Foundation guide • AustraliaRead the New Zealand version

How to Build an Australian ML/TF Risk Assessment

Learn what an Australian ML/TF risk assessment must cover, how to rate risk and when the assessment must be reviewed.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. The Four-Part Method
  3. Key words explained
  4. Part 1: What the Assessment Must Cover
  5. Part 2: A Simple Method That Can Be Explained
  6. Part 3: Worked Example
  7. Part 4: When the Assessment Must Be Reviewed
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

A risk assessment explains how the business could be used for money laundering, terrorism financing or proliferation financing. It must be written, based on the real business and completed before a designated service starts.

The assessment should drive the AML/CTF policies. A list of risks with no reasons, sources or link to controls will be hard to rely on.

At a glance

The Four-Part Method

  • Identify

    List the services, customers, countries and delivery methods that could be misused.

  • Assess

    Decide how open each risk is to misuse and how serious that misuse could be.

  • Evaluate

    Set a clear rating and record the facts and sources behind it.

  • Respond

    Use the result to choose the controls in the AML/CTF policies.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

ML/TF risk
The chance that a service could be used for money laundering, terrorism financing or proliferation financing.
Inherent risk
The risk that exists before the business applies its AML/CTF controls.
Residual risk
The risk that is left after the controls are applied.
Risk factor
A fact that can raise or lower risk, such as a service, customer type, country or delivery method.
Control
A step used to manage risk, such as CDD, approval, monitoring or a service limit.
Risk rating
A clear label, such as low, medium or high, used to show the level of risk.

What the Assessment Must Cover

The steps used must suit the nature, size and complexity of the business. The following areas must be considered.

  1. Step 1

    Designated services

    List each service the business provides or plans to provide. Include new technology linked to the service.

    • How can value be placed, moved, hidden or changed?
    • Can ownership or the source of funds be hidden?
    • Can the service be used fast, remotely or through another person?
  2. Step 2

    Kinds of customers

    Group customers by features that change the risk. A job title or legal form is not enough on its own.

    • Ownership and control
    • Source of wealth or funds
    • Public office, criminal links or adverse information
    • Cash-intensive, cross-border or high-risk activity
  3. Step 3

    Delivery channels

    Check how customers reach the business and how the service is completed.

    • In person, online or through an agent
    • Level of staff contact
    • Use of third parties, platforms or automated systems
    • New or emerging technology
  4. Step 4

    Countries

    Consider where customers, owners, funds, assets, counterparties and service steps are located.

    • Sanctions and high-risk jurisdiction information
    • Corruption, crime and terrorism financing risk
    • Quality of local AML/CTF controls
    • The reason for the country link
  5. Step 5

    AUSTRAC risk information

    Current national, sector and typology information from AUSTRAC should be used where it is relevant.

Inherent risk first

AUSTRAC expects the risk before controls to be identified and assessed. Residual risk may then be assessed after controls are applied.

A Simple Method That Can Be Explained

A small business does not need false precision. It does need a method that is clear, repeatable and supported by facts.

  1. Step 1

    Map the business

    List the designated services, customer groups, delivery channels and country links. Use real data where it is available.

  2. Step 2

    Describe the misuse

    For each area, write a short risk statement. Say who could misuse what, how it could happen and what could be hidden or moved.

  3. Step 3

    Rate the inherent risk

    Use a small scale such as low, medium and high. Define each rating before it is used. Record likelihood and effect if that helps the business.

  4. Step 4

    Write the reason

    Point to customer data, service features, country information, AUSTRAC material and known warning signs. A rating without a reason should be challenged.

  5. Step 5

    Connect the controls

    Show which AML/CTF policies manage each risk. Higher risk should lead to stronger CDD, approval, monitoring or service limits.

  6. Step 6

    Name the owner and review date

    The compliance officer should know who watches each risk, what change triggers a review and when the next full review is due.

Worked Example

This example shows the level of reasoning that should be visible. It is not a template and should not be copied without checking the facts.

Example risk entry for a professional service
FieldExample
ServiceReceiving and paying client money for a property transaction.
Possible misuseCriminal funds may be passed through the trust account to make them look linked to a lawful sale.
Risk factorsHigh value, third-party funds, a complex company owner, overseas funds and pressure to settle fast.
Inherent ratingHigh. Large sums can be moved quickly and the real owner or source may be hidden.
ControlsBeneficial ownership checks, source-of-funds checks, payment rules, senior approval, monitoring and suspicious matter escalation.
Review triggerA new payment platform, a new country corridor or a change in customer type.

When the Assessment Must Be Reviewed

The full assessment must be reviewed at least every three years. Some events require an earlier review.

  • A designated service starts or changes in a significant way.
  • A customer type, delivery channel or country exposure changes.
  • New or emerging technology is introduced.
  • AUSTRAC gives the business or sector new risk information.
  • An independent evaluation makes an adverse finding about the assessment.
  • A control fails or new suspicious activity shows that the risk was understated.
Timing matters

A planned change should be assessed before it starts. An unplanned change should be assessed as soon as possible after it is found. Updates should be documented within 14 days.

Common Mistakes

  • A sector document is copied and treated as the business’s own assessment.
  • Controls are used to lower the risk before the inherent risk is understood.
  • All customers or services are given the same rating.
  • The risk scale is not defined.
  • Ratings are stated without facts, sources or reasons.
  • Proliferation financing is left out without a supported low-risk assessment.
  • The assessment and AML/CTF policies do not point to each other.
  • The document is reviewed by date only and business changes are missed.

Common Questions

Short answers to the questions businesses ask most often.

When must an Australian ML/TF risk assessment be completed?

It must be in place before the reporting entity starts to provide a designated service. It must then be kept current.

What risks must be assessed?

Money laundering, terrorism financing and proliferation financing risks that the business may reasonably face when it provides designated services.

Must inherent risk be assessed?

AUSTRAC expects the risk before controls to be identified and assessed. This lets the business choose controls that match the risk.

Must residual risk be assessed?

A business may assess the risk left after controls. The method should stay clear and should not hide the inherent risk.

How often must the assessment be reviewed?

It must be reviewed at least every three years and when set changes, AUSTRAC information or adverse evaluation findings occur.

Can the AUSTRAC starter kit be used as the assessment?

A starter kit can help, but it must be checked and changed so it matches the services, customers, delivery, countries and risks of the business.

Official Sources

This guide cites the following sources.

  1. Regulator guidanceAUSTRAC
    Step 2: Identify and assess your risks

    Current AUSTRAC method for identifying, assessing and evaluating inherent ML/TF risk.

  2. Regulator guidanceAUSTRAC
    Step 4: Review and update your AML/CTF program

    Review triggers, three-year review rule and documentation timing.

  3. Regulator guidanceAUSTRAC
    Your AML/CTF program overview

    How the risk assessment and AML/CTF policies form the program.

  4. Primary lawFederal Register of Legislation
    Anti-Money Laundering and Counter-Terrorism Financing Act 2006

    Sections 26C to 26E set the risk-assessment and review duties.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your Australia business does and where the uncertainty sits. We will help you work out the practical AML/CTF response.

Tell us about your situation