dooit.ai — Platform Overview
Enterprise-Wide Risk Assessment & GRC platform for AML/CTF compliance
dooit.ai is an end-to-end AML/CTF compliance management platform built to meet AUSTRAC, FATF, and ISO 31000 requirements. It covers the full compliance lifecycle — entity setup, obligation mapping, enterprise-wide risk assessment, customer risk scoring, control testing, issue remediation, and executive reporting.
Entity Setup
Register regulated entities and instantiate obligations
Controls Library
Browse and own 200+ AML/CTF controls
EWRA Assessment
Run enterprise-wide risk assessments
Customer Risk (CRA)
Score individual customer ML/TF risk
Control Testing
Schedule and record test results
Issues
Log findings and manage remediation
Country Risk
FATF-aligned jurisdiction ratings
RG Mapper
Map regulatory guides to obligations
Obligation Library
Browse all regulatory obligations
How modules connect
Entity is the anchor. All other modules link back to one or more entity profiles:
- Obligation Library → Entity Obligations: Instantiation copies matching library obligations into the entity's obligation register.
- Controls Library → EWRA: Control effectiveness scores inform residual risk calculations in the EWRA.
- Country Risk → CRA: A customer's country geography score is derived from the country risk table.
- Control Testing → Issues: Failed tests should produce linked issues for remediation tracking.
- RG Mapper → Obligation Library → Entity: Regulatory guides bundle obligations that can be bulk-mapped to entity profiles.
- All modules → Reports: The Executive Dashboard and EWRA Dashboard aggregate data across all modules.
Quick-Start Flow
Recommended sequence for a new deployment
Seed reference data
SetupRun seed scripts: country risk (seedCountryRisk.js), obligation library (seedObligations.js), controls library (seedControls.js).
Create Entity Profile
SetupEntity Setup → New Entity. Fill entity name, type, licenses, designated services, and jurisdictions. Save as Draft.
Instantiate Obligations
SetupEntity detail page → 'Instantiate Obligations'. The system auto-matches library obligations to the entity. Review and adjust statuses.
Assign Control Owners
SetupControls → Assign Owners. Map an owner and testing frequency to each applicable control before scheduling tests.
Run EWRA Assessment
AssessEWRA → New Assessment. Score each risk factor (inherent risk 1–5, control effectiveness) and approve the assessment.
Score Customer Risk (CRA)
AssessCustomer Risk → New Assessment. Complete the 7-factor scoring form for each customer to generate a risk label.
Schedule Control Tests
OperateTesting → Schedule Test (or use templates). Assign testers and set scheduled dates. Record results when tests are performed.
Log & Resolve Issues
OperateIssues → Log Issue for any compliance finding. Track status through to Closed. Fail test results must produce an issue.
Review Reports
ReviewReports → Executive Dashboard. Review open issues, pass rates, residual risk trends, and country risk exposure.
Entity Setup
Register and configure regulated entities and their obligation registers
Create a new entity profile
Navigate to Entity Setup → New Entity.
Set the status to Draft while completing setup, then switch to Active when ready for obligations to be instantiated.
Entity Profile — Field Reference
| Field | Required | Description |
|---|---|---|
| Entity Name | Yes | Full legal name of the regulated entity. Used across all reports and linked assessments. |
| Entity Type | Yes | Select from master list (e.g. AFSL Holder, REM — Remittance, Digital Currency Exchange, ADFS). Determines which obligations are matched during instantiation. |
| Category | Auto | Derived from Entity Type (e.g. Tranche 1, Tranche 2). Used for FATF classification and obligation matching. |
| Licenses | Rec. | Multi-select from LicenseType master (AFSL, ACL, DCE, REM, etc.). Influences which licensed-product obligations are instantiated. |
| Designated Services | Rec. | Services the entity provides (e.g. Provide a designated remittance service, Exchange digital currency). Drives applicable AML/CTF obligations. |
| Jurisdictions | Rec. | Countries where the entity operates. Used for EWRA geography scoring and cross-border obligation assessment. |
| Status | Yes | Draft → Active → Archived. Only Active entities can receive EWRA assessments. Archived entities are read-only. |
| ABN / ARBN | No | Australian Business Number or Company Number for identification purposes. |
| AML/CTF Programme Start Date | No | Date the entity's AML/CTF program was first established. Useful for audit trail. |
| Notes | No | Internal compliance notes visible only to users of this platform. |
Entity Types Reference
| Code / Name | Tranche | Description |
|---|---|---|
| AFSL Holder | Tranche 1 | Australian Financial Services Licence holder providing designated financial services. |
| ADI | Tranche 1 | Authorised Deposit-taking Institution (banks, credit unions, building societies). |
| REM | Tranche 1 | Remittance dealer or registrant — provides designated remittance services. |
| DCE | Tranche 1 | Digital Currency Exchange — buys/sells digital currency for fiat on behalf of customers. |
| ADFS | Tranche 1 | Provider of a designated alternative remittance or financial service. |
| Bullion Dealer | Tranche 1 | Dealer in precious metals or stones above threshold. |
| Gambling Service | Tranche 2 (proposed) | Casinos, bookmakers, sports wagering providers subject to AML/CTF obligations. |
| Real Estate Agency | Tranche 2 (proposed) | Real estate agents dealing with high-value property transactions. |
| Accounting / Legal | Tranche 2 (proposed) | Professional services firms in scope of proposed Tranche 2 reforms. |
Instantiate obligations
On the entity detail page click "Instantiate Obligations". The system queries the Obligation Library and filters by:
- Entity Type name — matches
applicableEntityTypesexactly or as "All Entities" - Entity Category — regex match against
applicableEntityTypes(e.g. "Tranche 1") - Licenses — matches obligations with
applicableLicensescontaining any of the entity's licenses
Obligations already instantiated are skipped (no duplicates). The response shows created and skipped counts.
