AML and KYC Client Onboarding Software for Law Firms and Regulated Practices: What It Costs to Close the Gap Between Matter Opening and a File Your Supervisor Will Accept
If you are the money laundering reporting officer at a firm with more than roughly 50 fee earners, running client and matter risk assessments in spreadsheets while partners chase documents by email, a custom build is usually justified. A focused first release covering risk assessment, client and matter onboarding workflow, document collection and the evidence file typically runs $60,000 to $130,000 and ships in 10 to 16 weeks in our delivery experience. A full platform adding beneficial ownership mapping, screening integration with alert adjudication, source of funds workflow, periodic review scheduling and practice management integration lands at $180,000 to $400,000, phased over 6 to 12 months. Below that size, Amiqus or Thirdfort connected to your practice management system is the right answer and costs a fraction.
Why onboarding stalls where the regulator later looks
A corporate partner wants to open a matter on Monday. The client is a holding company registered offshore with two corporate shareholders, one of which is a trust. Compliance needs identification for the individuals who ultimately own or control it, a structure chart, an explanation of where the funds for the transaction come from, and a risk assessment recorded before work begins. The partner sends an email asking for passports. Two arrive as phone photographs, one as a scan of a scan. The structure chart arrives as a slide from a pitch deck. Three weeks pass. Work has quietly started because the client is important and the deadline is real. When the supervisor visits eighteen months later and samples files, the questions will be when the risk assessment was completed, what evidence supported it, and whether work commenced before it existed.
The tools around this are genuinely useful. Amiqus and Thirdfort handle individual identity verification and source of funds collection well, and consumer-facing verification through those channels is far better than emailed photographs. ComplyAdvantage and LexisNexis Bridger Insight are serious screening providers. What none of them owns is the shape of a professional practice's obligation: risk assessed at both client and matter level, an engagement that cannot open until compliance clears it, partner accountability, and a file that a professional body supervisor will recognise as complete. Those products were largely built for financial institutions onboarding customers. A law firm does not onboard customers, it accepts instructions on matters, and the difference is not cosmetic.
Problem 1: the risk assessment is a documented judgement, not a score
The Money Laundering Regulations 2017 in the United Kingdom, and the risk-based approach in every comparable regime, require a firm-wide risk assessment and then risk assessment of the individual relationship, with the level of due diligence following from it. Supervisors do not object to a firm concluding that a client is low risk. They object when the conclusion has no reasoning, when it contradicts obvious factors like an offshore structure or a politically exposed person connection, or when it was recorded after the work started.
Build it as a structured judgement with an audit trail rather than a numeric score. Factors are captured with their answers and their evidence, the model proposes a rating, and the responsible person confirms or overrides with a written reason. Overrides are not a failure, they are the point: professional judgement is what the regulations expect, and the record of it is what protects the firm. Every assessment is timestamped and immutable once submitted, and the matter opening workflow refuses to release a file number until it exists. That single control, technically trivial, removes the most common finding in practice inspections.
Problem 2: beneficial ownership is a graph, and everyone stores it as a document
An offshore holding company owned by two corporates, one of which is owned by a trust with a protector and a class of discretionary beneficiaries, sitting under a nominee arrangement. The obligation is to identify the natural persons who ultimately own or control the client, and to understand the ownership and control structure. Under the United States customer due diligence rule the beneficial ownership threshold for legal entity customers at covered financial institutions is 25 percent, and comparable thresholds operate elsewhere, but a threshold does not resolve control exercised by other means.
Storing a structure chart as a PDF makes the file look complete and answers nothing. Model the structure as entities and relationships with percentages, dates and evidence per edge, so the system can compute effective ownership through layers and surface anyone crossing the threshold or holding control by other means. Then when the client restructures, you update an edge rather than commissioning a new chart. This is also where periodic review becomes cheap: the question is not whether to redo the whole exercise, it is which edges have changed. Firms that do this stop treating group clients as a fresh project every time a new matter opens.
Problem 3: source of funds is evidence gathering, not a text field
Source of funds means where the money for this transaction came from. Source of wealth means how the client accumulated their wealth overall. They are different questions, they are frequently conflated, and the conflation is a standard inspection finding. Both require evidence proportionate to risk: bank statements showing the funds arriving and their origin, a sale contract, a probate grant, share sale documentation, tax returns.
The build should treat these as evidence chains rather than narrative boxes. A stated source, the documents supporting it, a reviewer's conclusion on whether the evidence supports the statement, and gaps flagged explicitly. Where funds pass through several accounts before arriving, the chain has to be traceable rather than summarised. Extraction tooling has a genuine role, reading bank statements into structured transactions so a reviewer can follow the flow instead of reading PDFs, and flagging where a stated origin does not appear. It should never conclude. The conclusion is a regulated judgement made by a named person, and the record must show who made it and what they saw.
Problem 4: screening produces noise, and the noise is the record
Sanctions, politically exposed person and adverse media screening against a common name produces alerts, most of them irrelevant. Whether a firm dismisses them properly is exactly what an inspection examines. The failure is not the false positive, it is a dismissal with no recorded reason, or a screening run whose results nobody can reproduce because the provider's data has moved on.
Keep the screening provider, because maintaining sanctions and adverse media data is not a build you should attempt, and connect it. What you build is the adjudication layer: every alert with the match data as it was at the time, the discounting reason, the reviewer, and the timestamp, stored immutably. Ongoing screening then runs continuously against the client base rather than only at onboarding, because a client who was clean in March may be listed in September and the obligation is ongoing. Route new hits to a queue with a service level, and report on the queue, because a screening system nobody clears is worse than none: it creates a record of alerts you received and did not act on.
