KYC & AML Counterparty Due Diligence with real public registry checks — EU VAT validation against VIES, company status and directors, French address normalisation and insolvency notices, each a dated verdict citing its source. Conflict of interest checks, calculated AML/CFT (LCB-FT) due diligence level, beneficial owners and five-year retention.
Professions subject to due diligence before entering a business relationship
Overview
Counterparty Verification — DYONYSOS
App for professionals required to perform counterparty due diligence before entering into a business relationship — lawyers, condominium managers, real estate agents, chartered accountants — on Odoo 19 Community.
Also searched as: AML/CFT software for regulated professions, beneficial owner verification, lawyer conflict of interest check, enhanced customer due diligence, suspicious activity report register, firm KYC, intra-EU VAT number verification, customer SIREN check, customer insolvency proceedings check.
What public registries know, the module actually checks. The validity of an intra-EU VAT number with the European Commission's VIES service; a company's identity, activity code and status — active or ceased — with the French company search service (recherche d'entreprises); normalization of a French address with the Base Adresse Nationale (national address database); the officers declared in the register; insolvency proceedings published in the BODACC. Six free public services provide the answers, five of them without any account. Each check returns a dated finding citing its source, and an outdated finding becomes a gap again: a company that was active two years ago proves nothing today.
The module records findings; it does not draw conclusions. That a VAT number is unknown to VIES or that a company is listed as ceased in the register is a fact, recorded as such with its source and date. Deciding whether to proceed with the business remains the professional's call, and they answer for it to their supervisory authority — no adverse finding blocks the onboarding of a client. Software claiming to say “this person is high-risk” would be wrong and dangerous: this is not that software.
A public registry that is down never blocks data entry. Calls go through the queue of the Public registry connections module, free and installed with this one: nothing is sent from a screen, a silent service leaves a gap rather than an error, the last known response remains readable with its true date, and an offline mode lets you work without outbound access. Above all, an overloaded service is never read as a negative answer: declaring a perfectly valid VAT number invalid because a Member State's tax authority was overloaded would be the most serious mistake such a module could make.
Better still: when one service is missing, another answers. Each reference source is served by a chain of providers, tried in order. For a company's identity, INSEE's Sirene API is authoritative but requires a free key; the company search service, by contrast, is always open. With no key at all, everything works. With a key, identity comes from INSEE — and since INSEE does not publish company officers, the chain drops down one level to obtain them: adding a key enriches the findings and never weakens any of them.
Every finding names the service that provided it. A file can thus carry an identity obtained from INSEE and officers obtained from the company search service, each with its exact source. A finding obtained from a second-tier service is flagged as such: it remains valid, but it does not carry quite the same weight as one from the official source, and that must be visible.
No sanctions list, no database of politically exposed persons. No free and reliable one exists: those criteria are still ticked based on the professional's expert judgment. The module organizes and records due diligence — who checked what, against which source, when, and what decision was made. That is what an inspection by the supervisory authority asks for: proof of due diligence, not a score.
Two distinct obligations, which the module never confuses.
Conflict of interest: a lawyer may not act against a former client in a related matter (French national rules of the legal profession — RIN, art. 4). The case file records the opposing party and automatically detects whether it has previously been a client of the firm — client intake is blocked until the conflict is explicitly waived and justified.
Anti-money laundering (LCB-FT): identification of the client and the beneficial owner, screening for politically exposed person status, risk assessment and enhanced due diligence when the risk is high (French Monetary and Financial Code, art. L561-1 et seq.).
The due diligence level is calculated, not chosen by hand. Three levels — simplified, standard, enhanced — derived from the criteria checked: type of client, country involved, nature of the transaction, amount, onboarding channel. An enhanced level requires additional measures (enhanced identity verification, source of funds, approval by the compliance officer) and blocks onboarding until they are completed.
The beneficial owner is the natural person. Behind a company, you must trace back to the natural persons holding more than 25% of the capital or exercising control. The ownership chain is modeled with percentages, and the module flags when the sum of known holdings does not reach 100% — the most common gap in a file — blocking the onboarding of a legal entity until the chain is complete.
Retention is five years after the end of the business relationship. Each file carries its end date and its calculated purge date, and files due for purging are listed in a dedicated filter.
Suspicious activity reports exist, and they are confidential. If a report is filed with Tracfin, the file records that it took place, its date and its author — never its content — and this information is visible only to the compliance officer: a staff member without that role can neither read it nor infer it, including through a technical search. The legal prohibition on informing the client concerned (art. L561-18 of the French Monetary and Financial Code) is displayed on screen.
What the module does not do
It never reaches a conclusion: it issues no risk score, no credit rating and no opinion on whether to enter into a business relationship. It checks no sanctions list, no beneficial ownership register and no database of politically exposed persons — none of them is public and free. It calls no identity verification API for individuals. It files no report with Tracfin: filing remains external, and the module only records that it took place. It does not manage the engagement letter, invoicing or the client matter itself: it is a prior check and its audit trail, not a client file.
Two roles
Associate: prepares the file — identification, risk criteria, chain of beneficial owners, opposing party. Never has access to suspicious activity reports. Compliance officer: approves enhanced due diligence, clears justified conflicts of interest, and is the only one able to record and view a suspicious activity report.
Key points
- Conflict of interest — Detects whether the opposing party has previously been a client of the firm; blocks onboarding until the conflict is cleared and justified (RIN, art.
- Calculated due diligence level — PEP, high-risk country, amount, channel, client type: the simplified / standard / enhanced level is derived from these criteria.
- Enhanced due diligence — Enhanced identity verification, source of funds, compliance officer approval — onboarding waits until they are completed.
Specifications
| Price | €309 excl. VAT |
|---|---|
| License | OPL-1 |
| Odoo series | 19.0: published on the Odoo Apps Store; 20.0: published on the Odoo Apps Store |
| Version | 3.0.0 |
| Edition | Odoo Community / on-premise |
| Technical name | dyo_verification_contrepartie |
| Domain | Industries and services |
Price excluding VAT as displayed on the Odoo Apps Store; purchase and installation are done on the Store or through your Omnifloo instance.