Manage the obligation register
Go to the entity's Obligations tab. Inline-edit each obligation's status and test result directly in the table.
Obligation Status Values
| Status | Meaning | When to use |
|---|---|---|
| Active | Obligation applies and is being managed | Default for all instantiated obligations |
| Pending | Obligation applies but implementation is not yet complete | Use during onboarding or when a new regulation comes into effect |
| Exempt | Formally exempted — e.g. via AUSTRAC class order or internal waiver | Requires documented justification. Attach the exemption reference in the notes field. |
| Not Applicable | Obligation does not apply to this entity's activities | Use sparingly. Document why in the obligation notes. |
Obligation Test Result Values
| Result | Meaning |
|---|---|
| Pass | The obligation was tested and found to be fully met |
| Fail | The obligation was tested and found to be not met. Must generate an Issue. |
| Partial | The obligation is partially met — some elements pass, others need remediation |
| Not Tested | Default. The obligation has not yet been tested in this period |
applicableEntityTypes / applicableLicenses values in the Obligation Library seed data. Check for case sensitivity and spacing.Controls Library
Browse, filter, and assign ownership across 200+ AML/CTF controls
Browse and filter controls
Go to Controls Library. Use domain pills (GOV, CDD, SCR…) to filter by domain. Use the toolbar dropdowns to narrow by Control Type, Automation Level, and Risk Level.
Assign control owners
Go to Controls → Assign Owners. The bulk assignment table lets you set Owner (free text or user lookup) and Testing Frequency for multiple controls in one save. Ownership is a prerequisite for scheduling tests.
View a control detail
Click View → on any row. The detail page shows: full description, FATF Recommendations, linked obligation IDs, control type, automation level, and edit history.
Control Types
| Type | Description | Example |
|---|---|---|
| Preventative | Stops a risk event from occurring | Transaction limit rules that block high-risk transfers above threshold |
| Detective | Identifies a risk event after it occurs | Transaction monitoring alerts, screening hits, audit log reviews |
| Corrective | Fixes the impact of a risk event | Account remediation process, SAR filing workflow, incident response |
| Directive | Provides instruction or guidance to prevent errors | AML/CTF policy manual, staff procedures, training requirements |
| Compensating | Fills a gap where a primary control is absent or weak | Enhanced manual review compensating for a missing automated screen |
Automation Levels
| Level | Description | Testing Priority |
|---|---|---|
| Manual | Performed entirely by staff — no system assistance | Highest — human error risk |
| Semi-Automated | Partially automated; requires human review/decision at some step | High — validate both the system and human components |
| Automated | Fully system-driven with no manual intervention for routine operation | Medium — focus on exception handling, alert calibration, system uptime |
EWRA Assessment
Enterprise-Wide Risk Assessment — ISO 31000 + FATF methodology
Create a new assessment
Go to EWRA → New Assessment.
Select: Entity Profile, Assessment Type, and the Period (start year / end year). Name the assessment descriptively — e.g. "ACME Financial — Annual EWRA 2025".
Assessment Types
| Type | When to use |
|---|---|
| Annual | Standard yearly EWRA as required by AUSTRAC Rule 4.1.2 |
| Periodic | Half-yearly or quarterly review cycle for higher-risk entities |
| Triggered | Unscheduled — triggered by a material event (new product, merger, regulatory finding, FATF list change) |
| Initial | First-ever assessment for a newly registered entity |
Score each risk factor
For each factor, provide two inputs:
- Inherent Risk Score (1–5) — the raw risk level before any controls
- Control Effectiveness — how well the controls mitigate that inherent risk
The system calculates Residual Risk = Inherent Risk × Control Effectiveness multiplier.
EWRA Risk Factors
| Factor | What to score | Key considerations |
|---|---|---|
| Customer Risk | Overall ML/TF risk of the customer base | Mix of PEPs, high-risk occupations, complex structures, cash users |
| Product & Service Risk | Inherent risk in the products/services offered | Cash intensity, anonymity features, cross-border capability |
| Delivery Channel Risk | Risk introduced by how services are delivered | Non-face-to-face, agent networks, digital-only, cryptocurrency |
| Geographic Risk | Risk from the jurisdictions of operations and customers | FATF Grey/Black list countries, sanctioned jurisdictions, offshore hubs |
| Transaction Risk | Patterns of transactional risk in the business | High-value, high-frequency, structured/round transactions |
| Control Environment | Overall maturity and coverage of the AML/CTF control framework | Policy completeness, training frequency, testing regularity |
| Regulatory History | History of regulatory findings, enforcement, or self-reported incidents | Previous AUSTRAC findings, audits, enforceable undertakings |
Inherent Risk Scoring Guide (1–5)
Control Effectiveness Ratings
| Rating | Multiplier | Description | Criteria |
|---|---|---|---|
| Strong | 0.25× | Controls are robust and consistently applied | Tested annually or more, no material exceptions, documented procedures, trained staff |
| Adequate | 0.50× | Controls generally work; minor gaps exist | Tested, mostly compliant, occasional exceptions remediated within SLA |
| Weak | 0.75× | Controls exist but are inconsistently applied | Rarely tested, recurring exceptions, gaps in coverage or documentation |
| Ineffective | 1.00× | Controls are absent, untested, or known to be failing | No testing evidence, known failures, no documented procedures |
Residual Risk Ratings
| Rating | Residual Score Range | Required Action |
|---|---|---|
| Low | 0 – 1.5 | Standard monitoring. Annual review cycle. |
| Medium | 1.5 – 2.5 | Heightened monitoring. Semi-annual review. Board reporting. |
| High | 2.5 – 3.5 | Enhanced monitoring. Quarterly review. Senior management escalation. Consider voluntary disclosure to AUSTRAC. |
| Critical | 3.5 – 5.0 | Immediate action. Executive escalation. Potential SAR obligation. Consider proactive contact with AUSTRAC. |
Approve and manage the lifecycle
Move the assessment through: Draft → In Review → Approved.
