F Fedix  合规工作流程 Compliance Workflow
Fedix 合规工作流程说明 Fedix Compliance Workflow

KYC / AML 合规流程,从头到尾讲清楚 KYC / AML compliance, explained end to end

这份说明覆盖一个客户从转所到持续监控的完整合规链条:转所五步、身份核验,以及 PEP、不良媒体、制裁名单三类筛查各自的底层逻辑。我们把系统"到底怎么做的"完整披露给你 — 包括它能做什么、不能做什么。 This walkthrough covers a client's full compliance journey — from transferring in, to ongoing monitoring: the five-stage transfer pipeline, identity verification, and the underlying logic of each screening type (PEP, adverse media, sanctions). We disclose exactly how the system works — including what it does and does not do.

5转所步骤Transfer stages
3筛查类型Screening types
7yr审计留存Audit retention
PDF/A报告格式Report format

0合规边界:这是一个工具,不是你的合规官Scope: a tool, not your compliance officer

开始之前,先把边界说清楚 — 这对你、对我们都重要。Fedix 是一套合规工具,帮你把 KYC/AML 流程做得更快、更规范、更可追溯。但它不能代替你自身的合规义务,我们也不是律师。最终的合规判断、决定和法律责任,始终在你(会计师 / 报告实体)手里。 Before anything else, let's be clear about the boundary — it matters to you and to us. Fedix is a compliance tool that makes your KYC/AML process faster, more consistent and fully auditable. It does not replace your own compliance obligations, and we are not lawyers. The final compliance judgement, decision and legal responsibility always rest with you (the accountant / reporting entity).

一句话记住In one line

系统负责初筛、留痕、归档、提醒你负责判断和决定。凡是有命中或存疑的地方,系统一律翻给人工复核,绝不替你自动放行。

The system does the first-pass screening, record-keeping, archival and reminders; you make the judgement and the decision. Anything that matches or is uncertain is always escalated to human review — the system never auto-clears on your behalf.

讲解提示Talk-track 开场就把这句话讲给大家:我们给的是"证据 + 流程 + 记录",不是"法律意见"。这样后面讲筛查时,大家就理解为什么每个命中都要人工确认。 Open with this: we provide "evidence + process + records", not "legal advice". It frames why, later, every screening hit needs human confirmation.

1客户转所:会计要走的五步Client transfer: the five stages

当一个客户从别的事务所转到你这里,系统把它建模成一条入职流水线。会计从头到尾要走这五步 — 系统会在客户详情页用进度条实时显示每一步的状态。 When a client transfers from another firm to you, the system models it as an onboarding pipeline. The accountant works through these five stages — a progress bar on the client record shows the live status of each.

1

建档 / 录入Intake

新建客户,打开"上一任会计"开关,填前任会计的姓名、所名、邮箱、电话。Create the client, switch on "previous accountant", enter their name, firm, email, phone.

2

KYC 尽调KYC

跑 KYC 评估:风险分析、文档清单、三类筛查、批准或拒绝。Run the KYC assessment: risk analysis, document checklist, the three screenings, approve or reject.

3

身份核验Identity

发核验链接(邮件/短信/本机),客户上传证件+自拍,Stripe Identity 核验。Send a verification link (email/SMS/in-app); client submits ID + selfie; verified by Stripe Identity.

4

业务约定书Engagement

发约定书(Engagement Letter),客户签字,状态变为已签署。Send the engagement letter; client signs; status moves to signed.

5

续约Re-engagement

年度续约信流程,用于已有客户的持续关系维护。The annual re-engagement letter flow for ongoing client relationships.

转所的"灵魂":职业清关(Ethical Clearance)The heart of a transfer: Ethical Clearance

转所专属、也最容易被忽略的一步,是给上一任会计发一封职业清关信。这是会计行业的职业规矩:接手一个客户前,要正式征询前任会计,是否有职业理由反对你接手。 The stage unique to a transfer — and the one most often missed — is sending an ethical clearance letter to the previous accountant. It's professional etiquette: before taking on a client, you formally ask the outgoing accountant whether there is any professional reason you should not.

