatu Financial Services Commission (Offshore)
- Trading: Maximum leverage
- Not capped by the regime
- Trading: Promotional bonuses
- Permitted
- Routing: Country matching
- Exclusion list
- Routing: Platform sanctions floor
- Applied
- Reporting & disputes: Suspicious activity reports
- FIU Vanuatu
Maximum leverage is a seeded default for VFSC, not a floor — any brand can override it, and all 26 rules, in its own licence.
Rest of World — No single regulator — the fallback regime (Fallback)
- Routing: Role
- Catches anything the other licences don't
- Routing: Platform sanctions floor
- Applied
- Trading: Maximum leverage
- Not capped by the regime
- Trading: Promotional bonuses
- Permitted
Maximum leverage is a seeded default for ROW, not a floor — any brand can override it, and all 26 rules, in its own licence.
Trading
- Maximum leverage
- 30:1
- Permitted platforms
- MT5
- Negative balance protection
- Required
Onboarding & classification
- Cooling-off
- 1 day before first trade
- Vulnerable customer flag
- Required
Marketing & disclosure
- Marketing approval
- Required
Reporting & disputes
- Suspicious activity reports
- NCA
- Complaint response deadline
- 56 days
Seeded from FCA Handbook COBS 22.5 · FCA Handbook DISP 1.6
Maximum leverage is a seeded default, not a floor.
Before this licence goes live
The platform computes what is missing. A licence with an open gap cannot be activated.
- Identity verification documentsA document type in this category the brand can actually collect
- Proof of address documentsSame test, second mandatory category
- Risk warning templatePublished, mandatory, and scoped to appear at this brand's signup
- Client lifecycleAn initial state, and no state stranded off the graph
The six regimes play in turn. Pick one, or override a rule yourself.
All 19 regimes in TradeCore’s rulebook
Onshore · 10
- FCA (United Kingdom)
- CySEC (Cyprus, MiFID II)
- ASIC (Australia)
- DFSA (Dubai, DIFC)
- MAS (Singapore)
- JFSA (Japan)
- FSCA (South Africa)
- CIRO (Canada)
- FMA (New Zealand)
- FSRA (Abu Dhabi, ADGM)
Offshore · 8
- VFSC (Vanuatu)
- FSC (Belize)
- FSC (Mauritius)
- FSC (British Virgin Islands)
- FSA (Seychelles)
- CIMA (Cayman Islands)
- SVGFSA (Saint Vincent)
- Labuan FSA (Malaysia)
Fallback · 1
- Rest of World
Start from a template, not a blank page. TradeCore Compliance ships four client-lifecycle templates to fork — Standard Offshore, Demo-first, CySEC (MiFID II) and FCA — and a KYC verdict moves the client through those states automatically.
Can a broker stop signups from countries it isn’t licensed for?
The signup country list is generated from the brand’s licences, not typed into a form. A country nobody holds a licence for is never offered — on the portal, and on every lead-capture form the marketing team builds.
Signup — country
Generated from this brand's licences. Not a list somebody typed.
- North Korea
- Iran
- Syria
- Cuba
That floor is the platform's. Narrowing further — United States, China, anywhere else a brand will not serve — is the broker's own decision, made in the jurisdiction editor.
Which jurisdiction is this client under?
The same four steps every time, and the answer is on the record before the account exists.
Declared country
The client picks from the list the brand's licences generate.
Mandatory for a regime?
A country a regime claims for its own residents wins, whatever the broker's preference.
Broker priority
Otherwise the brand's own priority order across its licences decides.
Fallback, or refusal
No candidate falls to the brand's fallback regime. No fallback is a refusal with a named reason.
Signup completed — ban check
Three identity signals, hashed and checked against the ban registry for the whole brokerage.
Match — banned under another brand
The client is restricted automatically, and the match is on the record. The stored value was never read: only the hashes were compared.
Three ban types
Blacklist and fraud block a client across every brand in the brokerage. Unsuitable restricts a client the broker will not serve, without accusing them of anything.
- Blacklist
- Fraud
- Unsuitable
- Your own reason lists
Matched without being read
Email, phone and document number are compared as keyed hashes, so the stored value is never queried. The ban check runs when signup completes, once the full identity exists.
- Hashed email
- Hashed phone
- Hashed document number
- Whole email domains
Restricted, never cut off
A restriction profile denies up to eight permissions and never support, so a banned client can still dispute the ban or close the account.
- Up to 8 permissions
- Support always open
- Every ban on the record
A ban is an automation trigger. Bans is one of the 17 areas behind TradeCore’s 200+ event triggers, so a new ban can notify the desk, create a task or start a journey the moment it lands.
