Skip to main content

Ignition Compliance (AU) (Early Access)

Written by Nicole Baptiste

Stay on top of your AML/KYC obligations without leaving Ignition. Compliance helps Australian practices verify client identity and conduct due diligence before delivering in-scope services, keeping your workflow in one place and giving you a clear audit trail.

Ignition Compliance is available in Early Access to practices
in Australia and the United Kingdom.

This article describes the Australian experience, and the regulatory references in it are specific to Australia. United Kingdom practices should refer to the United Kingdom version of this article.

This feature is currently available on Core, Pro, and Pro+ plans.

It is currently rolling out in early access via Labs.


Before you begin

Compliance is an opt-in feature. Before enabling it, make sure:

  • Your practice has multi-factor authentication (MFA) set up. Ignition will enforce MFA on your practice as part of enabling Compliance.

  • You have admin access to your Ignition account.

Ignition Compliance is designed to support your due diligence workflow — it is not legal advice. For guidance specific to your obligations under AUSTRAC Tranche 2, speak with your compliance advisor.


Interactive Demo

demo gif


How to enable Compliance

  1. Go to Settings → Labs.

  2. Find the Compliance card and select Get started.

  3. Read and acknowledge the information, then confirm to enable the feature.

  4. You'll be taken to the Compliance setup wizard, where you can:

    • Choose one or more Compliance Managers — team members who will receive notifications, action review items, access audit trails and verification PDF's.

    • Set a compliance notification email for your practice

Once set up, Ignition will run in the background to recommend which services in your library may require client verification.

Reviewing your service classifications

Ignition analyzes your services — including service name, description, and category — and recommends which ones may require client verification under AML/CTF obligations.


You'll see verification badges appear on services in your Services library. From there you can:

  • Accept a recommendation — confirming that the service requires verification

  • Change the verification package — choose between Identity verification, Enhanced verification or Enhanced Verification with entity & ownership collection (see below)

  • Remove a classification — if you've determined a service does not require verification

  • Manually add a classification to a service that wasn't flagged automatically

Ignition's recommendations are a starting point based on service wording and category. They are not a definitive determination of your compliance obligations. Always review classifications against your own compliance policy and advice.

Verification types

There are three verification types. You choose which one applies to a service or client.

Package

What it covers

Standard identity check

Identity verification + AML screening

Enhanced identity & AML/CTF check

Identity verification + business registry lookup + KYB collection + AML screening

Enhanced identity & AML/CTF check with entity & ownership collection

The same Enhanced check, plus collection of entity, ownership, and control details, with follow-up checks for additional directors or beneficial owners. Gated to the Pro plan and above.

Your classification choices are saved — they won't be overwritten if the recommender runs again in future.


Pricing

Compliance has no separate feature fee. You pay per check only:

  • Standard identity check: $6 AUD

  • Enhanced identity & AML/CTF check: $10 AUD

  • Enhanced check with entity & ownership collection: $10 AUD (Pro plan and above)

Compliance is included on the Core, Pro, and Pro+ plans.


Sending a proposal with Compliance

Once Compliance is enabled, proposals that include classified services will show a Verification required badge on those services in the proposal editor.

At the Send step, you can choose which verification type to request. In the instance where a send is blocked, Ignition explains the compliance blockers and the actions needed before you can send. A client-facing verification request is only created when you explicitly choose to send one.

Compliance does not block you from sending, signing, or accepting a proposal, or from collecting payment. The verification step happens after your client accepts.


Your client's experience

After your client accepts a proposal, they'll see a Client Verification checklist directly on their acceptance confirmation screen.


The checklist walks your client through the verification steps entirely within Ignition. They won't be redirected to a third-party site or see any provider-specific language. From your client's perspective, it's a seamless part of the Ignition experience.

Your client will also receive an email with a link back to the checklist if they need to return to it later.

If a client doesn't complete verification straight away, you can resend or regenerate their verification link from their client record.

Communicating the changes with your clients

For Australian practices, AML/CTF verification is a new step for many clients, so a short heads-up can go a long way in setting expectations and avoiding back-and-forth. Below are two templates you can adapt (one for a standalone email, and one for a short note inside your proposals).

Please note: These are optional starting points, not legal or compliance advice. Adjust the wording to suit your firm's voice and your obligations, and check with your compliance advisor if you're unsure what to include.

