J. Harrow
Principal · Admin
Standard
D. Marsh
Senior Associate · Fee Earner
Standard
Risk & GC Office
General Counsel · Admin
Enterprise
A. Reddy
AML/CTF Compliance Officer
Enterprise
K. Vance
Partner · Fee Earner
Enterprise
✅ My Compliance Queue
Items requiring your review and sign-off, assigned to you as Compliance Officer / Admin. Every decision here is recorded to the audit trail with your name, role and reasoning.
Pending & recent
📜 Sign-Off Audit Trail
◈ Practice Health Score refresh
91
/ 100
Strong — trending up
Rolls up trust reconciliation, AML/CTF readiness, costs disclosure, conflicts, critical dates and CPD into one score. Up 4 points since last quarter. Biggest drag: AML/CTF program still in draft.
◈ Compliance Overview
Overall compliance
91%
↑ 4% since last quarter
Trust account flags
2
1 requires action today
AML/CTF readiness
63%
Tranche 2 obligations in force since 1 Jul 2026
CPD compliance
7/8
practitioners on track
✨ AI-surfaced this morning
✨
Trust anomaly detection
Matter 20458 — Whitfield Estate. Trust ledger shows a round $340.00 disbursement outside the matter's normal pattern, logged after hours (9:47pm). Flagged before it becomes a reconciliation variance.
⚠ Needs attention
Trust ledger variance — Matter 20458 (Whitfield Estate)
Balance does not reconcile with statement as at 5 Aug 2026. Variance $340.00. LPUL s137 reporting trigger if unresolved by 10 Aug.
Action required
Limitation period — Matter 20390 (Coogan v Bramwell)
Statute of limitations expires 14 Aug 2026. Originating process not yet filed.
9 days left
Costs disclosure overdue — Matter 20502 (Ibrahim v Coastal Constructions)
No disclosure on file 14 days after matter opened. AI draft ready.
Overdue
CPD shortfall — D. Marsh (Senior Associate)
4.5 of 10 units logged, ethics unit outstanding. AI has 3 suggested units.
Behind pace
Practicing certificate renewal — D. Marsh
Certificate expires 30 Sep 2026, 41 days remaining. A lapsed PC means the practitioner cannot practice.
41 days left
Module summary
🏦 Trust Account Monitor
Reconciliation vs LPUL trust rules, second-check layer alongside your PMS trust ledger.
2 flags
🛂 AML/CTF Readiness
KYC and reporting-entity readiness folded into one register, not a separate tool.
63% ready
📄 Costs Disclosure
LPUL Part 4.3 tracking across every open matter with AI-drafted letters.
3 overdue
⚖️ Conflicts Register
Entity search with AI risk notes on any related-party match.
1 review
⏰ Critical Dates
Limitation periods and filing deadlines tracked across every open matter.
1 urgent
📋 Complaint Register
LPUL-required complaint log with resolution tracking.
Up to date
🎓 CPD Tracker
Per-practitioner units with AI-suggested courses to close gaps.
1 behind
📦 Evidence Pack
Audit-ready bundle with an AI-written covering summary.
Ready
📊 Peer Benchmark & PI
See how you rank against similar firms and export a risk summary for your PI insurer.
Top 18%
◈ Panel Compliance Score refresh
88
/ 100
Strong — 1 item needs GC attention
Rolls up OCG compliance, cyber/ISO27001 attestation, DLP posture, conflicts and jurisdiction tracking across all offices. Biggest drag: Meridian Insurance Group billing sign-off breaches.
◈ Risk & Panel Overview
Panel readiness score
88%
across 14 active panel relationships
OCG requirements at risk
6
across 4 panels
ISO27001 status
Certified
surveillance audit due Nov 2026
Conflict escalations
1
open, awaiting GC sign-off
✨ AI-surfaced this morning
✨
Panel billing anomaly detection
Meridian Insurance Group. 2 invoices this month issued above the $50k OCG billing threshold without the required named-partner sign-off. AI cross-checked against the panel's Outside Counsel Guidelines and flagged both before the Sep 2026 panel review.
⚠ Panel risk items
Meridian Insurance Group — OCG breach risk
Named-partner billing sign-off required above $50k. 2 invoices this month issued without it. Panel review scheduled Sep 2026.
Action required
Continental Bank panel — cyber attestation renewal
Annual security questionnaire due 21 Aug 2026. DLP evidence pack 70% complete.
Due 21 Aug
Cross-jurisdiction — NSW/QLD trust rule variance
Brisbane office onboarding process does not yet reflect QLD-specific trust account variations. 4 matters affected.
Update needed
Platform modules
🔐 Cyber & ISO27001
Live control status, exportable whenever a panel or insurer requests proof.
