Agora builds the CDD Platform, a fourteen-module customer due diligence engine for banks, payment institutions, asset managers and other regulated financial institutions. It covers the full lifecycle in one system: onboarding and identification, beneficial ownership resolution, sanctions, PEP and adverse media screening, customer risk assessment, enhanced due diligence, remediation of the existing back book, and ongoing monitoring through periodic and perpetual KYC.
Agora is a technology provider. We supply and configure the platform your own teams operate. Review, approval and accountable decisions stay inside your firm. We do not supply analysts, reviewers or an outsourced financial-crime operation.
What Agora is, in one paragraph
A single-tenant, UK cloud region-pinned SaaS platform that automates the mechanical parts of customer due diligence and evidences the judgemental parts. Entity resolution, registry enrichment, ownership chains, screening and risk scoring run automatically under rules you configure; the cases that genuinely need a person are routed to your reviewers with the work already assembled. Every field carries its source and date, and every decision carries its rationale, its rule version and its author. The platform is certified to ISO 27001, ISO 9001, ISO 42001, CREST and Cyber Essentials, and is live in five working days.
Who it is for
- Banks and building societies running onboarding and periodic review at volume.
- Payment and e-money institutions scaling customer numbers faster than review capacity.
- Asset, wealth and fund managers with complex entity and ownership structures.
- Firms carrying a remediation or back-book refresh obligation alongside business as usual.
- MLROs and financial-crime change teams replacing a multi-vendor patchwork with one auditable record.
What the platform covers, end to end
Each capability below is a module of the same engine, sharing one customer record, one risk methodology and one audit trail.
Onboarding and identification
Individual, corporate and charity onboarding from a single field. Companies House and the Charity Commission resolve the entity, retrieve officers, PSCs and filings, and open the case without re-keying.
Entity and UBO resolution
Recursive ownership chains rebuilt from registry data, effective percentages computed across layered structures, and beneficial owners identified against a configurable threshold (25% by default). Where the chain cannot be resolved from available sources, that is flagged rather than assumed.
Identity verification and ID&V integration
Document forensics, liveness and biometric match for the natural persons behind the entity. Beneficial owners can be verified through a time-limited token without a platform login. Firms can keep an existing ID&V provider or use the one we supply.
Sanctions, PEP and adverse media screening
Screening across sanctions, PEP and adverse media watchlists with fuzzy and transliteration matching, address screening, and your own matching rules applied before an alert reaches a queue.
Nature and purpose of the relationship
Nature of business inferred from website, registry filings, SIC code, geography and revenue source, each element sourced and dated so the conclusion is citable rather than asserted.
Customer risk assessment
A weighted, configurable risk engine produces a customer rating, sets the due diligence level (SDD, CDD or EDD) and records the evidence behind every factor. The methodology is versioned, so a reviewer can see which model was in force.
Enhanced due diligence workflow
EDD triggered by rule rather than by memory, with the additional evidence requirements, SME referral and approval route configured into the workflow and recorded on the case.
Remediation of the back book
The same engine runs bulk population ingestion, gap identification, enrichment and re-screening for existing customers, so remediation uses one standard with new onboarding rather than a parallel process.
Periodic and perpetual monitoring
Continuous screening and configured change signals convert into triggers under your policy, driving a targeted refresh. Scheduled risk-based review points can be retained alongside event-led review.
Workflow, quality control and management information
Case assignment, reviewer and SME queues, escalation and rework, sampling and defect capture, with progress, ageing and defect reporting drawn from the live record set.
Case report and audit trail
Profile, nature of business, ownership, screening, risk, verification and the full decision trail assembled live and exportable as PDF, JSON, XML or CSV.
What it automates, and what it deliberately does not
The platform automates retrieval, reconciliation and computation: resolving the entity, pulling officers, PSCs and filings, rebuilding ownership to the configured threshold, refreshing registry data, running screening with your matching rules applied first, and calculating the risk rating and due diligence level from the evidence gathered.
It deliberately does not automate accountable judgement. Acceptance of a customer, approval of an enhanced due diligence case, discounting of a genuine screening match and sign-off of a remediated file remain decisions taken by a named person in your firm. What the platform does is put the evidence in front of that person and record what they concluded.
How it fits an existing financial-crime stack
Most firms are not replacing everything at once. The platform is provider-agnostic: existing identity verification, screening and data providers can be retained and called from the workflow, or replaced with the ones we supply, or consolidated over time. Population and case data can be loaded by structured upload or by integration, depending on what your architecture supports. Case output exports as PDF, JSON, XML or CSV for onward use in case management, data warehousing or regulatory reporting. Architecture, tenancy, hosting and data-portability detail is set out on the Security and architecture page.
