9 questions to ask whoever manages your systems
Including us.
·18 August 2026·About 5 minutes
AML/CTF and the Privacy Act have arrived together with a great deal of noise and very little that tells someone what to actually check.
Almost all of it comes down to how your systems are configured, and that is one part of your business you cannot inspect for yourself. The only way to find out is to ask whoever manages them.
So we wrote the questions for you to ask. Nine of them, built from what the regulator expects a business to do to protect the personal information it holds. Each one comes with what a good answer sounds like, and why you are asking it.
9 Helpful questions
1. Can you give me a current list of every place client identity documents are held, which systems they sit in, and who can open each one?
A good answer sounds like: here is the list, here is when it was last updated, and here is who has access to each place on it.
Why you are asking: if nobody can produce that list, none of the answers below can be relied on. A document cannot be protected, handed over or deleted until somebody knows where it is.
2. Is multi-factor authentication turned on for every person on every system, and can you show me the exceptions?
A good answer sounds like: everyone, everywhere, and there are two exceptions, which are these, for this reason, until this date.
Why you are asking: a password on its own can be leaked, guessed, or given away to a convincing email. Somebody only needs one account with no second step to get in, and that account is usually an old one nobody uses any more.
3. What is patched automatically, what needs somebody to do it by hand, and is anything we use no longer supported?
A good answer sounds like: a named list for each of the three, with a date against anything still outstanding.
Why you are asking: every piece of software reaches a date after which the company that wrote it stops issuing updates for that version. Past that date, any new weakness somebody finds in it is never fixed, and those weaknesses are logged in public databases that anyone can read.
4. If I asked who opened a particular client file in March, could you tell me? And could you tell me the same about the mailbox those documents were emailed to?
A good answer sounds like: yes to both, and here is how far back the record goes.
Why you are asking: most identity documents arrive by email and never leave it. If the mailboxes are not covered, the place a client's licence is most likely sitting is the one place nobody can see into.
5. Which outside parties can reach our client identity data, and what do our agreements with them say about handling it?
A good answer sounds like: a named list of the parties, and the clause in each agreement that covers it.
Why you are asking: if a supplier loses your client's documents, it is still your client on the phone. Katie Miller, Deputy Chief Executive Officer of AUSTRAC, told the Law Society Journal: "You can outsource the doing and the execution, but you can't outsource the liability and responsibility." The agreement is the only say you have in how they hold it.
6. Where is our data breach response plan, when was it last tested, and who has the authority to make decisions during an incident?
A good answer sounds like: a document you can open now, a test within the last year, and a named person with a named deputy.
Why you are asking: incidents start at inconvenient hours. A plan nobody has opened since it was written will not be found or followed quickly, and every hour of delay costs more than the last. With no named decision maker, the first call stalls while somebody works out who can make it.
7. How are client identity documents removed once we no longer need them, and does that happen automatically or does somebody have to remember?
A good answer sounds like: a rule that runs to a schedule, and a report showing what it removed.
Why you are asking: the obligation is to take reasonable steps to destroy or de-identify information once it is no longer needed. Anything relying on a person remembering works for a while and then stops, and nobody notices. The report is how you know it is still running.
8. If a client asked for everything we hold about them, could we produce it, and could we hold back specific records without the system revealing why?
A good answer sounds like: yes to both, with the second one demonstrated rather than assumed.
Why you are asking: a request like this comes with a deadline, and there are circumstances where particular records have to be held back and the reason cannot be given. If the system can only hand over everything or nothing, both answers are wrong.
9. If our systems were breached tonight, how quickly could you tell me exactly which client records were reached?
A good answer sounds like: within hours, from records we already keep, and here is what that report looks like.
Why you are asking: nothing can be shut down and no client can be told anything until somebody knows what was reached. The thirty day assessment period the Privacy Act allows starts the moment a firm suspects a breach, not the moment it works out what happened, so every day spent piecing it together is a day gone. Answering in hours means reading records that were set up beforehand.
Before you have the conversation
Take these to whoever manages your systems. Before you do, spend three minutes finding out which of the nine your firm already has covered.
Our AML/CTF technology and data checklist asks thirteen questions, and gives you a written findings report. You walk in with the report rather than a list of questions, so the conversation starts at the gaps. Start the checklist.
Questions 1 to 6 are built from the OAIC's published examples of reasonable steps under Australian Privacy Principle 11.1. Questions 7 to 9 come from other parts of the same guidance. The OAIC describes those examples as examples rather than a complete list. efex does not determine whether a business is captured by AML/CTF. That question belongs to the business and its own advisers.
Thirteen questions. About three minutes. No client files.
Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.
These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.
