Customer Risk Under Australia’s AML/CTF Laws: Complete Guide for Reporting Entities

Published By:

Hannah Deuk

Founder & Principal Lawyer

Key Takeaways:

  • Case-by-case assessment: Assess each customer using reasonably available KYC information before providing designated services.
  • Risk rating method: Consider customer, service, delivery channel and country factors together to assign low, medium or high risk.
  • Simplified or enhanced CDD: Low-risk customers may receive simplified CDD, while high-risk customers require enhanced CDD appropriate to assessed ML/TF risk.
  • Ongoing review: Review and update customer risk and KYC information when circumstances change, unusual behaviour occurs or SMR obligations may arise.
Jump to...
October 2, 2026

Introduction

Australian reporting entities must assess the money laundering, terrorism financing and proliferation financing (ML/TF/PF) risk posed by each customer as part of initial and ongoing customer due diligence (CDD). Customer risk assessment supports a risk-based AML/CTF program by helping businesses assign an appropriate risk rating and apply suitable policies.

Customer risk assessment differs from a business-wide ML/TF risk assessment. This article explains how reasonably available know your customer (KYC) information and relevant risk factors inform each assessment, and how the result affects simplified or enhanced CDD for reporting entities.

Interactive Tool: Check What Due Diligence Your Customer Needs

Customer AML/CTF Risk Assessment Checker

Quickly check if your customer risk assessment process aligns with Australia’s AML/CTF laws and triggers the right due diligence steps.

What is the current risk rating for your customer?

✅ Simplified CDD May Apply

Your customer is rated low risk. Under Section 31 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), you may apply simplified customer due diligence (CDD) if all other requirements are met.

However, you must still complete initial and ongoing CDD as required by the AML/CTF Act and AML/CTF Rules. Document your risk assessment and review it regularly.

Legal References:

• Section 31 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

• Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth)

Get AML/CTF Legal Advice

⚖️ Standard CDD Required

Your customer is rated medium risk. You must apply standard CDD measures and monitor for any changes in risk factors.

Ensure your assessment is documented and update it if circumstances change. Ongoing review is required under Section 30(2)(b) of the AML/CTF Act.

Legal References:

• Section 30(2)(b) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

Speak to a Lawyer

⚠️ Enhanced CDD Required

Your customer is rated high risk. Under Section 32 of the AML/CTF Act, you must apply enhanced CDD measures. This includes additional KYC checks, source of funds/wealth enquiries, and closer transaction monitoring.

Senior management approval may be required. Enhanced CDD is also mandatory if the customer or beneficial owner is a foreign PEP or if a suspicious matter reporting obligation arises.

Legal References:

• Section 32 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

• Section 41 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

Get AML/CTF Legal Advice

⚠️ Risk Reassessment Required

A change in customer circumstances or unusual transactions has occurred. Under Section 30(2)(b) of the AML/CTF Act, you must review and, where appropriate, update your risk assessment and KYC information.

Failure to do so may result in non-compliance and regulatory action.

Legal References:

• Section 30(2)(b) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

Speak to a Lawyer

❌ Enhanced CDD Mandatory for Foreign PEP

A foreign Politically Exposed Person (PEP) is involved. Under Section 32 of the AML/CTF Act, enhanced CDD is mandatory. You must apply strict controls, including verifying the source of funds and obtaining senior management approval before proceeding.

Legal References:

• Section 32 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

Get AML/CTF Legal Advice

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Understanding Customer Risk under the AML/CTF Act

Customer Risk Assessment V Business-Wide Risk Assessment

Customer risk is the ML/TF/PF risk presented by an individual customer. It is assessed case by case during CDD, using the reporting entity’s broader risk assessment as a foundation.

A business-wide assessment, by contrast, examines broad risks across the reporting entity’s operations, including:

  • its designated services;
  • its customer types;
  • its delivery channels; and
  • the countries it operates in.

Under Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘), the reporting entity must assess the ML/TF risks it may reasonably face. Customer risk assessment applies those broader risk factors to the circumstances of a particular customer.

Role of KYC Information

Under Section 28(3)(b) of the AML/CTF Act, a reporting entity must identify a customer’s ML/TF risk using KYC information about the customer that is reasonably available before the reporting entity begins providing a designated service. The information must be sufficient to assess the customer’s circumstances and determine whether further CDD is appropriate.