Procurement and assessment
- Deployment model. SaaS subscription, single-tenant per client, UK cloud region-pinned. Live in five working days, with no bespoke implementation programme.
- Certifications. ISO 27001, ISO 9001, ISO 42001, CREST and Cyber Essentials.
- Regulatory alignment. Built against the Money Laundering Regulations 2017, the FCA Handbook and JMLSG Guidance; see the 2026 JMLSG checklist for the programme expectations the platform is designed around.
- Auditability of AI. The AI SME answers from MLR 2017, the FCA Handbook, JMLSG and your own procedures, with a confidence score, a citation to the underlying rule and a human override log on every AI-assisted step.
- Exit. A documented exit and data-portability path from day one.
- Commercials. Not published. They depend on population, scope and deployment, and are discussed after an initial scoping conversation.
Technology by requirement
If you are buying for a specific problem rather than the whole lifecycle, these pages cover the individual requirements in depth:
- KYC remediation software, for back-book refresh at scale: bulk ingestion, data cleansing, gap identification, enrichment, re-screening and completion evidence.
- Periodic and perpetual KYC software, for scheduled risk-based review and event-driven trigger monitoring, operated together.
- Customer risk assessment software, for configurable risk factors, weighting, evidence and governed overrides.
- KYC workflow software: assignment, reviewer and SME queues, escalation, rework and management information.
- KYC quality assurance software: sampling, defect capture, recheck loops and consistency reporting.
A note on the term “due diligence software”
The phrase covers a broad market: M&A data rooms, legal research, vendor risk, even health-and-safety inspection tooling. This page uses the narrower regulated meaning, AML and customer due diligence software for financial institutions. Products built for the other meanings were not designed for MLR 2017, do not produce JMLSG-shaped audit output, and treat ownership, screening and monitoring as separate add-ons. Agora is a single regulated CDD engine, built UK-first, that an MLRO can hand to a supervisor without translation.
Frequently asked questions
What is a CDD platform?
A CDD platform is the technology layer a regulated firm uses to carry out customer due diligence: identifying and verifying customers and their beneficial owners, understanding the nature and purpose of the relationship, screening for sanctions, PEP and adverse media exposure, assessing customer risk, and keeping that information current through ongoing monitoring. A platform differs from a point solution in that it holds the whole lifecycle and the audit evidence in one record rather than stitching several vendors together.
Is Agora a software provider or a consultancy?
Agora is a technology provider. We supply and configure the CDD Platform that your own teams operate. Review, approval and accountable decisions remain with your firm; we do not supply analysts, reviewers or an outsourced operations team.
Who is the platform built for?
UK and internationally regulated firms carrying out customer due diligence under the Money Laundering Regulations 2017, the FCA Handbook and JMLSG Guidance: banks, payment and e-money institutions, asset and wealth managers, and other regulated financial institutions.
Can it work alongside our existing financial-crime stack?
Yes. The platform is provider-agnostic. Firms can retain existing identity verification, screening or data providers, use the ones we supply, or consolidate over time. Population and case data can be loaded by structured upload or integration depending on what your architecture supports.
Does it handle both onboarding and ongoing CDD?
Yes. The same engine runs new customer onboarding, ongoing monitoring and trigger-led refresh, and large-scale remediation of the existing back book, so one standard and one audit record apply across all three.
How is enhanced due diligence handled?
EDD is triggered by the risk assessment under rules you configure, for example high-risk third countries, PEP exposure, opaque ownership or other factors your policy defines. The additional steps, evidence requirements and approval route are configured as part of the workflow rather than handled outside the system.
What evidence does it produce for audit or a supervisory review?
Each case exports as a structured pack covering what was checked, the source and retrieval date of each item, what was decided, under which version of the risk methodology, and by whom. Overrides record who departed from the automated outcome, when, on what basis and with what approval.
Do you publish pricing?
No. Commercials depend on population size, scope and deployment, so they are discussed after an initial scoping conversation. The platform is delivered as a SaaS subscription, single-tenant per client.
Further practitioner reading
The topics behind each module are covered in depth in the Financial Crime Knowledge Hub: how CDD automation is governed, when enhanced due diligence applies, how beneficial ownership and KYB chains are resolved, the difference between periodic and perpetual KYC, how customer risk assessment is designed, and what a regulator-defensible audit trail contains. Short, source-backed responses to common supervisory questions are in the UK CDD and KYC regulatory answers section.
Talk to us
Most engagements start with a 20-minute scoping call. Use the enquiry form to arrange a demonstration against your own customer types, risk model and data.