Email template

Use this to give clients advance notice of the new identity verification requirements before you send affected proposals.

_______________________________________________________________________

Subject: Changes to how we verify your identity

Hi {{First Name}},

From 1 July 2026, if you engage us for certain services that are regulated under Australia's anti-money laundering and counter-terrorism financing (AML/CTF) laws, we're required by AUSTRAC to verify your identity before we can provide those services.

These requirements apply to all Australian accounting and bookkeeping firms offering these designated services. You can find more information, including which professional services are covered, on AUSTRAC's website.

What this means for you

If the services you've requested require verification, we'll send you a secure request to complete the process. Depending on your circumstances, this may include verifying the identity of individuals and businesses, as well as completing regulatory checks such as politically exposed person (PEP) and sanctions screening.

To help avoid delays, we encourage you to complete your verification as soon as you receive the request. By law, we're unable to commence work on affected services until the required verification has been completed and approved.

We understand this introduces an additional step to the onboarding process. However, these requirements are mandated by AUSTRAC and apply consistently across the industry — they're not unique to our firm.

If you have any questions about the new requirements or the verification process, please don't hesitate to get in touch. We're committed to making the process as simple and seamless as possible.

Kind regards,

{{Firm Name}}

Proposal Intro Message Paragraph

Add this short note to the intro message of proposals that include services requiring verification, so clients know what to expect at acceptance.

_______________________________________________________________________

Please note: To comply with Australia's AML/CTF laws, some services require us to verify your identity before we can begin work. If verification is required, you'll be prompted to complete it as part of accepting this proposal. We recommend completing it promptly to help avoid any delays to your engagement.


Verifying companies and entities (KYB)

The Enhanced check with entity & ownership collection (Pro plan and above) lets you collect a company's entity, ownership, and control details, and run an Enhanced AML/CTF check on the recipient.

If you need to verify specific people, you can send follow‑up checks to additional directors or beneficial owners. These company verification checks use official business registries and support director identification.

How the multi-owner (entity & ownership) flow works

When you send an Enhanced check with entity & ownership collection, it helps to know which party is responsible for which step.

1. Your client lists the owners (not you)

As part of completing their verification, your client fills in the company's directors and beneficial owners themselves. You generally don't need to add these people manually beforehand.

Pre-adding them usually creates duplicate requests (and duplicate charges) once your client enters the same people through their form.

2. Ignition creates the follow-up checks automatically, but doesn't send them.

Once the entity verification is complete, the directors and beneficial owners your client listed appear as associated parties on that client's Compliance tab, and are counted in your Home action-required summary.

Ignition creates a follow-up check for each of them, but does not send these automatically. This is intentional: because owner details are entered by your client, you get a chance to review them before any check (and its cost) is sent.

3. You review and send each follow-up check

Open your client's Compliance tab, review the associated parties, and:

  • Send a check to each person who still needs to be verified, and

  • Mark as "not required" for anyone who doesn't need to be verified
    (For example, the primary contact who already verified as part of the entity check, or someone verified on another engagement. This is how you avoid duplicate checks and charges.)

Until you send these follow-up checks, the owners won't receive anything, and their verifications will stay outstanding.

To stop one person's check, use Mark as not required on that individual. Note that cancelling the request at the top level cancels it for everyone on that entity, including anyone who has already completed their part.

An entity check can show as complete once the primary individual has been verified, even when the directors or beneficial owners your client listed have not been checked yet. We recommend reviewing the associated parties on the Compliance tab before you treat an entity as fully verified.

Short communication template for your clients

When you complete the company verification, please list all directors and beneficial owners accurately. Each person listed may receive their own short identity check by email. If the person completing the form is also an owner, they generally won't need to verify twice. We will manage that from our end.

Please note: Some capabilities for complex structures are still being built (e.g. linking non-director persons of authority, bulk group-level verification for larger corporate/family-group structures..etc)

Please check in with our Support team or watch out for future updates on this feature.


Bulk verification

You can send verification requests to multiple clients at once. To do this, navigate to your Clients tab and select all the clients you wish to bulk verify.

Then, click More actions → Request verification to start the process.

Note: The bulk verification feature is only available on the Pro plan and above.


