KYC and AML for legal professionals

Legal and Conveyancing KYC and AML Checks

Build consistent client identity, entity, beneficial-owner and screening evidence for covered professional services—while keeping matter scope, risk assessment and AML/CTF decisions with your practice.

Australian conveyancer reviewing identity and property documents with a client in a professional office

Legal client due diligence

Tell us about your client types, matter intake and review workflow so we can help scope the appropriate checks.

Built for your workflow

Risk-based onboarding for law firms and conveyancing practices

01

Individual KYC and entity KYB

02

Beneficial-owner and authority workflows

03

PEP, sanctions and watchlist screening

04

Timestamped onboarding evidence

Legal profession AML/CTF preparation

A clearer KYC and AML workflow for legal and conveyancing matters

Legal client due diligence is more than collecting a driver licence. For a covered professional designated service, a practice may need to understand the client’s legal form, verify individuals, establish authority, identify beneficial owners, screen relevant people and retain evidence that supports its own risk-based decision. AuthNTick helps organise those verification and screening steps without claiming to replace the practice’s AML/CTF program, professional judgement or reporting responsibilities.

Relevant checks

Checks that can support legal client due diligence

Configure the checks and review points that match your customer, service and risk-based process.

01

Individual identity verification

Verify an individual client’s identity through a configured KYC workflow and retain a timestamped record of the details, evidence and result used at onboarding.

02

Company and entity verification

Check an Australian company or other organisation through a KYB workflow, then connect the entity record with the relevant directors, trustees, partners, representatives and beneficial owners.

03

Authority and representative checks

Capture who is instructing the practice, the capacity in which they act and the evidence used to assess whether they are authorised to act for the client or legal arrangement.

04

Beneficial-owner workflow

Support the identification and verification of the natural people who ultimately own or control an entity, with escalation for layered ownership, trusts, nominees or information gaps.

05

PEP and sanctions screening

Screen relevant individuals against politically exposed person, sanctions and watchlist data, then review similarities using available identifiers rather than treating a name match as conclusive.

06

Evidence for the matter file

Create a consistent evidence trail for the checks performed, match-review status and point-in-time outcome so the practice can document its own risk assessment and acceptance decision.

Workflow

How to structure a matter-intake screening workflow

  1. 01

    Confirm whether the matter is in scope

    Identify whether the proposed work involves a covered professional designated service. The AML/CTF rules do not apply to every legal task, so the practice should document its scope decision before choosing a workflow.

  2. 02

    Classify the client and connected people

    Determine whether the client is an individual, company, partnership, trust, association, government body or another structure, and identify agents, representatives, officeholders and beneficial owners relevant to that customer type.

  3. 03

    Collect identity and relationship information

    Request identifying information, authority evidence, ownership details, purpose of the relationship and other risk inputs required by the practice’s documented customer due diligence procedure.

  4. 04

    Verify, screen and review

    Run the configured KYC or KYB checks, screen relevant people for PEP, sanctions and watchlist indicators, and refer possible matches or incomplete ownership information for authorised review.

  5. 05

    Assess risk and retain the decision

    The practice combines the check results with matter, service, delivery-channel, geographic and client risk factors, applies any enhanced steps it requires and records its own acceptance or escalation decision.

  6. 06

    Refresh information when required

    A point-in-time onboarding check does not replace ongoing customer due diligence. Define periodic reviews and event-driven refreshes separately, based on the relationship and the practice’s AML/CTF program.

Scope and responsibility

Compliance boundaries your practice should preserve

AuthNTick supports identity and screening evidence; your practice remains responsible for its AML/CTF program and obligations.

  1. 01

    From 1 July 2026, AML/CTF obligations apply to a legal practice when it provides a covered professional designated service. They do not automatically apply to every legal service or every matter.

  2. 02

    AuthNTick provides identity, business and screening inputs. The legal practice remains responsible for determining whether it is a reporting entity, enrolling where required, assessing risk and designing and maintaining its AML/CTF program.

  3. 03

    Using an external provider for a KYC or KYB step does not transfer the practice’s legal responsibility. The practice must decide whether the process and evidence satisfy its own obligations and risk settings.

  4. 04

    A clear identity or screening result is not a complete client-risk assessment. The practice must consider the nature of the service, purpose of the matter, delivery channel, jurisdictions, ownership structure and other relevant risk factors.

  5. 05

    AuthNTick does not make the client-acceptance decision, provide legal advice, conduct transaction monitoring or submit suspicious matter, threshold transaction or other regulatory reports for the practice.

  6. 06

    Potential PEP, sanctions or watchlist matches require contextual review. PEP status is not proof of wrongdoing, and a similar name alone does not confirm that a sanctions record relates to the client.

  7. 07

    A one-off report records information available at that time. Ongoing CDD, transaction monitoring, regulatory reporting, staff training, independent evaluation and record-retention governance are separate controls.

Industry guidance

Build the process around the work.