91/93
🏛️ Panel Requirements
OCG obligations tracked per client panel — billing, staffing, reporting.
6 at risk
🛡️ Data Governance
DLP policy compliance and incident register mapped to panel requirements.
96% coverage
📅 Panel Renewal Calendar
Every panel renewal, questionnaire and audit date in one register.
1 urgent
⚖️ Enterprise Conflicts
Cross-office, cross-entity conflict search across the national client base.
1 escalated
🗺️ Cross-Jurisdiction
Maps LPUL variations across every state the firm operates in.
1 update
📈 Board / GC Reporting
Compliance posture summarised for risk committee and GC audiences.
Ready
📦 Panel Evidence Pack
Bundled proof of compliance for any panel administrator or insurer.
Ready
🏦 Trust Account Monitor
Trust ledger balance
$1.84M
across 214 active matters
Unreconciled variance
$340
1 matter flagged
Statutory deposit account
Compliant
last swept 4 Aug 2026
Reconciliation flags run reconciliation
Matter 20458 — Whitfield EstateAction required
Ledger/statement variance · $340.00 · ✨ AI-flagged
Matter 20390 — Coogan Family TrustReview due
Controlled money — signatory review due · $88,200.00
Matter 20471 — Sundstrom Pty LtdMonitor
Disbursement pending 3+ days · $1,250.00
All others (211 matters)Reconciled
No issues detected
✨ AI risk read — Matter 20458
✨
Anomaly explanation
This matter's disbursement pattern has been 3–5 itemised entries under $150 for the past 4 months. The $340 round-figure entry on 5 Aug breaks that pattern and was logged outside normal processing hours. Recommend confirming against a signed disbursement authority before reconciling.
LPUL trust rule checklist
✓ Trust records kept in approved software
✓ Monthly trust account statements issued
✓ External examination completedlast: May 2026
! All ledger variances resolved within 5 business days1 open
✓ Trust money receipted within 1 business day
🛂 AML/CTF Program
Practice readiness
63%
Clients KYC'd
148/230
High-risk clients open
1
Screening & BO pending
2
1. Risk Assessment Builderbuild risk assessment
Legal services risk assessmentNot started
Covers professional legal services — trust structuring, business sales, estate matters
Conveyancing risk assessmentNot started
Separate risk assessment required — mixed practice offering both legal and conveyancing services
AUSTRAC requires a separate risk assessment per regulated service line. A practice offering both legal and conveyancing services must maintain two.
2. Governance Registeradd role
J. Harrow — AML/CTF Compliance OfficerAppointed
Delegated compliance oversight · appointed 12 Jun 2026 · PDD complete
K. Vance — Senior Manager (approver)Appointed
Approves the AML/CTF program and material changes
D. Marsh — CDD dutiesPDD pending
Conducts client due diligence · personnel due diligence check not yet completed
✨ 3. Client Risk Tiering & Enhanced CDD
Coastal Constructions Pty LtdLow risk · Verified
Business sale · source of funds confirmed
R. & T. NguyenMedium risk · In progress
Conveyancing · source of funds pending
Marlow Holdings TrustHigh risk · Escalation required
Trust structuring · complex legal arrangement, difficult to identify beneficial owners
✨
AI risk tiering — Marlow Holdings Trust
Rated high risk: complex trust structure creating effective anonymity (high-risk factor per AUSTRAC guidance), client interacting via remote channels only, no in-person meeting to date. Recommend PEP and sanctions screening before escalating to the Compliance Officer for enhanced CDD sign-off.
4. Ongoing Transaction Monitoring
Clients monitored
230
Alerts open
2
Alerts cleared (30 days)
5
Monitoring rules active
6
Monitoring rules
Disbursement deviationActive
Flags disbursements >150% of a client's 6-month rolling average
Rapid succession transactionsActive
Flags 3+ transactions over $5,000 within any 14-day window
Dormant account reactivationActive
Flags activity on a trust ledger dormant for 90+ days
Threshold cash transactionActive
Flags any cash transaction ≥$10,000, feeds directly into the TTR Log below
Round-figure / after-hours entryActive
Flags round-sum disbursements logged outside normal processing hours
Geographic risk indicatorActive
Flags transactions linked to a jurisdiction on the DFAT/FATF high-risk list
Alert registerreview flagged activity
Marlow Holdings Trust — unusual disbursement patternFlagged
3 disbursements over $8,000 in 10 days, no comparable pattern in prior 6 months · Rule: Disbursement deviation
Delacroix Pty Ltd — dormant account reactivationUnder review
Trust ledger inactive since Feb 2026, disbursement request received 2 Aug 2026 · Rule: Dormant account reactivation
Rennick Building Dispute — clearedCleared
Flagged 28 Jul 2026 for rapid succession transactions, reviewed and confirmed consistent with settled adjudication schedule
Coastal Constructions Pty LtdNormal activity
Transaction pattern consistent with 12-month baseline
R. & T. NguyenNormal activity
Transaction pattern consistent with baseline
All other monitored clients (225)Normal activity
No rule triggered in the past 30 days
Distinct from onboarding CDD — this continuously compares each existing client's transaction pattern against their own historical baseline, not just a one-time check at intake. AUSTRAC expects ongoing monitoring for the life of the client relationship, not only at onboarding.
