Skip to main content

Using the Program Builder

The program builder is a guided wizard that produces your firm's AML/CTF program. It is at Program Builder in the sidebar, under the AML Program group.

For what a program must contain and why, see Build your program. This page is the walkthrough.

The wizard has three steps

The steps are named in the interface as:

  1. Risk Assessment
  2. Personnel & Governance
  3. Client Due Diligence

A step rail runs down the left, the questions for the current section fill the centre, and the policy text your answers are generating appears on the right. On most screens you can edit that policy text directly with the pencil control, so the wording is yours rather than fixed.

Step 1: Risk Assessment

Seven sections. This step establishes the risk your firm reasonably faces, and it is the groundwork the rest of the program rests on.

SectionWhat it asks
Designated ServicesWhich designated services your firm provides under Tranche 2
Additional ServicesServices you offer that are not designated services
Customer TypesThe types of customers your firm typically engages
Delivery ChannelsHow services are delivered to customers
TechnologiesThe technologies and platforms used in service delivery
Risk Factors & AppetiteML/TF risk factors, and your firm's risk appetite
Countries & JurisdictionsThe geographic areas and jurisdictions your firm operates in

Designated Services

The rest of the wizard depends on this section. It lists the AUSTRAC regulated professional services, taken from the tables in s 6 of the AML/CTF Act 2006, and you tick the ones your firm provides. Each entry carries a risk tag, such as High or Medium, and an information control explaining what the service covers.

Step 1, Designated Services, with services ticked.Step 1, Designated Services, with services ticked.
Step 1, Designated Services, with services ticked.

What you tick here propagates in two directions. The program's CDD sections are generated from it, and the services available to classify when you scope a matter come from the same list. Understate it and you get a program that does not cover the work you do, and a scoping step where the right service cannot be selected.

An Additional regulated activities expander sits at the bottom of the screen, for services from other regulated sectors your firm may also provide.

Additional Services

Anything you enter here stays out of AML/CTF scope. There is no CDD and no risk assessment attached to it. It is recorded so the audit trail shows the full picture of what the firm does, and so a reader can see a service was considered and deliberately excluded rather than missed.

This section is not required. A firm with no services beyond its designated ones is not blocked from approval by leaving it empty. If a service is a designated service, it belongs in the first section: putting it here would record it as out of scope.

Customer Types

The types of customer your firm typically engages, each with a risk tag. The options cover individuals and sole traders, body corporate, trust, partnership, association, government body, and charity or not-for-profit, and each carries a Show details control explaining who it covers.

Step 1, Customer Types.Step 1, Customer Types.
Step 1, Customer Types.

This section is required. Selecting a customer type here makes the corresponding questions appear when you reach the CDD step.

Delivery Channels, Technologies and Countries & Jurisdictions

Three sections with no screenshot in this knowledge base yet, described here from the product.

  • Delivery Channels asks how services are delivered to customers, which is the face-to-face, remote and digital mix your firm works through
  • Technologies asks about the technologies and platforms used in service delivery, which covers the systems that hold customer data and the tools customers interact with
  • Countries & Jurisdictions asks about the geographic areas your firm operates in, which is the country risk input

All three are required, and all three feed the generated risk assessment and the CDD sections.

Risk Factors & Appetite

This is where you set how much risk your firm is prepared to accept, factor by factor. The factors are grouped into Service Risk Factors, Customer Risk Factors and Delivery Channel Risk Factors, and each individual factor shows a read-only inherent risk badge (High, Medium or Low), an Accept risk? YES/NO toggle, and a Show details explanation.

Step 1, Risk Factors and Appetite.Step 1, Risk Factors and Appetite.
Step 1, Risk Factors and Appetite.

The risk factors include service factors such as high value transactions and unusual virtual asset transactions, customer factors such as politically exposed persons, charities and low complexity clients, and delivery channel factors such as suspected fraud. The risk level on each factor is fixed. What you set is whether the firm accepts that risk. Choosing NO makes How will you avoid this risk? mandatory for that factor. Those YES and NO answers are the firm's stated appetite, and they are what the program holds you to.

Step 2: Personnel & Governance

Two sections, both about who is responsible for what.