别搞混Don't confuse these

系统里还有一个"事务所所有权转移"(Practice Ownership Transfer),那是把整个事务所的所有权转给团队里另一个成员,跟客户转所完全无关There is also a "Practice Ownership Transfer" in the system — that transfers ownership of the whole practice to another team member, and is entirely unrelated to client transfer.

2KYC 尽职调查:判断这个客户有多"风险"KYC due diligence: how risky is this client

身份核验回答的是"这个人是谁";KYC 回答的是更大的问题:这个客户有多大风险,我要做多深的尽调。二者不同 — 身份核验只是 KYC 的一个输入,不是全部。 Identity verification answers "who is this person"; KYC answers the bigger question: how risky is this client, and how deep must my due diligence go. They are different — a verified identity is one input to KYC, not the whole of it.

  1. 设计服务判定Designated-service check

    系统先判断你为这个客户提供的服务是否属于 AML/CTF 法下的"设计服务",从而决定是否需要做 KYC。The system first checks whether the service you provide is a "designated service" under the AML/CTF Act, which determines whether KYC is required.

  2. AI 风险分析AI risk analysis

    系统对客户情况做风险打分(0–100),归入 低 / 中 / 高 / 禁止 四档,并列出风险因素和缺失文档。这是初步分析,最终评级由你确认。The system risk-scores the client (0–100) into low / medium / high / prohibited, listing risk factors and missing documents. This is a first-pass analysis; you confirm the final rating.

  3. 文档清单与筛查Document checklist & screening

    按实体类型给出 CDD 文档清单,上传的证件存入客户档案;一键"Run All"跑 PEP / 制裁 / 不良媒体三类筛查(下一节详解)。An entity-type-aware CDD checklist; uploaded documents are stored to the client file; one "Run All" click runs PEP / sanctions / adverse-media screening (detailed next).

  4. 受益所有权Beneficial ownership

    映射谁真正拥有和控制这个实体(≥25% 受益所有人),必要时记录法定代表人。Map who really owns and controls the entity (≥25% beneficial owners), recording a legal personal representative where needed.

  5. 批准 / 拒绝Approve / reject

    会计做最终决定,必须填写理由。高风险或 PEP 命中的客户,需要高级管理层签核。The accountant makes the final decision with a mandatory reason. High-risk or PEP-flagged clients require senior-management sign-off.

3AML 三类筛查:我们到底是怎么做的AML screening: exactly how we do it

这是最需要完整披露的部分。三类筛查的"成色"不一样,我们如实告诉你每一类背后是什么数据源、什么逻辑,好让你知道该在哪些地方加人工判断。 This is the part that most needs full disclosure. The three screenings differ in strength; we tell you honestly what data source and logic sits behind each, so you know where to apply your own judgement.

🛡

制裁名单 (Sanctions)Sanctions

真实官方数据源Real official source
数据源Source
澳洲外交贸易部 (DFAT) 综合制裁名单官方 XLSX,实时下载。The Australian DFAT Consolidated Sanctions List (official XLSX), downloaded live.
匹配逻辑Matching
对姓名做模糊匹配(Levenshtein 相似度):≥0.95 判精确命中,≥0.8 判可能命中;有出生日期时加权。Fuzzy name matching (Levenshtein similarity): ≥0.95 = exact match, ≥0.8 = possible match; boosted when a date of birth is available.
覆盖范围Coverage
DFAT 名单已合并澳洲实施的联合国名单 + 澳洲自主制裁。目前不含美国 OFAC / 欧盟独立名单(补齐计划见路线图)。DFAT already consolidates AU-implemented UN listings + autonomous AU sanctions. Does not yet include US OFAC / EU standalone lists (see roadmap).
失败保护Fail-safe
若名单拉取失败,系统拒绝给出"清白"结论:要么返回 503,要么把结果降级为"可能命中 + 需人工复核",绝不误报清白。If the list can't be fetched, the system refuses to return a "clear" result: it either returns 503 or downgrades to "possible match + needs human review" — never a false all-clear.
🏛

