Choosing AML software for an Irish firm: 10 questions to ask
Ahead of the AMLR’s 10 July 2027 start date, every vendor will tell you they are “AMLR-ready”. These ten questions — usable in any demo, including ours — separate the systems built for Irish obligations from the ones repainted for them.
When choosing AML software for an Irish firm, test five things hard: EU data residency you can evidence, templates genuinely mapped to Regulation (EU) 2024/1624, support for Ireland-specific workflows (the RBO extract and STR dual reporting to goAML and ROS), transparent per-verification pricing, and the ability to retain records for five years and then delete them — with an audit trail behind it all.
What are the 10 questions to ask any AML software vendor?
Take these into the demo. The good vendors will enjoy answering them; the evasions are as informative as the answers.
Where is our data hosted — and can you prove EU residency?
Your CDD files hold passports, PPS-adjacent identifiers and beneficial-ownership detail. Ask for the specific region (not just “the cloud”), whether data ever leaves the EU for processing or support, and how that is documented for your own GDPR obligations.
Are your templates built for the AMLR, or retro-fitted from the old rules?
Regulation (EU) 2024/1624 replaces the framework your current policies were written under from 10 July 2027. Ask whether the risk-assessment and policy templates map to the AMLR’s articles, and how the vendor ships updates as AMLA technical standards land.
Does it handle Ireland’s RBO workflow?
Irish designated persons must obtain an RBO extract before a new business relationship and report discrepancies. There is no public RBO API, so the honest answer is a guided workflow: prompt, store the extract, record the comparison, log the decision. Be wary of anyone claiming a live RBO integration.
Does it support Ireland’s STR dual reporting?
An Irish STR goes to FIU Ireland via goAML and to Revenue via ROS. Ask whether the system produces goAML-compatible XML, tracks both submissions, and is honest about who files — the MLRO does, not the software.
How is pricing structured — and what does a verification actually cost?
Per-client or per-seat pricing punishes growth; opaque per-check fees punish thoroughness. Ask for the base subscription, what it includes, the exact cost of each additional identity verification, and whether screening re-runs are charged.
Can it retain for five years and then delete?
The AMLR requires records to be retained for five years and then deleted. Ask how the system tracks the retention clock per record and how deletion actually executes — including from backups. “We keep everything forever” is now a liability.
Is there a complete audit trail?
When a supervisor asks who checked what and when, the answer should be a report, not an archaeology project. Ask to see the audit trail behind a single client file: every action, every user, every timestamp.
What does screening actually cover?
Ask which lists are screened — the EU consolidated financial sanctions list, UN lists, PEP data — whether screening is ongoing or one-off, and how potential matches are resolved and evidenced.
What happens to our data if we leave?
You must keep records for five years even if you change vendor. Ask about export formats, whether export is self-service, and what it costs. A vendor who makes leaving hard is answering a different question honestly.
Who is the software actually built for?
A tool built for a bank’s compliance department will bury a five-person practice in configuration. Ask to see the product working for a firm your size and sector, and who at the vendor understands the Irish supervisory landscape.
How does CompliDesk answer these questions?
We wrote this checklist, so it is fair to hold us to it. CompliDesk Ireland hosts data in the EU on AWS eu-west-1 (Dublin). Templates are built to the AMLR, not adapted from the CJA 2010, with the compliance manager and compliance officer designations built in. The RBO workflow is exactly what we said an honest vendor should offer — a guided extract-compare-decide process with evidence storage, because there is no public API. The STR builder exports goAML-compatible XML and tracks both the goAML and ROS submissions; your MLRO files. Pricing is transparent: indicative launch pricing of €19, €49 or €79 per month plus VAT with unlimited clients, and additional identity verifications at €3 each. Records carry a five-year retain-then-delete clock, and every action sits on an audit trail.
Where we are honest about limits: CompliDesk is built for small and mid-sized designated persons — practices, agencies, dealers, TCSPs — not for banks, and it prepares and records reports rather than filing them for you. If you need a bank-grade transaction-monitoring engine, we are the wrong tool and will say so in the demo. See pricing and security & data residency for the detail.
Ask us all ten questions
Book a demo and put this checklist to us directly — or join the waitlist for free early access and founding-member pricing.