Reviewing verification results

Once your client completes their verification, the result will appear in the Compliance section of your Ignition navigation (between Clients and Services in the main menu).


The Compliance workbench shows separate queues for:

  • Review required — results that need your attention before proceeding

  • Client action pending — waiting on your client to complete their steps

  • Verified clients — a register of completed verifications for your records

  • Delivery blocked — agreed services that are currently on hold pending verification

  • Failed / expired / cancelled — results that did not complete successfully

Your Ignition Home dashboard also shows a summary count of any compliance actions that need attention.

For Enhanced (Tranche 2) checks, the verification result also displays an AUSTRAC AML/CTF policy assurance section, indicating that the relevant checks have been carried out.


When a result needs your review

Some results will require you to make a judgment call before the agreed service can proceed. In these cases you can:

  • Approve the result and allow service delivery to proceed

  • Reject the result and decide not to proceed with the service

  • Mark as not required — if you've determined verification is not needed for this client or service

  • Record an override with a written rationale for audit purposes

Risk levels (Low / Medium / High) are provided as evidence to inform your decision, not as a final recommendation.

When a service is blocked for delivery

After a proposal is accepted, any agreed services that require verification are blocked for delivery until verification is complete and satisfactory.

You'll see these in the Delivery blocked queue in your Compliance workbench. The block clears automatically when:

  • Verification passes and no review is required

  • You approve a result that needed advisor review

  • You mark the requirement as not required, with a recorded rationale

Delivery blocking is applied to the agreed service — it does not affect billing, invoicing, or payment collection.

Your Clients tab can also show Delivery blocked separately from verification status, so you can spot clients who are verified but still blocked because an enhanced check is needed.

Pre-commencement clients (NEW)

Clients you already worked with before AML/CTF commencement are treated as pre-commencement clients. You don’t need to re‑check every one of these clients straight away. Instead, you only need to run a new check when something in the relationship changes (e.g. a new designated service, higher risk, or suspicious behaviour). When to run that check is ultimately up to your practice and your compliance adviser.

To help you review these clients easier, Ignition provides:

  • A Client relationship filter in your Clients tab (select Pre-commencement to see existing clients that pre-date the compliance start date)

  • A banner on the client record flagging a pre-commencement client.

  • Pre-commencement evidence on the client's Compliance tab, showing the evidence date, source, source record, and compliance start date — provided as context, not as a legal status.

Pre-commencement clients without a verification request are not treated as delivery-blocked. This visibility is an early version and will continue to be developed.

Verifying existing clients

For clients you're onboarding outside of a new proposal — such as existing clients you've worked with before — you can send a verification request directly from their client record.

Navigate to the client record → Compliance tab → Request verification, then choose the appropriate verification package.


The client will receive an email with a link to complete their verification in the Ignition portal.


Records, exports, and permissions

Ignition stores the outcome and status of each verification. Raw identity documents, biometrics, and detailed provider reports are not stored within Ignition. Verification records are retained for your audit trail, and each verification is recorded as a separate entry on the client's Compliance tab.

You can export and access records in several ways:

  • Compliance register CSV export — a practice-wide view of requests, review candidates, evidence context, delivery state, and latest activity. Navigate to your Compliance tab → Export CSV.

  • Services CSV export — now includes Compliance classification columns, so you can review which services require checks and what type. Learn more here.

  • Per-verification PDF — accessible to users with the Compliance Manager permission.


FAQs

Does enabling Compliance affect my existing proposals?
No. Compliance applies to proposals created after you enable the feature. Existing accepted proposals are not affected.

What if my client can't complete verification online?
You can record a manual override with a written rationale directly in the Compliance workbench. This is intended for situations where a client has already provided verification by other means (e.g. in person).

Can I upload my client's ID documents for them?

No. Your client completes the verification themselves, including uploading their own documents. Uploading documents on a client's behalf is not supported. If a client cannot complete verification online at all, record a manual override with a written rationale in the Compliance workbench.

Can I turn Compliance off after enabling it?
You can pause Compliance from Settings → Labs. Existing verification records are retained and any in-progress provider checks will still be reconciled for audit purposes. Note that MFA will remain active on your practice after pausing.

Will my clients see any third-party provider branding during verification?
No. The verification experience is fully embedded within Ignition. Your clients will only see Ignition branding and plain-language instructions. There is no third-party provider names or technical terminology.

