Evidence Packs
An evidence pack is a versioned snapshot of everything recorded against a matter at a point in time: the scoping decision, the customer details, the verification and screening outcomes, the risk assessment, and the decisions with their rationales.
You generate one from the Evidence tab on a matter. For the record keeping obligation a pack serves, see Record keeping.


Generating a pack
A pack is a snapshot of the matter as it stands now: a pack generated in March keeps showing what was true in March even after the matter changes.
Sections fill in as the work is completed, so a pack generated early will be thinner than one generated later. Generate a fresh pack once the engagement is further along rather than relying on an early one for the full record.
Each generation produces a new version. Versions accumulate rather than replacing each other, so the matter carries a history of what was exported and when.
Generating one is a two step choice: open the Evidence tab on the matter, then choose Generate Pack for a standard pack or Generate Sensitive Pack (AMLCO) for the AMLCO-only version.
What a pack contains
A pack covers the matter's compliance record:
- The scoping decision and the designated services behind it
- The customer details and, for an entity, the recorded beneficial owner and controller structure
- Verification runs with their method path, result, and identity binding basis
- Screening runs with their candidates and adjudications
- The risk assessment and any enhanced due diligence
- The decisions taken, each with its rationale and the person who made it
The PDF hash is often described more strongly than it should be. It is a SHA-256 hash of the rendered PDF itself. Its purpose is file integrity: you can confirm the file has not been altered since it was produced.
It is a fingerprint of the document, not a signature over the underlying records. It tells you the PDF you are holding is the PDF that was generated. It does not independently prove that the records inside it are accurate or complete, which remains a question about the work that was done.
Standard and sensitive packs
Every matter can produce two kinds of pack, and they differ in redaction, not in the completeness of the workflow record.
| Standard pack | Sensitive pack | |
|---|---|---|
| Redaction level | Standard | Sensitive |
| Who can generate and open it | Users with compliance access | AMLCO only |
| Purpose | The default export for most purposes | Where the full detail is warranted, including AMLCO review |
The sensitive pack is restricted because it contains material that is not appropriate for general distribution. Who holds the AMLCO role, and what that role gates, is on Roles and permissions.
Reviewing and downloading a pack
From the Evidence tab you can see every version with its version number, the date and time it was generated, the first 16 characters of its PDF hash (SHA-256), its redaction level, a Snapshot stored marker, and a Download PDF action.
The retention anchor is set on the matter rather than on the pack. It sets the date from which the seven year retention period runs, and the Evidence tab shows both the anchor date and the resulting minimum expiry. See Record keeping for how retention works.
Packs and the reporting record
Packs cover the matter's compliance work. They are not the mechanism for reports to AUSTRAC, which are prepared and recorded separately. See Filing a report.
Related pages
- Record keeping, for the retention obligation and the record form requirement.
- Roles and permissions, for the AMLCO role that governs sensitive packs.
- Creating a matter, for the retention anchor and the scoping decision a pack contains.
- Review and evaluation, for the assurance activity that tests whether records like these hold up.