Open each topic for practical considerations and implementation guidance.

01The 1 July 2026 boundary: covered services, not every legal instruction

Australia’s expanded AML/CTF regime brings legal practitioners into scope when they provide specified professional designated services from 1 July 2026. The practical starting point is therefore the service being supplied, not merely the fact that the client has engaged a lawyer or conveyancer. A practice should map its matter types against the legislation and AUSTRAC guidance and retain a reasoned scope decision.

  • Covered activities can include assisting a client with a transaction involving real property, a body corporate or a legal arrangement, subject to the precise statutory service description and exclusions.
  • Creating or restructuring a body corporate or legal arrangement, and other services listed for professional service providers, may also be designated services.
  • Advice, litigation and other legal work should not be labelled in scope simply because it occurs near a transaction; assess the actual service the practice provides.
  • A mixed matter may contain both covered and non-covered work. Define when the regulated service starts and what client due diligence must be completed before it is provided.
  • When the scope is uncertain, obtain appropriate legal or compliance advice and consult current AUSTRAC material rather than relying on a software workflow.
02Build a risk-based legal client onboarding workflow

Customer due diligence should fit the practice’s AML/CTF program and the risks presented by its services and clients. A repeatable digital workflow can reduce inconsistent collection, but the practice still needs documented rules for ordinary, simplified where permitted, and enhanced treatment. The result should help a reviewer understand who the client is, why the matter exists and who ultimately benefits from or controls the transaction.

  • Collect the client’s identity, contact details and relationship purpose using fields that match the customer type and the practice’s approved procedure.
  • Include risk inputs relevant to legal work, such as matter type, asset or transaction context, delivery channel, source and destination jurisdictions and the use of intermediaries.
  • Define who may approve higher-risk clients, what additional information they need and when work must pause while questions remain unresolved.
  • Do not let a successful document or database check automatically assign a low risk rating; verification and risk classification answer different questions.
  • Keep the onboarding output with the matter-level assessment, reviewer notes and final decision so the file explains the practice’s reasoning.
03Verify individuals, entities and trusts according to structure

Legal and conveyancing clients are not always a single natural person. Instructions may come from a director for a company, a trustee for a trust, a partner, an executor, an attorney or an agent. The practice needs to identify the customer correctly, understand the structure and verify the people required by its procedure. More complex arrangements may require documents and manual analysis beyond an automated result.

  • For an individual, collect and verify the identifying information required by the practice and resolve material discrepancies before relying on the result.
  • For a company, verify the entity, review registration information and identify the people who direct, control or ultimately own it under the applicable procedure.
  • For a trust, record the trust type and relevant parties, obtain appropriate trust evidence and identify trustees, beneficial owners or other connected people as required.
  • For partnerships and associations, adapt collection to their legal form instead of forcing the customer into a company workflow.
  • Escalate foreign, layered, nominee or opaque ownership structures when reliable ownership and control information cannot be established through the standard workflow.
04Confirm representatives and authority to instruct

Knowing the client is not enough when another person gives instructions. The practice should identify the representative, understand their role and take reasonable steps under its procedure to verify authority. This can also help address impersonation, fraudulent property transactions and instructions that do not align with an established client relationship.

  • Record whether the person acts as a director, trustee, partner, attorney, executor, employee, agent or in another capacity.
  • Verify the representative’s identity where required, rather than relying only on an email signature or information supplied by a referrer.
  • Collect authority evidence appropriate to the relationship, such as registry information, a resolution, power of attorney, trust document or direct confirmation.
  • Use a separate communication channel or known contact details for high-risk changes to payment instructions, ownership details or authorised representatives.
  • Document unresolved inconsistencies and require an authorised reviewer to decide whether further evidence or escalation is necessary.
05Identify beneficial owners and people who control the client

Beneficial ownership is a core part of understanding an entity client. Registry information can be useful, but it may not provide a complete view of the natural people who ultimately own or control a layered structure. A KYB workflow should organise entity information and connected-person checks while leaving room for documentary evidence, questions and reasoned human review.

  • Trace ownership and control to natural persons using the thresholds and control tests set by the practice’s current legal and regulatory procedure.
  • Consider control exercised through voting rights, appointments, trusts, agreements or other means, not ownership percentage alone.
  • Compare information from the client with reliable independent records and investigate material conflicts or unexplained gaps.
  • Apply individual KYC and relevant screening to beneficial owners and controllers identified as part of the entity workflow.
  • Record the steps taken when no beneficial owner can be identified under the applicable test and follow the practice’s escalation procedure.
06Review PEP, sanctions and watchlist results in context

Name screening can generate false positives, especially for common names or incomplete identity data. A useful process compares dates of birth, locations, aliases, nationality and other available identifiers before a result is cleared or escalated. It also distinguishes different forms of financial-crime risk rather than presenting every record as an automatic failure.