Approved assessments are read-only — use Archived when superseded by a newer assessment.
Customer Risk Assessment (CRA)
AUSTRAC-aligned 7-factor individual customer scoring model
Create a new CRA
Go to Customer Risk → New Assessment.
Enter: customer name, customer type (Individual / Company / Trust / Partnership / Other), and country of residence/operation.
Score the 7 risk factors
Each factor is scored 1–5. The composite score is a weighted average that maps to a risk label.
CRA Factor Scoring Reference
Factor 1 — Customer Type
Factor 2 — Business / Occupation Nature
Factor 3 — Transaction Volume & Value
Factor 4 — Geographic Risk
Factor 5 — PEP / Sanctions / Adverse Media
Factor 6 — Delivery Channel
Factor 7 — Relationship Complexity
CRA Risk Labels — Composite Score Thresholds
| Label | Score Range | Required Actions |
|---|---|---|
| Low | 1.0 – 2.0 | Standard CDD. Annual review cycle. |
| Medium | 2.0 – 3.0 | Standard CDD with heightened monitoring. Review on trigger events. |
| High | 3.0 – 4.0 | Enhanced Due Diligence (EDD) required. Senior approval for onboarding. 6-month review cycle. |
| Unacceptable | 4.0 – 5.0 | Do not onboard / exit relationship. SAR consideration. Report to Compliance Officer. Executive notification. |
Country Risk Ratings
FATF-aligned jurisdiction risk ratings used across CRA and EWRA
Understand the four tiers
Country risk tiers are used directly in CRA Factor 4 (Geographic Risk) and EWRA Geographic factor scoring.
| Tier | Label | CRA Score | FATF Status | Description |
|---|---|---|---|---|
| LRC | Low Risk | 1 | Member | FATF member with effective AML/CTF framework. Standard monitoring. |
| MRC | Medium Risk | 2–3 | Observer / Non-Member | Some AML/CTF weaknesses identified. Elevated vigilance required. |
| HRC | High Risk | 3–4 | Grey List | Significant AML/CTF deficiencies. FATF-enhanced monitoring. EDD for customers from HRC. |
| UHRC | Ultra-High Risk | 4–5 | Black List / Sanctioned | FATF Black List or heavily sanctioned. May be prohibited. Contact Compliance Officer before dealing. |
Risk Score Fields (1–5)
| Field | Description |
|---|---|
| ML Risk Score | Money Laundering risk score for this jurisdiction (1 = low, 5 = extreme) |
| TF Risk Score | Terrorist Financing risk score (separate from ML — some low-ML countries are high-TF) |
| Sanctions Risk | Level of UN/OFAC/DFAT sanctions exposure for this jurisdiction |
| Corruption Score | Corruption Perceptions Index proxy — higher score = more corruption risk |
Keeping ratings current
Update country risk ratings when:
- FATF publishes its plenary outcomes (February, June, October)
- DFAT or OFAC adds/removes a sanctions designation
- A country's AML/CTF framework has a material change (new legislation, major enforcement action)
Control Testing
Schedule, perform, and record evidence of control effectiveness
Create test templates
Go to Testing → Templates. Create a template per control type/domain. Templates pre-fill the test type, domain, and procedure description when scheduling a new test.
Schedule a test
Go to Testing → Schedule Test. Link to a control (using the control ID), assign a tester, set the scheduled date and frequency. Status defaults to Scheduled.
Test Types
| Type | Description |
|---|---|
| Walkthrough | Step-by-step walkthrough of the control with the control owner — verifies the control exists and is understood |
| Sample Review | Review a sample of transactions/records to assess whether the control was applied correctly |
| Re-performance | Tester independently performs the control procedure and compares result to control owner's output |
| Observation | Directly observe the control being performed in real time |
| Inquiry | Structured interviews with staff responsible for the control — lowest evidence strength |
| Automated Log Review | Review system-generated logs/exception reports to assess automated control performance |
| Penetration / Technical | Technical testing of system-enforced controls (e.g. transaction limits, screening rules) |
Testing Frequencies
| Frequency | Interval | Typical use |
|---|---|---|
| Monthly | Every calendar month | High-risk manual controls, regulatory-critical processes |
| Quarterly | Every 3 months | Preventative controls for critical risk domains |
| Semi-Annual | Every 6 months | Standard detective and corrective controls |
| Annual | Once per year | Low-risk / highly automated controls with strong track record |
| Biennial | Every 2 years | Low-risk directive controls (policy reviews, training completions) |
| Ad-hoc | Triggered by event | Triggered tests following an incident, finding, or regulatory change |
Evidence Requirements by Test Result
| Result | Minimum Evidence Required |
|---|---|
| Pass | Test workpapers showing procedure followed, sample reviewed, conclusion documented. Reviewer sign-off. |
| Partial | Workpapers identifying which elements passed and which failed. Action plan for failed elements. Manager review. |
| Fail | Workpapers documenting failure. Root cause analysis. Linked Issue created in the Issues Register. Escalation to Compliance Officer. |
| Not Applicable | Brief rationale why the test does not apply to this control in this period. |
Issues & Remediation
Log findings, track status, and demonstrate regulatory follow-through
Log an issue
Go to Issues → Log Issue. Every compliance finding — whether from testing, audit, incident, or self-review — should be logged.
