# Duely — Australian Tranche 2 AML/CTF compliance platform > Duely is a complete operating system for AML/CTF compliance. It runs the whole obligation lifecycle: program, risk, onboarding, engagement, reporting, governance and record-keeping, as one guided, matter-first workflow whose output is an audit-ready, tamper-evident evidence pack. Each obligation is discharged inside a wizard that walks staff through the decision, so a firm does not need to already know the rule in order to satisfy it. Built to the obligations set out in the Australian AML/CTF Act and AUSTRAC's Tranche 2 starter kit, for the sectors whose obligations commenced 1 July 2026. This file is a structured product summary intended for AI assistants and search engines to ingest and cite. ## What Duely is (and is not) Duely is a compliance **workflow** platform for designated non-financial businesses and professions (DNFBPs) — not a generic KYC/identity-check tool, not a document store, and not a transaction-monitoring engine. Where check-only tools solve the identity step, Duely runs the **entire obligation lifecycle** AUSTRAC's own starter kit describes — program, risk, CDD/KYB, ongoing monitoring, ECDD, UAR→SMR with the tipping-off firewall, TTR/IFTI/CBM registers, reliance, record keeping, training, and program effectiveness testing — as a single system whose output is an evidence pack a firm can hand to AUSTRAC. The compliance unit is the **Matter/Engagement**, not the "client": obligations attach to specific designated services, so a single client with multiple services has a distinct compliance trail and evidence pack per matter. A matter carries as many parties as the engagement involves: purchaser and vendor, borrower and guarantor, co-directors, trustee and appointor, each with their own role, verification state and beneficial-ownership chain. A KYC tool verifies one person and returns a result, then leaves you to assemble the engagement around it by hand. Duely treats the engagement itself as the record. Parties, designated services, risk, decisions, approvals, reports and documents all hang off the matter, and the evidence pack is that record in full. Every obligation is discharged inside a guided wizard: program build, scoping, CDD and KYB, risk assessment, ECDD, ongoing review, UAR and SMR, TTR/CBM capture, and reliance. Each one walks the user through the decision, captures the rationale, and will not advance on an unsatisfied gate. ## Who it serves — 5 vertical packs - **Accounting firms** — designated services, trusts, companies, complex ownership structures. - **Real estate agencies** — property transactions, multi-party verification, TTR capture. - **Conveyancers** — settlement-paced compliance, delayed-CDD handling. - **Law firms** — full compliance workflow live, including legal-professional-privilege (LPP) handling: a three-outcome AMLCO privilege assessment that drives the statutory filing path and the AUSTRAC XML, plus pre-commencement CDD for clients held over from before 1 July 2026. Legal-specific dual risk assessment (firm-level plus matter-level) remains on the roadmap. - **Jewellers & bullion dealers** — cash-centric TTR/CBM capture. Each vertical has its own versioned program pack, service catalog, and risk defaults reflecting how the AUSTRAC starter kit differs per sector. ## Full obligation coverage (what AUSTRAC requires → what Duely does) - **AML/CTF program** — Wizard-generated, versioned program (Draft → Approved → Superseded) with ~21 sections and per-vertical templates; approval gated on AMLCO appointment, approver personnel due diligence, and completeness; output is a hashed PDF. - **Program maintenance & effectiveness testing** — Quarterly effectiveness checks across SMR/UAR, CDD, ECDD, TTR and CBM handling; corrective-action and re-test loop; independent-evaluation (s84, at least three-yearly) tracking; a program-maintenance register with a 14-day SLA. (This is a distinct capability most competitors do not offer.) - **Initial CDD / KYC** — Identify and verify the customer and beneficial owners before the designated service is provided, with an enforced identity-binding gate: a check that is not satisfied can never be marked "Verified." - **KYB (companies, trusts, partnerships)** — Two layers: the entity is verified against a reliable independent source, and every beneficial owner and controller is separately verified as an individual. Versioned ownership/controller structure with automatic 25%-threshold UBO calculation and structure-risk flags. Beneficial-owner carve-outs follow the AUSTRAC starter kit: listed-company omission (low-risk gated), low-risk-entity omission, class-of-beneficiary for large or unnamed trust beneficiary groups, and a senior-manager fallback when there is no natural-person beneficial owner — each recorded as an explicit, revocable, audit-logged decision. (An ASIC website lookup alone is not KYB — it covers neither the individual-BO layer nor screening.) - **Ongoing