Alert resolution history
Rennick Building Dispute — clearedResolved 30 Jul 2026
Reviewed by J. Harrow — transactions matched adjudication payment schedule, no further action
Sundstrom Pty Ltd — clearedResolved 15 Jul 2026
Reviewed by K. Vance — disbursement deviation explained by settlement completion, confirmed against file notes
Whitfield Estate — clearedResolved 8 Jul 2026
Reviewed by J. Harrow — reactivation matched expected final distribution, no further action
5. PEP & Sanctions Screeningscreen new client
Marlow Holdings Trust — S. Marlow (trustee)Pending screening
Flagged from risk tiering — screening required before enhanced CDD sign-off
Coastal Constructions Pty Ltd — M. Coastal (director)Clear
Screened 22 Jul 2026 — no PEP or sanctions list match
R. & T. NguyenClear
Screened 30 Jul 2026 — no PEP or sanctions list match
6. Beneficial Ownership Registeradd owner record
Marlow Holdings TrustIncomplete
Discretionary trust — ultimate beneficial owner(s) not yet fully identified
Coogan Family TrustComplete
2 beneficial owners identified and verified, 100% ownership accounted for
Coastal Constructions Pty LtdComplete
1 beneficial owner (M. Coastal, 100%) identified and verified
Required for trusts, companies and other legal structures under AUSTRAC's beneficial ownership identification obligations — distinct from CDD on the immediate client.
7. Know Your Business (KYB) — Structure Verificationverify new structure
Marlow Holdings Trust — discretionary trustIn progress
Trust deed requested, appointor/trustee chain not yet fully mapped
Coogan Family Trust — discretionary trustVerified
Trust deed on file, trustee and appointor confirmed against ASIC/trust register
Coastal Constructions Pty Ltd — Pty LtdVerified
ASIC extract confirms sole director/shareholder structure, no corporate chain
Verifies the legal structure itself — registration, control chain, trustee/appointor/director relationships — distinct from beneficial ownership (the economic interest) and CDD (the immediate client's identity). Covers trusts, SMSFs, companies and multi-layer corporate chains.
8. Threshold Transaction Report (TTR) Loglog cash transaction
No threshold transactions currently loggedClear
AUSTRAC requires reporting of cash transactions of $10,000 or more (or foreign equivalent) within 10 business days
9. Suspicious Matter Report (SMR) Loglog new SMR trigger
No SMR triggers currently openClear
Register ready — triggers will appear here when flagged by staff or AI risk tiering
✨ 10. AML/CTF Program Document Generator
✨
Drafts your Policy & Process documents
Once your risk assessment(s) and governance register are complete, AI assembles a firm-specific AML/CTF Policy document and Process document from the AUSTRAC Legal Profession Program Starter Kit structure — ready for the Senior Manager to review and approve as your practice's official program.
11. Ongoing Review & Maintenance Tracker
Program reviewDue
Annual policy/process review — next due 1 Jul 2027
Staff AML/CTF trainingOverdue
2 of 5 staff have not completed initial training
Independent evaluation (AUSTRAC Step 5)Not scheduled
Periodic independent evaluation of program effectiveness
AUSTRAC Tranche 2 — enrolment opened 31 Mar 2026, obligations commenced 1 Jul 2026, enrolment deadline 29 Jul 2026 (all now passed). Built against the AUSTRAC Legal Profession Program Starter Kit structure. Confirm current AUSTRAC guidance before client-facing use.
