AML/CTF compliance in Law App: Setup, Risk and Verification

Contents

    From 1 July 2026, Australian law firms have AML/CTF obligations for the first time — and Law App builds them into your normal file and contact workflow rather than a separate system. This guide walks through the whole process: flagging a matter, assessing risk at the matter level, verifying and risk-rating each client (including organisations, their beneficial owners and anyone acting on their behalf), generating the official AUSTRAC forms and reports, and keeping the audit trail the legislation requires.

    Files area

    On the matter — flag, assess and report

    On the file you mark the matter as a designated service, record the source of funds, and run the matter-level risk assessment. The file’s AML row also generates the working AML report and the official AUSTRAC forms.

    Contacts area

    On the contact — verify and rate

    Verification happens on the contact: the KYC questionnaire, entity details and beneficial owners for organisations, identity verification (VOI), the risk rating, and the periodic reviews.

    Setting up AML/CTF compliance on a matter

    AML/CTF obligations only apply to matters that involve a designated service under the AML/CTF Act, so Law App doesn’t apply the requirements to every file — only the ones you flag. You set this on a new file, or at any time on an existing file’s Details tab.

    Flagging a matter as a designated service

    1. Set Designated Service (AML/CTF) to Yes.
    2. Choose the relevant Designated Service Type.
    3. Record the Source of Funds. This is multi-select — record more than one if it applies (for example, Savings and Gift) — and choose Other to free-type anything not listed.
    Legacy matters. Matters opened before 1 July 2026 show a Legacy status and sit outside the AML requirements unless you choose to opt them in. Matters that aren’t designated services show a quiet dash in the AML column — nothing is required.
    An admin can set certain matter types to open as a designated service automatically — see Auto-Flagging Designated-Service Matter Types.

    Assessing risk at the matter level

    Alongside verifying each client, every designated-service matter carries its own AML risk assessment. Open it from the AML Risk button in the matter’s AML row (see “AML on the matter” below for where that sits).

    Matter facts and risk questions

    The assessment opens with two matter facts — does the matter involve physical cash (and the amount), and does it involve virtual assets (and the amount). These are records, not answers: if a fact is set, a prompt appears beside the related risk question, but you still have to answer the question yourself.

    AML Risk Assessment dialog showing the Matter Facts fields and the designated-service risk questions

    Below the facts sit the risk questions — a property-specific set on real-property matters (a $1.5 million-plus no-mortgage purchase, $50,000-plus in physical currency, and similar) and a general set on everything else (high-value transactions, physical cash, virtual assets, anonymity structures).

    AML Risk Assessment dialog showing a fact prompt appearing beside a risk question once a matter fact has been recorded
    Any “Yes” flags the whole file red — regardless of how compliant the clients on it are — and shows the AUSTRAC caution, which you have to acknowledge (this is audited) and record the additional steps you’ve taken.
    AUSTRAC caution acknowledgement dialog, shown when an adverse risk answer is recorded AML Risk Assessment dialog with the FLAGS THE FILE RED chip and the mandatory additional-steps box

    Final onboarding checks and sign-off

    The final onboarding checks are the AUSTRAC satisfaction list — things like whether the client’s identity has been established and whether their PEP and sanctions status has been considered. Any “No” also flags the file red. Sign-off comes last: Use my details fills in your name, role and today’s date, and you record when the designated service started.

    AML Risk Assessment dialog showing Final Onboarding Checks, Sign-off and Escalation

    Escalating a matter to the Compliance Officer

    If a file needs to go to your AML/CTF Compliance Officer, tick escalation required in the assessment. The file stays red until a written approval is recorded — the decision (approve or do not approve), who recorded it, and when, are all captured and audited. Recording the decision here is also what feeds the firm’s AML/CTF register.

    Withdrawing and re-raising an escalation voids the previous approval — the current escalation always has to be decided on its own.
    Escalation section of the AML Risk Assessment showing a written decision recorded against the matter

    Each contact’s Identity & AML tab shows an AML escalation history panel listing every escalation across their matters, with the file number — so anyone reviewing the contact can see the full picture at a glance.

    AML escalation history panel on a contact, listing every escalation across their matters

    AML on the matter — the AML row

    On a designated-service matter, the File Details toolbar carries an AML row: the file’s AML status pill, a Risk: Low/Medium/High pill summarising the matter’s clients, and three buttons — AML Risk, AML Report and AUSTRAC Form.