Issue Fields Reference
| Field | Required | Description |
|---|---|---|
| Title | Yes | Concise description of the issue (e.g. 'Transaction Monitoring — Rule X has 14-day alert backlog') |
| Domain | Yes | Control domain the issue relates to (GOV, CDD, TM, SCR, RPT, etc.) |
| Severity | Yes | Critical / High / Medium / Low — determines SLA and escalation path |
| Source | Yes | How the issue was identified: Audit / Control Test / Incident / Self-Identified / Regulator / External Review |
| Owner | Yes | Person responsible for remediation. Must be a named individual, not a team. |
| Due Date | Yes | Target remediation date. Apply the SLA table below based on severity. |
| Control Ref | No | Link to the specific control in the Controls Library that this issue relates to |
| Description | Rec. | Detailed description of the issue, including root cause if known |
| Remediation Plan | Rec. | Specific steps to be taken, by whom, by when |
Severity SLA Table
| Severity | Max Remediation Period | Escalation | Reporting |
|---|---|---|---|
| Critical | 7 calendar days | CEO / Board immediately. Compliance Officer daily update. | Board report within 24 hours. Voluntary disclosure to AUSTRAC if ML/TF risk is implicated. |
| High | 30 calendar days | Senior management within 24 hours. Weekly update. | Monthly board report. Compliance Officer weekly. |
| Medium | 90 calendar days | Compliance Officer within 5 business days. | Quarterly compliance report. |
| Low | 180 calendar days | Issue owner to manage. Monthly check-in. | Annual compliance report. Board risk committee. |
Issue Sources — Meaning
| Source | Description |
|---|---|
| Audit | Found during an internal or external audit / AUSTRAC examination |
| Control Test | Found during a scheduled control effectiveness test — link the test ID in the description |
| Incident | Found following a breach, near-miss, or operational incident |
| Self-Identified | Proactively identified by the business without a formal audit/test trigger — viewed most favourably by regulators |
| Regulator | Raised by AUSTRAC, ASIC, APRA, or another regulator directly |
| External Review | Found by an external compliance adviser, law firm, or independent reviewer |
Track through to closure
Update the status as work progresses. Never skip status steps — each transition should be supported by documented evidence.
RG Obligation Mapper
Link regulatory guides to entity obligation registers in bulk
Create a regulatory guide record
Click New Guide. Enter: title, regulator, guide code, version, effective date, review date, a document URL (link to official source), and description. Status defaults to Draft.
Supported Regulators
| Regulator | Full Name | Scope |
|---|---|---|
| AUSTRAC | Australian Transaction Reports and Analysis Centre | AML/CTF Act compliance, SMR/TTR reporting, CDD, record keeping |
| ASIC | Australian Securities and Investments Commission | Financial services licensing, market conduct, financial product disclosure |
| APRA | Australian Prudential Regulation Authority | Prudential standards for ADIs, insurers, superannuation |
| FATF | Financial Action Task Force | International AML/CTF standards (40 Recommendations + 9 Special Recommendations) |
| ISO | International Organisation for Standardisation | ISO 31000 risk management, ISO 27001 information security |
| Treasury | Australian Treasury | AML/CTF legislative reform, Tranche 2 regulations |
| Other | Any other regulator or standard body | State regulators, overseas regulators, industry standards |
Manage guide status over time
When AUSTRAC releases an updated regulatory guide:
- Create a new guide record for the updated version
- Mark the old version as Superseded
- Update the effective date on the new guide
- Re-run bulk mapping from the new guide to update entity obligations
Obligation Library
Master repository of all AML/CTF regulatory obligations
Obligation Categories
| Code | Category | Description |
|---|---|---|
| GOV | Governance | Board-level oversight, ARCO appointment, AML/CTF program structure, internal audit |
| CON | Conduct / Compliance Mgmt | Breach reporting, compliance monitoring, regulatory liaison, enforceable undertakings |
| AML | AML/CTF Program | Core AML/CTF program obligations — Part A (risk-based) and Part B (customer identification) |
| CDD | Customer Due Diligence | KYC, beneficial ownership, EDD, ongoing due diligence, correspondent banking |
| CUS | Customer Monitoring | Ongoing transaction monitoring, customer profile updates, risk re-assessment triggers |
| RPT | Reporting | Suspicious Matter Reports (SMR), Threshold Transaction Reports (TTR), IFTI, compliance reports |
Obligation Data Fields (expanded view)
| Field | Description |
|---|---|
| Obligation ID | Unique identifier (e.g. OB-AML-001). Used to cross-reference with control and RG mapper records. |
| Category | GOV / CON / AML / CDD / CUS / RPT |
| Description | Plain-English description of the obligation requirement |
| Regulatory Source | The regulation or rule that creates this obligation (e.g. AML/CTF Rules 2007, Rule 4.1.2) |
| Legislative Reference | The specific Act section (e.g. AML/CTF Act 2006, s.36) |
| Risk Category | Which risk type this obligation primarily addresses (ML, TF, Fraud, Sanctions, etc.) |
| Applicable Entity Types | Which entity types this obligation applies to — used for instantiation matching |
| Required Licenses | Specific licenses that trigger this obligation |
| Linked Controls | Control IDs from the Controls Library that implement this obligation |
| Policy Template | Suggested policy language or procedure guidance for implementing this obligation |
| Default Weight | Importance weighting used in obligation completeness scoring (1–5) |
Reports & Dashboards
Executive reporting, compliance analytics, and EWRA intelligence
Two dedicated report views aggregate data from every module into actionable compliance intelligence. Neither page requires manual input — all data is drawn live from the platform.
