
Digital client onboarding that integrates AML compliance follows a fixed sequence: collect, verify, screen, assess, decide, record. Initial customer due diligence (CDD) has to be complete before a designated service starts, apart from limited cases where part of it can be delayed. Technology handles the lookups and the paperwork; the decision to proceed, hold or decline is best left with a person, usually a compliance officer.
TL;DR:
- Verification and screening can be automated; the decision to proceed, hold or decline should rest with a person, and the record should show who made it.
- Parts of initial CDD can wait only where delay is essential to avoid interrupting the ordinary course of business and the added risk is low, and only within the timeframes in the AML/CTF Rules.
- Vendor APIs for document checks, sanctions screening and storage need careful integration if onboarding is to be quick, secure and accurate.
- The Act’s record-keeping minimum is seven years; AML Guard keeps every step, decision and piece of evidence for 8 years.
- Ongoing CDD continues after onboarding, and enhanced CDD applies when risk is high or another section 32 trigger applies, with each case reviewed and recorded.
Table of Contents
- The onboarding sequence: collect, verify, screen, assess, decide, record
- How it works: integrations, API patterns and operational controls
- Risk-based onboarding and when verification can lawfully wait
- Ongoing monitoring and enhanced due diligence in a digital system
- Governance, officer approval and record keeping done properly
- A practical roadmap for building the process
- Automation speeds onboarding, judgement still decides it
- Where AML Guard fits into the onboarding sequence
- FAQ
- Sources
The onboarding sequence: collect, verify, screen, assess, decide, record
Every digital AML onboarding process reduces to six steps, and understanding which ones a system can handle alone, and which ones need a person, determines whether the process actually holds up under scrutiny.
- Collect: capture identity details, beneficial ownership information and the purpose of the relationship through a structured intake form.
- Verify: confirm the customer is who they claim to be, using documents, government-source checks and biometric liveness.
- Screen: run sanctions, politically exposed person (PEP) and adverse media checks against current lists.
- Assess: combine the verification and screening results into a documented money laundering and terrorism financing (ML/TF) risk rating.
- Decide: have a compliance officer approve, hold or decline the relationship based on that rating.
- Record: keep an evidence trail of every input, check result and decision for the retention period the law requires.
Collect is where structured digital intake earns its keep. A well-designed portal captures name, date of birth, address, source of funds and beneficial ownership fields in one pass, using secure upload rather than email attachments. Our client intake portal is built around this exact step, reducing the back-and-forth that paper-based intake creates.
Verify is where AUSTRAC’s own framing matters most. Its overview of customer due diligence says initial CDD must be complete before the designated service starts: identifying the customer and other specified persons, such as beneficial owners, and identifying the customer’s ML/TF risk, generally by collecting and verifying know your customer (KYC) information. Verification itself can run through document checks against government-source data, with biometric liveness added as a control against impersonation and synthetic identity fraud rather than as a separate legal test. This distinction is covered in more depth in the piece on non-face-to-face verification.
Screen runs in parallel with verification wherever possible. Sanctions, PEP and adverse media checks draw on current list data, and the cadence matters: a one-off check at onboarding catches today’s status, but ongoing re-screening catches a customer who becomes sanctioned or politically exposed six months later.
Assess is where the system stops being a checklist and starts being a risk engine. The outputs from verification and screening feed into a risk rating, and the reasoning behind that rating, not just the score itself, is what a reviewer will need to see later.
Decide is the gate. Lower-risk profiles that clear verification and screening cleanly can move to an officer for a quick approval; higher-risk profiles, inconsistent documents or screening hits should route automatically to a hold queue pending closer review. A system can recommend a decision. It cannot make one.
Record closes the loop. The audit trail needs to show what was collected, what was verified, what was screened, how the risk rating was reached and who approved the outcome, retained for the period the Act requires.
How it works: integrations, API patterns and operational controls
A digital onboarding system is only as good as the parts that connect it, and those connections determine both how fast a customer moves through the sequence and how defensible the resulting record is.
- Identity vendors supply document verification and liveness checks through an API, typically returning a match confidence score and a document authenticity result.
- Sanctions, PEP and adverse media providers return screening hits against current list data, which then need officer triage rather than automatic rejection.
- CRM integrations push compliance status indicators, such as “cleared”, “pending” or “on hold”, without transferring the underlying CDD data itself.
- Secure storage holds documents and check results with encryption at rest and in transit, and access limited to staff who need it for their role.
On the API side, synchronous checks suit document verification and liveness, where the customer is waiting on screen for a result. Screening and beneficial ownership checks are better handled asynchronously, since sanctions list matches and company register lookups can take longer and often need a human look before they resolve. A system that forces every check into a single synchronous call tends to either time out or return false negatives under load.
