This update adds the Audit Trail, a tamper-proof log of every change made across your firm's compliance data. Also in this release: View Only permissions now actually restrict editing, several Firm Program bugs fixed, and a direct link to the Learning Channel from the Training screen.
In this release
New Features
Audit Trail — Phase 1
Firm Verify now keeps a permanent, uneditable record of every create, update, and delete action across Firm Profile, Firm Users / Key Personnel (including the Training Register), and Firm Policy / Procedure / Process. This satisfies AUSTRAC record-keeping requirements under the AML/CTF Amendment Act (Tranche 2), effective 1 July 2026.
Where to find it
Go to Settings > Audit Log. Account Owner and Admin roles
only.
What's included:
- Audit Log Viewer — Browse and search the full change history, filtered by User, Module, Action type, or Date range. Click any row to see exactly what changed, including the before and after values for each field.
- Field-level tracking — Each saved change records the specific field, old and new values, who made the change, and a UTC timestamp. Changes saved together share a correlation ID so you can see them as a group.
- Lifecycle events — Send for Review, Approve, Reject, Cancel Review, Mark as Current, Mark as Non-Current, Archive, and Upload Document all appear in the log as distinct events.
- Immutable records — No one can edit or delete a log entry after it is written. Records are kept for a minimum of 7 years per AUSTRAC requirements.
- Access control — View Only users cannot access the Audit Log. Navigating to the URL without the right role redirects to the dashboard.
Improvements
| Feature | What changed |
|---|---|
| View Only Permissions | View Only users can no longer add, edit, or delete records. Previously their access matched Admin and Account Owner — this is now corrected. |
| Auto-apply Current Tag | When a newly uploaded or generated document is the only approved document in its category (Risk Assessment, Policy, Process, or Program), it is automatically tagged as Current. No manual step needed. |
| Date Approved & Reviewed By Persist | Date Approved and Reviewed By now stay populated when a document is marked as Current or Non-Current. Both fields were previously cleared on status change. |
| Ceased Status Accuracy | Users with no roles attached no longer show as Ceased. Ceased status applies only to users removed via SSO, or Key Personnel with no active roles. |
| Training — Direct Link to Learning Channel | A link to the Learning Channel now appears on the Training screen: next to Add Training when no records exist, and in the header when records are present. |
Errors Corrected
| Area | Fix |
|---|---|
| Generated Documents — Approved By | Approved By and Date Approved were not appearing in generated Risk Assessment, Policy, Process, and Program documents where a previous version had been approved. Both fields now populate correctly. |
| Generate Policy & Process — 500 Error | A 500 error occurred when regenerating a Policy or Process document after restoring a default that had been viewed on a Draft. This no longer happens. |
| Risk Assessment — Delete Confirmation | Pressing Cancel in the delete confirmation modal was still deleting the row. Cancel now correctly leaves the record in place. |
| Firm Users — Empty Roles Validation | Saving a user with no roles attached showed no error message and left the form stuck. A validation message now appears and the issue is resolved. |