政治敏感人物 (PEP)Politically Exposed Persons (PEP)

AI 辅助初筛AI-assisted first pass
当前做法Current method
目前由 AI 模型作为"初筛分析师",判断某人是否可能是政治敏感人物或其密切关系人。这是初筛,不是持牌 PEP 数据库。Currently an AI model acts as a "first-pass analyst", assessing whether a person may be a PEP or a close associate. This is a first pass, not a licensed PEP database.
为什么这样Why
在接入商业 PEP 数据源之前,AI 初筛能立刻覆盖明显的高知名度案例,作为一道过滤网。Before a commercial PEP feed is connected, AI screening immediately catches obvious high-profile cases as a first filter.
失败保护Fail-safe
任何解析失败、低置信、无法确定的情况,一律强制判为"可能命中 + 需人工复核",绝不静默判清白。Any parse failure, low confidence or uncertainty is forced to "possible match + needs human review" — never a silent all-clear.
升级计划Roadmap
正在对接商业级 PEP 数据源(见路线图),届时将带名单版本号与可核验来源。A commercial-grade PEP source is being integrated (see roadmap), which will carry list versions and verifiable sourcing.
📰

不良媒体 (Adverse Media)Adverse Media

AI 辅助初筛AI-assisted first pass
当前做法Current method
由 AI 模型扫描是否存在金融犯罪、欺诈、洗钱、逃税等负面信息,返回"清白 / 已标记"。这是初筛,不是持续的新闻媒体数据流。An AI model scans for negative signals — financial crime, fraud, money laundering, tax evasion — returning "clear / flagged". This is a first pass, not a live news-media feed.
失败保护Fail-safe
上游报错、解析失败、结果无法识别,一律判为"已标记"(从严),交人工复核。Upstream errors, parse failures or unrecognised results all resolve to "flagged" (conservative) for human review.
升级计划Roadmap
与 PEP 一并接入商业级不良媒体数据源。Being connected to a commercial adverse-media source alongside PEP.
关键披露 — 请务必对客户讲清楚Key disclosure — state this to your client

制裁名单是真实官方数据源(DFAT)。PEP 与不良媒体目前是 AI 辅助初筛,用于快速发现明显风险,不构成对持牌数据库的完整检索。所有命中与存疑一律由人工复核并做最终判断。商业级 PEP / 不良媒体数据源正在对接中。Sanctions screening uses a real official source (DFAT). PEP and adverse media are currently an AI-assisted first pass to surface obvious risk quickly, and do not constitute a full search of a licensed database. All hits and uncertainties are reviewed by a human who makes the final judgement. Commercial-grade PEP / adverse-media sources are being integrated.

讲解提示Talk-track 讲到这里可以停下来演示一次"Run All",让大家看到三个结果并排出现,然后指着 PEP/不良媒体的黄色徽标说明"这是初筛,绿色的 Sanctions 才是官方名单"。 Pause here and run "Run All" live so everyone sees the three results side by side; point to the amber PEP/adverse-media badges vs. the green Sanctions badge to make the distinction concrete.

4报告、归档与审计链:帮客户留好合规证据Report, archival & audit trail: keeping compliance evidence

合规不只是"做了",还要"证明做了"。系统为每个客户生成一份完整的 AML 评估报告,并保留一条不可篡改的审计记录。 Compliance isn't only about "doing it" — it's about "proving it". The system produces a complete AML assessment report per client and keeps a tamper-evident audit record.

AML 评估报告(11 个区块)AML assessment report (11 blocks)

