“If someone wanted to learn about my business, I would much rather get on a call and talk to you about it than I would sitting through a Word document answering forty questions.”
Annature founder Corey Cacic and host Trent McLaren tackle the AML tranche two risk-assessment requirements landing on 1 July. Rather than send clients yet another sixty-five-question form, they propose capturing the same information conversationally during a recorded onboarding or discovery call, then using AI to generate the risk assessment from the transcript.
Trent demos the workflow end to end: an AML toolkit page with a pre-meeting agenda and post-meeting checklist, a prompt dropped into Vinyl’s AI chat (or Claude/ChatGPT/Copilot) that produces a risk rating with supporting evidence in under ninety seconds, and an auto-drafted follow-up email requesting whatever the meeting didn’t cover. Corey argues the ID, PEP and sanctions checks should run first, because the outcome steers the conversation and can deter onboarding before you invest time.
Corey then walks through how Annature houses the program, compliance officer, audit log, staff-training acknowledgements and review schedule, syncing with Xero Practice Manager so each client shows ID, AML/CTF screening, ongoing monitoring and risk rating at a glance. Low-risk clients get a multi-year review cadence; high-risk clients flow into a senior manager approvals register for enhanced due diligence. He’s deliberately stripping the bloated AUSTRAC starter kit of irrelevant sections to keep the program practical.
The broader theme is using AI to work across multiple layers of context — meetings, documents, and soon emails and SharePoint files — to convert messy, unstructured input into structured compliance output faster. Annature plans a dedicated AML webinar the following week, and Corey is candid that if AI-generated assessments don’t land in practice, they’ll build a questionnaire instead.
Key lessons
- Treat the risk assessment as a conversation, not another client questionnaire — you're already halfway there in a discovery call.
- Run the ID, PEP and sanctions checks first; the result steers what you ask and may deter you from onboarding.
- Record the onboarding call, feed the transcript a prompt, and AI drafts a risk rating with evidence plus a follow-up email for missing items in under two minutes.
- Risk rating drives what happens next: low risk gets ongoing monitoring and a ~3-year review; high risk triggers enhanced due diligence and senior manager approval.
- The real win is letting AI work across layers of context — meeting, documents, emails — to turn unstructured data into structured output faster.
- Strip the AUSTRAC starter kit of irrelevant fluff and keep the program simple while staying compliant.
Tools mentioned
Resources & links
- Annature tool
- Vinyl tool
- ContentSnare tool
- AUSTRAC tranche two starter kit reference
- 10:06 “If someone wanted to learn about my business, I would much rather get on a call and talk to you about it than I would sitting through a Word document answering forty questions.”
- 13:11 “It's all well and good to be sitting down, meeting with a client, having a discovery call for thirty minutes, and everything looks good. After the fact you send them an ID, and it comes back that they're on a sanctions list.”
- 29:23 “I recorded a meeting. I've given it a prompt, and we had a risk assessment inside ninety seconds. I had an email twenty seconds later that said, based on what we spoke about, here's the things that I'm missing.”
- 31:42 “I can probably confidently tell you I've never spoken to any accountant who has received a cash payment of more than ten thousand dollars before.”
Corey Cacic — Founder & Lead Developer, Annature
with Trent McLaren — Host, Vinyl
04:22Why this session: easing the AML risk-assessment burden
The purpose of this session is to talk through the different ways you could be using AI to help with your AML burden and the workflow issues coming up around the tranche two requirements that go live on the first of July.
Corey called me about four to six weeks back, and we had a really good chat. He had this idea: what if we could capture a lot of the questions and information you need to ask of your client in a meeting, then use AI to unpick everything we have and haven’t captured, and then get that information into Annature to help verify it on the other side?
You don’t necessarily have to use Vinyl or Annature, but they’ll be the examples we run through today. We want this to be educational for everyone, so use your imagination. We’re not saying you have to use those systems, but we’re going to use them as examples for you to look at and play around with.
05:11Meet Corey and Annature
I’m Corey Cacic, founder and very much still the lead developer at Annature. For those who haven’t heard of us, we’ve been in what I call the Xero ecosystem since 2020. We launched as an e-signing tool to really just take on DocuSign. Six years ago the landscape was very different — virtually everyone was using DocuSign and the price firms were paying was just ridiculous. We’ve taken a lot of businesses off DocuSign, which is awesome.