    File Details toolbar showing the AML status pill, Risk pill, and the AML Risk, AML Report and AUSTRAC Form buttons

    The AML report

    AML Report opens a live report over the whole matter: the designated service and its start date, matter facts, the risk answers, the final onboarding checks, the sign-off, any escalation and its decision, and then each client on the matter with their rating, VOI position, questions, people register and representatives. It’s generated fresh from current data every time you open it — a working report, not a signed record. Print or download it from the toolbar.

    The AML report for a matter, showing the designated service, risk assessment, sign-off and each client's AML position
    For a signed, point-in-time record of an individual client’s own assessment, use the KYC Assessment Record on their contact instead — see further down this guide.

    Generating the official AUSTRAC form

    AUSTRAC Form generates the official AUSTRAC customer due diligence form for the matter, for the situations described in “When the official AUSTRAC forms apply” at the end of this guide. The dialog lists the starter-kit forms from Law App’s global template library — the conveyancers kit first on real-property matters, the legal profession kit first on everything else — with chips to jump to the variant you need (individual or sole trader, trust, body corporate/partnership/association, government body), plus the escalation and unusual activity report forms.

    Generate the official AUSTRAC form dialog, showing the entity-type chips and starter-kit forms

    Pick a form, choose the folder it should file into, and it’s created in the matter’s Documents with the file code and client name filled in — complete the rest in Word. These are AUSTRAC’s own documents, so they aren’t editable as firm templates.

    Verifying identity and assessing client risk — the Identity & AML tab

    Identity verification and risk-rating happen on the contact, not the file. Open the client in the Contacts area and go to their Identity & AML tab — this is where you complete and track everything the legislation requires for that person or organisation.

    You can’t complete AML functions on a joint card. Each person or entity on the matter needs their own individual contact card.

    Completing the KYC questionnaire

    The questionnaire matches AUSTRAC’s official customer due diligence forms word-for-word, and adjusts depending on whether the contact is an individual or an organisation. Individuals answer 12 questions, covering PEP status (two separate Yes/No questions — domestic or international-organisation PEP, and foreign PEP), financial sanctions, criminal or unusual activity, third-party representatives, medium and high-risk countries, charities and NPOs, unexplained wealth, and remote-only contact channels. Organisations answer 13 questions, including the same two PEP questions extended to cover any related party, beneficial owner or CEO.

    Individual KYC question set on a contact's Identity and AML tab Organisation KYC question set on a contact's Identity and AML tab, including beneficial owner and CEO PEP questions
    PEP Details appears automatically when either PEP question is answered Yes — record the role or connection there.

    Once the questionnaire is answered, Law App calculates the risk rating for you — you don’t score it manually.

    Sole traders

    The individual question set includes a gate question: is this person a sole trader? It has to be answered before the review clock starts, just like the other questions. Answer Yes and a Sole trader card appears with two groups — Business profile (business name, address, activity, GST registration and the business’s source of funds — the ABN itself stays on the contact’s Details tab) and Firm verification (which documents you used to verify the business, the unique identifier you relied on, whether the documents matched onboarding, and any concerns). The official AUSTRAC form for a sole trader is the same as for an individual.

    Sole trader card with business profile and firm verification

    How the risk rating is worked out

    The rating is weighted, not just counted — each question carries a weight, exactly as AUSTRAC’s forms prescribe:

    • High — a Yes to any single high-weight question (for example, foreign PEP, sanctions, a high-risk country, unexplained wealth, or remote-only contact channels).
    • Medium — a Yes to two or more medium-weight questions (for example, domestic PEP, a third-party representative, a medium-risk country, or an NPO).
    • Low — anything less.

    The rating appears after you Save. The review clock only starts once every question has been answered — a partly-answered questionnaire will show a rating, but won’t schedule the periodic review. Until the questionnaire is completed, the contact shows as Not assessed.

    For organisations, PEP status set on a person in the beneficial owner register (see below) feeds this rating too: a foreign PEP anywhere in the register makes the client High risk on its own, and a domestic PEP counts as one medium-weight factor — exactly as if the organisation’s own PEP question had been answered Yes. The risk banner names the person and factor, so it’s clear why the rating moved.
    If your professional judgement differs from the calculated rating, you can override it. A reason is mandatory and is recorded against the contact for your audit trail — though overriding the rating doesn’t mark the contact as AML-compliant; identity verification and review requirements still apply.

