By Justin Amos, Co-Founder & CEO, iDeed Pty Ltd
The views expressed in this article are those of the author and reflect our interpretation of AUSTRAC’s published guidance and the AML/CTF Act as at July 2026. This article is general in nature and does not constitute legal advice. If you have questions about how the reforms apply to your specific practice, get in touch at ideedworks.com.au.
The final post in the iDeed Beyond the Checkbox series
Over the past weeks we have been walking through what AUSTRAC Tranche 2 actually means in practice. Not the checklist version. The real version.
We have covered UBO determination in a world of discretionary trusts and non-beneficially held shares. The Russian doll complexity hiding inside ordinary Australian cap tables. The difference between being enrolled and being genuinely compliant. The cost of poor CDD UX on client relationships. And why co-sourcing the compliance function is the smartest move a professional services firm can make right now.
This is the last post in the series. And it is the most important one.
Because 1 July is here. And what most firms are about to discover is that the deadline was the easy part.
What the market thinks compliance looks like
Buy software. Enrol with AUSTRAC. Send a verification request. Done.
We understand why it feels that way. That is what most of the marketing in this space has implied. Get the tool, tick the box, move on.
But that is not what running a compliant AML program actually requires. And the firms that bought software in May are about to find that out.
What running a compliant AML program actually requires
This is not a one-time exercise. It is an ongoing compliance function. Every day. Every new client. Every triggering event.
Before you can verify anyone
- Identifying which clients trigger CDD obligations and when
- Determining the correct risk rating for each client
- Deciding who needs to be verified and who does not
- Reading trust deeds, constitutions and shareholder agreements
- Mapping ownership structures and voting rights across multiple entities
- Determining UBOs — or correctly concluding there are none and defaulting to the Senior Managing Official
- Identifying when Enhanced Customer Due Diligence is triggered and what that actually requires
The verification itself
- Collecting the right documents from the right people — not everyone, just the right ones
- Chasing outstanding documents so your team does not have to
- Reviewing what comes back and assessing whether it is sufficient
- PEP and sanctions screening with proper context and judgement
The ongoing obligation
- Recording everything in a way that is audit-ready and defensible
- Keeping records updated every time a triggering event occurs
- Monitoring ongoing transactions for suspicious activity
- Filing suspicious matter reports when required
- Maintaining and updating the AML program as the framework evolves
- Conducting annual program reviews
- Training staff on their obligations
And behind all of it — a compliance analyst. The specialist human who catches what the software misses and fixes it before it becomes a problem.
That role is the one nobody has been talking about. And it is the most important one in the entire program.
The role nobody told you about
A compliance analyst is not someone who checks a box. They are the specialist human expertise that sits behind every compliant CDD program — making judgements, fixing errors, understanding nuance and defending decisions to a regulator under scrutiny.
They are the person who:
- Reads a trust deed and makes a legal determination
- Knows the difference between a UBO Shareholder and a Senior Managing Official
- Identifies when a structure triggers ECDD and what that actually requires
- Catches what the software misses — and fixes it before it becomes a problem
What happens without one
This week, a major Australian bank’s automated system misidentified the UBO on one of our own structures. The compliance analyst — the only person who could identify and fix the error — was off sick. The process stalled for three weeks. When they returned and corrected the system error, the application had timed out. Directors had to get involved again from scratch.
This is a major Australian bank. Full compliance team. Every resource available.
And the process still failed — because the human expertise was not there when it was needed.
Now imagine a two-person accounting firm with a bolt-on tool and no compliance expertise on staff. What happens when a complex structure lands on their desk and there is no analyst to call?
The software flagged the problem. But only the analyst could fix it. That distinction matters more than any feature comparison.
The gap nobody is talking about
Buying software does not give you a compliance function. It gives you a workflow.
The compliance function is the human expertise, the ongoing commitment and the specialist judgement that makes the workflow mean something. Without it:
- The software produces outputs that look complete but are not defensible
- Determinations that look right but are not correct
- Files that look ready but would not survive regulatory scrutiny
This is the gap most firms are about to discover. And discovering it after 1 July — when you are already a reporting entity — is not the moment you want to find out.
It is not too late. But you need more than software.
iDeed can get your firm operationally compliant in days. Not because we have the fastest software. Because we have the people.
What the co-sourced model actually delivers
| Your firm | iDeed |
|---|---|
| AMLCO appointed and accountable | Compliance function behind them |
| Governing body approves the program | Analysts build and maintain it |
| Clients receive verification requests | Via professional portal, not a plain email |
| Senior manager owns oversight | iDeed delivers the outcomes |
Complex structures handled correctly. The right people verified. The wrong people left alone. An audit-ready file at the end of every verification.
Credits don’t expire — you only pay for completed verifications, whenever you need them. No annual fees. No idle licence costs. No headcount required.
You have spent years getting it right
We said it at the start of this series and we will say it at the end.
You have built a reputation on getting it right. Your clients chose you because when something important needs to be handled properly, you are the person they call.
AUSTRAC compliance is no different. Getting it wrong has consequences — for your firm, for your clients, and for the real people behind the structures who deserve to be treated with precision and care.
iDeed exists so you do not have to get it wrong.
One ask
If you have read this series and you are still on the fence — pick up the phone. Not to be sold to. Just a straight conversation about where you are, what you actually need and what getting properly set up looks like for your firm.
We are an Australian team. We answer our own phones. We do the work ourselves. And we will be honest with you about what you need and what you do not.
Book a 15 minute call at ideedworks.com.au — no pressure, just a straight conversation.
Thank you for following the Beyond the Checkbox series. We look forward to being your compliance partner for the long term.
Justin Amos is Co-Founder and CEO of iDeed Pty Ltd, operators of ARCaml, an AML/CTF compliance platform built for Australian designated service providers. ideedworks.com.au
The views expressed in this article are those of the author and reflect our interpretation of AUSTRAC’s published guidance and the AML/CTF Act as at July 2026. This article is general in nature and does not constitute legal advice. If you have questions about how the reforms apply to your specific practice, get in touch at ideedworks.com.au.
Justin Amos
Co-Founder & CEO, iDeed Pty Ltd
Justin is Co-Founder and CEO of iDeed, operators of ARCaml - an AML/CTF compliance platform built for Australian designated service providers.
Connect on LinkedIn