Digital AML onboarding: six steps, one decision

Digital AML onboarding: six steps, one decision

Digital AML onboarding in six steps: collect, verify, screen, assess, decide and record. What to automate, who decides, and when verification can wait.

AML/CTF Compliance 7 October 2026 12 min read AML Guard

Compliance officers reviewing an AML onboarding decision

Digital client onboarding that integrates AML compliance follows a fixed sequence: collect, verify, screen, assess, decide, record. Initial customer due diligence (CDD) has to be complete before a designated service starts, apart from limited cases where part of it can be delayed. Technology handles the lookups and the paperwork; the decision to proceed, hold or decline is best left with a person, usually a compliance officer.


TL;DR:


AML Guard
Make AML Onboarding Easier to Manage
AML Guard brings customer due diligence, officer decisions, reporting workflows and audit records into one Australian compliance platform.
Book a demo

Table of Contents

The onboarding sequence: collect, verify, screen, assess, decide, record

Every digital AML onboarding process reduces to six steps, and understanding which ones a system can handle alone, and which ones need a person, determines whether the process actually holds up under scrutiny.

  1. Collect: capture identity details, beneficial ownership information and the purpose of the relationship through a structured intake form.
  2. Verify: confirm the customer is who they claim to be, using documents, government-source checks and biometric liveness.
  3. Screen: run sanctions, politically exposed person (PEP) and adverse media checks against current lists.
  4. Assess: combine the verification and screening results into a documented money laundering and terrorism financing (ML/TF) risk rating.
  5. Decide: have a compliance officer approve, hold or decline the relationship based on that rating.
  6. Record: keep an evidence trail of every input, check result and decision for the retention period the law requires.

Collect is where structured digital intake earns its keep. A well-designed portal captures name, date of birth, address, source of funds and beneficial ownership fields in one pass, using secure upload rather than email attachments. Our client intake portal is built around this exact step, reducing the back-and-forth that paper-based intake creates.

Verify is where AUSTRAC’s own framing matters most. Its overview of customer due diligence says initial CDD must be complete before the designated service starts: identifying the customer and other specified persons, such as beneficial owners, and identifying the customer’s ML/TF risk, generally by collecting and verifying know your customer (KYC) information. Verification itself can run through document checks against government-source data, with biometric liveness added as a control against impersonation and synthetic identity fraud rather than as a separate legal test. This distinction is covered in more depth in the piece on non-face-to-face verification.

Screen runs in parallel with verification wherever possible. Sanctions, PEP and adverse media checks draw on current list data, and the cadence matters: a one-off check at onboarding catches today’s status, but ongoing re-screening catches a customer who becomes sanctioned or politically exposed six months later.

Assess is where the system stops being a checklist and starts being a risk engine. The outputs from verification and screening feed into a risk rating, and the reasoning behind that rating, not just the score itself, is what a reviewer will need to see later.

Decide is the gate. Lower-risk profiles that clear verification and screening cleanly can move to an officer for a quick approval; higher-risk profiles, inconsistent documents or screening hits should route automatically to a hold queue pending closer review. A system can recommend a decision. It cannot make one.

Record closes the loop. The audit trail needs to show what was collected, what was verified, what was screened, how the risk rating was reached and who approved the outcome, retained for the period the Act requires.

How it works: integrations, API patterns and operational controls

A digital onboarding system is only as good as the parts that connect it, and those connections determine both how fast a customer moves through the sequence and how defensible the resulting record is.

On the API side, synchronous checks suit document verification and liveness, where the customer is waiting on screen for a result. Screening and beneficial ownership checks are better handled asynchronously, since sanctions list matches and company register lookups can take longer and often need a human look before they resolve. A system that forces every check into a single synchronous call tends to either time out or return false negatives under load.

Partial verification is the trickiest UX problem. A customer who passes document checks but fails liveness, or clears screening but has an unresolved beneficial ownership question, needs a status that reflects “in progress” honestly rather than a binary pass or fail. Progressive disclosure, asking for only what each step needs, when it needs it, keeps abandonment down while still preserving a complete evidence trail behind the scenes.

Partial verification paths joining an evidence trail

Pro Tip: Push only status flags to a CRM, never raw CDD data: it keeps sales and operations teams informed without expanding who can see sensitive identity information.

Approaches to secure capture and storage are detailed further in the guide to secure client intake, covering encryption and access-control practices relevant to this layer.

Risk-based onboarding and when verification can lawfully wait

A flat rule of “complete everything before any service” misreads the framework, but so does treating delay as routine. Initial CDD, meaning identifying the customer and other specified persons and identifying the customer’s ML/TF risk, must be complete before a designated service starts. Under section 29 of the AML/CTF Act and the AML/CTF Rules 2025, parts of it can wait only where, before starting, the firm determines on reasonable grounds that delay is essential to avoid interrupting the ordinary course of business and that the added ML/TF risk is low. Inconvenience to the firm or the customer is not enough.

Deferral is not a shortcut. Before delaying any check, the firm assesses whether the relationship genuinely presents low ML/TF risk, based on information already on hand, such as the nature of the designated service, the customer type and any early screening results. The determination has to be made before the service starts, and AUSTRAC expects the firm to be able to show how it reached it, so record the assessment at the time rather than reconstructing it later.

