What the law requires
The Act requires a risk assessment "that identifies and assesses the risks of money laundering, financing of terrorism and proliferation financing that the reporting entity may reasonably face in providing its designated services".1 The steps you take must be appropriate to the nature, size and complexity of your business.2
You must have regard to six matters:3
Your services
The kinds of designated services you provide or plan to provide, including new or emerging technologies relating to them. s 26C(3)(a)
Your clients
The kinds of customers you serve or will serve. s 26C(3)(b)
Your delivery channels
How you provide the services, including new or emerging technologies. s 26C(3)(c)
Your countries
The countries you deal with, or will deal with, in providing the services. s 26C(3)(d)
What AUSTRAC tells you
Information AUSTRAC communicates, directly or indirectly, about the risks of your services. s 26C(3)(e)
Rules matters
Any matters the Rules specify. s 26C(3)(f)
Three consequences follow. You must not start providing a designated service to a client without a risk assessment that meets these requirements.4 It must be written down before your first designated service.5 And a senior manager must approve it.6
AUSTRAC says a small, less complex business "may have a simple risk assessment".7 Short is fine. Missing one of the matters above is not.
Before you start: list your designated services
AUSTRAC expects you to start by listing every designated service you provide.7 That list decides what the assessment is about. If you are not sure which of your services are designated, use our free check and read is my business a reporting entity? first.
Step 1: identify your inherent risks
AUSTRAC expects your assessment to focus on inherent risk: the risk you may reasonably face before your policies and controls are applied. You may then choose to assess residual risk, which is the risk left after your policies are in place.7 For each of the four categories, record what you do and why it carries risk.
| Category | Consider, as a starting point |
|---|---|
| Services | High-value transactions, including physical currency; legal structures that help clients stay anonymous or disguise where their wealth or funds came from; new technologies. |
| Clients | Each kind of client you have (individuals, sole traders, companies, trusts, partnerships, associations, government bodies), and risk factors such as politically exposed persons, high-net-worth individuals, non-residents, complex structures, clients acting through third parties and unexplained wealth. |
| Delivery channels | Whether you deal in person, remotely with staff involved, through self-service without staff, or through third parties or intermediaries. |
| Countries | Every country you or your clients deal with, including Australia; where individual clients live; where entity clients are registered. |
For countries, AUSTRAC suggests a reliable rating method such as the Basel AML Index, and expects a high rating for any country on the Financial Action Task Force grey or black lists or subject to Australian sanctions.7
Keep a register of what AUSTRAC tells you. AUSTRAC expects you to show you considered its national risk assessments, indicators and any direct feedback, for example in a table recording the date, why it is relevant, what you changed and who reviewed it.7 This is how you show you had regard to the fifth matter.
Proliferation financing must be assessed. AUSTRAC says a business is less likely to face this risk if it operates only in Australia, has no clients in or connected to high-risk jurisdictions, does not move money or sensitive or dual-use goods, and offers no service relevant to proliferation financing.7 If you reasonably assess the risk as low, and your other policies manage it, you do not need separate proliferation financing policies. You bear the burden of showing that, so record your reasons.8
Step 2: assess each risk
AUSTRAC describes two ways to rate inherent risk. A smaller, low-complexity business can rate impact only. A medium-complexity business can rate likelihood and impact and combine them in a matrix.7
| Rating | Impact (the damage if criminals exploit the risk) | Likelihood (within a given timeframe) |
|---|---|---|
| High / Very likely | Major damage: serious terrorism or extensive money laundering | Almost certain, or a known or recurring issue |
| Medium / Likely | A moderate level of money laundering or terrorism financing | High probability, but not certain |
| Low / Not likely | Minor or negligible consequences | Unlikely, but not impossible |
| Likelihood | Low impact | Medium impact | High impact |
|---|---|---|---|
| Very likely | Medium | High | High |
| Likely | Low | Medium | High |
| Not likely | Low | Low | Medium |
Whichever method you use, AUSTRAC expects a short explanation of each rating, based on the data you consulted, such as its risk products.7 A rating without a reason is hard to defend and hard to review. You can use another method if it suits your business better, as long as the cut-off points between low and high are clear.
