AML software for accountants
Has a client ever received your engagement letter before their AML checks were done? In FigsFlow, you can set the letter to wait for them. If a client is high risk or fails a check, the letter stays unsent until your firm decides whether to go ahead. The decision stays with your firm.
G2 reviews
Google reviews
Verified reviews
AML/KYC Solution of the Year 2026 · SME500 UK
- OpenedFrom the accepted proposal
- VerificationPhoto ID · liveness check
- RatingFactors shown · officer sign-off logged
- OfficerNotified in platform
- RetentionFive years · flagged
nobody starts acting early
Customer due diligence from one place.
Each client counted once. Cleared with conditions is a pass — the conditions are tracked in monitoring, not a separate outcome.
Enhanced · 2-month cadencein 6d →
2 candidates · disposition pending3h →
Customer due diligence from one place.
| Client | Status | Verification | Screening | Risk | CRR | Actions |
|---|
No CRM is connected, so nothing is pre-filled. Pull the company structure directly from the source register, then walk it to every natural person.
Screen the entity and every person against sanctions, PEP and adverse-media lists.
A PEP match on the beneficial owner makes enhanced due diligence mandatory under regs 33 and 35, and clearance needs a named MLRO approval before it can be recorded. Both run on live client data.
Customer due diligence is always about a subject. Pick a test client — their type decides which flow runs.
3 test clients. Nothing here touches a real record or a real check.
Bring a client you are onboarding this week. No scripted demo, no invented data.
Was the due diligence finished before the firm started acting?
It is Friday. The engagement letter went out on Tuesday and the first invoice is already raised. Somebody now has to establish whether client due diligence was completed before the practice began to act — and where the evidence for that sits.
Was the letter sent before the checks were done?
Five steps to find out, and none of them gives you a clear answer.
- 01Ask three people who ran the ID check
- 02Search the shared drive for the AML folder
- 03Find one passport scan and no risk assessment
- 04Work out whether the letter went before or after the checks
- 05Write the file note after the event
Nobody decided the order. It just happened.
You can make the letter wait for the checks
Five steps. One way it can run.
- 01The proposal is done
- 02AML checks run on the client
- 03FigsFlow rates how risky the client is
- 04The letter waits until the checks are cleared
- 05Once cleared, the next step starts by itself
You set the order, and you can change it for one client when you need to.
What happens the moment the rating lands?
Nothing on your side. The rating is an event in FigsFlow, not a status somebody has to remember to change.
01 / 04 · the measures are set
The measures are set.
Standard or enhanced measures open against the client from the risk level the rating produced, with the fields your procedure specifies. Nobody decides on the day what extra information to ask for.
The letter is held.
Nobody can send the engagement letter while a due diligence check is still open. Not a reminder and not a red flag on a dashboard — the firm cannot begin acting for the client.
The officer is notified in the platform.
Escalation routes to your nominated officer inside FigsFlow rather than through an email thread, and the notification carries a timestamp that stays on the record.
Nothing is marked by hand.
No “CDD done” checkbox, no status to update, no folder to file the passport scan into, and no file note written three months after the fact.
Nobody has to decide to escalate.
Watch a rating land on a test client →
Is due diligence a gate, or a to-do?
A gate. FigsFlow holds the engagement letter until client due diligence is complete, so your team can keep preparing the file but cannot let the practice start acting for a client whose check is unfinished. The letter can be sent as soon as the last check is done.
Your team can start preparing the work, but cannot complete it until due diligence is cleared.
See how the letter is held →Does every client get the same diligence?
No. The measures follow the risk level, so the check changes without anyone rewriting it. Select a level below and the measures swap in; everything in the base check is untouched.
Measures specific to each risk level are marked. Everything else in the check is untouched.
No higher-risk factors recorded. Identity, beneficial ownership and the purpose of the relationship are evidenced and the engagement releases.
Review frequency set by your firmOne or more factors raised the client’s risk. The rating shows which ones, and your compliance officer signs it off or rejects it with a reason on record.
