Xama Technologies (AML)

Introduction

PracticeFlow manages AML risk assessment tasks and deadlines. It does not manage the AML checks themselves.


AML checks are the identity and other AML verification checks carried out on a client or relevant individuals.

AML risk assessment is the assessment of the client’s overall AML risk level (High, Medium or Low), which PracticeFlow tracks as a recurring task. The review frequency is set in Account Settings.


If you do not use an AML provider, you can carry out the AML checks separately and record the risk assessment directly in PracticeFlow.


If you use Xama, the AML checks and risk assessment are completed in Xama. The PracticeFlow AML risk assessment task remains in place for tracking and deadlines and is completed automatically when PracticeFlow receives the completed risk assessment from Xama. PracticeFlow then updates the client’s AML information and schedules the next review.


This avoids duplicating the risk assessment outcome in PracticeFlow while keeping AML tasks visible alongside the rest of the work you manage for the client.


This guide explains how to connect PracticeFlow to Xama, create or link clients, and how completed risk assessments in Xama are reflected in PracticeFlow.


  1. Connect to Xama

Before you can create or link clients in Xama, you need to connect your Xama account to PracticeFlow.


Go to: Settings (cog icon) > Integrations


Initially you will see the Xama integrations panel with fields for the required Xama settings and an arrow icon that links to the location where you can copy the API credentials.

Link to the API credentials:

https://platform.xamatech.com/portal/hub/settings/apps/open-api


In the Xama section, enter:

  • API Client ID
  • OAuth Client ID
  • OAuth Client Secret

Once saved, your account will show as connected. A disconnect option is also available.


  1. Prior to linking a client

Clicking on a client in PracticeFlow opens the side panel showing client details. Scroll down to the AML section.


Before linking:

  • The client will show as Not linked to Xama.
  • You will see:

- Create in Xama button.

- the search box will already be pre-populated with the client’s name.

- You can overwrite the pre-populated name if required.



  1. Link an existing Xama client

If the client already exists in Xama (or you want to search):

  • Accept the pre-populated client name or replace it with another search term
  • Click Search
  • Select the correct client from the results
  • Click the blue Link button

This connects the existing Xama client to the PracticeFlow client.

Important:

  • Where a registration number is available, PracticeFlow checks it against the selected Xama client. If the numbers do not match, you will be asked to confirm before linking.


  1. Create and link a new Xama client

4.1 Client does not exist in Xama

Click Create in Xama.


This will:

  • Create a new client in Xama using the organisation name, company registration number and primary contact details (first name, last name and email) held in PracticeFlow.
  • Automatically link the client

The primary contact details must be set in PracticeFlow.

Important:

  • If the client already exists in Xama, a confirmation message will be shown asking you to confirm before proceeding.

4.2 Client does not exist in either system

Create the client in PracticeFlow first manually or using Companies House import.


Next:

  • Add the required contact details.
  • Click Create in Xama


  1. After linking

Once linked, the status will show as Connected.

You will see:

  • Refresh Status
  • Unlink

AML data (status, risk level, last RA date, notes) will be populated from Xama.



  1. How AML works once linked

When a client is linked to Xama:

  • AML risk assessments are completed in Xama only.
  • PracticeFlow updates automatically when an assessment is completed.
  • The following fields are updated:

- AML status

- Risk level

- Last AML (RA) date

- Notes (if provided)


  • You cannot manually complete AML tasks in PracticeFlow.
  • Historical AML assessments already completed in Xama before linking are not imported into PracticeFlow as historical AML tasks. The latest completed risk assessment is synchronised and used to manage AML tasks going forward.




  1. How PracticeFlow handles updates from Xama

When a risk assessment is completed in Xama, PracticeFlow compares the assessment date to the client’s last completed AML task.


7.1 Same date > update existing record

If the Xama assessment date is the same as the last AML date:

  • The existing completed AML task is updated.
  • Risk level and notes are refreshed.
  • No new task is created.

PracticeFlow does not create multiple AML tasks for the same day.

The latest assessment updates the existing AML task for that date.


7.2 Earlier date > ignore update

If the Xama assessment date is before the last AML date:

  • The update is ignored.
  • No tasks or client data are changed.

7.3 Later date > complete current task

If the Xama assessment date is after the last AML date:

  • The current AML task is completed.
  • The completion date is taken from Xama.
  • The client’s AML details are updated.
  • A new AML task is scheduled.

Important:

  • A new AML task is created for the next cycle based on the RA date from Xama.


  1. How future AML tasks are created after linking

AML tasks continue to be created and tracked within PracticeFlow.


Once a client is linked, AML tasks are completed automatically based on updates received from Xama. Each completed AML cycle creates a new AML task for the next review period. Existing completed AML tasks within PracticeFlow remain unchanged.


  1. Timing of updates

Updates usually happen automatically when a risk assessment is completed in Xama.


You can also refresh the status at any time by clicking the Refresh Status button at the top of the AML section in the client-side panel.



  1. Disconnecting

10.1 Disconnecting a Client:

If you disconnect a client from Xama:

  • The link to Xama is removed.
  • Existing AML history and tasks remain unchanged.
  • You can manage AML manually in PracticeFlow again.

10.2 Disconnecting the Account:

If you disconnect the entire account from Xama by clicking Disconnect in the Integrations tab:

  • The links to all clients are removed.
  • Existing AML history and tasks remain unchanged.
  • You can manage AML manually in PracticeFlow again.

After reconnecting to Xama, all clients must be linked again.



  1. Working in Xama (overview)

In Xama you can:

  • Create clients
  • Open a client record
  • Carry out identity verification and AML checks
  • Run client risk assessments
  • Record risk levels, completion dates and notes
  • Save and approve assessments.

Once completed, the update is sent back to PracticeFlow automatically.