What's the difference between Identity verification and Enhanced verification?

The Standard identity check verifies a government-issued ID document only. It does not include AML/CTF screening, and satisfies ATO/TPB identity requirements but not, on its own, Tranche 2 obligations.

The Enhanced identity & AML/CTF check adds a biometric selfie, proof of address, and enhanced AML/CTF screening (PEP and sanctions) with continuous monitoring, and is the check aligned to Tranche 2.

The Enhanced check with entity & ownership collection adds entity, ownership, and control collection with follow-up checks for additional directors or beneficial owners. If you're unsure which to use, speak with your compliance advisor.

What does Ignition store from the verification process?
Ignition stores the outcome and status of each verification for your records. Raw identity documents, biometrics, and detailed provider reports are not stored within Ignition.

Can I export my verified clients register?
Yes. You can run a Compliance CSV export (via Compliance tab → Export) for a practice-wide view of requests, review candidates, evidence context, delivery state, and latest activity. Your Services CSV export also now includes Compliance classification columns, and individual verification PDFs are available to users with the Compliance Manager permission.

How much does Ignition Compliance cost, and how does billing work?

There's no extra fee just to access Compliance: it's included on Core, Pro and Pro+ plans. You only pay when you run a check: $6 for a Standard identity check, and $10 for an Enhanced AML/CTF check (which covers biometric verification, proof of address, PEP and sanctions screening, and ongoing monitoring). If you're verifying a company or trust, the $10 entity check and each individual follow-up check (for directors, trustees or beneficial owners) are billed separately, so a company with one director works out to $20 in total.

These appear as line items on your regular Ignition invoice. There's no way yet to pass this cost on to your client directly through Ignition, so most firms either absorb it, build it into their pricing, or add it as a disbursement.

Ignition bills a check when it is completed, not when it is sent. A request your client has not finished, a partially completed request, and a check that ends in an error are not billed. If you reject a result and send a new check, Ignition bills that new check once it is completed.

Which plans include this, and do I need to upgrade?

It's available on Core, Pro and Pro+ and nothing extra to set up beyond what's already in your account. It's currently available to AU and UK customers; and rolling out very soon to New Zealand. If you’re located in either of these 2 regions, contact us so we can keep you updated.

If a company has more than one director or beneficial owner, do I need to send separate checks to each of them?

Your client lists the company's directors and beneficial owners as part of completing their own verification. Ignition then creates a follow-up check for each person listed, but does not send them automatically. This gives you a chance to review the list before any check, and its cost, goes out.

Open the client's Compliance tab, then send a check to each person who needs to be verified and mark anyone who does not need verifying as not required. Until you send a follow-up check, that person receives nothing and their verification stays outstanding.

Each associated party check is billed as its own check, and you choose the level of check to send to each person. If the same person is both your main point of contact and a director or beneficial owner, they can occasionally be asked to verify twice. Only one needs to be completed, and our support team can help tidy up the other.

We often deal with a whole group of related entities (company, trust, individuals) under one engagement. Can we verify the whole group in one go?

Not quite yet. Right now, each entity in a group needs its own verification, started from that entity's own client record. The Enhanced check bundles one entity together with its own directors and beneficial owners, but it doesn't yet let you manage a whole related-entity group (say, a company plus its shareholding trust plus the individuals behind both) as a single check.

We know this is a common scenario for group engagements, and a smoother group-level workflow is something we're actively working towards.

The same person is a director or beneficial owner of several of our client entities. Do they really need to verify separately and pay for each one?

At the moment, yes: each entity's check runs independently, so the same individual may need to complete (and be billed for) verification more than once if they sit across multiple related entities. We know this adds cost and friction for exactly the kind of family and corporate groups accountants deal with every day, and it's high on our list to improve.

Do I have to send a check as part of a proposal, or can I send one separately?

You can send a verification request directly from a client's record at any time, no proposal needed. You can also have it trigger automatically when you send a proposal. If you're using Classic Proposals, the automatic trigger isn't supported, but you can still send a check separately. Already sent your proposals for the new financial year? No problem, just send the verification request directly from the client record. And if you're on Pro or above, you can send checks to multiple clients at once instead of one by one.