Roles & Responsibilities

This section defines the firm's AML/CTF structure. Working down the screen:

  • AML/CTF Compliance Officer: the person appointed, with a Change AMLCO control
  • An AUSTRAC notification warning directly under the appointment, reading that AUSTRAC requires notification of the AMLCO within 14 days, through AUSTRAC Online. The warning also points out that the enrolment details need to be up to date. See Appoint your AMLCO for the obligation
  • Is your AMLCO also the governing body or principal, and is this a single employee business, both yes or no
  • Senior Manager, the person responsible for approving changes to the program and retaining the decisions
  • AML/CTF Responsibilities Assignment, a matrix assigning each function to the AMLCO, the Senior Manager, or CDD Staff. The functions run across Initial CDD, Ongoing CDD, Enhanced CDD, Screening, SMR preparation, TTR preparation, personnel due diligence on others, training delivery, and program review
  • Escalation Path, a choice between Staff to AMLCO to Principal, Staff to AMLCO to Board, or a custom path
Step 2, Roles and Responsibilities.Step 2, Roles and Responsibilities.
Step 2, Roles and Responsibilities.

Completing this section requires an AMLCO to be appointed. That is the gate the rest of the wizard depends on.

When you open the officer picker, members who cannot be appointed are shown disabled with the reason stated rather than being hidden, so you can see why someone is unavailable.

The AMLCO picker.The AMLCO picker.
The AMLCO picker.

For which roles the product lets you select, see Roles and permissions. The appointment rule and the roles rule are two different things and both apply.

Training Program

This section configures how the firm trains its staff. Working down the screen:

  • PDD completion status, showing how many personnel have completed their due diligence, with a Manage personnel PDD action
  • Training compliance status, showing how much of the firm's training is current, with a Manage training action
  • Training delivery method, multi-select, across in-platform modules, external provider, in-person sessions and self-paced materials
  • Training frequency, across on appointment and annually, on appointment and after material change, both, or custom
  • Training assessment, across a comprehension quiz, manager sign-off, or both
  • Scenario-based learning, which is included with the in-platform modules
Step 2, Training Program.Step 2, Training Program.
Step 2, Training Program.

The obligation behind this section, including who has to be trained and what the training must cover, is on Staff training.

Step 3: Client Due Diligence

Five sections take user input, Tipping Off is information only, and one is a review screen. This step writes the procedures your firm follows when dealing with customers.

SectionUser inputWhat it covers
Initial CDDRequiredHow you identify and verify customers before acting for them
Ongoing CDDRequiredYour ongoing customer monitoring approach
Escalation & ECDDRequiredEscalation triggers and enhanced due diligence procedures
ReportingOptional, defaults from Firm SettingsAUSTRAC reporting, and how reports are escalated
Tipping OffNothing to enterThe s 123 offence and how Duely isolates suspicious matter information
OffboardingRequiredYour policy for customers who fall outside your risk appetite
Preview & DownloadNothing to enterReview the full program and download the PDF before requesting approval

Initial CDD

There is no screenshot for this section yet, so here it is from the product. It covers how your firm identifies and verifies customers before acting for them. That means the identity data you collect, how you verify it, and the customer types it applies to, which is why the customer types you selected in Step 1 shape what appears here.

For the legal requirement, see Customer due diligence.

Ongoing CDD

This section sets how often customers are reviewed, by risk level, and how often screening is refreshed. Both are set as a number of months.

Step 3, Ongoing CDD.Step 3, Ongoing CDD.
Step 3, Ongoing CDD.

Monitoring frequency: how often client due diligence is reviewed for each risk level. In the screenshot the defaults are 12 months for high risk, 24 for medium and 36 for low.

Sanctions and PEP screening refresh: a second set of intervals, and the section notes that leaving them blank uses the platform defaults, which are 6, 12 and 24 months. It also notes that the screening interval is capped at the review interval for that risk level, so screening can be more frequent than the review but never less.

Pre-commencement CDD appears at the bottom of the screen as read-only. It records how customers already receiving designated services when the obligations commence are handled, and the screen states that this policy is applied by the product's matter workflow and cannot be modified.

Escalation & ECDD

No screenshot yet, so from the product: this section defines the triggers that escalate a customer or engagement, and the enhanced due diligence procedures that follow. It is where the firm states what makes it treat a customer as higher risk and what it then does about it.

Reporting

This section configures which AUSTRAC report types apply to your firm, and states who submits them. It is optional: the TTR and CBM toggles start from your firm's reporting settings on Firm Setup, and the section counts as complete without any changes.

