For accountants

Building the AML/CTF risk assessment for an accounting practice

The AML/CTF risk assessment is the document that explains every other control in the program. It asks what money laundering, terrorism financing and proliferation financing risk the practice faces, where that risk comes from, and what the practice does about it. For an accounting practice the answer is rarely one risk level: entity formation, business sales, client money and advisory services each carry different exposures. This guide sets out the structure AUSTRAC's program guidance expects and the accountant-specific content that makes the assessment defensible.

See the accountants AML/CTF workspace

Identify the risk sources

AUSTRAC's program guidance structures the assessment around the business's ML/TF/PF risks and the factors that drive them. The practice should rate each combination and explain the rating, not copy a template with a different firm's conclusions.

  • Services: each designated service and how it can be misused
  • Customers: client types, entities, trusts, high-risk jurisdictions and PEPs
  • Channels: how clients engage, pay and move funds
  • Geography: where clients, counterparties and funds are located
  • New technology: payment methods and virtual assets in client transactions

Rate and document the inherent risk

For each service and customer group, assess the inherent risk before controls: how likely is the service to be misused, and what would the impact be? An entity-formation service for complex cross-border trusts has a different inherent profile from routine bookkeeping for local trades. Record the reasoning and the factors that moved the rating.

The rating language should be the practice's own: high, medium or low (or the practice's defined scale), with the criteria for each level. AUSTRAC does not prescribe one universal scale; it prescribes a risk-based assessment that is documented and reviewed.

Define the controls that respond

Every identified risk should trace to a control in the program. If the assessment says cross-border entity work is higher risk, the program should say what happens on those files: enhanced verification, senior approval, source-of-funds review and more frequent monitoring.

  • CDD depth by risk tier, including ECDD triggers
  • Screening frequency for PEPs, sanctions and adverse media
  • Source-of-funds and wealth expectations
  • Approval authority for higher-risk clients
  • Monitoring, review cycles and trigger events
  • Training by role

Keep it current

A static risk assessment is a compliance artefact. The practice should treat it as a living document: versioned, approved and connected to the program, so a new service line triggers a new assessment rather than an assumption.

  • Review the assessment when services, customers or channels change
  • Refresh it after material events or regulatory guidance
  • Conduct the independent evaluation on the program's calendar
  • Record version history so an examiner can see the practice's thinking over time

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Do we need a separate risk assessment for each client?

No. The practice-level assessment covers ML/TF/PF risk across services, customers, channels and geography. Individual clients are then rated against that framework.

Can we use AUSTRAC's starter kit risk assessment?

The starter kit is an optional starting point for eligible small practices. Confirm the suitability criteria and customise the assessment to the practice's actual services and risk factors.

What does AUSTRAC expect the assessment to contain?

Identification of the practice's ML/TF/PF risks, the factors that drive them, ratings with reasoning, the controls that respond, and review and approval arrangements.

How often should the risk assessment be updated?

On a defined review cycle and whenever services, customers, channels, geography or guidance materially change. Version history should show the updates.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.