A partner at a Melbourne firm showed me their compliance folder last month.
It was thorough. Identity documents scanned and filed. A risk assessment form completed at onboarding. Emails exchanged with the client about source of funds. All of it there, in a well-organised drive folder.
I asked one question: “If AUSTRAC issued a Section 167 notice tomorrow asking you to demonstrate your ongoing CDD for this client over the past two years, how long would it take to produce that?”
Long pause. Then: “We would have to go through emails, pull the Xero notes, find the original file, check if anything changed since onboarding.”
That is not an audit trail. That is an audit recovery project.
The gap between having records and having an audit trail is where most firms are currently exposed.
The difference is not volume. The Melbourne firm had plenty of documents. The difference is connection. An audit trail links who the client was, what changed in their risk profile, when a trigger event occurred, what the firm did about it, and who made the decision — in sequence, traceable, retrievable in minutes not days.
This is what an Evidence Graph does.
A document vault answers one question: did you collect this?
An Evidence Graph answers five: who was this client, what changed, when did the firm know, what decision was made, and what evidence supports that decision.
In an examination, AUSTRAC can follow the chain from the initial risk assessment through trigger events, periodic reviews, and CDD updates. A folder full of documents can show you collected the right things at onboarding. It cannot show what happened on the 400 days after that.
The firms that survive Tranche 2 examinations cleanly will not be the ones with the most complete folders. They will be the ones whose system connected every document to a decision, every decision to a timestamp, and every timestamp to the client relationship it belongs to.
If your audit trail only exists after someone spends two days rebuilding it, it is not an audit trail yet.


