How to evaluate Korvos
Don’t take our word for it. Run the tests.
We are a young company selling compliance software to a risk-averse industry, in a category where most of the “best AML software” comparisons you will find are written by vendors marketing their own products. You should treat anyone’s verdict with suspicion, including ours.
So here is something more useful than a verdict. These are the seven tests a careful agency should run on any platform in this category — the ones that separate a real compliance system from a verification widget. Each one includes our honest answer and the way to check it yourself.
Test 1
Put a discretionary trust with a corporate trustee through it.
Property is full of family trusts, SMSFs, two-dollar development companies and offshore buyers. Cheap tools do individuals well and fall over on structures — which means your hardest customer due diligence is the part you end up doing by hand.
Korvos treats companies, trusts, SMSFs, partnerships, associations, foreign companies and government bodies as first-class customers, not as an individual with a company name attached. It captures the ownership and control structure, checks the declared percentages arithmetically, and where a beneficial owner cannot be identified — a layered or nominee-shaped structure, or an unresolved corporate-trustee chain — it does not quietly pass. It flags the structure as opaque and routes the customer into enhanced due diligence.
How to check
- Add a trust with a corporate trustee and confirm you are asked for the trustee's directors and the beneficial owners, not just one director's licence
- Declare ownership totalling less than 100% and confirm the unexplained holding is flagged rather than accepted
- Confirm an unresolvable structure routes to enhanced due diligence instead of returning a clear result
- What it does not do: silently trace a deep multi-layer chain for you. It detects that one exists and escalates it to a human — by design, because a wrong automated trace is worse than a flagged one
Test 2
Check the auction and delayed-CDD clock.
You need to identify a bidder and exchange on the fall of the hammer. If the workflow assumes days of lead time, it does not fit how you sell.
The delayed initial CDD concession in r 6-32(4) is implemented as a deadline engine, not as a note in a policy document. When a matter goes under contract, Korvos computes the counterparty's deadline as the earlier of 28 days after exchange and 3 days before the initially agreed settlement day, records the s 29 low-risk delay determination, and tracks the matter against that date.
How to check
- Confirm the concession is applied to the counterparty only — your own client must be verified before you commence, and no concession applies to them
- Confirm dual representation short-circuits the concession entirely, because both parties are then your own clients
- Check the date the system computes against your own reading of r 6-32(4) on a real contract
Test 3
Is the screening scheduled, or is it a one-off?
A single sanctions and PEP check at onboarding is not ongoing customer due diligence. Lists change; your customer's status changes with them.
Screening re-runs on a cron every Monday at 02:00 Brisbane time across every active party in every tenant, against versioned watchlists. It is scheduled infrastructure, not a reminder for someone to click. New matches are raised as decisions requiring a human disposition rather than being auto-cleared.
How to check
- Ask when your parties were last screened and against which list version — the answer should be a timestamp and a version, not 'at onboarding'
- Confirm a new match surfaces as something requiring your sign-off rather than a passive log entry
- Ask us directly about screening-data depth for adverse media in Australia. It is the thinnest part of the market and we would rather tell you than have you find out
Test 4
Test your exit before you need it.
Your seven-year retention obligation survives our business. If we fold or you leave, you need the records in a form AUSTRAC would accept — and you need it without our cooperation.
The AUSTRAC export is a self-contained ZIP: every append-only record chain as newline-delimited JSON, a manifest with a SHA-256 of every file, per-chain verification results, and human-readable registers. It ships with a standalone Python verifier that uses only the standard library, so an auditor with no internet access and no Korvos tooling can re-check every hash on a laptop. The export refuses to assemble if any chain fails verification — a broken chain surfaces as an error, not a quietly incomplete bundle.
How to check
- Download an export today, while you are not under pressure, and run the included verify.py against it
- Read the integrity spec and the verifier source before you trust either — both are published
- On cancellation the full bundle is assembled automatically and a signed download link is emailed to you. You do not have to ask us for your records at the moment you have decided to leave
Test 5
Does the generated programme read like yours?
AUSTRAC will ask you to explain your reasoning, and "the software wrote it" is not an answer. A programme that could belong to any agency belongs to none.