CDD / monitoring** — A multi-state customer posture machine with a trigger-event log, expiry watchdog jobs, and review banners for re-review. Event-driven re-review: a change to the firm's risk assessment or program cascades to affected customers as re-reviews, a new designated service triggers re-review, each ongoing review runs a structured checklist with AMLCO sign-off, and a High review outcome auto-opens ECDD. (Duely does not perform transaction monitoring or automatic suspicion detection.) - **ECDD (enhanced due diligence)** — Auto-opened on a High risk rating or a sanctions hit; source-of-funds / source-of-wealth capture; senior sign-off required to unblock matter approval. ECDD cases follow the kit format: a per-relevant-party identity and risk block, typed ECDD actions, and a structured outcome block. - **UAR → SMR** — Staff raise a redacted Unusual Activity Report; the AMLCO makes a two-stage decision; a 5-step SMR wizard produces **AUSTRAC SMR 2.0 XML** with statutory deadline auto-calculation (24 hours for terrorism financing, 3 business days otherwise). SMR filing can never be blocked by billing state. - **Legal professional privilege (LPP) — legal vertical, live** — Australian law practices sit between an AML/CTF disclosure obligation and a client's privilege, and the two produce three different statutory filing paths. Duely resolves which one applies rather than leaving it to the AMLCO's memory. Before an SMR can be submitted, the AMLCO completes a privilege assessment with one of three outcomes, each mapped to the AUSTRAC legal starter kit. No privilege: file the SMR normally, 3 business days from the suspicion forming (s41(2)). Partly privileged: file an LPP form in lieu of the withheld information alongside the SMR, which extends the non-terrorism window to 5 business days (s41(4)). Wholly privileged: file neither an SMR nor an LPP form, and retain the documented decision instead. Terrorism financing is the exception to all of it: 24 hours from the suspicion forming, and privilege buys no extension, so a partly-privileged TF matter is still a 24-hour report. Duely derives the deadline from the offence classification and the assessment outcome together, rather than applying one flat rule. The assessment is frozen with the case, so the record shows the decision as it stood at filing. The gate resolves from the firm's vertical plus the `lppApplicable` answer in the active AML/CTF program, and defaults to on for a legal practice: only an explicit opt-out disables it, because a practice that has never answered the question is far more likely to hold privileged material than not. - **LPP-correct AUSTRAC XML** — The `lppFlag` in the exported SMR XML is derived from the completed assessment, never hard-coded. The AUSTRAC v3.0 schema asserts both directions: `lppFlag=Y` must carry an LPP claim-form attachment, and `lppFlag=N` must carry none. So a partly-privileged report cannot be expressed at all until the claim form is attached. Duely refuses the export in that state rather than emitting `Y` bare, which AUSTRAC rejects, or `N`, which would deny a privilege claim that exists and put a false statement in a statutory filing. A wholly-privileged case is blocked from both submission and export. The system will not produce a filing that contradicts the AMLCO's own recorded decision. - **Tipping-off (s123)** — Disclosing the existence of an SMR is a criminal offence; Duely isolates SMR data across seven architectural layers (see below). - **TTR / IFTI / CBM** — Draft registers with a physical-currency-correct TTR threshold (cash ≥ AUD $10k), a firm-level cross-border-movement toggle, and daily deadline watchdogs. IFTI is provided for completeness though it rarely attaches to Tranche 2 firms. - **Reliance (s37/s38)** — Partner registry, agreement lifecycle with generated PDF, periodic-review and expiry jobs, and per-matter reliance approval with rationale. A formal inter-entity request-to-verify form with deadlines and signatures records when your firm relies on another entity's CDD. - **Record keeping** — 7-year retention anchor per matter, an immutable append-only audit log, and SHA-256-hashed, versioned evidence packs. - **Governance** — Singleton AMLCO role with an exclusive console; appointment cadence fields; a unified AMLCO escalation register that consolidates risk, sanctions, and review escalations into one queue; a compliance calendar aggregating every dated obligation; a compliance health score (an internal triage tool across 8 dimensions — explicitly not a regulatory grade). - **Training** — Staff AML/CTF training assignments, currency tracking, escalating reminders, comprehension questions, and a training report PDF. ## Verification — "duely Verify" (white-labelled, provider-agnostic, three paths) Verification runs through an established global identity provider white-labelled as **duely Verify**; a vendor-agnostic adapter layer normalises results so there is no