The Two Requests You Send at Once: PBC and AML in One Step
Most firms split document requests from AML/KYC checks — and lose time in both. Here's how to fold onboarding evidence into a single, tracked step.
Think about how a new engagement actually starts in most practices. You send an engagement letter. Then you send a PBC (prepared-by-client) list of documents you need to do the work. Then, somewhere in the gap, someone remembers you also need to verify the client's identity for AML/KYC — so you send a third message asking for a driver's licence, a passport photo, maybe a copy of a rates notice.
Three separate asks. Three separate inboxes to chase. Three separate points where the client goes quiet. And two entirely different purposes — one to do the job, one to satisfy your compliance obligations — that you're treating as unrelated tasks when they're really the same moment.
The firms that onboard cleanly have stopped separating these. The document request and the identity check go out together, land in one place, and get tracked as one milestone. Here's what that looks like and why it matters.
Why the split happens
The PBC list belongs to the accountant doing the work. The AML/KYC check belongs to whoever owns your practice's compliance obligations. In a lot of firms these are different people, using different tools, on different timelines. The accountant wants the trial balance and the bank statements. The compliance function wants proof of identity and a record that the check was done.
So the client gets two conversations. Worse, the AML step often runs on memory — a note in someone's head that identity still needs verifying, mentioned in a previous post as the KYC check you did in your head. It gets skipped, done informally, or done weeks after the work has already started. That's a real risk. Under Australia's AML regime, tranche-two reforms are bringing accountants and other professional services into scope, and "we always meant to" won't be a defence when the obligation is documented and dated.
What good client accounting onboarding actually collects
Before any work begins on a new engagement, you're gathering two kinds of evidence at once:
The compliance evidence
- Identity documents — passport, driver's licence, or the combination your risk policy requires.
- Beneficial ownership — for company and trust clients, who actually controls the entity.
- The verified ABN/ACN and confirmation the entity is what it says it is.
- A dated record that the check was performed, by whom, and against what documents.
The work evidence (your PBC list)
- Prior-year financials and tax returns, if you're taking over from another firm.
- Bank statements, loan documents, asset registers.
- Access to their ledger — and this is where accounting client management software earns its place, because a two-way Xero connection means half the PBC list stops being a request at all.
The overlap is the point. When a new client entity comes in, you're checking the ABN and ACN anyway for the compliance side. You're collecting director details anyway. Doing the identity verification in the same breath adds almost nothing to the client's effort — but only if your process treats it as one step.
One request, one place, one record
Here's the shift. Instead of email one (engagement), email two (PBC), and email three (please send your licence), you run a single onboarding flow through a client portal:
- The engagement letter goes out for e-signing.
- The document checklist — work items and identity items on the same list — appears in the client's portal.
- The client uploads everything to one secure place, not scattered across email attachments.
- Each item is ticked off as it arrives, so both the accountant and the compliance owner can see, at a glance, what's outstanding.
This is what good client accounting software should do: not just store documents, but collect them against a defined list and show you what's missing without anyone re-reading a thread. The PBC items that trickle in get chased automatically. The identity documents land in a secure, access-controlled spot rather than someone's inbox — which matters, because these are exactly the documents you don't want floating around in email.
The record you can actually produce later
The reason to run AML/KYC through your account practice management software rather than a filing cabinet or a spreadsheet is the audit trail. When the obligation is questioned — by a regulator, by a professional body, by your own quality review — you need to show:
- What documents you sighted.
- When you sighted them.
- Who performed the check.
- That it happened before you started work, not after.
If the check lives inside the same system that holds the client record, the engagement letter, and the job board, that trail assembles itself. In Finye, the onboarding checklist, the signed engagement letter, the uploaded identity documents, and the verified ABN/ACN all sit against the one client. You're not hunting through email to reconstruct what you did. It's already there, dated, next to the work.
Making it a standard, not a scramble
The last piece is repeatability. If every new client onboarding is assembled by hand, someone will forget the AML step on the busy weeks — and the busy weeks are when new clients arrive. Standardise it:
- Build one onboarding checklist that covers both compliance evidence and work evidence, and reuse it for every new engagement.
- Set the identity verification as a required item that can't be skipped, so the job can't quietly proceed without it.
- Trigger the whole flow the moment a client is created — engagement letter, portal checklist, and KYC request in one motion — so there's no gap for the AML step to fall through.
None of this makes Finye a tax return software or a lodgment tool — it doesn't verify identity documents for you or lodge anything with the ATO. What it does is make sure the request goes out once, the evidence lands in one secure place, and the record of your check sits permanently against the client. The compliance obligation stops being a thing you remember and becomes a thing your process does.
The one-step test
Look at your last five new clients. For each one, ask: did the identity check happen before work started, and can you show it with a date? If you're not sure — or if the answer lives in someone's memory rather than a system — you're running two requests where you should be running one. Fold them together, put them in the portal, and let the record keep itself.