Introduction
The products and services a business provides can create money laundering, terrorism financing and proliferation financing (ML/TF/PF) risk when criminals exploit vulnerabilities to move, conceal or store illicit funds. Reporting entities must assess the risks they may reasonably face when providing designated services.
Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act’) requires this assessment to reflect the business’s own designated services and circumstances, including its customers, delivery channels, countries and new or emerging technologies. This guide explains how product and service characteristics affect risk and how businesses should assess them within their AML/CTF program.
Interactive Tool: Check the AML/CTF Risk of Your Products & Services
AML/CTF Product & Service Risk Checker
Quickly assess whether your business’s products or services create higher money laundering or terrorism financing risk under Australian AML/CTF law.
Does your business provide any of the following designated services?
Do your products or services allow for rapid movement of funds, high-value transactions, or involve anonymous or complex ownership structures?
Are any new or emerging technologies (such as online platforms, virtual assets, or remote delivery channels) involved in delivering your services?
⚠️ Higher AML/CTF Risk Identified
📋 Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
📋 Section 26F of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
📋 Section 26D of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
⚖️ Moderate AML/CTF Risk – Assessment Required
📋 Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
✅ Low AML/CTF Risk – Maintain Compliance
📋 Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
✅ No Designated Service – Minimal AML/CTF Risk
📋 Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
How Products & Services Create AML/CTF Risk
Providing a designated service or product does not automatically mean that it presents a high level of ML/TF/PF risk. A business’s products and services can create ML/TF/PF risk when criminals exploit the way those offerings allow money, property or other value to be moved, converted, raised, stored or concealed. The risk may increase where a product or service involves:
- rapid movement of funds or virtual assets;
- high-value transactions;
- anonymous customers or ownership structures;
- complex companies, trusts, or other legal arrangements;
- third-party agents, representatives, or intermediaries; or
- cross-border transactions.
Remote products and services, including those delivered through new or emerging technologies, may reduce visibility of the customer, transaction, or source of funds. These features can help criminals disguise illicit origins, conceal ownership or use a legitimate business to support further criminal activity.
How to Assess the ML/TF/PF Risks of a Product or Service
Assessing Risks Reasonably Faced When Providing Designated Services
Section 26C(1) of the AML/CTF Act requires each reporting entity to undertake an AML/CTF risk assessment to identify and assess the ML/TF/PF risks that the reporting entity may reasonably face when providing its designated services.
The steps used for the assessment must be appropriate to the nature, size, and complexity of the reporting entity's business under Section 26C(2).
Evaluating New Products & Emerging Technologies Before Launch
For reporting entities that provide designated services at or through a permanent establishment in Australia, Section 26C(3)(a) of the AML/CTF Act requires the ML/TF risk assessment to consider designated services provided or proposed to be provided. This also includes new or emerging technologies connected with those services. The assessment should address how the proposed service or technology could expose the business to ML/TF/PF risk.
A product or service should not be assessed in isolation from the way it operates. A reporting entity should examine:
- the features of the proposed service;
- the value or property involved; and
- whether new technology changes how customers access or use the service.
For further assistance, download the AML/CTF Rules 2025 (Cth) Free Guide – Tranche 2 & Existing Reporting Entities.
Services With Higher ML/TF/PF Risks for Reporting Entities
Moving or Transferring Money & Value
Remittance, payment and value-transfer services can allow funds to move quickly, including across national borders. This speed, low cost and access to offshore destinations may make these services attractive for ML/TF/PF.
Section 6(2), Table 1 items 29–31 of the AML/CTF Act identifies the relevant designated services, which involve:
- an ordering institution accepting a transfer instruction;
- a beneficiary institution making value available to a payee; or
- an intermediary institution passing on a transfer message.
A reporting entity should assess how its particular service could allow value to be raised, moved or stored, including through high-value transactions and exposure to higher-risk countries.
Virtual Asset Services & Convergence Risks
Virtual asset services can allow value to move quickly between virtual assets, traditional money and different jurisdictions. Virtual asset exchanges may make funds harder to trace, while virtual asset safekeeping services can allow value to be stored through digital wallets that are difficult to attribute to the person controlling them.
AUSTRAC's 'Money laundering update 2026' identifies convergence between virtual asset service providers, remittance services, bullion dealing and cash services as a key risk. Criminal networks may combine these services to convert and transfer value rapidly while reducing reliance on regulated conversion points and creating gaps in detection.
Managing or Controlling Customer Assets
A service may create greater risk where a business receives, holds, controls, disburses or manages customer property as part of a transaction. Section 6(5B), Table 6 item 3 of the AML/CTF Act covers customer money, accounts, securities, securities accounts, virtual assets and other property.
Control over customer assets can provide access to value that criminals may seek to move, conceal or use in a transaction. The risk assessment should therefore consider:
- the type of property involved;
- how the business receives or controls it; and
- whether the service could obscure the source or ownership of that property.
Creating or Managing Companies & Trusts
Company and trust services can create risk where legal structures make it harder to identify the person who owns, controls or benefits from assets. Under Section 6(5B), Table 6, items 5-9 of the AML/CTF Act, relevant designated services include:
- creating or restructuring a body corporate or legal arrangement;
- selling a shelf company;
- arranging nominee directors or shareholders; or
- providing a registered office address.
Criminals may use companies, trusts and other structures to appear legitimate, hide connections to illegal activity or disguise the source of funds and wealth. Complex structures linked to other countries may also help move illegal funds to higher-risk jurisdictions.
