How to Build an Australian ML/TF Risk Assessment
Learn what an Australian ML/TF risk assessment must cover, how to rate risk and when the assessment must be reviewed.
How this guide was researched and reviewedOn this page
Short answer
A risk assessment explains how the business could be used for money laundering, terrorism financing or proliferation financing. It must be written, based on the real business and completed before a designated service starts.
The assessment should drive the AML/CTF policies. A list of risks with no reasons, sources or link to controls will be hard to rely on.
At a glance
The Four-Part Method
Identify
List the services, customers, countries and delivery methods that could be misused.
Assess
Decide how open each risk is to misuse and how serious that misuse could be.
Evaluate
Set a clear rating and record the facts and sources behind it.
Respond
Use the result to choose the controls in the AML/CTF policies.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- ML/TF risk
- The chance that a service could be used for money laundering, terrorism financing or proliferation financing.
- Inherent risk
- The risk that exists before the business applies its AML/CTF controls.
- Residual risk
- The risk that is left after the controls are applied.
- Risk factor
- A fact that can raise or lower risk, such as a service, customer type, country or delivery method.
- Control
- A step used to manage risk, such as CDD, approval, monitoring or a service limit.
- Risk rating
- A clear label, such as low, medium or high, used to show the level of risk.
Part 1
What the Assessment Must Cover
The steps used must suit the nature, size and complexity of the business. The following areas must be considered.
- Step 1
Designated services
List each service the business provides or plans to provide. Include new technology linked to the service.
- How can value be placed, moved, hidden or changed?
- Can ownership or the source of funds be hidden?
- Can the service be used fast, remotely or through another person?
- Step 2
Kinds of customers
Group customers by features that change the risk. A job title or legal form is not enough on its own.
- Ownership and control
- Source of wealth or funds
- Public office, criminal links or adverse information
- Cash-intensive, cross-border or high-risk activity
- Step 3
Delivery channels
Check how customers reach the business and how the service is completed.
- In person, online or through an agent
- Level of staff contact
- Use of third parties, platforms or automated systems
- New or emerging technology
- Step 4
Countries
Consider where customers, owners, funds, assets, counterparties and service steps are located.
- Sanctions and high-risk jurisdiction information
- Corruption, crime and terrorism financing risk
- Quality of local AML/CTF controls
- The reason for the country link
- Step 5
AUSTRAC risk information
Current national, sector and typology information from AUSTRAC should be used where it is relevant.
AUSTRAC expects the risk before controls to be identified and assessed. Residual risk may then be assessed after controls are applied.
Part 2
A Simple Method That Can Be Explained
A small business does not need false precision. It does need a method that is clear, repeatable and supported by facts.
- Step 1
Map the business
List the designated services, customer groups, delivery channels and country links. Use real data where it is available.
- Step 2
Describe the misuse
For each area, write a short risk statement. Say who could misuse what, how it could happen and what could be hidden or moved.
- Step 3
Rate the inherent risk
Use a small scale such as low, medium and high. Define each rating before it is used. Record likelihood and effect if that helps the business.
- Step 4
Write the reason
Point to customer data, service features, country information, AUSTRAC material and known warning signs. A rating without a reason should be challenged.
- Step 5
Connect the controls
Show which AML/CTF policies manage each risk. Higher risk should lead to stronger CDD, approval, monitoring or service limits.
- Step 6
Name the owner and review date
The compliance officer should know who watches each risk, what change triggers a review and when the next full review is due.
Part 3
Worked Example
This example shows the level of reasoning that should be visible. It is not a template and should not be copied without checking the facts.
| Field | Example |
|---|---|
| Service | Receiving and paying client money for a property transaction. |
| Possible misuse | Criminal funds may be passed through the trust account to make them look linked to a lawful sale. |
| Risk factors | High value, third-party funds, a complex company owner, overseas funds and pressure to settle fast. |
| Inherent rating | High. Large sums can be moved quickly and the real owner or source may be hidden. |
| Controls | Beneficial ownership checks, source-of-funds checks, payment rules, senior approval, monitoring and suspicious matter escalation. |
| Review trigger | A new payment platform, a new country corridor or a change in customer type. |
Part 4
When the Assessment Must Be Reviewed
The full assessment must be reviewed at least every three years. Some events require an earlier review.
- A designated service starts or changes in a significant way.
- A customer type, delivery channel or country exposure changes.
- New or emerging technology is introduced.
- AUSTRAC gives the business or sector new risk information.
- An independent evaluation makes an adverse finding about the assessment.
- A control fails or new suspicious activity shows that the risk was understated.
A planned change should be assessed before it starts. An unplanned change should be assessed as soon as possible after it is found. Updates should be documented within 14 days.
Part 5
Common Mistakes
- A sector document is copied and treated as the business’s own assessment.
- Controls are used to lower the risk before the inherent risk is understood.
- All customers or services are given the same rating.
- The risk scale is not defined.
- Ratings are stated without facts, sources or reasons.
- Proliferation financing is left out without a supported low-risk assessment.
- The assessment and AML/CTF policies do not point to each other.
- The document is reviewed by date only and business changes are missed.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
When must an Australian ML/TF risk assessment be completed?
It must be in place before the reporting entity starts to provide a designated service. It must then be kept current.
What risks must be assessed?
Money laundering, terrorism financing and proliferation financing risks that the business may reasonably face when it provides designated services.
Must inherent risk be assessed?
AUSTRAC expects the risk before controls to be identified and assessed. This lets the business choose controls that match the risk.
Must residual risk be assessed?
A business may assess the risk left after controls. The method should stay clear and should not hide the inherent risk.
How often must the assessment be reviewed?
It must be reviewed at least every three years and when set changes, AUSTRAC information or adverse evaluation findings occur.
Can the AUSTRAC starter kit be used as the assessment?
A starter kit can help, but it must be checked and changed so it matches the services, customers, delivery, countries and risks of the business.
Reference
Official Sources
This guide cites the following sources.
- Regulator guidanceAUSTRACStep 2: Identify and assess your risks
Current AUSTRAC method for identifying, assessing and evaluating inherent ML/TF risk.
- Regulator guidanceAUSTRACStep 4: Review and update your AML/CTF program
Review triggers, three-year review rule and documentation timing.
- Regulator guidanceAUSTRACYour AML/CTF program overview
How the risk assessment and AML/CTF policies form the program.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
Sections 26C to 26E set the risk-assessment and review duties.