Detected country: US
logo
‌
‌
‌
logo

Powered by

  • Home
  • Frequently Asked Questions
  • Compliance Centre FAQs

Compliance Centre FAQs

12min read

Share

Costs & Pricing

  1. What does the Compliance Centre cost (subscription, per client, or per service)? There is no subscription cost to use the Compliance Centre. The cost included is purely transactional. We have bundled costs, from individual KYC onboardings, company & trust KYB onboardings.
  2. Are there additional or hidden fees (e.g. VOI, searches, reports)? There are no additional costs or hidden fees.
  3. Will pricing change in the future? There will be no cost added to the Compliance Centre. Transactional pricing is reviewed and sometimes adjusted per annum.

Data Security, Privacy & Storage

  1. Where is client and staff data stored? Client data is stored within a secure, private and encrypted environment within Australian servers. No client information is stored in offshore servers.
  2. What security measures and encryption are used to protect data? Our data storage is aligned with data storage requirements of ARNECC, AUSTRAC and Privacy Act 1988. We are an ISO/IEC 27001:2022, SOC 2 type 2 compliant organisation.
  3. How long is data retained, and when does the retention period start? As per AUSTRAC requirements, data is stored and retained for 7 years in the Compliance Centre. The period starts once the client has completed and submitted their verification information.
  4. Who can access the data? The Firm, InfoTrack, triSearch and AUSTRAC. Third parties will only access the data if AUSTRAC has appointed them as auditors.
  5. Will we retain access to our data if we change providers or systems? Yes, you will retain access. A data migration process will need to be conducted should you wish to move the data to another system or provider.
  6. What happens to client data after 7 years? Data stored within InfoTrack is safely deleted in accordance with regulatory requirements after the 7 year period.

Integrations & Systems Compatibility

  1. Does the Compliance Centre integrate with Practice Management Systems? The Compliance Centre currently integrates with all Practice management systems where Infotrack is available, via the link in InfoTrack's header. LEAP, Smokeball, triConvey, SILQ, LawMaster, ActionStep (via Konekta), CLIO and more have in-depth InfoTrack AML integrations available.
  2. What data syncs between the Compliance Centre and our Practice Management System (e.g. client data, reports, costs)? Data provided from the Practice Management System, such as matter reference, costs and client data will filter through to the Compliance Centre.
  3. Can reports (VOI, CDD) be automatically saved to matters? Yes, all VOI and CDD information will automatically save through to the matter.
  4. Can the platform be used without an integrated Practice Management System? Yes, the platform can be used without an integrated Practice Management System. You will need an account with either InfoTrack or triSearch.

Client Onboarding & VOI

  1. How does the VOI process work? The VOI feature facilitates secure digital collection of client identity documents. Clients can upload their identification through a guided process, ensuring required documentation is captured accurately and stored securely for compliance and audit purposes.
  2. Can onboarding forms be customised or branded? We offer digital onboarding forms for both KYC (individuals) and KYB (trusts and companies), which are based on the AUSTRAC starter kits to ensure regulatory alignment. The standardised compliance questions cannot be removed. We are actively working on making these forms editable to add additional custom questions where required however, this functionality is not yet available and may not be ready until after July 2026.
  3. Can we use external VOI providers (e.g. Australia Post) instead of InfoTrack VOI? Yes. InfoTrack and triSearch allows you to manually upload VOIs conducted through external providers. Accepted options include Australia Post and Certified Copies of ID, among others. Once uploaded, you can run the full suite of associated compliance checks — including Screening Checks and the KYC Onboarding form — alongside your externally sourced VOI, giving you flexibility in how you meet your verification obligations.

Overseas clients and staff

  1. Can the platform support onboarding and verification of overseas clients? Yes. However, there may be certain hurdles depending on the jurisdiction they are based in.
  2. How are identity checks handled without Australian mobile numbers? We can verify a vast amount of overseas mobile numbers. The correct country code is necessary but there are some restrictions on certain countries access. However, we can also verify individuals via their email.
  3. How are foreign staff verified (e.g. police checks)? Standard VOI verification applies to foreign staff where they submit their documents with their government issue ID. Police checks are only required for the Compliance Officer who should be based in Australia.

Compliance, AML/CTF & AUSTRAC

  1. Does using the Compliance Centre ensure compliance with AUSTRAC requirements? Absolutely. The Compliance Centre has been purpose built with industry leaders who were instrumental in the creation of the AUSTRAC starter kits. We have digitised these starter kits into a comprehensive digital workflow covering all basis of AML compliance.

