Every compliance officer in the islands has had this conversation. A file comes back from review with one line against it: proof of address out of date. Somebody emails the client, the client sends a gas bill, the bill goes on the file, the line clears. Everyone moves on.
Nothing in that exchange established where the client lives.
That is not a pedantic point. It is the difference between a file that survives an inspection and one that collapses under a single question, and the gap has widened every year as the documents themselves have become easier to produce and harder to trust.
What the Handbook actually asks for
The GFSC Handbook on Countering Financial Crime separates two things that firms routinely collapse into one. Identification is obtaining the data: for a natural person, that includes their principal residential address. Verification is establishing, from a source independent of the customer, that the data is correct. Chapters 4 to 7 carry the customer due diligence measures, and the distinction runs through all of them.
Read that way, the question a proof of address answers is not "do we have an address on file". It is "what independent source tells us this person lives there, and how good is that source". A document the client hands you is, by construction, not independent of the client. It becomes evidence only to the degree that the institution which issued it did some work you are content to rely on.
The Handbook does not hand you a list of acceptable documents with a tick beside each one, and firms that want such a list are asking the wrong regulator. What it requires is a risk-sensitive judgement, made by your firm, recorded on the file, and consistent with your own procedures. Chapter 10 governs how that risk-based approach is applied. Your procedures decide what is acceptable for a low-risk file and what is not enough for a high-risk one. The Commission's interest is in whether you wrote that down, whether it is defensible, and whether you actually followed it.
What a utility bill proves
Start from what the document is. A utility bill is a billing record produced by a company that wanted to be paid. Its purpose was never identity assurance.
Consider what the issuer verified before printing it. In most cases: that somebody asked for a supply at that address and gave a name. Some suppliers do more. Many do not. The bill proves that a supplier believes a person by that name is responsible for an account at that address, which is a real fact and a weaker one than it looks.
Then consider the artefact you are actually holding. It is almost never a bill. It is a PDF downloaded from a customer portal, or a photograph of a piece of paper, or a screenshot. It arrived by email. It has no envelope, no postmark and no physical existence to corroborate. A PDF's text layer can be edited in software most people already have, and the result will look exactly like the original, because it is the original with different words in it.
This is the uncomfortable part: a firm that accepts a portal PDF as proof of address is, in evidential terms, accepting the client's own assertion in a nicer font. There is nothing scandalous about that when the file is low risk and your procedures say so in writing. It becomes a finding when the file is high risk, when the procedures said something stronger was needed, or when nobody at the firm can explain what the document was supposed to prove.
The three-month rule, and what it is for
Almost every firm in the islands works to some version of "dated within the last three months". It is a good rule and it is widely misunderstood.
Currency is not authenticity. A bill dated last week is exactly as forgeable as one dated last year. What the recency rule buys you is a different thing entirely: it tells you the relationship between the person and the address is probably still live. People move. A bill from 2021 may have been perfectly genuine in 2021 and tell you nothing about where the client sleeps tonight. That is the risk the rule addresses, and it is worth addressing.
What the rule does not do is upgrade a weak source into a strong one, and a firm that applies the date rule rigorously while never asking about the source has automated the easy half of the question.
One practical trap follows from this. A recency rule needs a date to measure from, and there are usually three candidates: the date printed on the document, the date somebody uploaded it, and the date the record was created. They are not the same. A 2023 bill uploaded last week is three months old by the wrong measure and two years old by the right one. Whichever your procedures pick, pick it explicitly and apply it the same way every time, because an inspector who finds two files measured differently has found a procedure nobody is following.
What raises the evidential value
None of this argues for abandoning documentary proof of address. It argues for being honest about the strength of each source, and for matching that strength to the risk of the file.
Sources issued by a government body or a regulated financial institution generally carry more weight than one issued by a commercial supplier, because more was verified before issue and the consequences of forging one are more serious. A document that reached the client through the post carries more than one downloaded from a portal, because delivery to the address is itself a weak proof of residence. Two independent sources agreeing carries more than either alone. Electronic verification against an independent data set carries more than any of them and is, for a remote onboarding, usually the strongest thing available.
And this is worth stating plainly: address evidence is not the load-bearing part of a modern identity check. A verified passport with a document authenticity result, an active liveness check and a face match against the portrait establishes that the person is who they claim to be, to a standard no gas bill approaches. The address tells you where to find them, which matters for jurisdiction, for tax residency and for risk, but it is not what proves the identity. Firms that spend most of their chasing effort on address documents are often optimising the weakest link in the chain.
The state to avoid
The worst outcome is not a weak document. It is a file that appears to hold address evidence when it does not, or holds a document nobody would defend if asked.
This happens quietly. A field called "proof of address" gets a green tick when someone uploads anything at all. A status is typed in by hand at onboarding and never revisited, so a document that has aged past the firm's own rule still shows as satisfied three years later. An entity, which has no residential address to prove, shows a gap forever and everyone learns to ignore the colour.
Each of those is a record that says something untrue about itself. An inspector who finds one stops trusting the rest, and they are right to.
What Flarion does about it
Flarion derives the proof of address position rather than storing it as something a person typed. It reads the newest address document on the file, takes the date it speaks for, and reports one of a small number of honest states: accepted, expired, not held, or not required where the party is an entity with no residential address to prove. Nobody can mark a file satisfied by hand, because there is no field to mark.
The recency window is the three-month rule, measured in days, and it is measured from the date the document itself carries wherever one is available, falling back to the upload only when it is not. A document that ages past the window flips to expired on its own, without waiting for a review to notice.
On the verification record, the line reads the same way an inspector would want it to read. Where no address document is held it says so in plain words rather than leaving a blank that could be mistaken for a tick. The record shows the evidence that exists and states the absence of the evidence that does not, which is the only version of a compliance record worth keeping.