EWRA Platform

dooit.ai — Platform Overview

Enterprise-Wide Risk Assessment & GRC platform for AML/CTF compliance

dooit.ai is an end-to-end AML/CTF compliance management platform built to meet AUSTRAC, FATF, and ISO 31000 requirements. It covers the full compliance lifecycle — entity setup, obligation mapping, enterprise-wide risk assessment, customer risk scoring, control testing, issue remediation, and executive reporting.

How modules connect

Entity is the anchor. All other modules link back to one or more entity profiles:

  • Obligation Library → Entity Obligations: Instantiation copies matching library obligations into the entity's obligation register.
  • Controls Library → EWRA: Control effectiveness scores inform residual risk calculations in the EWRA.
  • Country Risk → CRA: A customer's country geography score is derived from the country risk table.
  • Control Testing → Issues: Failed tests should produce linked issues for remediation tracking.
  • RG Mapper → Obligation Library → Entity: Regulatory guides bundle obligations that can be bulk-mapped to entity profiles.
  • All modules → Reports: The Executive Dashboard and EWRA Dashboard aggregate data across all modules.

Quick-Start Flow

Recommended sequence for a new deployment

1

Seed reference data

Setup

Run seed scripts: country risk (seedCountryRisk.js), obligation library (seedObligations.js), controls library (seedControls.js).

2

Create Entity Profile

Setup

Entity Setup → New Entity. Fill entity name, type, licenses, designated services, and jurisdictions. Save as Draft.

3

Instantiate Obligations

Setup

Entity detail page → 'Instantiate Obligations'. The system auto-matches library obligations to the entity. Review and adjust statuses.

4

Assign Control Owners

Setup

Controls → Assign Owners. Map an owner and testing frequency to each applicable control before scheduling tests.

5

Run EWRA Assessment

Assess

EWRA → New Assessment. Score each risk factor (inherent risk 1–5, control effectiveness) and approve the assessment.

6

Score Customer Risk (CRA)

Assess

Customer Risk → New Assessment. Complete the 7-factor scoring form for each customer to generate a risk label.

7

Schedule Control Tests

Operate

Testing → Schedule Test (or use templates). Assign testers and set scheduled dates. Record results when tests are performed.

8

Log & Resolve Issues

Operate

Issues → Log Issue for any compliance finding. Track status through to Closed. Fail test results must produce an issue.

9

Review Reports

Review

Reports → Executive Dashboard. Review open issues, pass rates, residual risk trends, and country risk exposure.

Setup
Assess
Operate
Review

Entity Setup

Register and configure regulated entities and their obligation registers

1

Create a new entity profile

Navigate to Entity Setup → New Entity.

Set the status to Draft while completing setup, then switch to Active when ready for obligations to be instantiated.

Entity Profile — Field Reference

FieldRequiredDescription
Entity NameYesFull legal name of the regulated entity. Used across all reports and linked assessments.
Entity TypeYesSelect from master list (e.g. AFSL Holder, REM — Remittance, Digital Currency Exchange, ADFS). Determines which obligations are matched during instantiation.
CategoryAutoDerived from Entity Type (e.g. Tranche 1, Tranche 2). Used for FATF classification and obligation matching.
LicensesRec.Multi-select from LicenseType master (AFSL, ACL, DCE, REM, etc.). Influences which licensed-product obligations are instantiated.
Designated ServicesRec.Services the entity provides (e.g. Provide a designated remittance service, Exchange digital currency). Drives applicable AML/CTF obligations.
JurisdictionsRec.Countries where the entity operates. Used for EWRA geography scoring and cross-border obligation assessment.
StatusYesDraft → Active → Archived. Only Active entities can receive EWRA assessments. Archived entities are read-only.
ABN / ARBNNoAustralian Business Number or Company Number for identification purposes.
AML/CTF Programme Start DateNoDate the entity's AML/CTF program was first established. Useful for audit trail.
NotesNoInternal compliance notes visible only to users of this platform.

Entity Types Reference

Code / NameTrancheDescription
AFSL HolderTranche 1Australian Financial Services Licence holder providing designated financial services.
ADITranche 1Authorised Deposit-taking Institution (banks, credit unions, building societies).
REMTranche 1Remittance dealer or registrant — provides designated remittance services.
DCETranche 1Digital Currency Exchange — buys/sells digital currency for fiat on behalf of customers.
ADFSTranche 1Provider of a designated alternative remittance or financial service.
Bullion DealerTranche 1Dealer in precious metals or stones above threshold.
Gambling ServiceTranche 2 (proposed)Casinos, bookmakers, sports wagering providers subject to AML/CTF obligations.
Real Estate AgencyTranche 2 (proposed)Real estate agents dealing with high-value property transactions.
Accounting / LegalTranche 2 (proposed)Professional services firms in scope of proposed Tranche 2 reforms.
2

Instantiate obligations

On the entity detail page click "Instantiate Obligations". The system queries the Obligation Library and filters by:

  • Entity Type name — matches applicableEntityTypes exactly or as "All Entities"
  • Entity Category — regex match against applicableEntityTypes (e.g. "Tranche 1")
  • Licenses — matches obligations with applicableLicenses containing any of the entity's licenses

Obligations already instantiated are skipped (no duplicates). The response shows created and skipped counts.

3

Manage the obligation register

Go to the entity's Obligations tab. Inline-edit each obligation's status and test result directly in the table.

Obligation Status Values

StatusMeaningWhen to use
ActiveObligation applies and is being managedDefault for all instantiated obligations
PendingObligation applies but implementation is not yet completeUse during onboarding or when a new regulation comes into effect
ExemptFormally exempted — e.g. via AUSTRAC class order or internal waiverRequires documented justification. Attach the exemption reference in the notes field.
Not ApplicableObligation does not apply to this entity's activitiesUse sparingly. Document why in the obligation notes.

Obligation Test Result Values

ResultMeaning
PassThe obligation was tested and found to be fully met
FailThe obligation was tested and found to be not met. Must generate an Issue.
PartialThe obligation is partially met — some elements pass, others need remediation
Not TestedDefault. The obligation has not yet been tested in this period
After updating entity attributes (new license, new jurisdiction), re-run "Instantiate Obligations" — newly matched obligations will be added; previously instantiated ones will be skipped.
If instantiation returns 0 new obligations, the entity type/license values in the profile must exactly match the applicableEntityTypes / applicableLicenses values in the Obligation Library seed data. Check for case sensitivity and spacing.