  2. Is this a complete AML/CTF program or a supporting tool? The Compliance Centre is a supporting tool to adhere to the AML/CTF regulations that are directly built in-line with AUSTRAC’s requirements. The onus is on the firm to adhere to the program and is best achieved by utilising the tool and it’s capabilities.

  3. Can we upload externally prepared AML/CTF programs and policies? Yes, the Compliance Centre supports the upload of externally prepared programs and policies.

  4. Do we need separate compliance setups for different services (e.g. legal vs conveyancing)? If your firm covers both Legal Services and Conveyancing, select Legal Services as this will include both sectors.

  5. What sector should I choose if I have a Real Estate business and a Conveyancing business? If you're running both a real estate business and a conveyancing business, you'll actually need to set up a separate Compliance Centre account for each sector.

    Here’s how the sectors are generally categorised:

    • Conveyancing/Legal: These fall under the Legal Services sector (though "Conveyancing" may also appear as its own option depending on your setup).
    • Real Estate: This is handled under the Real Estate Services sector.

    Since these businesses often have different reporting obligations under AUSTRAC, the Compliance Centre requires a separate account for each to ensure all the data and reporting for your real estate activities stay distinct from your conveyancing work. If you're an Admin, you can choose the sector when you first access the Compliance Centre link in the InfoTrack/triSearch header.

  6. Do we register with AUSTRAC through the Compliance Centre or separately? You can access the AUSTRAC Enrolment website directly from the Compliance Centre. Once registered, you can then enter your AUSTRAC number in the Compliance Centre for record purposes.

  7. What is a Designated service? To check to see if your services falls into a designated service, use our Designated service checker tool which can be found here.

Risk Assessments, Policies and Customisation

  1. Can risk assessments, policies, and procedures be edited after creation? A Firm Risk assessment can be updated, removed and replaced. A Policy can be removed, downloaded and replaced. The Compliance Officer will need to manage both.

  2. Can we create multiple policies for different services or business areas? You can only display one Policy and Process document in the Compliance Centre.

  3. Can custom risks be added to the Firm Risk assessment to suit our firm? We do not allow clients to add any custom risks. All risks and sections are aligned per industry type as stated in the Starter kits. The current risk assessment is comprehensive and covers most areas and risks firms are exposed to.

  4. Are Risk Assessment and Policy templates suitable for firms of different sizes? Yes. The templates are adequate for all firms, but are generally tailored for smaller firms. For the Risk Assessments, the Compliance Centre has digitised all of the inherent risks each sectors face under Tranche 2. For the AML Policy & Process, AUSTRAC’s supplied policy is designed for smaller firms with staff between 1–15, but can still be used for larger firms with a suitability statement included. The suitability statement should include details on how the standard policy and process template can be applied to your firm.

  5. Is version control or document locking available?

    The Compliance Officer has unlimited access and permissions in the Compliance Centre. The Governing Body shares the same level of visibility as the Compliance Officer however, the Governing Body, Senior Manager and Client-facing staff have restricted access to core compliance documents to ensure integrity. They cannot edit or remove core compliance documents. This is restricted to the Compliance Officer.

Staff Access, Roles & Permissions

  1. Can multiple Compliance Officers be assigned? Yes, the Compliance Centre has this capability.
  2. What user roles and permission levels are available?
    • The Compliance Officer has unlimited access and permissions in the Compliance Centre.
    • The Governing Body shares the same level of visibility as the Compliance Officer however, they have read only access to Risk Assessments and Policies. They can view audit trails and version histories to track changes and have full visibility into transaction logs and personal training records.
    • The Senior Manager and Client-facing staff have full visibility over Transactions and their Training modules. They are unable to access Staff Onboarding and have read only access to Risk Assessments and Policies.
  3. Who can edit risk assessments, policies, and compliance data? Only the Compliance Officer.

Training & Staff Onboarding

  1. What training is included in the platform? The learning program contains 10 individual training modules for completion. These 10 modules provide a basic level of risk awareness training for all staff members.
  2. Is training role-specific and ongoing? Yes. The Compliance Centre now offers two tiers of training: Foundational Training is designed for all staff members and covers a basic level of AML/CTF risk awareness across 10 modules. This is the starting point for everyone in your firm. Additional Training is role-specific and provides extended AML/CTF knowledge for more advanced staff and compliance teams who require a deeper understanding of their obligations.
  3. Who in the firm is required to complete training? Anyone appointed the role of Governing Body, Senior Manager, Compliance Officer or Client-facing staff.
  4. Can training completion be tracked and recorded? Yes. Compliance Officers have oversight of staff’s completion progress of the AML training within the Staff Onboarding tab.
  5. Does training include how to use InfoTrack or triSearch tools, and does it qualify for CPD? The training provides a basic level of risk awareness knowledge about AML in general. It is not specify the InfoTrack or triSearch tools.
  6. Does training qualify for CPD? Yes. A certificate of completion will be generated from the completion of all 10 training modules which staff and claim CPD Points. Please note that practitioners residing in Western Australia cannot claim CPD points from InfoTrack training through the Legal Practice Board of Western Australia.
  7. Can we access the training videos once training has been completed? Yes, you can re-watch completed training videos from the Staff Training tab in the Compliance Centre.

