Skip to content

Running the checks is the easy bit: what firms asked us about AML risk assessments

Line icons of an ID card, a risk rating gauge and a signed document, under the title Running the checks is the easy bit

On 1 October we ran a session on the Seamlss AML risk assessment tool. Near the end, Clayton said running the checks was the easy bit.

From paper and spreadsheets to one record

Most firms we talk to already run ID, PEP and sanctions checks, usually in one app, with the results saved somewhere else. The risk assessment is done separately, in Word, in Excel or on paper. That’s the slow part. Every answer the client gives has to be weighed against every risk factor by hand, and the result then has to be written up, signed off and filed so you can find it at review time.

In Seamlss it runs as one flow, from onboarding to a filed PDF. Here’s what your team does at each step, and what your client sees:

  1. Onboard the client and check their ID
    In Seamlss

    You send an onboarding request. When it comes back, their details, ID check result and signed engagement letter are on the client’s record. Existing clients brought in from XPM are already here.

    Your client

    Gets a secure link, fills in their details, verifies their ID with a photo of their document and a selfie, and signs the engagement letter.

  2. Start the risk assessment and run the AML checks
    In Seamlss

    Choose the designated service and the people involved, then run the PEP and sanctions checks inside the assessment, or reuse a recent result for someone who sits behind several entities.

    Your client

    Nothing to do.

  3. Answer the risk questions, or send them to the client
    In Seamlss

    Answer from what your team already knows, or send the questions to the client. The record shows where each answer came from, and your team’s own observations stay internal.

    Your client

    If you send them, answers the questions online.

  4. Complete it and file the outcome
    In Seamlss

    You get a rating and the reason for it. Low ratings can be completed by your admin team; medium and high go to a partner or your compliance officer to sign off. Download the PDF for the client’s file, with the next review date set.

    Your client

    Nothing to do.

The checks sit inside the assessment, so there’s nothing to copy across from another app. The record holds your reasoning, which means you can show anyone who asks how you reached the rating. When the review comes round, last time’s answers are there to start from. Our AML risk assessment page has more on what the tool covers.

Questions firms asked us

People sent in questions when they registered, and more came through the chat on the day. Some are about obligations we’ve written about before, so where an earlier post covers a topic in more depth, we’ve linked to it rather than repeat it. The answers are checked against AUSTRAC’s guidance as at October 2026. They’re general information, not advice for your firm’s AML/CTF program. For a wider set, our AML questions accounting firms ask page answers over 200 questions, each linked to AUSTRAC’s guidance.

Jump to a question:

Who should do the work?

Your admin team, for most of it. We built the tool for them to run, with medium and high ratings going to a partner or your AML/CTF compliance officer, who signs off and decides whether to keep acting. Complex groups, with entities owning entities, are where someone senior usually needs to step in.

AUSTRAC requires senior manager approval for some clients: where the client, a beneficial owner or a beneficiary is a foreign PEP, or a domestic or international organisation PEP and the client is high risk. See AUSTRAC on politically exposed persons.

When do you need a risk assessment, and at what point?

When you provide a designated service. For most accounting firms the common ones are acting as a client’s registered office, setting up or restructuring a company, trust or partnership, and in some circumstances handling a client’s money as part of a transaction. Preparing a tax return isn’t a designated service on its own. Our AML scope page works through which services bring a firm in, and AUSTRAC lists them all on its professional designated services page.

Do it before you start the work. AUSTRAC expects you to establish the client’s identity and their ML/TF risk before you start providing the designated service, with limited exceptions that allow delaying parts of it under conditions. This customer risk assessment is separate from your firm’s own ML/TF risk assessment, which is part of your AML/CTF program.

“I’m doing ID checks and CDD. Is it good enough?”

An ID check covers one part of it. Initial CDD also means establishing who the beneficial owners are, whether anyone involved is a politically exposed person or sanctioned, and the nature and purpose of the relationship, on reasonable grounds and verified to a level that suits the client’s risk. If you can’t establish those matters, AUSTRAC says you must not provide the designated service. We went through each part in customer due diligence for accounting firms, and AUSTRAC sets it out in its overview of initial CDD.

“Reasonable grounds” is an objective test: would a reasonable person in your position be satisfied with what you had? The risk assessment is where you show that reasoning. A check result on its own doesn’t.

Do we need to redo our existing clients?

Mostly, no. Clients you were providing a designated service to on 1 July 2026, or had an ongoing business relationship with that involved designated services before then, are what AUSTRAC calls pre-commencement customers. You can keep acting for them without initial CDD unless a suspicious matter report obligation comes up, or there’s a significant change in the nature and purpose of the relationship that makes the client medium or high risk. Ongoing CDD still applies to them.

A client you set up a company for years ago, with no ongoing relationship since, may not count, so initial CDD would apply before any new designated service. Question 1 of the 7 AML questions every accounting firm is asking covers this in more detail, and AUSTRAC explains it in transitioning existing customers.