Controls Library

Browse, filter, and assign ownership across 200+ AML/CTF controls

1

Browse and filter controls

Go to Controls Library. Use domain pills (GOV, CDD, SCR…) to filter by domain. Use the toolbar dropdowns to narrow by Control Type, Automation Level, and Risk Level.

2

Assign control owners

Go to Controls → Assign Owners. The bulk assignment table lets you set Owner (free text or user lookup) and Testing Frequency for multiple controls in one save. Ownership is a prerequisite for scheduling tests.

3

View a control detail

Click View → on any row. The detail page shows: full description, FATF Recommendations, linked obligation IDs, control type, automation level, and edit history.

Control Types

TypeDescriptionExample
PreventativeStops a risk event from occurringTransaction limit rules that block high-risk transfers above threshold
DetectiveIdentifies a risk event after it occursTransaction monitoring alerts, screening hits, audit log reviews
CorrectiveFixes the impact of a risk eventAccount remediation process, SAR filing workflow, incident response
DirectiveProvides instruction or guidance to prevent errorsAML/CTF policy manual, staff procedures, training requirements
CompensatingFills a gap where a primary control is absent or weakEnhanced manual review compensating for a missing automated screen

Automation Levels

LevelDescriptionTesting Priority
ManualPerformed entirely by staff — no system assistanceHighest — human error risk
Semi-AutomatedPartially automated; requires human review/decision at some stepHigh — validate both the system and human components
AutomatedFully system-driven with no manual intervention for routine operationMedium — focus on exception handling, alert calibration, system uptime
Sort controls by Risk Level (Critical / High first) and Automation Level (Manual first) to build a risk-based testing priority list.

EWRA Assessment

Enterprise-Wide Risk Assessment — ISO 31000 + FATF methodology

1

Create a new assessment

Go to EWRA → New Assessment.

Select: Entity Profile, Assessment Type, and the Period (start year / end year). Name the assessment descriptively — e.g. "ACME Financial — Annual EWRA 2025".

Assessment Types

TypeWhen to use
AnnualStandard yearly EWRA as required by AUSTRAC Rule 4.1.2
PeriodicHalf-yearly or quarterly review cycle for higher-risk entities
TriggeredUnscheduled — triggered by a material event (new product, merger, regulatory finding, FATF list change)
InitialFirst-ever assessment for a newly registered entity
2

Score each risk factor

For each factor, provide two inputs:

  • Inherent Risk Score (1–5) — the raw risk level before any controls
  • Control Effectiveness — how well the controls mitigate that inherent risk

The system calculates Residual Risk = Inherent Risk × Control Effectiveness multiplier.

EWRA Risk Factors

FactorWhat to scoreKey considerations
Customer RiskOverall ML/TF risk of the customer baseMix of PEPs, high-risk occupations, complex structures, cash users
Product & Service RiskInherent risk in the products/services offeredCash intensity, anonymity features, cross-border capability
Delivery Channel RiskRisk introduced by how services are deliveredNon-face-to-face, agent networks, digital-only, cryptocurrency
Geographic RiskRisk from the jurisdictions of operations and customersFATF Grey/Black list countries, sanctioned jurisdictions, offshore hubs
Transaction RiskPatterns of transactional risk in the businessHigh-value, high-frequency, structured/round transactions
Control EnvironmentOverall maturity and coverage of the AML/CTF control frameworkPolicy completeness, training frequency, testing regularity
Regulatory HistoryHistory of regulatory findings, enforcement, or self-reported incidentsPrevious AUSTRAC findings, audits, enforceable undertakings

Inherent Risk Scoring Guide (1–5)

1
Negligible— Minimal exposure. Activity is very limited in volume and nature.
Single-product AFSL with domestic retail clients only
2
Low— Limited exposure. Some risk indicators present but well-contained.
Small remittance dealer, domestic only, low transaction volumes
3
Medium— Moderate exposure. Multiple risk indicators; mixed customer and product risk.
Mid-size AFSL with some offshore clients and complex products
4
High— Significant exposure. Multiple elevated risk indicators across factors.
DCE with international transfers, PEP exposure, cash-adjacent services
5
Very High— Extreme exposure. Operates in high-risk jurisdictions with complex, cash-intensive products.
Cross-border remittance to UHRC jurisdictions at scale

Control Effectiveness Ratings

RatingMultiplierDescriptionCriteria
Strong0.25×Controls are robust and consistently appliedTested annually or more, no material exceptions, documented procedures, trained staff
Adequate0.50×Controls generally work; minor gaps existTested, mostly compliant, occasional exceptions remediated within SLA
Weak0.75×Controls exist but are inconsistently appliedRarely tested, recurring exceptions, gaps in coverage or documentation
Ineffective1.00×Controls are absent, untested, or known to be failingNo testing evidence, known failures, no documented procedures

Residual Risk Ratings

RatingResidual Score RangeRequired Action
Low0 – 1.5Standard monitoring. Annual review cycle.
Medium1.5 – 2.5Heightened monitoring. Semi-annual review. Board reporting.
High2.5 – 3.5Enhanced monitoring. Quarterly review. Senior management escalation. Consider voluntary disclosure to AUSTRAC.
Critical3.5 – 5.0Immediate action. Executive escalation. Potential SAR obligation. Consider proactive contact with AUSTRAC.
3

Approve and manage the lifecycle

Move the assessment through: Draft → In Review → Approved.

Approved assessments are read-only — use Archived when superseded by a newer assessment.

FATF Recommendation 1 requires a risk assessment that is current, documented, and considers all relevant ML/TF risk factors. The EWRA module is designed to produce an auditable record meeting this requirement.

Customer Risk Assessment (CRA)

AUSTRAC-aligned 7-factor individual customer scoring model

1

Create a new CRA

Go to Customer Risk → New Assessment.

Enter: customer name, customer type (Individual / Company / Trust / Partnership / Other), and country of residence/operation.

2

Score the 7 risk factors

Each factor is scored 1–5. The composite score is a weighted average that maps to a risk label.

