I was talking to a partner at a 12-person Sydney accounting firm last week.
They provide SMSF setup, business structuring, and M&A advisory — caught by Tranche 2 on at least three designated services. Enrolled with AUSTRAC. AML/CTF program drafted.
I asked one question: “What does your trigger detection look like today?”
Long pause.
“We rely on the relationship. If something changes with a client, they tell us.”
This is anecdotal compliance. The firm’s evidence of ongoing CDD is the partner’s memory of the client relationship. It feels sufficient because the relationships are real. It is not sufficient because AUSTRAC does not examine relationships — they examine records.
The gap between the two is where most accounting firms currently sit.
What Trigger Event Detection Actually Requires
When a director is quietly added to a client entity, the firm’s system should surface it before the client mentions it. When a sanctions list changes, a passive evidence system checks every active client relationship automatically — without the partner having to think about it. When a client moves from in-person service to online-only, the delivery channel risk assessment should update.
None of these require a partner to log in. None of them require the client to volunteer the information. They require a system that watches the right data sources continuously and surfaces only what needs a human decision.
Most firms do not have that system. They have a relationship.
“I’ve known him for 10 years” is not evidence. It is a confession of a lack of process.
The firms building for July 2026 are replacing anecdotal compliance with system evidence. The firms still relying on the relationship will find out the difference when the examination notice arrives.
Where does trigger detection break first in most firms: ownership changes, PEP changes, sanctions updates, or delivery-channel changes?


