Introduction
Australian reporting entities must assess the money laundering, terrorism financing and proliferation financing (ML/TF/PF) risk posed by each customer as part of initial and ongoing customer due diligence (CDD). Customer risk assessment supports a risk-based AML/CTF program by helping businesses assign an appropriate risk rating and apply suitable policies.
Customer risk assessment differs from a business-wide ML/TF risk assessment. This article explains how reasonably available know your customer (KYC) information and relevant risk factors inform each assessment, and how the result affects simplified or enhanced CDD for reporting entities.
Interactive Tool: Check What Due Diligence Your Customer Needs
Customer AML/CTF Risk Assessment Checker
Quickly check if your customer risk assessment process aligns with Australia’s AML/CTF laws and triggers the right due diligence steps.
What is the current risk rating for your customer?
✅ Simplified CDD May Apply
Legal References:
• Section 31 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
• Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth)
⚖️ Standard CDD Required
Legal References:
• Section 30(2)(b) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
⚠️ Enhanced CDD Required
Legal References:
• Section 32 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
• Section 41 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
⚠️ Risk Reassessment Required
Legal References:
• Section 30(2)(b) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
❌ Enhanced CDD Mandatory for Foreign PEP
Legal References:
• Section 32 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Understanding Customer Risk under the AML/CTF Act
Customer Risk Assessment V Business-Wide Risk Assessment
Customer risk is the ML/TF/PF risk presented by an individual customer. It is assessed case by case during CDD, using the reporting entity’s broader risk assessment as a foundation.
A business-wide assessment, by contrast, examines broad risks across the reporting entity’s operations, including:
- its designated services;
- its customer types;
- its delivery channels; and
- the countries it operates in.
Under Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘), the reporting entity must assess the ML/TF risks it may reasonably face. Customer risk assessment applies those broader risk factors to the circumstances of a particular customer.
Role of KYC Information
Under Section 28(3)(b) of the AML/CTF Act, a reporting entity must identify a customer’s ML/TF risk using KYC information about the customer that is reasonably available before the reporting entity begins providing a designated service. The information must be sufficient to assess the customer’s circumstances and determine whether further CDD is appropriate.
Customer risk must also be considered during ongoing CDD. Under Section 30(2)(b) of the AML/CTF Act, the reporting entity must review and, where appropriate, update its identification and assessment of the customer’s ML/TF risk when relevant circumstances change or unusual transactions or behaviour may give rise to a suspicious matter reporting (SMR) obligation.
Factors to Consider When Assessing Customer Risk
Customer Characteristics & Ownership Structures
Under Section 28(4) of the AML/CTF Act, a reporting entity must consider the kind of customer when identifying the customer’s ML/TF risk. The assessment may involve considering whether the customer is an:
- individual;
- company;
- trust;
- partnership;
- association;
- government body; or
- another legal arrangement.
Relevant customer information can include:
- the ownership and control structure;
- beneficial owners;
- business activities;
- residence or place of incorporation; and
- whether the customer acts through an agent or representative.
A complex legal structure, unexplained wealth, criminal history, non-residence or politically exposed person (PEP) status may increase customer risk, particularly when combined with other risk factors.
Products & Designated Services
Section 28(4) also requires the reporting entity to consider the kinds of designated services provided, or proposed to be provided, to the customer. The relevant risk may depend on the service, transaction value, use of physical currency or virtual assets, and whether legal structures could conceal ownership or the source of funds.
AUSTRAC guidance identifies services that may involve higher ML/TF risks as examples, including:
- real estate brokering;
- remittance services;
- virtual asset services;
- registered office services; and
- bullion dealing.
The service should be assessed in the context of the particular customer rather than treated as determinative on its own.
Delivery Channels & Remote Onboarding
Section 28(4) also requires a reporting entity to consider the delivery channels used to provide designated services to the customer. These may include:
- in-person service;
- staff-assisted remote contact;
- self-service channels; and
- third-party agents or intermediaries.
Remote service delivery can make it harder to identify unusual behaviour and may increase reliance on identification documents, third-party technology or external controls. Remote self-service may also make it easier for a person to hide their identity or the source of funds. Third-party delivery can create further difficulty in confirming who the customer is and, where necessary, verifying the source of funds.
Countries & Geographic Risk
Section 28(4) also requires a reporting entity to consider the countries with which it deals, or will deal, when providing designated services to the customer. This may include the customer’s country of residence, place of incorporation and the countries connected with the service or movement of value.
AUSTRAC guidance states that countries on the Financial Action Task Force (FATF) grey or blacklists, or countries subject to Australian sanctions, should receive a high-risk rating. Other geographic factors may be assessed using a reliable country-risk method, including:
- the country’s AML/CTF framework;
- corruption levels;
- financial transparency;
- public accountability; and
- legal or political risks.
For a practical guide to the relevant rules, download AML/CTF Rules 2025 Free Guide – Tranche 2 & Existing Reporting Entities.
How Should Reporting Entities Assign a Customer Risk Rating
Develop a Documented Risk Rating Methodology
A reporting entity should document a customer risk rating method within its AML/CTF policies, with advice from AML/CTF compliance lawyers for customer risk-rating processes. The method should identify the risk factors drawn from the business’s ML/TF risk assessment and explain how staff assess whether each factor is present for a customer.
