Risk & Compliance Intelligence
TumiTrust Portable Trust Infrastructure (PTI) delivers Risk & Compliance Intelligence as a reusable layer — not a bespoke vertical integration. Any institution that assesses people or businesses can consume the same JSON, PDF, and hub experience on hosted TumiTrust at tumitrust.com.
Who this is for
| Persona | Lookup profile | Contexts emphasized |
|---|---|---|
| Insurer | risk_assessment | insurance, employment, risk_compliance lens |
| Bank / digital lender | lending | lending (Day-1 wedge), rental (expansion) |
| Fintech / payments | merchant_onboarding | merchant, digital_platform |
| Payroll / HR | general_trust | employment, family |
| Government / civic | risk_assessment | civic, employment |
How it fits together
Partner activity → Trust signals → Context-scoped report → Screening (when enabled)
→ Trust intelligence (JSON) → Insights Studio / API / Verify QR
One PTI-ID can carry insurance, merchant, and employment signals together — each context scored and explained separately, with partner-submitted activity attributed in the evidence trail. Machine-readable fields are defined in OpenAPI at tumitrust.com/api/docs/.
Producer path (ingest)
- Register as a trust producer (same rails as commerce integrations).
- Configure event catalog:
policy_issued,premium_paid,claim_settled, and related event types for your vertical. - Map events to trust signals via trigger rules in the hub — no code deploy required.
- Pulse shows entities linked, TCU usage, and ingestion health.
See Partner connector configuration.
Consumer path (lookup)
- Institution home — Risk & Compliance spotlight with one-click Run risk assessment lookup.
- Lookup Studio — choose profile or contexts; generate report.
- Insights Studio — screening summary, score composition, heatmap, explain panel, and verify link.
- Public verify — scan QR on PDF; tamper-proof portal matches hub scores.
See For institutions.
API contract
Reports include additive compliance_intelligence alongside core trust_intelligence.v1:
confidence— score_pct, band, driversrisk_indicators— trust-derived bands (identity, payments, claims, community)coverage_gaps— explicit missing or thin data (never implied as full clearance)recommendations— next verification stepsscreening_summary— sanctions, PEP, identity, registry (with provenance)trust_timeline— score and identity eventscompliance_lens— executive synthesis across contexts
Governance and data rights (public commitments)
TumiTrust operates in a regulated-risk-adjacent category: trust lookups, risk assessment, identity resolution, and analytics create obligations institutions and borrowers should expect us to document.
| Obligation | Public commitment |
|---|---|
| Borrower consent | Explicit consent before sharing trust data with third parties (Privacy Policy) |
| Data minimization | Context-scoped lookups request only entitled fields |
| Retention limits | Account deletion flow with grace period; legal-hold exceptions documented in Privacy |
| Explainability | Structured drivers, provenance, and evidence trails in reports — not black-box scores |
| Data-subject rights | Access, correction, deletion, and export (Privacy Policy) |
| Adverse action | Institutions receive explainable outcomes suitable for committee and adverse-action workflows |
Operating architecture details are covered in Trust governance and the Trust platform API. Create API keys under API & trust signals in your workspace after registration.
Screening
Screening checks (sanctions, PEP, identity, registry, and related dimensions) run when your workflow includes them.
People already on TumiTrust
When you generate a full trust report with the Risk assessment workflow (or lookup_profile: risk_assessment in the API), compliance screening is included automatically. You do not order screening separately.
People not yet on TumiTrust
When directory search returns no match but you provide strong identifiers (national ID, passport, or phone), TumiTrust automatically routes to an external screening report:
- Runs sanctions and PEP checks using your workflow’s screening pack
- Opens a trust record the person can claim when they join TumiTrust
- Bills external screening credits (separate from basic/detailed/predictive tiers)
- Does not include a trust score or AI predictions
You do not pick “external screening” as a workflow or report tier — pick Risk assessment (or your usual workflow), search, and the hub routes for you. After screening, search again to generate a full report.
| Status | Meaning |
|---|---|
clear | No actionable match in the provider dataset |
match_review | Potential match — manual review recommended |
not_run | Check not executed (unsupported dimension or configuration) |
unavailable | Provider error — fail closed; never reported as clear |
When your contract includes UNSCR screening, screening_summary also includes unscr_1267, unscr_1373, and unscr_1988 with the same status semantics.
Screening sources (sanctions, PEP, UN lists) are operated by TumiTrust on platform infrastructure — institutions consume results in Screening Intelligence and Compliance Center without pasting API keys. Contact your operator if federation status shows inactive checks.
Provenance: every completed check records provider_id, checked_at, dataset version, and integration source in the report and Compliance Center audit history.
Screening providers are configured for your hosted environment automatically based on your contract. Adverse media and specialized watchlists may return not_run until a dedicated provider is enabled for your plan.
Get started in your workspace
Register at tumitrust.com, complete institution onboarding, then use your own subjects in the institution hub:
- Producer path — ingest partner events via connector or CSV upload; confirm signals in Pulse and Partner Operations.
- Consumer path — dashboard spotlight → Lookup Studio → pick Risk assessment → search subject → generate report → Insights Studio → verify link on PDF.
- External subjects — if search returns no match, add national ID or phone; the hub runs automatic external screening (see Screening above).
- API parity — same JSON via
POST …/trust-reports/reports/generate/andPOST …/trust-intelligence/screening/. Create a sandbox API key under API & trust signals; move to live only after account verification.
See Trust infrastructure API and external screening API.
Trust platform surfaces
- Audit history — every lookup is recorded; repeat subjects may use cached results while provenance is preserved.
- Compliance Center — screening status grid, history table, and CSV audit export (institution hub → Compliance).
- Evidence Explorer — Insights Studio traces score → signals → source activity.
- Unified timeline — subject activity feed in Insights Studio and via the trust timeline API.
Related
- Screening services — TumiTrust’s dedicated screening product (outside the PTI open standard)
- Trust contexts
- Portable Trust Infrastructure
- Institution report lookup