Step 3, Reporting.Step 3, Reporting.
Step 3, Reporting.

The three report types appear as toggles:

  • SMR (Suspicious Matter Report), marked Always On and not adjustable, with the note that the deadline is 24 hours or 3 business days
  • TTR (Threshold Transaction Report), switchable, described as cash transactions of $10,000 or more
  • CBM (Cross-Border Movement), switchable, described as physical cross-border movement of currency

Below the toggles, Who Submits Reports states that the AML/CTF Compliance Officer submits all AUSTRAC reports, and that SMRs are submitted after notifying the governing body.

A Legal Professional Privilege (LPP) panel follows, noting that where the firm is a legal practice its compliance officer must assess whether report information is subject to privilege held by a third party before submission. The obligation is on Reporting.

Tipping Off

This section has nothing for you to enter. It records the s 123 tipping off offence and how Duely isolates suspicious matter information, and it is stated as fact rather than asked as a question. The offence itself is on Reporting.

Offboarding

No screenshot yet, so from the product: this section sets the firm's policy for customers who fall outside its risk appetite. There are three choices: offboard them, offboard them with senior manager approval, or a custom policy that you describe.

Preview & Download

The last section, and the last chance to read the program as a document before asking for approval.

Step 3, Preview and Download.Step 3, Preview and Download.
Step 3, Preview and Download.

It shows how much of the policy text has generated, such as 20 of 22 sections, with a Read more control to review it and a Download PDF action. The PDF is the full formatted document including cover page, tables and appendices.

Download it and read it. This is where an answer that produced text you would not want a regulator to read is still cheap to fix.

How the steps interlock

Step 3 is parameterised by Step 1. The customer types, delivery channels and jurisdictions you entered there drive the questions and the generated text here, so a section in this step can be shaped by answers from two steps earlier. Changing your customer types in Step 1 after working through Step 3 changes what Step 3 generates.

Approving creates a new version

Versioning determines what you can prove later.

Approving a draft produces a new version and marks the previously approved version superseded. Both are retained. You can therefore answer two different questions:

  • "What does our program say?" refers to the currently approved version.
  • "What did our program say in March?" refers to the version that was current then.

A draft can also be rejected, with comments recorded in the change log, and the rejected draft is terminal. Rejection is a review outcome, not an error.

Versions are listed at Program Versions in the AML Program group, with their status, effective date and approval date. Each approved version exports to PDF, and that PDF is your program of record.

Program Versions, with the approved version and its history.Program Versions, with the approved version and its history.
Program Versions, with the approved version and its history.

Asking for approval

Once the sections are done, you request approval and an approver decides. Who can approve and what gates approval are enforced at different points.

Who can approve

Approval capability comes from the person's firm role: Admin, Approver, or AMLCO. A staff member cannot approve a program.

When you request approval, the person you pick must be able to approve and cannot be you.

At approval, the author of a draft cannot approve it while another active member who can approve exists. If you are the only member who can approve, you may approve your own draft, and the product asks for a justification and records it in the change log. An auto-generated draft produced because the AMLCO changed is exempt, so changing the officer does not lock the firm out of approving the revision.

An AMLCO must be appointed before an approval can be requested, and again at the point of approval.

What gates approval

ConditionEnforced by
An AML/CTF Compliance Officer is appointedRefused at both request and approval
The chosen approver is approval-capable and not the requesterRefused at request
The approver is not the author of the draft, unless they are the firm's only approver, who must record a justificationRefused at approval
All required wizard sections are completeRe-checked by the domain at approval

Auto-generated sections are excluded from the completeness check, because there is nothing for you to fill in. Additional Services is also excluded, so a firm with no services beyond its designated ones is not blocked.

Scoping depends on a published version

A matter cannot be scoped until the firm has a published program version. The scoping decision is pinned to a specific program version, so a historical decision remains valid against the program that was in force when it was made, even after the program changes.

That makes the program builder a prerequisite for the rest of the workflow rather than a parallel task. See Creating a matter.

The approved program.The approved program.
The approved program.

If your firm changes

Do not edit around the program. Produce a new version. The version history is what demonstrates the program was reviewed and updated, which is the point of the maintenance stage and of the review obligation covered in Review and evaluation.

Changing the AMLCO is a special case: the product generates a revision draft when the officer changes, so the program does not sit out of step with the appointment.