The Onboarding Document Trail You Can Actually Audit
AML/KYC checks and PBC requests both leave a paper trail. Here's how to keep that trail complete, consistent and ready when a regulator asks.
Two things happen at the start of every new engagement, and both leave a trail you might one day have to produce. The first is your AML/KYC onboarding — verifying who the client is, checking identity documents, and satisfying yourself they are who they claim to be. The second is your first PBC request — the documents you need from the client to actually do the work.
Most firms treat these as separate, informal exercises. The identity check happens over email or in a quick face-to-face. The PBC list goes out as a Word attachment or a line in a message. Neither leaves a record you'd want to rely on months later. When a professional standards review, an insurer, or a future AML obligation lands on your desk, you're reconstructing what you did from memory and a scattered inbox.
The problem with informal verification
The classic phrase is "the KYC check you did in your head". You met the client, they seemed legitimate, you saw their driver's licence at some point, and you got on with the work. It felt sufficient at the time. But there's no record of what you checked, when you checked it, who did the checking, or what document you sighted.
Australia's AML/CTF regime is expanding to cover more professional services, and accountants are squarely in the frame. Whatever the precise obligations end up being for your firm, the direction is clear: informal, undocumented verification won't hold up. You need to be able to demonstrate a process, not just assert that you were satisfied.
The good news is that this doesn't require a separate compliance system bolted onto your practice. The same client accounting workflow that collects source documents can capture the verification evidence — if it's set up to.
Two requests, one moment
The natural time to run identity verification is exactly when you're already asking the client for things: the very start of the engagement. You're sending the PBC list anyway. Adding the identity documents to that same request is barely more effort for the client and gives you both records in one place.
The key is that both requests land in the same channel and both responses are captured against the same client file. When identity documents arrive by email and PBC documents arrive through a portal — or worse, both arrive by email and get lost in a thread — you've fractured the trail before the job has even started.
A good client accounting management setup lets you send both in a single onboarding step and collect both in a single place. In Finye, the client portal collects everything the client sends against their record, so the ID verification documents and the PBC materials sit together, timestamped, with no attachment archaeology later.
What a clean onboarding trail actually contains
- The request itself — a record of what you asked for and when, for both identity and PBC items.
- The documents received — stored against the client, not floating in an inbox, with the date each item arrived.
- Who verified what — the staff member who reviewed the identity documents and confirmed the check.
- The outstanding items — what's still missing, so a half-complete onboarding doesn't quietly become a started engagement.
- A repeatable checklist — the same steps every time, so verification doesn't depend on who happened to onboard the client.
The PBC list that comes back complete
Even setting AML aside, the PBC request is where a lot of practices lose days. You send a list, half the items come back, you chase the rest, some arrive in the wrong format, and the job stalls before it starts. The problem is rarely the client's willingness — it's that the request has no structure the client can track against.
When the PBC list lives in a portal as a checklist rather than in the body of an email, the client can see what they've provided and what's still outstanding. You can see it too, without opening a thread and counting attachments. The request becomes a shared, live view of progress instead of a static message that ages into irrelevance the moment it's sent.
This matters for the audit trail as well. "We asked, they didn't send, we chased twice" is a defensible position — but only if it's recorded. A structured request captures the chasing automatically. An email thread captures it only if you go looking.
Why this belongs in your practice management system
There's a temptation to solve identity verification with a standalone KYC tool and PBC collection with a separate document-request tool. You end up with client identity in one system, source documents in another, the job itself in a third, and no single place that tells you the full story of an engagement.
Account practice management software earns its place by keeping the client, the work, the documents and the record in one system. The onboarding checklist is part of the client's file. The PBC request is part of the job. The verification evidence sits with the client record it belongs to. When someone asks "did we onboard this client properly?", the answer is one screen, not a scavenger hunt.
This is also where a tidy client record pays off downstream. Verified client details — legal names, ABNs, ACNs, entity structures — flow into engagement letters, invoices and your Xero sync. Getting them right at onboarding, and recording how you confirmed them, means you're not correcting the same details in four places later.
Getting started
You don't need to overhaul everything at once. Start with a single onboarding checklist that combines your identity verification steps and your standard PBC items. Send both through one channel. Store both against the client. Record who verified what.
Then make it the default for every new client. The value of an audit trail isn't in the impressive cases — it's in the ordinary ones you'd otherwise never document. When onboarding runs the same way every time, the record builds itself, and the day someone asks to see your process, you already have the answer.