Executive Reports — 5 Tabs
Navigate to Reports → Executive Reports. Switch between tabs using the tab bar at the top of the page.
| Tab | What it shows | Key metrics |
|---|---|---|
| Overview | High-level KPIs and cross-module risk summary | Total entities, active controls, CRA count, EWRA approved, open issues, critical issues, tests completed, pass rate. Pie charts for CRA distribution, Country Risk distribution, Issues by severity. Controls by domain bar chart. |
| Customer Risk | CRA breakdown and concentration analysis | Risk label distribution (Low / Medium / High / Unacceptable). Volume by risk tier. Trend over time. High-risk customer count. Average composite score. |
| Control Testing | Test schedule health and pass/fail rates | Completed vs Overdue vs Scheduled counts. Pass rate gauge. Pass/Fail/Partial breakdown by domain. Trend of test results over time. |
| Issues | Open issue register summary and remediation health | Issues by status, by severity, by domain. Average time to close. Overdue issues (past due date). Critical issues requiring immediate attention. |
| Controls | Controls library coverage and ownership metrics | Controls by domain, by type, by automation level. Unowned controls count. Controls without a testing frequency set. |
EWRA Dashboard — Risk Intelligence View
Navigate to Reports → EWRA Dashboard. This view provides deep analytics specific to risk assessments.
| Chart / Panel | Description |
|---|---|
| Risk Factor Radar | Radar chart showing inherent vs residual scores across all EWRA factors for the selected entity / assessment period. A wide gap between inherent and residual indicates strong control effectiveness. |
| Assessment Status Bar | Counts of assessments by status (Draft / In Review / Approved / Archived) across all entities. Used to track EWRA program completion. |
| Residual Risk Distribution | Breakdown of approved assessments by residual risk rating (Low / Medium / High / Critical). The goal is to see the distribution shift left over time. |
| Factor Heatmap | Colour-coded matrix of inherent risk scores by factor and entity. Red cells = high priority for control investment. |
| Recent Assessments | List of the 10 most recently created or updated EWRA assessments with their ratings and status. Quick access to assessments requiring action. |
| Control Effectiveness Distribution | How control effectiveness ratings (Strong / Adequate / Weak / Ineffective) are distributed across all assessed factors. |
KPI Definitions
| KPI | Calculation | Target |
|---|---|---|
| Test Pass Rate | (Completed tests with result = Pass) ÷ (All completed tests) × 100 | ≥ 85% — below 70% is a significant control concern |
| Open Issues | Count of all issues with status ≠ Closed and ≠ Accepted Risk | Zero Critical open > 7 days. Minimise High open > 30 days. |
| EWRA Approved | Count of assessments with status = Approved | Every Active entity should have ≥ 1 Approved EWRA in the current period. |
| CRA Coverage | Count of CRA assessments ÷ total active customers (where known) | 100% of onboarded customers should have a current CRA. |
| Overdue Tests | Count of test schedules with status = Overdue | Zero. Any overdue tests should be escalated daily. |
| Critical Issues (SLA) | Count of Critical issues open for > 7 calendar days | Zero. Each day past SLA is a regulatory risk. |
Domain Code Glossary
All AML/CTF control and issue domains explained
| Code | Domain Name | Description |
|---|---|---|
| GOV | Governance & Management | Board oversight, ARCO role, AML/CTF program accountability, committee structure, management reporting |
| CDD | Customer Due Diligence | KYC procedures, identity verification, beneficial ownership, EDD, third-party reliance, PEP identification |
| SCR | Sanctions Screening | Customer and transaction screening against UN, OFAC, DFAT, and internal watchlists. Alert management and escalation. |
| TM | Transaction Monitoring | Rule-based and behavioural monitoring of transactions. Alert review, case management, and escalation to SMR. |
| RPT | Regulatory Reporting | SMR filing, TTR reporting, IFTI submission. Timeliness, completeness, and accuracy of mandatory reports. |
| RA | Risk Assessment | Enterprise-wide and customer-level risk assessment processes. Methodology, calibration, and periodic review. |
| TECH | Technology & Systems | AML/CTF system configuration, data quality, system access controls, vendor management, change management. |
| FRD | Fraud Prevention | Internal and external fraud controls. Fraud detection, investigation, and recovery procedures. |
| CYB | Cybersecurity | Information security controls relevant to AML/CTF data protection. Access management, incident response, data classification. |
| PRV | Privacy & Data Protection | Privacy Act compliance for CDD data. Data retention, destruction, access controls, and privacy impact assessments. |
| TRN | Training & Awareness | AML/CTF training program for all staff. Role-based training, completion tracking, refresher frequency, new joiner onboarding. |
| RK | Record Keeping | Retention of CDD records (7 years), transaction records (7 years), SMR/TTR copies, and audit trails. |
| OUT | Outsourcing & Third Party | Due diligence on outsourced AML/CTF functions. Contract controls, monitoring, and exit planning. |
| COM | Compliance Management | Internal compliance monitoring, breach management, regulatory liaison, enforceable undertaking management. |
| FC | Financial Crime Intelligence | Typologies, red flags, financial crime intelligence, AUSTRAC feedback, industry information sharing. |
| FR | Fraud Risk | Fraud risk assessment, fraud typologies, fraud controls independent of financial crime obligations. |
| CM | Change Management | Assessment of AML/CTF impact of new products, new channels, new markets, system changes, and M&A activity. |
Status Workflows
Allowed status transitions for each module
Entity Profile
Draft → Active: Obligations can be instantiated. Active → Archived: Entity is no longer operating. Cannot go from Archived back to Active.
EWRA Assessment
Draft: editable by assessor. In Review: submitted to Compliance Officer / ARCO for review. Approved: read-only, locked. Archived: superseded by newer assessment.
Issue / Remediation
Accepted Risk requires Board/senior sign-off and cannot be moved back to Open without a new issue being logged.
Control Test Schedule
Overdue is set automatically by the system when a Scheduled test passes its scheduled date. Cancelled should be used when a test is formally deferred or removed from scope.
