From Client Creation to AUSTRAC-Ready in 90 Seconds
Three Layer Architecture
(Triggers)
- Xero Practice Manager
- Xero Accounting webhook fallback
- Manual UI trigger
- n8n workflow engine
- MySQL — AWS Sydney
- FastAPI backend
- React dashboard
- Redis queue
- SHA-256 audit chain
(Holds PII)
- Stripe Identity (biometric IDV)
- ComplyAdvantage (PEP/Sanctions)
- SendGrid (email)
- Twilio (SMS/WhatsApp)
- ASIC Connect (entity verify)
The 14-Step Compliance Pipeline
XPM Polling Detects New Client
Cron-based trigger polls XPM every 15 minutes
Deduplication and Client Record Creation
Check if record exists, create with status INITIATED
Generate Stripe IDV Session
Short-lived URL for ID upload and liveness check
Send Branded IDV Email
Sent from firm's address via SendGrid with 24hr expiry
Client Completes Biometric IDV
Document upload plus liveness check
IDV Webhook Received and Validated
Stripe signature verified, outcome parsed
Client Questionnaire
5 questions covering entity, source of funds, geo, industry, cash
Firm Selects Service and Complexity
Designated service type and complexity tier
Validate Inputs Complete
48-hour reminder if anything missing
PEP Sanctions and Adverse Media Screening
6 list categories via ComplyAdvantage
F7-Factor Risk Score Computed
Weighted score output Low, Medium, or High
Decision Routing
Standard CDD or EDD branch triggered
Audit Trail Sealed
Engagement letter sent, SHA-256 hash-chained log sealed
XPM Job Note and Slack Alert
Status written to XPM, firm partner notified
How the Risk Engine Works
ComplyHub scores each client across 7 weighted factors:
| Risk Factor | Weight |
|---|---|
| Customer type (individual / company / trust / offshore) | 20% |
| Source of funds | 20% |
| Geographic risk (FATF country list) | 15% |
| Service type (designated service AUSTRAC list) | 20% |
| Industry (cash-intensive sectors) | 10% |
| Cash intensity | 10% |
| Transaction complexity | 5% |
Note: Weights are configurable per firm by your AML consultant.
EDD Decision Matrix
6-month review
Engagement held
3-month review
SMR within 3 days
SMR Workflow
- Customer ID and designated service
- Screening history and IDV result
- Risk score history with factor breakdown
- Transaction details pulled from Xero/MYOB/QBO
- Related parties and beneficial owners
- Grounds for suspicion narrative
- Review and edit the AI draft
- Finalise and submit via AUSTRAC Online
What We Hold — And What We Don't
(AWS Sydney)
- Operational client status
- Verification reference IDs
- Risk score outputs
- Decision rationale
- Audit log append-only encrypted at rest
7-year retention · ap-southeast-2
- Stripe — biometric data and ID document images
- ComplyAdvantage — match details and list references
- All accessible via reference ID
- All vendor-encrypted
- Raw biometric templates
- Full sanctions list extracts
- Client passwords or auth tokens
- Plaintext document content
- Cross-border data replication
Three Paths to Compliance
$0–$2,000
Cheap, fragile
- Delivered: AUSTRAC templates only
- Time to ready: 40–80 hours internal
- Day-2 operations: Manual
- Audit readiness: Strong policies, weak evidence
- Best for: Sole practitioners
Thorough, still incomplete
- Delivered: Bespoke 60–100 page program
- Time to ready: 6–12 weeks
- Day-2 operations: Manual
- Audit readiness: Strong policies, weak evidence
- Best for: Top-200 firms
Recommended
Operational, audit-ready
- Delivered: Tailored program + ComplyHub platform
- Time to ready: 2–4 weeks
- Day-2 operations: Fully automated
- Audit readiness: 7-year tamper-proof trail, s.167 in hours
- Best for: SMEs, advisory firms, M&A practices