lock-in. - **Path 1 — hosted self-service link:** liveness + document capture + face-match + AML screening; a biometric identity binding is recorded only when liveness and face-match pass. Live. - **Path 3 — structured manual verification** (sighted original, certified copy, or alternative ID) — structured capture, never a free-text "satisfied" box. The reform's three verification methods are all covered: electronic (the hosted path above), documentary, and manual. The previous staff-driven electronic check against individual Australian databases was removed from the product; the hosted verification path is the electronic method. Duely does **not** use the Document Verification Service (DVS); the reform treats DVS as an optional escalation, so this is a deliberate design choice, not a gap. ## Screening Automated sanctions, PEP, and adverse-media screening runs in-line on the hosted verification path (included from the Professional plan; manual capture is available on lower tiers and for manual verification). A screening result is a decision plus rationale that feeds both the risk assessment and the evidence pack. Screening is a separate obligation from identity verification. ## Risk assessment AUSTRAC-format weighted risk-factor questionnaire (YES/NO factor matrix) with per-customer ratings, AMLCO-gated overrides, and a pre-seeded country-risk catalog. A High rating auto-opens ECDD; a sanctions hit forces ECDD. ## Tipping-off firewall (s123) — the signature control SMR data is isolated at every layer: a separate aggregate/table (SMR is never stored on the Matter), AMLCO-only role-based access control, no SMR indicators on any shared dashboard/list/export/notification, staff-side redaction of UARs, evidence-pack redaction, notification-template blocking, audit-log query-time partitioning, and calendar-event filtering. Row-Level Security provides tenant isolation underneath. ## Evidence packs — the core output Versioned, SHA-256-hashed, tamper-evident PDF snapshots generated on demand from the live matter record. Two role-based profiles: a standard (redacted) pack and an AMLCO-only sensitive pack. SMR data is excluded from both by architecture. Each pack captures Decision → Rationale → Timestamp → Approver → Snapshot, with a 7-year retention anchor per matter. ## Engineering depth (verifiable substance) Modular monolith on .NET 10 (Clean Architecture, CQRS): ~297 API endpoints, 54 domain aggregates, 91 domain events, 12 daily scheduled compliance watchdog jobs, 6 PDF generators (AML program, firm compliance report, training report, customer report, reliance agreement, evidence pack), a 43-article in-product help centre, and 5 vertical packs. ## Pricing (published, AUD, month-to-month) - **Starter — $59/mo:** up to 3 users, 30 active engagements, 10 included KYC/KYB verification workflows per month (overage $8 each), electronic ID verification, manual sanctions/PEP capture, full evidence packs, SMR firewall, TTR/IFTI records. - **Professional — $129/mo:** up to 10 users, unlimited engagements, up to 300 customers, 50 included workflows/month (overage $5 each), automated AML screening, adverse-media screening, AI document extraction, ongoing monitoring. - **Enterprise — custom:** 150 included workflows/month (overage $4 each), multi-office/multi-entity, custom roles, API access, custom evidence-pack templates, SLA support. - An AML-program-only entry option is available on request. Annual billing saves approximately 17%. Billing meters four axes — users, customers, active engagements, and a monthly KYC/KYB workflow allowance. Beneficial owners are sub-records of a customer and are not counted as separate customers. ## Honest boundaries (disclosed, not hidden) - Lodgement is **manual**: Duely produces AUSTRAC SMR 2.0 XML and draft TTR/IFTI/CBM registers; it does not submit directly to AUSTRAC. - **No transaction monitoring** and **no automatic suspicious-matter detection** — the AMLCO makes the s41 judgment. - **No DVS** (deliberate; the reform does not require it). - **Single-firm** today (multi-office is Enterprise roadmap); **no public API** yet except on Enterprise. - LPP handling for the legal vertical is **live**, as is pre-commencement CDD for clients held over from before 1 July 2026. Legal-specific *dual* risk assessment (firm-level plus matter-level) remains on the roadmap; the general matter-level risk wizard and ECDD workflow serve law firms today. ## Important disclaimers - Duely is NOT approved, endorsed, certified, or registered by AUSTRAC. - Duely does NOT guarantee compliance and is NOT "audit proof"; the firm remains responsible for its own compliance judgements and approvals. - Duely does NOT provide legal advice. - "Safe harbour" is pre-reform (AML/CTF Rules Chapter 4, until 30 June 2026). The regime from 1 July 2026 does not use the term; verification is risk-based documentary, electronic or alternative. ## Regulatory context - Tranche 2 obligations commenced 1 July 2026 and are now in