Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/Core obligations

Obligations

How to build an ML/TF/PF risk assessment for an Australian business

6 min read · Updated 1 August 2026

An AML/CTF risk assessment is the evidence base for a reporting entity's program, not a generic industry heat map. It should identify the money laundering, terrorism financing and proliferation financing risks the particular business reasonably faces, explain how those risks arise, and support proportionate controls. The assessment must reflect the services actually delivered, customers accepted, channels used and jurisdictions encountered. It should also be usable: matter-opening rules, enhanced CDD, monitoring, approvals and training should trace back to it. This guide sets out a practical inherent-risk, control and residual-risk method while recognising that the Act and AUSTRAC guidance govern the legal requirement. Numerical scoring can support consistency, but it must not replace reasoned analysis or disguise gaps in evidence.

On this page

  1. Step-by-step process
  2. Set scope and ownership before scoring risk
  3. Assess the mandatory and business-specific risk dimensions
  4. Distinguish inherent risk, controls and residual risk
  5. Use internal and external evidence
  6. Make the assessment a living control document
  7. Official sources
  8. Frequently asked questions

Step-by-step process

  1. Define scope

    Map reporting entities, designated services, delivery processes and assessment ownership.

  2. Identify exposure

    Assess customer, service, channel, jurisdiction and business-specific ML/TF/PF scenarios.

  3. Evaluate controls

    Rate inherent risk, test actual control evidence and determine residual risk with reasons.

  4. Act and review

    Connect ratings to controls, approvals and remediation, then monitor change triggers.

Set scope and ownership before scoring risk

Define the reporting entities, business units, locations and designated services covered. Map actual delivery from customer acquisition through execution, payment and relationship exit. Include variations such as client accounts, third-party payments, remote onboarding, agents, outsourced verification and offshore support. A group-wide assessment may provide context, but each reporting entity needs enough specificity to show the risks it reasonably faces and the controls for which it is accountable.

Assign an accountable senior manager, a competent assessment lead and contributors from frontline operations, compliance, finance, technology and governance. Record the assessment period, information sources, methodology, rating definitions, assumptions and limitations. Approval should demonstrate informed challenge, not just a signature. If reliable data is missing, describe the gap, use a cautious interim treatment and set a remediation owner rather than presenting an unsupported low-risk conclusion.

Assess the mandatory and business-specific risk dimensions

AUSTRAC's program guidance expects reporting entities to consider customer types, designated services, delivery channels and foreign jurisdictions, together with other factors relevant to their business. Customer analysis can include legal form, ownership transparency, PEP exposure, cash intensity and use of intermediaries. Service analysis should identify opportunities to move, conceal, convert or legitimise value. Channel analysis covers non-face-to-face delivery, introducers, agents and technology. Jurisdiction analysis should use current, credible information rather than nationality stereotypes.

Add risks revealed by the operating model: trust or client money, rapid settlement, linked purchases, nominees, complex structures, high-value portable goods, virtual assets, unusual refund paths, privileged or confidential engagements, and staff ability to override controls. Consider ML, TF and PF separately where their indicators or consequences differ. Proliferation financing can involve trade, dual-use goods, sanctions evasion, layered ownership and payments that appear commercially ordinary, so it should not be treated as a footnote to money laundering.

Distinguish inherent risk, controls and residual risk

A useful operational model first rates the risk before controls, then evaluates the design and operation of relevant controls, and finally records the risk that remains. Define likelihood and consequence scales in plain language. Require a written rationale for material ratings and use examples to reduce inconsistent scoring. Weighting can be appropriate, but a mathematical average must not cancel a severe sanctions or ownership concern simply because other factors are low.

Control assessment should test evidence: whether CDD rules are configured, screening is current, approvals occur before service, monitoring alerts are reviewed, personnel are trained, and exceptions are resolved. A policy that is not implemented should not reduce residual risk. Link intolerable or high residual risks to a decision such as enhanced measures, restricted services, senior approval, technology change, additional monitoring or cessation. State risk appetite and escalation thresholds so frontline decisions reflect the assessment.

Use internal and external evidence

Internal evidence can include customer and matter data, transaction values, payment methods, jurisdictions, risk ratings, alerts, SMR themes, declined work, exceptions, audit findings, complaints and staff workshops. Check data completeness and avoid treating no reports as proof of no risk. Segment information far enough to reveal concentration; a firm-wide average may hide a small but exposed service line. Where volumes are low, qualitative case analysis and scenario testing can be more useful than unstable percentages.

External evidence should be current and relevant. Use AUSTRAC guidance, national and sector risk assessments, typologies, targeted financial sanctions information, credible law-enforcement material and applicable professional guidance. Record publication dates and the business inference drawn from each source. Copying a regulator's risk rating without connecting it to the firm's customers and services produces a weak assessment. Where sources conflict, document the judgement and apply a cautious control until better evidence is available.

Make the assessment a living control document

Version control matters. Preserve what the business knew, when it knew it, the change made and the decision that followed. A concise assessment that drives controls is stronger than a long document nobody uses. Test usability by selecting a risk scenario and tracing it through the program, customer file, monitoring result, training content and governance report.

  • Create a risk register with scenario, cause, exposed service, customer, channel, jurisdiction, existing controls and accountable owner.
  • Define evidence-based inherent and residual rating criteria, including escalation for severe risks that should not be averaged away.
  • Map every material risk to policies, onboarding questions, monitoring rules, training and management information.
  • Record control gaps and remediation dates, and preserve approval and challenge by senior management.
  • Trigger review for new services, technologies, jurisdictions, acquisition, major incidents, typologies, sanctions changes and control failures.
  • Review the broader AML/CTF program within the applicable cycle and update the assessment sooner when material change occurs.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC - Identify and assess your risks
  • AUSTRAC - AML/CTF program overview
  • AUSTRAC - Manage and mitigate risks
  • Federal Register - AML/CTF Act 2006

Frequently asked questions

Is an AML/CTF risk assessment the same as a customer risk rating?

No. The business assessment identifies enterprise and service-level ML/TF/PF exposure and informs the program. A customer risk rating applies those policies to a particular relationship. The two should connect, but one cannot substitute for the other.

Must a business use numerical risk scores?

AUSTRAC's risk-based approach requires identification, assessment and management of risk, not a particular scoring engine. Numbers can improve consistency if definitions and evidence are sound. They should be supplemented by written reasoning, override controls and escalation for severe factors.

How often should the assessment be updated?

Update it when material internal or external change affects exposure or control effectiveness, and align it with the review cycle required by the current program rules. Do not wait for a calendar deadline after launching a new designated service, entering a jurisdiction or discovering a major control failure.

What if the business has no historical AML data?

Use service mapping, file sampling, staff workshops, credible external typologies and cautious assumptions. Record data limitations and implement a plan to collect meaningful metrics. Lack of previous alerts or SMRs is not evidence that the underlying risk is low.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

Obligations

Your AML/CTF program

Read
Obligations

Officer and governance

Read
Obligations

Independent evaluation

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.