The programme and risk assessment are drafted from your agency's own profile — an interview covering how you actually operate — and the emphasis of each section shifts with what you tell it. But we are deliberate about what this is: Korvos is a drafter, not an oracle. The draft goes to the licensed principal, who reviews, amends and seals it. That review is the point at which it becomes your programme, and it is not optional.
How to check
- Open the draft and look for your actual risk profile: your buyer mix, whether you hold deposits, your offshore exposure, the way your office really works
- If a section reads as though it could belong to any agency, amend it before sealing — that is what the seal step is for
- Every generated claim cites the source it came from. Follow a few of them
Test 6
Ask what actually enforces immutability.
"Tamper-proof" is a marketing word. The question is what physically stops a record being changed, and whether the vendor itself could change it.
AML records are append-only at the PostgreSQL level: UPDATE and DELETE are revoked from the application roles, and database triggers reject any mutation that gets past the grant model. Each row carries a sequence number and a hash over its predecessor, so altering any record anywhere in the history breaks the chain and the break is detectable by anyone holding an export. Raw watchlist payloads are separately archived to AWS S3 Object Lock in Compliance mode with seven-year retention, which Korvos itself cannot delete or shorten.
How to check
- Read the hash-chain spec — the algorithm is documented, not asserted
- Verify an export yourself with the supplied script; you are checking our arithmetic, not our promise
- Be precise about scope when comparing vendors: the record chains are protected by the database layer, and the Object Lock storage covers watchlist payloads. Migrating the chains themselves onto object-lock storage is planned work, not a control we have today
Test 7
Ask where the data and the AI actually run.
APP 8 makes offshore disclosure your problem, not your vendor's. Most AI compliance tools route inference through the United States.
Agency data is stored and processed in ap-southeast-2 (Sydney), and AI inference runs on AWS Bedrock in Sydney. Where a US-hosted service is unavoidable — workflow orchestration and billing webhooks — the payloads carry opaque identifiers only, and the data a workflow needs is re-read inside each step from Sydney rather than crossing the boundary.
How to check
- Settings › Data residency is a read-only register of every integration and where its data sits — check it against this claim
- Ask any vendor the same question about their AI inference specifically, not just their database
What Korvos is not
The limits, stated plainly
Getting these wrong creates legal exposure for you, not for us. That is exactly why they belong on our own website rather than in the fine print.
You cannot rely on us the way you can rely on a solicitor
Korvos is not a reporting entity. Under the AML/CTF Act we are an outsourced service provider under s 37, not a third party who can be relied on under s 37A or s 38 — AUSTRAC excludes KYC and outsourced providers from the reliance regime expressly, because they are not supervised under the AML/CTF laws. The verification we run is your customer due diligence, performed on your behalf, and the liability for it stays with you. Any vendor who implies otherwise is selling you a defence you do not have.
Four obligations remain entirely yours
Enrolling with AUSTRAC, appointing your AML/CTF compliance officer, delivering and recording your staff training, and commissioning your independent evaluation. These run alongside the platform, not inside it. We will remind you and hold the records; we cannot discharge them for you.
The suspicion is yours to form
Korvos surfaces indicators and drafts suspicious matter reports. It does not decide that you are suspicious — that judgement, and the decision to report, is the principal's. So is managing the tipping-off prohibition in s 123: your team must understand they cannot mention a report to the customer.
We do not give legal advice
Our Learn library explains the regime and cites primary sources for every claim, and we would rather you check them than take our word. It is not a substitute for your own adviser. If you are relying on a single source for a regime with civil penalties attached, make sure it is one that owes you a duty.
What to ask us directly
Vendor due diligence is part of demonstrating that your programme is risk-appropriate, and a desk review will look at it when a small agency has outsourced its compliance stack. Ask us what independent assurance we hold and what is in progress, how we handle a data-breach notification, and what our incident history looks like. Document the answers. If we are evasive, that is itself a finding.
One more piece of advice against our own commercial interest: if you are standing up compliance for the first time, budget for an AML/CTF adviser to review your sealed programme and your first dozen files. That covers the gap between “the software produced a document” and “I can defend this to AUSTRAC” — and it is the part you, not we, are personally exposed on.