From e-signing, we moved quickly into ID verification in 2022, off the back of the TPB and the ATO requirements for client verification, which just about everyone is doing now. We’ve been working pretty quietly for the last few months expanding that to cater to the tranche two requirements that are coming out.
07:39The problem with treating risk assessment as just another questionnaire
When all of this came about more than twelve months ago — and particularly over the last twelve months — we saw a lot of noise: a lot of products with new solutions, a lot of educational pieces, all on what the tranche two changes mean for you. The item that stood out for me was this risk assessment piece. Accountants providing designated services for clients need to conduct a risk assessment, and virtually everyone assumed that meant sending a questionnaire to clients.
The purpose of those questions is to establish what sort of business they operate, where their source of funds is coming from, who the UBOs are, who’s benefiting from the income, what their suppliers look like, whether they have suppliers in Russia or the Middle East. You’re looking for answers that help you establish what risk the business poses when it comes to money laundering and counter-terrorism financing.
Everyone I saw was building this around a questionnaire, and I just know for our customers — we have over two thousand accounting or bookkeeping firms using Annature for ID verification — the feedback on sending another questionnaire would be: “Really? It’s another thing I have to ask my clients to do.” Getting clients through an ID process alone was a big shift for firms. There are all these hoops we have to jump through before we can actually start doing what we’re here to do, which is serve clients and help businesses run more efficiently. The risk assessment just looked like another thing you have to send, chase up, and make sure they’re filling out correctly. There has to be a better way.
10:06Flipping it: capture risk during the conversation, not on a form
The phone conversation we had was: rather than look at what a risk assessment is, let’s look at the purpose of it. What are you looking to achieve? You’re looking to assess the risk of the client — does this client pose any risk in terms of money laundering and counter-terrorism financing?
When you meet with a client, whether face to face or over Zoom, you’re kind of fifty percent of the way there already — talking to the client, getting to know them, learning about their business. These are questions you naturally have when you meet someone. So if we’re already fifty percent of the way there, what can we do to bridge that last fifty percent and capture it verbally? If someone wanted to learn about my business, I’d much rather get on a call and tell you about it than sit through a Word document answering forty questions.
In the chat, feel free to jump in on how you’re planning to solve this. Are you thinking of an onboarding form? We do recommend that too — great tools like ContentSnare work well for that. But the other side of it is: if you’re going to sit down for an onboarding or discovery call, can you ask a bulk of these questions in the meeting and capture them in your transcript? That’s what we want to show today.
11:44The AML toolkit and end-to-end workflow
We’ve created a few resources for you to check out. The first is an AML toolkit document we’ll put into the chat. It covers who’s affected, how we think this whole flow fits together, and the workflow end to end.
The AUSTRAC information runs to something like sixty-five questions — it’s quite lengthy. Our proposed flow is: book the meeting, have the meeting, do the risk assessment, then upload and file the assessment in Annature. We’re about to go live with a calendar scheduling tool in Vinyl at the end of June, so if you’re not using Calendly or Microsoft Bookings you’ll be able to book with a Vinyl link. You can run the risk assessment in Vinyl, or you can do it in Claude — I’ve got all the prompts for that — and then do the assessment in Annature. We’ll show both today.
13:11Why the ID check should come first
Doing an ID check and running AML and CTF checks is still definitely something that needs to be done. Right now everyone is just doing the ID check to cite an ID document and verify it’s legitimate, but that expands into running an AML and CTF check that tells you whether this person is on any sanctions list or is a politically exposed person.
In terms of order, when it comes to these risk assessments I think it makes sense to do the ID check first, because the outcome may guide what questions you ask. It’s all well and good to sit down for a thirty-minute discovery call where everything looks good, then send the ID afterwards and find they’re on a sanctions list, have been convicted of financial crime, or are a PEP. That would prompt going back to the client for more information or doing enhanced due diligence. Doing the ID check first helps you understand whether the client is a PEP, works in government or council, or has been convicted of financial crime — and in some cases it may immediately deter you from working with the client, or otherwise steer the questions you ask during the discovery call.
