Skip to content
View all servicesIndependent AML/CTF evaluationML/TF risk assessment + AML/CTF programRemediation and advisory
ResourcesMeet the team
AustraliaAUNew ZealandNZ
Request a quote
Australia

Services

00View all services01Independent AML/CTF evaluation02ML/TF risk assessment + AML/CTF program03Remediation and advisory
ResourcesMeet the team
Switch to NZRequest a quote

Client safeguards • Australia

Client Data

The operating rules used to protect audit evidence, CDD samples and other client information, including when AI may assist.

Applies from29 July 2026
MarketAustralia

At a glance

  • Only the minimum client information needed should be supplied
  • Consumer AI accounts are not approved for personal or sensitive data
  • Every AI-assisted conclusion requires human source checking
  • Clients may opt out of AI before an engagement begins

On this page

  1. 01Purpose and status
  2. 02Responsibilities
  3. 03Client authority and notice
  4. 04Minimum information
  5. 05Prohibited and restricted information
  6. 06Transfer and access
  7. 07Permitted AI assistance
  8. 08AI controls
  9. 09AI uses that are not permitted
  10. 10Client choice and opt-out
  11. 11Retention and deletion
  12. 12Incidents and individual requests
  13. 13Providers and overseas processing
  14. 14Review and contact
On this page
  1. 01Purpose and status
  2. 02Responsibilities
  3. 03Client authority and notice
  4. 04Minimum information
  5. 05Prohibited and restricted information
  6. 06Transfer and access
  7. 07Permitted AI assistance
  8. 08AI controls
  9. 09AI uses that are not permitted
  10. 10Client choice and opt-out
  11. 11Retention and deletion
  12. 12Incidents and individual requests
  13. 13Providers and overseas processing
  14. 14Review and contact
01

Purpose and status

This Client Data and AI Schedule sets the minimum rules for client information used during a Seamless AML engagement. It applies when it is referred to in a proposal, engagement letter or other accepted engagement document.

If this Schedule conflicts with the engagement letter, the engagement letter takes priority for that engagement. A law, regulator direction or court order takes priority over both.

02

Responsibilities

Client
Decides what information is supplied, keeps the original statutory records, controls its nominated users and remains responsible for its legal duties.
Seamless AML
Uses information only for the accepted work, protects the copies it holds, keeps a suitable work record and returns or deletes material under this Schedule.
Both parties
Must act promptly on access changes, suspected breaches, legal restrictions and requests from an individual or regulator.

Each party is responsible for the personal information it holds. A party may also be treated as holding information processed by a service provider acting on its behalf.

03

Client authority and notice

The client confirms that it has lawful authority to collect, use and disclose the information supplied for the engagement. It must meet any confidentiality, privilege, employment, secrecy and privacy duties that apply before material is shared.

Where personal information is supplied about customers, beneficial owners, staff or other people, any required collection or indirect collection notice must be given. For New Zealand information, this includes Information Privacy Principle 3A from 1 May 2026 unless an exception applies. The client must be able to explain the lawful basis or exception if asked.

04

Minimum information

Only information reasonably needed for the agreed scope should be supplied. Before transfer, the client should remove unrelated documents, blank pages, duplicate files, account passwords, authentication codes and information outside the sample or period requested.

  • Registers and client lists should use internal identifiers where names are not needed.
  • Identity documents should be limited to the selected test sample and should not be supplied if a result or verification record is enough.
  • Transaction data should be limited to the fields and period needed for the test.
  • Health, criminal, biometric and other highly sensitive information should be removed unless its review is necessary and agreed.
  • The client should tell Seamless AML if a document contains legal privilege or a special secrecy restriction.
05

Prohibited and restricted information

New Zealand SAR material

A full SAR register, an SAR, or information that discloses or is reasonably likely to disclose the existence of an SAR must not be supplied to Seamless AML. Process evidence, blank templates, training records, access controls and a compliance officer attestation may be used instead.

Australian SMR material

An SMR, a document prepared for an SMR, or information protected by the tipping-off offence must not be supplied unless the client has assessed the disclosure as lawful and it has been agreed in writing. A restricted and de-identified evaluation extract should be used where it can meet the test.

SAR and SMR information must never be sent to an AI provider. It must not be placed in a public form, ordinary email or an unrestricted shared link.