🛂 AML/CTF Program — Enterprise
Program status
Adopted
Approved by Risk Committee 18 Jun 2026
Offices covered
4 / 4
High-risk clients open
1
PDD outstanding
3 staff
Multi-Office Risk Assessmentview all
VIC — Melbourne (HQ)Current
Legal services + trust structuring · reviewed 18 Jun 2026
NSW — SydneyCurrent
Legal services + M&A advisory · reviewed 18 Jun 2026
QLD — BrisbaneReview due
Legal services + conveyancing · separate risk assessment required for conveyancing, not yet completed
WA — PerthCurrent
Legal services + resources sector advisory · reviewed 18 Jun 2026
Governance Registeradd delegate
Group AML/CTF Compliance Officer — Risk & GC OfficeAppointed
National oversight · appointed 2021
Office delegates — Melbourne, Sydney, PerthAppointed
Day-to-day compliance oversight per office · PDD complete
Office delegate — BrisbanePDD pending
Newly appointed, personnel due diligence in progress
✨ CDD Escalation — linked to Enterprise Conflicts Engine
✨
Shared risk signal across AML and conflicts
Continental Bank is both a high-risk AML client (complex joint venture structure, flagged for enhanced CDD) and the subject of an escalated conflict (matter 88213). Because the same underlying entity triggers both, AI has linked the two escalations so the GC office reviews them together rather than in separate workflows.
Ongoing Transaction Monitoring — National
Relationships monitored
312
Alerts open
2
Alerts cleared (30 days)
9
Offices covered
4 / 4
National monitoring rules
Fund movement deviationActive
Flags transfers >150% of a relationship's 6-month rolling average, applied uniformly across all 4 offices
Cross-office entity correlationActive
Flags when the same client or related entity triggers alerts in more than one office within 30 days
Conflicts/AML cross-referenceActive
Automatically links a transaction alert to any open conflicts escalation on the same entity
Threshold cash transactionActive
Flags any cash transaction ≥$10,000, feeds directly into the national TTR Log
Geographic risk indicatorActive
Flags transactions linked to a jurisdiction on the DFAT/FATF high-risk list
National alert registerreview flagged activity
Continental Bank — unusual fund movement patternFlagged
Sydney office — 2 transfers inconsistent with the JV structure's historical baseline · Rule: Fund movement deviation, cross-referenced with conflicts escalation
Meridian Insurance Group — cross-office correlationUnder review
Melbourne office — related entity also flagged in Sydney within the same 30-day window · Rule: Cross-office entity correlation
Local Government Procurement Panel client — clearedCleared
Perth office — flagged for threshold cash transaction, confirmed as a standard government settlement payment
All other monitored relationships (309)Normal activity
No rule triggered in the past 30 days, across all 4 offices
Continuous monitoring across the life of each client relationship, not just at onboarding — aggregated nationally for GC/Risk Committee visibility.
National alert resolution history
Local Government Procurement Panel client — clearedResolved 2 Aug 2026
Reviewed by A. Reddy — confirmed against panel settlement schedule, no further action
Nautilus Resources Ltd — clearedResolved 22 Jul 2026
Reviewed by Risk & GC Office — fund movement matched a disclosed resources sector settlement
PEP & Sanctions Screening — Nationalrun batch screening
Continental Bank — JV partner (Sydney)Pending
Flagged via linked conflicts escalation — screening required before GC sign-off
All other active high-value mattersClear
142 clients screened this quarter across 4 offices, no PEP or sanctions matches
Beneficial Ownership & KYB — Nationalview register
Complex structures (trusts, JVs, multi-layer entities)3 incomplete
Across all offices — includes Continental Bank JV structure pending GC review
Standard corporate clientsComplete
Beneficial ownership identified and verified for all standard structures
KYB structure verification (corporate chains, JVs)4 in progress
Trust deeds, JV agreements and corporate registry extracts being collected across offices
Threshold Transaction Report (TTR) Log — Nationallog cash transaction
No threshold transactions currently loggedClear
Aggregates TTR obligations across all offices — cash transactions $10,000+ reportable within 10 business days
Suspicious Matter Report (SMR) Loglog new SMR trigger
No SMR triggers currently openClear
National register — triggers from any office appear here
AML/CTF program adopted and maintained by the firm's Risk & GC office; this view aggregates program status across offices for GC/board reporting and feeds one line into the Panel Evidence Pack. Built against AUSTRAC Tranche 2 obligations — confirm current AUSTRAC guidance before client-facing use.
📄 Costs Disclosure Tracker
Matters compliant
198/214
Overdue disclosure
3
Updates required
13
✨ AI-drafted disclosure — Matter 20502
✨
Draft letter — review before sending
Dear Mr Ibrahim,

In accordance with our obligations under the Legal Profession Uniform Law, we are required to disclose the likely costs of acting for you in your matter against Coastal Constructions Pty Ltd. Based on the scope of instructions to date, we estimate professional fees of $8,000–$14,000 plus disbursements...