    Periodic review dates

    Law App schedules the next review date automatically, based on the risk rating: low risk reviews every 3 years, medium risk every 2 years, and high risk every year.

    Verifying identity (VOI)

    The Identity & AML tab is also where you manage identity verification — documents captured in person, and electronic VOI checks run through InfoTrack. Having the documents on file isn’t enough by itself: a person must confirm the VOI before it counts.

    The VOI panel shows a live identity points total (passport 70, licence 40, Medicare 25, an InfoTrack VOI Report 100, and so on) summed across unexpired documents. The 100-point standard is a guide — if the total is below 100 you’ll see a warning, but you can still accept if you’re satisfied by other means. That call is yours, and it’s audited.

    VOI Acceptance panel showing the identity points total and a below-100-points warning, before acceptance

    Press Confirm VOI meets AML requirements — the panel turns green and records who accepted it, when, and at how many points.

    VOI Acceptance panel in its accepted, green state, showing who accepted it, when and at how many points
    Hard rule: you can’t accept while every identity document is expired, or none has an expiry date recorded. The button disables until you correct an expiry date or add a current document. Points below 100 never block acceptance — expired documents always do.

    Expiry lapses the acceptance. When the documents an acceptance covered have all expired, the panel turns amber (“no longer effective”) and the contact goes red until someone re-confirms against current documents. A document uploaded later never revives an old acceptance — re-confirming is always a deliberate step.

    Lapsed VOI acceptance panel in its amber state, after the identity documents it covered expired
    Existing compliant contacts were grandfathered when this was introduced: anyone who already had a valid, unexpired identity document received an automatic system acceptance labelled “(grandfathered at the v3 upgrade)”. Nobody was flipped to red by the change itself.

    Requesting an InfoTrack VOI

    1. On the contact, click Request InfoTrack VOI, then select the matter to link the verification to.
    2. Navigate to All Services > People > AML Onboarding (incl. VOI).
    3. For an individual, InfoTrack pre-fills the client’s name, email, phone and address. For an organisation or trust, first complete your ASIC search and/or review the trust documents to establish the Ultimate Beneficial Owner, then select +Add new client, choose the organisation type, and complete the party details.
    4. The client completes the VOI. Once you’ve reviewed and finalised it, the finished report flows back into Law App and attaches to the contact automatically.
    5. If it can’t be matched automatically, the report appears on the matter’s InfoTrack list — use Assign to contact to attach it.
    One VOI covers one person. The order opens pre-filled with the current contact’s details, so finish that contact’s VOI first, then come back and start the next one.

    When a VOI is returned, record the expiry date on the document record — a VOI only counts toward compliance while it hasn’t expired. For now this is entered manually; InfoTrack is working on sending the expiry date automatically.

    Setting up an organisation — the entity identity card

    An organisation’s Identity & AML tab starts with an Entity identity card. Pick the entity type first — Australian company, Trust, Partnership, Foreign company, Government body, or Other/association — and the card then shows only the identity details AUSTRAC asks for that structure, in three tinted groups: Registration (registered office, ASIC registration, listing details; trust type and beneficiary class for a trust; overseas registration number for a foreign company; jurisdiction for a government body), Beneficial owner exemption (AUSTRAC C1) (see below), and Governing documents and evidence (the constitution, trust deed or partnership agreement, or evidence of existence for a government body).

    Entity identity card for an Australian company, showing Registration, Beneficial owner exemption and Governing documents groups Entity identity card and register for a discretionary family trust, showing trustee, beneficiaries, settlor and appointor

    The entity type also drives which people you record in the register below it (directors for a company, trustee and beneficiaries for a trust, partners for a partnership, and so on) and which official AUSTRAC form applies if the client ends up above low risk. Foreign companies show an extra reminder to consider the medium- and high-risk country questions — the reminder doesn’t answer them for you.

