Help Centre/Uploading evidence

Uploading evidence

In brief: How to attach certificates, ID docs, SoF proofs, audit reports.

Watch this in the product

All tutorials

Producing a client file for an inspection

Firm-level reports and the one-document compliance pack, in about thirty seconds.

Open on YouTube

Several compliance records (training certificates, audit reports, BO ID documents, source-of-funds proofs, the PCP source PDF) need actual files attached rather than just URLs.

Where you'll see the upload

Every dialog that needs evidence shows an Upload evidence control inline with the existing URL input:

  • Settings → AML Compliance → Staff AML Training Register: add record → upload certificate
  • Settings → AML Compliance → Independent AML Audit Reviews: record review → upload reviewer's report
  • Settings → AML Compliance → Policies, Controls & Procedures: publish version → upload source document
  • Client profile → Beneficial owners: add owner → upload ID
  • Client profile → Source of Funds: add declaration → upload evidence

What's accepted

PDF or image (JPG, PNG, WEBP, HEIC, HEIF), DOC or DOCX. Max 20 MB per file.

How files are stored

Files are stored in a private storage bucket scoped to your firm. The path convention is <your-firm-id>/<category>/<record-key>/<filename>. Only active members of your firm can read, upload, update, or delete files under your firm's prefix. Cross-firm access is blocked at the database level.

How files are served

When a staff member clicks "Open" or "View evidence", we generate a 60-second signed URL that proxies through Supabase Storage. The URL expires automatically; there's no permanent public link to any file.

What the Compliance Pack does with them

The Compliance Pack ZIP automatically bundles every uploaded evidence file alongside the three PDFs, so an inspector gets everything in a single download. Files are renamed in the zip to be recognisable (e.g. jane-doe-AML-induction-2026-01-15.pdf) and prefixed with a short uuid to guarantee uniqueness.

URL or upload?

If you keep the certificate in an external system (e.g. ICAEW's provider portal), you can still paste the URL; the record accepts either or both. The upload takes precedence in the UI; if you upload later, the link badge switches to "Uploaded evidence".

Deleting evidence

The "X" button on an uploaded file removes it from storage and clears the link on the record. Use with caution: there's no undo. The parent record itself is preserved.

Company records in Documents

A company's Documents section shows Company records, including saved Companies House register copies and company checks. Each saved copy is listed as Companies House record with its date. Use Download beside it to save a readable JSON file named with the client reference, company name and record date. These records are kept for 5 years after the relationship ends.

Individual clients continue to show Identity check evidence. If records cannot be loaded, the page shows an error and a Try again button.

Didn't find what you needed?

Contact support