KT Sparks

Chartered accountancy practice · London · works with high-net-worth clients

Secure Client Onboarding on Dataverse for a UK Accountancy Firm

A firm that must verify every new client cannot onboard through email. It is slow, insecure and weak as evidence: passports sent as attachments, questions buried in long threads, staff typing everything again before any check could begin. Clients now sign in to a secure portal, provide their details and identity documents once, and message the staff handling their case. All of it reaches the firm's Dataverse app as structured data, and the driving licence and public-record checks run there.

Secure Client Onboarding on Dataverse for a UK Accountancy Firm
Industry
Accounting & Bookkeeping
Function
Legal & Compliance
Region
United Kingdom

Results

1
secure portal covering details, ID and chat
Client sign-in via Microsoft Entra (Azure AD B2C). This is scope, not a measured saving.
0
client details typed again by staff
Submissions reach Dataverse as structured data via its API.
2
check types run inside the staff app
Custom connectors verify driving licences and public records.

01

The challenge

The client is a chartered accountancy firm in London. It works with high-net-worth individuals, entrepreneurs and international groups. Under the Money Laundering Regulations, every UK accountancy firm must identify and verify a new client before it can act for them. Staff did this verification in an internal model-driven Power Apps app built on Dataverse. On the client side, though, there was no proper channel at all.

Where it fell short

  • Personal data travelling by email. Passports, addresses and other personal details came in as attachments, with no controlled system around them.
  • Typing before checking. Before verification could begin, staff had to copy each client's information into the internal app by hand.
  • Questions going missing. Clients reported problems by phone or email, and nothing linked those conversations to their case.
  • Checks that took too long. Driving licence and public-information checks were manual and happened outside the app.
  • A weak first impression. For a high-net-worth client, an awkward onboarding is the first thing they experience of the firm.

02

What we did

We delivered a secure onboarding application for clients and linked it to the internal app the firm runs on Dataverse. Clients now provide everything once, in a single place, and staff work with structured data.

The pieces

  1. Onboarding portal for clients. A custom application in Node.js. New clients sign in via Microsoft Entra (Azure AD B2C) and move through a set onboarding process.
  2. Details and identity documents. The portal is where clients enter their information and upload their ID documents, replacing email.
  3. Messaging the case team. Chat inside the application links each client to the staff assigned to their case, so issues are raised and resolved with the case in view.
  4. Data sent directly to Dataverse. The Dataverse Web API receives what clients submit and populates the firm's model-driven app, already in the structure that verification staff need.
  5. An upgraded model-driven app. We added more information to the internal app, plus custom connectors that check driving licences and other public information.

Stack

LayerTools
Portal for clientsNode.js
Sign-in for clientsMicrosoft Entra (Azure AD B2C)
Data layerMicrosoft Dataverse with its Web API
Staff applicationModel-driven app in Power Apps
VerificationCustom Power Platform connectors that check driving licences and public information
CommunicationDocument upload and in-app chat linking clients with their case team

03

The outcome

Every new client goes through the same secure onboarding process. When staff open their model-driven app, the client's data is already in it, structured and ready for verification.

BeforeAfter
ID documents and personal detailsSent as email attachmentsProvided via a secure portal
Moving data into the staff appTyped again manuallyPushed to Dataverse via its API
Questions from clientsPhone and email, with no link to the caseIn-portal chat with the assigned staff
Driving licence and public-record checksDone by hand outside the appRun by custom connectors in the app
  • A proper, secure onboarding process for clients, replacing email.
  • Clients take issues straight to the staff handling their case, within the portal.
  • Staff use structured data that is already in their model-driven app, with no retyping.
  • The app itself runs driving licence and public-record checks.

This engagement did not record any time-saving or volume figures. The numbers on this page describe its scope.

What teams often underestimate

A portal that collects clients' passports is a security project before it is a user-experience project. External users need an identity separate from staff identity. Personal data must end up in a system that controls who can see it. Nothing sensitive should stay in the portal any longer than the handover takes. Client sign-in through Entra B2C, with data moved directly into Dataverse, where access controls set by the firm already apply, keeps the portal light and the sensitive data in a single governed location.