What happens between a client uploading their ID and a verified client?
TradeCore routes each check on the client’s own attributes to one of five KYC providers — SumSub, Onfido, Cellbunq, GBG, ComplyAdvantage — then settles it by policy: rejections always land, approvals auto-pass only where the broker allowed it, and everything else parks for an officer.
The rule that picked the route
nationality is andcheck type is Identity
Requested
In progress
Submitted
Verdict
A client can never select their own route. Every attribute a rule matches on is derived by the platform, never sent by the browser.
What the verdict becomes
Set per capability, by the broker.
How TradeCore settles a KYC provider's verdict, by the broker's auto-approval setting:
- Provider approves: with auto-approval on, the check becomes Passed; with auto-approval off, it becomes Review needed.
- Provider rejects: with auto-approval on, the check becomes Failed; with auto-approval off, it becomes Failed.
- Provider asks for review: with auto-approval on, the check becomes Review needed; with auto-approval off, it becomes Review needed.
- Provider errors: with auto-approval on, the check becomes Review needed; with auto-approval off, it becomes Review needed.
| Provider says | The check becomes |
|---|---|
| Provider approves | Passed |
| Provider rejects | Failed |
| Provider asks for review | Review needed |
| Provider errors | Review needed |
A rejection lands whatever the setting. Auto-approval is the only half a broker opts into.
Parked for an officer
Reject — pick a reason
- Sanctions list match
- Politically exposed person confirmed
- Adverse media finding
- Identity verification mismatch
- Insufficient documentation
- Suspected fraud
- Duplicate account
- Compliance decision
A closed list, not a text box — so the audit record never carries free-text personal data.
If the provider goes quiet
A lost callback cannot strand a client mid-verification.
- 30 minReconcile sweepRuns across every brand, looking for checks still waiting.
- 1 hourPoll the providerA check open this long is asked directly, closing the gap a lost webhook leaves.
- 14 daysHard timeoutA check still unanswered is timed out by the platform, never left open forever.
Seven check types
Suitability is the one TradeCore runs itself: a MiFID II questionnaire, scored and routed back onto the client record.
- Identity
- Document
- Address
- PEP
- Sanctions
- Liveness
- Suitability
Seven attributes a route reads
Nationality leads, because the documents a person can present follow citizenship. Rules run in priority order and the first match wins.
- Nationality
- Country of residence
- Individual or corporate
- Resolved jurisdiction
- Client status
- Check type
- Brand
Seven capabilities per integration
A client can only start a check the broker has enabled on that provider, and auto-approval is set per capability.
- Identity verification
- Document verification
- Liveness
- Face match
- Address verification
- AML screening
- PEP screening
Verified data, written back your way
What the provider verified can fill empty fields, overwrite what the client declared, or stay off — off being the default in every ambiguous case, so a partial extraction never deletes good data.
- Off
- Fill blanks
- Overwrite
- Identity
- Address
- Corporate
- Beneficiaries
Nothing edited after the fact
A settled check is never edited. A re-check creates a new attempt that supersedes the last one, so what was decided, and when, survives.
- Superseded, never edited
- One attempt per re-check
Nothing forged, nothing hidden
Provider verdicts are authenticated over the raw request bytes, and every exchange — what was sent, what came back, how long it took — is readable per client.
- Raw-bytes authentication
- Redelivery de-duplicated
- Encrypted credentials
- Sandbox isolated
- Full exchange log
Five KYC providers, one connection layer. SumSub, Onfido, Cellbunq, GBG and ComplyAdvantage sit among TradeCore’s 200+ integrations, next to 8 trading platforms and 100+ PSPs.
Where does a broker keep KYC evidence so an audit can find it?
On the client record, in the broker’s own document catalogue. Documents the verification provider collected are filed under the same types as documents a client uploaded, so there is one place to look — and completeness is computed, not remembered.
What is this client still missing?
Computed on two dimensions at once, not remembered by an operator.
Required types
Specific document types the brand marks required. Every one must be approved.
Mandatory categories
A category satisfied by an approved document of any type inside it — one government ID, whichever the client holds.
Review queue
Every decision writes its own record.
Recorded — decision, reviewer and time, appended not overwritten
Cannot proceed until a reason is picked from your own rejection reason list.
Before it expires, not after
A passport crossing each warning threshold, then expiring — which reopens the client's completeness.
90 days
60 days
30 days
7 days
Expired
Identity evidence expires. A transaction receipt is history and never does.
What the provider collected
Filed under your own document types — not left in a vendor dashboard.