    Changing the entity type after people have been recorded warns you first: people whose role still makes sense for the new type are kept, everyone else is removed when you confirm. Nothing is deleted until you press Save.
    Organisations assessed before this feature existed show a blue note at the top of the tab saying they’re due at their next scheduled review, and that the current AML status stands until then — nothing turns red because of the upgrade. You can set the entity type and fill in the people register earlier if you like; the note disappears as soon as an entity type is saved.
    Blue note on an organisation assessed before the entity-type release, showing the due date of their next review

    Beneficial owner exemption (AUSTRAC C1)

    Some clients don’t need a beneficial-owner register. In the Beneficial owner exemption group on the entity card, record that the client is, or is controlled by, a government body or a publicly listed company — the register is switched off outright, and the card says the beneficial-owner register isn’t required. For a regulated entity (for example an AFS licensee) or a strata/body corporate, the register is switched off only while the client stays Low risk with no open escalation — if the rating rises or the matter is escalated, the exemption stops applying and the register becomes required again. Always record the details that support the exemption (the exchange and ticker, the licence, the government act) — they print on the KYC Assessment Record.

    Publicly listed company with the C1 exemption applied, switching off the beneficial owner register

    Recording the people behind the entity

    Under the entity card sits the people register, whose heading changes with the entity type: Directors and beneficial owners (company), Trustee, beneficiaries, settlor and appointor (trust), Partners (partnership), Office holders and controllers (association), Authorised representative (government body).

    • When the register is empty, the usual roles are pre-seeded as blank rows (for example two directors and a beneficial owner for a company) — fill them in, add more, or remove the ones you don’t need.
    • Each row records the person’s full name, other names, date of birth, residential address, country, occupation, ownership percentage, how they control the entity, and which documents you verified them against.
    • 25% or more ownership or control marks the person as a beneficial owner automatically (a “BO” chip appears) whatever their title. If nobody reaches 25%, record the CEO or senior officer instead.
    • Tick Verified once you hold identity evidence for the person — unverified rows show as such on the record.
    • A row can be linked to an existing contact, so their own card holds their identity documents and PEP details rather than duplicating them.
    Directors and beneficial owners register showing a domestic PEP and automatic BO chips Edit party dialog for recording a person in the beneficial owner register Partners register showing a foreign PEP pushing the client to High risk
    Save writes the register immediately from the edit dialog; removing a row asks you to confirm. A row you’ve added but not yet saved carries an “Unsaved — press Save” chip.

    Representatives and authority to act

    Where someone deals with you on the client’s behalf — an attorney under a power of attorney, an agent, an officer of a company client, a family member with written authority — record them in the Representatives and authority to act register, which appears on both individual and organisation cards.

    • A representative is always an existing contact — search and pick them. Their identity documents and PEP questions live on their own card; the register holds only the facts about their authority.
    • Record their capacity, whether they’re AUSTRAC-enrolled, the type of authority (power of attorney, agency agreement, written authorisation, office held, other), the details and any unique identifier (for example a Titles Registry dealing number), and optionally which identity document on the client’s card evidences it.
    • Tick Satisfied the person has authority to act once you are. If you can’t establish authority, or you have concerns about the onboarding information, the row is flagged and you should complete the official AUSTRAC form for that representative.
    • A representative can be tied to a particular matter — the matter opens in a new tab from the row.
    Representatives and authority to act on an individual client Recording a representative's authority
    Answering Yes to “a third party is acting” in the client’s own KYC questions is still the risk factor — this register is where you record who that is and why they may act.

    The KYC Assessment Record

    Every time a client’s assessment is completed, a review confirmed, or a rating override set or cleared, Law App takes a point-in-time snapshot: the answers and their weights, the suggested and effective rating, the register and representatives as they stood, and the VOI position — documents, points, acceptance.

    KYC Assessment Record panel on the Identity and AML tab

    The KYC Assessment Record panel opens a printable record built from the latest snapshot — older snapshots are listed so you can print an earlier one. It carries a signature block for the person who assessed the client. Use the toolbar to print or download it.

    A printed KYC Assessment Record, showing the risk rating, risk factors, client details, representatives and VOI position at the time of assessment
    This is an internal compliance record. It’s never client-facing, and it doesn’t replace the official AUSTRAC forms where those apply — see “When the official AUSTRAC forms apply” below.

    Running your AML searches from Law App

    Run your identity, ASIC and other searches from inside Law App rather than going direct to InfoTrack. For AML you’ll use InfoTrack for identity verification and to complete ASIC or other company and person searches — you don’t need to go beyond that for AML purposes.