Obligation Status
Scoring Rubrics
Quick-reference scoring guides for EWRA and CRA
EWRA — Control Effectiveness × Inherent Risk = Residual
| Inherent Risk → | 1 (Neg.) | 2 (Low) | 3 (Med.) | 4 (High) | 5 (V.High) |
|---|---|---|---|---|---|
| Strong (×0.25) | 0.25 | 0.50 | 0.75 | 1.00 | 1.25 |
| Adequate (×0.50) | 0.50 | 1.00 | 1.50 | 2.00 | 2.50 |
| Weak (×0.75) | 0.75 | 1.50 | 2.25 | 3.00 | 3.75 |
| Ineffective (×1.00) | 1.00 | 2.00 | 3.00 | 4.00 | 5.00 |
Residual ≤ 1.5 = Low · 1.5–2.5 = Medium · 2.5–3.5 = High · > 3.5 = Critical
CRA — Composite Score → Risk Label
| Avg. Factor Score | Risk Label | CDD Level | Review Frequency |
|---|---|---|---|
| 1.0 – 2.0 | Low | Simplified CDD acceptable if low-risk product threshold met | Annual or on trigger event |
| 2.0 – 3.0 | Medium | Standard CDD required | Annual with trigger-event refresh |
| 3.0 – 4.0 | High | Enhanced Due Diligence (EDD) required. Senior approval. | Every 6 months |
| 4.0 – 5.0 | Unacceptable | Do not onboard / exit. EDD + SAR consideration mandatory. | Immediate action required |
Compliance Calendar
Key regulatory dates and recurring obligations
Use this calendar as a guide for scheduling EWRA reviews, country risk updates, and platform maintenance. Add these as recurring tasks in your organisation's project management system and link them to corresponding Issues in dooit.ai.
Annual Recurring Schedule
| Month | Activity | Module | Priority |
|---|---|---|---|
| January | Plan annual EWRA cycle — create draft assessments for all Active entities | EWRA | High |
| February | FATF Plenary outcomes published — review Grey/Black list changes | Country Risk | Critical |
| February | Update Country Risk ratings based on FATF plenary | Country Risk | Critical |
| March | Q1 control testing completion review — chase overdue tests | Testing | High |
| April | EWRA completion deadline — all Annual assessments should be In Review or Approved | EWRA | High |
| June | FATF Plenary outcomes published — review Grey/Black list changes | Country Risk | Critical |
| June | Mid-year CRA refresh for High and Unacceptable rated customers | CRA | High |
| June | AUSTRAC compliance report period (if applicable to entity type) | Reports | High |
| July | Annual staff AML/CTF training completion check | Controls (TRN) | Medium |
| September | Q3 control testing review — issues from Q1/Q2 tests should be closed | Testing / Issues | High |
| October | FATF Plenary outcomes published — review Grey/Black list changes | Country Risk | Critical |
| October | Update Country Risk ratings based on FATF plenary | Country Risk | Critical |
| November | Annual EWRA sign-off deadline — Board approval of current year EWRA | EWRA | Critical |
| December | Year-end issue register review — close or formally accept remaining issues | Issues | High |
| December | Regulatory calendar planning for next year — schedule all tests and EWRAs | All modules | Medium |
AUSTRAC Reporting Deadlines
| Report Type | Trigger | Deadline | Where to track |
|---|---|---|---|
| SMR — Suspicious Matter Report | Suspicion formed of ML/TF, or other serious offence | As soon as practicable (no defined limit, but prompt). Best practice: within 3 business days. | Log as a Critical issue in Issues Register. AUSTRAC AUSTRAC Online. |
| TTR — Threshold Transaction Report | Cash transaction ≥ AUD $10,000 | Within 10 business days of the transaction | TTR count should be visible in Reports. Submit via AUSTRAC Online. |
| IFTI — International Funds Transfer | Electronic instruction to/from outside Australia | Within 10 business days | IFTI count tracked in Reports. Submit via AUSTRAC Online. |
| AML/CTF Annual Compliance Report | Required for all reporting entities | 31 March each year (for previous calendar year) | Create a Triggered EWRA as the basis. Log deadline as a High issue if overdue. |
| Correspondent Banking Due Diligence | Before establishing a correspondent relationship | Prior to commencement of relationship | Log as a CDD obligation in the entity's obligation register. |
Trigger-Event Checklist
The following events should trigger immediate platform actions:
| Event | Actions Required |
|---|---|
| New product or service launch | Triggered EWRA · Update entity profile (designated services) · Re-instantiate obligations · Review TM rules |
| New jurisdiction / market entry | Triggered EWRA · Update entity profile (jurisdictions) · Check country risk tier · Update CRA criteria |
| Material change in customer mix | Triggered EWRA · Bulk CRA re-assessment for affected segment |
| Ownership / management change | Triggered EWRA · Board notification · PEP screening of new controllers |
| AUSTRAC regulatory finding | Log as Critical issue · Triggered EWRA · Consider voluntary disclosure · Escalate to ARCO immediately |
| FATF Grey/Black list change | Update Country Risk · Identify affected customers · EDD review for HRC→UHRC customers · CRA re-assessment |
| UN / OFAC / DFAT sanctions designation | Immediate sanctions screening · Freeze implicated accounts · SMR consideration · Board notification |
| Significant IT system change | TECH domain control test · EWRA technology factor re-score · Access control review |
| Key staff departure (ARCO / CCO) | Board notification · Interim ARCO appointment · AML/CTF program review · Triggered EWRA |
| External audit / AUSTRAC examination | Issue register review · EWRA review · Testing evidence collation · Ensure all documentation is current |
Sidebar
| Action | How to do it |
|---|---|
| Collapse sidebar to icon rail | Click the ← collapse icon (top right of sidebar) to collapse to a compact icon-only rail — useful on smaller screens. |
| Expand sidebar | Click the → expand icon at the bottom of the collapsed rail, or hover over any icon to see the label tooltip. |
| Mobile navigation | On mobile/tablet, tap the ≡ hamburger icon in the top bar to open the sidebar as a full-screen drawer. Tap the backdrop or × to close. |
| Grouped nav items | Items like 'Entity Setup' and 'Testing' have sub-items. Click the group label to expand/collapse the sub-menu. The active sub-item stays highlighted. |
Table Controls (DataTable)
| Control | Location | How it works |
|---|---|---|
| Column resize | Drag the right edge of any column header | Drag left/right to resize. Double-click the resize handle to reset to default width. |