Problem 5: periodic review is where good firms quietly fall behind
Onboarding gets attention because it blocks revenue. Periodic review does not block anything, so it slips, and then a supervisor asks when the file on a long-standing high risk client was last refreshed and the honest answer is 2019. Every firm knows this and most fix it with a spreadsheet and a diary reminder that survives until the compliance manager changes.
Build the review cycle into the data: each client carries a review frequency derived from its risk rating, the system generates the review as work with an owner and a due date, and overdue reviews escalate to the reporting officer and appear on a management dashboard the managing partner sees. Trigger events matter as much as the calendar: a new matter of a different type, a change in the ownership graph, a screening hit, a jurisdiction moving onto a high risk list. Those should all raise a review rather than waiting for the anniversary. The dashboard is the deliverable that changes behaviour, because partners respond to visibility in a way they do not respond to email reminders.
What this costs and how long it takes
Across the 2,000-plus projects Digital Heroes has delivered, here is the honest shape. A focused first release covering client and matter risk assessment, the onboarding workflow with a hard gate on matter opening, document collection and the structured evidence file runs $60,000 to $130,000 and ships in 10 to 16 weeks. A full platform adding beneficial ownership graph modelling, screening integration with alert adjudication, source of funds evidence chains, periodic review scheduling with escalation, and integration into your practice management and matter opening systems runs $180,000 to $400,000 phased over 6 to 12 months.
What drives price up: integration depth with your practice management system, because a compliance tool that does not stop a matter opening is advisory rather than controlling and the hard gate is the whole value. The complexity of your client base, since a firm doing private client trust work has a materially harder ownership modelling problem than one doing residential conveyancing. Multi-jurisdictional operation, because supervisors differ in what they expect to see in a file. And migration, since existing client files have to be assessed and brought onto the new standard, which is a remediation programme in its own right and frequently larger than the software project.
Build versus buy, and when buying is right
Buy, and do not call us, if you are a smaller practice with a fairly homogeneous client base. Amiqus or Thirdfort will handle identity verification and source of funds collection properly, ComplyAdvantage will handle screening, and connecting those to your practice management system gets you most of the way for a subscription. That combination is genuinely good and most firms under about 50 fee earners should stop there.
Build when two or more of these are true. Your risk model is your own and your supervisor expects to see it applied consistently, which a generic product's scoring cannot express. Your clients are corporate structures, trusts and funds where beneficial ownership requires a graph rather than a form. You need a hard gate between compliance clearance and matter opening, integrated into the system fee earners actually use. You operate under more than one supervisor or in more than one jurisdiction. Or your periodic review programme has fallen behind and you need scheduling, escalation and visibility built into the workflow rather than maintained beside it. The tipping point is when compliance stops being a form and becomes a control that has to be enforced by software because it cannot be enforced by asking.
How to choose a developer for AML onboarding software
Ask them how they model an ownership structure. If the answer is a document upload, they have built a filing cabinet. You want entities and relationships with percentages, dates and evidence attached per edge, and the ability to compute effective ownership through layers and identify control exercised by means other than shareholding.
Ask what happens when a risk rating is overridden. The right answer treats the override as expected professional judgement, captures the reason, records who made it, and keeps the original proposal visible. A system that hides overrides is a system that will be embarrassing in an inspection.
Ask how screening results are preserved. You need the match data as it was at the time of the decision, not a live re-query, because provider data changes and you must be able to show what your reviewer actually saw when they discounted an alert.
Ask who owns the code and get it in writing before kickoff. You should own the repository, the infrastructure accounts and the right to hire another firm. At Digital Heroes the code is yours from the first commit. This system holds identity documents and financial evidence for your clients, so also ask where that data lives, how long it is retained, and how a deletion request is honoured, because your data protection obligations do not pause because a compliance obligation exists.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- McKinsey argues software developer productivity can be measured by combining system-level metrics (DORA and SPACE) with its own outcome-oriented approach, which it reports deploying across nearly 20 tech, finance, and pharmaceutical companies - a claim that sparked significant debate in the engineering community. Source: McKinsey & Company (2023) →
- The 2015 CHAOS data (based on the modern definition of success) reports that only about 29% of software projects succeed, 52% are challenged, and 19% fail, with the three most important success skills being executive sponsorship, emotional maturity, and user involvement. Source: The Standish Group (reported via InfoQ Q&A with Jennifer Lynch) (2015) →
- In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
- 88% of organizations are concerned about employee retention, and providing learning opportunities is respondents' #1 retention strategy; career progress is cited as people's top motivation to learn, yet only 36% of organizations qualify as 'career development champions.'. Source: LinkedIn Learning (2025) →
Khushi runs several client projects at once, which mostly means deciding whose problem gets solved first. She coordinates developers, designers and clients across time zones, tracks budget against work completed, and raises the difficult conversation early. Readers learn how an agency actually allocates attention when everything is urgent.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
How much does custom AML and KYC onboarding software cost for a law firm?
Are Amiqus and Thirdfort enough, or should we build?
How should software handle beneficial ownership for offshore and trust structures?
What is the difference between source of funds and source of wealth in a compliance file?
Can AI review bank statements for source of funds?
How do we stop fee earners opening matters before compliance clears them?
How should ongoing screening and alert dismissals be recorded?
What is involved in remediating existing client files onto a new standard?
Who owns the code and where does the client data live?
What does a $50,000 custom software budget actually buy?
What is a discovery phase, and is it worth paying for separately?
We run everything on Airtable and spreadsheets. When is it time to go custom?
Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?
How do I make sure custom software is secure and compliant with rules like HIPAA?
How long does it take from first call to software my team can actually use?
Does the tech stack matter, and which one should I ask for?
Should I ask for a fixed price or pay the agency hourly?
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.