15:24Prepping the meeting: the pre-meeting agenda
So if you’ve done the identity verification and it comes back low risk, you can go into more detail to capture everything else. We’d recommend sending a pre-meeting agenda. You could use Claude or Vinyl’s AI chat to help with this.
The agenda has different steps: the setup (what the meeting is about, why you need to cover it, that you think you can get it done in thirty to forty minutes), the about-business section, ownership and control, trust structures, the services they’re engaging you for, source of funds and wealth, PEP and sanctions checks, ongoing relationship, what to bring to the meeting, and confidentiality — all information is collected, stored, and securely used for our compliance obligations.
This isn’t necessarily a linear path, because it depends on when you find out certain bits of information. Some of it might land after your scope and discovery, or be baked into discovery. On the link in the chat you can open the agenda in Gmail or Outlook; if the email shows blank, hit the copy button and the whole agenda is already in your clipboard, or click “copy as email” and paste it in. In the spirit of vibe coding, I’ve vibe coded this whole page to make your life a little easier.
16:58Running the meeting and capturing the answers
Once you’ve sent the agenda, the next part is running the meeting. On the page you can tick the things you’ve done, reset it, or print a document version. It’s long, and the things you don’t answer might be the ones you then chase in your onboarding form. But you can go through a lot of it live — what country, cited the passport, the name and address, who you’re acting on behalf of. You might answer some of it as you go, or at least talk to all of it.
If you’ve successfully asked these questions and captured them in your transcript — the meeting recording — you’ll have a lot of information to generate your risk assessment. There’s also a post-meeting checklist at the bottom. The prompt Corey and I worked on can go into Claude, ChatGPT, or Copilot, or into Vinyl.
On the question of charging: a lot of people on recent webinars say they’d charge for this meeting, or at least mark it up in their services, because there’s a real time and cost to doing this. I think you should be charging or finding a way to recover that cost.
19:11Live demo: generating the risk assessment in Vinyl
This is a meeting I had with Amy Holdsworth. Inside Vinyl there’s an AI chat that works across all your meeting transcripts. I paste the prompt in and it generates the AML risk assessment based on the recorded meeting, in real time.
The report first gives a risk recommendation — here, the recommended risk rating is low — and then explains why, citing the evidence. The AI has looked at the transcript, gone through all the information covered, and made its assessment. It captures what was discussed and flags what was not discussed as “to be completed.” You get a really nice long report based on all the questions asked, generated within minutes of the meeting finishing. If you’ve done it in a thirty-minute call, you’ll have all of this the moment the meeting is processed.
Here’s a PDF I created earlier: “AML Client Risk Assessment — read this first.” Based on the meeting, we believe the client is low risk, and it gives the evidence. It tries to answer all the questions from our checklist, except we’ve done it in that thirty-to-forty-minute window. This may also be easier when the client isn’t sure, given the way AUSTRAC has worded some of those questions.
Once it’s done, we can draft a follow-up email: “Hey Amy, great catching up — to wrap up the compliance we need a few extra things.” Based on what we could and couldn’t answer, it drafts the request. That could be an email, or it could go into a form-based system like ContentSnare or Onboard Me.
22:12After the assessment: enhanced due diligence and ongoing monitoring
The next step after the risk assessment depends on the risk rating. In Annature, one of the AML/CTF programs we help generate defines that when a customer is identified as high risk, it needs to go through senior manager or compliance officer approval, and you treat that client with enhanced due diligence — doing more than you would for an ordinary client.
For a normal Australian business that isn’t a PEP and is very stock-standard — which most of the time will be the case — it’s low risk. You still do your initial CDD (the PEP and CTF checks you’d have done before the meeting), enrol the client in ongoing monitoring, and set a review cadence of around three years. The AUSTRAC starter kit suggests something like every three years you sit down, review the client, make sure their business operations and suppliers are still the same, record that you did the review, and keep going. For clients that come back high risk, additional things then need to happen, and that’s what we’re looking to capture in Annature.
