Chartered accountancy practice · London · works with high-net-worth clients
Secure Client Onboarding on Dataverse for a UK Accountancy Firm
A firm that must verify every new client cannot onboard through email. It is slow, insecure and weak as evidence: passports sent as attachments, questions buried in long threads, staff typing everything again before any check could begin. Clients now sign in to a secure portal, provide their details and identity documents once, and message the staff handling their case. All of it reaches the firm's Dataverse app as structured data, and the driving licence and public-record checks run there.

- Industry
- Accounting & Bookkeeping
- Function
- Legal & Compliance
- Region
- United Kingdom
Results
- 1
- secure portal covering details, ID and chat
- Client sign-in via Microsoft Entra (Azure AD B2C). This is scope, not a measured saving.
- 0
- client details typed again by staff
- Submissions reach Dataverse as structured data via its API.
- 2
- check types run inside the staff app
- Custom connectors verify driving licences and public records.
01
The challenge
The client is a chartered accountancy firm in London. It works with high-net-worth individuals, entrepreneurs and international groups. Under the Money Laundering Regulations, every UK accountancy firm must identify and verify a new client before it can act for them. Staff did this verification in an internal model-driven Power Apps app built on Dataverse. On the client side, though, there was no proper channel at all.
Where it fell short
- Personal data travelling by email. Passports, addresses and other personal details came in as attachments, with no controlled system around them.
- Typing before checking. Before verification could begin, staff had to copy each client's information into the internal app by hand.
- Questions going missing. Clients reported problems by phone or email, and nothing linked those conversations to their case.
- Checks that took too long. Driving licence and public-information checks were manual and happened outside the app.
- A weak first impression. For a high-net-worth client, an awkward onboarding is the first thing they experience of the firm.
02
What we did
We delivered a secure onboarding application for clients and linked it to the internal app the firm runs on Dataverse. Clients now provide everything once, in a single place, and staff work with structured data.
The pieces
- Onboarding portal for clients. A custom application in Node.js. New clients sign in via Microsoft Entra (Azure AD B2C) and move through a set onboarding process.
- Details and identity documents. The portal is where clients enter their information and upload their ID documents, replacing email.
- Messaging the case team. Chat inside the application links each client to the staff assigned to their case, so issues are raised and resolved with the case in view.
- Data sent directly to Dataverse. The Dataverse Web API receives what clients submit and populates the firm's model-driven app, already in the structure that verification staff need.
- An upgraded model-driven app. We added more information to the internal app, plus custom connectors that check driving licences and other public information.
Stack
| Layer | Tools |
|---|---|
| Portal for clients | Node.js |
| Sign-in for clients | Microsoft Entra (Azure AD B2C) |
| Data layer | Microsoft Dataverse with its Web API |
| Staff application | Model-driven app in Power Apps |
| Verification | Custom Power Platform connectors that check driving licences and public information |
| Communication | Document upload and in-app chat linking clients with their case team |
03
The outcome
Every new client goes through the same secure onboarding process. When staff open their model-driven app, the client's data is already in it, structured and ready for verification.
| Before | After | |
|---|---|---|
| ID documents and personal details | Sent as email attachments | Provided via a secure portal |
| Moving data into the staff app | Typed again manually | Pushed to Dataverse via its API |
| Questions from clients | Phone and email, with no link to the case | In-portal chat with the assigned staff |
| Driving licence and public-record checks | Done by hand outside the app | Run by custom connectors in the app |
- A proper, secure onboarding process for clients, replacing email.
- Clients take issues straight to the staff handling their case, within the portal.
- Staff use structured data that is already in their model-driven app, with no retyping.
- The app itself runs driving licence and public-record checks.
This engagement did not record any time-saving or volume figures. The numbers on this page describe its scope.
What teams often underestimate
A portal that collects clients' passports is a security project before it is a user-experience project. External users need an identity separate from staff identity. Personal data must end up in a system that controls who can see it. Nothing sensitive should stay in the portal any longer than the handover takes. Client sign-in through Entra B2C, with data moved directly into Dataverse, where access controls set by the firm already apply, keeps the portal light and the sensitive data in a single governed location.
Built with
The platforms and tools this engagement runs on.
More case studies
Similar problems, measured the same way.

Dutch-headquartered food retail group · one of the biggest globally · centres worldwide
Procurement on Power Platform for a Global Food Retail Group
- single system covering all in-scope procurement
- 1
- single system covering all in-scope procurement
- ways in, licensed according to user type
- 2
- ways in, licensed according to user type

UK risk and compliance practice · KYC and AML reviews for financial-services firms and other UK organisations
A 13-Step KYC and AML Case Platform for a UK Compliance Practice
- steps structure each KYC case
- 13
- steps structure each KYC case
- roles that keep duties separate
- 3
- roles that keep duties separate

Bulgarian accounting firm · 10-15 people · bookkeeping for 100+ client companies
Hands-Free Bank Statement Retrieval
- client companies handled twice a month
- 70+
- client companies handled twice a month
- bank portals driven by RPA
- 3
- bank portals driven by RPA


