Industry guide · Custom Software

AML and KYC Client Onboarding Software for Law Firms and Regulated Practices: What It Costs to Close the Gap Between Matter Opening and a File Your Supervisor Will Accept

Aml Kyc Client Onboarding software visual showing id card lanyard, mail question, and compliance shield.
The short answer

If you are the money laundering reporting officer at a firm with more than roughly 50 fee earners, running client and matter risk assessments in spreadsheets while partners chase documents by email, a custom build is usually justified. A focused first release covering risk assessment, client and matter onboarding workflow, document collection and the evidence file typically runs $60,000 to $130,000 and ships in 10 to 16 weeks in our delivery experience. A full platform adding beneficial ownership mapping, screening integration with alert adjudication, source of funds workflow, periodic review scheduling and practice management integration lands at $180,000 to $400,000, phased over 6 to 12 months. Below that size, Amiqus or Thirdfort connected to your practice management system is the right answer and costs a fraction.

Why onboarding stalls where the regulator later looks

A corporate partner wants to open a matter on Monday. The client is a holding company registered offshore with two corporate shareholders, one of which is a trust. Compliance needs identification for the individuals who ultimately own or control it, a structure chart, an explanation of where the funds for the transaction come from, and a risk assessment recorded before work begins. The partner sends an email asking for passports. Two arrive as phone photographs, one as a scan of a scan. The structure chart arrives as a slide from a pitch deck. Three weeks pass. Work has quietly started because the client is important and the deadline is real. When the supervisor visits eighteen months later and samples files, the questions will be when the risk assessment was completed, what evidence supported it, and whether work commenced before it existed.

The tools around this are genuinely useful. Amiqus and Thirdfort handle individual identity verification and source of funds collection well, and consumer-facing verification through those channels is far better than emailed photographs. ComplyAdvantage and LexisNexis Bridger Insight are serious screening providers. What none of them owns is the shape of a professional practice's obligation: risk assessed at both client and matter level, an engagement that cannot open until compliance clears it, partner accountability, and a file that a professional body supervisor will recognise as complete. Those products were largely built for financial institutions onboarding customers. A law firm does not onboard customers, it accepts instructions on matters, and the difference is not cosmetic.

Problem 1: the risk assessment is a documented judgement, not a score

The Money Laundering Regulations 2017 in the United Kingdom, and the risk-based approach in every comparable regime, require a firm-wide risk assessment and then risk assessment of the individual relationship, with the level of due diligence following from it. Supervisors do not object to a firm concluding that a client is low risk. They object when the conclusion has no reasoning, when it contradicts obvious factors like an offshore structure or a politically exposed person connection, or when it was recorded after the work started.

Build it as a structured judgement with an audit trail rather than a numeric score. Factors are captured with their answers and their evidence, the model proposes a rating, and the responsible person confirms or overrides with a written reason. Overrides are not a failure, they are the point: professional judgement is what the regulations expect, and the record of it is what protects the firm. Every assessment is timestamped and immutable once submitted, and the matter opening workflow refuses to release a file number until it exists. That single control, technically trivial, removes the most common finding in practice inspections.

Problem 2: beneficial ownership is a graph, and everyone stores it as a document

An offshore holding company owned by two corporates, one of which is owned by a trust with a protector and a class of discretionary beneficiaries, sitting under a nominee arrangement. The obligation is to identify the natural persons who ultimately own or control the client, and to understand the ownership and control structure. Under the United States customer due diligence rule the beneficial ownership threshold for legal entity customers at covered financial institutions is 25 percent, and comparable thresholds operate elsewhere, but a threshold does not resolve control exercised by other means.

Storing a structure chart as a PDF makes the file look complete and answers nothing. Model the structure as entities and relationships with percentages, dates and evidence per edge, so the system can compute effective ownership through layers and surface anyone crossing the threshold or holding control by other means. Then when the client restructures, you update an edge rather than commissioning a new chart. This is also where periodic review becomes cheap: the question is not whether to redo the whole exercise, it is which edges have changed. Firms that do this stop treating group clients as a fresh project every time a new matter opens.