  • Treat a PEP connection as a factor requiring the assessment and controls specified by the practice, not as evidence that the person has acted improperly.
  • Identify the sanctions list or other source involved and follow the practice’s legal escalation steps where a match may be genuine.
  • Use enough identifiers to reduce false positives, while collecting and handling personal information consistently with privacy and security requirements.
  • Classify the outcome as cleared, confirmed or unresolved under a documented review standard and retain the reasons and supporting evidence.
  • Decide separately whether recurring screening or an event-driven rescreen is needed; a point-in-time result does not remain current indefinitely.
07Keep evidence and preserve the practice’s decision-making role

A third-party check can make collection and evidence more consistent, but the reporting entity remains responsible for its AML/CTF obligations. Before relying on a workflow, the practice should understand what was checked, which sources and matching methods were in scope, when the result was generated, how exceptions are handled and how records can be retrieved.

  • Retain the submitted identifiers, verification result, entity and ownership information, screening status, match-review notes and timestamps relevant to the decision.
  • Document any information obtained outside AuthNTick, including trust instruments, corporate records, source-of-funds material or direct authority confirmation.
  • Keep the practice’s risk rating, enhanced due diligence, approval and matter-acceptance decision as its own record rather than outsourcing the judgement.
  • Define access, retention, privacy and security controls for personal and sensitive information across the practice and its service providers.
  • Test the end-to-end procedure—including exceptions and manual referrals—rather than assuming a successful API or portal response proves the control is effective.
08Plan for ongoing CDD and transaction-related controls

Initial KYC and AML screening establishes a point-in-time foundation. During a long-running matter or continuing client relationship, information can change: directors are appointed, trustees are replaced, ownership is transferred, new jurisdictions are introduced or activity no longer matches the stated purpose. The practice must separately define the monitoring and review controls that apply to its services and risk profile.

  • Set periodic review frequencies that reflect customer risk and define events that trigger an earlier identity, ownership or screening refresh.
  • Reassess when the client requests a materially different service, the purpose changes or the practice becomes aware of inconsistent information.
  • Maintain transaction monitoring and regulatory reporting processes outside the identity verification workflow where those obligations apply.
  • Ensure staff know how to escalate unusual behaviour or information without tipping off a client or disrupting an appropriate internal review process.
  • Check current AUSTRAC guidance as the reformed framework is implemented and update policies, system configuration, training and records when requirements change.

Practical questions, answered.

Do all Australian lawyers and conveyancers need to perform KYC and AML checks?

Not for every legal task. From 1 July 2026, AML/CTF obligations apply when a practice provides a covered professional designated service. A practice should assess each service line and matter against the law and current AUSTRAC guidance and obtain advice where its scope is uncertain.

Which legal and conveyancing services may be covered from 1 July 2026?

Relevant services can include assisting with specified transactions involving real estate, bodies corporate or legal arrangements, creating or restructuring entities and trusts, and other professional services described in the designated-services framework. The exact statutory description, circumstances and exclusions matter, so practices should use current AUSTRAC guidance rather than a generic industry label.

What is the difference between KYC and KYB for a legal client?

KYC focuses on verifying an individual. KYB focuses on establishing and checking a company, trust, partnership or other organisation and coordinating identification of relevant representatives, beneficial owners and controllers. An entity client will commonly require both an entity-level KYB workflow and individual checks for connected people.

Do we need to verify a person who acts for the client?

Your procedure should identify when a representative must be verified and how their authority will be established. The appropriate evidence depends on whether they act as a director, trustee, partner, attorney, executor, employee or agent and on the customer and matter risk.

Does a KYC and AML check identify beneficial owners?

An individual KYC check does not establish an entity’s complete ownership structure. Use a KYB workflow to organise entity, ownership and control information, then verify relevant natural persons. Layered, foreign, nominee or trust structures may require additional documents, enquiries and manual review.

What happens if PEP or sanctions screening returns a possible match?

A possible match should be compared with available identifiers such as date of birth, location, nationality and aliases. It should be cleared, confirmed or escalated according to the practice’s approved procedure. PEP status is a risk factor rather than proof of misconduct, and a name similarity alone is not a confirmed sanctions match.

Can a law firm outsource KYC and transfer its AML/CTF responsibility?

No. A provider can support collection, verification, screening and record creation, but outsourcing a step does not transfer the reporting entity’s responsibility. The practice must assess the provider, understand the scope and evidence, and ensure its own AML/CTF program and decisions meet the obligations that apply.

Does AuthNTick provide transaction monitoring or submit AUSTRAC reports?

No. AuthNTick’s KYC, KYB and screening services support identity and onboarding evidence. The legal practice remains responsible for its client risk assessment, ongoing due diligence, transaction monitoring, suspicious matter and other reporting processes, record keeping, governance and regulatory decisions.

Talk to AuthNTick

Make client due diligence clearer from matter intake.

Tell us about your client types, services and review process so we can scope the right checks.