Audit Readiness

Tamper-Evident
Evidence Packs

Versioned, hashed snapshots of every compliance decision — with configurable redaction rules that control what appears in different export contexts. Audit-ready evidence packs at the click of a button.

Overview

How It Works

An evidence pack is the culmination of your compliance work on a matter. It's a versioned, tamper-evident snapshot that captures every scoping decision, verification result, risk assessment, ECDD outcome, approval, and audit log excerpt for that engagement.

Every evidence pack is hashed using SHA-256 for integrity verification. If a single character changes in the pack, the hash changes — providing tamper detection that you can demonstrate to auditors. Version history maintains a complete record of how the evidence evolved.

Configurable redaction rules control what appears in different export contexts. Default exports exclude raw provider payloads, detailed sanctions hit information, and any SMR-related data. Your AMLCO can generate expanded 'sensitive packs' when explicitly needed — but the default is always privacy-protective.

Workflow

Step by Step

Follow the structured workflow from start to finish.

01

Evidence Accumulation

As your team works through the matter workflow, evidence accumulates automatically — scoping decisions, verification results, risk assessments, approvals.

02

Pack Generation

Generate an evidence pack snapshot at any point. The pack captures the current state of all compliance evidence for the matter.

03

SHA-256 Hashing

Each pack is hashed for tamper detection. The hash is stored alongside the pack, enabling integrity verification at any future date.

04

Redaction Rules Applied

Configurable rules control what appears in the export. Default packs exclude sensitive provider data, sanctions details, and SMR information.

05

Export & Distribution

Export as PDF (human-readable) or ZIP (PDF + attachments index + hashes + selected attachments). Ready for auditor review.

Capabilities

Key Features

Everything you need for this workflow, built into the platform.

SHA-256 Integrity Hashing

Every evidence pack is hashed for tamper detection. Demonstrate to auditors that evidence has not been altered since generation.

Version History

Complete version history with diff tracking. See exactly how evidence evolved across the matter lifecycle.

Configurable Redaction

Rules control what appears in each export context. Default packs protect sensitive data while remaining audit-ready.

PDF & ZIP Export

Human-readable PDF for review. ZIP bundles include the PDF, attachments index, file hashes, and selected supporting documents.

Automatic Evidence Capture

Evidence accumulates as your team works. No separate data entry — the compliance workflow is the evidence trail.

Sensitive Pack Generation

AMLCO can generate expanded packs with raw provider data when explicitly needed. Access controlled by role and permission flags.

Regulatory Context

Evidence for AUSTRAC Compliance Reviews

When AUSTRAC reviews your compliance, they expect to see documented decisions, rationale, verification evidence, and risk assessments for each designated service engagement. Evidence packs bundle all of this into a single, integrity-verified snapshot. Default redaction rules ensure that sensitive information (raw provider payloads, sanctions hit details, SMR data) is excluded unless explicitly required.

  • Record-keeping: 7-year retention from anchor date
  • Evidence must include: scoping decisions, CDD steps, risk ratings, approvals
  • Default exports exclude: raw provider payloads, sanctions details, SMR data
  • AMLCO-only access for expanded 'sensitive packs'

Be Audit-Ready from Day One

Tamper-evident evidence packs that demonstrate your compliance decisions and procedures.

Get Started