KYC, PEP & Due Diligence

  1. What checks are included (e.g. KYC, PEP, sanctions, adverse media)? Yes, we cover the end-to-end AML transactional workflow. KYC, ECDD, KYB, Screening, Ongoing Monitoring, Reporting.
  2. How are source of funds and source of wealth verified? The Source of Funds check is completed as part of the Enhanced Client Due Diligence. Clients securely upload bank statements, which are analysed using AI technology. The system extracts key transactional insights and generates a clear summary report for the firm. This allows practitioners to quickly assess source-of-funds legitimacy, identify unusual activity, and document their due diligence efficiently.
  3. Can trusts, companies, and beneficial owners be assessed? Yes, Compliance Centre has capabilities for clients to verify companies, trusts and detect and verify beneficial owners globally across 150+ jurisdictions.

Workflow, Processes & Functionality

  1. Is the onboarding and compliance workflow automated? Not entirely. We have created the tools to reduce the admin of onboarding and compliance, but a level of manual oversight is important to make risk-based decisions. We provide the tools to identify the risk, you make the assessment on how you deal with the risk.
  2. Can submissions be edited or restarted after completion? For the firm’s client, there is no possibility to restart or re-complete a submission. Firms can control this and request a re-submission from their clients. In the instance where a firm is unhappy with the quality of a VOI document, they can request a resubmission.
  3. Can reports be generated, exported, and shared easily? The platform will facilitate the collection of the required data for reporting and enable export functionality to support easier upload to the AUSTRAC portal. Submission will still need to be completed by logging directly into the AUSTRAC portal.
  4. Is there audit trail and reporting functionality? Yes. We have a complete audit trail and record keeping functionality embedded throughout most areas of the Compliance Centre. We show line-by-line item, date & time stamped of each activity conducted.

Firm size & suitability

  1. Is the Compliance Centre suitable for small, medium, and large firms? Yes. The Compliance Centre is suitable for firms of all sizes and the designated services they provide.
  2. Can it replace external compliance consultants? Yes. Majority of consultants support with the creation of Risk Assessments and Policy & Processes frameworks in-line with AUSTRAC’s guidance. We have digitised the AUSTRAC’s guidance which simplifies the process and eliminates the need to spend money with consultants. However, the Compliance Centre acts as a repository to store external documents conducted with an external consultant.

Access, Setup & Availability

  1. How do we access and set up the Compliance Centre? As a triSearch or InfoTrack website user, simply click the Compliance Centre link from the header. If you are using an integrated Practice Management Software like Leap, Smokeball or triConvey, you can either access the Compliance Centre from the AML link in the Home Dashboard or directly from a matter. To set up the Compliance Centre, refer to our help article.
  2. Can we trial or train in the system before going live? Yes. There is no cost to using the Compliance Centre.
  3. Can staff be onboarded before AUSTRAC registration? Yes and we encourage it.
  4. Is the platform available to non-InfoTrack or non-triSearch users? No, you will need an account with either InfoTrack or triSearch.

Record Keeping & Ongoing Compliance

  1. Does the system notify when compliance actions (e.g. VOI) expire? We do not store any PII data, therefore we won't alert clients on specific ID documents expiring, we don't retain that data outside of the full report. Broadly, the purpose of VOI is to identify a person is who they say they are, document expiry doesn't really change that. We are currently not doing alerts in this area.
  2. How long are records stored and can they be retrieved later? As per AUSTRAC requirements, data is stored and retained for 7 years in the Compliance Centre. They can be accessed and retrieved at anytime from the platform. We have full coverage of record-keeping in line with the regulations.
  3. Can compliance data be shared across professionals to avoid duplication? Yes, we can facilitate this through our Reliance offering. The Reliance process allows professional firms, such as law firms and real estate agencies, share AML checks via a secure portal. This means your clients aren’t asked for the same information twice, transactions move faster, and your obligations are met without the added workload.

Share