Connecting Xero Practice Manager (XPM)
Overview. Connect XPM to IdentityCheck once, and IdentityCheck adds KYC (and, for Tranche 2, AML) command and status fields to your XPM clients. Tick the command checkbox on a client and IdentityCheck sends them a verification link and writes the result back onto the client record. The XPM connection runs on an hourly background sync, so treat it as automatic rather than instant. XPM is also the only system where a completed self-serve check can create a new client.
How the connection works
XPM is one of our out-of-the-box integrations, so it is available on every tier, including the free plan. Only custom integrations require a paid tier.
You connect XPM to IdentityCheck through a secure authorisation (OAuth), so you never hand over your password. Once connected, IdentityCheck adds a small set of custom fields to your XPM clients: a KYC Command checkbox and a KYC Status field, plus an AML Command checkbox and AML Status field if you use the Tranche 2 risk-assessment flow. These fields are created for you automatically the first time each feature is enabled, and they are only ever created once, so you will not end up with duplicates.
From then on, XPM is where your staff act and IdentityCheck does the rest in the background: it starts the check, emails your client the link, and writes progress and results back onto the same client record. Nobody has to copy details between systems.
You connect and manage XPM from your Integrations settings in the app.
The hourly sync (why it is not instant)
XPM is a scheduled (polling) integration. That means IdentityCheck runs a background job roughly once an hour that scans your XPM clients for any command field that has been ticked, and acts on the ones it finds.
This is important to plan around: when a staff member ticks a command box, the check is not sent the instant they click. It is sent on the next sync, which can be up to an hour away. It is best to describe this to your team as automatic, not instant. Everything still happens without anyone re-keying data; there is just a short, predictable delay. If you need to confirm a check has fired straight away, send yourself a test rather than watching a real client record (see Testing your integration end to end).
Setting up the trigger (KYC Command and AML Command)
The command field is the switch that tells IdentityCheck to act on a client.
- KYC Command starts a plain identity (KYC) check. Tick it on a client, and on the next sync IdentityCheck emails that client a verification link and sets KYC Status to Started. When the client finishes, the identity result is written back.
- AML Command starts a full Tranche 2 risk assessment: the consent, intake, biometric and risk-assessment journey. This only works once the account-level Tranche 2 flow is switched on. See Setting up your Tranche 2 compliance flow.
The command field is a trigger only. IdentityCheck reads it to know it should start; it never writes results into the command box. Results go to the separate status and result fields described below.
On XPM you can also set a client's status to Excluded to exempt them from ever triggering a check, which is handy for clients you have already verified elsewhere or who are out of scope.
What gets written back
Once a check runs, IdentityCheck writes the outcome onto the XPM client so your system of record stays current.
- For a KYC check: the identity decision and status are written back onto the client.
- For a Tranche 2 (AML) check: when the assessment completes, five fields are written back: Risk Rating, RA Completed Date (written as a true date field in XPM), RA Completed By, Risk Assessment Link, and AML Status. The AML Status tracks the assessment through Started, Awaiting risk assessment, and Completed or Failed.
Because the result lives on the client record in XPM, your evidence sits in the practice system you already use for record keeping.
Using IdentityCheck for onboarding
XPM is not just for verifying clients you already have. You can also use it to onboard brand-new clients. IdentityCheck can generate a public link that contains your intake form, which you put on your website or send to a prospect. When someone submits the form and completes their check, IdentityCheck can create the matching XPM client record (or records) for you, with the result already written onto it, so a new client arrives in XPM ready to go rather than as a manual data-entry job.
The public onboarding link is a Growth-plan feature. Creating the XPM client from a completed public check works out of the box on XPM; the same record creation in other platforms is available on request and needs at least the Growth plan. The mechanics are covered in the next section and in Your public intake link.
Creating a new client from a self-serve check
XPM has one capability the other integrations do not: it can create a brand-new client from a completed public self-serve verification. If you publish an intake link and a new person verifies themselves through it, IdentityCheck can create a matching XPM client for them and write the result onto it.
A few things worth knowing:
- This is XPM only. Other connected systems do not create clients from a self-serve check.
- An admin turns this on and chooses when it fires (after intake, after the biometric, or after the risk assessment), and maps the intake questions to XPM profile fields.
- Each qualifying completion creates exactly one client, and re-processing never creates a duplicate. Starting a check on a client who already exists in XPM does not create a second record; it just writes back to the existing one.
For how the public link itself works, see Your public intake link.
Frequently asked
How do I start a check from inside XPM? Tick the KYC Command checkbox on the client (or the AML Command checkbox for a Tranche 2 risk assessment). On its next hourly sync IdentityCheck picks up the ticked client, emails them a verification link, and sets the status field to Started. You do not need to leave XPM to send a check.
Why did nothing happen straight after I ticked the box? The XPM connection runs on an hourly background sync, not in real time. Allow up to an hour for the check to be sent and the status to update. If nothing happens after that, confirm the account-level flow is on and the client has a valid email, then see the troubleshooting article.
Does IdentityCheck create clients in XPM? Only in one direction. XPM is the one system where a completed public self-serve verification can create a brand-new client record. Starting a check on an existing XPM client never creates a duplicate; it just writes the result back onto that client.
Where do the AML results appear on the client? When a Tranche 2 assessment completes, IdentityCheck writes five fields onto the XPM client: Risk Rating, RA Completed Date, RA Completed By, Risk Assessment Link and AML Status. The completed date is stored as a real date field, and the Risk Assessment Link opens the full assessment record.