Real Estate Transactions
Real estate can be used to combine illegal funds with the economy or store value derived from crime. Criminals may also attempt to change property values or use complex ownership structures to hide who owns the property.
Section 6(5A), Table 5, items 1 and 2 of the AML/CTF Act covers:
- brokering the sale, purchase, or transfer of real estate on behalf of specified parties; and
- certain sales or transfers by businesses selling real estate where the transaction is not brokered by an independent real estate agent.
Section 6(5B), Table 6 item 1 separately covers certain professional services involving assisting, or acting for or on behalf of a person, in a transaction to sell, buy or otherwise transfer real estate.
Businesses providing real estate services can download the AML/CTF Compliance Guide for Real Estate Agents (2026 Readiness).
Buying & Selling High-Value Assets
Bullion and other high-value assets can allow illicit cash or virtual assets to be converted into property that is stable, portable, and capable of being resold. Bullion may also be moved overseas or used to support further criminal activity or proliferation financing.
The designated services provisions cover buying or selling bullion under Section 6(3), Table 2 item 1 of the AML/CTF Act. Further, Section 6(3), Table 2 item 2 also covers buying or selling precious metals, precious stones and precious products where the purchase involves physical currency, virtual assets or both with a total value of at least $10,000, whether through one transaction or linked transactions.
The Impact of Other Risk Factors on Product & Service Risk
Delivery Channels & Remote Technologies
Delivery channels can change the risk associated with a product or service. Remote delivery through email, telephone, video chat or online platforms may reduce face-to-face visibility, making it harder to identify unusual behaviour, verify identity documents, or understand the source of funds and wealth.
In addition, self-service methods, such as smart ATMs, pre-paid cards, online banking and online remittance services, remove staff interaction before a transaction occurs. Third-party agents and platforms may also make it harder to know who the customer is and verify the source of funds. Risk factors may include:
- forged or stolen identification;
- reliance on external systems or controls;
- weak document security; and
- fraudulent or cross-border transactions.
Customer & Geographic Risk Factors
Customer and country risk should be assessed alongside product and service risk. Customers with criminal histories, foreign politically exposed person (PEP) status, unexplained wealth, complex legal structures, non-resident status or third-party representatives may create higher ML/TF risk when using an otherwise ordinary service.
Furthermore, a reporting entity should list the countries it deals with, including where customers reside or where companies and legal arrangements are registered. Country risk may be assessed using reliable information, including the Basel AML Index, Financial Action Task Force (FATF) grey and blacklists, and Australian sanctions information.
Under Section 26C(3)(b)–(d) of the AML/CTF Act, these customer, delivery channel and country factors must be considered when undertaking the ML/TF risk assessment.
Tips for Rating & Reassessing Product & Service Risk
Assessing Inherent Risk Before Applying Controls
AUSTRAC guidance expects businesses to assess inherent risk before considering their existing policies, procedures, systems, and controls. This means examining how easily each product or service could be exploited to:
- hide identity;
- obscure the source of funds or wealth; or
- raise, move or store value.
A medium-complexity business may assess likelihood and impact, while a smaller, less complex business may assess impact alone. The reasoning and information used to assign each risk rating should be clearly documented.
Matching AML/CTF Controls to the Level of Risk
Under Section 26F(1) of the AML/CTF Act, a reporting entity must develop and maintain policies, procedures, systems, and controls that appropriately manage and mitigate the ML/TF/PF risks it may reasonably face, with AML/CTF compliance lawyers able to assist with applying risk-based controls.
AUSTRAC guidance states that controls should be targeted, proportionate, ongoing and effective. Higher risks generally require stronger and more focused controls, while lower risks may be managed with simpler measures. A reporting entity may also use service limits, additional customer monitoring or enhanced customer due diligence where the assessed risk requires those measures.
Triggers for Reassessing Product & Service Risk
Under Section 26D(1) of the AML/CTF Act, a reporting entity must review its ML/TF risk assessment in the following circumstances:
- there is a significant change to a relevant risk factor;
- AUSTRAC communicates information about risks associated with its designated services; or
- circumstances specified in the AML/CTF Rules occur.
The assessment must also be reviewed at least once every three years.
The review should occur before a major change that is within the reporting entity's control. Relevant triggers may include:
- a new designated service;
- a change to an existing product;
- new or emerging technology;
- a new delivery channel; or
- updated AUSTRAC risk information.
Businesses can use the AML/CTF Compliance Checklist (Free) to review their existing compliance processes.
Common Product & Service Risk Assessment Mistakes
A risk assessment should not treat every service as having the same risk. A sector, product, or service should not be labelled automatically high or low risk without considering the business's own circumstances, vulnerabilities and available information.
Common mistakes include:
- assessing products separately from customers, delivery channels and countries;
- overlooking new or emerging technologies;
- failing to assess proposed services before launch; and
- assigning generic risk ratings without recording the reasoning and supporting data.
The assessment should explain how each rating was reached and remain flexible enough to capture new or emerging risks.
Conclusion
Products and services can create ML/TF/PF risk when their features allow value to be moved, stored or concealed, particularly when combined with customer, delivery channel and country risks. Section 26C of the AML/CTF Act requires reporting entities to assess these risks, apply suitable controls under Section 26F, and review the assessment under Section 26D.
To take the next step, contact our AML/CTF compliance lawyers at Click Legal for clear assistance with assessing product and service risk within your AML/CTF program.