CRA Factor Scoring Reference

Factor 1 — Customer Type

1
Low-risk individual— Retail customer, known occupation, domestic
2
Standard individual / SMSF— Self-managed super, small business owner
3
Company / Partnership— Private company, standard commercial activity
4
Complex structure / Trust— Discretionary trust, foreign company
5
Shell / High-risk structure— Bearer share company, anonymous structure, nominee arrangement

Factor 2 — Business / Occupation Nature

1
Low-risk occupation— Salaried employee, pensioner, public servant
2
Standard business— Retail trade, professional services (non-PEP)
3
Cash-adjacent business— Hospitality, parking, car washing, markets
4
High-cash business— Licensed gambling, money services, nightclubs
5
Prohibited / Sanctioned— Arms dealing, sanctions-listed entity, illegal activity

Factor 3 — Transaction Volume & Value

1
Very low— < $10,000/month, infrequent, consistent with profile
2
Low— $10K–$50K/month, occasional variation
3
Moderate— $50K–$200K/month, some unexplained variation
4
High— $200K–$1M/month, structuring patterns, round amounts
5
Very high— > $1M/month, inconsistent with profile, rapid movement

Factor 4 — Geographic Risk

1
LRC jurisdiction— Low-risk country — FATF member with strong AML/CTF framework
2
MRC jurisdiction— Medium-risk country — known weaknesses, increased vigilance
3
HRC jurisdiction— High-risk country — FATF Grey List, significant deficiencies
4
UHRC jurisdiction— Ultra-high risk — FATF Black List, heavily sanctioned
5
Sanctioned country— Subject to UN/OFAC/DFAT sanctions. Potential prohibition applies.

Factor 5 — PEP / Sanctions / Adverse Media

1
No indicators— No PEP, no sanctions, no adverse media
2
Potential/former PEP— Family member of former PEP, historical adverse media
3
Domestic PEP— Domestic Politically Exposed Person
4
Foreign PEP— Foreign PEP — heightened ML/TF risk per FATF R.12
5
Sanctioned / Prohibited— Match on sanctions list (UN, OFAC, DFAT). Must not onboard.

Factor 6 — Delivery Channel

1
Face-to-face verified— In-person identity verification completed
2
Standard digital onboarding— Verified digitally via approved DVCR or biometric
3
Non-face-to-face— Remote onboarding without certified digital verification
4
Agent / Third-party— Introduced via agent or broker without direct verification
5
Anonymous / Unverified— Identity not verified. High anonymity. Possible synthetic identity.

Factor 7 — Relationship Complexity

1
Simple, single customer— One beneficial owner, straightforward purpose of relationship
2
Small group / simple trust— 2–3 beneficial owners, clear business purpose
3
Multiple UBOs / layered— Multiple beneficial owners, some layers, purpose less clear
4
Complex structure— Multiple entities, offshore holdings, hard to identify UBOs
5
Opaque / unresolvable— Cannot identify ultimate beneficial owner. Nominee directors. Circular ownership.

CRA Risk Labels — Composite Score Thresholds

LabelScore RangeRequired Actions
Low1.0 – 2.0Standard CDD. Annual review cycle.
Medium2.0 – 3.0Standard CDD with heightened monitoring. Review on trigger events.
High3.0 – 4.0Enhanced Due Diligence (EDD) required. Senior approval for onboarding. 6-month review cycle.
Unacceptable4.0 – 5.0Do not onboard / exit relationship. SAR consideration. Report to Compliance Officer. Executive notification.
An Unacceptable rating does not automatically generate a SAR — but you must determine whether the suspicious activity threshold is met and make a documented decision either way.

Country Risk Ratings

FATF-aligned jurisdiction risk ratings used across CRA and EWRA

1

Understand the four tiers

Country risk tiers are used directly in CRA Factor 4 (Geographic Risk) and EWRA Geographic factor scoring.

TierLabelCRA ScoreFATF StatusDescription
LRCLow Risk1MemberFATF member with effective AML/CTF framework. Standard monitoring.
MRCMedium Risk2–3Observer / Non-MemberSome AML/CTF weaknesses identified. Elevated vigilance required.
HRCHigh Risk3–4Grey ListSignificant AML/CTF deficiencies. FATF-enhanced monitoring. EDD for customers from HRC.
UHRCUltra-High Risk4–5Black List / SanctionedFATF Black List or heavily sanctioned. May be prohibited. Contact Compliance Officer before dealing.

Risk Score Fields (1–5)

FieldDescription
ML Risk ScoreMoney Laundering risk score for this jurisdiction (1 = low, 5 = extreme)
TF Risk ScoreTerrorist Financing risk score (separate from ML — some low-ML countries are high-TF)
Sanctions RiskLevel of UN/OFAC/DFAT sanctions exposure for this jurisdiction
Corruption ScoreCorruption Perceptions Index proxy — higher score = more corruption risk
2

Keeping ratings current

Update country risk ratings when:

  • FATF publishes its plenary outcomes (February, June, October)
  • DFAT or OFAC adds/removes a sanctions designation
  • A country's AML/CTF framework has a material change (new legislation, major enforcement action)
Australia (AU) and New Zealand (NZ) should always be LRC. If you see them at HRC or UHRC, a data entry error has occurred — correct immediately as this will inflate all domestic CRA scores.

Control Testing

Schedule, perform, and record evidence of control effectiveness

1

Create test templates

Go to Testing → Templates. Create a template per control type/domain. Templates pre-fill the test type, domain, and procedure description when scheduling a new test.

2

Schedule a test

Go to Testing → Schedule Test. Link to a control (using the control ID), assign a tester, set the scheduled date and frequency. Status defaults to Scheduled.

