Under the Australian AML/CTF Act 2006, a Money Laundering and Terrorism Financing (ML/TF) risk assessment is not a optional compliance exercise—it is the foundational pillar upon which your entire compliance program is built. AUSTRAC requires every Tranche 2 reporting entity to conduct and document a comprehensive risk assessment before finalising their written AML/CTF Program.

Whether you are managing a law firm, an accounting practice, a real estate agency, a conveyancing firm, a trust and company service provider (TCSP), a precious metals dealership, or a virtual asset service provider (VASP), you must systematically identify and evaluate the specific risks your business faces. This guide provides a practical, step-by-step framework to help your organisation meet this critical requirement.

What is an AML/CTF Risk Assessment?

An AML/CTF risk assessment is a structured process where a business identifies the ways in which its services could be exploited by criminals to launder money or finance terrorism. The goal is to determine the "inherent risk" of your operations and implement appropriate controls to reduce this to an acceptable level of "residual risk".

AUSTRAC adopts a **risk-based approach**. This means you are not expected to eliminate all risk; rather, you must understand where your greatest risks lie and allocate your compliance resources accordingly. A high-risk client or service requires stringent controls, while a low-risk client can be managed with standard procedures.

The Four Risk Categories to Assess

AUSTRAC requires reporting entities to evaluate their risk exposure across four primary categories. You must assess each of these categories in relation to your specific business operations:

1. Customer Risk

Different types of clients present different levels of ML/TF risk. You must evaluate your customer base and identify higher-risk segments, including:

2. Product and Service Risk

Certain services you provide are more attractive to money launderers because they can be used to move large sums of money or hide ownership. High-risk services include:

3. Delivery Channel Risk

The method you use to onboard clients and deliver services affects your risk exposure. For example, onboarding clients entirely online without face-to-face interaction carries a higher risk of identity fraud. Using third-party brokers or introducers also increases delivery channel risk, as you are relying on another party's compliance checks.

4. Geographic Risk

Geographic risk refers to the locations where your clients are based, where their funds originate, or where their transactions occur. You must monitor whether your clients have links to high-risk countries, tax havens, or jurisdictions subject to international sanctions (such as those listed on the DFAT Consolidated Sanctions List).

How to Conduct Your Risk Assessment

A practical risk assessment involves the following structured steps:

  1. Identify the Risks: Review your business model and list every designated service you provide. Identify potential vulnerabilities in how these services are delivered and who they are delivered to.
  2. Analyse the Risks: Assess the likelihood of each risk occurring and the potential impact it would have on your business (regulatory fines, reputational damage, operational disruption).
  3. Evaluate and Rate: Assign an "inherent risk rating" (Low, Medium, High, or Very High) to each identified risk factor.
  4. Apply Controls: Document the specific compliance controls you have in place to mitigate each risk (e.g., KYC checks, transaction monitoring, staff training).
  5. Determine Residual Risk: Re-evaluate the risk rating after taking your controls into account. This is your "residual risk". If the residual risk remains too high, you must implement additional controls.

Important: Your risk assessment must be committed to writing, formally approved by senior management, and reviewed at least annually. Failing to keep your risk assessment updated is a common audit failure.

Understanding Risk Ratings

To help structure your assessment, use a standard risk matrix combining Likelihood and Impact:

Common Mistakes to Avoid

During AUSTRAC audits, several recurring mistakes are identified in risk assessments:

Automate your AML Risk Assessments

CompliDesk includes a built-in, industry-specific risk assessment wizard that guides you through every step, automatically generating your risk register and linking it to your AML program.

Get Started Free

Frequently Asked Questions

Is an AML/CTF risk assessment mandatory for all Tranche 2 entities?
Yes. Under Part A of the AML/CTF Act, completing and documenting a risk assessment is a mandatory prerequisite before you can design or implement your written AML/CTF Program.
How is a risk assessment different from an AML/CTF program?
The risk assessment identifies and rates the specific money laundering risks your business faces. The AML/CTF Program is the document that outlines the policies, procedures, and systems your business will use to manage and mitigate those identified risks.
How often should a Tranche 2 entity update its ML/TF risk assessment?
You should review and update your risk assessment at least once every 12 months, or immediately if there is a material change to your business, such as offering a new service, targeting a new customer segment, or expanding into a new geographic market.

Related reading: Customer due diligence explained · Enhanced due diligence guide · Ongoing customer monitoring best practices · Frequently asked questions