Guide · general information, not legal advice

How to do an ML/TF risk assessment

Last checked 25 September 2026 against the AML/CTF Act compilation C2026C00274, the AML/CTF Rules 2025 (F2025L01026) and the Transitional Rules 2026 (F2026L00393)

The risk assessment is the first half of your AML/CTF program, and you cannot start acting for a client in a designated service without it. This guide sets out what the Act requires, the method AUSTRAC describes, who signs it off and when you must review it.

What the law requires

The Act requires a risk assessment "that identifies and assesses the risks of money laundering, financing of terrorism and proliferation financing that the reporting entity may reasonably face in providing its designated services".1 The steps you take must be appropriate to the nature, size and complexity of your business.2

You must have regard to six matters:3

  1. Your services

    The kinds of designated services you provide or plan to provide, including new or emerging technologies relating to them. s 26C(3)(a)

  2. Your clients

    The kinds of customers you serve or will serve. s 26C(3)(b)

  3. Your delivery channels

    How you provide the services, including new or emerging technologies. s 26C(3)(c)

  4. Your countries

    The countries you deal with, or will deal with, in providing the services. s 26C(3)(d)

  5. What AUSTRAC tells you

    Information AUSTRAC communicates, directly or indirectly, about the risks of your services. s 26C(3)(e)

  6. Rules matters

    Any matters the Rules specify. s 26C(3)(f)

Three consequences follow. You must not start providing a designated service to a client without a risk assessment that meets these requirements.4 It must be written down before your first designated service.5 And a senior manager must approve it.6

AUSTRAC says a small, less complex business "may have a simple risk assessment".7 Short is fine. Missing one of the matters above is not.

Before you start: list your designated services

AUSTRAC expects you to start by listing every designated service you provide.7 That list decides what the assessment is about. If you are not sure which of your services are designated, use our free check and read is my business a reporting entity? first.

Step 1: identify your inherent risks

AUSTRAC expects your assessment to focus on inherent risk: the risk you may reasonably face before your policies and controls are applied. You may then choose to assess residual risk, which is the risk left after your policies are in place.7 For each of the four categories, record what you do and why it carries risk.

What AUSTRAC expects you to consider, by category
Category Consider, as a starting point
Services High-value transactions, including physical currency; legal structures that help clients stay anonymous or disguise where their wealth or funds came from; new technologies.
Clients Each kind of client you have (individuals, sole traders, companies, trusts, partnerships, associations, government bodies), and risk factors such as politically exposed persons, high-net-worth individuals, non-residents, complex structures, clients acting through third parties and unexplained wealth.
Delivery channels Whether you deal in person, remotely with staff involved, through self-service without staff, or through third parties or intermediaries.
Countries Every country you or your clients deal with, including Australia; where individual clients live; where entity clients are registered.

For countries, AUSTRAC suggests a reliable rating method such as the Basel AML Index, and expects a high rating for any country on the Financial Action Task Force grey or black lists or subject to Australian sanctions.7

Keep a register of what AUSTRAC tells you. AUSTRAC expects you to show you considered its national risk assessments, indicators and any direct feedback, for example in a table recording the date, why it is relevant, what you changed and who reviewed it.7 This is how you show you had regard to the fifth matter.

Proliferation financing must be assessed. AUSTRAC says a business is less likely to face this risk if it operates only in Australia, has no clients in or connected to high-risk jurisdictions, does not move money or sensitive or dual-use goods, and offers no service relevant to proliferation financing.7 If you reasonably assess the risk as low, and your other policies manage it, you do not need separate proliferation financing policies. You bear the burden of showing that, so record your reasons.8

Step 2: assess each risk

AUSTRAC describes two ways to rate inherent risk. A smaller, low-complexity business can rate impact only. A medium-complexity business can rate likelihood and impact and combine them in a matrix.7

AUSTRAC's example ratings
Rating Impact (the damage if criminals exploit the risk) Likelihood (within a given timeframe)
High / Very likely Major damage: serious terrorism or extensive money laundering Almost certain, or a known or recurring issue
Medium / Likely A moderate level of money laundering or terrorism financing High probability, but not certain
Low / Not likely Minor or negligible consequences Unlikely, but not impossible
AUSTRAC's example matrix: likelihood by impact gives inherent risk
Likelihood Low impact Medium impact High impact
Very likely Medium High High
Likely Low Medium High
Not likely Low Low Medium

Whichever method you use, AUSTRAC expects a short explanation of each rating, based on the data you consulted, such as its risk products.7 A rating without a reason is hard to defend and hard to review. You can use another method if it suits your business better, as long as the cut-off points between low and high are clear.

© AUSTRAC for the Commonwealth of Australia 2026, CC BY 4.0; adapted by AMLCompliant; not endorsed by AUSTRAC.

