Problems & solutions · Custom Software

AML and KYC Onboarding Software Problems: The 7 That Fail an Inspection, and How to Avoid Them

AML KYC Client Onboarding Software workflow illustration showing common problems and fixes.
The short answer

The most expensive failure in this category is work starting before the risk assessment exists. A partner opens a matter for an important client with a real deadline, compliance is still chasing a structure chart, and the file number is issued anyway because the system that issues file numbers has no idea a clearance is outstanding. Eighteen months later a supervisor samples that file and asks three questions: when was the risk assessment completed, what evidence supported it, and did work commence before it existed. The answers are in the timestamps and they are not good ones. The remedy is not more training. It is a hard gate in the system fee earners actually use, which is technically trivial and organisationally difficult, and it removes the single most common finding in practice inspections.

Why does digitise our onboarding form become a controls project?

Firms scope this as a form. Collect the identification, upload the documents, record a rating. Then the questions arrive. What stops a matter opening before clearance. Who may override a rating and what happens to the original proposal. What happens when the client is a holding company owned by two corporates, one of which is owned by a trust. What happens when a jurisdiction moves onto a high risk list next March and forty existing clients are suddenly in scope.

This is specific to professional practice because you do not onboard customers, you accept instructions on matters, and the obligation attaches at both levels. A client can be low risk and a matter high risk, and the file has to show the judgement at each. That means the deliverable is a set of controls with an evidence trail, not a data capture screen, and firms that discover this mid build end up with a form plus a spreadsheet, which is where they started.

The fix is to name the controls at kickoff and design them first: the matter opening gate, the override with reason, the immutable assessment record, the review trigger. Then build the form around them. Capture the risk assessment as a structured judgement rather than a numeric score, with factors, answers, evidence, a proposed rating and a confirmation or override by the responsible person in writing. Overrides are not a failure of the model, they are what the risk based approach expects, and the record of them is what protects the firm.

What goes wrong when existing client files are remediated onto a new standard?

Firms budget the software and forget the remediation, which is frequently the larger programme. Every existing client has to be assessed under the current model, gaps in identification and source of funds evidence identified, and outreach sequenced. That means contacting clients who consider themselves long standing and well known to the firm and asking them for documents, which partners resist and which takes months.

The data problem underneath is that legacy files are documents, not records. A structure chart is a slide from a pitch deck, identification is a photograph in an email thread, and the rating is a tick on a paper form signed by someone who has retired. None of it carries the fields a new system needs, so migration is really re assessment with a document attached.

The fix is to sequence by risk and by activity rather than attempting the whole book. Prioritise clients with live matters and high ratings, run them through the new standard first, and use the review scheduling in the new system to carry the remainder across a defined period with progress visible to the managing partner. Attach legacy documents to the new record so nothing is lost, but do not pretend they populate fields they do not. And publish a completion percentage internally, because remediation programmes without visible progress stall in month three and stay stalled until an inspection wakes them up.

Why do screening, identity verification and practice management integrations break after launch?

Three integrations carry this category. Screening providers such as ComplyAdvantage or LexisNexis Bridger Insight change their data continuously, which is the point, so a match you saw in March may not reproduce in September. Identity verification through Amiqus or Thirdfort is journey based, so the failure mode is an abandoned journey rather than an error: the client started, could not complete, and nothing in your system knows the difference between not started and stuck. Practice management integration is the one that has to write as well as read, because a gate that cannot block matter opening is advisory.

The break after launch is usually a silent gap rather than an outage. Ongoing screening runs, hits accumulate in a queue, nobody has been given ownership of the queue, and six months later you hold a record of alerts you received and did not act on. That is worse than not screening, because it is documented.

The fix is to preserve state and assign ownership. Store screening results as they appeared at the time of the decision, with the match data, the discounting reason, the reviewer and the timestamp, held immutably rather than re queried. Give the alert queue a named owner and a service level, and report on the age of the oldest open item to the reporting officer weekly. For identity journeys, model the states explicitly, including expired and abandoned, and chase from the system rather than from a partner's memory. For practice management, test the gate as a control, meaning someone tries to open a matter without clearance and confirms they cannot.

What happens when the matter gate and periodic review are not covered?

These two gaps produce the findings. The matter gate is the one that catches new work: without it, compliance is advisory and advisory controls fail under deadline pressure, every time, at every firm, regardless of culture. The gate has to live in the process fee earners already use, which usually means the matter opening flow in your practice management platform cannot issue a file number until a completed risk assessment and clearance exist.

Periodic review catches the existing book. It blocks nothing, so it slips, and then a supervisor asks when a long standing high risk client's file was last refreshed and the honest answer is several years ago.

The fix on the gate is to build it as a hard control with a documented exception path, because there will be genuine emergencies and an undocumented workaround is worse than a documented one. Log every exception with an approver. The fix on review is to make the cycle part of the data: each client carries a review frequency derived from its risk rating, the system generates the review as work with an owner and a due date, and overdue items escalate to the reporting officer and appear on a dashboard the managing partner sees. Trigger events matter as much as the calendar, so a new matter of a different type, a change in the ownership graph, a screening hit or a jurisdiction moving onto a high risk list should all raise a review rather than waiting for an anniversary.

