Skip to content
§
§ · build vs buy

AML and KYC Client Onboarding Software: Build or Buy for a Regulated Practice

The threshold is roughly 50 fee earners combined with a client base that includes corporate structures, trusts or offshore vehicles.

Custom Software Development workflow illustration for AML KYC Client Onboarding Software Build vs Buy Guide.
The short answer

The threshold is roughly 50 fee earners combined with a client base that includes corporate structures, trusts or offshore vehicles. Below that, an anti money laundering (AML) and know your customer (KYC) verification product such as Amiqus or Thirdfort connected to your practice management system covers the obligation properly, and most firms reading this sit below the line. Above it, where the failure mode is a matter opening before the risk assessment exists, a custom build costs $60,000 to $130,000 for a first release in 10 to 16 weeks and $180,000 to $400,000 for a full platform phased over 6 to 12 months in Digital Heroes delivery experience.

When is off the shelf genuinely the right call here?

For most firms the honest answer is buy. Amiqus and Thirdfort handle individual identity verification and source of funds collection properly, and both are a large improvement on a partner asking for a passport photograph by email. ComplyAdvantage and LexisNexis Bridger Insight are serious sanctions and politically exposed person screening providers, and screening is not a problem you should be solving yourself. If your firm has fewer than about 50 fee earners, your client base is mostly individuals and domestically registered companies, and your matter types repeat, one of those verification products wired into your practice management system covers the obligation at a fraction of a build.

There are two further cases where buying is correct even at larger firms. The first is where your professional body has raised nothing, your internal file reviews come back clean, and the pain you feel is administrative rather than evidential. Administrative pain is cheaper to fix with a written process and a properly staffed compliance team than with software. The second is where your practice management vendor already ships a compliance module you have never configured. Configuring something you have already bought is the cheapest project available to you, and you should exhaust it before commissioning anything.

What buying does not give you is a risk assessment recorded at both client and matter level, a matter number that cannot be issued until compliance clears it, and a file shaped the way your supervisor reads files rather than the way a bank onboards a retail customer. Those products were largely built for financial institutions. A law firm does not onboard customers, it accepts instructions, and the difference shows up when someone samples your files eighteen months later.

When does a custom build actually pay off?

The build pays when the gap between what you are told and what you can evidence has a name and a date attached to it. There are three conditions, and you want at least two of them present before you spend anything.

The first is the gate. Every firm that has been through a difficult file review says the same thing: the risk assessment existed, it was just completed after work had started. A gate that refuses to issue a matter number until a completed assessment exists is the entire value of this category, and it only works if it lives inside the system your fee earners already use to open matters. No verification product can build that gate, because it does not own your matter opening.

The second is structure. If a meaningful share of your clients are holding companies, trusts, offshore vehicles or funds, you need beneficial ownership modelled as a graph with evidence attached to each link, not as a free text box recording the name of an ultimate owner. Products built for retail onboarding treat ownership as an attribute on a record. You need it as a structure you can redraw and re-evidence when the client restructures, which they will.

The third is source of funds. This is where files fail. A source of funds record is a chain: the client says the money came from a property sale, you hold the completion statement, the bank statement showing receipt, and a note explaining why the amount differs by eleven thousand. Nothing off the shelf models that chain, because it is professional judgement with documents attached rather than a verification result with a green tick.

How do they compare on the things that matter in this industry?

Compare on the points a supervisor will actually test, not on feature lists.

  • Risk assessment scope. Bought products assess the client. Your obligation runs to the matter as well, because a conveyance for a known client is not the same risk as a corporate acquisition for the same client. Some practice management modules allow a second assessment, most treat it as a form rather than as a gate.
  • Where the block sits. A product that advises will be bypassed under deadline pressure by a partner with a real completion date. A block that sits inside matter opening will not. This is the single largest difference between the two options.
  • Evidence file shape. Verification providers give you a verification result and a document store. A supervisor wants a chronology: what was assessed, when, on what evidence, who approved the override, and whether work started before any of it existed.
  • Integration burden. Buying does not remove integration work, it relocates it. Connecting a verification product into matter opening still means somebody maintaining that connection through both vendors' release cycles.
  • Per seat economics. Verification products charge per check, which scales with instructions rather than headcount, and that is usually reasonable. Compliance platforms charge per user, and firms end up rationing licences so the people who most need visibility do not have it.
  • Data portability. Ask, in writing, how you extract five years of assessments, documents and audit trail in a form you can read without the vendor. If the answer is a comma separated export without the audit trail, you do not own your evidence.

What does total cost of ownership look like at your scale?

A focused first release covering client and matter risk assessment, the onboarding workflow with a hard gate on matter opening, document collection and the structured evidence file runs $60,000 to $130,000 and ships in 10 to 16 weeks in our delivery experience. A full platform adding beneficial ownership graph modelling, screening integration with alert adjudication, source of funds evidence chains, periodic review scheduling with escalation and practice management integration runs $180,000 to $400,000 phased over 6 to 12 months.