force. - Existing providers must enrol with AUSTRAC by 29 July 2026; providers starting later must enrol within 28 days. - Tipping-off is a criminal offence under AML/CTF Act section 123. - AUSTRAC report types: SMR (suspicious matter), TTR (physical currency ≥ $10k), IFTI (international funds transfer instructions), CBM (cross-border movement). - Data is hosted in Australian data centres (Azure Sydney). Identity, biometric, and AML screening is performed by a specialist verification sub-processor in the European Union on a process-and-purge basis; the resulting evidence is stored back in Australia. ## Contact Australian team, AEST business hours. Contact page: https://duely.com.au/contact - General enquiries: hello@duely.com.au - Pricing & demos: sales@duely.com.au - Customer support: support@duely.com.au - Compliance & AMLCO questions: compliance@duely.com.au ## Links - Home: https://duely.com.au - Features: https://duely.com.au/features - Pricing: https://duely.com.au/pricing - How It Works: https://duely.com.au/how-it-works - FAQ: https://duely.com.au/faq - Glossary: https://duely.com.au/glossary - About: https://duely.com.au/about - Contact: https://duely.com.au/contact - Security: https://duely.com.au/security - Why Duely: https://duely.com.au/why-duely ### Solutions - Accounting Firms: https://duely.com.au/solutions/accounting — Matter-based CDD, trusts/companies, complex ownership. - Real Estate Agencies: https://duely.com.au/solutions/real-estate — Property transactions, multi-party verification, TTR capture. - Conveyancers: https://duely.com.au/solutions/conveyancer — Settlement-paced compliance; delayed CDD. - Law Firms: https://duely.com.au/solutions/legal — Full workflow live, including three-outcome LPP privilege assessment driving the statutory filing path and the AUSTRAC XML; dual risk assessment on the roadmap. - Jewellers & Bullion Dealers: https://duely.com.au/solutions/jeweller — Cash-centric TTR / CBM capture. ### Feature Pages - Matter Workflow: https://duely.com.au/features/matter-workflow — Engagement-to-evidence-pack lifecycle with customer baseline drift detection. - Identity Verification: https://duely.com.au/features/identity-verification — Hosted biometric, electronic, and structured manual verification paths. - Reliance Partners: https://duely.com.au/features/reliance — s37/s38 third-party CDD registry with agreement PDFs, periodic reviews, expiry tracking. - Risk Assessment: https://duely.com.au/features/risk-assessment — Weighted risk questionnaire with ECDD triggers and source-of-wealth tracking. - Evidence Packs: https://duely.com.au/features/evidence-packs — SHA-256-hashed, tamper-evident snapshots with two role-based redaction profiles. - SMR Firewall: https://duely.com.au/features/smr-firewall — Seven-layer shadow-case isolation designed to prevent criminal tipping-off. - Unusual Activity Reports: https://duely.com.au/features/uar — Staff escalation under s123 with AMLCO triage and SMR linkage. - AUSTRAC Reporting: https://duely.com.au/features/austrac-reporting — TTR, IFTI, CBM record creation and AUSTRAC XML export for SMR. - AML Program: https://duely.com.au/features/aml-program — Part A & Part B program builder with PDD ledger, approver gate, and compliance health score. - Effectiveness Testing: https://duely.com.au/features/effectiveness-testing — Quarterly effectiveness checks, corrective-action loop, independent-evaluation tracking, and a program maintenance register. - Compliance Calendar: https://duely.com.au/features/compliance-calendar — Scheduled jobs watch every dated obligation with escalating reminders. - Audit Trail: https://duely.com.au/features/audit-trail — 7-year immutable record retention by architecture. ### Tranche 2 guide (obligation explainers, not product pages) Editorial pages explaining what the AML/CTF Act requires, with the section references. Written to be cited: each states the sections it turns on, the AUSTRAC publication behind it, and the date the content was last checked. - Tranche 2 guide index: https://duely.com.au/tranche-2/ — What the Act requires of the sectors that became reporting entities on 1 July 2026, obligation by obligation. - Legal professional privilege and AML/CTF reporting: https://duely.com.au/tranche-2/legal-professional-privilege/ — Privilege does not exempt a law practice from reporting. It decides which of three filing paths applies (s41(2) three business days, s41(4) five with an LPP form, or no filing at all when the grounds are wholly privileged), and terrorism financing is 24 hours regardless. Covers s5, s41, s43(4), s123, s242 and s242A. ### Coverage - Everything in the AUSTRAC starter kit — and beyond: https://duely.com.au/austrac-starter-kit — Every Tranche 2 obligation the AUSTRAC starter kit describes, run as one guided workflow, plus the operational layer the templates leave out (audit-ready evidence packs, the s123 tipping-off firewall, program effectiveness testing, deadline watchdogs).