- Passport
- National ID
- Driver's licence
- Residence permit
- Utility bill
- Bank statement
- Selfie
- Verification report
Anything the provider cannot name lands in a catch-all type rather than being dropped, and the gap is raised for an operator.
Request a document
A formal pull, not an email thread — tracked until the document is decided.
Requested
An officer asks for a named document type, with instructions the client sees word for word.
Uploaded
The client's upload links itself to the request.
Decided
The review outcome is mirrored on the request.
Chased
A request still open past its date escalates every day.
Review you can defend
Each decision writes its own record, a rejection names a reason from the broker's own list, and a decision made against a stale version is refused rather than quietly applied.
- Append-only
- A reason on every rejection
- Bulk review
- Per-document outcomes
Evidence on the right object
Documents attach to more than the client, and are readable from the object they belong to.
- Partners
- Trading accounts
- Payment accounts
- Transactions
- Beneficiaries
Evidence that stays true
TradeCore never deletes a document — only the brokerage can remove one. If a provider erases a client's data, the approvals it supported reopen, and only identity documents ever expire.
- Never deleted by TradeCore
- Approvals reopen
- Receipts never expire
Pending documents join the desk's queue. Documents arrive in the BrokerIQ CRM’s unified work queue with tasks, tickets, withdrawals, deposits and bank-account verifications — one prioritised list.
How does a broker prove which terms a client actually accepted?
Every legal document is versioned per brand, jurisdiction and language. A major revision invalidates prior consent and asks again; a minor one does not. Until a mandatory consent is settled, the client can log in — and cannot deposit, withdraw, transfer or trade.
Terms of business — version chain
Which exact version a client accepted is always answerable.
- v1.0PublishedAccepted at signup — context, IP and user agent recorded.
- v1.1Minor revisionA typo and a new address. The version is recorded; consent stands.
- v2.0Major revisionTerms materially changed. Prior consent stops counting and the client is asked again.
Which document this client sees
One winning document per purpose, with a language fallback.
While a mandatory consent is outstanding
has not accepted v2.0 yet.
A gated client must still be able to reach the portal to accept the document that ungates them.
Eight consent purposes
- Service terms
- Privacy policy
- Risk disclosure
- Cookie policy
- AML policy
- Marketing communications
- Professional trader declaration
- A purpose you define yourself
A major revision asks again
Publish a major revision and prior consents stop counting; a minor one bumps the version for the record and leaves consent standing.
Every decision carries its context
Signup, a re-consent prompt, portal settings, an operator acting on the client's behalf, or the API — with the IP address and user agent captured at the moment of the decision.
Withdrawal is per purpose
A client can withdraw marketing consent without touching service terms. Where a brand does not allow immediate withdrawal of a mandatory consent, the client files a request an operator or an automation actions.
Withdrawn consent stops the messages. Withdrawing marketing consent exits every TradeCore marketing journey automatically, with an audit entry, and any further send is refused with “no consent” on the record.
Licences and verification on every plan
TradeCore's free plan runs 1 regulatory licence — regulated brands welcome — with the full manual KYC review flow. TradeCore's Core plan carries any number of regulatory licences and verifies clients automatically through a connected KYC provider, with each further provider €100 a month.
TradeCore's free plan
€0Your compliance team reviews every client
- 1 regulatory licenceRegulated brands welcome.
- The full KYC review flowThe document catalogue, requirements, questionnaires and bulk review, with every decision on the client's audit trail.
- 1 signup flow and 1 questionnaireCustom fields, conditional logic, suitability scoring and verification requirements.
Core
€2,500 a month, flatVerification runs itself
- Any number of regulatory licencesEvery licence with its own regime, priority order and country list, from one back office.
- Automated verificationOne of the five KYC providers is included, and each further provider is €100 a month, with conditional routing across all of them.
- Document requestsAsk any client for a named document, and overdue requests escalate every day.
- Unlimited signup flows and questionnairesA signup flow per signup type, brand and jurisdiction.
Add a KYC provider whenever you need one. Each eKYC provider beyond the one Core includes is €100 a month, with conditional routing across every provider you connect. No per-trader fees, no per-trade fees, no setup fees.
What’s inside Compliance
Every part of Compliance, by area — the rulebook, jurisdictions, verification, documents, consent, bans and the record.
Rulebook
19 seeded regimes, 26 rules each, every rule yours to override per brand.
