Back to Blog
Compliance
October 4, 20269 min read

Do not show the client your red flag list

Do not show the client your red-flag list, because that list is how staff decide what to escalate. Handing it over tells the client what the firm treats as sensitive.

Quick answer

You may tell a client that the program requires identification before a designated service. You do not walk them through which facts would cause a report, and you do not email the list, a summary of the list, or a cleaned-up version. What you must not say on a live suspicion is a different page. This one only keeps the list inside the firm.

People search β€œdo not show client the red flag list” when a principal is asked to email the firm's internal red-flag list so a client can 'get the file right'. Checked against AUSTRAC's tipping-off page on 4 October 2026. This is general information, not legal advice. This page does not reproduce that guidance. What not to tell a client is tipping off: what not to tell the client. The sector map is /tranche-2.

The list is a control

Do not show client the red flag list is a rule of handling, not a slogan. The list tells staff which facts to escalate, and a client who reads it learns which facts to avoid mentioning. That is why it stays in the office. Editing a few lines, or turning it into a preparation guide, does not change what it is.

Ordinary program talk is still allowed. You can say identification is required before the service, and you can email the check link. You cannot explain which combination of facts would make you report. This page does not script that conversation, and it does not decide whether a suspicion exists.

  • Keep the list with staff. People who apply the program can see it. The client cannot.
  • Do not attach it to the link. The email that asks the client to complete a check carries the link, not your indicators.
  • Refuse the shortened copy. A one-page version for the client's accountant is still the list. Do not send it.
  • Separate ordinary words from suspicion. Saying the program needs identification is ordinary. Saying what would trigger a report is not. The tipping-off page carries that line.

Who may see which paper

A sorting aid for papers a client asks to see. This table does not reproduce AUSTRAC's tipping-off guidance.

PaperWho may see itWhy
Internal red-flag listStaff who need it for the programIt is a control, not a handout
A shortened or 'friendly' copyStill only those staffEditing it does not make it a brochure
The fact that identification is requiredThe clientThat is an ordinary program step
Whether you have formed a suspicionNot the clientTelling them is the tipping-off problem

Where the red-flag-list page stops

This page keeps the list internal. It is not a script for client conversations. How to talk about the obligation without tipping off sits on how to talk about AML with clients. This page does not publish indicators.

What the client pays

On FreeAML the firm suite is A$0. The firm emails the client a link. Verification is client-pays. On the public list a personal KYC check is A$20 and a company or trust KYB check is A$40. Use KYB when the customer is a company or a trust. A client-facing version of the red-flag list is not included in the firm suite. Confirm the live amounts on FreeAML pricing. FreeAML does not draft a client-safe version of your red-flag list, or decide whether you have formed a suspicion.

Frequently Asked Questions

Keep the list on the staff side.

The firm suite is A$0. The client pays the check. The red-flag list is not a document you attach to that link.

Open the Tranche 2 guide

Questions: team@freeaml.com.au