From Client Creation to AUSTRAC-Ready in 90 Seconds

A full technical walkthrough of what ComplyHub does, how it does it, and what the evidence looks like.

Three Layer Architecture

All compliance data, audit trails, and PII transformations happen in the orchestration layer.
Source Layer
(Triggers)
Orchestration Layer (ComplyHub)
External Services
(Holds PII)
All ComplyHub-owned data lives on AWS Sydney ap-southeast-2. Biometric data is processed by Stripe and never stored on ComplyHub servers. 7-year retention.

The 14-Step Compliance Pipeline

Average end-to-end time from XPM client creation to AUSTRAC-ready: 90 seconds excluding client IDV completion.
Phase 1 — Trigger and Setup
01

XPM Polling Detects New Client

Cron-based trigger polls XPM every 15 minutes

≤15 min latency
02

Deduplication and Client Record Creation

Check if record exists, create with status INITIATED

~50ms
Phase 2 – Identity Verification
03

Generate Stripe IDV Session

Short-lived URL for ID upload and liveness check

$1.50/check · ~300ms
04

Send Branded IDV Email

Sent from firm's address via SendGrid with 24hr expiry

~200ms
05

Client Completes Biometric IDV

Document upload plus liveness check

Median 4 minutes
06

IDV Webhook Received and Validated

Stripe signature verified, outcome parsed

~50ms
Phase 3 – Risk Data Collection
07

Client Questionnaire

5 questions covering entity, source of funds, geo, industry, cash

08

Firm Selects Service and Complexity

Designated service type and complexity tier

09

Validate Inputs Complete

48-hour reminder if anything missing

Phase 4 – Decision and Audit
10

PEP Sanctions and Adverse Media Screening

6 list categories via ComplyAdvantage

~$2/search · ~800ms
11

F7-Factor Risk Score Computed

Weighted score output Low, Medium, or High

~10ms
12

Decision Routing

Standard CDD or EDD branch triggered

13

Audit Trail Sealed

Engagement letter sent, SHA-256 hash-chained log sealed

14

XPM Job Note and Slack Alert

Status written to XPM, firm partner notified

How the Risk Engine Works

ComplyHub scores each client across 7 weighted factors:

Risk Factor Weight
Customer type (individual / company / trust / offshore) 20%
Source of funds 20%
Geographic risk (FATF country list) 15%
Service type (designated service AUSTRAC list) 20%
Industry (cash-intensive sectors) 10%
Cash intensity 10%
Transaction complexity 5%

Note: Weights are configurable per firm by your AML consultant.

EDD Decision Matrix

Five outcomes from screening and 7-factor risk score. Every outcome writes to the audit log.
Low
Standard CDD
No hits. Score below 1.5. Engagement proceeds.
12-month review
Medium
Standard CDD
Score 1.5–2.3. Elevated monitoring.

6-month review

EDD-1
EDD Light
Adverse media or PEP family. Source of wealth requested. Partner approval.

Engagement held

EDD-2
EDD Heavy
Direct PEP or offshore structure. UBO tracing. Partner sign-off mandatory.

3-month review

Blocked
Engagement Blocked
Sanctions match DFAT, UN, OFAC, UK HMT. Automatically blocked. Partner notified.

SMR within 3 days

SMR Workflow

All compliance data, audit trails, and PII transformations happen in the orchestration layer.
What ComplyHub Pre-Fills Automatically (~70%)
What the AML Officer Provides (~30%)
ComplyHub drafts. The firm files. ComplyHub never pushes SMRs to AUSTRAC directly. Filing is a statutory obligation of the reporting entity — the boundary is deliberate.

What We Hold — And What We Don't

ComplyHub Holds
(AWS Sydney)

7-year retention · ap-southeast-2

External Services Hold
Never Stored by Design

Three Paths to Compliance

DIY Starter Kit

$0–$2,000

Cheap, fragile

Big-4 Specialist Build
$30,000– $80,000+

Thorough, still incomplete

Recommended

ComplyHub Blended
$10,000– $15,000

Operational, audit-ready

See the Full Platform in a 30-Minute Demo

Watch both compliance paths live — a clean run with Mehta Holdings in 90 seconds and a flagged run with Volkov Trading triggering EDD-1 with adverse media match.
Scroll to Top