| Column reorder | Drag a column header left or right | Grab the column header (not the resize handle) and drag to a new position. Pinned columns (leftmost, rightmost) cannot be reordered. |
| Page size | Dropdown at the bottom-left of the table | Choose 25 / 50 / 100 rows per page. In server-side mode, changing page size triggers a new API call. |
| Pagination | Previous / Next buttons and page number display at bottom | In server-side mode all navigation calls the API. In client-side mode, pagination is computed locally. |
| Search (toolbar) | Search box in the table toolbar | In server-side mode, submitting the search form triggers an API call. Press Enter or click Go. |
| Filter dropdowns | Dropdowns in the table toolbar | Changing a dropdown immediately re-fetches data (server-side) or filters the local data (client-side). |
| Domain / status pills | Above the table on list pages | Click a pill to filter by that domain or status. Click again (or 'All') to clear. Works in combination with toolbar filters. |
| Clear all filters | 'Clear all' button in the toolbar | Appears when any filter or search is active. Resets all filters and search in one click. |
Drawer (Edit Panels)
| Action | How to do it |
|---|---|
| Open edit drawer | Click 'Edit' or the pencil icon on any detail page |
| Scroll within drawer | The drawer body scrolls independently — the Save / Cancel footer is always visible at the bottom regardless of content length. |
| Close without saving | Click the × in the drawer header, or click the backdrop behind the drawer. |
| Save | Click the Save button in the drawer footer. Validation errors appear inline below each field. |
Breadcrumbs & Back Navigation
Most detail pages show breadcrumbs at the top (e.g. Entity Profiles → ACME Financial → Obligations). Click any breadcrumb to navigate up the hierarchy without losing your place in the list (page number and filters are stored in URL query params on some pages).
Toast Notifications
| Toast Type | Meaning |
|---|---|
| Green (Success) | Action completed successfully — record saved, obligation instantiated, etc. |
| Red (Error) | Action failed — check the message for details. Common causes: validation error, network error, session expiry. |
| Amber (Warning) | Action completed with caveats — e.g. 0 new obligations created, some items skipped. |
Best Practices
Evidence-based compliance tips from the dooit.ai methodology
Keep entity profiles current at all times
Update licenses, services, and jurisdictions immediately when they change. Stale profiles generate incorrect obligation sets, leading to gaps that regulators may treat as a failure of governance.
Test controls on schedule — document everything
Testing without evidence is as bad as no testing. Record the procedure followed, the sample reviewed, the conclusion, and the reviewer's sign-off. A Pass with no evidence will not satisfy an AUSTRAC examination.
Log every finding — even minor ones
Self-identified issues handled promptly are viewed very favourably by AUSTRAC. A visible, active issue register demonstrates a culture of compliance. Regulators distinguish between 'finds nothing' and 'finds, logs, and fixes'.
Fail → Issue is a mandatory link
Every failed control test must produce a linked issue in the Issues Register. The connection between testing and remediation is the core of a risk-based AML/CTF program.
Update country risk after every FATF plenary
FATF plenary outcomes (Feb, Jun, Oct) can add or remove countries from the Grey and Black lists. Update ratings within 2 weeks. Countries moving from HRC → MRC need CRA re-assessments for affected customers.
Triggered EWRA is a regulatory expectation
Annual EWRA is the minimum. Material changes — new product, new channel, new jurisdiction, significant customer mix shift, regulatory findings — require a triggered EWRA. Document the trigger in the assessment name.
'Accepted Risk' requires Board sign-off and annual review
Accepted Risk is not a way to close hard issues. Regulators look at accepted risk decisions carefully. Each acceptance needs: documented rationale, residual risk estimate, monitoring plan, and annual re-assessment.
CRA is point-in-time — define your trigger events
A Low CRA today does not mean Low forever. Define and document the trigger events that mandate a CRA refresh: new BO, adverse media, new business activity, threshold transaction, PEP designation.
Automated controls are not zero-maintenance
Automated controls still require periodic review: rule calibration, alert volume analysis, exception rate monitoring, system access controls, and vendor SLA checks. Include them in your testing schedule.
Don't instantiate obligations without reviewing matches
After instantiation, review the generated list. Some obligations may be instantiated because of a broad 'All Entities' match but may not be relevant to your specific business. Mark inapplicable ones as 'Not Applicable' with a documented reason.
FAQ & Troubleshooting
Answers to the most common platform questions
Glossary
Key terms used throughout the platform
Anti-Money Laundering and Counter-Terrorism Financing. The regulatory framework governing obligations on reporting entities in Australia under the AML/CTF Act 2006.
AML/CTF Reporting and Compliance Officer. The designated senior individual responsible for an entity's AML/CTF compliance program. Must be appointed in the Part A program.
Australian Transaction Reports and Analysis Centre. Australia's financial intelligence and AML/CTF regulator. Administers the AML/CTF Act 2006.
Customer Due Diligence. The process of identifying, verifying, and understanding a customer, including their beneficial owners, source of funds, and purpose of relationship.
Customer Risk Assessment. The process of scoring an individual customer's ML/TF risk using standardised factors to determine the appropriate level of due diligence.
Digital Currency Exchange. A provider of digital currency exchange services — a designated service under the AML/CTF Act.
Enhanced Due Diligence. Additional CDD measures applied to higher-risk customers, including obtaining additional information and requiring senior approval for the relationship.
Enterprise-Wide Risk Assessment. A comprehensive assessment of the ML/TF risks faced by a reporting entity across all its customers, products, services, channels, and jurisdictions. Required by AUSTRAC Rule 4.1.2.