23:51Annature as your AML toolkit: program, training, audit log
What we’re building with Annature is designed to be your AML toolkit. We want to help you generate an AML/CTF program, your risk assessment procedure, and your identity verification procedure — and the recommended procedure for a risk assessment is to record it with Vinyl on an onboarding or discovery call.
Annature houses those documents and records who your compliance officer is, so we can help you monitor the review schedule and keep an audit log of every time your program changes — whether from a scheduled review or a considerable change in your organisation.
The other piece is staff training. You can add all your staff into Annature as participants in your AML program, send them the policy documents, and have them acknowledge they’ve read and understood them. Staff training on a predefined cadence — every three, six, or twelve months — is another key piece of tranche two, and we’re looking to house all of it in Annature.
25:21Tying the risk assessment into practice management
Assuming you’re using Annature to send the initial identity verification request and you’re using XPM (Xero Practice Manager), which we have available today — you can open a client and at a glance see whether you’ve done an ID check and what the results were.
Looking at a Hugh Goodman client synced from XPM, we can see an ID check done, an AML and CTF screening (your AML check) done, and ongoing monitoring turned on. What’s missing is the risk assessment — this client doesn’t yet have a risk rating. This is where you upload the PDF that comes from Vinyl or any other tool. If you’re using ContentSnare to capture information before the meeting, provided you can get it into PDF format, you can upload it to the client. By analysing that document, we’ll assume a risk rating, or you can go in and change it yourself.
Based on that rating: if it’s low, we can set the next review for two or three years out. If it’s high, the review schedule becomes a lot more frequent and the client goes into the senior managers’ approval register.
27:48The senior manager approval register
On the AML program, your compliance officer or senior managers — whom you define in Annature — get an approvals register listing all the clients defined as high risk. You go in and review them. The purpose is to first identify what greater risk they pose based on their position or the nature of their business, confirm whether enhanced due diligence has been conducted, and have a senior manager identify whether there’s a way to mitigate the risks raised, or conditions to working with them. Based on the different designated services you provide, you may decide there’s a service you don’t want to offer because it carries greater risk. The register tells you when the next review is scheduled — all of it driven by what we capture through the risk assessment.
In summary: getting the risk assessment, whether through a meeting recording or a questionnaire, is all well and good — but there are then steps that need to happen based on the outcome, and the question is what you’re using to capture, record, and monitor those additional steps. That’s what we want to do at Annature.
29:23The real point: letting AI work across layers of context
Coming back to the topic — how do we use AI to generate our risk assessments — the real benefit is grabbing multiple layers of context: the meeting context, the document context, the questions we needed to ask, and how we produce the risk assessment on the back of it. Paul’s question was whether you could bring information from the form into the meeting transcript and produce something out of both — yes, that’s exactly how I want you all to think about this.
My hope for everyone when we run sessions like this isn’t just “let’s use AI, let’s build fun tools.” It’s expanding the thought of how we let AI get amongst all the different context layers available to it, so it can take messy, unstructured data and help us produce structured information faster.
I recorded a meeting, gave it a prompt, and had a risk assessment inside ninety seconds — and an email twenty seconds later listing what I was missing and requesting it. Without AI this would have taken fifteen, twenty, thirty minutes or longer, and you’re busy. The best use case for AI, for me, is everything around admin and processing — helping you get things done much faster and automatically. We’ve had sessions all day on daily morning briefings and automatic emails. By the time I wake up at nine AM, my AI has already been through my inbox, drafted my replies, and marked off the things that were done — like having an admin sweep through all the junk you don’t need.
For now this is largely text-based — copy and paste — but we’ll move to documents, MD files, and storage that AI can grep and access: your Dropbox, your SharePoint. Email integration goes live next week, so your emails can be fetched into Vinyl, your meetings are already fetched, your documents fetched from SharePoint — and the AI takes all those context elements to produce whatever the output is.
31:42Building the AML program without the AUSTRAC fluff
The first phase of the Annature AML module will probably be ready next week, focused on building a program. We have a questionnaire that asks about your firm and what designated services you provide, and off the back of it produces an AML/CTF program.