Review frequency set by your firmEnhanced due diligence applies, including where a politically exposed person is involved. High-risk clients complete enhanced due diligence questions before they can be cleared.
Review frequency set by your firmYour firm sets how often clients at each risk level are reviewed. The three risk levels are fixed in FigsFlow.
How do you know they are not on a list?
The identity check tells you the person is who they say they are. It does not tell you whether they are sanctioned, politically exposed, or named in adverse media. That is a separate screen, and it runs against the same client record.
Screening covers the client and the beneficial owners recorded during due diligence. Whether a possible match is your client, and what follows if it is, remains your nominated officer’s judgement.
Run screening on all parties →What the Money Laundering Regulations 2017ask of your practice
Accountancy service providers in the UK are supervised for anti-money laundering purposes and are required to run due diligence before acting, apply enhanced measures where the risk is higher, appoint a nominated officer, retain the evidence, and report suspicion without tipping the client off. Here is where each obligation sits in FigsFlow.
| Obligation | What it requires | Where it sits in FigsFlow |
|---|---|---|
| Client due diligenceMLR 2017, regs 27–28 | Identify and verify the client, and the beneficial owner, before the business relationship is established. | Due diligence opens from the accepted proposal, and the engagement letter is held until it is complete. |
| Enhanced due diligenceMLR 2017, regs 33 & 35, as amended from 30/06/2026 | Additional measures where the risk is higher, and for politically exposed persons. Since 30 June 2026 the mandatory trigger attaches to FATF black-list jurisdictions; grey-list countries feed the risk assessment without automatically requiring enhanced measures. | The EDD stage opens on the rating and blocks the work downstream of it until the officer clears it. |
| Ongoing monitoringMLR 2017, reg 28(11) | Keep the business relationship and the client’s information under review. | A review cycle per client, set by risk level and surfaced before it falls due. |
| Record keepingMLR 2017, reg 40 | Retain the diligence evidence for five years from the end of the relationship. | The record seals on the client file and is flagged for deletion review at the end of the period. |
| Nominated officerMLR 2017, reg 21(3) | A named officer within the firm to receive and consider internal reports. | An MLRO role with escalation routing and a log that cannot be edited after the event. |
| Reporting suspicionPOCA 2002, ss 330 & 333A | Report to the National Crime Agency, and do not tip the client off. | The client record is structured and exportable, so the officer has the information in one place. |
This table summarises obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and the Proceeds of Crime Act 2002. It describes how FigsFlow supports a firm’s compliance workflow and is not legal or regulatory advice. Your own supervisory body’s guidance takes precedence, and your firm remains responsible for its AML policies, controls and procedures.
Get these obligations mapped to your workflow →Built inside a working UK practice
FigsFlow is used day to day by UK Property Accountants, a London practice supervised for anti-money laundering, with delivery support from the Sterling Wells team in Kathmandu.
Named practice references and review-platform ratings are not shown on this page yet. They will be added once the practices concerned have agreed in writing and the figures have been verified.
Book a demo with the team that built it →Priced per check · programme flat per firm
What an AML check costs
One price per check with everything in it, and a risk-assessment programme that gives your supervisor the record they expect to see.
per check on the Compliance Programme, and £3.00 from your 100th check, for good.
Once you reach the lower rate, it stays.
- Electronic identity and address
- PEP and sanctions screening
- Amberhill check
- 24 months of ongoing screening
- Companies House ID verification workflow
- The inspection-ready record
- Client and firm-wide risk assessment
- Enhanced due diligence workflow
- Policies, controls and MLRO roles
- Monitoring alerts and training log

Pay as you go
Checks only, no programme
Everything included
- Same complete check
- Buy credits in packs of 10; they never expire
Above 15 checks a month the programme costs less, and it adds the risk assessment, EDD workflow and MLRO record. Figures use the £3.50 rate, before the £3.00 rate applies.
