AML/CTF Risk Assessment

An AML/CTF risk assessment identifies the money laundering and terrorism financing risk a reporting entity faces across four dimensions: the designated services provided, customer types, delivery channels and jurisdictions. It must be documented and kept current rather than completed once.

Table of Contents

AML/CTF Risk Assessment Australia:
A Guide for Professional Services Firms

An ML/TF risk assessment is the foundation of every compliant AML/CTF program in Australia. Before a professional services firm can draft its program, build its customer due diligence procedures, or configure its transaction monitoring, it needs to understand where its actual exposure to money laundering and terrorism financing risk sits.

This guide explains what the AML/CTF risk assessment for Australian professional services firms must cover, how to conduct it, and how to document the findings in a form that satisfies AUSTRAC’s evidence standard.

Key Takeaways
an overhead image of a rocky shore with lush vegetation, symbolising the potentially severe impacts of disregarding AML/CTF Risk Assessment

What an AML/CTF Risk Assessment Australia Requires Actually Is

An ML/TF risk assessment is a structured analysis of the money laundering and terrorism financing risks associated with a firm’s designated services, its customers, its delivery channels, and the jurisdictions in which it operates. AUSTRAC requires every reporting entity to conduct a business-wide risk assessment and to use that assessment as the basis for its AML/CTF program.

The risk assessment is not a one-time exercise. AUSTRAC requires reporting entities to review and update their risk assessment when there are material changes to the firm’s services, customer base, ownership structure, or operating environment. For most professional services firms, an annual review is appropriate.

The 4 Risk Dimensions

AUSTRAC’s rules require that the ML/TF risk assessment address four dimensions: the nature, scale, and complexity of the designated services provided; the customer types and the associated risk indicators; the delivery channels through which services are provided; and the countries and jurisdictions to which the firm’s services relate.

1. Designated Services Risk

Not all designated services carry the same ML/TF risk. For a legal firm, the highest-risk designated services are those involving the management of client money and the formation or management of legal persons or legal arrangements. Conveyancing, trust and company formation, and the handling of settlement funds carry higher risk than, say, advisory-only services with no funds management component. The risk assessment must address the specific services the firm provides and assess their relative risk level.

2. Customer Risk

Certain customer characteristics are internationally recognised as higher-risk indicators: politically exposed persons (PEPs) and their associates; non-face-to-face customers; customers using complex or opaque ownership structures; customers from high-risk jurisdictions; customers involved in cash-intensive industries; and customers where the beneficial ownership is unclear. The risk assessment must identify the proportion of the firm’s client base that falls into higher-risk categories and describe how those customers will be managed.

an image of a flame dancer during an intense performance, symbolising the potential negative consequences firms may face without a proper AML/CTF Risk Assessment from DBA Advisory

3. Delivery Channel Risk

Services delivered through digital channels, without face-to-face contact, present higher identity verification risks than services delivered through in-person client engagement. The risk assessment should address whether the firm uses digital onboarding, remote instruction, or digital document signing, and how the KYC risk associated with those channels is managed.

4. Jurisdiction Risk

Services with a connection to high-risk jurisdictions (countries subject to FATF mutual evaluation findings, countries on AUSTRAC’s high-risk jurisdiction list, or countries subject to UN or Australian targeted financial sanctions) require enhanced due diligence. The risk assessment must identify whether any of the firm’s services have connections to such jurisdictions.

Documenting the Risk Assessment

The risk assessment must be documented in writing. The document should describe the methodology used, the data sources consulted, the risk ratings applied to each dimension, the overall risk rating for the firm’s designated services, and the control measures that mitigate the identified risks. AUSTRAC will request the risk assessment document in any supervisory review.

The document must be approved by senior management and should record the date of the assessment and any previous reviews. Version control is important, AUSTRAC’s supervisory approach examines whether the risk assessment has been maintained over time, not just adopted at commencement.

Keeping the risk assessment alive

A risk assessment is a snapshot that ages the day it is approved. New service lines, new client segments, a merger, a new delivery channel. Each one changes the risk picture the document claims to describe, and a reviewer reading a two-year-old assessment against today’s practice will treat the gap as the finding.

The maintenance rhythm that works: a scheduled annual refresh (diarised, owned, minuted), plus trigger-based updates whenever the firm changes shape. Keep a short change log at the front of the document (date, what changed, who approved) so the assessment’s history is visible at a glance. Ten minutes per quarter asking ‘what changed?’ keeps the document true; the alternative is rewriting it under supervision.

an image of a cliff diver mid-air, symbolising the confidence and peace of mind firms enjoy with DBA Advisory's AML/CTF Risk Assessment service

AML/CTF risk assessment Australia: keeping it alive after version one

DBA Advisory facilitates the risk assessment workshop and reviews existing assessments against how the firm actually operates now.

This document dates faster than anything else in the program. A new service line, a merger, an office in another state or a shift in client mix can each make it describe a firm you no longer are. Reviewers check whether it has moved, because a risk assessment that has not been touched since commencement tells them the program is not being operated.

Four dimensions carry the assessment: the designated services you provide, your customer types, your delivery channels, and the jurisdictions you touch. Each rating needs its reason recorded alongside it, and the whole thing needs refreshing on a set cycle and whenever something material changes. The conclusions then have to flow into your Part B procedures, or the program contradicts itself.

Frequently Asked Questions (FAQs)

An ML/TF risk assessment is a structured analysis of the money laundering and terrorism financing risks associated with a firm's designated services, customers, delivery channels, and jurisdictions. Every reporting entity under the AML/CTF Act (including, from 1 July 2026, accountants, lawyers, conveyancers, and other Tranche 2 entities) must conduct a business-wide risk assessment and use it as the basis for their AML/CTF program.

AUSTRAC requires reporting entities to review and update their risk assessment when there are material changes to the firm's designated services, customer base, ownership structure, or operating environment. For most professional services firms, an annual review timed to the program's annual review cycle is appropriate. Material regulatory changes, such as amendments to AUSTRAC's rules, should also trigger a review.

An inadequate risk assessment (one that does not address the four required dimensions, does not reflect the firm's actual services and customer base, or was adopted at commencement and never updated) is a compliance deficiency that AUSTRAC will identify in a supervisory review. A deficient risk assessment also undermines the entire program, because the procedures built on it may not address the firm's actual risks.

How DBA AML Supports You

This work is delivered by DBA AML Group Pty Ltd, the specialist AML/CTF compliance entity within DBA Advisory. It is a service rather than software: real AML/CTF practitioners do the work, so what leaves your desk is the function itself, not a portal to configure and operate. You remain the reporting entity; the operations move.

DBA AML Group Pty Ltd · ACN 697 643 404 · hello@dbaaml.com · dbaaml.com · We respond within one business day. Scope and fees are confirmed after a discovery call.

How DBA Advisory Supports You

An AML/CTF risk assessment Australia requires sits underneath everything else in your program. Every procedure you write, every customer check you perform and every monitoring rule you set should trace back to a risk you identified here. Get it wrong and the rest of the program is calibrated to the wrong thing.

DBA Advisory offers fixed-fee AML/CTF risk assessment, program build, and AUSTRAC registration support engagements with no hidden costs. Contact our team at dbaadvisory.com to discuss your requirements. General information only, not legal, tax, or compliance advice. Verify all obligations against current AUSTRAC, ATO, and legislative guidance.

Not sure where your firm stands under Tranche 2? The AML/CTF Compliance Readiness Assessment is a scored, plain-English self-assessment you can complete in fifteen minutes. Download it free or book a meeting today!

Disclaimer

© DBA Advisory 2026. This article is intended as general information only and does not constitute legal or compliance advice. Businesses should seek qualified advice specific to their circumstances before acting on any information contained in this article.

Pin
Share
Save
Related Insights
an image of a strait or narrow channel, symbolising the rigorous process firms must go through to ensure a succesful 30 June Tax Planning Australia
Read now
an image of a wolf with eyes blazing, symbolising the strict AUSTRAC Audit Process
Read now
an image of a male hiker leaping across a big gash or gap in the mountain, symbolising What Non-Compliance Actually Costs with AML/CTF Penalties
Read now
an image of a fisherman throwning a net into the water while the sun sets in the background, symbolising AML/CTF compliance program requirements.
Read now
We build the resilient foundations
empowering you to scale your business
Get in touch
AML/CTF Risk Assessment
Alquin Dagamina

Business Transformation and Technology Services, Manager