Test Types

TypeDescription
WalkthroughStep-by-step walkthrough of the control with the control owner — verifies the control exists and is understood
Sample ReviewReview a sample of transactions/records to assess whether the control was applied correctly
Re-performanceTester independently performs the control procedure and compares result to control owner's output
ObservationDirectly observe the control being performed in real time
InquiryStructured interviews with staff responsible for the control — lowest evidence strength
Automated Log ReviewReview system-generated logs/exception reports to assess automated control performance
Penetration / TechnicalTechnical testing of system-enforced controls (e.g. transaction limits, screening rules)

Testing Frequencies

FrequencyIntervalTypical use
MonthlyEvery calendar monthHigh-risk manual controls, regulatory-critical processes
QuarterlyEvery 3 monthsPreventative controls for critical risk domains
Semi-AnnualEvery 6 monthsStandard detective and corrective controls
AnnualOnce per yearLow-risk / highly automated controls with strong track record
BiennialEvery 2 yearsLow-risk directive controls (policy reviews, training completions)
Ad-hocTriggered by eventTriggered tests following an incident, finding, or regulatory change

Evidence Requirements by Test Result

ResultMinimum Evidence Required
PassTest workpapers showing procedure followed, sample reviewed, conclusion documented. Reviewer sign-off.
PartialWorkpapers identifying which elements passed and which failed. Action plan for failed elements. Manager review.
FailWorkpapers documenting failure. Root cause analysis. Linked Issue created in the Issues Register. Escalation to Compliance Officer.
Not ApplicableBrief rationale why the test does not apply to this control in this period.
Never mark a test Completed without attaching or linking evidence. AUSTRAC expects to see testing evidence during an examination — an unsubstantiated Pass is as problematic as no testing at all.

Issues & Remediation

Log findings, track status, and demonstrate regulatory follow-through

1

Log an issue

Go to Issues → Log Issue. Every compliance finding — whether from testing, audit, incident, or self-review — should be logged.

Issue Fields Reference

FieldRequiredDescription
TitleYesConcise description of the issue (e.g. 'Transaction Monitoring — Rule X has 14-day alert backlog')
DomainYesControl domain the issue relates to (GOV, CDD, TM, SCR, RPT, etc.)
SeverityYesCritical / High / Medium / Low — determines SLA and escalation path
SourceYesHow the issue was identified: Audit / Control Test / Incident / Self-Identified / Regulator / External Review
OwnerYesPerson responsible for remediation. Must be a named individual, not a team.
Due DateYesTarget remediation date. Apply the SLA table below based on severity.
Control RefNoLink to the specific control in the Controls Library that this issue relates to
DescriptionRec.Detailed description of the issue, including root cause if known
Remediation PlanRec.Specific steps to be taken, by whom, by when

Severity SLA Table

SeverityMax Remediation PeriodEscalationReporting
Critical7 calendar daysCEO / Board immediately. Compliance Officer daily update.Board report within 24 hours. Voluntary disclosure to AUSTRAC if ML/TF risk is implicated.
High30 calendar daysSenior management within 24 hours. Weekly update.Monthly board report. Compliance Officer weekly.
Medium90 calendar daysCompliance Officer within 5 business days.Quarterly compliance report.
Low180 calendar daysIssue owner to manage. Monthly check-in.Annual compliance report. Board risk committee.

Issue Sources — Meaning

SourceDescription
AuditFound during an internal or external audit / AUSTRAC examination
Control TestFound during a scheduled control effectiveness test — link the test ID in the description
IncidentFound following a breach, near-miss, or operational incident
Self-IdentifiedProactively identified by the business without a formal audit/test trigger — viewed most favourably by regulators
RegulatorRaised by AUSTRAC, ASIC, APRA, or another regulator directly
External ReviewFound by an external compliance adviser, law firm, or independent reviewer
2

Track through to closure

Update the status as work progresses. Never skip status steps — each transition should be supported by documented evidence.

Open
→
In Progress
→
Under Review
→
Closed
Accepted Risk is a terminal status that requires: (1) written sign-off from the Board or ARCO, (2) a documented residual risk assessment, (3) a monitoring plan for the accepted risk, and (4) annual review of the acceptance decision.

RG Obligation Mapper

Link regulatory guides to entity obligation registers in bulk

1

Create a regulatory guide record

Click New Guide. Enter: title, regulator, guide code, version, effective date, review date, a document URL (link to official source), and description. Status defaults to Draft.

Supported Regulators

RegulatorFull NameScope
AUSTRACAustralian Transaction Reports and Analysis CentreAML/CTF Act compliance, SMR/TTR reporting, CDD, record keeping
ASICAustralian Securities and Investments CommissionFinancial services licensing, market conduct, financial product disclosure
APRAAustralian Prudential Regulation AuthorityPrudential standards for ADIs, insurers, superannuation
FATFFinancial Action Task ForceInternational AML/CTF standards (40 Recommendations + 9 Special Recommendations)
ISOInternational Organisation for StandardisationISO 31000 risk management, ISO 27001 information security
TreasuryAustralian TreasuryAML/CTF legislative reform, Tranche 2 regulations
OtherAny other regulator or standard bodyState regulators, overseas regulators, industry standards
2

Manage guide status over time

When AUSTRAC releases an updated regulatory guide:

  1. Create a new guide record for the updated version
  2. Mark the old version as Superseded
  3. Update the effective date on the new guide
  4. Re-run bulk mapping from the new guide to update entity obligations

Obligation Library

Master repository of all AML/CTF regulatory obligations

Obligation Categories

CodeCategoryDescription
GOVGovernanceBoard-level oversight, ARCO appointment, AML/CTF program structure, internal audit
CONConduct / Compliance MgmtBreach reporting, compliance monitoring, regulatory liaison, enforceable undertakings
AMLAML/CTF ProgramCore AML/CTF program obligations — Part A (risk-based) and Part B (customer identification)
CDDCustomer Due DiligenceKYC, beneficial ownership, EDD, ongoing due diligence, correspondent banking
CUSCustomer MonitoringOngoing transaction monitoring, customer profile updates, risk re-assessment triggers
RPTReportingSuspicious Matter Reports (SMR), Threshold Transaction Reports (TTR), IFTI, compliance reports

Obligation Data Fields (expanded view)

FieldDescription
Obligation IDUnique identifier (e.g. OB-AML-001). Used to cross-reference with control and RG mapper records.
CategoryGOV / CON / AML / CDD / CUS / RPT
DescriptionPlain-English description of the obligation requirement
Regulatory SourceThe regulation or rule that creates this obligation (e.g. AML/CTF Rules 2007, Rule 4.1.2)
Legislative ReferenceThe specific Act section (e.g. AML/CTF Act 2006, s.36)
Risk CategoryWhich risk type this obligation primarily addresses (ML, TF, Fraud, Sanctions, etc.)
Applicable Entity TypesWhich entity types this obligation applies to — used for instantiation matching
Required LicensesSpecific licenses that trigger this obligation
Linked ControlsControl IDs from the Controls Library that implement this obligation
Policy TemplateSuggested policy language or procedure guidance for implementing this obligation
Default WeightImportance weighting used in obligation completeness scoring (1–5)

Reports & Dashboards

Executive reporting, compliance analytics, and EWRA intelligence

Two dedicated report views aggregate data from every module into actionable compliance intelligence. Neither page requires manual input — all data is drawn live from the platform.

