Skip to main content

Risk & Compliance Intelligence

TumiTrust Portable Trust Infrastructure (PTI) delivers Risk & Compliance Intelligence as a reusable layer — not a bespoke vertical integration. Any institution that assesses people or businesses can consume the same JSON, PDF, and hub experience on hosted TumiTrust at tumitrust.com.

Who this is for

PersonaLookup profileContexts emphasized
Insurerrisk_assessmentinsurance, employment, risk_compliance lens
Bank / digital lenderlendinglending (Day-1 wedge), rental (expansion)
Fintech / paymentsmerchant_onboardingmerchant, digital_platform
Payroll / HRgeneral_trustemployment, family
Government / civicrisk_assessmentcivic, employment

How it fits together

Partner activity → Trust signals → Context-scoped report → Screening (when enabled)
→ Trust intelligence (JSON) → Insights Studio / API / Verify QR

One PTI-ID can carry insurance, merchant, and employment signals together — each context scored and explained separately, with partner-submitted activity attributed in the evidence trail. Machine-readable fields are defined in OpenAPI at tumitrust.com/api/docs/.

Producer path (ingest)

  1. Register as a trust producer (same rails as commerce integrations).
  2. Configure event catalog: policy_issued, premium_paid, claim_settled, and related event types for your vertical.
  3. Map events to trust signals via trigger rules in the hub — no code deploy required.
  4. Pulse shows entities linked, TCU usage, and ingestion health.

See Partner connector configuration.

Consumer path (lookup)

  1. Institution home — Risk & Compliance spotlight with one-click Run risk assessment lookup.
  2. Lookup Studio — choose profile or contexts; generate report.
  3. Insights Studio — screening summary, score composition, heatmap, explain panel, and verify link.
  4. Public verify — scan QR on PDF; tamper-proof portal matches hub scores.

See For institutions.

API contract

Reports include additive compliance_intelligence alongside core trust_intelligence.v1:

  • confidence — score_pct, band, drivers
  • risk_indicators — trust-derived bands (identity, payments, claims, community)
  • coverage_gaps — explicit missing or thin data (never implied as full clearance)
  • recommendations — next verification steps
  • screening_summary — sanctions, PEP, identity, registry (with provenance)
  • trust_timeline — score and identity events
  • compliance_lens — executive synthesis across contexts

See Trust infrastructure API.

Governance and data rights (public commitments)

TumiTrust operates in a regulated-risk-adjacent category: trust lookups, risk assessment, identity resolution, and analytics create obligations institutions and borrowers should expect us to document.

ObligationPublic commitment
Borrower consentExplicit consent before sharing trust data with third parties (Privacy Policy)
Data minimizationContext-scoped lookups request only entitled fields
Retention limitsAccount deletion flow with grace period; legal-hold exceptions documented in Privacy
ExplainabilityStructured drivers, provenance, and evidence trails in reports — not black-box scores
Data-subject rightsAccess, correction, deletion, and export (Privacy Policy)
Adverse actionInstitutions receive explainable outcomes suitable for committee and adverse-action workflows

Operating architecture details are covered in Trust governance and the Trust platform API. Create API keys under API & trust signals in your workspace after registration.

Screening

Screening checks (sanctions, PEP, identity, registry, and related dimensions) run when your workflow includes them.

People already on TumiTrust

When you generate a full trust report with the Risk assessment workflow (or lookup_profile: risk_assessment in the API), compliance screening is included automatically. You do not order screening separately.

People not yet on TumiTrust

When directory search returns no match but you provide strong identifiers (national ID, passport, or phone), TumiTrust automatically routes to an external screening report:

  • Runs sanctions and PEP checks using your workflow’s screening pack
  • Opens a trust record the person can claim when they join TumiTrust
  • Bills external screening credits (separate from basic/detailed/predictive tiers)
  • Does not include a trust score or AI predictions

You do not pick “external screening” as a workflow or report tier — pick Risk assessment (or your usual workflow), search, and the hub routes for you. After screening, search again to generate a full report.

StatusMeaning
clearNo actionable match in the provider dataset
match_reviewPotential match — manual review recommended
not_runCheck not executed (unsupported dimension or configuration)
unavailableProvider error — fail closed; never reported as clear

When your contract includes UNSCR screening, screening_summary also includes unscr_1267, unscr_1373, and unscr_1988 with the same status semantics.

Screening sources (sanctions, PEP, UN lists) are operated by TumiTrust on platform infrastructure — institutions consume results in Screening Intelligence and Compliance Center without pasting API keys. Contact your operator if federation status shows inactive checks.

Provenance: every completed check records provider_id, checked_at, dataset version, and integration source in the report and Compliance Center audit history.

Screening providers are configured for your hosted environment automatically based on your contract. Adverse media and specialized watchlists may return not_run until a dedicated provider is enabled for your plan.

Get started in your workspace

Register at tumitrust.com, complete institution onboarding, then use your own subjects in the institution hub:

  1. Producer path — ingest partner events via connector or CSV upload; confirm signals in Pulse and Partner Operations.
  2. Consumer path — dashboard spotlight → Lookup Studio → pick Risk assessment → search subject → generate report → Insights Studio → verify link on PDF.
  3. External subjects — if search returns no match, add national ID or phone; the hub runs automatic external screening (see Screening above).
  4. API parity — same JSON via POST …/trust-reports/reports/generate/ and POST …/trust-intelligence/screening/. Create a sandbox API key under API & trust signals; move to live only after account verification.

See Trust infrastructure API and external screening API.

Trust platform surfaces

  • Audit history — every lookup is recorded; repeat subjects may use cached results while provenance is preserved.
  • Compliance Center — screening status grid, history table, and CSV audit export (institution hub → Compliance).
  • Evidence Explorer — Insights Studio traces score → signals → source activity.
  • Unified timeline — subject activity feed in Insights Studio and via the trust timeline API.

See Trust platform overview.