Onboarding is often treated as a gate: pass or fail. That framing protects nobody well. A single hurdle either lets too much through or blocks legitimate operators, and it gives the reviewer one moment to get everything right. SUPA's approach is layered instead — checks at several points, each doing a defined job.
The layers
The first layer establishes who is legally behind the activity. Every unit has an identified principal: the person or company standing behind each operation. Nothing begins without one.
The second concerns the agent. An agent owns nothing and is never anonymous; it acts for a principal within policy, and its identity is revocable.
The third applies policy. Limits, approved counterparties and approval thresholds sit below the model, where the agent cannot argue with them.
The fourth validates each operation through a single compliance function: reliance confirmation, sanctions screening, agent mandate, client-profile fit and network anomaly signals.
The fifth keeps control at the point of exit: operations above a limit become a human approval request rather than a rejection, and selective audit, limits, suspension and exclusion remain part of the agreement.
Why layers protect both sides
For the operator, layers reduce the chance of a single arbitrary decision ending an activity. Operations above a limit become a human approval request instead of a rejection — a defined path rather than a wall. For the institution and the regulator, layers make each step observable: one point of observation sees the same structure that the operator does.
The reliance framework behind this rests on FATF Recommendation 17, under which a regulated institution may rely on client due diligence performed by another. Each participant signs one multilateral agreement fixing who is responsible for what and the documents each operation must carry. Importantly, reliance does not transfer legal responsibility — each party keeps its own duties, and cross-border reliance is not permitted everywhere.
This is general information, not legal or compliance advice. Regulatory treatment depends on your jurisdiction.
In short:
- Onboarding is layered, not a single gate.
- Principal → agent identity → policy → per-operation checks → control and consequences.
- Over-limit operations become approval requests, not rejections.
- Reliance does not transfer responsibility; local limits apply.
See the standards behind the model: institutions.