Problem 3: source of funds is evidence gathering, not a text field

Source of funds means where the money for this transaction came from. Source of wealth means how the client accumulated their wealth overall. They are different questions, they are frequently conflated, and the conflation is a standard inspection finding. Both require evidence proportionate to risk: bank statements showing the funds arriving and their origin, a sale contract, a probate grant, share sale documentation, tax returns.

The build should treat these as evidence chains rather than narrative boxes. A stated source, the documents supporting it, a reviewer's conclusion on whether the evidence supports the statement, and gaps flagged explicitly. Where funds pass through several accounts before arriving, the chain has to be traceable rather than summarised. Extraction tooling has a genuine role, reading bank statements into structured transactions so a reviewer can follow the flow instead of reading PDFs, and flagging where a stated origin does not appear. It should never conclude. The conclusion is a regulated judgement made by a named person, and the record must show who made it and what they saw.

Problem 4: screening produces noise, and the noise is the record

Sanctions, politically exposed person and adverse media screening against a common name produces alerts, most of them irrelevant. Whether a firm dismisses them properly is exactly what an inspection examines. The failure is not the false positive, it is a dismissal with no recorded reason, or a screening run whose results nobody can reproduce because the provider's data has moved on.

Keep the screening provider, because maintaining sanctions and adverse media data is not a build you should attempt, and connect it. What you build is the adjudication layer: every alert with the match data as it was at the time, the discounting reason, the reviewer, and the timestamp, stored immutably. Ongoing screening then runs continuously against the client base rather than only at onboarding, because a client who was clean in March may be listed in September and the obligation is ongoing. Route new hits to a queue with a service level, and report on the queue, because a screening system nobody clears is worse than none: it creates a record of alerts you received and did not act on.

Problem 5: periodic review is where good firms quietly fall behind

Onboarding gets attention because it blocks revenue. Periodic review does not block anything, so it slips, and then a supervisor asks when the file on a long-standing high risk client was last refreshed and the honest answer is 2019. Every firm knows this and most fix it with a spreadsheet and a diary reminder that survives until the compliance manager changes.

Build the review cycle into the data: each client carries a review frequency derived from its risk rating, the system generates the review as work with an owner and a due date, and overdue reviews escalate to the reporting officer and appear on a management dashboard the managing partner sees. Trigger events matter as much as the calendar: a new matter of a different type, a change in the ownership graph, a screening hit, a jurisdiction moving onto a high risk list. Those should all raise a review rather than waiting for the anniversary. The dashboard is the deliverable that changes behaviour, because partners respond to visibility in a way they do not respond to email reminders.

What this costs and how long it takes

Across the 2,000-plus projects Digital Heroes has delivered, here is the honest shape. A focused first release covering client and matter risk assessment, the onboarding workflow with a hard gate on matter opening, document collection and the structured evidence file runs $60,000 to $130,000 and ships in 10 to 16 weeks. A full platform adding beneficial ownership graph modelling, screening integration with alert adjudication, source of funds evidence chains, periodic review scheduling with escalation, and integration into your practice management and matter opening systems runs $180,000 to $400,000 phased over 6 to 12 months.

What drives price up: integration depth with your practice management system, because a compliance tool that does not stop a matter opening is advisory rather than controlling and the hard gate is the whole value. The complexity of your client base, since a firm doing private client trust work has a materially harder ownership modelling problem than one doing residential conveyancing. Multi-jurisdictional operation, because supervisors differ in what they expect to see in a file. And migration, since existing client files have to be assessed and brought onto the new standard, which is a remediation programme in its own right and frequently larger than the software project.

Build versus buy, and when buying is right

Buy, and do not call us, if you are a smaller practice with a fairly homogeneous client base. Amiqus or Thirdfort will handle identity verification and source of funds collection properly, ComplyAdvantage will handle screening, and connecting those to your practice management system gets you most of the way for a subscription. That combination is genuinely good and most firms under about 50 fee earners should stop there.

Build when two or more of these are true. Your risk model is your own and your supervisor expects to see it applied consistently, which a generic product's scoring cannot express. Your clients are corporate structures, trusts and funds where beneficial ownership requires a graph rather than a form. You need a hard gate between compliance clearance and matter opening, integrated into the system fee earners actually use. You operate under more than one supervisor or in more than one jurisdiction. Or your periodic review programme has fallen behind and you need scheduling, escalation and visibility built into the workflow rather than maintained beside it. The tipping point is when compliance stops being a form and becomes a control that has to be enforced by software because it cannot be enforced by asking.