Should you build custom or configure what you already own?

Configure and stop if you are a smaller practice with a fairly homogeneous client base. Amiqus or Thirdfort will handle individual identity verification and source of funds collection properly, and both are materially better than emailed photographs. ComplyAdvantage handles screening. Connect those to your practice management system and you have most of the obligation covered for a subscription, and most firms under roughly fifty fee earners should stop there and spend the difference on a better trained compliance function.

They become limiting in three specific situations. Your clients are corporate structures, trusts and funds, so beneficial ownership needs a graph rather than a form. Your own risk model has to be applied consistently across the firm and a generic product's scoring cannot express it. Or you need compliance clearance to genuinely block matter opening rather than advise on it, which requires depth in the system fee earners use.

The tipping point is when compliance stops being a form and becomes a control that has to be enforced by software because it cannot be enforced by asking. A useful middle path is to keep the verification and screening products, which are genuinely good at what they do, and build only the assessment, ownership modelling and gate layer around them. That is a smaller project than replacing anything and it addresses where the findings actually come from.

How do hidden costs get into an AML software quote?

The first is practice management integration depth. Reading matters is straightforward. Blocking matter opening is not, and older on premise installations may need a middleware layer rather than a modern interface. Since the gate is the whole value, this is not a place to accept a vague answer, and it should be proven against your actual instance in the first two weeks rather than described.

The second is client complexity. A firm doing private client trust work has a materially harder ownership modelling problem than one doing residential conveyancing, and a quote scoped on your simplest clients will miss the layered structures entirely. Bring three of your hardest real structures to the scoping conversation.

The third is multi jurisdiction operation, because each additional supervisor is a rule set with its own evidence expectations. The fourth is remediation, which is frequently larger than the software. In Digital Heroes delivery experience a focused first release covering client and matter risk assessment, onboarding workflow with a hard gate, document collection and the evidence file runs 60,000 to 130,000 US dollars over 10 to 16 weeks, with a full platform at 180,000 to 400,000 over 6 to 12 months.

What separates an AML build that works from one that fails?

The builds that work model the ownership structure as a graph from the first sprint. Entities and relationships with percentages, dates and evidence attached to each link, so effective ownership computes through layers and anyone crossing the relevant threshold surfaces automatically. The United States customer due diligence rule uses a twenty five percent beneficial ownership threshold for legal entity customers at covered financial institutions, and comparable thresholds operate elsewhere, but a threshold never resolves control exercised by other means, so the model needs a place to record that judgement too. Firms that store a structure chart as a document have built a filing cabinet that looks complete and answers nothing.

They also keep the human judgement visible. Source of funds and source of wealth are different questions and conflating them is a routine inspection finding, so capture each as a stated position with supporting documents, a reviewer's conclusion on whether the evidence supports the statement, and explicit flags where the chain has gaps. Extraction tooling has a real role reading bank statements into structured transactions so a reviewer can follow the flow rather than read PDFs, and it must never conclude, because the determination is a regulated judgement made by a named person.

The builds that fail share three habits. They re query screening providers instead of preserving what the reviewer actually saw, which means a discounted alert cannot be defended later. They build the gate as a warning rather than a block. And they leave the review queue without an owner, which converts a control into a documented backlog. Ask any prospective developer what happens when a risk rating is overridden. If the override is hidden rather than recorded with its reasoning and the original proposal, the system will be an embarrassment during an inspection rather than a defence.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. A 100-millisecond delay in website load time can cut conversion rates by 7%; a two-second delay increases bounce rates by 103%; and 53% of mobile visitors leave a page that takes longer than three seconds to load. Source: Akamai Technologies (2017) →
  2. The performance gap between digital and AI leaders and laggards is widening: McKinsey reports leaders pull ahead on shareholder returns, and the average maturity spread between top and bottom performers jumped ~60% (from 10 points in 2016-19 to 16 points in 2020-22), reinforcing that the returns to transformation concentrate among top performers. Source: McKinsey & Company (2023) →
  3. Total US training expenditure rose 4.9% to $102.8 billion; learning management systems were used at 89% of organizations (90% of large, 97% of midsize, 84% of small companies), with average training at 40 hours per employee and $874 spent per learner. Source: Training Magazine (2025) →
  4. Grand View Research valued the global field service management market at USD 4.43 billion in 2022 and projects it to reach USD 11.78 billion by 2030, a 13.3% CAGR, driven by growing field operations in telecom, utilities, construction and energy. Source: Grand View Research (2023) →
Aanya B. · Senior Frontend Engineer · Next.js · Delhi