Executive Reports — 5 Tabs

Navigate to Reports → Executive Reports. Switch between tabs using the tab bar at the top of the page.

TabWhat it showsKey metrics
OverviewHigh-level KPIs and cross-module risk summaryTotal entities, active controls, CRA count, EWRA approved, open issues, critical issues, tests completed, pass rate. Pie charts for CRA distribution, Country Risk distribution, Issues by severity. Controls by domain bar chart.
Customer RiskCRA breakdown and concentration analysisRisk label distribution (Low / Medium / High / Unacceptable). Volume by risk tier. Trend over time. High-risk customer count. Average composite score.
Control TestingTest schedule health and pass/fail ratesCompleted vs Overdue vs Scheduled counts. Pass rate gauge. Pass/Fail/Partial breakdown by domain. Trend of test results over time.
IssuesOpen issue register summary and remediation healthIssues by status, by severity, by domain. Average time to close. Overdue issues (past due date). Critical issues requiring immediate attention.
ControlsControls library coverage and ownership metricsControls by domain, by type, by automation level. Unowned controls count. Controls without a testing frequency set.
The Overview tab is designed for Board and senior management reporting. Export the page as PDF from your browser (Ctrl+P → Save as PDF) for monthly compliance reports.

EWRA Dashboard — Risk Intelligence View

Navigate to Reports → EWRA Dashboard. This view provides deep analytics specific to risk assessments.

Chart / PanelDescription
Risk Factor RadarRadar chart showing inherent vs residual scores across all EWRA factors for the selected entity / assessment period. A wide gap between inherent and residual indicates strong control effectiveness.
Assessment Status BarCounts of assessments by status (Draft / In Review / Approved / Archived) across all entities. Used to track EWRA program completion.
Residual Risk DistributionBreakdown of approved assessments by residual risk rating (Low / Medium / High / Critical). The goal is to see the distribution shift left over time.
Factor HeatmapColour-coded matrix of inherent risk scores by factor and entity. Red cells = high priority for control investment.
Recent AssessmentsList of the 10 most recently created or updated EWRA assessments with their ratings and status. Quick access to assessments requiring action.
Control Effectiveness DistributionHow control effectiveness ratings (Strong / Adequate / Weak / Ineffective) are distributed across all assessed factors.
The EWRA Dashboard is best used after all assessments for the current period are in Approved status. Draft and In Review assessments may distort the aggregate metrics.

KPI Definitions

KPICalculationTarget
Test Pass Rate(Completed tests with result = Pass) ÷ (All completed tests) × 100≥ 85% — below 70% is a significant control concern
Open IssuesCount of all issues with status ≠ Closed and ≠ Accepted RiskZero Critical open > 7 days. Minimise High open > 30 days.
EWRA ApprovedCount of assessments with status = ApprovedEvery Active entity should have ≥ 1 Approved EWRA in the current period.
CRA CoverageCount of CRA assessments ÷ total active customers (where known)100% of onboarded customers should have a current CRA.
Overdue TestsCount of test schedules with status = OverdueZero. Any overdue tests should be escalated daily.
Critical Issues (SLA)Count of Critical issues open for > 7 calendar daysZero. Each day past SLA is a regulatory risk.

Domain Code Glossary

All AML/CTF control and issue domains explained

CodeDomain NameDescription
GOVGovernance & ManagementBoard oversight, ARCO role, AML/CTF program accountability, committee structure, management reporting
CDDCustomer Due DiligenceKYC procedures, identity verification, beneficial ownership, EDD, third-party reliance, PEP identification
SCRSanctions ScreeningCustomer and transaction screening against UN, OFAC, DFAT, and internal watchlists. Alert management and escalation.
TMTransaction MonitoringRule-based and behavioural monitoring of transactions. Alert review, case management, and escalation to SMR.
RPTRegulatory ReportingSMR filing, TTR reporting, IFTI submission. Timeliness, completeness, and accuracy of mandatory reports.
RARisk AssessmentEnterprise-wide and customer-level risk assessment processes. Methodology, calibration, and periodic review.
TECHTechnology & SystemsAML/CTF system configuration, data quality, system access controls, vendor management, change management.
FRDFraud PreventionInternal and external fraud controls. Fraud detection, investigation, and recovery procedures.
CYBCybersecurityInformation security controls relevant to AML/CTF data protection. Access management, incident response, data classification.
PRVPrivacy & Data ProtectionPrivacy Act compliance for CDD data. Data retention, destruction, access controls, and privacy impact assessments.
TRNTraining & AwarenessAML/CTF training program for all staff. Role-based training, completion tracking, refresher frequency, new joiner onboarding.
RKRecord KeepingRetention of CDD records (7 years), transaction records (7 years), SMR/TTR copies, and audit trails.
OUTOutsourcing & Third PartyDue diligence on outsourced AML/CTF functions. Contract controls, monitoring, and exit planning.
COMCompliance ManagementInternal compliance monitoring, breach management, regulatory liaison, enforceable undertaking management.
FCFinancial Crime IntelligenceTypologies, red flags, financial crime intelligence, AUSTRAC feedback, industry information sharing.
FRFraud RiskFraud risk assessment, fraud typologies, fraud controls independent of financial crime obligations.
CMChange ManagementAssessment of AML/CTF impact of new products, new channels, new markets, system changes, and M&A activity.

Status Workflows

Allowed status transitions for each module

Entity Profile

Draft
→
Active
→
Archived

Draft → Active: Obligations can be instantiated. Active → Archived: Entity is no longer operating. Cannot go from Archived back to Active.

EWRA Assessment

Draft
→
In Review
→
Approved
→
Archived

Draft: editable by assessor. In Review: submitted to Compliance Officer / ARCO for review. Approved: read-only, locked. Archived: superseded by newer assessment.