Step 3: decide how you will respond
Rank the risks. AUSTRAC's example response is: high risks are mitigated by your policies as a priority, medium risks are mitigated or managed, and low risks are managed with simpler measures. For high risks AUSTRAC gives examples such as limiting the services or channels those clients can use and monitoring them more closely. If a risk cannot be managed, AUSTRAC expects you to consider whether to keep acting for the client.7
Those responses become your AML/CTF policies, which must manage and mitigate the risks you have identified.9 Our program guide lists what the policies must cover.
Sign-off and records
A senior manager approves it
And every later update. A senior manager is someone who makes, or takes part in making, decisions affecting the whole or a substantial part of the business. s 26P s 5
The governing body is told of updates
In writing, as soon as practicable after each update. s 26P
It is documented in time
Before your first designated service; each update within 14 days. s 26N Rules 5-15
It is written for its readers
AUSTRAC expects it to be easy to understand and use by the governing body, senior managers, the compliance officer and relevant staff. AUSTRAC
When you must review it
The review duty is in s 26D. You must review the risk assessment:10
- before a significant change to your services, clients, channels or countries, where the change is within your control, and as soon as practicable after one that is not;
- as soon as practicable after AUSTRAC gives you information about the risks of your services;
- as soon as practicable after your governing body receives an independent evaluation report with adverse findings about the risk assessment;11
- in any event, at least once every 3 years.
After a review, update the assessment to deal with what you found, then have the update approved and documented within 14 days.12 Your policies must say how you spot a significant change in the first place.13
Clients you already had on 1 July 2026
A client whose business relationship with you involved only designated services in Table 5 (real estate) or Table 6 (professional services) at the start of 1 July 2026 is a pre-commencement customer.14 Initial customer due diligence does not apply to them unless a suspicious matter reporting obligation arises for that client, or a significant change in the nature and purpose of the relationship makes the client's risk medium or high. Once you complete initial due diligence for a client, they stop being a pre-commencement customer.15 The usual duty to re-rate a client's risk when things change does not apply to them either. Instead, you must monitor for significant changes of that kind.16
Treat these clients as a kind of customer in your risk assessment: how many there are, what you do for them and what would move them to medium or high risk. AUSTRAC explains the transition on its transitioning existing customers page.
AUSTRAC's full method is on its Step 2: identify and assess your risks page. AUSTRAC links on this page open in a new window. AUSTRAC has not reviewed or endorsed this guide.
Where we fit
- Try it free: our risk assessment draft generator builds a first draft in your browser, in the structure above.
- Your sector: accounting practices, real estate agencies, conveyancers and legal practices.
- The documents: document 02 in our kit is the risk assessment, built on AUSTRAC's starter kit, and document 24 is the senior-manager approval record.
- Set-up with us: in the set-up service we rate your actual services, clients, channels and countries with you. Your senior manager approves the result; the decisions stay with your firm.
- More: the other guides and every source we use on the sources page.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. AUSTRAC pages are guidance, not law.
-
AML/CTF Act s 26C(1). legislation.gov.au/C2006A00169/latest/text
-
AML/CTF Act s 26C(2).
-
AML/CTF Act s 26C(3). These matters apply where you provide designated services through a permanent establishment in Australia.
-
AML/CTF Act s 26E.
-
AML/CTF Act s 26N; AML/CTF Rules 2025 (F2025L01026), rule 5-15(1). legislation.gov.au/F2025L01026/latest/text
-
AML/CTF Act s 26P(1).
-
AUSTRAC, "Step 2: Identify and assess your risks: risk assessment", last updated by AUSTRAC in March 2026, read 25 September 2026. Guidance, not law. © AUSTRAC for the Commonwealth of Australia 2026, CC BY 4.0.
-
AML/CTF Act s 26F(11) and (12).
-
AML/CTF Act s 26F(1)(a).
-
AML/CTF Act s 26D(1) and (2).
-
AML/CTF Rules 2025, rule 5-1.
-
AML/CTF Act ss 26D(4) and 26P; AML/CTF Rules 2025, rule 5-15(2).
-
AML/CTF Act s 26F(3)(a).
-
AML/CTF Act s 36(1).
-
AML/CTF Act s 36(2)–(4).
-
AML/CTF Act ss 36(3) and 30(2)(b) and (d).