AML software for accountants — the engagement cannot start without the check.
FigsFlow is AML software for accountants — client due diligence and AML compliance built into the system UK accountancy practices already work in. The check opens on the client record the moment a proposal is accepted, the risk rating shows the factors behind it, enhanced due diligence blocks the work downstream of it, and the record seals with the date the relationship began.
281 reviews from
G2 reviews
Google reviews
Verified reviews
- OpenedFrom the accepted proposal
- VerificationPhoto ID · liveness check
- RatingFactors shown · override logged
- OfficerNotified in platform
- RetentionFive years · flagged
nobody starts acting early
Customer due diligence from one place.
Each client counted once. Cleared with conditions is a pass — the conditions are tracked in monitoring, not a separate outcome.
Enhanced · 2-month cadencein 6d →
2 candidates · disposition pending3h →
Customer due diligence from one place.
| Client | Status | Verification | Screening | Risk | CRR | Actions |
|---|
No CRM is connected, so nothing is pre-filled. Pull the company structure directly from the source register, then walk it to every natural person.
Screen the entity and every person against sanctions, PEP and adverse-media lists.
A PEP match on the beneficial owner makes enhanced due diligence mandatory under regs 33 and 35, and clearance needs a named MLRO approval before it can be recorded. Both run on live client data.
Customer due diligence is always about a subject. Pick a test client — their type decides which flow runs.
3 test clients. Nothing here touches a real record or a real check.
Bring a client you are onboarding this week. No scripted demo, no invented data.
Was the due diligence finished before the firm started acting?
It is Friday. The engagement letter went out on Tuesday and the first invoice is already raised. Somebody now has to establish whether client due diligence was completed before the practice began to act — and where the evidence for that sits.
Still doing it this way?
Five steps, and none of them produce a date.
- 01Ask three people who ran the ID check
- 02Search the shared drive for the AML folder
- 03Find one passport scan and no risk assessment
- 04Work out whether the letter went before or after
- 05Write the file note after the event
Three people, three answers, and a practice that has already acted. That is not a diligence problem — it is a sequencing problem.
Three steps between a new client and a sealed record
The chasing, the filing and the file note are already done.
- 01The client accepts the proposal
- 02The rating sets the measures
- 03The record seals and the letter releases
The identity evidence, the rating factors, every officer decision and the date the relationship began are already attached to the client record.
What happens the moment the rating lands?
Nothing on your side. The rating is an event in FigsFlow, not a status somebody has to remember to change.
01 / 04 · the measures are set
The measures are set.
Standard or enhanced measures open against the client from the band the rating produced, with the fields your procedure specifies. Nobody decides on the day what extra information to ask for.
The letter is held.
The release control is unavailable while a diligence item is open. Not a reminder and not a red flag on a dashboard — the firm cannot begin acting for the client.
The officer is notified in the platform.
Escalation routes to your nominated officer inside FigsFlow rather than through an email thread, and the notification carries a timestamp that stays on the record.
Nothing is marked by hand.
No “CDD done” checkbox, no status to update, no folder to file the passport scan into, and no file note written three months after the fact.
Nobody has to decide to escalate.
Watch a rating land on a test client →Is due diligence a gate, or a to-do?
A gate. FigsFlow holds the engagement letter until the diligence stage is complete, so your team can keep preparing the file but cannot let the practice start acting for a client whose check is unfinished. The letter unlocks the moment the last item closes.
Staff can open and prepare blocked work. They cannot complete it before the stage it depends on is cleared.
See the gate hold an engagement letter →Does every client get the same diligence?
No. The measures follow the band, so the check changes without anyone rewriting it. Select a band below and the measures swap in; everything in the base check is untouched.
Band-specific measures are marked. Everything else in the check is untouched.
No elevating factors recorded. Identity, beneficial ownership and the purpose of the relationship are evidenced and the engagement releases.
