How-to guides

How to do an ML/TF risk assessment (step by step)

A money-laundering and terrorism-financing risk assessment is the foundation of your AML/CTF program. Here's a plain-English, step-by-step way to do one that matches AUSTRAC's reformed requirements — proportionate to a small business.

By Daniel Ebiau, AMLCompliant ·

The ML/TF risk assessment is the foundation of your AML/CTF program — everything else (your policies, your CDD, your monitoring) has to address the risks you identify here. Under AUSTRAC's reformed regime it's mandatory, and it must be proportionate to your business. Here's a practical, step-by-step way to do one. (This is a method, not a fill-in-the-blanks legal document — adapt it to your firm.)

What the assessment must cover

AUSTRAC requires you to identify and assess the money laundering, terrorism financing and proliferation financing risks your business reasonably faces, using a methodology proportionate to the nature, size and complexity of the business, developed with senior management. (Source: AUSTRAC — summary of changes.)

Before you start, confirm you're actually captured — capture is service-based, so work through Is my business an AUSTRAC reporting entity? first.

Step 1 — List your designated services

Write down the specific designated services you provide (e.g. brokering property sales, managing client money, forming companies). These are your risk surface — the points where money can move through your business.

Step 2 — Assess your customers

Who are your customers? Consider entity types (individuals, companies, trusts), beneficial-ownership complexity, whether any are politically exposed persons, and whether you ever deal with customers you can't easily verify. AUSTRAC treats identifying beneficial owners (generally individuals owning ≥25% or controlling the customer) as central. (Source: AUSTRAC — beneficial owner.)

Step 3 — Assess products, channels and jurisdictions

For each designated service, consider how it could be misused — cash intensity, speed of settlement, ability to obscure ownership — and your delivery channels (face-to-face vs remote/online) and any foreign jurisdictions involved.

Step 4 — Rate the risk

For each combination, rate the inherent risk (e.g. low / medium / high), note the controls you already have, and decide on a residual rating. This is what drives whether you can use simplified CDD (only for genuinely low-risk customers where enhanced CDD isn't required) or must apply enhanced CDD (mandatory in specified higher-risk circumstances). (Source: AUSTRAC — customer due diligence reform.)

Step 5 — Document, approve, and connect it to your program

Write it up, have senior management approve it in writing, and make sure your AML/CTF policies actually address each identified risk. AUSTRAC's reformed program has three parts — risk assessment, policies, and governance (including your compliance officer) — and the assessment sits underneath the other two. (Source: AUSTRAC — about the reforms.)

Step 6 — Keep it current and plan for evaluation

Your policies set the review cadence, and you must refresh the assessment when risks change. Note that AUSTRAC also requires an independent evaluation of your whole program (this replaced the old "independent review"). For newly regulated Tranche 2 entities, the first evaluation is staggered by the last two digits of your AUSTRAC account number — earliest 30 June 2029, latest 31 December 2030 — so no newcomer has to complete one earlier than three years from commencement. (Source: AUSTRAC — conduct an independent evaluation.)

Keep records

Retain your risk assessment and supporting records — AUSTRAC's general retention period is 7 years. (Source: AUSTRAC — record-keeping overview.)

Profession-specific starting points: real estate · accountants.

General information only, not legal advice. Reflects AUSTRAC guidance current to June 2026. Confirm your obligations with AUSTRAC (austrac.gov.au) or a qualified adviser.

Run the free ML/TF risk assessment →

Frequently asked questions

Does it have to be a big document?
No. AUSTRAC requires a methodology proportionate to the nature, size and complexity of your business. A small, low-risk practice can have a short, focused risk assessment — but it must be genuine and documented.
What risks do I have to assess?
Money laundering, terrorism financing and proliferation financing — across your customers, the designated services/products you offer, delivery channels, and relevant jurisdictions. Source — AUSTRAC summary of changes.
How often do I update it?
Your AML/CTF policies set the review frequency, and you must update the assessment when your risks change. Newly regulated entities also face a first independent evaluation of the whole program, staggered between 30 June 2029 and 31 December 2030 by AUSTRAC account number.
risk assessmentml/tfaml/ctf programhow toaustrac