Topical anchor · Tier 1 + Tier 3
Since 1 July 2026, Australian legal practices providing designated services have been AUSTRAC reporting entities, and the 29 July 2026 enrolment deadline has passed. The obligations are no longer approaching; they are live. They include an anti-money-laundering / counter-terrorism-financing (AML/CTF) program (Part A risk-management processes and Part B customer identification, including beneficial owners and politically-exposed persons, PEPs), customer due diligence (CDD) with simplified and enhanced tiers, ongoing CDD as risk changes, source-of-funds and source-of-wealth checks in some circumstances, and record-keeping that must survive a request years after a matter closes. This audit does not opine on your legal obligations; it examines whether your Sharedo platform can evidence them.
Do intake work types capture identity verification, beneficial-owner structures, PEP flags, and source-of-funds and source-of-wealth fields as structured data rather than free text? A fact recorded in a note cannot be reported on, gated on, or produced on request.
Fill rates are measured over the live matter population, so a control that exists on the form but not in the data is exposed. In the synthetic demonstration corpus, 189 of 287 attribute fields were dead or sparse: a field with no enforcement behind it decays towards zero, and compliance fields are no exception.
Is there an enforced phase gate so a matter cannot progress from intake to active work without CDD completion recorded? A control that relies on memory is not a control.
Ongoing CDD is a standing obligation, not an intake step. Are periodic or event-driven review triggers configured for higher-risk matters: a review key date with an owner and a reminder, re-raised when circumstances change, rather than a diary note?
Can the platform distinguish a simplified from an enhanced due-diligence path by matter risk, with a rating that phase guards and routing actually read, or is every matter treated the same?
Could you answer an AUSTRAC record-keeping request from the data? CDD records must be retrievable years after a matter closes, and evidence trapped in free-text notes fails that test. The free-text lens measures how much CDD fact lives in notes rather than fields, the sign of a control that exists on paper but not in the data.
Configuration capture confirms which CDD fields, phase gates, and review triggers exist; the shipped fill-rate lens then measures whether the fields that do exist actually carry data across the live matter population. Where the Intelligence add-on is engaged, the on-premise free-text lens tests whether CDD facts are being recorded in structured fields or scattered through notes. Client data never leaves a controlled environment.
The intake work type had no CDD checkpoint between the 'Received' and 'Active' phases, so matters opened and progressed without verification evidence attached. Of 7 expected CDD controls, none was fully configured: the only two present at all were a free-text verification note and a risk-rating field filled on 3% of matters.
| Expected CDD control | Configured? | What good looks like |
|---|---|---|
| Identity-verification fields on the intake work type | Weak | Structured verification-status and document-reference fields, not a free-text note |
| Beneficial-owner structure captured | Absent | A repeating party structure in the Operational Data Store, one record per owner |
| Politically-exposed-person (PEP) flag | Absent | A mandatory option-set field with a screening date, not a comment |
| Source-of-funds and source-of-wealth fields | Absent | Structured fields on the matters where the program requires them, queryable per matter |
| Risk-rating field (drives simplified vs enhanced due diligence) | Weak | An option-set rating that phase guards and routing actually read |
| Enforced phase gate: no progression without CDD complete | Absent | A guard on the intake-to-active transition that blocks, rather than reminds |
| Ongoing-CDD review trigger for higher-risk matters | Absent | A review key date with an owner and a reminder, re-raised when risk changes |
A control-by-control gap list, cited to configuration rule identifiers, that turns 'we believe we are ready' into 'here is the evidence'. With the obligations now live, each gap has a named fix: the field to add, the gate to enforce, the trigger to configure, closed before a regulator asks the question for you.