The business may use the impact rating from its ML/TF risk assessment as a starting point when assessing customer risk. Its documented method should also explain how staff:
- reach low, medium, or high customer risk ratings; and
- record the decision and reasons for it.
Consider Multiple Risk Factors Together in Context
A customer risk rating should reflect the nature and scale of all relevant risk factors present, rather than treating one red flag as automatically determinative. Reporting entities should check each identified factor, balance the factors together and consider indicators of unusual or criminal activity.
As a result, a customer may have several medium-risk factors without meeting the conditions for a high-risk rating. Conversely, one factor may have a high impact under the business’s documented method and contribute to a high customer risk rating when assessed alongside the customer’s circumstances.
How Does Customer Risk Affect CDD for Your Business
Simplified CDD for Lower-Risk Customers
Under Section 31 of the AML/CTF Act, a reporting entity may apply simplified CDD measures when:
- the customer’s ML/TF risk is low;
- Section 32 of the AML/CTF Act does not apply; and
- the reporting entity complies with the requirements specified in the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (‘AML/CTF Rules’).
However, a low-risk rating does not remove the need for CDD. The reporting entity must still meet the applicable initial or ongoing CDD obligation, using measures permitted by the AML/CTF Act and the AML/CTF Rules.
Implementing Enhanced CDD for Higher-Risk Customers
Under Section 32 of the AML/CTF Act, a reporting entity must apply enhanced CDD measures appropriate to the customer’s ML/TF risk when:
- the customer’s ML/TF risk is high;
- a suspicious matter reporting obligation arises under Section 41 of the AML/CTF Act and the reporting entity proposes to continue providing a designated service; or
- the customer, beneficial owner, or relevant representative is a foreign PEP.
In these circumstances, a high-risk rating does not automatically require the relationship to end. The reporting entity should apply the enhanced CDD measures set out in its AML/CTF policies and consider whether the risk can be managed through appropriate controls.
Reassessing and Updating Customer Risk Ratings
Events That May Trigger a Risk Reassessment
As discussed above, Section 30(2)(b) requires a reporting entity to review and, where appropriate, update its assessment of a customer’s ML/TF risk when relevant circumstances change. This includes changes to:
- the customer type;
- the ownership structure;
- the beneficial owners;
- the designated services;
- the delivery channels; or
- the countries connected with the relationship.
Unusual transactions or behaviour that may give rise to an SMR obligation also require review. Examples include:
- an unexplained increase in transaction volumes;
- a new higher-risk service;
- changes in the customer’s business model; or
- a shift to online service delivery or agent involvement.
Updating KYC Information & Risk Profiles
Under Section 30(2)(c) of the AML/CTF Act, a reporting entity must review, update and reverify KYC information at a frequency appropriate to the customer risk. Further checks may be needed where information appears inadequate or unreliable, or where the customer or beneficial owner becomes a foreign PEP.
AML/CTF policies can set out practical methods, including:
- asking customers to confirm details during telephone or face-to-face contact;
- using a business app to request updates; and
- verifying changes to ownership, beneficial owners, representatives, source of funds or source of wealth.
Managing High-Risk Customers & Avoiding Common Assessment Mistakes
Alternatives to Rejecting High-Risk Customers
A high customer risk rating does not automatically require a reporting entity to reject or end the customer relationship. As discussed above, Section 32 of the AML/CTF Act requires the reporting entity to apply enhanced CDD measures appropriate to the customer’s ML/TF risk.
Those measures may include:
- additional KYC checks.
- source of funds and source of wealth enquiries.
- closer transaction monitoring.
- limits on particular services or channels.
- senior management approval where required by the reporting entity’s AML/CTF policies.
AUSTRAC guidance states that higher risk does not automatically mean services must stop, provided suitable systems and controls can manage the risk.
Common Mistakes in Customer Risk Assessments
Customer risk assessments can become unreliable when a business applies a generic score without considering the customer’s circumstances. Other common mistakes include:
- treating one red flag as conclusive without weighing other factors.
- failing to assess the customer, service, delivery channel and countries involved.
- confusing individual customer risk with the business-wide ML/TF risk assessment.
- failing to record the rating, reasons and supporting KYC information.
- failing to update the rating when circumstances, transactions or behaviour change.
A rating should reflect the nature and scale of the relevant factors considered together.
Practical Steps for Assessing Customer Risk
A customer risk assessment can follow a documented sequence:
- Collect reasonably available KYC information before providing the designated service.
- Identify the relevant customer, service, delivery channel and country risk factors.
- Apply the business’s documented method to assign a low, medium or high rating.
- Collect and verify further KYC information required by the customer’s risk level.
- Record the rating, reasons, CDD response and verification steps.
- Monitor the relationship and review the rating when relevant circumstances change.
Click Legal’s AML/CTF Compliance Checklist (Free) can assist with reviewing related customer risk and CDD controls.
Conclusion
Customer risk must be assessed case by case using reasonably available KYC information and the relevant factors identified in the reporting entity’s broader ML/TF risk assessment. Customer risk ratings guide initial and ongoing CDD, including when simplified CDD may apply and when enhanced CDD is required, but a high-risk rating does not automatically require the relationship to end.
With these requirements in mind, contact AML/CTF compliance lawyers at Click Legal for help reviewing your AML/CTF policies and customer risk processes.