Issue / Remediation

Open
→
In Progress
→
Under Review
→
Closed
Open / In Progress
→
Accepted Risk

Accepted Risk requires Board/senior sign-off and cannot be moved back to Open without a new issue being logged.

Control Test Schedule

Scheduled
→
In Progress
→
Completed
Scheduled → past due
→
Overdue
Any status
→
Cancelled

Overdue is set automatically by the system when a Scheduled test passes its scheduled date. Cancelled should be used when a test is formally deferred or removed from scope.

Obligation Status

Active
→
Pending
→
Exempt
→
Not Applicable

Scoring Rubrics

Quick-reference scoring guides for EWRA and CRA

EWRA — Control Effectiveness × Inherent Risk = Residual

Inherent Risk →1 (Neg.)2 (Low)3 (Med.)4 (High)5 (V.High)
Strong (×0.25)0.250.500.751.001.25
Adequate (×0.50)0.501.001.502.002.50
Weak (×0.75)0.751.502.253.003.75
Ineffective (×1.00)1.002.003.004.005.00

Residual ≤ 1.5 = Low · 1.5–2.5 = Medium · 2.5–3.5 = High · > 3.5 = Critical

CRA — Composite Score → Risk Label

Avg. Factor ScoreRisk LabelCDD LevelReview Frequency
1.0 – 2.0LowSimplified CDD acceptable if low-risk product threshold metAnnual or on trigger event
2.0 – 3.0MediumStandard CDD requiredAnnual with trigger-event refresh
3.0 – 4.0HighEnhanced Due Diligence (EDD) required. Senior approval.Every 6 months
4.0 – 5.0UnacceptableDo not onboard / exit. EDD + SAR consideration mandatory.Immediate action required

Compliance Calendar

Key regulatory dates and recurring obligations

Use this calendar as a guide for scheduling EWRA reviews, country risk updates, and platform maintenance. Add these as recurring tasks in your organisation's project management system and link them to corresponding Issues in dooit.ai.

Annual Recurring Schedule

MonthActivityModulePriority
JanuaryPlan annual EWRA cycle — create draft assessments for all Active entitiesEWRAHigh
FebruaryFATF Plenary outcomes published — review Grey/Black list changesCountry RiskCritical
FebruaryUpdate Country Risk ratings based on FATF plenaryCountry RiskCritical
MarchQ1 control testing completion review — chase overdue testsTestingHigh
AprilEWRA completion deadline — all Annual assessments should be In Review or ApprovedEWRAHigh
JuneFATF Plenary outcomes published — review Grey/Black list changesCountry RiskCritical
JuneMid-year CRA refresh for High and Unacceptable rated customersCRAHigh
JuneAUSTRAC compliance report period (if applicable to entity type)ReportsHigh
JulyAnnual staff AML/CTF training completion checkControls (TRN)Medium
SeptemberQ3 control testing review — issues from Q1/Q2 tests should be closedTesting / IssuesHigh
OctoberFATF Plenary outcomes published — review Grey/Black list changesCountry RiskCritical
OctoberUpdate Country Risk ratings based on FATF plenaryCountry RiskCritical
NovemberAnnual EWRA sign-off deadline — Board approval of current year EWRAEWRACritical
DecemberYear-end issue register review — close or formally accept remaining issuesIssuesHigh
DecemberRegulatory calendar planning for next year — schedule all tests and EWRAsAll modulesMedium

AUSTRAC Reporting Deadlines

Report TypeTriggerDeadlineWhere to track
SMR — Suspicious Matter ReportSuspicion formed of ML/TF, or other serious offenceAs soon as practicable (no defined limit, but prompt). Best practice: within 3 business days.Log as a Critical issue in Issues Register. AUSTRAC AUSTRAC Online.
TTR — Threshold Transaction ReportCash transaction ≥ AUD $10,000Within 10 business days of the transactionTTR count should be visible in Reports. Submit via AUSTRAC Online.
IFTI — International Funds TransferElectronic instruction to/from outside AustraliaWithin 10 business daysIFTI count tracked in Reports. Submit via AUSTRAC Online.
AML/CTF Annual Compliance ReportRequired for all reporting entities31 March each year (for previous calendar year)Create a Triggered EWRA as the basis. Log deadline as a High issue if overdue.
Correspondent Banking Due DiligenceBefore establishing a correspondent relationshipPrior to commencement of relationshipLog as a CDD obligation in the entity's obligation register.

Trigger-Event Checklist

The following events should trigger immediate platform actions:

EventActions Required
New product or service launchTriggered EWRA · Update entity profile (designated services) · Re-instantiate obligations · Review TM rules
New jurisdiction / market entryTriggered EWRA · Update entity profile (jurisdictions) · Check country risk tier · Update CRA criteria
Material change in customer mixTriggered EWRA · Bulk CRA re-assessment for affected segment
Ownership / management changeTriggered EWRA · Board notification · PEP screening of new controllers
AUSTRAC regulatory findingLog as Critical issue · Triggered EWRA · Consider voluntary disclosure · Escalate to ARCO immediately
FATF Grey/Black list changeUpdate Country Risk · Identify affected customers · EDD review for HRC→UHRC customers · CRA re-assessment
UN / OFAC / DFAT sanctions designationImmediate sanctions screening · Freeze implicated accounts · SMR consideration · Board notification
Significant IT system changeTECH domain control test · EWRA technology factor re-score · Access control review
Key staff departure (ARCO / CCO)Board notification · Interim ARCO appointment · AML/CTF program review · Triggered EWRA
External audit / AUSTRAC examinationIssue register review · EWRA review · Testing evidence collation · Ensure all documentation is current
Pin the FATF calendar (fatf-gafi.org) to your compliance calendar tool. FATF plenary dates are announced 6–12 months in advance — schedule your Country Risk review in dooit.ai as a recurring test in the Testing module.