    Search from the file, or the cost is lost. Law App only records the disbursement and imports the transaction when the search is run from Law App. If you run searches outside Law App, we have no visibility of them — the cost isn’t captured and won’t reach the file or your accounting.

    Everything is logged. Every change to a contact’s Identity & AML tab — KYC answers, risk-rating changes, VOI records and acceptances — is recorded with who made it and when, giving you a clean audit trail for regulators.

    Understanding AML status

    Every contact and matter shows a live AML status:

    StatusMeaning
    AML: OKAn accepted VOI with a valid document, a completed KYC assessment, and the next review date set and still in the future.
    AML: ReviewThe contact is compliant, but a review is due within 30 days, or a VOI document is expiring within 30 days. The alert tells you which one it is.
    AML: RequiredOne or more conditions is missing: no accepted VOI, KYC not completed, or the review date is overdue or not set.
    Not assessedThe KYC questionnaire hasn’t been answered yet.
    Pre-commencementFlagged as an existing client — compliant without fresh VOI/KYC on matter types the firm already handled for them before 1 July 2026.

    A new or partly set-up contact shows Required until all steps are done — that’s expected, not a problem. A matter’s status rolls up from its clients: if any client on the matter is Required, the matter is Required. It only turns OK once every client is compliant.

    Admin override

    Sometimes a client can’t complete the standard ID or KYC process. Where that happens, and depending on your firm’s policies, an admin can mark them as AML-satisfied directly from the matter’s AML alert — a reason is mandatory and is recorded at the time of the override. The matter shows an orange AML: Overridden status, so anyone on the file can see what’s happened at a glance, and the override record shows who made it, when, and why.

    The override dialog pre-selects every non-compliant client on the matter — untick anyone you don’t mean to include. Clearing the override reinstates the standard checks.

    Override AML Compliance dialog, pre-selecting the non-compliant clients on the matter

    Pre-commencement clients

    Admin-level users can flag a long-standing client as a pre-commencement client on their Identity & AML page. Flagged clients don’t need new identity verification on matters of a kind the firm already handled for them before 1 July 2026 — those matters show a blue Pre-commencement status. A new kind of matter for them still needs full verification as normal.

    Where AML status appears in Law App

    You’ll see AML status in several places, so it stays in front of the people who need to act on it:

    • File list — an AML status column shows at a glance which matters need attention. Non-AML matters show a quiet dash.
    • Clients grid on a matter — per-client AML status, with non-compliant rows flagged.
    • Contact list — a risk-rating column across all your contacts.
    • Identity & AML tab — the full detail view: the status pill, an alert banner when action is needed, and a complete history of changes.
    • File Details toolbar — the AML row’s status and risk pills, on any designated-service matter.

    AML questions on Client Intake forms

    Firms using Client Intake can add Identity & AML questions to an intake form: the client’s country of residence, occupation, source of wealth, whether they’re a sole trader and their business profile, the entity type and details for an organisation, and rows for the people behind the entity and any representative.

    When you accept a submission, the declarations are written to a new contact’s Identity & AML card as a starting point, and any representatives the client named are created as contacts and linked in the register. If the submission is matched to an existing contact, only blank fields are filled and the registers are only seeded when they’re empty — nothing you’ve already recorded is overwritten. Anything that didn’t apply is kept in the AML notes so it isn’t lost.

    The submission review page shows an “Identity & AML (client declarations)” line summarising how many fields, people and representatives the client supplied. The declarations are the client’s own statements — you still answer the risk questions, verify identity and set PEP status yourself.

    When the official AUSTRAC forms apply

    Law App handles standard, low-risk clients end-to-end, including their people registers and representatives. The “When the official AUSTRAC forms apply” panel at the foot of every Identity & AML tab sets out when to go further:

    • Complete the official Initial CDD form for the client type (use the AUSTRAC Form button on the matter) when the client rates medium or high, has an unusually complex ownership structure, can’t provide photo identification or there are issues with the documents, a representative’s identity or authority can’t be verified, initial due diligence is being delayed, or the client has been referred to the Compliance Officer.
    • Escalate with the Escalation form where your program requires it, and record the outcome on the matter so it appears in the AML/CTF register.

    Updated on 23 September 2026

    Leave a Reply

    Your email address will not be published. Required fields are marked *