Where deferral applies, controls carry the risk in the meantime:

The Rules set the outer limits, and completion must still come as soon as reasonably practicable: 20 business days in the general case (Rules section 6-12) and, in real estate, the earlier of 28 days after exchange or 3 days before the initially agreed settlement day for the party the agent is not acting for (section 6-32). What can wait also varies: in the general case the customer’s own identity is still established first, and it is verifying other KYC information, such as beneficial owners and PEP and sanctions status, that can follow. Delay is not a general licence to onboard first and verify later. Relying on KYC information another reporting entity has collected and verified is a separate arrangement with its own conditions, covered in our guide to CDD reliance.

Ongoing monitoring and enhanced due diligence in a digital system

Onboarding does not end when the customer is approved. Ongoing customer due diligence requires monitoring transactions and behaviour for anything unusual, re-verifying identity information where circumstances change, and keeping records that show how that monitoring was actually done.

Enhanced CDD applies when the customer’s ML/TF risk is high and in the other circumstances section 32 of the Act sets out, such as a foreign PEP; a domestic or international organisation PEP calls for it only where the risk is high. A PEP match, an adverse media hit, a complex ownership structure or a transaction pattern that does not fit the customer’s stated profile is the kind of fact that should prompt that review. Enhanced measures can include:

AML/CTF programs must set out how ongoing CDD and monitoring will work, including policies for flagging unusual transactions and updating customer information over time. That requirement is what should drive how monitoring rules get built, not the other way around.

Automated alerts work well for pattern detection, flagging a transaction that breaks from a customer’s usual behaviour or a re-screening hit that did not exist at onboarding. What they should never do is auto-close the alert. Every enhanced CDD trigger needs to land in an officer’s queue, with the measures applied and the reasoning for the final decision recorded alongside it. Due diligence guidance covers the practical mechanics of setting ongoing and enhanced CDD policies within a Tranche 2 program, available at customer due diligence.

Governance, officer approval and record keeping done properly

Digital onboarding tools can automate a great deal: document checks, list screening, data capture, risk scoring calculations. What they cannot do is make the judgement call on behalf of a reporting entity, and the record should show who made it.

Pro Tip: Record the officer’s sign-off next to the decision, not just the system’s output: the file should show who decided, and on what basis.

For firms weighing company structures against trusts and SMSFs, our beneficial ownership guide sets out the correct approach for each entity type in detail.

A practical roadmap for building the process

Rolling out a compliant digital onboarding workflow is a sequence in itself, and skipping steps tends to show up later as gaps in the audit trail.

  1. Confirm enrolment on the Reporting Entities Roll and map which teams touch onboarding.
  2. Update the AML/CTF program to reflect the six-step sequence and where officer approval sits.
  3. Choose identity, screening and storage vendors, and set risk thresholds for auto-progress versus hold.
  4. Build integrations, test partial-verification handling, and confirm status flags reach the CRM without exposing CDD data.
  5. Train staff on the new workflow, set monitoring rules, and schedule regular program reviews.
Phase Core action Owner
Pre-implementation Confirm enrolment and update the program Compliance officer
Design Set risk thresholds and officer gating points Compliance officer and systems lead
Build Connect vendors, test flows, secure storage Systems lead
Launch Train staff, set monitoring rules, schedule reviews Compliance officer

Automation speeds onboarding, judgement still decides it

The honest view is that digital onboarding is at its best when it removes the repetitive parts of CDD, document checks, list screening, data entry, so an officer can spend their attention on the decisions that actually need it. Treating liveness as a legal mandate rather than a fraud control, misreads what the Act asks for, and treating a clean system output as the decision leaves no one accountable for it. A person should decide, and the record should show who. Seeing the full sequence in practice is easier with a working demo than with a description of one.

Where AML Guard fits into the onboarding sequence

AML Guard is built around the sequence described above rather than a generic KYC checklist: client intake, document capture, government-source checks and biometric liveness sit in one record, with an officer reviewing the outcome.

AML Guard runs on a subscription, month to month or on a 12-month term. A transaction party can pay for their own check, and each eligible CDD check fee earns a credit against that calendar month’s subscription, capped at the subscription fee. AML Guard is not self-service: firms start with a demo, then set up their services and risk profile. Full detail on plans and features is available, along with pricing for firms ready to compare options.

FAQ

What is client onboarding in AML KYC?

Client onboarding in an AML and KYC context is the process of identifying a customer, verifying that identity, screening for sanctions and adverse media exposure, and assessing risk before a designated service begins. It follows the sequence of collect, verify, screen, assess, decide and record, with initial CDD generally required before service starts.

What are the four Cs of successful onboarding?

There’s no single official “four Cs” framework recognised in AUSTRAC guidance, and definitions vary depending on the source. A practical reading for AML onboarding emphasises collecting accurate data, confirming identity, checking risk exposure and capturing a complete record, which maps closely to the collect, verify, screen and record steps of the standard sequence.

How many processes does AML client onboarding consist of?

AML client onboarding runs through six core steps: collect, verify, screen, assess, decide and record. Each step has its own data requirements and controls, and together they form the evidence trail a compliance officer relies on to approve or hold a relationship.

What is digital onboarding?

Digital onboarding is the process of capturing, verifying and assessing a customer’s identity and risk profile through online tools rather than in-person paperwork. In an AML context, a person still makes the final decision; the technology handles document checks, screening and data capture, not the final decision.

Yes, remote verification is a controls question rather than a prohibition. The Act requires confirming the customer is who they claim to be, and biometric liveness checks serve as a fraud-prevention control supporting that requirement rather than a separate legal mandate.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 7 October 2026.