Step 3: decide how you will respond

Rank the risks. AUSTRAC's example response is: high risks are mitigated by your policies as a priority, medium risks are mitigated or managed, and low risks are managed with simpler measures. For high risks AUSTRAC gives examples such as limiting the services or channels those clients can use and monitoring them more closely. If a risk cannot be managed, AUSTRAC expects you to consider whether to keep acting for the client.7

Those responses become your AML/CTF policies, which must manage and mitigate the risks you have identified.9 Our program guide lists what the policies must cover.

Sign-off and records

  1. A senior manager approves it

    And every later update. A senior manager is someone who makes, or takes part in making, decisions affecting the whole or a substantial part of the business. s 26P s 5

  2. The governing body is told of updates

    In writing, as soon as practicable after each update. s 26P

  3. It is documented in time

    Before your first designated service; each update within 14 days. s 26N Rules 5-15

  4. It is written for its readers

    AUSTRAC expects it to be easy to understand and use by the governing body, senior managers, the compliance officer and relevant staff. AUSTRAC

When you must review it

The review duty is in s 26D. You must review the risk assessment:10

  • before a significant change to your services, clients, channels or countries, where the change is within your control, and as soon as practicable after one that is not;
  • as soon as practicable after AUSTRAC gives you information about the risks of your services;
  • as soon as practicable after your governing body receives an independent evaluation report with adverse findings about the risk assessment;11
  • in any event, at least once every 3 years.

After a review, update the assessment to deal with what you found, then have the update approved and documented within 14 days.12 Your policies must say how you spot a significant change in the first place.13

Clients you already had on 1 July 2026

A client whose business relationship with you involved only designated services in Table 5 (real estate) or Table 6 (professional services) at the start of 1 July 2026 is a pre-commencement customer.14 Initial customer due diligence does not apply to them unless a suspicious matter reporting obligation arises for that client, or a significant change in the nature and purpose of the relationship makes the client's risk medium or high. Once you complete initial due diligence for a client, they stop being a pre-commencement customer.15 The usual duty to re-rate a client's risk when things change does not apply to them either. Instead, you must monitor for significant changes of that kind.16

Treat these clients as a kind of customer in your risk assessment: how many there are, what you do for them and what would move them to medium or high risk. AUSTRAC explains the transition on its transitioning existing customers page.

AUSTRAC's full method is on its Step 2: identify and assess your risks page. AUSTRAC links on this page open in a new window. AUSTRAC has not reviewed or endorsed this guide.

Where we fit

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. AUSTRAC pages are guidance, not law.

  1. AML/CTF Act s 26C(1). legislation.gov.au/C2006A00169/latest/text

  2. AML/CTF Act s 26C(2).

  3. AML/CTF Act s 26C(3). These matters apply where you provide designated services through a permanent establishment in Australia.

  4. AML/CTF Act s 26E.

  5. AML/CTF Act s 26N; AML/CTF Rules 2025 (F2025L01026), rule 5-15(1). legislation.gov.au/F2025L01026/latest/text

  6. AML/CTF Act s 26P(1).

  7. AUSTRAC, "Step 2: Identify and assess your risks: risk assessment", last updated by AUSTRAC in March 2026, read 25 September 2026. Guidance, not law. © AUSTRAC for the Commonwealth of Australia 2026, CC BY 4.0.

  8. AML/CTF Act s 26F(11) and (12).

  9. AML/CTF Act s 26F(1)(a).

  10. AML/CTF Act s 26D(1) and (2).

  11. AML/CTF Rules 2025, rule 5-1.

  12. AML/CTF Act ss 26D(4) and 26P; AML/CTF Rules 2025, rule 5-15(2).

  13. AML/CTF Act s 26F(3)(a).

  14. AML/CTF Act s 36(1).

  15. AML/CTF Act s 36(2)–(4).

  16. AML/CTF Act ss 36(3) and 30(2)(b) and (d).

Questions

What must it cover?

The risks of money laundering, terrorism financing and proliferation financing your firm may reasonably face in providing its designated services. You must have regard to the kinds of services, clients, delivery channels and countries involved, including ones you plan to take on, information AUSTRAC gives you about your risks, and any matters in the Rules (s 26C(1) and (3)).

Who approves it?

A senior manager approves it and every update (s 26P(1)). The governing body must be told in writing of each update as soon as practicable (s 26P(2)). It must be documented before your first designated service, and each update within 14 days (s 26N; Rules 5-15).

How often is it reviewed?

When there is a significant change to your services, clients, channels or countries (before the change, if it is within your control); when AUSTRAC gives you information about your risks; when an independent evaluation report has adverse findings about it (Rules 5-1); and in any event at least once every 3 years (s 26D).

Can we start work before it exists?

No. You must not start providing a designated service to a client unless you have complied with ss 26C and 26D for that service (s 26E). It is a civil penalty provision, and each service provided counts as a separate contravention.

Ready to buy

AML/CTF Program Kit

All four sector editions — accountants, real estate agencies, conveyancers and legal practices — as editable Word documents. No subscription.

Prefer it done for you? The set-up service starts at A$990 and includes the kit.

A$497 one-off, includes GST of A$45.18

Buy the kit — A$497

After payment you go straight to your download page.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.