06

Transfer and access

Client evidence should be transferred through the client's dedicated Dropbox folder or another method agreed in writing. Public enquiry forms are not approved transfer channels for client records.

  • Casey Marsh has direct access to the main client-data Dropbox.
  • A client folder is shared only with client users nominated for that engagement.
  • The client must tell Seamless AML when a user should be added or removed.
  • Multi-factor authentication should be used for accounts with access.
  • Links must not be forwarded and files must not be copied to personal accounts.
  • A specialist may receive only the minimum information needed, under confidentiality terms and with identifiers removed where practical.
07

Permitted AI assistance

Subject to this Schedule, an approved AI system may assist with:

  • researching legislation, rules and regulator materials
  • drafting and structuring working material and deliverables
  • checking references, consistency and missing cross-references
  • comparing working papers with source documents
  • suggesting possible risk ratings, findings or wording for human review
  • designing a sample-selection method without receiving an identifiable client list

These uses support the work. They do not transfer professional responsibility to the AI provider.

08

AI controls

Before client information is used with AI:

  1. the use must be needed for the accepted scope
  2. a suitable business or API service must have been approved after privacy, security and contract checks
  3. the provider's training, retention, location, access and subprocessors must be understood
  4. personal and confidential information must be removed or reduced where practical
  5. the input must exclude identity documents, authentication data, full raw CDD files, SARs and SMRs
  6. the output must be checked against the source evidence and law by a suitable person
  7. the material use of AI and the human check must be recorded in the work file

Personal or sensitive client information is not authorised for consumer ChatGPT, Claude or another consumer AI account. Client information must not be used to train a general model for other customers.

09

AI uses that are not permitted

  • making or issuing a finding, rating or professional conclusion without human review
  • selecting samples from a named or directly identifiable full client list
  • uploading a full client folder or bulk CDD repository
  • entering SAR, SMR, law-enforcement, password or authentication information
  • using client data to develop or train a model for unrelated use
  • trying to re-identify information that has been coded or de-identified
  • allowing an AI provider or plugin to send information to an unapproved third party
10

Client choice and opt-out

The client may request that no AI be used by giving written notice before the engagement begins. The proposal may then be revised to reflect any change to method, timing or fee.

If a request is made after work begins, it will be handled as a scope change. Work already completed in line with the accepted Schedule will not be repeated unless that is agreed.

11

Retention and deletion

Raw CDD and audit samples
Deleted within 90 days after the final report or deliverable, unless a legal hold or written exception applies.
Core engagement record
Kept for seven years after the engagement ends. It may include key working papers, test results, methodology, findings, correspondence, final deliverables, review evidence and the AI-use record.
Temporary AI input
Kept only for the shortest period supported by the approved service and required for the task. Zero-retention or equivalent settings should be used where available.

A client may ask for early return or deletion of material that is no longer needed. Seamless AML may keep information required by law, professional accountability, an insurer, a dispute or a legal hold. The client remains responsible for keeping its original AML records for the period required by law.

12

Incidents and individual requests

Each party must tell the other without undue delay if client information may have been lost, wrongly disclosed, altered or accessed without authority. The parties will cooperate to contain the event, preserve evidence, assess harm and meet any notification duty.

If an individual asks to access or correct information held for the engagement, the parties will cooperate so the request can be answered by the responsible agency. Protected SAR, SMR, privileged and third-party information will not be released where the law permits or requires refusal.

13

Providers and overseas processing

Approved providers may include Dropbox, Google Workspace, Xero, website and security providers, video meeting providers and approved AI services. Their systems or subprocessors may operate in New Zealand, Australia, the United States or other countries.

Suitable due diligence and contractual safeguards will be used before sensitive client information is processed. The current provider list relevant to an engagement can be requested.

14

Review and contact

This Schedule will be reviewed when the type of client data, AI use, provider or law changes. A material change affecting an active engagement must be agreed before the changed practice is used.

Questions or opt-out requests should be sent to casey@seamlessaml.com.

Related documents

Privacy statementWebsite termsEngagement terms
casey@seamlessaml.com+61 423 472 666

Services

View all servicesIndependent AML/CTF evaluationML/TF risk assessment + AML/CTF programRemediation and advisory

Company

ResourcesGuidance and legislationMeet the team

Legal

Privacy statementWebsite termsEngagement termsClient data

© 2026 Seamless AML

Switch to
AustraliaAUNew ZealandNZ