01
Individual identity verification
Verify an individual client’s identity through a configured KYC workflow and retain a timestamped record of the details, evidence and result used at onboarding.
KYC and AML for legal professionals
Build consistent client identity, entity, beneficial-owner and screening evidence for covered professional services—while keeping matter scope, risk assessment and AML/CTF decisions with your practice.
Legal client due diligence
Tell us about your client types, matter intake and review workflow so we can help scope the appropriate checks.
Built for your workflow
Risk-based onboarding for law firms and conveyancing practices
Individual KYC and entity KYB
Beneficial-owner and authority workflows
PEP, sanctions and watchlist screening
Timestamped onboarding evidence
Legal profession AML/CTF preparation
Legal client due diligence is more than collecting a driver licence. For a covered professional designated service, a practice may need to understand the client’s legal form, verify individuals, establish authority, identify beneficial owners, screen relevant people and retain evidence that supports its own risk-based decision. AuthNTick helps organise those verification and screening steps without claiming to replace the practice’s AML/CTF program, professional judgement or reporting responsibilities.
Relevant checks
Configure the checks and review points that match your customer, service and risk-based process.
01
Verify an individual client’s identity through a configured KYC workflow and retain a timestamped record of the details, evidence and result used at onboarding.
02
Check an Australian company or other organisation through a KYB workflow, then connect the entity record with the relevant directors, trustees, partners, representatives and beneficial owners.
03
Capture who is instructing the practice, the capacity in which they act and the evidence used to assess whether they are authorised to act for the client or legal arrangement.
04
Support the identification and verification of the natural people who ultimately own or control an entity, with escalation for layered ownership, trusts, nominees or information gaps.
05
Screen relevant individuals against politically exposed person, sanctions and watchlist data, then review similarities using available identifiers rather than treating a name match as conclusive.
06
Create a consistent evidence trail for the checks performed, match-review status and point-in-time outcome so the practice can document its own risk assessment and acceptance decision.
Workflow
Identify whether the proposed work involves a covered professional designated service. The AML/CTF rules do not apply to every legal task, so the practice should document its scope decision before choosing a workflow.
Determine whether the client is an individual, company, partnership, trust, association, government body or another structure, and identify agents, representatives, officeholders and beneficial owners relevant to that customer type.
Request identifying information, authority evidence, ownership details, purpose of the relationship and other risk inputs required by the practice’s documented customer due diligence procedure.
Run the configured KYC or KYB checks, screen relevant people for PEP, sanctions and watchlist indicators, and refer possible matches or incomplete ownership information for authorised review.
The practice combines the check results with matter, service, delivery-channel, geographic and client risk factors, applies any enhanced steps it requires and records its own acceptance or escalation decision.
A point-in-time onboarding check does not replace ongoing customer due diligence. Define periodic reviews and event-driven refreshes separately, based on the relationship and the practice’s AML/CTF program.
Scope and responsibility
AuthNTick supports identity and screening evidence; your practice remains responsible for its AML/CTF program and obligations.
From 1 July 2026, AML/CTF obligations apply to a legal practice when it provides a covered professional designated service. They do not automatically apply to every legal service or every matter.
AuthNTick provides identity, business and screening inputs. The legal practice remains responsible for determining whether it is a reporting entity, enrolling where required, assessing risk and designing and maintaining its AML/CTF program.
Using an external provider for a KYC or KYB step does not transfer the practice’s legal responsibility. The practice must decide whether the process and evidence satisfy its own obligations and risk settings.
A clear identity or screening result is not a complete client-risk assessment. The practice must consider the nature of the service, purpose of the matter, delivery channel, jurisdictions, ownership structure and other relevant risk factors.
AuthNTick does not make the client-acceptance decision, provide legal advice, conduct transaction monitoring or submit suspicious matter, threshold transaction or other regulatory reports for the practice.
Potential PEP, sanctions or watchlist matches require contextual review. PEP status is not proof of wrongdoing, and a similar name alone does not confirm that a sanctions record relates to the client.
A one-off report records information available at that time. Ongoing CDD, transaction monitoring, regulatory reporting, staff training, independent evaluation and record-retention governance are separate controls.
Industry guidance
Open each topic for practical considerations and implementation guidance.