Overdue & pending
20502 — Ibrahim v Coastal ConstructionsOverdue
Opened 22 Jul 2026
20515 — Petrakis Family LawOverdue
Opened 29 Jul 2026
20488 — Delacroix Pty LtdDue in 2 days
Opened 15 Jul 2026
⚖️ Conflicts Registersearch entity
Coastal Constructions Pty LtdClear
Director cross-checked against 3 related entities
Marlow Holdings TrustReview
Trustee overlaps with matter 19887 (opposing party) · ✨ AI-flagged
Sundstrom Pty LtdClear
No related-party overlap detected
✨ AI risk note — Marlow Holdings Trust
✨
Plain-English conflict summary
The trustee named on this matter, S. Marlow, is also the trustee of record on matter 19887 (Coogan v Marlow Holdings), where Marlow Holdings appears as the opposing party. This is a same-person overlap across current and historical matters — recommend a conflict check memo before proceeding.
⚖️ Enterprise Conflicts Enginesearch entity
Meridian Insurance GroupReview
Melbourne, Sydney offices · 2 subsidiaries flagged
Nautilus Resources LtdClear
Perth, Brisbane offices · no related-party overlap
Continental BankEscalated
All offices · joint venture partner overlap — matter 88213 · ✨ AI-flagged
✨ AI conflict escalation note — Continental Bank
✨
Cross-office risk summary
A joint venture partner named on matter 88213 (Sydney office) also appears as a related entity on 2 historical Melbourne office matters for Continental Bank. This overlap was not visible to either office individually — recommend GC review before further work is billed.
🗂️ File Compliance Checker
Matter 20458
Engagement letter ✓ · Costs agreement ✓ · ID verification ✓ · Closing checklist ⬜
Matter 20502
Engagement letter ✓ · Costs agreement ⬜ · ID verification ✓ · Closing checklist ⬜
Matter 20390
Engagement letter ✓ · Costs agreement ✓ · ID verification ✓ · Closing checklist ✓
⏰ Critical Dates & Limitation Periods
Urgent (under 14 days)
1
Due this month
4
Tracked matters
214
Upcoming deadlinessend reminders
Matter 20390 — Coogan v Bramwell9 days left
Limitation period expires 14 Aug 2026 — originating process not yet filed
Matter 20355 — Rennick Building Dispute22 days left
Adjudication response due 29 Aug 2026
Matter 20502 — Ibrahim v Coastal Constructions31 days left
Defence filing deadline 7 Sep 2026
Matter 20211 — Whitfield probate40 days left
Notice of intended distribution period expires 16 Sep 2026
Missed limitation periods are consistently among the leading causes of professional negligence claims against Australian legal practices — this register exists to make that risk visible before it becomes a claim.
📋 Complaint Registerlog new complaint
Open complaints
1
Resolved (12 months)
4
Escalated to LSC
0
Register
Complaint 0005 — billing dispute, Matter 20211Open
Received 28 Jul 2026 · response due 11 Aug 2026 (LPUL 14-day guideline)
Complaint 0004 — communication delay, Matter 19980Resolved
Received 2 May 2026 · resolved 9 May 2026
Maintaining a documented complaint register is expected practice under LPUL professional conduct obligations and is routinely requested by external examiners.
📮 Regulatory Correspondence Loglog correspondence
Law Institute VIC — external examination confirmationFiled
Received 6 May 2026 — confirmed May 2026 external examination as satisfactory
AUSTRAC — Tranche 2 enrolment confirmationFiled
Received 2 Apr 2026 — enrolment reference on file
A record of correspondence with the Law Society, Legal Services Commissioner and AUSTRAC — distinct from the Complaint Register, and often the first thing an examiner asks to see.
🔐 Cyber & ISO27001 Attestationexport attestation
Controls implemented
91/93
Certification status
Active
Surveillance audit
Nov 2026
⚙ Powered by ISO27001Guard — full ISMS engine
🔄 Live data — last synced from ISO27001Guard control register: 2 minutes ago
Outstanding controls
A.8.28 Secure codingIn progress
Technological domain
A.5.30 ICT readiness for business continuityIn progress
Organisational domain
✨ AI attestation reader
✨
Panel questionnaire matcher
Continental Bank's annual security questionnaire (23 questions) maps to 21 of your 91 implemented ISO27001 controls directly. The remaining 2 questions concern secure coding practices (A.8.28) — currently in progress. AI has pre-filled 21/23 answers from your control evidence.
This page summarises live data from ISO27001Guard, VericertAI's full ISMS compliance engine — the 93-control register, evidence attachments, Statement of Applicability and sign-off workflow are managed there, not duplicated here.