Book a demo →Nothing is sold separately. What you see is the whole price of the check. A 250-client re-check on the programme costs about £800 once, and there is nothing per client per month after that.
What does the file look like three years later?
Reviewable, not editable. Each review is a version on the same client record, so what the check contained, who decided what, and when, is still readable long after the people involved have moved on.
Twelve months of scheduled reviews at a glance. A client who has drifted past their review date is visible before a file review finds them.
See a three-year-old client file →What this looks like at your size
Sole practitioners
Run the check on a new client yourself, without a second tool or a manual checklist to maintain.
See it on one client →2 to 10
Anyone on the team can start a check. The nominated officer still sees every escalation.
See the officer view →10 to 50
Standardise the procedure before headcount turns inconsistency into a supervisory finding.
Risk assessment and scoring →50+ and multi-office
Diligence records held inside your own Microsoft tenant, under your IT team’s existing policy.
Talk to us about deployment →Everything the check connects to
AML software for accountants only earns its place if it reads the rest of the practice. Client due diligence here is not a separate tool bolted on: it reads from and writes to the parts of FigsFlow your firm already runs.
The band that decides whether the engagement continues or pauses for enhanced measures.
See risk assessment → Engagement lettersThe document FigsFlow holds until due diligence on that client is complete.
See engagement letters → Onboarding suiteProposal, fee, letter and client due diligence as one sequence rather than four.
See onboarding → Client portalWhere the client uploads identity and ownership evidence, without an email thread.
See the client portal →The AML Essentials Kit
A practical walk-through of what a supervised practice has to hold and be able to produce, written for accountants, bookkeepers and tax advisers rather than for full-time compliance officers. Useful whichever AML software for accountants you end up choosing.
Collecting client identity data
What to ask an individual and what to ask an organisation, and where the two part company.
Verifying it independently
Confirming identity from a source other than the client, and what actually counts as evidence afterwards.
Client and firm-wide risk
Assessing the risk a client presents, and the separate annual assessment of the practice itself.
Policies, controls and training
Writing the procedure your risk assessment implies, and training the people who have to follow it.
Two guides, one for individual clients and one for organisations. They are sent by email, so the kit asks for an address. The kit describes what the Money Laundering Regulations 2017 require of a supervised practice; it is not legal or regulatory advice, and your supervisory body’s guidance takes precedence.
What UK practices ask before they switch
Client due diligence is the set of measures a supervised firm must take to identify and verify a client, and any beneficial owner, and to understand the purpose and nature of the business relationship, before that relationship is established. The requirement sits in regulations 27 and 28 of the Money Laundering Regulations 2017.
No. FigsFlow produces a rating from the diligence data collected and the risk factors your firm has configured, and it shows which factors drove that rating. Your compliance officer reviews the reasoning and signs off the rating, or rejects it with a reason on record. The rating and the decision both stay on the record.
No. Nobody can send the letter while a due diligence check is still open. Your team can keep preparing the file, but the practice cannot begin acting for a client whose check is unfinished.
FigsFlow sends the identity request to the client by email or SMS. They confirm their identity with photo ID and a liveness check, without downloading an app or coming into the office, and the result posts back to the client record rather than arriving as an attachment somebody has to file.
Regulation 40 of the Money Laundering Regulations 2017 requires diligence records to be retained for five years from the end of the business relationship. FigsFlow seals the record against the client file, tracks the retention period, and flags the file for deletion review when it ends.
It is built for supervised accountancy practices. The anti-money laundering checks sit on the same client record as the proposal, the engagement letter and the onboarding work, which is why the letter can be held until the diligence is finished. A standalone AML tool cannot hold work it does not know about.
No. FigsFlow routes the escalation to your nominated officer with a timestamped log and keeps the client record structured and exportable, so the information is in one place. Whether a report goes to the National Crime Agency is your officer’s decision and your firm’s submission.
Run it on a client you are onboarding this week. No scripted demo and no invented data.
Book a demo →