Sidebar

ActionHow to do it
Collapse sidebar to icon railClick the ← collapse icon (top right of sidebar) to collapse to a compact icon-only rail — useful on smaller screens.
Expand sidebarClick the → expand icon at the bottom of the collapsed rail, or hover over any icon to see the label tooltip.
Mobile navigationOn mobile/tablet, tap the ≡ hamburger icon in the top bar to open the sidebar as a full-screen drawer. Tap the backdrop or × to close.
Grouped nav itemsItems like 'Entity Setup' and 'Testing' have sub-items. Click the group label to expand/collapse the sub-menu. The active sub-item stays highlighted.

Table Controls (DataTable)

ControlLocationHow it works
Column resizeDrag the right edge of any column headerDrag left/right to resize. Double-click the resize handle to reset to default width.
Column reorderDrag a column header left or rightGrab the column header (not the resize handle) and drag to a new position. Pinned columns (leftmost, rightmost) cannot be reordered.
Page sizeDropdown at the bottom-left of the tableChoose 25 / 50 / 100 rows per page. In server-side mode, changing page size triggers a new API call.
PaginationPrevious / Next buttons and page number display at bottomIn server-side mode all navigation calls the API. In client-side mode, pagination is computed locally.
Search (toolbar)Search box in the table toolbarIn server-side mode, submitting the search form triggers an API call. Press Enter or click Go.
Filter dropdownsDropdowns in the table toolbarChanging a dropdown immediately re-fetches data (server-side) or filters the local data (client-side).
Domain / status pillsAbove the table on list pagesClick a pill to filter by that domain or status. Click again (or 'All') to clear. Works in combination with toolbar filters.
Clear all filters'Clear all' button in the toolbarAppears when any filter or search is active. Resets all filters and search in one click.

Drawer (Edit Panels)

ActionHow to do it
Open edit drawerClick 'Edit' or the pencil icon on any detail page
Scroll within drawerThe drawer body scrolls independently — the Save / Cancel footer is always visible at the bottom regardless of content length.
Close without savingClick the × in the drawer header, or click the backdrop behind the drawer.
SaveClick the Save button in the drawer footer. Validation errors appear inline below each field.

Breadcrumbs & Back Navigation

Most detail pages show breadcrumbs at the top (e.g. Entity Profiles → ACME Financial → Obligations). Click any breadcrumb to navigate up the hierarchy without losing your place in the list (page number and filters are stored in URL query params on some pages).

Toast Notifications

Toast TypeMeaning
Green (Success)Action completed successfully — record saved, obligation instantiated, etc.
Red (Error)Action failed — check the message for details. Common causes: validation error, network error, session expiry.
Amber (Warning)Action completed with caveats — e.g. 0 new obligations created, some items skipped.
If you get a persistent red toast on login or page load, your session may have expired. Refresh the page — you'll be redirected to the login screen. Sessions last for the duration configured in the API's JWT settings.

Best Practices

Evidence-based compliance tips from the dooit.ai methodology

Keep entity profiles current at all times

Update licenses, services, and jurisdictions immediately when they change. Stale profiles generate incorrect obligation sets, leading to gaps that regulators may treat as a failure of governance.

Test controls on schedule — document everything

Testing without evidence is as bad as no testing. Record the procedure followed, the sample reviewed, the conclusion, and the reviewer's sign-off. A Pass with no evidence will not satisfy an AUSTRAC examination.

Log every finding — even minor ones

Self-identified issues handled promptly are viewed very favourably by AUSTRAC. A visible, active issue register demonstrates a culture of compliance. Regulators distinguish between 'finds nothing' and 'finds, logs, and fixes'.

Fail → Issue is a mandatory link

Every failed control test must produce a linked issue in the Issues Register. The connection between testing and remediation is the core of a risk-based AML/CTF program.

Update country risk after every FATF plenary

FATF plenary outcomes (Feb, Jun, Oct) can add or remove countries from the Grey and Black lists. Update ratings within 2 weeks. Countries moving from HRC → MRC need CRA re-assessments for affected customers.

Triggered EWRA is a regulatory expectation

Annual EWRA is the minimum. Material changes — new product, new channel, new jurisdiction, significant customer mix shift, regulatory findings — require a triggered EWRA. Document the trigger in the assessment name.

'Accepted Risk' requires Board sign-off and annual review

Accepted Risk is not a way to close hard issues. Regulators look at accepted risk decisions carefully. Each acceptance needs: documented rationale, residual risk estimate, monitoring plan, and annual re-assessment.

CRA is point-in-time — define your trigger events

A Low CRA today does not mean Low forever. Define and document the trigger events that mandate a CRA refresh: new BO, adverse media, new business activity, threshold transaction, PEP designation.

Automated controls are not zero-maintenance

Automated controls still require periodic review: rule calibration, alert volume analysis, exception rate monitoring, system access controls, and vendor SLA checks. Include them in your testing schedule.

Don't instantiate obligations without reviewing matches

After instantiation, review the generated list. Some obligations may be instantiated because of a broad 'All Entities' match but may not be relevant to your specific business. Mark inapplicable ones as 'Not Applicable' with a documented reason.

FAQ & Troubleshooting

Answers to the most common platform questions

Glossary

Key terms used throughout the platform

AML/CTF

Anti-Money Laundering and Counter-Terrorism Financing. The regulatory framework governing obligations on reporting entities in Australia under the AML/CTF Act 2006.

ARCO

AML/CTF Reporting and Compliance Officer. The designated senior individual responsible for an entity's AML/CTF compliance program. Must be appointed in the Part A program.

AUSTRAC

Australian Transaction Reports and Analysis Centre. Australia's financial intelligence and AML/CTF regulator. Administers the AML/CTF Act 2006.

CDD

Customer Due Diligence. The process of identifying, verifying, and understanding a customer, including their beneficial owners, source of funds, and purpose of relationship.

CRA

Customer Risk Assessment. The process of scoring an individual customer's ML/TF risk using standardised factors to determine the appropriate level of due diligence.

DCE

Digital Currency Exchange. A provider of digital currency exchange services — a designated service under the AML/CTF Act.

EDD

Enhanced Due Diligence. Additional CDD measures applied to higher-risk customers, including obtaining additional information and requiring senior approval for the relationship.

EWRA

Enterprise-Wide Risk Assessment. A comprehensive assessment of the ML/TF risks faced by a reporting entity across all its customers, products, services, channels, and jurisdictions. Required by AUSTRAC Rule 4.1.2.