🏛️ Client & Panel Requirements
Panel relationships
14
5 detailed below, 9 fully compliant
OCG requirements at risk
6
across 4 panels
Fully compliant panels
11 / 14
Meridian Insurance Groupreview breach
Panel since 2019 · renewal Mar 2027 · panel review scheduled Sep 2026
Named-partner billing sign-off >$50k2 invoices missing sign-off
Matters 44210 and 44287 — required under OCG clause 6.2
Quarterly conflicts disclosure formOverdue
Due 31 Jul 2026, not yet submitted to panel administrator
Named-partner staffing on fileCompliant
All active matters correctly staffed and recorded
Continental Bank
Panel since 2021 · renewal Aug 2026
Annual security questionnaireDue 21 Aug 2026
91% pre-fillable from existing ISO27001 control evidence
ISO27001 attestation on fileCompliant
Diversity reportingSubmitted
State Government Legal Panel (VIC)
Panel since 2018 · renewal Dec 2026
Sub-contractor disclosure updateOverdue
Required whenever sub-contracted counsel is engaged on a panel matter
Model Litigant obligations trainingCompliant
Data sovereignty requirementsCompliant
Local Government Procurement Panel (LGPP)
Panel since 2022 · renewal Nov 2026
Annual fee schedule auditOverdue
Required confirmation that billed rates match the panel fee schedule — due 15 Jul 2026
Insurance certificate of currencyCurrent
Nautilus Resources Ltd
Panel since 2023 · renewal Jun 2027
All OCG requirementsFully compliant
Conflicts clearance process, billing guidelines and e-billing integration all current
9 additional panel relationships (government, insurer and corporate) are tracked with no open items and are not itemised here — see the full panel register for the complete list of 14.
🛡️ Data Governance (DLP)
Policy coverage
96%
Open incidents
0
Client data reqs pending review
4
⚙ Powered by DLPGuard — full CASB, Shadow IT & classification engine
🔄 Live data — last synced from DLPGuard: 5 minutes ago
Available in the full DLPGuard engine
CASB cloud app registerIn DLPGuard
Sanctioned and unsanctioned cloud application inventory across the firm
Shadow IT detectionIn DLPGuard
Unauthorised app and data-transfer detection
Document classification & review queueIn DLPGuard
Per-document sensitivity classification with a human review workflow
DLP alert feed & audit logIn DLPGuard
Real-time policy violation alerts with a full audit trail
Policy coverage by arealog incident
Email & file transfer DLP rulesActive
Applied across all 4 offices, last reviewed Jun 2026
Endpoint device encryptionActive
100% of managed devices covered
Third-party vendor data handling review2 vendors pending
Annual review of data processors used on panel matters
Client-specific data residency requirementsPartial
Continental Bank and State Government Legal Panel require data to remain onshore — controls verified for Continental Bank, State Government Legal Panel pending confirmation
Client data requirements pending review (4)
Continental Bank — encryption-at-rest standardPending
Confirm AES-256 standard applied to all matter documents
State Government Legal Panel — data residencyPending
Confirm all matter data remains within Australian data centres
Meridian Insurance Group — breach notification SLAPending
Confirm 24-hour breach notification commitment is reflected in incident response plan
Nautilus Resources Ltd — third-party access log retentionPending
Confirm 12-month access log retention meets panel requirement
✨ AI incident readiness check
✨
Cross-referenced against panel data requirements
2 of the 4 pending reviews (Continental Bank, State Government Legal Panel) are also referenced in active panel renewal or questionnaire items — closing these clears both the DLP review and the related panel requirement in one action.
🚨 Notifiable Data Breaches (NDB) — Nationallog potential breach
No breaches currently openClear
National register across all 4 offices — a breach likely to cause serious harm must be assessed within 30 days and reported to OAIC and affected individuals if it meets the threshold
Privacy Act 1988 (Cth) obligation, separate from the panel-specific breach notification SLAs above — this is the statutory obligation to OAIC and affected individuals.
📅 Panel Renewal Calendarsend reminders
Continental Bank — security questionnaire14 days left
Due 21 Aug 2026 · 70% of DLP evidence pack complete
State Government Legal Panel (VIC) — renewalDec 2026
Sub-contractor disclosure update outstanding
Meridian Insurance Group — panel reviewSep 2026
Billing sign-off breaches must be remediated before review
Nautilus Resources Ltd — renewalJun 2027
No outstanding items
Missing a panel renewal window is one of the more common ways firms lose panel status entirely — this calendar exists to make that risk visible with enough lead time to act.
