Guided risk assessments
with clear escalation to ECDD
duely assesses money laundering and terrorism financing (ML/TF) risk on each engagement using the AUSTRAC starter kit questions. Every rating carries a written rationale, and a high rating or another trigger moves the engagement into enhanced due diligence (ECDD).
The risk tab: the rating, what drove it, and whether enhanced due diligence is required. Sample data. See the full walkthrough
Why this matters
Risk is where firms often lose consistency. One person writes a paragraph. Another gives a traffic light score. Later, nobody can explain why the engagement was treated that way.
duely records the rating, the answers behind it, the rationale, and whether ECDD is required. When the rating is high, or another trigger applies (such as a politically exposed person (PEP) answer, a confirmed sanctions hit or a failed identity verification), the engagement moves into a structured ECDD path instead of an informal side conversation.
What's included
Low / Medium / High rating
Assign a structured risk rating based on assessed factors. The rating drives review frequency and ECDD requirements.
Structured risk triggers
Evaluate risk factors including customer type, geographic risk, product complexity, and transaction patterns.
Mandatory rationale
A risk rating cannot be saved without a written rationale explaining it.
ECDD when triggered
A high rating, a PEP answer, a confirmed sanctions hit or a failed identity verification opens a structured ECDD path with source of funds and source of wealth, including attachments. An approver (the AML/CTF compliance officer (AMLCO), or a user with the Approver role) signs it off.
Kit-format ECDD case structure
When an engagement escalates, ECDD follows the AUSTRAC starter kit's structure: an identity and risk section for each relevant party, ECDD actions tracked as requested, evidenced and completed, and a structured outcome. Enhanced due diligence runs as a defined workflow instead of a free-text note.
Version history
Track how risk assessments change over time. Each version records the rating, triggers, and rationale at that point.
Reassessment path
When new evidence changes the picture, reassess risk with a clear record of what changed and why.
What opens ECDD
Five things open an enhanced due diligence case.
| Trigger | What happens | Who is told |
|---|---|---|
| A High risk rating | Case opens on the engagement | AMLCO, by email |
| A PEP answer in the risk questionnaire | Case opens, even if the rating is Low or Medium | AMLCO, by email |
| A confirmed sanctions hit | Case opens, even if the rating is Low or Medium | AMLCO, by email |
| A failed identity verification | The customer rating is set to High and a case opens | AMLCO, by email |
| The AMLCO opens one manually | Case opens on any engagement | The AMLCO who opened it |
Once the actions are complete, an approver (the AMLCO, or a user with the Approver role) resolves the case. An engagement with an open ECDD case cannot be approved.
Risk assessment under Tranche 2
- Risk-based approach: low, medium, high ratings with documented rationale
- ECDD required for high-risk indicators (PEP, high-risk jurisdictions, complex structures)
- Source of funds and source of wealth are distinct ECDD requirements
- Every engagement is approved by an approver (the AMLCO, or a user with the Approver role), and ECDD is signed off by an approver
Related features
Other parts of the compliance workflow this connects to.
Identity Verification
Screening hits and verification outcomes are key inputs to the risk assessment.
See details →SMR Firewall
If suspicion arises during risk assessment, the AMLCO can escalate to an isolated shadow case.
See details →Evidence Packs
Risk assessment decisions and ECDD outcomes are captured in the evidence pack.
See details →Screening Sources
Screening hits that feed into risk come from these sanctions, law enforcement and PEP lists.
See details →Turn risk decisions into a consistent record
Structured risk assessment with documented rationale and clear ECDD escalation.