Introduction
Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘), every reporting entity must complete a documented risk assessment before providing any designated service. Section 26E makes it a civil penalty provision to commence services without a current risk assessment in place.
This requirement applies to reporting entities subject to Part 1A of the AML/CTF Act and regulated by the Australian Transaction Reports and Analysis Centre (AUSTRAC). In this article, we explain how to conduct an AML/CTF risk assessment and what it should include.
Interactive Tool: Check If Your AML/CTF Risk Assessment Is Up to Date & Approved
AML/CTF Risk Assessment Readiness Checker
Quickly check if your business meets the core AML/CTF risk assessment requirements under the AML/CTF Act before providing designated services.
Have you completed a documented AML/CTF risk assessment for your business within the last three years?
Has there been any significant change to your services, customers, delivery channels or countries of operation since your last assessment?
Has your risk assessment been formally approved by a senior manager or governing body as required?
✅ AML/CTF Risk Assessment Likely Compliant
Legal References:
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26D of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26F(4)(c) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
⚠️ Risk Assessment Outdated or Not Reviewed After Trigger
Legal References:
- Section 26D of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26E of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
❌ Risk Assessment Not Formally Approved
Legal References:
- Section 26F(4)(c) of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
❌ No AML/CTF Risk Assessment Completed
Legal References:
- Section 26C of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Section 26E of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
The Legal Framework for AML/CTF Reporting Entities
Understanding the Core Obligations
A reporting entity‘s risk assessment is a legal requirement, not merely an internal compliance document. Under Section 26C(1) of the AML/CTF Act, the entity must identify and assess the money laundering, terrorism financing and proliferation financing (ML/TF/PF) risks it may reasonably face when providing designated services. Further, in terms of Rule 5-15(1) of the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (‘AML/CTF Rules’), the risk assessment needs to be documented before the entity first commences providing the designated service.
Section 26C(2) requires the steps used for the risk assessment to suit the nature, size and complexity of the business. For reporting entities providing designated services through a permanent establishment in Australia, Section 26C(3) also identifies matters to consider, including:
- the entity’s services;
- customers;
- delivery channels;
- countries of operation;
- AUSTRAC communications; and
- matters specified in the AML/CTF Rules.
Civil Penalty Consequences
A reporting entity cannot commence providing a designated service to a customer unless it complies with Section 26C or Section 26D of the AML/CTF Act. Section 26E(1) applies where the entity does not have a risk assessment that meets the relevant requirements or has not completed a required review or update.
Section 26E(2) makes this a civil penalty provision, with the following consequences:
- each designated service provided through a permanent establishment in Australia is treated as a separate contravention under Section 26E(3); and
- each day of provision through a permanent establishment in a foreign country is treated as a separate contravention under Section 26E(4).
Where a civil penalty provision is contravened, the AUSTRAC CEO may apply for a civil penalty order under Section 176, and the Federal Court may impose a pecuniary penalty under Section 175.
Core Risk Categories Reporting Entities Must Include in an Assessment
Assessing Customer Types & Their Risk Factors
Customer types can create different ML/TF/PF risks. Under Section 26C(3)(b) of the AML/CTF Act, the assessment must consider the kinds of customers to whom designated services are provided or proposed to be provided.
AUSTRAC guidance identifies customer risk factors that may be relevant to this assessment, including:
- Politically exposed persons (PEPs), including foreign PEPs, domestic PEPs and their family members or close associates;
- high-net-worth individuals whose source of wealth or funds may be difficult to establish; and
- non-residents, third parties, customers with significant unexplained wealth and customers using complex legal structures.
A customer’s risk may increase when combined with higher-risk services or countries.
Evaluating Products & Designated Services
The designated services offered by a business can create different ML/TF/PF risks. Under Section 26C(3)(a) of the AML/CTF Act, the risk assessment must consider existing and proposed designated services, including new or emerging technologies connected with those services.
AUSTRAC identifies factors that may increase the ML/TF risk of particular services, including whether they involve:
- high-value transactions, including physical currency or virtual assets;
- legal structures that conceal ownership or the source of wealth or funds;
- cross-border movement or storage of value; or
- virtual asset safekeeping, virtual asset exchanges, remittance services, real estate transactions or bullion.
The assessment should record why each service may be vulnerable to exploitation.
Analysing Delivery Channels & Remote Services
The way a designated service is delivered can affect the business’s exposure to ML/TF/PF risks. Section 26C(3)(c) of the AML/CTF Act requires consideration of delivery channels, including new or emerging technologies used to provide those services.
Face-to-face delivery may allow staff to observe unusual behaviour, but forged or stolen identification can still be used.