Australia’s expanded AML/CTF regime brings legal practitioners into scope when they provide specified professional designated services from 1 July 2026. The practical starting point is therefore the service being supplied, not merely the fact that the client has engaged a lawyer or conveyancer. A practice should map its matter types against the legislation and AUSTRAC guidance and retain a reasoned scope decision.
Customer due diligence should fit the practice’s AML/CTF program and the risks presented by its services and clients. A repeatable digital workflow can reduce inconsistent collection, but the practice still needs documented rules for ordinary, simplified where permitted, and enhanced treatment. The result should help a reviewer understand who the client is, why the matter exists and who ultimately benefits from or controls the transaction.
Legal and conveyancing clients are not always a single natural person. Instructions may come from a director for a company, a trustee for a trust, a partner, an executor, an attorney or an agent. The practice needs to identify the customer correctly, understand the structure and verify the people required by its procedure. More complex arrangements may require documents and manual analysis beyond an automated result.
Knowing the client is not enough when another person gives instructions. The practice should identify the representative, understand their role and take reasonable steps under its procedure to verify authority. This can also help address impersonation, fraudulent property transactions and instructions that do not align with an established client relationship.
Beneficial ownership is a core part of understanding an entity client. Registry information can be useful, but it may not provide a complete view of the natural people who ultimately own or control a layered structure. A KYB workflow should organise entity information and connected-person checks while leaving room for documentary evidence, questions and reasoned human review.
Name screening can generate false positives, especially for common names or incomplete identity data. A useful process compares dates of birth, locations, aliases, nationality and other available identifiers before a result is cleared or escalated. It also distinguishes different forms of financial-crime risk rather than presenting every record as an automatic failure.
A third-party check can make collection and evidence more consistent, but the reporting entity remains responsible for its AML/CTF obligations. Before relying on a workflow, the practice should understand what was checked, which sources and matching methods were in scope, when the result was generated, how exceptions are handled and how records can be retrieved.
Initial KYC and AML screening establishes a point-in-time foundation. During a long-running matter or continuing client relationship, information can change: directors are appointed, trustees are replaced, ownership is transferred, new jurisdictions are introduced or activity no longer matches the stated purpose. The practice must separately define the monitoring and review controls that apply to its services and risk profile.
Keep exploring
Not for every legal task. From 1 July 2026, AML/CTF obligations apply when a practice provides a covered professional designated service. A practice should assess each service line and matter against the law and current AUSTRAC guidance and obtain advice where its scope is uncertain.
Relevant services can include assisting with specified transactions involving real estate, bodies corporate or legal arrangements, creating or restructuring entities and trusts, and other professional services described in the designated-services framework. The exact statutory description, circumstances and exclusions matter, so practices should use current AUSTRAC guidance rather than a generic industry label.
KYC focuses on verifying an individual. KYB focuses on establishing and checking a company, trust, partnership or other organisation and coordinating identification of relevant representatives, beneficial owners and controllers. An entity client will commonly require both an entity-level KYB workflow and individual checks for connected people.
Your procedure should identify when a representative must be verified and how their authority will be established. The appropriate evidence depends on whether they act as a director, trustee, partner, attorney, executor, employee or agent and on the customer and matter risk.
An individual KYC check does not establish an entity’s complete ownership structure. Use a KYB workflow to organise entity, ownership and control information, then verify relevant natural persons. Layered, foreign, nominee or trust structures may require additional documents, enquiries and manual review.
A possible match should be compared with available identifiers such as date of birth, location, nationality and aliases. It should be cleared, confirmed or escalated according to the practice’s approved procedure. PEP status is a risk factor rather than proof of misconduct, and a name similarity alone is not a confirmed sanctions match.
No. A provider can support collection, verification, screening and record creation, but outsourcing a step does not transfer the reporting entity’s responsibility. The practice must assess the provider, understand the scope and evidence, and ensure its own AML/CTF program and decisions meet the obligations that apply.
No. AuthNTick’s KYC, KYB and screening services support identity and onboarding evidence. The legal practice remains responsible for its client risk assessment, ongoing due diligence, transaction monitoring, suspicious matter and other reporting processes, record keeping, governance and regulatory decisions.
Talk to AuthNTick
Tell us about your client types, services and review process so we can scope the right checks.