🗺️ Cross-Jurisdiction Tracker
VIC — Melbourne (HQ)Compliant
Baseline trust rule set
NSW — SydneyCompliant
Statutory deposit variation tracked
QLD — BrisbaneUpdate needed
Trust account variation not yet reflected in onboarding
WA — PerthCompliant
Baseline trust rule set
🎓 CPD Tracker
J. Harrow (Principal)Compliant
10/10 units · ethics ✓ · CPD year ends 31 Mar 2027
K. Vance (Principal)Compliant
9/10 units · ethics ✓
D. Marsh (Senior Associate)Behind pace
4.5/10 units · ethics ⬜
S. Ojo (Associate)On track
6/10 units · ethics ✓
✨ AI suggestions for D. Marsh
✨
Gap-targeted CPD recommendations
Ethics unit outstanding is the priority gap (mandatory component). Based on Marsh's practice mix (60% property, 25% commercial), suggested units: Ethics in Property Transactions (1 unit), Trust Account Obligations Refresher (1 unit), Commercial Conflicts in Practice (1 unit). Closes the ethics gap and reduces the trust-flag rate for this practitioner's matters.
🪪 Practicing Certificate Register
Certificates current
3/4
Renewals due <60 days
1
Practicing certificate year
Ends 31 Mar 2027
Registerrenew certificate
J. Harrow — PrincipalCurrent
Unrestricted, VIC · expires 31 Mar 2027
K. Vance — PrincipalCurrent
Unrestricted, VIC · expires 31 Mar 2027
D. Marsh — Senior AssociateRenewal due
Employee, VIC · expires 30 Sep 2026 — 41 days remaining
S. Ojo — AssociateCurrent
Employee, VIC · expires 31 Mar 2027
A lapsed practicing certificate means the practitioner is not entitled to practice law — matters they're the fee earner on are exposed until renewed. This register exists to make sure that never happens by surprise.
📋 Practice Succession & Continuity Planupdate plan
Nominated successor / locumNamed
K. Vance nominated to manage the practice if J. Harrow is unable to
Trust account signatory continuityCovered
Both principals hold signatory authority — no single point of failure
Document/system access continuityNot documented
No written record of who can access practice management, trust and email systems in an emergency
Plan last reviewedOver 12 months ago
Law Society guidance recommends annual review
Particularly important for sole practitioners and small firms — the Law Society expects a documented plan for what happens to client matters and trust money if a principal is suddenly unable to practice.
🏢 ILP Management System
✓ Appropriate management systems policy adopted
✓ Annual self-assessment lodged
✓ Legal Practice Director compliance declaration current
! Ethics infrastructure review overdue18 months
Admission & Practicing Certificate Register — Nationalview register
Practitioners current332 / 340
Across VIC, NSW, QLD and WA admissions
Renewals due <60 days8 practitioners
Mostly VIC and NSW certificate years ending Sep/Oct 2026
Interstate practice notificationsCurrent
All fee earners admitted or notified correctly for the jurisdiction they're practicing in
📋 Business Continuity Planupdate plan
Office-level continuity leadsNamed
Each of the 4 offices has a nominated continuity lead and deputy
Critical system access continuityDocumented
Trust, PMS and document management access mapped for emergency continuity
Plan last reviewedFeb 2026
Reviewed annually by Risk Committee
📮 Regulatory Correspondence Log — Nationallog correspondence
Victorian Legal Services Board — ILP self-assessment acknowledgementFiled
Received Mar 2026
AUSTRAC — Tranche 2 group enrolment confirmationFiled
Received Apr 2026
✨ Ask LegalGuard
Do I need to re-issue costs disclosure on matter 20458 now that the estate valuation has come in higher than expected?
Yes — if the revised estimate represents a "significant change" to the costs previously disclosed, LPUL Part 4.3 requires you to disclose that change to the client as soon as reasonably practicable. A valuation increase that materially shifts your fee estimate would typically meet that bar.Ref: Legal Profession Uniform Law, s174 — disclosure of significant change
Can I draft that update now?
Yes — I can generate a disclosure update letter using the revised estimate from Matter 20458. Open it in Costs Disclosure once ready, and review before sending; it's a draft, not a filed document.
✨ Ask LargeFirmGuard
Does the Continental Bank questionnaire due 21 Aug require anything we haven't got evidence for?
Almost everything is covered — 21 of 23 questions map directly to your existing ISO27001 controls. The 2 gaps both relate to secure coding practices (control A.8.28), which is currently in progress. I've pre-filled the 21 answered questions; you'll need to note the secure coding control as "in progress, target date Q4 2026" for the remaining 2.