- 19 seeded regulatory regimes — 10 onshore, 8 offshore, 1 fallback
- FCA · CySEC · ASIC · DFSA · MAS · JFSA · FSCA · CIRO · FMA · FSRA
- VFSC · Belize · Mauritius · BVI · Seychelles · CIMA · SVGFSA · Labuan
- 26 rules per regime across 5 families
- Every rule overridable per brand, validated for shape, never for direction
- Licences carry a priority order and an optional narrower country list
- Computed activation gap list before a licence can go live
- One-click provisioning of the document collection a regime mandates
- 4 forkable client-lifecycle templates: Standard Offshore, Demo-first, CySEC (MiFID II) and FCA
- A KYC verdict moves the client's lifecycle state automatically
- Retiring a licence keeps its history for audit and reactivation
TradeCore Compliance — Rulebook
19 seeded regimes, 26 rules each, every rule yours to override per brand.
- 19 seeded regulatory regimes — 10 onshore, 8 offshore, 1 fallback
- FCA · CySEC · ASIC · DFSA · MAS · JFSA · FSCA · CIRO · FMA · FSRA
- VFSC · Belize · Mauritius · BVI · Seychelles · CIMA · SVGFSA · Labuan
- 26 rules per regime across 5 families
- Every rule overridable per brand, validated for shape, never for direction
- Licences carry a priority order and an optional narrower country list
- Computed activation gap list before a licence can go live
- One-click provisioning of the document collection a regime mandates
- 4 forkable client-lifecycle templates: Standard Offshore, Demo-first, CySEC (MiFID II) and FCA
- A KYC verdict moves the client's lifecycle state automatically
- Retiring a licence keeps its history for audit and reactivation
TradeCore Compliance — Jurisdictions
Which countries a brand may onboard, and which regime each client falls under.
- Signup country list generated from the brand's active licences
- The same list drives lead-capture forms, so marketing cannot collect a lead signup would refuse
- Mandatory-resident precedence over broker preference
- Broker-set priority order across licences
- Fallback regime, and a named refusal when there is none
- Platform embargo floor: North Korea, Iran, Syria, Cuba
- Include-list and exclude-list country matching
- Passporting for MiFID II licences
TradeCore Compliance — Verification
Five KYC providers, routed per client and settled by the broker's own policy.
- 5 KYC providers: SumSub, Onfido, Cellbunq, GBG, ComplyAdvantage
- Conditional routing across providers
- No-code provider activation — enter the provider's API keys
- 7 check types: identity, document, address, PEP, sanctions, liveness, suitability
- 7 provider capabilities declared per integration
- Routing conditioned on 7 client attributes, priority-ordered, first match wins
- A client can never select their own verification route
- KYC before or after the first deposit — the broker's choice
- Auto-approval configured per capability; auto-rejection always on
- 8 canned officer rejection reasons, so the audit record carries no free text
- Raw-bytes webhook authentication and redelivery de-duplication
- 30-minute reconcile sweep, 1-hour provider poll, 14-day hard timeout
- Settled checks are superseded, never edited
- Verified-data write-back across identity, address, corporate and beneficiary data, in fill-blanks or overwrite mode
- Encrypted provider credentials, strict sandbox and production isolation
- Full provider exchange log per client
TradeCore Compliance — Documents
The broker's own document catalogue, reviewed on the record and never lost.
- Broker-owned catalogue: categories, types, expected file slots, purposes
- 6 seeded categories and 9 starter types, enabled as needed
- Completeness computed on required types and mandatory categories together
- Document requests with instructions the client sees verbatim
- Uploads auto-link to the request and mirror its outcome
- Daily escalation on overdue requests
- Append-only review with optimistic concurrency
- Rejections must name a reason from the broker's own list
- Bulk review with per-document outcomes
- Expiry warnings at 90, 60, 30 and 7 days
- Identity-class evidence expires; transaction evidence never does
- Provider-collected documents filed under the broker's own types
- Documents are never deleted by TradeCore — only the brokerage can remove one
- Documents attached to partners, trading accounts, payment accounts, transactions and beneficiaries
- Cross-client review KPIs, narrowed to the clients an operator may see
TradeCore Compliance — Consent
Versioned legal documents, and proof of which version every client accepted.
- 8 consent purposes, including one you define
- Major and minor revisions, with re-consent forced on major
- Resolution by brand, then jurisdiction, then language, then version
- 5 consent contexts recorded, with IP address and user agent
- Deposit, withdrawal, transfer and trading gated until a mandatory consent settles
- Portal access deliberately never gated
- Per-purpose withdrawal with an audit entry
- A withdrawal-request path where a brand does not allow immediate withdrawal
- Documents held as a hosted URL, an uploaded file, or markdown — per brand, jurisdiction and language
- Exportable consent history
TradeCore Compliance — Bans & standing
Who may stay a client, and the compliance standing of everyone who is.
