AML/CTF and customer due diligence (CDD)
SBOS includes a built-in AML/CTF compliance module so your firm meets Customer Due Diligence (CDD) obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), as amended by the Tranche 2 reforms effective 1 July 2026.
Matters for offerings marked as designated services must go through the AML/CTF process before the matter can be progressed.
The CDD workflow
Each new client onboarding or relevant matter creation follows five sequential steps. These steps can all be completed via the matter's AML/CTF page.
- Client disclosure - Collect entity-specific KYC information using the client disclosure form
- Risk assessment - Score the client's risk profile (low / medium / high)
- Verification of identity (VOI) - Establish the UBO (Ultimate Business Owner) structure and issue identity checks to each UBO
- PEP & sanctions screening - Screen all UBOs and the entity against DFAT, PEP (Politically Exposed Person) records, and adverse media
- Sign-off - Compliance officer approves and locks the decision with a full audit trail
Where to find AML tools
- Compliance → AML dashboard - Portfolio view of all active CDD runs. Requires
ReleasePermission.BetaandCddProfile.View. - Contact/Organisation/Client → AML tab - Start or continue a CDD run for a specific entity. Requires
ReleasePermission.BetaandCddProfile.View. This can also be completed for the entity from the relevant Matter. - Matter → AML tab - Matter-level CDD gate. Requires
ReleasePermission.BetaandMatterAmlGate.View. - CDD run detail - Full detail view for a single CDD run. Requires
CddRun.View.
Key rules
- One CDD pack per matter: A separate pack is required for each matter, even for existing clients. VOI results can be reused across matters - the disclosure form and risk assessment cannot. If the client for the matter is made up of an organisation and a contact, CDD should only be completed for the party the work relates to the most, not both.
- Re-verification is risk-based: Every 3 years (low), 18 months (medium), 12 months (high).
- Audit trail is mandatory: A complete record of every decision must be retained in the system. The trail is locked on sign-off.
Roles and permissions
AML features use fine-grained permissions including CddProfile.View, MatterAmlGate.View, CddRun.View, CddRun.Approve, and ReleasePermission.Beta. If a menu entry is missing, request access from your administrator.
Never share screenshots of verification data or screening results outside approved channels.
