Scope the practice's real workflow first
A generic KYC platform can look capable until a tax agent must record why a company-formation engagement is in scope and a routine return is not. Profession-specific scope logic is the difference between a compliance file and a compliance theatre.
- The professions and designated services the product models
- Whether scope decisions are recorded with reasons, not just a checkbox
- How the tool handles the practice's boundary work: routine tax advice, general legal advice, asset-only sales
- Whether the workflow order matches AUSTRAC's sequence: enrolment, risk, program, staff, training, clients
Test the evidence spine
Ask the vendor how a file looks after an auditor's second question. If the answer is a spreadsheet of uploads, the evidence is not connected. The product should show the chain: scope decision, customer, identity, screening, risk, enhanced measures, approval and monitoring.
- CDD and identity results linked to the exact client and subject
- Screening dispositions recorded with dates, providers and reasons
- Approval separation: the person who prepared is not the person who approved
- Immutable records and audit events that survive edits
- Export paths for AUSTRAC-ready records
Check reporting controls, not just report templates
SMR and TTR work should be restricted to the people who need to know, with deadlines calculated and evidence retained. Some products claim AUSTRAC reporting but only provide a form. Confirm whether the product supports restricted suspicious-matter work, validation, export and manual lodgement evidence, and whether any 'AUSTRAC lodgement' claim is actually a live connection.
Be equally careful with identity claims. A product that says it offers DVS must connect to the government service or an accredited intermediary; hosted document verification is not DVS. Providers that label every check DVS should be asked to prove the connection.
Security, integration and honesty
Cassandra AML is built for this evaluation: profession-specific scope, connected CDD evidence, restricted reporting, approval separation, tenant isolation and honest provider boundaries - including stating that it does not provide Australian DVS or live Xero/PMS sync. The strongest buyer's test is to run a real file through the trial and ask where the evidence breaks.
- Tenant isolation and role-based access, not shared folders
- Encryption, Australian hosting and a published security posture
- Client collection that is secure and expiring, not email attachments
- Integrations the practice actually uses, with live connections tested
- A vendor that documents what it does not do
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
What is the most important feature in AML software?
Connected evidence: every scope decision, identity check, screening result, risk rating and approval linked to the client and retained with a date and reason. Reporting templates without evidence do not survive scrutiny.
Should we buy from a vendor that claims AUSTRAC lodgement?
Check what is actually connected. AUSTRAC lodgement claims should be tested against a live integration or a documented export and manual lodgement path. Unverified claims should not be assumed.
Is DVS required in AML software?
No. DVS is one verification path. If a vendor claims DVS, verify the connection; hosted document verification is not the same as a DVS match against government records.
Does Cassandra AML lodge reports to AUSTRAC?
No. Cassandra supports restricted SMR work, validation, immutable export and manual lodgement evidence. It does not claim a direct AUSTRAC lodgement connector, and it documents that boundary.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.