The AUSTRAC starter kit comes with a templated program — about forty-six pages — and reading through it is painful. It covers so many things that just aren’t really relevant to the accounting industry. Tranche two isn’t only for accountants; it’s expanded into real estate, conveyancing, professional financial advisors and more. One of the keys in the AUSTRAC kit is threshold transaction reporting — there’s an entire section on what to do if you receive cash payments greater than ten thousand dollars. I can confidently say I’ve never spoken to an accountant who has received a cash payment of more than ten thousand dollars. So does that section just become fluff? Are we creating a program with extra complexity for use cases that practically don’t make sense in our industry?
There are other tools doing a full AML module that I think are blown out with features and registers — like where you record information when you receive a cash payment. If our audience isn’t doing that, why include a module for it? You end up with a product over-complicated with bells and whistles that don’t get used.
The program we generate is contextualised to your questionnaire answers and the services you provide. It gives you a purpose, talks about related procedure documents (how you do a risk assessment, how you do verification), defines the compliance officers, and has practical steps on how you identify a client and what information you ask for. After you generate a program, a review schedule goes in: your compliance officer reviews it at a predefined cadence, and you train all your staff on it.
36:27What “training” really needs to look like
Training hasn’t really been defined or tested yet. Some tools have an interactive quiz where you answer twenty multiple-choice questions, and once you get them all right you’re deemed trained. Practically, I don’t think people will do this — it becomes such an overhead.
What I think it comes down to is: if you’re asked how you train your staff, you can say you sent the staff member an email on this date, they opened it, they clicked a button to acknowledge it, and you have all of that in an audit log. That, to me, is training staff. We can bulk-add all your staff and, in one click, send out the policy documents. Staff see the documents on screen the same way they’d sign a document, click a button at the end to acknowledge they’ve read and reviewed the program, and we record it. That’s the first component of the AML module, and keeping it simple is the most important part — as long as we’re still compliant and following the rules.
37:55Audits, fines, and a dedicated Annature webinar
This is one of those things we’ll evolve with. As it comes into effect, I’m sure we’ll all start hearing stories about whether people followed the procedures and whether anyone got in trouble. There were good questions in the chat about generating the register to lodge your annual report and pass your three-year audit with AUSTRAC, and about compliance with legislation — you risk a thirty million dollar fine otherwise.
As we go into the broader product, we’re going to dedicate an entire webinar to that. The email that goes out after this session will have details about an Annature webinar where we go into these additional steps. We wanted to focus today on the risk assessment and where AI capabilities exist in practice.
39:23Designated services: the threshold question
In summary, there are a few ways to capture all this information. We recommend some sort of onboarding flow, and doing the ID check first — because if they flag as medium to high risk, you may want to avoid doing the rest of your onboarding flow in the first place. This has been live in the UK for a number of years, so it’s been painful for them for a long time. There won’t be an easy way out, but there will be easier ways to capture the information.
The one counter to doing the ID check up front is that you may not know, when first engaging a client, whether you’re providing a designated service. This whole process comes down to whether you’re providing a designated service for that client — if you’re not, you don’t need to do any of this; the whole thing goes out the window. But in most cases you should know: clients don’t just say “can we talk, I want to do business.” It’s “I need help managing my company,” “I need help doing tax returns,” “I need help setting up a company.” So it’s something we’re thinking about — not always required upfront, but it just makes sense, because the outcome steers the conversation you have.
41:42How to reach Corey, and the next steps
If you’ve got strong opinions or feedback, the contact form on our website still comes to me and the broader team. Our website is annature.com.au. If you’re a user, we have a live chat in the bottom right, and I get notified for every single live chat that comes through the app.
Next week is when we’ll do our first webinar on Annature AML. We did a release log last week acknowledging we’ve been quiet on it, and why we decided not to leave it to the last minute but let everyone else get in first, do the education piece, show what other products are out there, and then talk about what we do and don’t like or what could be done differently. That webinar will be interactive. The questions being asked today are exactly the sorts we want to hear — we may not have a solution for everything, and it’s through these conversations that I learn what to build, what’s missing, and what’s working well.
And if it turns out that using AI to generate a risk assessment just doesn’t work for whatever reason, then we’ll go and build a questionnaire. These are all things we noodle on.