区块Block内容Contents
0–1头部元数据(文档 ID、版本、SHA-256、PDF/A 合规)+ 身份与核验(provider 标注 Stripe Identity)Header metadata (doc ID, version, SHA-256, PDF/A) + identity & verification (provider: Stripe Identity)
2–3受益所有权(≥25% UBO)+ 四因素风险(客户 / 服务 / 渠道 / 国别)Beneficial ownership (≥25% UBO) + four-factor risk (customer / service / channel / country)
4–5总体风险评级与分数 + CDD 等级(简化 / 标准 / 强化)及理由Overall risk rating & score + CDD level (simplified / standard / enhanced) with justification
6筛查行 — 每类都如实标注数据源:PEP 标 AI 模型、Sanctions 标 "DFAT Consolidated List"、不良媒体标 AI 模型,含结果 / 名单版本 / 日期 / 是否需人工复核Screening rows — each honestly labels its source: PEP = AI model, Sanctions = "DFAT Consolidated List", adverse media = AI model, with result / list version / date / needs-review flag
7–9资金/财富来源 + 持续监控与下次复查 + 签核(高风险/PEP 需高管)Source of funds/wealth + ongoing monitoring & next review + sign-off (senior mgmt for high-risk/PEP)
10不可篡改审计链摘录(hash-chain)Tamper-evident audit-trail extract (hash-chain)
正在完善中Being improved

我们正在增强归档能力:生成的报告 PDF 将持久化存储并附不可变输入快照,让任何一份历史报告日后都能逐字节复现给审计员;同时补上审计链的运行时校验功能。We are strengthening archival: generated report PDFs will be persisted with an immutable input snapshot so any historical report can be reproduced byte-for-byte for an auditor later; plus a runtime verifier for the audit chain.

5现场操作脚本:会上跟着点一遍Live demo script: click along in the meeting

下面是会上现场演示的顺序。每一步都可以停下来讨论具体客户的情况。 Here's the order to demo live. Pause at any step to discuss a specific client's situation.

  1. 新建一个转所客户Create a transferring client

    客户列表 → New Client → 打开"Has Previous Accountant"开关 → 填前任信息 → 保存。观察:清关信自动发出。Client list → New Client → toggle "Has Previous Accountant" → fill predecessor details → save. Watch: the clearance letter is sent automatically.

  2. 打开客户,看进度条Open the client, view the progress bar

    Summary tab 顶部的五步进度条,指出"职业清关"这一步现在是"已发送"。The five-stage progress bar at the top of the Summary tab — point out that "Ethical Clearance" now shows "sent".

  3. 跑 KYC 评估Run the KYC assessment

    Compliance tab → KYC/AML Assessment → Start → AI Risk Analysis,展示风险评级与因素。Compliance tab → KYC/AML Assessment → Start → AI Risk Analysis; show the risk rating and factors.

  4. 跑三类筛查 (Run All)Run all three screenings

    点 "Run All Checks",三个结果并排出现。重点讲:绿色 Sanctions = 官方名单,黄色 PEP/不良媒体 = AI 初筛,命中都会翻人工复核。Click "Run All Checks"; three results appear side by side. Emphasise: green Sanctions = official list, amber PEP/adverse-media = AI first pass, all hits escalate to human review.

  5. 发身份核验链接Send identity verification

    Identity tab → Send verification link,演示客户端收到链接、上传证件的流程(可用测试客户)。Identity tab → Send verification link; demo the client receiving it and uploading ID (use a test client).

  6. 生成 AML 报告 / 证据包Generate the AML report / evidence pack

    导出 AML 报告 PDF,翻到筛查行,指出每类的数据源标注 — 呼应前面的完整披露。Export the AML report PDF, scroll to the screening rows, and point at the per-source labels — tying back to the full disclosure.

讨论环节Discussion 留一段时间,让会计们拿自己手上真实客户的情形提问:新移民客户怎么做 CDD、公司客户的 UBO 怎么查、前任会计不回信怎么办 — 这些都可以现场走一遍。 Leave time for accountants to raise real client scenarios: CDD for new-migrant clients, tracing UBO for a company, what to do when a predecessor doesn't respond — walk each through live.

!专业免责声明Professional disclaimer

请在使用本系统进行任何 KYC/AML 工作前,阅读并向你的客户传达以下声明。 Please read the following, and convey it to your clients, before using this system for any KYC/AML work.

本页仅作产品说明与培训用途,不构成法律、税务或合规意见。如需正式意见,请咨询持牌专业人士。 This page is for product explanation and training only and does not constitute legal, tax or compliance advice. For formal advice, consult a licensed professional.