Introduction
Geographic exposure is a key anti-money laundering and counter-terrorism financing (AML/CTF) risk factor for Australian reporting entities and newly regulated Tranche 2 businesses. Countries connected with customers, transactions, or designated services can create money laundering, terrorism financing, and proliferation financing (ML/TF/PF) risks because criminals may exploit cross-border vulnerabilities to hide funds or move assets.
Businesses must assess country risk alongside customer, service, and delivery-channel risks. FATF-listed jurisdictions do not automatically make every customer or transaction high risk; geographic exposure should inform customer due diligence (CDD), transaction monitoring, and other AML/CTF controls.
Interactive Tool: Check Your AML Country Risk Level
AML Geographic Risk Assessment Checker
Quickly assess if your business’s country connections trigger higher AML/CTF risk and require enhanced due diligence under the AML/CTF Act.
Does your business or any of its customers deal with, or have connections to, countries outside Australia?
Are any of these countries listed as high-risk by the FATF or subject to Australian sanctions?
Has your business updated its ML/TF risk assessment in the last 3 years or after any significant change in country exposure?
⚠️ High-Risk Country Exposure Detected
📋 Section 26C(3)(d) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
📋 Section 28(4)(e) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
📋 Anti-Money Laundering and Counter-Terrorism Financing (Prescribed Foreign Countries) Regulations 2018 (Cth)
✅ Foreign Country Connections – Standard Risk
📋 Section 26C(3)(d) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
📋 Section 28(4)(e) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
⚖️ Uncertain Country Risk – Further Assessment Needed
📋 Section 26C(3)(d) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
📋 Section 28(4)(e) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
✅ Domestic Only – Lower Geographic Risk
📋 Section 26D of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
❌ Outdated or Missing ML/TF Risk Assessment
📋 Section 26D of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
What Is Geographic Risk for AML/CTF Purposes
Which Countries Should a Business Consider
Under Section 26C(3)(d) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘), a reporting entity that provides designated services at or through a permanent establishment in Australia must have regard to the countries with which it deals, or will deal, in providing its designated services. Separately, AUSTRAC guidance expects businesses to identify every country they deal in or with when providing designated services, including Australia, including relevant countries connected with customers and their dealings.
Relevant connections include:
- the country where an individual customer resides;
- the country where a body corporate or legal arrangement is registered or incorporated; and
- countries involved in transactions or other dealings connected with the designated service.
Geographic Risk vs Customer Risk
Under Section 28(4)(e) of the AML/CTF Act, geographic exposure is one factor in assessing a customer’s overall ML/TF/PF risk. A customer connected with a higher-risk country is not automatically a high-risk customer solely for that reason.
The country connection should be assessed alongside other customer and service factors. These may include:
- the customer’s type;
- ownership structure;
- delivery channel;
- source of funds or wealth; and
- the designated service being provided.
A customer who resides overseas may present additional risk, because identity information or financial details can be harder to verify even where the country itself has a lower country-risk rating.
Geographic Risk in Customer Due Diligence
Under Section 28(3)(b) of the AML/CTF Act, a reporting entity must identify the ML/TF risk of a customer through CDD using reasonably available know-your-customer (KYC) information before providing a designated service. Under Section 28(4)(e) of the AML/CTF Act, this assessment must take account of the countries with which the reporting entity deals, or will deal, in providing designated services to that customer.
Country exposure is assessed alongside:
- the reporting entity’s overall ML/TF risk assessment;
- the type of customer;
- the designated service; and
- the delivery channel.
The customer’s ML/TF risk then informs the KYC information collected, and the information verified using reliable and independent data.
Updating Your Geographic Risk Assessment
Under Section 26D(1)(a)(i)-(ii) of the AML/CTF Act, a reporting entity must review its ML/TF risk assessment in the following circumstances:
- when there is a significant change to matters considered under Section 26C(3) of the AML/CTF Act, including the countries with which it deals;
- AUSTRAC communicates information identifying or assessing risks associated with its designated services; and
- in any event at least once every three years.
Under Section 26D(4)(a)-(b) of the AML/CTF Act, the entity must update its ML/TF risk assessment to address issues identified by the review before a significant change that is within its control occurs, or, in any other case, as soon as practicable after the review is completed.
What Makes a Country or Region Higher Risk?
FATF High-Risk & Monitored Jurisdictions
The Financial Action Task Force (FATF) publishes statements about jurisdictions with serious weaknesses in their AML/CTF regimes. These statements can inform a reporting entity’s country risk assessment, but a FATF listing does not automatically make every customer or transaction high risk.
The FATF’s “black list” covers high-risk jurisdictions subject to a call for action. In its statement dated 19 June 2026, this category included:
- the Democratic People’s Republic of Korea;
- Iran; and
- Myanmar.