What about a client overseas with no Australian ID?

Australian ID isn’t required. AUSTRAC lists a passport or a foreign national identity card as acceptable government-issued photo ID, alongside a driver’s licence. Alternative identification procedures are for a different situation: someone who can’t obtain or access standard ID because of circumstances beyond their control. Living overseas isn’t one of those on its own, and your AML/CTF program needs to cover when and how you use them. See initial CDD for individuals and identifying individuals who don’t have standard ID.

In Seamlss, the ID check accepts identity documents from most countries, and you can also send a source ID request asking the client to upload documents for your team to review. The help guides show how: verifying your identity with Stripe, the source verification guide for clients and client verification step by step.

Do I need a new PEP and sanctions check for every entity?

Not necessarily. If one person sits behind three companies, a recent result can be used across all three risk assessments, as long as your AML program allows it and nothing has changed. Sanctions lists are updated often, so how recent is recent enough is a decision your program should set. In Seamlss you can choose an earlier result instead of running and paying for a new one. For what the check itself involves, see what an AML check actually looks like for an accounting firm.

A company owns 25 per cent or more, and it isn’t our client

Work through that company to the people who own or control it, and check them as individuals in your risk assessment. They don’t need to become clients of your firm: Seamlss can run an ID check on a contact on their own, without onboarding them. Our CDD guide covers beneficial ownership for companies and trusts, and AUSTRAC’s guide to determining ownership and control covers how far to go.

What if an owner refuses an ID check?

We’ve heard of a 25 per cent owner who refused outright. A background check using what you know from the ASIC extract (name and address, plus date of birth if they’re also an officeholder) can confirm some details from other sources. Whether that’s enough is a decision for your AML program and whoever signs off the client. AUSTRAC lists refusing to provide information as a risk indicator, and if you can’t establish who the beneficial owners are on reasonable grounds, you can’t provide the service. If the refusal comes with anything unusual, consider whether a suspicious matter report is needed.

Can we rely on another firm’s CDD?

In some cases, yes. If the other firm is also a reporting entity (or an equivalently regulated firm overseas), you can rely on the identity and KYC information it collected and verified. For an ongoing CDD arrangement, the arrangement must be in writing, approved by a senior manager and reassessed at least every two years. Case by case reliance is also possible. Either way, keep a record showing why relying on them was appropriate. The client’s risk rating for your service is still your firm’s call. AUSTRAC covers this in reliance on a third party.

What will we have to report to AUSTRAC, and when?

The three main reports, on different timetables:

  • An annual compliance report: reporting periods now follow the financial year. The next one runs from 1 July 2026 to 30 June 2027, and the report is due by 30 September 2027. See compliance reports.
  • Suspicious matter reports, when they arise: within 3 business days of forming a suspicion, or 24 hours if it relates to terrorism financing. Telling the client you’ve made one is tipping off, which is an offence. We covered it in Tranche 2 for accountants: what onboarding actually looks like. See also AUSTRAC on suspicious matter reports.
  • Threshold transaction reports, if you handle cash: for a designated service involving $10,000 or more in physical cash, within 10 business days. Question 6 of the 7 AML questions explains why a client’s own cash takings usually aren’t this. See AUSTRAC on threshold transaction reports.

Where do I start with the policy documents?

With AUSTRAC’s accountant program starter kit. It’s free and it’s designed for practices of 15 or fewer people that only provide professional designated services. If your firm is larger or more complex, AUSTRAC says you can’t rely on it as it stands, though you can adapt parts of it. We wrote about what’s in it when it came out: AUSTRAC accountants guide: the starter kit.

Printing a risk assessment, and contacts from XPM

  • Printing a risk assessment: once it’s completed, download it as a PDF for your file.
  • Contacts missing a date of birth or address: contacts brought in from XPM often have only a name, phone and email, and PEP and sanctions matching is more reliable with a date of birth and address. If the person is already a client, Seamlss can sync and copy their details across from their client record. If they aren’t a client, such as a shareholder of a client company, you can send them the risk assessment questionnaire to fill in their own details. Either way, clients and non-clients can both be risk assessed.

Questions from our earlier sessions

Firms have asked plenty more at our earlier AML sessions and in response to past posts. Each link goes to the answer. For the full list, with every answer checked against AUSTRAC’s guidance, see AML questions accounting firms ask.

Which services bring you in

Clients and risk

Running your AML program

Where to start

If you already subscribe to Seamlss, the risk assessment tool is in your account now. If you’re still doing assessments in Word, Excel or on paper, start with your next new designated service rather than your whole client list. When a question comes up, search AML questions accounting firms ask.

AML checks, inside onboarding rather than bolted on

Identity verification, screening and record keeping happen as the client comes on board. Try the platform free for 14 days. AML tools are available on paid plans.

Start your free trial
author avatar
Clayton Wood
Tech startup co-founder of Seamlss. Managing director of accounting and bookkeeping firm Business Edge Advisors. Owner operator of Escape Room Albury