Annual reviewOne or more factors your firm treats as higher risk. Source of funds is evidenced and onboarding needs senior approval before the letter releases.
Six-month reviewEnhanced due diligence applies, including where a politically exposed person is involved. Source of wealth is documented and the nominated officer clears the file.
Continuous monitoringBand names, thresholds and cadences are configured by your firm in its written risk assessment. FigsFlow applies what you have set; it does not decide the thresholds for you.
How do you know they are not on a list?
The identity check tells you the person is who they say they are. It does not tell you whether they are sanctioned, politically exposed, or named in adverse media. That is a separate screen, and it runs against the same client record.
Screening covers the client and the beneficial owners recorded on the diligence stage. Whether a possible match is your client, and what follows if it is, remains your nominated officer’s judgement.
Run screening on all parties →What the Money Laundering Regulations 2017ask of your practice
Accountancy service providers in the UK are supervised for anti-money laundering purposes and are required to run due diligence before acting, apply enhanced measures where the risk is higher, appoint a nominated officer, retain the evidence, and report suspicion without tipping the client off. Here is where each obligation sits in FigsFlow.
| Obligation | What it requires | Where it sits in FigsFlow |
|---|---|---|
| Client due diligenceMLR 2017, regs 27–28 | Identify and verify the client, and the beneficial owner, before the business relationship is established. | The diligence stage opens from the accepted proposal, and the engagement letter is gated on it. |
| Enhanced due diligenceMLR 2017, regs 33 & 35, as amended from 30/06/2026 | Additional measures where the risk is higher, and for politically exposed persons. Since 30 June 2026 the mandatory trigger attaches to FATF black-list jurisdictions; grey-list countries feed the risk assessment without automatically requiring enhanced measures. | The EDD stage opens on the rating and blocks the work downstream of it until the officer clears it. |
| Ongoing monitoringMLR 2017, reg 28(11) | Keep the business relationship and the client’s information under review. | A review cycle per client, set by risk band and surfaced before it falls due. |
| Record keepingMLR 2017, reg 40 | Retain the diligence evidence for five years from the end of the relationship. | The record seals on the client file and is flagged for deletion review at the end of the period. |
| Nominated officerMLR 2017, reg 21(3) | A named officer within the firm to receive and consider internal reports. | An MLRO role with escalation routing and a log that cannot be edited after the event. |
| Reporting suspicionPOCA 2002, ss 330 & 333A | Report to the National Crime Agency, and do not tip the client off. | The client record is structured and exportable, so the officer has the information in one place. |
This table summarises obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and the Proceeds of Crime Act 2002. It describes how FigsFlow supports a firm’s compliance workflow and is not legal or regulatory advice. Your own supervisory body’s guidance takes precedence, and your firm remains responsible for its AML policies, controls and procedures.
Get these obligations mapped to your workflow →Built inside a working UK practice
FigsFlow is used day to day by UK Property Accountants, a London practice supervised for anti-money laundering, with delivery support from the Sterling Wells team in Kathmandu.
Named practice references and review-platform ratings are not shown on this page yet. They will be added once the practices concerned have agreed in writing and the figures have been verified.
Book a demo with the team that built it →What an AML check costs
What AML software for accountants costs is a fair question to ask first. Per-check rates and the subscription tiers that include the module are being confirmed before they go on this page; the pricing model we can tell you now.
Per check, not per client
Identity and screening checks are credit-metered, so the cost follows the AML checks you actually run rather than the number of names on your client list.
Not a second subscription
Client due diligence sits inside FigsFlow beside proposals, engagement letters and onboarding, rather than arriving as a separate AML tool with its own renewal date.
Coming to this page
We would rather publish a rate we have verified than a rate we have to correct. Ask and we will send you the current per-check price and the tiers it sits in.
What does the file look like three years later?
Reviewable, not editable. Each review is a version on the same client record, so what the check contained, who decided what, and when, is still readable long after the people involved have moved on.