How to choose a developer for AML onboarding software

Ask them how they model an ownership structure. If the answer is a document upload, they have built a filing cabinet. You want entities and relationships with percentages, dates and evidence attached per edge, and the ability to compute effective ownership through layers and identify control exercised by means other than shareholding.

Ask what happens when a risk rating is overridden. The right answer treats the override as expected professional judgement, captures the reason, records who made it, and keeps the original proposal visible. A system that hides overrides is a system that will be embarrassing in an inspection.

Ask how screening results are preserved. You need the match data as it was at the time of the decision, not a live re-query, because provider data changes and you must be able to show what your reviewer actually saw when they discounted an alert.

Ask who owns the code and get it in writing before kickoff. You should own the repository, the infrastructure accounts and the right to hire another firm. At Digital Heroes the code is yours from the first commit. This system holds identity documents and financial evidence for your clients, so also ask where that data lives, how long it is retained, and how a deletion request is honoured, because your data protection obligations do not pause because a compliance obligation exists.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey argues software developer productivity can be measured by combining system-level metrics (DORA and SPACE) with its own outcome-oriented approach, which it reports deploying across nearly 20 tech, finance, and pharmaceutical companies - a claim that sparked significant debate in the engineering community. Source: McKinsey & Company (2023) →
  2. The 2015 CHAOS data (based on the modern definition of success) reports that only about 29% of software projects succeed, 52% are challenged, and 19% fail, with the three most important success skills being executive sponsorship, emotional maturity, and user involvement. Source: The Standish Group (reported via InfoQ Q&A with Jennifer Lynch) (2015) →
  3. In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
  4. 88% of organizations are concerned about employee retention, and providing learning opportunities is respondents' #1 retention strategy; career progress is cited as people's top motivation to learn, yet only 36% of organizations qualify as 'career development champions.'. Source: LinkedIn Learning (2025) →
Khushi G. · Project Manager · Lucknow

