This update extends the Audit Trail to every remaining area of Firm Verify, so all firm and client data changes are now logged. Program documents also gain a Document History panel showing their full lifecycle. Also in this release: a dedicated Audit Log permission, new Users fields, and a set of corrections across Program, Training, and template screens.
In this release
New Features
Audit Trail — Phase 2
Phase 1 delivered audit logging for Firm Profile. Phase 2 extends the same logging to every remaining screen that saves firm or client data, so every create, update, delete, and lifecycle change now produces an immutable, field-level audit record.
What's included:
- Email Templates — Adding, editing, deleting, and setting a default template are audited. When the default moves from one template to another, both sides of the change are recorded.
- Document Templates — Report and document template versions are audited on create, update, and delete, with before and after snapshots.
- Training — Training records added, edited, or removed against a user or Key Personnel record now write to the audit log.
- Users and Key Personnel — Audit events are published when personnel are added, when their details are edited, and when training is recorded against them.
- Firm Programs and Program Components — Creation, editing, and deletion are audited, along with the full review workflow and Mark as Current / Non-Current / Next Review Date changes.
Document History — Program Documents
Program documents now have a Document History panel: a read-only, reverse-chronological record of every event in the document's life. It's available as soon as a document is created, at any status, to any user in the firm with view or edit access — useful for evidencing document governance without needing to interrogate the full audit log.
What's included:
- Nine event types — Document Created, Document Updated, Review Requested, Review Rejected, Review Approved, Review Cancelled, Marked as Approved, Marked as Current, and Marked as Non-Current.
- Relevant detail per event — creation and update events show the title, version, summary of changes, attached file names, and next review date; review events show the reviewer message or comments. Fields with no value are hidden rather than shown empty.
- Who and when — every event records the full name of the person who triggered it, as their name was at the time, with a local-date, 12-hour timestamp and timezone (e.g. 16 Apr 2026 at 1:55 PM AEDT).
- Read-only — events can't be added, edited, or removed by any user.
Improvements
| Feature | What changed |
|---|---|
| View Audit Log Permission | Access to the Audit Log is now controlled by a dedicated permission that can be toggled per role, instead of being fixed to Account Owner and Admin. It defaults on for Account Owner/Admin and off for View Only, and can be enabled on custom roles. |
| Phone Number and Date of Birth on Users | These fields have been added to user and Key Personnel records, in line with the personnel data firms need for customer due diligence and Key Personnel identification. |
| Annual Compliance Report Date Corrected | The Policy template previously stated 31 March for the Annual Compliance Report. It now correctly states 30 September, in line with current AUSTRAC guidance. |
| Searchable Country Field | The Country field in Generate Risk Assessment is now searchable, so you can type to filter instead of scrolling the full list. |
| Screens Now Open at the Top | Moving to the next screen in the Risk Assessment, Policy, Process, and Program flows now scrolls to the top, instead of keeping the previous scroll position. |
| Date Picker Calendar Corrections | Several visual and interaction issues in the date picker calendar have been resolved. |
Errors Corrected
| Area | Fix |
|---|---|
| Learning Channel Button | Fixed a 400 error when clicking Learning Channel from the Training tab for firms without Learning Channel access. |
| Uploaded Document Status | Fixed an issue in the Program tab where a document uploaded and marked as reviewed was not being saved with a status of Approved. |
| Program Updates After Rejection | Fixed an issue where a Program or Program Component could not be updated once its status was Rejected. |
| Template Modified Time | Fixed an issue where the modified time on customised Email and Document templates was recorded in UTC rather than Australian Eastern time. |
| Ceased Date Validation | Fixed an issue where no validation appeared when a role was set to Ceased without a Ceased Date being supplied. |
| Restore Defaults Popover Spacing | Corrected the spacing of the Restore Defaults popover in Risk Assessment, Policy, and Process. |