Twelve months of scheduled reviews at a glance. A client who has drifted past their review date is visible before a file review finds them.
See a three-year-old client file →What this looks like at your size
Sole practitioners
Run the check on a new client yourself, without a second tool or a manual checklist to maintain.
See it on one client →2 to 10
Anyone on the team can start a check. The nominated officer still sees every escalation.
See the officer view →10 to 50
Standardise the procedure before headcount turns inconsistency into a supervisory finding.
Risk assessment and scoring →50+ and multi-office
Diligence records held inside your own Microsoft tenant, under your IT team’s existing policy.
Talk to us about deployment →Everything the check connects to
AML software for accountants only earns its place if it reads the rest of the practice. Client due diligence here is not a separate tool bolted on: it reads from and writes to the parts of FigsFlow your firm already runs.
The band that decides whether the engagement continues or pauses for enhanced measures.
See risk assessment → Engagement lettersThe document the diligence gate holds until the check on that client is complete.
See engagement letters → Onboarding suiteProposal, fee, letter and client due diligence as one sequence rather than four.
See onboarding → Client portalWhere the client uploads identity and ownership evidence, without an email thread.
See the client portal →The AML Essentials Kit
A practical walk-through of what a supervised practice has to hold and be able to produce, written for accountants, bookkeepers and tax advisers rather than for full-time compliance officers. Useful whichever AML software for accountants you end up choosing.
Collecting client identity data
What to ask an individual and what to ask an organisation, and where the two part company.
Verifying it independently
Confirming identity from a source other than the client, and what actually counts as evidence afterwards.
Client and firm-wide risk
Assessing the risk a client presents, and the separate annual assessment of the practice itself.
Policies, controls and training
Writing the procedure your risk assessment implies, and training the people who have to follow it.
Two guides, one for individual clients and one for organisations. They are sent by email, so the kit asks for an address. The kit describes what the Money Laundering Regulations 2017 require of a supervised practice; it is not legal or regulatory advice, and your supervisory body’s guidance takes precedence.
What UK practices ask before they switch
Client due diligence is the set of measures a supervised firm must take to identify and verify a client, and any beneficial owner, and to understand the purpose and nature of the business relationship, before that relationship is established. The requirement sits in regulations 27 and 28 of the Money Laundering Regulations 2017.
No. FigsFlow produces a rating from the diligence data collected and the risk factors your firm has configured, and it shows which factors drove that rating. Your nominated officer reviews the reasoning and can override it. The rating and the override both stay on the record.
No. The release control is unavailable while a diligence item is open. Staff can continue preparing the file, but the practice cannot begin acting for a client whose check is unfinished.
FigsFlow sends the identity request to the client by email or SMS. They confirm their identity with photo ID and a liveness check, without downloading an app or coming into the office, and the result posts back to the client record rather than arriving as an attachment somebody has to file.
Regulation 40 of the Money Laundering Regulations 2017 requires diligence records to be retained for five years from the end of the business relationship. FigsFlow seals the record against the client file, tracks the retention period, and flags the file for deletion review when it ends.
It is built for supervised accountancy practices. The anti-money laundering checks sit on the same client record as the proposal, the engagement letter and the onboarding work, which is why the letter can be held until the diligence is finished. A standalone AML tool cannot hold work it does not know about.
No. FigsFlow routes the escalation to your nominated officer with a timestamped log and keeps the client record structured and exportable, so the information is in one place. Whether a report goes to the National Crime Agency is your officer’s decision and your firm’s submission.
Bring a client you are onboarding this week
We will run the check on screen: the identity request, the rating and its factors, the enhanced stage, and the officer log — against your firm’s own procedure. No scripted demo and no invented data. Half an hour is enough to judge whether this is the AML software for accountants your practice can actually run.
Once the check clears, the band it produced drives the review cycle and the measures on every future engagement. Risk assessment and scoring
Run it on a client you are onboarding this week. No scripted demo and no invented data.
Book a demo →