FATF

Financial Action Task Force. Intergovernmental body that sets international AML/CTF standards (the 40 Recommendations). Produces Grey List (Jurisdictions Under Increased Monitoring) and Black List (High-Risk Jurisdictions Subject to a Call for Action).

IFTI

International Funds Transfer Instruction. Report required when an entity sends or receives an electronic funds transfer instruction from/to outside Australia above threshold.

ISO 31000

International standard for risk management principles and guidelines. Used as the methodological basis for the EWRA module.

KYC

Know Your Customer. The process of verifying customer identity and understanding the nature of the customer relationship. A subset of CDD.

ML / TF

Money Laundering / Terrorist Financing. The two primary financial crime risks regulated by AML/CTF laws.

OFAC

Office of Foreign Assets Control (US). Administers US economic sanctions programs. OFAC designations are internationally relevant for Australian entities with US-connected activities.

PEP

Politically Exposed Person. An individual who holds or has held a prominent public function, or is an immediate family member or close associate of such a person. PEPs require EDD under FATF Recommendation 12.

REM

Remittance Dealer. A provider of designated remittance services — must be registered with AUSTRAC on the Remittance Sector Register.

Residual Risk

The level of risk remaining after the application of controls. Calculated as Inherent Risk × (1 − Control Effectiveness). The goal of a risk management program is to reduce residual risk to an acceptable level.

SAR / SMR

Suspicious Activity Report (international term) / Suspicious Matter Report (Australian term). A mandatory report to AUSTRAC when an entity forms a suspicion that a customer or transaction is linked to ML/TF or other serious offences.

TTR

Threshold Transaction Report. Required when a cash transaction (or series of related transactions) meets or exceeds AUD $10,000 in value.

UBO / UBC

Ultimate Beneficial Owner / Ultimate Beneficial Controller. The natural person(s) who ultimately own or control a legal entity. CDD must identify and verify UBOs above 25% ownership threshold.

DVCR

Digital Identity Verification and Customer Records. An approved digital verification service used in lieu of face-to-face identity verification. Must meet AUSTRAC's prescribed requirements for reliable and independent sources.

Inherent Risk

The level of risk exposure before any controls or mitigating measures are applied. In the EWRA, inherent risk is scored 1–5 per risk factor. High inherent risk is not necessarily a problem — it is what controls are for.

Residual Risk

The remaining risk level after applying controls. Calculated as Inherent Risk × Control Effectiveness multiplier. The goal of the AML/CTF program is to reduce residual risk to an acceptable (Low/Medium) level across all factors.

Control Effectiveness

A qualitative rating (Strong / Adequate / Weak / Ineffective) of how well controls mitigate a specific risk factor. Determined through testing evidence, not assumption. Strong controls with no testing evidence should be rated Adequate or lower.

Part A Program

The risk-based part of an AML/CTF program, required for all reporting entities. Must include: ML/TF risk assessment (EWRA), customer due diligence procedures, transaction monitoring, and reporting obligations.

Part B Program

The customer identification part of an AML/CTF program. Sets out how the entity will identify and verify customers, including individuals, companies, trusts, and beneficial owners. Must be risk-based.

Reporting Entity

An organisation required to comply with the AML/CTF Act 2006 because it provides a designated service. All users of this platform should be reporting entities or their compliance advisers.

Designated Service

A service listed in Table 1 or Table 2 of the AML/CTF Act 2006 that triggers AML/CTF obligations. Examples: providing a loan, exchanging currency, sending a remittance, providing a digital currency exchange service.

FATF Recommendation 1

The core FATF standard requiring countries and entities to identify, assess, and understand ML/TF risks and apply risk-based measures. The EWRA module is the primary tool for meeting R.1 at the entity level.

Risk-Based Approach (RBA)

Applying AML/CTF measures in proportion to the assessed ML/TF risk — more controls for higher-risk customers, channels, and products; simplified controls for lower-risk. The RBA is mandated by FATF and AUSTRAC. The EWRA and CRA modules implement the RBA.

Correspondent Banking

A relationship where one bank (correspondent) provides services to another bank (respondent). Carries elevated ML/TF risk due to the layered nature of the relationship. Requires enhanced CDD under FATF R.13 and AML/CTF Rules.

Sanctions

Legal measures imposed by governments or international bodies (UN, OFAC, DFAT) restricting dealings with specific persons, organisations, or countries. Transacting with a sanctioned party is typically prohibited and a criminal offence. Sanctions screening is a mandatory control.

Typology

A documented pattern or method used to launder money or finance terrorism. Understanding typologies helps calibrate transaction monitoring rules and inform risk assessments. AUSTRAC, FATF, and ACAMS publish typology reports regularly.

Structuring

The practice of breaking up large transactions into smaller amounts to avoid reporting thresholds (TTR). Structuring is illegal under the AML/CTF Act. Transaction monitoring rules should detect structuring patterns.

EDD

Enhanced Due Diligence. Additional CDD measures applied to higher-risk customers (CRA = High or Unacceptable, PEPs, correspondent banks, complex structures). Must include: senior management approval, enhanced source of funds/wealth checks, more frequent review, closer transaction monitoring.

AML/CTF Rules

The subordinate legislation made under the AML/CTF Act 2006 (formally the Anti-Money Laundering and Counter-Terrorism Financing Rules Instrument 2007). Provides detailed requirements supplementing the Act. AUSTRAC amends the Rules periodically — subscribe to AUSTRAC regulatory updates.

Voluntary Disclosure

Proactively reporting a compliance breach or non-compliance to AUSTRAC before it is discovered by the regulator. Voluntary disclosures are treated as a significant mitigating factor in AUSTRAC's enforcement decisions. Critical and High issues with regulatory implications should be assessed for voluntary disclosure.

ACAMS

Association of Certified Anti-Money Laundering Specialists. The leading international professional body for AML/CTF practitioners. Publishes typologies, best-practice guides, and the CAMS certification program.

Tranche 2

Proposed reforms to the AML/CTF Act extending obligations to additional high-risk sectors not currently regulated under Tranche 1, including: real estate agents, lawyers, accountants, and trust and company service providers. Tranche 2 legislation is currently before the Australian Parliament.

dooit.ai · EWRA / GRC Platform · v1.0

Built for AUSTRAC · FATF · ISO 31000 compliance