The smallest thing worth building is the risk assessment model plus the hard gate, leaving document collection exactly as it is today. That runs $28,000 to $48,000 over six to eight weeks and addresses the finding most firms actually receive.

Against that, running costs. Infrastructure for a platform of this shape is typically $200 to $700 a month, driven by document retention rather than by activity. Budget continuing engineering at roughly a fifth of the build cost in year one and a tenth thereafter. Your verification and screening subscriptions do not disappear in a build scenario, because you should keep them.

On the buy side, the number to compute is not the subscription. It is the subscription plus the compliance time still spent chasing documents by email, plus the cost of the file reviews that come back with gaps. Firms tend to know the first number precisely and the second not at all. Work out how many partner and compliance hours a month go into chasing, then price them at charge out rather than salary, because that is what the hours were displacing.

What does the hybrid look like, and when is it the honest answer?

The hybrid is the right answer for most firms above the threshold, and it is what we recommend most often. Keep Amiqus or Thirdfort for individual verification and consumer facing source of funds collection, keep ComplyAdvantage or your existing screening provider for sanctions and politically exposed person checks, and build only the three things nobody sells you: the client and matter risk assessment model, the hard gate into matter opening, and the evidence file organised the way your supervisor reads it.

That is a genuinely smaller project than a platform. It reuses the verification you already trust, it keeps sanctions list maintenance with a vendor whose job that is, and it puts your money where the failure actually happens. It also fails more gracefully. If the build stalls, you still have working verification and screening, which is not true if you replaced everything.

The version of the hybrid that goes wrong is the one where the gate is advisory because integrating properly with the practice management system looked expensive during scoping. An advisory gate is a spreadsheet with better styling. If your practice management vendor will not expose matter creation, that is a fact to establish in week one, not month four, because it changes the project.

Which should you choose, by operator size and stage?

Under 20 fee earners, buy. A verification product plus a written risk assessment template plus a compliance officer who reads every file is proportionate and defensible. A build here is vanity and it consumes attention you need elsewhere.

Between 20 and 50 fee earners, buy and configure hard. Use your practice management compliance module properly, connect verification into it, and hold a monthly file sample. If you are feeling pain at this size it is usually process, not tooling.

Between 50 and 150 fee earners with corporate or international work, build the hybrid. Risk assessment, gate and evidence file, $60,000 to $130,000, keeping your verification and screening vendors. Add beneficial ownership and source of funds chains in a second phase once the first is in daily use.

Above 150 fee earners, or any size with multi jurisdiction obligations and several regulators, the full platform at $180,000 to $400,000 is defensible, but phase it. Firms that try to build everything before anyone uses any of it end up with an expensive system and partners still emailing for passports.

At any size, if you have just received a finding, resist the urge to buy your way out in a fortnight. Read what the finding actually says. A governance finding and a detection finding look similar on paper and cost very different amounts to fix.

If you want that decision made properly rather than quickly, Digital Heroes writes a product requirements document before any code exists, so the scope is fixed and priced rather than discovered later at a day rate. You can take that specification to any other firm on your shortlist.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey argues software developer productivity can be measured by combining system-level metrics (DORA and SPACE) with its own outcome-oriented approach, which it reports deploying across nearly 20 tech, finance, and pharmaceutical companies - a claim that sparked significant debate in the engineering community. Source: McKinsey & Company (2023) →
  2. Retailers improving Core Web Vitals saw measurable gains: Vodafone improved LCP by 31% for 8% more sales, Lazada saw a 16.9% mobile conversion increase, and Cdiscount saw a 6% Black Friday revenue uplift. Source: web.dev (Google Chrome team) (2021) →
  3. In an RCT, the no-show rate was 23.5% for patients receiving a text-message reminder versus 38.1% for the control group - a 14.6 percentage-point reduction (p = 0.04). Source: Clinical Pediatrics / PubMed Central (Lin et al.) (2016) →
  4. An EY survey found one in five U.S. payrolls contains errors, each costing an average of $291 to remediate, with a typical 1,000-employee organization spending roughly 29 workweeks per year fixing common payroll errors. Source: EY (Ernst & Young) (2022) →
FAQ

Frequently asked questions

Is Amiqus or Thirdfort enough for a firm of our size?

For a firm under roughly 50 fee earners with a client base of individuals and domestically registered companies, yes, and connecting it into your practice management system is a better use of the money than a build. Both products do individual identity verification and consumer facing source of funds collection well. Where they stop is matter level risk assessment, a hard gate on matter opening, and beneficial ownership modelled as a structure rather than a field. If those three are your problem, no amount of configuration in a verification product reaches them, because they were not built to.