📊 Peer Benchmark
Practice health score
91
vs. peer average 76
Percentile rank
Top 18%
of similar-sized VIC firms (2–15 partners)
Peer group size
312
firms in benchmark cohort
Where you rank against similar-sized practices
Trust reconciliation accuracyTop 15%
99.5% of matters reconciled cleanly vs. peer average 94%
Costs disclosure timelinessTop 25%
92% on-time vs. peer average 81%
AML/CTF program maturityMiddle 50%
Program still in draft — peer average has adopted programs at a similar rate post-Tranche 2
CPD compliance rateTop 20%
87.5% of practitioners on track vs. peer average 74%
🔐 Cyber Basicsrun check
Multi-factor authentication on email & case systemEnabled
Applied for all 8 staff
Device encryption (laptops & phones)Enabled
7 of 8 devices confirmed, 1 pending
Written incident response planMissing
No documented plan for a data breach or system compromise
Cyber insurance policy on fileNot confirmed
Separate from PI — confirm whether a standalone cyber policy is held
Client email/file-sharing basic controlsIn place
Encrypted transfer for sensitive documents
Scoped to what small practices actually need to evidence — not a full ISMS. Firms wanting formal ISO27001 certification can be pointed to ISO27001Guard separately.
🚨 Notifiable Data Breaches (NDB)log potential breach
No breaches currently openClear
Register ready — a breach involving personal information likely to cause serious harm must be assessed within 30 days and reported to OAIC and affected individuals if it meets the threshold
Separate from the Complaint Register and from Cyber Basics — this is the Privacy Act 1988 (Cth) obligation specifically, triggered whenever client or staff personal information is exposed.
🛡️ Professional Indemnity Insurance Readiness
Risk management evidence for renewalReady
Practice Health Score, trust reconciliation history, complaint register and Cyber Basics checklist are exportable for your PI insurer/broker
Estimated renewal positionFavourable
Documented risk management systems are increasingly factored into PI premium calculations by Lawcover/LPLC-aligned insurers — a Health Score of 91, clean complaint history and cyber basics evidence support a stronger renewal conversation
Cyber Basics gaps affecting renewal2 open
Incident response plan and cyber insurance confirmation — insurers increasingly ask for both at renewal
Export for insurer / broker
Benchmark figures are illustrative demo data. Actual peer comparisons would be built from an anonymised cohort of LegalGuard tenants once the platform has sufficient scale.
📊 Panel Peer Benchmark
Panel compliance score
88
vs. peer average 71
Percentile rank
Top 22%
of national/mid-tier firms with 10+ panel relationships
Peer cohort size
47
firms in benchmark cohort
Where you rank against similar-sized firms
ISO27001/cyber attestation maturityTop 10%
91/93 controls implemented vs. peer average 78/93
OCG billing complianceMiddle 50%
2 open breaches vs. peer average 1.4
Conflicts escalation speedTop 15%
Average 3 days to escalate vs. peer average 9 days
Benchmark figures are illustrative demo data. Actual peer comparisons would be built from an anonymised cohort of LargeFirmGuard tenants once the platform has sufficient scale.
📈 Board / GC Reportingexport board pack
Overall risk posture
Low
Panel items at risk
6
Escalated conflicts
1
Certifications current
ISO27001
📦 Evidence Pack
✓ Trust account reconciliation history (12 months)
✓ External examiner's report
✓ AML/CTF program & onboarding records
✓ Costs disclosure compliance log
✓ Conflicts register export
✓ Critical dates & limitation period log
✓ Complaint register
✓ CPD compliance summary by practitioner
✨ AI covering summary
✨
Auto-generated — verify before submission
Since the last examination (May 2026), trust reconciliation variances fell from 5 to 1 open item, costs disclosure compliance rose from 89% to 92% of matters, and one conflict was escalated and cleared (Marlow Holdings, 19887). No new AML/CTF onboarding gaps since Tranche 2 commencement.
Export
📦 Panel Evidence Pack
✓ ISO27001 certificate and Statement of Applicability
✓ DLP policy and incident history (12 months)
✓ OCG compliance summary per panel
✓ Enterprise conflicts engine audit log
✓ Panel renewal calendar status
✓ ILP management system self-assessment
✓ AML/CTF program status — 4/4 offices covered
✨ AI covering summary
✨
Auto-generated — verify before submission
Since last quarter, ISO27001 control coverage rose from 87/93 to 91/93, one conflict was escalated to GC review (Continental Bank, matter 88213), and OCG billing breaches at Meridian Insurance Group remain open pending remediation before the September panel review.
Export
🏢 Company Profile
PNG or JPG, square works best — used in the top nav and on generated reports
👥 Users+ add user
NameEmailRoleMFA
🔐 Security & Multi-Factor Authentication
Enforce MFA for all Admin users
Recommended — Admin accounts can manage users and export compliance evidence
Session timeout30 minutes
Password policyMinimum 12 characters, MFA required for reset
Your MFA enrollment
Scan with an authenticator app (Google Authenticator, Authy, 1Password) to enroll this account.

Record

Detail