Now that Australia’s expanded AML/CTF obligations have taken effect, law firms are adopting technology to help manage customer due diligence, identity verification and client risk.

Technology will undoubtedly play an important role in helping the legal profession implement the new regime. But an emerging issue deserves closer attention.

What happens when AML/CTF software dictates how a lawyer must verify a client’s identity?

In particular, some digital verification workflows require clients to complete biometric facial verification as the standard or mandatory pathway to proceed.

Biometric verification can be a useful tool. In appropriate circumstances, particularly where a client is being onboarded remotely or where the circumstances create heightened identity risk, it may provide valuable additional assurance.

But there is an important distinction between making biometric verification available and making it mandatory in every case.

Australia’s AML/CTF regime does not impose a universal legal requirement that lawyers use facial biometrics to verify every client.

The framework is risk-based.

AUSTRAC’s current customer due diligence guidance requires reporting entities to establish relevant KYC matters on reasonable grounds and to assess customer risk on a case-by-case basis, using the KYC information reasonably available and the ML/TF risk factors identified. Initial customer due diligence is intended to help the reporting entity decide what it needs to do to manage and mitigate the risks associated with providing a designated service.

This raises a difficult question.

If the software only permits one method of identity verification, is the law firm still genuinely applying its own risk-based approach?

The software vendor should not make the risk-based decision

Consider a client who has instructed the same law firm for 15 years.

The partners know the client. The firm has acted on previous transactions. The client attends the office and presents an original passport and driver licence. The information is consistent with the firm’s existing records and the circumstances of the engagement present no unusual identity concerns.

The client is then told:

“You must photograph your identification and complete a facial biometric check through a third-party platform.”

The client asks a perfectly reasonable question:

“Why?”

What is the answer?

Is biometric verification necessary because of the particular ML/TF risk presented by that client?

Or is it necessary because the firm’s software has been designed around a single digital verification pathway?

Those are not the same thing.

The risk-based approach requires the reporting entity to identify, assess, manage and mitigate ML/TF risk. It requires judgment.

Technology should support that judgment. It should be approached cautiously where its design effectively makes the judgment for the practitioner.

Clients may simply refuse

There is also a commercial reality that law firms should not overlook. Some clients do not want to provide facial biometric information. That does not necessarily make them suspicious, difficult or non-compliant.

A client may be concerned about data breaches. They may be uncomfortable providing facial images to a third-party technology provider. They may have concerns about offshore data handling. They may not understand how a biometric template is created, used or retained.

Others may simply hold a principled view that they do not wish to provide biometric data unless it is legally required.

Where a law firm or its technology provider is subject to the Australian Privacy Principles, the collection of personal information must be reasonably necessary for its functions or activities. Additional requirements apply to sensitive information, including biometric information used for automated verification or identification. Law firms therefore need to think carefully about the intersection between AML/CTF compliance and privacy.

The question should not simply be:

“Can our software collect biometrics?”

The better question may be, “Why are biometrics appropriate for this client and this engagement?”

If the only answer is, “because the software requires it”, firms should consider whether their technology is driving their compliance methodology rather than supporting it.

There is also a genuine risk to the professional relationship.

A longstanding client who is told that they must submit to facial biometric verification may simply refuse.

If the firm offers no alternative pathway, that client may leave.

The result could be the loss of a trusted professional relationship not because the AML/CTF Act required biometric verification, and not because the client presented an unacceptable ML/TF risk, but because the firm’s software did not permit the lawyer to exercise judgment about an appropriate verification method.

That deserves serious consideration.

Risk-based does not mean less rigorous

None of this means that law firms should adopt weak identity verification processes.

Quite the opposite.

A risk-based approach requires firms to think more carefully about the level of assurance required in the circumstances.

A new client instructing a firm remotely from overseas may require a different verification approach from a longstanding local client attending the firm’s office with original identification documents.

A client with inconsistent information may require further corroboration. A complex corporate structure may require independent company records and detailed beneficial ownership analysis.

A higher-risk client may require additional KYC information and enhanced customer due diligence. AUSTRAC’s guidance expressly contemplates verification appropriate to ML/TF risk and, in enhanced CDD, obtaining or verifying additional KYC information from independent and reliable sources where greater certainty is required.

That is the point of a risk-based framework.

Different risks may justify different controls

Applying the same verification method to every client may appear consistent. But consistency and risk sensitivity are not always the same thing.

A uniform process can be administratively convenient while still failing to reflect the particular circumstances of the customer and designated service.

Firms can also explore different verification approaches using our Identity Verification Pathway Explorer.

Lawyers already understand professional judgment

The legal profession should be particularly alert to this issue. Lawyers routinely make judgments about evidence.

We assess whether information is reliable. We identify inconsistencies. We seek corroboration. We distinguish between matters that require further enquiry and matters that do not.

AML/CTF compliance does not remove those skills. It requires lawyers to apply them in a structured and documented way.

For instance, a lawyer may sight original identification documents in person. Another client may provide certified copies. A remote client may complete electronic identity verification. In another matter, a combination of independent and reliable sources may be required because the information provided raises uncertainty.

AUSTRAC’s own guidance recognises that customer identification does not always fit a single standard pathway, including alternative processes for individuals who do not have standard identification documents.

The important issue is whether the firm can explain what information it obtained, how it verified relevant KYC information, why the process was appropriate having regard to the ML/TF risk and what further steps were taken where uncertainty remained.

That is professional judgment and it should remain with the reporting entity.

Technology should support judgment, not replace it

AML/CTF software has the potential to significantly reduce the administrative burden facing law firms.

It can structure workflows, identify missing information, assist with beneficial ownership, screen for PEP and sanctions exposure, guide enhanced due diligence, record approvals and preserve an audit trail.

Critically, technology should not automate away the very judgment that the risk-based regime requires.

Biometric identity verification should be available where it is appropriate. For some clients, it may be the preferred verification method. For others, it may provide an important additional control.

But law firms should ask whether their AML/CTF systems allow them to select and document a verification approach that reflects the actual risk presented by the client and engagement.

Flagship AML’s AML/CTF software for law firms supports multiple identity-verification pathways and records the firm’s risk-based decisions.

The new AML/CTF regime does not simply require lawyers to run checks. It requires firms to identify risk, assess information, apply appropriate controls and be able to explain their decisions.

If your AML/CTF software only permits one answer, one pathway and one verification method, it may be worth asking a difficult question: is the software supporting your professional judgment, or quietly replacing it?

By Dan Ward and Amira Ward
Co-founders, Flagship AML

Dan Ward and Amira Ward are lawyers and the co-founders of Flagship AML, an AML/CTF compliance platform designed for Australia’s newly regulated professional services.

This article is commentary only and is provided for general information. It is not intended to be, and should not be relied on as, legal advice. AML/CTF obligations depend on the specific services, structure and circumstances of each business. You should obtain legal or professional advice before acting or relying on this information.

© 2026 Flagship AML. All rights reserved.