Aanya builds frontends in Next.js at Digital Heroes, covering rendering strategy, component structure, accessibility and the performance work that decides how a site feels on a mid range phone. Her writing translates frontend decisions into the outcomes non technical stakeholders actually care about.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How do we stop fee earners opening matters before compliance clears them?
Put the gate in the process they already use, which usually means the matter opening flow in your practice management platform cannot issue a file number until a completed risk assessment and clearance exist. Build it as a hard block with a documented exception path and a named approver, because genuine emergencies will happen and an undocumented workaround is worse than a documented one. A compliance tool sitting alongside matter opening rather than in front of it is advisory, and advisory controls fail under deadline pressure.
Why is storing a structure chart as a PDF a problem?
Because it makes the file look complete while answering nothing. You cannot compute effective ownership through layers, you cannot surface who crosses the relevant threshold, and you cannot tell what changed when the client restructures. Model entities and relationships as a graph with percentages, dates and evidence attached per link, plus a place to record control exercised by means other than shareholding. Periodic review then becomes a question of which links changed rather than a fresh charting exercise every time.
Our screening queue has hundreds of open alerts. What went wrong?
Almost always ownership rather than technology. Ongoing screening was switched on, hits accumulated, and nobody was given the queue with a service level and a reporting line. That is worse than not screening continuously, because you now hold a documented record of alerts you received and did not act on. Assign a named owner, report the age of the oldest open item weekly to the reporting officer, and triage the backlog by client risk rating rather than by date received.
Can we re run screening later instead of storing the results?
No, and this is a common design mistake. Provider data changes continuously, which is the point of the service, so a match you saw in March may not reproduce in September and a supervisor asking why an alert was discounted will not accept a live re query as evidence. Store the match data exactly as it appeared at the time of the decision, alongside the discounting reason, the reviewer and the timestamp, held immutably. That record is what defends the judgement.
What is the difference between source of funds and source of wealth in practice?
Source of funds is where the money for this specific transaction came from. Source of wealth is how the client accumulated their overall wealth. Conflating them is a routine inspection finding and the fix is structural rather than educational: capture each as a stated position with supporting documents, a reviewer's conclusion on whether the evidence supports the statement, and explicit flags where the chain has gaps. Where funds pass through several accounts, the chain has to be traceable rather than summarised in a narrative box.
How large is the remediation programme for existing clients?
Frequently larger than the software project, and it is the item most firms omit from the budget. Every existing client has to be assessed under the current model, gaps identified and outreach sequenced, which means asking long standing clients for documents and managing partner resistance to that. Sequence by risk rating and by which clients have live matters, carry the remainder through the new system's review scheduling over a defined period, and publish a completion percentage internally or it will stall.
Are Amiqus and Thirdfort enough on their own?
For a smaller practice with a fairly homogeneous client base, yes, particularly combined with a screening provider and a link into practice management. They handle individual identity verification and source of funds collection well. They become limiting when clients are corporate structures and trusts needing an ownership graph, when your own risk model must be applied consistently and a generic score cannot express it, or when you need clearance to actually block matter opening rather than advise on it.
Can AI review bank statements for source of funds evidence?
It can extract and organise, and it must not conclude. Reading statements into structured transactions so a reviewer can follow the flow of funds, and flagging where a stated origin does not appear in the evidence, removes genuine clerical work and speeds up review considerably. The determination that evidence supports a stated source is a regulated judgement that has to be made by a named person, and the record must show who made it and what they were looking at when they did.
How many people should be working on my software project?
A typical $40,000 to $150,000 build runs on three to five people: a technical lead, one or two developers, a designer, and someone owning QA and project communication, often as overlapping part-time roles. More bodies do not make software arrive faster; past a point they slow it down with coordination overhead. The question that matters more than headcount is whether one named senior engineer is accountable for the outcome.
If an agency builds my software, who actually owns the code?
You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.
How do I make sure custom software is secure and compliant with rules like HIPAA?
Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.
Will custom software work with the tools we already use, like QuickBooks and Stripe?
Yes, and this is one of custom software's genuine advantages: QuickBooks, Stripe, Shopify, and most mainstream business tools publish documented APIs built for exactly this. Expect each standard integration to add one to two weeks of build time, and be suspicious of any quote that lists five integrations without asking what data flows in which direction. The hard cases are legacy systems with no API, which is a question to raise in discovery, not in week nine.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
What should I have ready before I contact a development agency?
Three things, none of them technical: a one-page description of the problem in your own words, a list of the tools and spreadsheets the new system must replace or connect to, and a must-have versus nice-to-have split of features. Add a budget range, even a wide one, because it changes the conversation from fantasy to engineering. You do not need a formal specification; producing that is what a discovery phase is for.
Does the tech stack matter, and which one should I ask for?
It matters less than agencies imply, provided it is boring. A mainstream stack, something like React or Next.js on the front end, Node.js or Python behind it, and PostgreSQL for data, means thousands of developers can maintain your system if you ever change vendors. Apply one test: ask how hard it would be to hire a replacement developer for the proposed stack, and walk away from anything built on an agency's in-house framework.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
Should we build an MVP first or go straight to the full system?
MVP first, for almost everyone: ship the single workflow that carries the business value in 10 to 16 weeks, learn from real users, then fund phase two from evidence instead of guesses. The caveat is that an MVP is a small version of a well-built system, not a badly built version of a big one; the data model must already support what comes next. An agency that cannot tell you what they deliberately left out of your MVP has not designed one.
Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?