What does it cost to switch off our current onboarding tool?

The subscription is the small part. Budget for extracting five years of assessments, documents and audit trail, checking the export is readable without the vendor, and running both systems in parallel for a full quarter so nothing opens outside the new gate. In our delivery experience that parallel period is where firms discover which matter types never went through the old tool at all. Ask your current vendor for a sample export before you commit to anything, and look specifically for whether the audit trail comes with it or stays behind.

What happens if our verification provider raises its per check price?

Per check pricing is the easier exposure to manage, because it scales with instructions rather than headcount and you can model it. The harder exposure is a platform priced per user, where a rise pushes firms into rationing licences and the people who most need visibility lose it. The practical protection is architectural: keep verification behind an interface of your own so swapping provider is a piece of integration work rather than a re-platforming. Firms that wire a provider directly into every screen find that switching costs more than the price rise they were escaping.

How long before fee earners are actually opening matters through it?

Ten to sixteen weeks for a first release, with the risk assessment and the gate usually first into production because everything else depends on them. Discovery takes the opening two to three weeks and is mostly spent reviewing ten real files against what a supervisor would ask for, which is the document that should exist before code is written. Plan a full month of live matter opening before you start phase two. Firms that skip that month find their assessment model wrong during a real deadline rather than during a quiet week.

Can we keep ComplyAdvantage for screening and build only the risk assessment?

Yes, and this is the pattern we recommend most often. Sanctions and politically exposed person list maintenance is a vendor's job and doing it yourself is a commitment with no upside. The build sits above screening, holds the assessment, owns the gate, and captures alert adjudication with a reason and a named approver, which is the part most screening tools record thinly. The cost is $28,000 to $48,000 over six to eight weeks for the assessment and gate alone, which is a fraction of a platform and addresses what most findings actually describe.

Will a build genuinely stop partners opening matters before clearance?

Only if the block lives inside matter opening in your practice management system, and that is the line item that carries the schedule risk. A separate screen that fee earners are asked to visit first will be bypassed by a partner with a completion date, every time, and everyone involved knows it. Establish in week one whether your practice management vendor exposes matter creation to an external check. If it does not, you are choosing between a different kind of control, such as blocking time recording, and a conversation with the vendor.

What should we budget for the year after launch?

Roughly a fifth of the build cost in year one and closer to a tenth in following years, spent on real change rather than on a support retainer. On a $110,000 first release that is around $22,000 in year one. Add infrastructure at $200 to $700 a month for a firm of this shape, driven by how long you retain documents rather than by how many checks you run. Your verification and screening subscriptions continue, because the sensible architecture keeps them.

What is the smallest useful thing we could build?

The client and matter risk assessment with structured factors, a proposed rating, a documented override and an immutable submission, plus the hard gate into matter opening. Documents keep arriving exactly as they do today. That is $28,000 to $48,000 over six to eight weeks, and it is the version we suggest when a firm is unsure whether the larger project is justified. If the gate holds for a quarter and the file reviews improve, you have your evidence for phase two. If partners route around it, you have learned that cheaply.

Is a solo freelancer enough for my project, or do I really need an agency?

A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.

What happens if I stop paying for maintenance after launch?

Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.

How do we get years of data out of our old system and into the new one?

Treat migration as a planned sub-project: a field-mapping document, at least one dry run on a copy of your data, then a cutover with the old system kept read-only for 30 days as a safety net. On Digital Heroes projects it consumes 10 to 15% of the budget when the old system has an export, and more when data must be pulled out screen by screen. Ask any vendor to walk you through their last migration before you sign.

How do I work out whether custom software will pay for itself?

Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.

How do I make sure custom software is secure and compliant with rules like HIPAA?

Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.

How many people should be working on my software project?

A typical $40,000 to $150,000 build runs on three to five people: a technical lead, one or two developers, a designer, and someone owning QA and project communication, often as overlapping part-time roles. More bodies do not make software arrive faster; past a point they slow it down with coordination overhead. The question that matters more than headcount is whether one named senior engineer is accountable for the outcome.

How do I calculate whether custom software will pay for itself?

Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.

If an agency builds my software, who actually owns the code?

You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.

Can I build my product on a no-code tool like Bubble instead of hiring developers?

For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.

Does it matter which tech stack the agency wants to use?

Yes, but not in the way most buyers expect: the goal is boring, popular technology such as React, Node.js or Python, and PostgreSQL, because any future team can maintain it and hiring a replacement developer takes days, not months. The red flag is an agency-proprietary framework or an unusual language, which welds you to that one vendor no matter what your contract says about code ownership. A useful test: could you find three freelancers fluent in this stack within a week? If not, push back.

What are the biggest mistakes first-time software buyers make?

Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.

Who owns the code when an agency builds my software?

You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply