An AML/CTF risk assessment identifies the money laundering and terrorism financing risk a reporting entity faces across four dimensions: the designated services provided, customer types, delivery channels and jurisdictions. It must be documented and kept current rather than completed once.
Table of Contents
AML/CTF Risk Assessment Australia:
A Guide for Professional Services Firms
An ML/TF risk assessment is the foundation of every compliant AML/CTF program in Australia. Before a professional services firm can draft its program, build its customer due diligence procedures, or configure its transaction monitoring, it needs to understand where its actual exposure to money laundering and terrorism financing risk sits.
This guide explains what the AML/CTF risk assessment for Australian professional services firms must cover, how to conduct it, and how to document the findings in a form that satisfies AUSTRAC’s evidence standard.
Key Takeaways
What an AML/CTF Risk Assessment Australia Requires Actually Is
An ML/TF risk assessment is a structured analysis of the money laundering and terrorism financing risks associated with a firm’s designated services, its customers, its delivery channels, and the jurisdictions in which it operates. AUSTRAC requires every reporting entity to conduct a business-wide risk assessment and to use that assessment as the basis for its AML/CTF program.
The risk assessment is not a one-time exercise. AUSTRAC requires reporting entities to review and update their risk assessment when there are material changes to the firm’s services, customer base, ownership structure, or operating environment. For most professional services firms, an annual review is appropriate.
The 4 Risk Dimensions
AUSTRAC’s rules require that the ML/TF risk assessment address four dimensions: the nature, scale, and complexity of the designated services provided; the customer types and the associated risk indicators; the delivery channels through which services are provided; and the countries and jurisdictions to which the firm’s services relate.
1. Designated Services Risk
Not all designated services carry the same ML/TF risk. For a legal firm, the highest-risk designated services are those involving the management of client money and the formation or management of legal persons or legal arrangements. Conveyancing, trust and company formation, and the handling of settlement funds carry higher risk than, say, advisory-only services with no funds management component. The risk assessment must address the specific services the firm provides and assess their relative risk level.
2. Customer Risk
Certain customer characteristics are internationally recognised as higher-risk indicators: politically exposed persons (PEPs) and their associates; non-face-to-face customers; customers using complex or opaque ownership structures; customers from high-risk jurisdictions; customers involved in cash-intensive industries; and customers where the beneficial ownership is unclear. The risk assessment must identify the proportion of the firm’s client base that falls into higher-risk categories and describe how those customers will be managed.
3. Delivery Channel Risk
Services delivered through digital channels, without face-to-face contact, present higher identity verification risks than services delivered through in-person client engagement. The risk assessment should address whether the firm uses digital onboarding, remote instruction, or digital document signing, and how the KYC risk associated with those channels is managed.
4. Jurisdiction Risk
Services with a connection to high-risk jurisdictions (countries subject to FATF mutual evaluation findings, countries on AUSTRAC’s high-risk jurisdiction list, or countries subject to UN or Australian targeted financial sanctions) require enhanced due diligence. The risk assessment must identify whether any of the firm’s services have connections to such jurisdictions.
Documenting the Risk Assessment
The risk assessment must be documented in writing. The document should describe the methodology used, the data sources consulted, the risk ratings applied to each dimension, the overall risk rating for the firm’s designated services, and the control measures that mitigate the identified risks. AUSTRAC will request the risk assessment document in any supervisory review.
The document must be approved by senior management and should record the date of the assessment and any previous reviews. Version control is important, AUSTRAC’s supervisory approach examines whether the risk assessment has been maintained over time, not just adopted at commencement.
Keeping the risk assessment alive
A risk assessment is a snapshot that ages the day it is approved. New service lines, new client segments, a merger, a new delivery channel. Each one changes the risk picture the document claims to describe, and a reviewer reading a two-year-old assessment against today’s practice will treat the gap as the finding.
The maintenance rhythm that works: a scheduled annual refresh (diarised, owned, minuted), plus trigger-based updates whenever the firm changes shape. Keep a short change log at the front of the document (date, what changed, who approved) so the assessment’s history is visible at a glance. Ten minutes per quarter asking ‘what changed?’ keeps the document true; the alternative is rewriting it under supervision.
AML/CTF risk assessment Australia: keeping it alive after version one
DBA Advisory facilitates the risk assessment workshop and reviews existing assessments against how the firm actually operates now.
This document dates faster than anything else in the program. A new service line, a merger, an office in another state or a shift in client mix can each make it describe a firm you no longer are. Reviewers check whether it has moved, because a risk assessment that has not been touched since commencement tells them the program is not being operated.
Four dimensions carry the assessment: the designated services you provide, your customer types, your delivery channels, and the jurisdictions you touch. Each rating needs its reason recorded alongside it, and the whole thing needs refreshing on a set cycle and whenever something material changes. The conclusions then have to flow into your Part B procedures, or the program contradicts itself.
Frequently Asked Questions (FAQs)
An ML/TF risk assessment is a structured analysis of the money laundering and terrorism financing risks associated with a firm's designated services, customers, delivery channels, and jurisdictions. Every reporting entity under the AML/CTF Act (including, from 1 July 2026, accountants, lawyers, conveyancers, and other Tranche 2 entities) must conduct a business-wide risk assessment and use it as the basis for their AML/CTF program.
AUSTRAC requires reporting entities to review and update their risk assessment when there are material changes to the firm's designated services, customer base, ownership structure, or operating environment. For most professional services firms, an annual review timed to the program's annual review cycle is appropriate. Material regulatory changes, such as amendments to AUSTRAC's rules, should also trigger a review.
An inadequate risk assessment (one that does not address the four required dimensions, does not reflect the firm's actual services and customer base, or was adopted at commencement and never updated) is a compliance deficiency that AUSTRAC will identify in a supervisory review. A deficient risk assessment also undermines the entire program, because the procedures built on it may not address the firm's actual risks.
How DBA AML Supports You
This work is delivered by DBA AML Group Pty Ltd, the specialist AML/CTF compliance entity within DBA Advisory. It is a service rather than software: real AML/CTF practitioners do the work, so what leaves your desk is the function itself, not a portal to configure and operate. You remain the reporting entity; the operations move.
DBA AML Group Pty Ltd · ACN 697 643 404 · hello@dbaaml.com · dbaaml.com · We respond within one business day. Scope and fees are confirmed after a discovery call.
How DBA Advisory Supports You
An AML/CTF risk assessment Australia requires sits underneath everything else in your program. Every procedure you write, every customer check you perform and every monitoring rule you set should trace back to a risk you identified here. Get it wrong and the rest of the program is calibrated to the wrong thing.
DBA Advisory offers fixed-fee AML/CTF risk assessment, program build, and AUSTRAC registration support engagements with no hidden costs. Contact our team at dbaadvisory.com to discuss your requirements. General information only, not legal, tax, or compliance advice. Verify all obligations against current AUSTRAC, ATO, and legislative guidance.
Not sure where your firm stands under Tranche 2? The AML/CTF Compliance Readiness Assessment is a scored, plain-English self-assessment you can complete in fifteen minutes. Download it free or book a meeting today!
Disclaimer
© DBA Advisory 2026. This article is intended as general information only and does not constitute legal or compliance advice. Businesses should seek qualified advice specific to their circumstances before acting on any information contained in this article.
Related Insights
We build the resilient foundations
empowering you
to scale your business
Get in touch
Alquin Dagamina
Business Transformation and Technology Services, Manager
- Alquin.Dagamina@dbaadvisory.com
- 09158918379