Customer risk must also be considered during ongoing CDD. Under Section 30(2)(b) of the AML/CTF Act, the reporting entity must review and, where appropriate, update its identification and assessment of the customer’s ML/TF risk when relevant circumstances change or unusual transactions or behaviour may give rise to a suspicious matter reporting (SMR) obligation.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Factors to Consider When Assessing Customer Risk

Customer Characteristics & Ownership Structures

Under Section 28(4) of the AML/CTF Act, a reporting entity must consider the kind of customer when identifying the customer’s ML/TF risk. The assessment may involve considering whether the customer is an:

  • individual;
  • company;
  • trust;
  • partnership;
  • association;
  • government body; or
  • another legal arrangement.

Relevant customer information can include:

  • the ownership and control structure;
  • beneficial owners;
  • business activities;
  • residence or place of incorporation; and
  • whether the customer acts through an agent or representative.

A complex legal structure, unexplained wealth, criminal history, non-residence or politically exposed person (PEP) status may increase customer risk, particularly when combined with other risk factors.

Products & Designated Services

Section 28(4) also requires the reporting entity to consider the kinds of designated services provided, or proposed to be provided, to the customer. The relevant risk may depend on the service, transaction value, use of physical currency or virtual assets, and whether legal structures could conceal ownership or the source of funds.

AUSTRAC guidance identifies services that may involve higher ML/TF risks as examples, including:

  • real estate brokering;
  • remittance services;
  • virtual asset services;
  • registered office services; and
  • bullion dealing.

The service should be assessed in the context of the particular customer rather than treated as determinative on its own.

Delivery Channels & Remote Onboarding

Section 28(4) also requires a reporting entity to consider the delivery channels used to provide designated services to the customer. These may include:

  • in-person service;
  • staff-assisted remote contact;
  • self-service channels; and
  • third-party agents or intermediaries.

Remote service delivery can make it harder to identify unusual behaviour and may increase reliance on identification documents, third-party technology or external controls. Remote self-service may also make it easier for a person to hide their identity or the source of funds. Third-party delivery can create further difficulty in confirming who the customer is and, where necessary, verifying the source of funds.

Countries & Geographic Risk

Section 28(4) also requires a reporting entity to consider the countries with which it deals, or will deal, when providing designated services to the customer. This may include the customer’s country of residence, place of incorporation and the countries connected with the service or movement of value.

AUSTRAC guidance states that countries on the Financial Action Task Force (FATF) grey or blacklists, or countries subject to Australian sanctions, should receive a high-risk rating. Other geographic factors may be assessed using a reliable country-risk method, including:

  • the country’s AML/CTF framework;
  • corruption levels;
  • financial transparency;
  • public accountability; and
  • legal or political risks.

For a practical guide to the relevant rules, download AML/CTF Rules 2025 Free Guide – Tranche 2 & Existing Reporting Entities.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

How Should Reporting Entities Assign a Customer Risk Rating

Develop a Documented Risk Rating Methodology

A reporting entity should document a customer risk rating method within its AML/CTF policies, with advice from AML/CTF compliance lawyers for customer risk-rating processes. The method should identify the risk factors drawn from the business’s ML/TF risk assessment and explain how staff assess whether each factor is present for a customer.

The business may use the impact rating from its ML/TF risk assessment as a starting point when assessing customer risk. Its documented method should also explain how staff:

  • reach low, medium, or high customer risk ratings; and
  • record the decision and reasons for it.

Consider Multiple Risk Factors Together in Context

A customer risk rating should reflect the nature and scale of all relevant risk factors present, rather than treating one red flag as automatically determinative. Reporting entities should check each identified factor, balance the factors together and consider indicators of unusual or criminal activity.

As a result, a customer may have several medium-risk factors without meeting the conditions for a high-risk rating. Conversely, one factor may have a high impact under the business’s documented method and contribute to a high customer risk rating when assessed alongside the customer’s circumstances.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

How Does Customer Risk Affect CDD for Your Business

Simplified CDD for Lower-Risk Customers

Under Section 31 of the AML/CTF Act, a reporting entity may apply simplified CDD measures when:

However, a low-risk rating does not remove the need for CDD. The reporting entity must still meet the applicable initial or ongoing CDD obligation, using measures permitted by the AML/CTF Act and the AML/CTF Rules.

Implementing Enhanced CDD for Higher-Risk Customers

Under Section 32 of the AML/CTF Act, a reporting entity must apply enhanced CDD measures appropriate to the customer’s ML/TF risk when:

  • the customer’s ML/TF risk is high;
  • a suspicious matter reporting obligation arises under Section 41 of the AML/CTF Act and the reporting entity proposes to continue providing a designated service; or
  • the customer, beneficial owner, or relevant representative is a foreign PEP.