- Ban registry spanning every brand in the brokerage
- Identity matching on hashed email, phone and document number
- Email-domain bans
- 3 ban types with broker-editable reason lists
- Restriction profiles over 8 permissions, support always preserved
- Ban check at signup completion
- Broker-defined compliance status and sub-status
- MiFID II appropriateness as a scored lifecycle questionnaire
- Forms that can be gated on a completed KYC session
TradeCore Compliance — The record
The audit trail and the access rules every compliance decision sits inside.
- Audit log on every mutating action
- Per-client activity stream
- Data is never deleted
- Field-level PII encryption
- Row-level visibility scoping — a client outside your scope is indistinguishable from one that does not exist
- Dual-attributed impersonation
- Permission-gated, audited CSV export of any list view
- Outbound webhooks at every compliance stage
How does TradeCore Compliance compare to legacy and generic CRMs?
Unlike legacy broker CRMs and generic CRMs, TradeCore Compliance ships the regulator's rules as configuration: 19 regimes pre-loaded, five KYC providers routed per client, and evidence and consent on the client record.
| Capability | BrokerIQTradeCore | Legacy broker CRMs | Generic CRMs |
|---|---|---|---|
| The rulebook | |||
Jurisdiction rules | 19 regimes pre-loaded, 26 rules each, every one overridable per brand | Hardcoded per deployment; a change is a vendor request | No concept of a regulator |
Adding a jurisdiction | Configuration, the same day | Part of a 3–6 month go-live | Not applicable |
Go-live readiness | A computed gap list; a licence cannot activate until the mandated documents and risk warnings exist | A checklist somebody keeps in a spreadsheet | None |
| Verification | |||
KYC providers | 5 providers with conditional routing, configured per capability | 1 basic KYC provider | None — bolt one on by API |
Verdict policy | Auto-approval per capability, auto-rejection always on, everything else parked for an officer | Fixed behaviour | None |
A lost provider callback | Polled after an hour, timed out at 14 days — the client is never stranded | Someone notices | Not applicable |
| Evidence | |||
Where KYC documents live | Filed under the broker's own document types, alongside client uploads, on the client record | The vendor's dashboard, plus an upload folder | File attachments |
Expiry | Warnings at 90, 60, 30 and 7 days; expiry reopens the client's completeness | A manual diary | None |
| The record | |||
Consent | Versioned per brand, jurisdiction and language; a major revision forces re-consent; money movement gated until it settles | A tickbox at signup | None |
Ban registry | Hashed identity ban registry across every brand, checked when signup completes | A per-brand blacklist | None |
Audit | Every mutating action logged; data is never deleted | Partial | None |
Competitor columns describe categories of product, not named vendors. TradeCore’s regime values are seeded defaults drawn from published regulator rules, which your compliance officer owns and can override per brand.
Questions about Compliance
What compliance officers ask before they run a licence on TradeCore.
No. Your compliance team files, and TradeCore gives them the right numbers for every licence. Each regime in the rulebook records where suspicious-activity reports go and the threshold amount: the NCA for FCA, MOKAS for CySEC, and AUSTRAC with AUD 10,000 for ASIC.
No. They are TradeCore's seeded defaults, drawn from published regulator rules. Your compliance officer starts from a full rulebook instead of a blank one, checks every value, and can override any rule per brand.
TradeCore's free plan runs the full KYC review flow — the document catalogue, requirements, questionnaires and bulk review — with 1 regulatory licence. Regulated brands are welcome. Core adds automated verification, with one of the five KYC providers included and each further provider €100 a month.
TradeCore warns at 90, 60, 30 and 7 days before the expiry date. On the day it expires the document moves to expired, which reopens the client's KYC completeness so the gap is visible rather than silent.
Yes. TradeCore's corporate onboarding covers beneficiaries and ultimate beneficial owners, and verification routes can send individuals and companies down different paths — individual KYC one way, corporate KYB the other.
Only operators whose TradeCore visibility scope includes that client. To anyone else the client is indistinguishable from one that does not exist, because the difference between the two answers would itself reveal that the client is there.
TradeCore connects five: SumSub, Onfido, Cellbunq, GBG and ComplyAdvantage. Conditional routing sends each client's check to the right one, and each integration declares which capabilities it is allowed to run.
Yes. TradeCore Compliance runs standalone against your existing CRM and sends your systems a webhook at every compliance stage — verification settled, document decided, consent accepted or withdrawn, client banned.
Still have questions?
Contact our teamRun Compliance for free
TradeCore's free plan switches on the BrokerIQ CRM core and every module, with unlimited clients, no time limit and no card to sign up. Your environment is ready as soon as you finish signup.
What TradeCore's free plan includes · TradeCore plans and add-on prices