> ## Documentation Index
> Fetch the complete documentation index at: https://rain-sandbox-trial.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Who Verifies What

> Your compliance model decides who collects identity data and who verifies it. Rain screens every party either way.

The first thing to settle in a compliance integration is who does what. Rain
offers two compliance models. Under **Standard Compliance**, Rain collects and
verifies customer identity directly. Under **Hybrid Compliance**, you verify
customers in your own compliance program first, and Rain still screens every
party.

That single difference changes what you send, what you do not have to send, and
how strictly country rules apply.

<Info>
  Your compliance model is separate from your [management model](/docs/first-steps).
  Rain-Managed and Partner-Managed describe how collateral and funds are handled,
  not who verifies your customers.
</Info>

## Responsibilities by compliance model

The following table compares the two models across both verification pipelines:

|                                                      | Standard Compliance                | Hybrid Compliance                                          |
| :--------------------------------------------------- | :--------------------------------- | :--------------------------------------------------------- |
| Collect identity data                                | Rain                               | You                                                        |
| Consumer applicant's identity document and selfie    | Required                           | Not required                                               |
| Verify identity                                      | Rain                               | You, in your own compliance program                        |
| AML, PEP, and sanctions screening                    | Rain                               | Rain                                                       |
| On-chain screening, when a wallet address is present | Rain                               | Rain                                                       |
| UBO checks                                           | Reviewed by Rain's compliance team | Run automatically alongside representatives                |
| Country and jurisdiction rules                       | All rules apply                    | Only hard-blocked countries are rejected outright          |
| Payments account owner check (CIP)                   | Rain runs the check                | You verify the account owner; Rain still screens the party |

Screening is the row that never moves. Every applicant is screened in both
models, so even if you have already cleared a customer under Hybrid Compliance,
Rain can still place that customer in manual review or reject them.

## What changes for a person

Under Standard Compliance you submit the full consumer profile, an identity
document, and a selfie with a liveness check. Verification begins once all three
are present.

Under Hybrid Compliance you submit only the identifying fields, because you
have already verified the person. No identity document or selfie upload is
needed. Rain runs AML, PEP, and sanctions screening on the applicant.

## What changes for a business

Under Standard Compliance you submit the company's full profile along with its
supporting documents.

Under Hybrid Compliance you manage your own company due diligence. Rain
requires the company's identifying fields and runs AML, PEP, and sanctions
screening on the company, on every representative, and on every UBO.

Both models require the people behind the business. Representatives and
Ultimate Beneficial Owners are part of a corporate application either way, and
UBOs provide an identity document in both models. What differs is whether
Rain's compliance team reviews the UBO checks or they run automatically. See
[Ultimate Beneficial Owner (UBO)](/docs/ultimate-beneficial-owner-ubo).

## What does not change

Three things are the same in both models:

* **Screening:** AML, PEP, and sanctions screening runs on every party, plus
  on-chain screening through Chainalysis whenever a wallet address is provided.
* **Two separate gates:** Cards approval and payments approval are independent.
  Clearing one does not clear the other.
* **Hard-blocked countries:** these are rejected in both models. Only the
  unsupported-state and soft-blocked rules relax under Hybrid Compliance.

## What's next

<Columns cols={3}>
  <Card title="Verification requirements" icon="shield-check" href="/docs/verification-requirements">
    The field-by-field tables for each model, the country rules, and how
    screening works.
  </Card>

  <Card title="Choose your model" icon="sitemap" href="/docs/first-steps">
    Pick your program type and management model, if you have not already.
  </Card>

  <Card title="Payments compliance" icon="money-check-dollar" href="/docs/payments-compliance">
    The separate gate that gates money movement rather than card issuance.
  </Card>
</Columns>
