Separate scope from risk
First establish which designated service you provide. Then assess how that service can be misused. These are different questions. The fact that a service is regulated does not establish that every customer receiving it has the same risk. The fact that a customer appears ordinary does not remove the service from the law.
For services provided at or through an Australian permanent establishment, section 26C requires consideration of the designated services the business provides or proposes to provide. This includes related new or emerging technologies. At customer level, section 28 asks you to consider the actual service provided or proposed for that customer.
- Scope: what service?
Identify the designated service and its applicable conditions.
- Risk: how could it be misused?
Consider what the work enables and how assets or arrangements could be used.
Legal scope and service risk are separate
A familiar customer does not remove a service from scope. A regulated service does not give every customer the same risk.
Separate evidence questions. An answer to one does not settle the others.
Describe what the service enables
A useful description goes beyond the commercial name of the service. Identify what staff do, what decisions the customer controls, and whether the service changes the ownership, location or use of assets. Consider how a person might use that work to disguise a transaction or give an arrangement an appearance of legitimacy.
The legal assessment is of risks the business may reasonably face. It does not require a claim that misuse has already occurred. Section 26F connects those risks to suitable policies and controls. The assessment should therefore explain a plausible mechanism that a control can address.
Worked example: same customer, different work
Consider a practice serving an established company. A new instruction involves creating an additional entity and moving an asset into it. The fact that the practice has dealt with the company before is relevant background, but it does not explain the purpose of the new arrangement.
The practice describes the instruction, the parties and the intended outcome. It asks why the structure is needed and who will control it. This example does not establish that the instruction is suspicious or that every similar service is regulated. It shows why the substance of the work matters after the scope question is answered.
Make the result usable
Try to connect the risk statement to a practical decision. If the concern is hidden control, the response should help reveal and check control. If it is an unexplained funding arrangement, unrelated identity documents may not resolve it. A larger file is not necessarily a better response.
Record the assumptions about how the service operates. For example, a control may depend on staff seeing an instruction before assets move. If the process changes, that assumption may fail. This review method helps explain service risk without creating an unsupported numerical risk score or replacing the business's complete assessment.