Financial Action Task Force. Intergovernmental body that sets international AML/CTF standards (the 40 Recommendations). Produces Grey List (Jurisdictions Under Increased Monitoring) and Black List (High-Risk Jurisdictions Subject to a Call for Action).
International Funds Transfer Instruction. Report required when an entity sends or receives an electronic funds transfer instruction from/to outside Australia above threshold.
International standard for risk management principles and guidelines. Used as the methodological basis for the EWRA module.
Know Your Customer. The process of verifying customer identity and understanding the nature of the customer relationship. A subset of CDD.
Money Laundering / Terrorist Financing. The two primary financial crime risks regulated by AML/CTF laws.
Office of Foreign Assets Control (US). Administers US economic sanctions programs. OFAC designations are internationally relevant for Australian entities with US-connected activities.
Politically Exposed Person. An individual who holds or has held a prominent public function, or is an immediate family member or close associate of such a person. PEPs require EDD under FATF Recommendation 12.
Remittance Dealer. A provider of designated remittance services — must be registered with AUSTRAC on the Remittance Sector Register.
The level of risk remaining after the application of controls. Calculated as Inherent Risk × (1 − Control Effectiveness). The goal of a risk management program is to reduce residual risk to an acceptable level.
Suspicious Activity Report (international term) / Suspicious Matter Report (Australian term). A mandatory report to AUSTRAC when an entity forms a suspicion that a customer or transaction is linked to ML/TF or other serious offences.
Threshold Transaction Report. Required when a cash transaction (or series of related transactions) meets or exceeds AUD $10,000 in value.
Ultimate Beneficial Owner / Ultimate Beneficial Controller. The natural person(s) who ultimately own or control a legal entity. CDD must identify and verify UBOs above 25% ownership threshold.
Digital Identity Verification and Customer Records. An approved digital verification service used in lieu of face-to-face identity verification. Must meet AUSTRAC's prescribed requirements for reliable and independent sources.
The level of risk exposure before any controls or mitigating measures are applied. In the EWRA, inherent risk is scored 1–5 per risk factor. High inherent risk is not necessarily a problem — it is what controls are for.
The remaining risk level after applying controls. Calculated as Inherent Risk × Control Effectiveness multiplier. The goal of the AML/CTF program is to reduce residual risk to an acceptable (Low/Medium) level across all factors.
A qualitative rating (Strong / Adequate / Weak / Ineffective) of how well controls mitigate a specific risk factor. Determined through testing evidence, not assumption. Strong controls with no testing evidence should be rated Adequate or lower.
The risk-based part of an AML/CTF program, required for all reporting entities. Must include: ML/TF risk assessment (EWRA), customer due diligence procedures, transaction monitoring, and reporting obligations.
The customer identification part of an AML/CTF program. Sets out how the entity will identify and verify customers, including individuals, companies, trusts, and beneficial owners. Must be risk-based.
An organisation required to comply with the AML/CTF Act 2006 because it provides a designated service. All users of this platform should be reporting entities or their compliance advisers.
A service listed in Table 1 or Table 2 of the AML/CTF Act 2006 that triggers AML/CTF obligations. Examples: providing a loan, exchanging currency, sending a remittance, providing a digital currency exchange service.
The core FATF standard requiring countries and entities to identify, assess, and understand ML/TF risks and apply risk-based measures. The EWRA module is the primary tool for meeting R.1 at the entity level.
Applying AML/CTF measures in proportion to the assessed ML/TF risk — more controls for higher-risk customers, channels, and products; simplified controls for lower-risk. The RBA is mandated by FATF and AUSTRAC. The EWRA and CRA modules implement the RBA.
A relationship where one bank (correspondent) provides services to another bank (respondent). Carries elevated ML/TF risk due to the layered nature of the relationship. Requires enhanced CDD under FATF R.13 and AML/CTF Rules.
Legal measures imposed by governments or international bodies (UN, OFAC, DFAT) restricting dealings with specific persons, organisations, or countries. Transacting with a sanctioned party is typically prohibited and a criminal offence. Sanctions screening is a mandatory control.
A documented pattern or method used to launder money or finance terrorism. Understanding typologies helps calibrate transaction monitoring rules and inform risk assessments. AUSTRAC, FATF, and ACAMS publish typology reports regularly.
The practice of breaking up large transactions into smaller amounts to avoid reporting thresholds (TTR). Structuring is illegal under the AML/CTF Act. Transaction monitoring rules should detect structuring patterns.
Enhanced Due Diligence. Additional CDD measures applied to higher-risk customers (CRA = High or Unacceptable, PEPs, correspondent banks, complex structures). Must include: senior management approval, enhanced source of funds/wealth checks, more frequent review, closer transaction monitoring.
The subordinate legislation made under the AML/CTF Act 2006 (formally the Anti-Money Laundering and Counter-Terrorism Financing Rules Instrument 2007). Provides detailed requirements supplementing the Act. AUSTRAC amends the Rules periodically — subscribe to AUSTRAC regulatory updates.
Proactively reporting a compliance breach or non-compliance to AUSTRAC before it is discovered by the regulator. Voluntary disclosures are treated as a significant mitigating factor in AUSTRAC's enforcement decisions. Critical and High issues with regulatory implications should be assessed for voluntary disclosure.
Association of Certified Anti-Money Laundering Specialists. The leading international professional body for AML/CTF practitioners. Publishes typologies, best-practice guides, and the CAMS certification program.
Proposed reforms to the AML/CTF Act extending obligations to additional high-risk sectors not currently regulated under Tranche 1, including: real estate agents, lawyers, accountants, and trust and company service providers. Tranche 2 legislation is currently before the Australian Parliament.
dooit.ai · EWRA / GRC Platform · v1.0
Built for AUSTRAC · FATF · ISO 31000 compliance