Partial verification is the trickiest UX problem. A customer who passes document checks but fails liveness, or clears screening but has an unresolved beneficial ownership question, needs a status that reflects “in progress” honestly rather than a binary pass or fail. Progressive disclosure, asking for only what each step needs, when it needs it, keeps abandonment down while still preserving a complete evidence trail behind the scenes.

Pro Tip: Push only status flags to a CRM, never raw CDD data: it keeps sales and operations teams informed without expanding who can see sensitive identity information.
Approaches to secure capture and storage are detailed further in the guide to secure client intake, covering encryption and access-control practices relevant to this layer.
Risk-based onboarding and when verification can lawfully wait
A flat rule of “complete everything before any service” misreads the framework, but so does treating delay as routine. Initial CDD, meaning identifying the customer and other specified persons and identifying the customer’s ML/TF risk, must be complete before a designated service starts. Under section 29 of the AML/CTF Act and the AML/CTF Rules 2025, parts of it can wait only where, before starting, the firm determines on reasonable grounds that delay is essential to avoid interrupting the ordinary course of business and that the added ML/TF risk is low. Inconvenience to the firm or the customer is not enough.
Deferral is not a shortcut. Before delaying any check, the firm assesses whether the relationship genuinely presents low ML/TF risk, based on information already on hand, such as the nature of the designated service, the customer type and any early screening results. The determination has to be made before the service starts, and AUSTRAC expects the firm to be able to show how it reached it, so record the assessment at the time rather than reconstructing it later.
Where deferral applies, controls carry the risk in the meantime:
- Cap transaction value or volume until verification completes.
- Apply negative-list and sanctions screening immediately, even if full identity verification is pending.
- Hold any transfer or release of money or property for the customer until initial CDD is complete, as the Rules require in the general case.
- Record exactly which exception applied, what information supported the low-risk assessment and when full verification was completed.
The Rules set the outer limits, and completion must still come as soon as reasonably practicable: 20 business days in the general case (Rules section 6-12) and, in real estate, the earlier of 28 days after exchange or 3 days before the initially agreed settlement day for the party the agent is not acting for (section 6-32). What can wait also varies: in the general case the customer’s own identity is still established first, and it is verifying other KYC information, such as beneficial owners and PEP and sanctions status, that can follow. Delay is not a general licence to onboard first and verify later. Relying on KYC information another reporting entity has collected and verified is a separate arrangement with its own conditions, covered in our guide to CDD reliance.
Ongoing monitoring and enhanced due diligence in a digital system
Onboarding does not end when the customer is approved. Ongoing customer due diligence requires monitoring transactions and behaviour for anything unusual, re-verifying identity information where circumstances change, and keeping records that show how that monitoring was actually done.
Enhanced CDD applies when the customer’s ML/TF risk is high and in the other circumstances section 32 of the Act sets out, such as a foreign PEP; a domestic or international organisation PEP calls for it only where the risk is high. A PEP match, an adverse media hit, a complex ownership structure or a transaction pattern that does not fit the customer’s stated profile is the kind of fact that should prompt that review. Enhanced measures can include:
- Source of funds and source of wealth documentation, requested specifically rather than generically.
- Closer examination of beneficial ownership layers, particularly for trusts or multi-entity structures.
- More frequent review cycles than the standard schedule.
- Senior manager approval before providing the service or continuing the relationship, which is required for a foreign PEP and for a domestic or international organisation PEP where the risk is high.
AML/CTF programs must set out how ongoing CDD and monitoring will work, including policies for flagging unusual transactions and updating customer information over time. That requirement is what should drive how monitoring rules get built, not the other way around.
Automated alerts work well for pattern detection, flagging a transaction that breaks from a customer’s usual behaviour or a re-screening hit that did not exist at onboarding. What they should never do is auto-close the alert. Every enhanced CDD trigger needs to land in an officer’s queue, with the measures applied and the reasoning for the final decision recorded alongside it. Due diligence guidance covers the practical mechanics of setting ongoing and enhanced CDD policies within a Tranche 2 program, available at customer due diligence.
Governance, officer approval and record keeping done properly
Digital onboarding tools can automate a great deal: document checks, list screening, data capture, risk scoring calculations. What they cannot do is make the judgement call on behalf of a reporting entity, and the record should show who made it.
- CDD determinations route to a compliance officer for approval before the relationship proceeds, with the system’s role limited to running lookups and assembling the record.
- The business-wide ML/TF risk assessment, the AML/CTF policies, the compliance action plan and the staff training manual work as one linked set, so that a policy statement matches the risk it was written against and the training reflects the policy actually in use.
