Your First 30 Days
These phases go in this order because each one unblocks the next. How fast you move through them is up to you. A two-person firm may work through all three in an afternoon, and a larger firm with a busy practice may spread them across several weeks. Most of the friction new firms hit comes from attempting a later step before an earlier one is done.
Phase 1: Establish the firm
Register the firm and complete the profile. The profile drives the rest of the product.
- Firm profile: legal name, ABN, and address. The legal name is printed on your AML/CTF program and evidence packs, so enter it exactly as it should appear on a document handed to a regulator.
- Vertical: accounting, real estate, legal, conveyancer, or jeweller. This drives your policy templates, designated service catalog, and terminology. Setting it correctly now avoids rewriting an approved program later.
- Reporting types: suspicious matter reporting is always included. Add threshold transaction and cross-border movement reporting if they apply to your firm.
- Designated services: choose the services your firm provides from the vertical catalog. Anything you leave out will not be scoped on a matter.
Also complete the firm setup attestation, which covers the statements required for customer verification. Until it is accepted, identity verification and AML screening are blocked for the whole firm. It is a short step, and skipping it is the most common reason a first verification attempt fails.
Phase 2: Appoint people and build the program
- Appoint your AMLCO. Only an Admin or an Approver can hold the role, Staff cannot be appointed, and the candidate's personnel due diligence must be current against the compliance-officer checklist. A reporting entity must appoint an AML/CTF Compliance Officer within 28 days of first providing a designated service, which for Tranche 2 firms is 1 July 2026 at the earliest.
- Invite your team. Assign the narrowest role that lets each person do their job. Most people need Staff. Approval rights should sit with a small number of senior people. Inviting someone also assigns their training and opens their personnel record, so the access level you pick is the one they start with.
- Complete the program builder. Three steps: risk assessment, personnel and governance, and customer due diligence. A fourth stage covering program maintenance is generated automatically into the finished document rather than asked as questions, so there is nothing to fill in for it. Answer for how your firm actually operates rather than how you would like it to, because the generated program describes the process you will be held to.
- Approve the program. An Approver or Admin signs it off. Where the person who wrote the draft can approve and someone else at the firm can too, the product requires them to ask that other person rather than approving their own work. Approval produces the versioned PDF that becomes your program of record, and it supersedes any earlier version rather than overwriting it.
- Assign training. Allocate training to your team and have them attest. Training records form part of what you will be asked to produce.
Phase 3: Run your first matter end to end
The fastest way to learn the product is to take one real engagement all the way through rather than setting up many at once.
- Add a customer. Capture the customer and, for an entity, its beneficial owners and controllers. Entity customers need the structure recorded as well as the company itself.
- Create a matter and scope it. The scoping step determines whether the engagement involves a designated service. If it does not, record it as out of scope: that decision is still audited, which is the point of recording it.
- Complete due diligence. Verify identity, then screen against sanctions, politically exposed person, and adverse media sources. Record the rationale for the decisions you make, not only the outcome.
- Assess risk. A high rating can trigger enhanced due diligence, which adds measures on top of the customer due diligence already completed. It does not restart it.
- Get it approved. An Approver, Admin or the AMLCO signs off, and the rationale and the approver are recorded against the decision.
- Generate the evidence pack. This is the artefact you would hand to an auditor or a regulator. Read the first one you produce as though you were the person receiving it, because that is the test it has to pass.
What done looks like
- An AML/CTF program is approved, and the version is the one you intend.
- An AMLCO is appointed, with personnel due diligence current against the compliance-officer checklist.
- Everyone who needs a role has one, and no one has more access than their job requires.
- The firm setup attestation is accepted, so verification and screening are unblocked.
- At least one matter has been taken from scoping through to an evidence pack.
Dates to put in the calendar
The Action Center collects these automatically once the firm is set up. Know these two before you get there:
- Annual compliance report: every reporting entity is on a financial-year schedule. The report is submitted between 1 July and 30 September each year, covering the previous financial year. For a Tranche 2 firm the first report covers the 2026 to 2027 financial year and is due by 30 September 2027.
- Independent evaluation of your program: required at least once every three years, starting from the deadlines set for your first evaluation. The AMLCO cannot perform the evaluation of the program they run.
Related pages
- Platform Tour, for where each of these steps lives in the product.
- Roles and permissions, before you assign roles.
- Obligations, for what each obligation requires of the firm.