In these circumstances, a high-risk rating does not automatically require the relationship to end. The reporting entity should apply the enhanced CDD measures set out in its AML/CTF policies and consider whether the risk can be managed through appropriate controls.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Reassessing and Updating Customer Risk Ratings

Events That May Trigger a Risk Reassessment

As discussed above, Section 30(2)(b) requires a reporting entity to review and, where appropriate, update its assessment of a customer’s ML/TF risk when relevant circumstances change. This includes changes to:

  • the customer type;
  • the ownership structure;
  • the beneficial owners;
  • the designated services;
  • the delivery channels; or
  • the countries connected with the relationship.

Unusual transactions or behaviour that may give rise to an SMR obligation also require review. Examples include:

  • an unexplained increase in transaction volumes;
  • a new higher-risk service;
  • changes in the customer’s business model; or
  • a shift to online service delivery or agent involvement.

Updating KYC Information & Risk Profiles

Under Section 30(2)(c) of the AML/CTF Act, a reporting entity must review, update and reverify KYC information at a frequency appropriate to the customer risk. Further checks may be needed where information appears inadequate or unreliable, or where the customer or beneficial owner becomes a foreign PEP.

AML/CTF policies can set out practical methods, including:

  • asking customers to confirm details during telephone or face-to-face contact;
  • using a business app to request updates; and
  • verifying changes to ownership, beneficial owners, representatives, source of funds or source of wealth.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Managing High-Risk Customers & Avoiding Common Assessment Mistakes

Alternatives to Rejecting High-Risk Customers

A high customer risk rating does not automatically require a reporting entity to reject or end the customer relationship. As discussed above, Section 32 of the AML/CTF Act requires the reporting entity to apply enhanced CDD measures appropriate to the customer’s ML/TF risk.

Those measures may include:

  • additional KYC checks.
  • source of funds and source of wealth enquiries.
  • closer transaction monitoring.
  • limits on particular services or channels.
  • senior management approval where required by the reporting entity’s AML/CTF policies.

AUSTRAC guidance states that higher risk does not automatically mean services must stop, provided suitable systems and controls can manage the risk.

Common Mistakes in Customer Risk Assessments

Customer risk assessments can become unreliable when a business applies a generic score without considering the customer’s circumstances. Other common mistakes include:

  • treating one red flag as conclusive without weighing other factors.
  • failing to assess the customer, service, delivery channel and countries involved.
  • confusing individual customer risk with the business-wide ML/TF risk assessment.
  • failing to record the rating, reasons and supporting KYC information.
  • failing to update the rating when circumstances, transactions or behaviour change.

A rating should reflect the nature and scale of the relevant factors considered together.

Practical Steps for Assessing Customer Risk

A customer risk assessment can follow a documented sequence:

  1. Collect reasonably available KYC information before providing the designated service.
  2. Identify the relevant customer, service, delivery channel and country risk factors.
  3. Apply the business’s documented method to assign a low, medium or high rating.
  4. Collect and verify further KYC information required by the customer’s risk level.
  5. Record the rating, reasons, CDD response and verification steps.
  6. Monitor the relationship and review the rating when relevant circumstances change.

Click Legal’s AML/CTF Compliance Checklist (Free) can assist with reviewing related customer risk and CDD controls.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Conclusion

Customer risk must be assessed case by case using reasonably available KYC information and the relevant factors identified in the reporting entity’s broader ML/TF risk assessment. Customer risk ratings guide initial and ongoing CDD, including when simplified CDD may apply and when enhanced CDD is required, but a high-risk rating does not automatically require the relationship to end.

With these requirements in mind, contact AML/CTF compliance lawyers at Click Legal for help reviewing your AML/CTF policies and customer risk processes.

Frequently Asked Questions

JUMP TO...
Table of Contents

Published By:

Hannah Deuk

Founder & Principal Lawyer

Request A Free Consultation

Our senior lawyers will contact you to discuss your situation & outline next steps.

Insights Library

Legal & Compliance Insights

Browse practical articles, guides & updates from our lawyers on key legal & compliance issues.

Join our Newsletter

Subscribe to our newsletter for the latest legal updates, insights, and firm news delivered straight to your inbox.

What Our Clients Say About Working With Us

Ready-to-Use Legal & Compliance Templates

Lawyer‑drafted legal templates in downloadable Word format.

CONTACT

Request A Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Inquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.