- Beneficial ownership checks differ by structure: a company resolves through its ACN, while a trust or SMSF is reached through its corporate trustee, which runs its own ACN-based determination; deed-level detail still needs officer review.
- The Act’s record-keeping periods run for seven years, from different starting points for different records; AML Guard’s audit trail and document vault hold records for 8 years, above the Act’s seven-year minimum.
Pro Tip: Record the officer’s sign-off next to the decision, not just the system’s output: the file should show who decided, and on what basis.
For firms weighing company structures against trusts and SMSFs, our beneficial ownership guide sets out the correct approach for each entity type in detail.
A practical roadmap for building the process
Rolling out a compliant digital onboarding workflow is a sequence in itself, and skipping steps tends to show up later as gaps in the audit trail.
- Confirm enrolment on the Reporting Entities Roll and map which teams touch onboarding.
- Update the AML/CTF program to reflect the six-step sequence and where officer approval sits.
- Choose identity, screening and storage vendors, and set risk thresholds for auto-progress versus hold.
- Build integrations, test partial-verification handling, and confirm status flags reach the CRM without exposing CDD data.
- Train staff on the new workflow, set monitoring rules, and schedule regular program reviews.
| Phase | Core action | Owner |
|---|---|---|
| Pre-implementation | Confirm enrolment and update the program | Compliance officer |
| Design | Set risk thresholds and officer gating points | Compliance officer and systems lead |
| Build | Connect vendors, test flows, secure storage | Systems lead |
| Launch | Train staff, set monitoring rules, schedule reviews | Compliance officer |
Automation speeds onboarding, judgement still decides it
The honest view is that digital onboarding is at its best when it removes the repetitive parts of CDD, document checks, list screening, data entry, so an officer can spend their attention on the decisions that actually need it. Treating liveness as a legal mandate rather than a fraud control, misreads what the Act asks for, and treating a clean system output as the decision leaves no one accountable for it. A person should decide, and the record should show who. Seeing the full sequence in practice is easier with a working demo than with a description of one.
Where AML Guard fits into the onboarding sequence
AML Guard is built around the sequence described above rather than a generic KYC checklist: client intake, document capture, government-source checks and biometric liveness sit in one record, with an officer reviewing the outcome.
- Structured intake forms that capture identity, ownership and risk information in one pass.
- Document verification, government-source checks and biometric liveness combined into a single evidence record.
- Beneficial ownership checks by ACN for companies, with corporate trustee determination for trusts and SMSFs.
- An audit trail retained for 8 years, above the Act’s seven-year minimum.
AML Guard runs on a subscription, month to month or on a 12-month term. A transaction party can pay for their own check, and each eligible CDD check fee earns a credit against that calendar month’s subscription, capped at the subscription fee. AML Guard is not self-service: firms start with a demo, then set up their services and risk profile. Full detail on plans and features is available, along with pricing for firms ready to compare options.
FAQ
What is client onboarding in AML KYC?
Client onboarding in an AML and KYC context is the process of identifying a customer, verifying that identity, screening for sanctions and adverse media exposure, and assessing risk before a designated service begins. It follows the sequence of collect, verify, screen, assess, decide and record, with initial CDD generally required before service starts.
What are the four Cs of successful onboarding?
There’s no single official “four Cs” framework recognised in AUSTRAC guidance, and definitions vary depending on the source. A practical reading for AML onboarding emphasises collecting accurate data, confirming identity, checking risk exposure and capturing a complete record, which maps closely to the collect, verify, screen and record steps of the standard sequence.
How many processes does AML client onboarding consist of?
AML client onboarding runs through six core steps: collect, verify, screen, assess, decide and record. Each step has its own data requirements and controls, and together they form the evidence trail a compliance officer relies on to approve or hold a relationship.
What is digital onboarding?
Digital onboarding is the process of capturing, verifying and assessing a customer’s identity and risk profile through online tools rather than in-person paperwork. In an AML context, a person still makes the final decision; the technology handles document checks, screening and data capture, not the final decision.
Is remote identity verification legal for AML purposes?
Yes, remote verification is a controls question rather than a prohibition. The Act requires confirming the customer is who they claim to be, and biometric liveness checks serve as a fraud-prevention control supporting that requirement rather than a separate legal mandate.
Sources
- Overview of customer due diligence | AUSTRAC
- Delayed initial customer due diligence | AUSTRAC
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 - Federal Register of Legislation
Recommended
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML risk scoring that stands up to AUSTRAC
- AML/CTF Program Documents for Tranche 2
- Tranche 2 customer due diligence in Australia
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.