Client onboarding for Australian accounting firms, rebuilt for 2026

Most accounting firms we talk to are running client onboarding on a combination of email, a Word engagement letter, a spreadsheet and somebody's memory. It works, right up until it doesn't — a client who never returned the signed letter, an ID that was collected but nobody can find, three weeks between "yes let's do it" and the first piece of actual work.
From July 2026, that same process has to also produce AML/CTF evidence that stands up years later. Bolting compliance onto a broken process gives you a slower broken process.
Here's how to rebuild it once so it does both jobs.
What onboarding has to achieve now
Five things, in one flow:
Capture who the client is — entity, structure, the people behind it
Verify their identity to a standard you can prove later
Rate their risk and record why
Get the engagement signed and the scope agreed
Set them up in your systems and start the work
Firms usually do all five. The problem is they do them in five different places, in an order that depends on who's handling it.
The seven-step flow that works
Step 1 — One intake form, not an email thread
A single form the prospect fills in themselves. Entity name and ABN, structure, directors and shareholders, the services they want, the industry they're in, and whether there's any overseas ownership.
This is doing two jobs at once. It's your client record, and it's the raw material for the risk rating. Ask the AML questions here and they feel like normal onboarding, because they are.
Step 2 — Identity verification from the same form
The moment the form is submitted, the identity check goes out to the named individuals — a link on their phone, done in two minutes. Results attach to the client record automatically.
Not "we'll get their licence at the first meeting". By the first meeting it's already done.
Step 3 — Risk rating, calculated
The form answers drive a rating: standard for a local company with two resident directors and a straightforward structure, enhanced for offshore ownership, layered trusts, cash-intensive industries, or anything that trips your criteria.
The compliance officer can override it. If they do, the system makes them type why. That note is the difference between a defensible decision and a gap.
Step 4 — Engagement letter, generated and signed
Scope, fees and terms pulled from the form answers, sent for e-signature. No re-typing the client's name into a Word template.
Step 5 — Systems setup
Xero or your ledger, your job management tool, your document folders, the client portal login. Triggered off the same record, so nothing gets typed twice and nothing gets missed.
Step 6 — Kickoff
Now you meet, and the meeting is about their business instead of chasing forms.
Step 7 — Ongoing monitoring
An annual review that re-checks whether anything material changed — structure, ownership, the nature of the work. Twenty minutes per client, scheduled, not remembered.
Why this is faster, not slower
The instinct is that adding compliance steps adds time. In practice the rebuild removes more than it adds, because most of the current time cost is waiting and chasing, not doing.
What disappears:
The email thread hunting for details the client already told you once
Re-typing the same information into three systems
Chasing the signed engagement letter
The awkward "sorry, can you send that ID again"
What we typically see in firms that do this properly: onboarding drops from two or three weeks of back-and-forth to a few days, and the partner's involvement drops to the parts that need judgement.
The three mistakes to avoid
Building a separate compliance system.
If AML lives in its own tool that only the compliance officer opens, it will fall out of date and it won't reflect what actually happened. Compliance data belongs in the client record.
Asking for everything up front.
A 40-field form kills conversion. Ask what you need to start and to rate risk; collect the rest once they're a client. The prospect stage and the client stage are different forms.
Automating a bad process.
Map what you actually do today, cut the steps that exist because of an old staffing arrangement, and then automate what's left. Automating the mess just makes it faster.
What it takes to build
For a small-to-mid practice this is usually a few weeks of work: intake form, verification integration, risk logic, document generation, and the connections to the systems you already run. It sits on top of your existing tools — you're not replacing your ledger or your practice management software.
We do this as fixed-price work. AML/CTF and client onboarding setup starts at A$999 for the compliance program and onboarding flow. Deeper automation into your job and document systems is quoted on the call, and you get the number before anything starts.
If you just want to see what your compliance program needs to say, the free AML Compliance Pack generator produces a starting risk assessment and program from a few questions about your firm.
Common questions
Do we have to replace our practice management software?
No. The onboarding flow feeds your existing systems. Replacing working software to solve a paperwork problem is the expensive way to do this.
How long before 1 July 2026 should we start?
Give yourself a quarter. Enrolment opens 31 March 2026, and you want the program written and the flow tested before then, not during.
Can one person run this in a five-person firm?
Yes, if it's automated. Manually, one person can handle it until you're onboarding more than a couple of clients a week, and then it becomes the bottleneck.
What about clients we onboarded years ago?
Existing clients need to be brought under your program too. Most firms work through the back book in risk order over several months rather than all at once.