Can this be part of our new client onboarding, so we don't have to remember to trigger it?

Yes, on Pro and Pro+ plans: you can set it up so a new client automatically receives a verification request as soon as they accept their first proposal, with nothing extra for you to do.

Are our clients' ID and biometric data safe with Ignition?

Yes. Everything is encrypted both in transit and at rest (bank-grade AES-256), and access to verification records is limited to people in your practice with the Compliance permission. Full details are at ignitionapp.com/security.

What does it mean when a service shows as 'delivery blocked'*?

It means Ignition is holding off marking that service as delivered – and therefore holding off invoicing – until the client's verification comes back as passed. You'll see the reason directly on the proposal or service record, and on the client's Compliance tab. If you've already verified someone another way and want to proceed anyway, you can manually clear the block yourself by entering a short note explaining why, which is saved for your records.

Please note: It is the responsibility of the practice to decide if a service should still be delivered after encountering a ‘delivery blocked’ status.

I sent a verification request to the wrong email address. How do I fix it?

Update the contact's email on the client record, then resend the verification link, and it'll go straight to the corrected address.

We use a lot of custom services we've built ourselves. Will Ignition still know which ones need a compliance check?

Yes: Ignition looks at the name, description and category of all your services, custom ones included, to recommend which need verification*. If one of yours isn't picked up automatically, you can classify it manually and that choice will stick. It's worth a quick review of your service library though, since very generically-named custom services can sometimes be missed.

Please note: Ignition is able to make recommendations for services that may require a compliance check but ultimately the responsibility is on the practice to ensure their services are classified correctly.

How do we manage who reviews flagged or higher-risk results?

You can assign someone in your practice the Compliance Manager role in Ignition. They'll get visibility of flagged and higher-risk verifications so they can review the detail and decide how to proceed.

Who actually runs these checks behind the scenes?

Checks run through our verification partner, ComplyCube, combining government document verification, biometric matching, and screening against PEP and sanctions lists. It all happens inside Ignition, so your client never has to visit a separate website or app.

Does Ignition Compliance provide ASIC Current Company Extracts for our due diligence records?

No. Company checks draw on official business registries to confirm entity details, but Ignition doesn't provide ASIC Current Company Extracts listing officeholders and shareholders. If your practice relies on those extracts as evidence, you'll need to obtain them separately.

Will this sync with XPM, Karbon or our other practice management software?

Compliance status can now sync to Xero Practice Manager (XPM). This is in Early Access and is switched on for selected practices only.

Once it is enabled for your practice, a Compliance section appears in your XPM settings with an opt-in toggle. Turning it on creates custom fields in XPM and backfills your existing clients, so you can see each client's verification status and the date it last changed without leaving XPM.

A link from XPM back to the verification request in Ignition is planned and is not yet switched on.

Compliance does not sync to Karbon, Handisoft or LodgeIT. If you already use the Ignition integration with Karbon for workflows, that is separate and does not carry compliance data.

To register your interest in the XPM sync, reach out to our support team.

We're setting up a brand-new company or trust that doesn't have an ABN/ACN yet. How do we verify it?

Verify the people first (the directors, trustees or beneficial owners, as individuals), then run the entity-level check once the ABN/ACN has been issued. If you're dealing with an entity that will never have an ABN/ACN (some investment trusts fall into this category), get in touch with support, since that scenario needs a manual workaround for now while we build a proper fix.

Our client is a foreign company with an ARBN but no ABN or ACN. How do they complete the entity form?

The ABN / ACN field is required, so enter a placeholder such as "TBA" to continue. Verification itself is carried out at an individual level, and the entity details are captured to record the company and identify additional directors for follow-up checks. Alternatively, cancel the request and send an Enhanced identity and AML/CTF check instead.

Can I add a compliance check to a proposal I've already sent?

Yes: move it back to Draft, add the check on the Send tab, and resend. Just be aware that if your client already signed the original version, they'll need to re-sign the updated one.

Can I get a version of the report without personal ID details in it, to keep in the client file?

Not yet. In the meantime, the safest approach is to leave the full report where it already lives (in Ignition, restricted to your Compliance Manager permission) rather than copying it into your client file. If you want a practice-wide view without any document images, the Compliance register CSV export is built for exactly that.

Did this answer your question?