The FATF calls for enhanced due diligence for high-risk jurisdictions and, in the most serious cases, countermeasures.
The “grey list“ covers jurisdictions under increased monitoring because they are working with the FATF to address identified deficiencies. The FATF does not call for enhanced due diligence solely because a jurisdiction appears on this list. Businesses should consider the information as part of a risk-based assessment, rather than automatically refusing all customers or transactions connected with a grey-listed jurisdiction.
Sanctions, Terrorism & Other Risk Indicators
A country or region may present elevated ML/TF/PF risk because it:
- is subject to sanctions;
- is a prescribed foreign country;
- is a known tax haven;
- has corruption concerns or weak AML/CTF controls; or
- is known to support terrorist organisations.
These indicators should be assessed as part of the business’s geographic risk assessment.
Sanctions compliance remains a separate issue from AML/CTF geographic risk. AUSTRAC guidance states that businesses must not:
- deal with assets owned or controlled by a person designated for targeted financial sanctions;
- make assets available to that person; or
- provide designated services to people on the Department of Foreign Affairs and Trade (DFAT) Consolidated List.
The prescribed foreign countries identified in AUSTRAC guidance are Iran and the Democratic People’s Republic of Korea. They are prescribed under the Anti-Money Laundering and Counter-Terrorism Financing (Prescribed Foreign Countries) Regulations 2018 (Cth) (‘Prescribed Foreign Countries Regulations‘), made under the AML/CTF Act.
Tax havens can increase geographic risk because limited taxation and restricted financial information-sharing may help criminals conceal income or evade tax obligations. Multiple international transfers to or from a known tax haven may require closer assessment, particularly where there are reasonable grounds to suspect tax evasion or another tax offence.
How Should Businesses Assess Geographic Risk?
Using Reliable Country Risk Sources
Country risk assessments should rely on current and credible information. AUSTRAC guidance identifies the Basel AML Index as one possible source for assessing ML/TF risk. This index considers the quality of a country’s AML/CTF framework, bribery and corruption, financial transparency, public accountability, and legal and political risks.
Compliance teams should also review:
- FATF updates on high-risk and monitored jurisdictions;
- AUSTRAC guidance and risk information; and
- DFAT sanctions lists and sanctions information.
Combining Geographic Risk With Other Risk Factors
AUSTRAC guidance expects businesses to assess inherent risk by considering how each factor could be exploited to conceal identity, source of funds or wealth, or the movement and storage of value.
The overall rating in an AML/CTF risk assessment should reflect the combined factors — such as the customer’s structure, the services provided, the delivery channel, and the likelihood and impact of the identified risks — rather than treating any higher-risk country connection as automatically high risk.
Practical Steps for Assessing Geographic Risk
A country-risk assessment can follow a documented sequence:
- list every country the business or its customers deal in or with, including Australia;
- record where individual customers reside and where bodies corporate or legal arrangements are registered or incorporated;
- assess each country using reliable risk sources;
- assign and explain a country-risk rating; and
- review the assessment as risks and available information change.
To help compliance teams apply these steps, download the AML/CTF Compliance Checklist (Free) from Click Legal.
Common Geographic Risk Assessment Mistakes
Overreliance on FATF Lists & Misunderstanding Grey Lists
Relying only on FATF lists can produce an incomplete geographic risk assessment. As discussed above, a high-risk jurisdiction subject to a call for action may require enhanced due diligence (or countermeasures in the most serious cases), whereas a grey listing does not itself call for enhanced due diligence. In both cases, the listing should be considered alongside the customer, designated service and delivery-channel risks rather than triggering automatic refusal of customers or transactions.
AML/CTF geographic risk should also be kept separate from sanctions compliance, as described above.
Overlooking Transaction Jurisdictions & Domestic Risks
A country-risk assessment should include every country the business or its customers deal in or with when providing designated services, including transaction-related countries. Omitting a transaction-related country can leave a material risk outside the assessment.
Australia should also be included rather than treated as risk-free. Country ratings should be supported by reliable information and kept current as risks change, including changes communicated by AUSTRAC or changes in country exposure; outdated ratings may fail to reflect new ML/TF/PF risks affecting the business’s designated services.
Conclusion
Geographic risk is one part of a reporting entity’s wider ML/TF/PF assessment, covering countries connected with customers, designated services and transactions, including Australia. FATF listings can inform risk ratings, but they do not automatically make every customer or transaction high risk, and geographic risk should remain separate from sanctions compliance.
To apply these requirements to your business, contact Click Legal’s AML/CTF compliance lawyers for help reviewing your country-risk assessment, customer due diligence and monitoring controls. Click Legal can provide clear guidance on how Section 26C, Section 28 and Section 26D of the AML/CTF Act relate to geographic risk.