# Console KYC reliance and onboarding assistance schedule Version 2.3 | Published 28 September 2026 Read with your completed account and service particulars. 1. Parties and selected route ----------------------------- Relying reporting entity: [exact legal entity, designated service, AUSTRAC details]. Supplying Firm: [legal name, reporting entity or eligible foreign status, jurisdiction, contact]. Idealx Platform's role: [relying entity / administrative facilitator for identified reporting entity]. Additional providers relying on this work: [separately identified accepting parties]. No automatic reliance by every Idealx group company, payment provider or execution provider arises. The default is document transmission only. Formal reliance or outsourced verification remains inactive until the required parties approve a completed route record. Select and document one route for each scope: (A) ongoing statutory reliance; (B) case-by-case statutory reliance; (C) outsourced/agency collection and verification; or (D) document transmission only. A Console login does not activate any route. The Firm's AFSL, professional membership or client mandate alone does not establish eligibility for statutory reliance. 2. Formal reliance ------------------ Before activation, establish eligible reporting-entity/foreign-equivalent status and document risk suitability, scope and standards. For ongoing reliance, obtain the required senior-manager approval of this written arrangement. Identify client types, jurisdictions, information covered, service exclusions and additional checks. Obtain required KYC information before service or within a legally available delayed-CDD period. Verification evidence must be accessible immediately or as soon as practicable; contractual maximum one business day, with faster access where risk requires. Assess ongoing arrangements at least every two years and on material change, more often where risk warrants; record assessments within ten business days. If reliance conditions fail, stop relying and perform required remediation. No automatic re-performance of valid verification is required merely because another eligible firm performed it. For case-by-case reliance, record eligibility, risk justification and grounds for timely access to information/evidence for that customer. It is not a substitute for documenting repeated ongoing arrangements. No contractual immunity from statutory responsibilities is provided. 3. Evidence and service delivery -------------------------------- The Firm must supply genuine, complete and accurate records of work actually performed, identifying the customer, relevant beneficial owners/representatives, verification date, method, source, scope and unresolved discrepancies as required by the accepted scope. A bare 'KYC passed' statement does not replace required information. No representation is made that every data item is required for every customer; the agreed applicable standard controls. The Firm must lawfully obtain and share information, preserve evidence for applicable retention periods, maintain access after termination for required records and promptly notify material deficiencies, loss of eligibility, record-access failures or relevant security incidents. Use secure named-user channels. Do not require sharing suspicious-matter reports or protected information where prohibited; escalation and information sharing must respect privacy, privilege, confidentiality and tipping-off restrictions. Ordinary record exchange is included in this schedule unless a separate price is accepted. No automatic investor KYC fee is created. Remediation costs caused by the Firm's proven breach may be recovered under the proportionate Console indemnity, excluding Idealx's contribution and non-indemnifiable penalties. 4. Residual functions and assistance routes ------------------------------------------- Each actual reporting entity retains duties applicable to its services that are not discharged by valid reliance, including its risk assessment, ongoing due diligence, enhanced checks and reporting where required. Allocating performance of a task is not the same as transferring statutory responsibility. Platform does not voluntarily become the reporting entity for another provider merely by operating the interface. For agency/outsourcing, specify tasks, controls, deliverables and the principal reporting entity. That entity's applicable liability remains; this route must not be labelled statutory reliance. For document transmission, the Firm supplies records and the receiving provider determines their sufficiency under its own process. The receiving provider may accept reusable evidence, request only missing or outdated information, or require fresh checks where justified. No blanket obligation to repeat all onboarding is imposed by this contract. Reliance does not prove client consent to trades, account mandates or fees; those use their separate evidence. Each provider may impose its own lawful onboarding requirements; Idealx cannot bind a payment provider or broker to accept another firm's checks without its agreement. 5. Approval, suspension and acceptance record --------------------------------------------- Record selected route, exact relying party, regulatory eligibility, agreed data fields and evidence access, permitted clients/services, responsibility allocation, risk assessment, required approvals, review triggers and effective date before reliance begins. The Firm accepts electronically through its authorised signatory; the relying entity records its own approval. Add the schedule to the Firm's accepted documents and make the client-facing privacy/collection notices accurate. Suspend new reliance where eligibility or evidence is inadequate; preserve necessary access and remediate affected customers under the applicable AML/CTF process. Ending reliance need not automatically end unrelated Console functionality. No existing firm is represented as approved under this draft. Platform and the Firm also accept document 24 for shared records and security. If another Idealx entity is the relying party, its documented accession or authorised agency acceptance is required. Platform cannot bind an unnamed reporting entity solely through the Firm's checkbox.