Under the Australian AML/CTF Act 2006, a Money Laundering and Terrorism Financing (ML/TF) risk assessment is not a optional compliance exercise—it is the foundational pillar upon which your entire compliance program is built. AUSTRAC requires every Tranche 2 reporting entity to conduct and document a comprehensive risk assessment before finalising their written AML/CTF Program.
Whether you are managing a law firm, an accounting practice, a real estate agency, a conveyancing firm, a trust and company service provider (TCSP), a precious metals dealership, or a virtual asset service provider (VASP), you must systematically identify and evaluate the specific risks your business faces. This guide provides a practical, step-by-step framework to help your organisation meet this critical requirement.
What is an AML/CTF Risk Assessment?
An AML/CTF risk assessment is a structured process where a business identifies the ways in which its services could be exploited by criminals to launder money or finance terrorism. The goal is to determine the "inherent risk" of your operations and implement appropriate controls to reduce this to an acceptable level of "residual risk".
AUSTRAC adopts a **risk-based approach**. This means you are not expected to eliminate all risk; rather, you must understand where your greatest risks lie and allocate your compliance resources accordingly. A high-risk client or service requires stringent controls, while a low-risk client can be managed with standard procedures.
The Four Risk Categories to Assess
AUSTRAC requires reporting entities to evaluate their risk exposure across four primary categories. You must assess each of these categories in relation to your specific business operations:
1. Customer Risk
Different types of clients present different levels of ML/TF risk. You must evaluate your customer base and identify higher-risk segments, including:
- Politically Exposed Persons (PEPs): Individuals holding prominent public positions, or their close associates, who may be vulnerable to corruption.
- Complex corporate structures: Entities with multi-layered offshore ownership, shell companies, or discretionary trusts where the ultimate beneficial owners are obscured.
- Cash-intensive businesses: Clients operating businesses that handle large volumes of physical cash (e.g., retail, hospitality, cash-in-transit).
- Non-resident clients: Clients located overseas, particularly in jurisdictions with weak AML regulatory frameworks.
2. Product and Service Risk
Certain services you provide are more attractive to money launderers because they can be used to move large sums of money or hide ownership. High-risk services include:
- Legal & Conveyancing: Managing client trust accounts, facilitating real estate transactions, or establishing complex corporate structures.
- Accounting: Acting as a nominee director or trustee, or managing transaction flows.
- TCSPs: Setting up express trusts or shell companies in offshore tax havens.
- VASPs: Facilitating anonymous cryptocurrency transfers or high-volume digital asset exchanges.
- Precious Metals: High-value cash transactions for gold or bullion.
3. Delivery Channel Risk
The method you use to onboard clients and deliver services affects your risk exposure. For example, onboarding clients entirely online without face-to-face interaction carries a higher risk of identity fraud. Using third-party brokers or introducers also increases delivery channel risk, as you are relying on another party's compliance checks.
4. Geographic Risk
Geographic risk refers to the locations where your clients are based, where their funds originate, or where their transactions occur. You must monitor whether your clients have links to high-risk countries, tax havens, or jurisdictions subject to international sanctions (such as those listed on the DFAT Consolidated Sanctions List).
How to Conduct Your Risk Assessment
A practical risk assessment involves the following structured steps:
- Identify the Risks: Review your business model and list every designated service you provide. Identify potential vulnerabilities in how these services are delivered and who they are delivered to.
- Analyse the Risks: Assess the likelihood of each risk occurring and the potential impact it would have on your business (regulatory fines, reputational damage, operational disruption).
- Evaluate and Rate: Assign an "inherent risk rating" (Low, Medium, High, or Very High) to each identified risk factor.
- Apply Controls: Document the specific compliance controls you have in place to mitigate each risk (e.g., KYC checks, transaction monitoring, staff training).
- Determine Residual Risk: Re-evaluate the risk rating after taking your controls into account. This is your "residual risk". If the residual risk remains too high, you must implement additional controls.
Important: Your risk assessment must be committed to writing, formally approved by senior management, and reviewed at least annually. Failing to keep your risk assessment updated is a common audit failure.
Understanding Risk Ratings
To help structure your assessment, use a standard risk matrix combining Likelihood and Impact:
- Low Risk: Standard compliance controls are sufficient (e.g., local individual clients undergoing standard KYC).
- Medium Risk: Requires regular monitoring and standard verification (e.g., domestic operating companies).
- High Risk: Requires Enhanced Due Diligence (EDD) and senior management approval (e.g., foreign PEPs, complex discretionary trusts).
Common Mistakes to Avoid
During AUSTRAC audits, several recurring mistakes are identified in risk assessments:
- Using a generic template: Simply copying a generic risk assessment without tailoring it to the actual services your firm provides.
- Underestimating risk: Rating all services as "low risk" to avoid implementing more stringent controls.
- Failing to document the methodology: Not explaining how you arrived at your risk ratings.
- Disconnect from the AML Program: Having a risk assessment that identifies high risks, but an AML Program that fails to apply corresponding controls.
Automate your AML Risk Assessments
CompliDesk includes a built-in, industry-specific risk assessment wizard that guides you through every step, automatically generating your risk register and linking it to your AML program.
Get Started FreeFrequently Asked Questions
Related reading: Customer due diligence explained · Enhanced due diligence guide · Ongoing customer monitoring best practices · Frequently asked questions