Step 2 — Internal risk assessment
Once the client disclosure form is saved, a practitioner completes an internal risk assessment to assign the client a low, medium, or high risk rating. A medium or high rating automatically triggers Enhanced Due Diligence (EDD).
Completing the assessment in SBOS
- With the disclosure form saved, open the Risk assessment tab within the CDD run.
- Review each risk factor and record your response.
- SBOS calculates an overall rating based on your responses and any configured weighting rules.
- If the rating is medium or high, the EDD flag is set and subsequent steps reflect the elevated requirements.
- Save the assessment and advance to Step 3 — Verification of identity (VOI).
Overriding the calculated rating
An authorised compliance officer can manually override the system-calculated rating. The override, the reason, and the approver are recorded in the audit trail.
EDD is not optional
Where EDD is triggered, all additional steps required under your AML/CTF program must be completed before sign-off. Incomplete EDD will block the approval workflow.
Risk factors
The assessment considers the following factors. Scoring rules and weightings are configured by your compliance administrator.
| Factor | Considerations |
|---|---|
| Distance from economic activity | Complex structures, nominee arrangements, or layers that obscure who ultimately owns or controls the entity |
| Transaction characteristics | High-value, unusually complex, or economically unexplained transactions |
| Physical cash or virtual assets | Involvement of cash or cryptocurrency (e.g. Bitcoin, stablecoins) |
| Suspected or unusual activity | Any indicator of criminal behaviour or patterns outside the norm for the client type |
| PEP status | Domestic, international, or foreign PEP status for the client or any related party |
| Non-profit or charity involvement | |
| Third party acting on behalf of the client | |
| Unexplained wealth | Assets or income disproportionate to known legitimate sources |
| Remote-only interaction | Inability to verify the client's identity in person |
| High- or medium-risk jurisdiction | Residency in, or transactions with, a FATF-listed or AUSTRAC-flagged country |
Risk ratings and obligations
| Rating | Re-verification frequency | EDD required? |
|---|---|---|
| Low | Every 3 years | No |
| Medium | Every 18 months | Yes |
| High | Every 12 months | Yes |
EDD requirements are defined in your firm's AML/CTF program and may include additional document requests, senior management sign-off, or enhanced ongoing monitoring.