Khushi runs several client projects at once, which mostly means deciding whose problem gets solved first. She coordinates developers, designers and clients across time zones, tracks budget against work completed, and raises the difficult conversation early. Readers learn how an agency actually allocates attention when everything is urgent.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom AML and KYC onboarding software cost for a law firm?
A focused first release covering client and matter risk assessment, onboarding workflow with a hard gate on matter opening, document collection and the evidence file runs $60,000 to $130,000 and ships in 10 to 16 weeks, based on Digital Heroes delivery experience. A full platform adding ownership graph modelling, screening adjudication, source of funds chains and periodic review runs $180,000 to $400,000 over 6 to 12 months. Integration depth with practice management usually drives cost more than feature count.
Are Amiqus and Thirdfort enough, or should we build?
For a smaller practice with a fairly homogeneous client base they are genuinely good and most firms under roughly 50 fee earners should stop there, combining them with a screening provider and a connection to practice management. They become limiting when your clients are corporate structures, trusts and funds where beneficial ownership needs a graph rather than a form, when your own risk model must be applied consistently across the firm, or when you need compliance clearance to actually block matter opening rather than advise on it.
How should software handle beneficial ownership for offshore and trust structures?
Model entities and relationships as a graph with percentages, dates and evidence attached to each link, then compute effective ownership through layers rather than storing a structure chart as a document. That lets the system surface anyone crossing the relevant threshold, such as the 25 percent used in the United States customer due diligence rule for legal entity customers, and flag control exercised by other means. It also makes periodic review cheap, because you are checking which links changed rather than rebuilding the chart.
What is the difference between source of funds and source of wealth in a compliance file?
Source of funds is where the money for this specific transaction came from. Source of wealth is how the client accumulated their overall wealth. Conflating them is a routine inspection finding, and the fix is structural: capture each as a stated position with supporting documents, a reviewer's conclusion on whether the evidence supports the statement, and explicit flags where the chain has gaps. Where funds pass through several accounts, the chain must be traceable rather than summarised in a narrative box.
Can AI review bank statements for source of funds?
It can extract and organise, and it must not conclude. Reading statements into structured transactions so a reviewer can follow the flow of funds, and flagging where a stated origin does not appear in the evidence, removes genuine clerical work. The determination that evidence supports a stated source is a regulated judgement that has to be made by a named person, and the record must show who made it and what they were looking at when they did.
How do we stop fee earners opening matters before compliance clears them?
Put the gate in the system fee earners actually use, which usually means the matter opening process in your practice management platform cannot issue a file number until a completed risk assessment and clearance exist. This is technically simple and organisationally difficult, and it is also the control that removes the most common finding in practice inspections. A compliance tool that sits alongside matter opening rather than in front of it is advisory, and advisory controls fail under deadline pressure.
How should ongoing screening and alert dismissals be recorded?
Keep a commercial screening provider rather than building sanctions and adverse media data yourself, and build the adjudication layer around it. Every alert should be stored with the match data exactly as it appeared at the time, the discounting reason, the reviewer and the timestamp, held immutably. Run screening continuously rather than only at onboarding, and report on the open queue, because a system that generates alerts nobody clears creates a record of things you were told and did not act on.
What is involved in remediating existing client files onto a new standard?
Treat it as a programme in its own right, frequently larger than the software project. Existing clients have to be risk assessed under the current model, gaps in identification and source of funds evidence identified, and outreach sequenced so the highest risk relationships are refreshed first. The practical approach is to prioritise by risk rating and by which clients have live matters, then use the new system's review scheduling to carry the remainder over a defined period with progress visible to the managing partner.
Who owns the code and where does the client data live?
You should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm, agreed in writing before kickoff, and at Digital Heroes the client owns the code from the first commit. Ask separately about data: this system holds identity documents and financial evidence belonging to your clients, so you need clarity on hosting location, retention periods and how a deletion request is handled, because data protection obligations run alongside your compliance obligations rather than being displaced by them.
What does a $50,000 custom software budget actually buy?
One core workflow done properly: 10 to 15 screens, two or three user roles, a couple of integrations, an admin panel, and automated tests, delivered in roughly 12 to 14 weeks. What it does not buy is that workflow plus a mobile app plus AI features plus five more integrations. The discipline of picking the one workflow that matters is what separates $50,000 projects that ship from $50,000 projects that stall at 70% complete.
What is a discovery phase, and is it worth paying for separately?
Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.
We run everything on Airtable and spreadsheets. When is it time to go custom?
The switch usually makes sense when you hit one of two walls: Airtable's record caps (125,000 records per base on the Business plan) or logic the tool cannot express, like multi-step approvals with conditional pricing. There is also a simple cost signal: 25 people on Business at roughly $45 per seat per month is about $13,500 a year, forever, for a tool you are already fighting. Custom is worth it when the workflow is core to how you make money; for peripheral processes, staying on Airtable is the right call.
Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?
For validating an idea with real users, yes, and we tell clients that honestly. The walls come later: Bubble apps cannot be exported as code to run anywhere else, performance drops on complex data operations, and usage-based pricing climbs as you grow. A meaningful share of Digital Heroes custom builds are rebuilds of no-code MVPs that proved the business worked, which is the system operating as intended: validate cheap, then build the version that scales.
How do I make sure custom software is secure and compliant with rules like HIPAA?
Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.
How long does it take from first call to software my team can actually use?
Plan for four to six months: two to three weeks of discovery, two to four weeks of design, then a 10 to 16 week build with testing. In Digital Heroes delivery experience the schedule killer is not engineering speed but decision lag; a client who takes two weeks to approve wireframes adds two weeks to launch. Book a weekly 30-minute decision slot before kickoff and most of that risk disappears.
Does the tech stack matter, and which one should I ask for?
It matters less than agencies imply, provided it is boring. A mainstream stack, something like React or Next.js on the front end, Node.js or Python behind it, and PostgreSQL for data, means thousands of developers can maintain your system if you ever change vendors. Apply one test: ask how hard it would be to hire a replacement developer for the proposed stack, and walk away from anything built on an agency's in-house framework.
Should I ask for a fixed price or pay the agency hourly?
Fixed price for the first version, hourly or retainer for what comes after launch. A fixed-scope, fixed-price V1 puts the estimation risk on the agency, which is exactly where you want it while trust is unproven; hourly billing on an unscoped greenfield build is a blank check. After launch, flip it, because maintenance and small features arrive unpredictably and fixed-pricing every ticket wastes everyone's time.
Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?