← Back to blog

What is a risk assessment under AUSTRAC's AML/CTF regime?

Every written AML/CTF program, every customer risk rating, every training session — all of it is supposed to sit on top of one document: your ML/TF risk assessment. Here's what AUSTRAC actually expects it to contain.

Key takeaways

A risk assessment isn't a form you fill in once — it's a documented analysis across four categories: your services, your customers, your delivery channels, and the countries you deal with.

You assess "inherent" risk first — the risk before any controls are applied — then use that to design the policies that reduce it. Skipping straight to policies is doing it backwards.

The depth should match your business: a simple impact-only assessment for a small operation, a full likelihood-and-impact risk matrix for a larger or more complex one.

In our last article, we walked through the order AUSTRAC expects reporting entities to build compliance in — and risk assessment came second, right after enrolment, before any written program, compliance officer appointment, or staff training. A lot of businesses skip straight past it, download an AML/CTF program template, and fill in the blanks. That approach doesn't hold up: the program is meant to be a direct response to risks you've actually identified in your own business, not a generic checklist.

What a risk assessment actually is

Under the AML/CTF Act, you're required to identify and assess the money laundering, terrorism financing, and proliferation financing risks your business reasonably faces — referred to collectively as ML/TF risk. This isn't about whether you personally suspect wrongdoing; it's about how a person could exploit vulnerabilities in how your business operates, whether or not you ever witness it happening.

Regulatory note

AUSTRAC is explicit that you don't need to have directly seen your business targeted to be "at risk." The obligation is to assess exposure, not to prove past incidents.

Why it has to come first

Your risk assessment is the input everything else is built from. It determines how you assign risk ratings to customers during due diligence, which controls your written AML/CTF program needs to include, what your staff training should actually focus on, and how closely you monitor different relationships. Write the program first and there's nothing for it to respond to — which is precisely what AUSTRAC's guidance is designed to prevent.

The three-step process

AUSTRAC's guidance breaks the exercise into three stages:

  • 1Identify — work out which ML/TF risks you may reasonably face, and when they could arise, across your services, customers, delivery channels, and countries.
  • 2Assess — work out the scale of each risk, typically by considering its likelihood and impact.
  • 3Evaluate — prioritise which risks need the most attention, so your resources and controls go where they matter most.

The four risk categories you must document

AUSTRAC expects your risk assessment to cover four areas. Tailor the depth to your business — a small, simple operation can document this briefly; a larger or more complex one is expected to go further.

1. The designated services you provide

Start by listing every designated service your business actually offers, then consider why each one could be exploited. AUSTRAC's own guidance gives examples: brokering real estate sales is attractive to launderers because property values can be manipulated and ownership hidden behind complex structures; providing a registered office address lets criminals appear legitimate while obscuring who really controls an entity; buying or selling bullion lets someone convert illicit cash into a stable, portable, easily resold asset. As a starting point, consider whether a service involves high-value transactions (cash or virtual assets) or structures that help a customer stay anonymous or disguise the source of their funds.

2. The kinds of customers you deal with

Different customer types carry different risk profiles, especially in combination with higher-risk services or countries. Factors AUSTRAC calls out specifically include:

  • Politically exposed persons (domestic, foreign, or from international organisations) — attractive targets for corruption and bribery
  • High-net-worth individuals, whose financial affairs are often complex enough to obscure source of wealth
  • Non-residents, who are harder to verify and monitor
  • Customers using complex legal structures — trusts, companies, layered ownership — that can hide who's really involved
  • Customers acting through a third party or agent, making it harder to know who you're really dealing with
  • Customers with wealth that doesn't match their known, lawful sources of income

3. Your delivery channels

How you deliver a service matters as much as what the service is. In-person delivery is generally lower risk, since staff can observe unusual behaviour directly — though forged identification remains a risk even face-to-face. Remote, staff-assisted delivery (phone, email, video) introduces harder identity verification and reliance on third-party technology. Fully remote, self-service delivery — online banking, smart ATMs, online remittance — carries the highest risk in this category, since there's no human check at all before a service is provided. Using third parties or intermediaries to reach customers adds a further layer of difficulty in knowing who you're actually dealing with.

4. The countries you deal with

List every country connected to your designated services — where your customers reside, where corporate customers are incorporated, and where transactions flow. AUSTRAC expects you to assess each using a recognised methodology (the Basel AML Index is one commonly used reference, scoring countries from 0–10 across quality of AML/CTF frameworks, corruption, financial transparency, and legal and political risk) and to automatically treat any country on the FATF grey or black lists, or subject to Australian sanctions, as high risk regardless of its index score.

Regulatory note

You must also factor in AUSTRAC's own published risk products — national risk assessments and typology reports — and keep a simple register showing you've considered them and what, if anything, you changed as a result.

Don't forget proliferation financing

Since the reforms, your risk assessment must separately consider proliferation financing risk — the risk of your business being used to help finance the spread of weapons of mass destruction. You can skip building separate policies for it only if you can reasonably show your exposure is low: broadly, that you operate solely within Australia, don't serve customers connected to high-risk jurisdictions, and don't deal in money movement or dual-use goods and technology. Most small, domestic, professional-services businesses will sit here — but the assessment still needs to say so, not simply omit the topic.

Inherent risk vs residual risk

AUSTRAC draws a clear line between two different measurements, and mixing them up is one of the most common mistakes:

  • Inherent risk — the risk that exists before you apply any controls, policies, or safeguards. This is what your risk assessment is primarily required to identify and assess.
  • Residual risk — what's left over after your AML/CTF policies are applied. Assessing this is optional, but it's a useful check on whether your controls are actually working.

Assessing inherent risk first, honestly and without your existing controls in mind, is what makes the resulting program meaningful rather than circular.

Scoring it: impact and likelihood

For a smaller, low-complexity business, AUSTRAC accepts a simpler approach: just consider the impact of each risk if it occurred (high, medium, or low), and treat that as your inherent risk rating.

For a medium-complexity business, the standard method multiplies likelihood by impact:

Low impactMedium impactHigh impact
Very likelyMediumHighHigh
LikelyLowMediumHigh
Not likelyLowLowMedium

Likelihood × impact = inherent risk rating. AUSTRAC's own worked example — adapt the number of levels to your business, but keep the cut-off between low and high explicit.

Larger, higher-complexity businesses are expected to go further still — a simple three-by-three matrix may not capture a genuinely dynamic risk profile, and AUSTRAC expects those businesses to use more extensive methods that stay current as risks change.

Keep it current — this isn't a one-off document

A risk assessment written once and filed away doesn't meet the obligation. You're required to reassess before offering any new designated service, before using a new delivery channel or technology, and before engaging with a new country. Beyond those specific triggers, the assessment itself needs regular review, and — as we covered in our first article — the reforms now require an independent evaluation of your entire AML/CTF program, including the risk assessment underneath it, on a cycle of at least every three years (more often if your risk profile justifies it).

Where this leads

Once your risk assessment is documented, it feeds directly into the next steps: the written AML/CTF program built to respond to it, the named Compliance Officer who owns its implementation, staff training focused on the risks you've actually identified, and the customer due diligence process that assigns risk ratings using this same framework. If you haven't read it yet, our piece on what it means to be captured as a Tranche 2 entity walks through that full sequence.

Not sure where to start?

A 20-minute call is usually enough to scope what your risk assessment actually needs to cover.

Book a free call