Skip to content

Step 6: Risk profile & decision

Every party is verified, the screenings are in, and the client is at Pending compliance. The decision is now taken in the Risk profile card at the bottom of the client’s Information tab. It holds both halves of the four-eyes control: the compliance judgement and the management decision.

FieldWho fills it inWhat it is for
Risk initial classificationRead-onlyThe risk the file started with: Low, Medium, High or Unacceptable.
Risk final classificationComplianceThe risk classification compliance settles on after assessing the file.
Does the MLCO agree with AML/CFT compliance?ComplianceThe compliance judgement itself: Yes or No.
Is the client approved by management?ManagementThe final decision: Yes or No.
Risk mitigationComplianceWhich measures reduce the identified risk.
Risk remarksComplianceRemarks about the risk assessment.
Additional information / RemarksAnyone with accessFree space for anything else worth recording in the file.

Press Save to store your changes. Once one of the three editable dropdowns has a value, it also offers Neutral, which clears the field again.

The two dropdowns unlock one after the other, which is what makes the four-eyes principle work: the person who judges the compliance is never the person who approves the client.

flowchart LR
    A[Pending<br>compliance] -->|MLCO agrees: Yes| B[Compliance<br>agrees]
    A -->|MLCO agrees: No| C[Compliance<br>disagrees]
    B --> D[Accepted]
    B --> E[Declined]
    C --> D
    C --> E
  1. The compliance officer opens the client’s Information tab and works through the file: the parties and their verification, the screening reports, the documents and the company information.

  2. Set the Risk final classification and write down the risk mitigation and risk remarks.

  3. Answer Does the MLCO agree with AML/CFT compliance? with Yes or No.

  4. Save.

The client’s status becomes Compliance agrees or Compliance disagrees, and every party of the client follows that status.

Once compliance has given its judgement, the Is the client approved by management? dropdown unlocks for management: the CEO or a managing director. Set it to Yes or No and save.

  • Yes → the client’s status becomes Accepted.
  • No → the client’s status becomes Declined.

When the decision is made:

  • The client’s status becomes Accepted or Declined, visible to your whole team in the client list.
  • Every party of the client shows Compliance agrees (or Compliance disagrees).
  • The complete risk profile is stored on the client and is visible to everyone with access to the Information tab.
  • Every status change along the way is recorded on the Audit trail tab, together with the screenings, emails and internal notes, so you can always show how the decision was reached.

The risk profile can also be included as the last page of the PDF export of the client, so the assessment travels with the dossier.

The file remains active after the decision: the client company keeps being monitored daily, changes a party makes via the client portal are tracked, and the ownership structure can keep evolving. The After onboarding section covers this next phase.