Remote service delivery may involve email, telephone, video chat or online platforms. Remote self-service may include smart ATMs, prepaid cards, online banking and online remittance services. Remote self-service channels may carry higher risk because customers can obtain services without staff assistance or face-to-face contact.
Determining Geographic & Country Risks
Country risk concerns the jurisdictions with which the business or its customers deal when designated services are provided. Under Section 26C(3)(d) of the AML/CTF Act, the assessment must consider the countries with which the reporting entity deals, or will deal, when providing its designated services. AUSTRAC guidance expects this assessment to include Australia, countries where individual customers reside and countries where corporate customers or legal arrangements are registered or formed.
The Basel AML Index may assist with assessing country risk across areas such as:
- the quality of the AML/CTF framework;
- bribery, corruption and financial transparency; and
- legal and political risks.
The assessment should also give a high-risk rating to countries on the Financial Action Task Force (FATF) grey or blacklists, or countries subject to Australian sanctions.
Practical Steps for Conducting an AML/CTF Risk Assessment
Identifying Inherent Risks & Vulnerabilities
Begin the risk assessment by identifying the ML/TF/PF risks the business may reasonably face before applying policies, procedures, systems or controls. This is known as assessing inherent risk. As outlined above, the assessment must address risks connected with the business’s designated services, customers, delivery channels and countries.
The assessment should record realistic scenarios, relevant customer due diligence (CDD) information and transaction data, staff feedback, industry information, regulator reports and AUSTRAC communications. It should also account for new or emerging technologies and planned services that could create additional vulnerabilities.
Assessing Likelihood & Impact
After identifying each inherent risk, assess its likelihood and potential impact. Likelihood concerns the possibility of the risk occurring within a given period, while impact concerns the damage or consequence if criminals exploit the vulnerability.
A medium-complexity business may use a risk matrix by combining likelihood and impact to produce a risk rating, such as low, medium, or high. Smaller, less complex businesses may assess impact alone. The selected method should reflect the nature, size, and complexity of the business and should be explained in the risk assessment.
Evaluating & Prioritising Your Risks
The risk assessment should show how the business will respond to each rating. Review existing controls, including Know Your Customer procedures, employee screening and transaction monitoring, then identify whether further safeguards are needed.
High-risk areas may require measures such as:
- limiting the services or delivery channels available to high-risk customers; and
- increasing transaction or behaviour monitoring.
If a risk cannot be appropriately managed or mitigated, the business may need to consider whether it should continue providing the designated service to that customer.
Documenting & Approving the Assessment
Record the following:
- the assessment methodology;
- information considered;
- risk ratings;
- reasons for those ratings; and
- proposed mitigation controls.
AUSTRAC expects the document to be understandable and usable by the governing body, senior managers, the AML/CTF compliance officer and relevant staff.
Section 26F(4)(c) of the AML/CTF Act requires the AML/CTF policies to designate one or more senior managers as responsible for approving the ML/TF risk assessment. Separately, Section 26P(1) requires the risk assessment, and any updates to it, to be approved by a senior manager. Rule 5-15(1) of the AML/CTF Rules 2025 requires the AML/CTF program to be documented before the reporting entity first commences providing a designated service.
Reporting entities reviewing their broader AML/CTF framework can also use Click Legal’s free AML/CTF Compliance Checklist to check their key compliance arrangements.
Reviewing & Updating Your AML/CTF Risk Assessment
Mandatory Three-Year Review Cycles
A reporting entity’s risk assessment cannot remain unchanged indefinitely. Under Section 26D(1)(b) of the AML/CTF Act, the reporting entity must review its ML/TF risk assessment at least once every three years.
The review must:
- identify and assess any new or changed money laundering, terrorism financing and proliferation financing risks; and
- reflect the nature, size and complexity of the business, as required by Section 26D(3) of the AML/CTF Act.
Trigger Events Requiring Immediate Updates
A review is also required outside the three-year cycle when a relevant risk trigger occurs. Under Section 26D(1)(a) of the AML/CTF Act, these triggers include:
- a significant change to the services, customers, delivery channels or countries considered under Section 26C(3);
- new information communicated by AUSTRAC about risks connected with the reporting entity’s designated services; or
- an independent evaluation report containing adverse findings about the ML/TF risk assessment, as specified in Rule 5-1(1) of the AML/CTF Rules 2025.
Under Section 26D(2) of the AML/CTF Act, the timing of the review depends on the nature of the trigger:
- a change within the reporting entity’s control must be reviewed before it occurs;
- a change outside its control must be reviewed as soon as practicable after it occurs; and
- AUSTRAC information must be reviewed as soon as practicable after it is communicated.
Section 26D(4) of the AML/CTF Act requires the risk assessment to be updated after the review identifies issues. For a significant change within the reporting entity’s control, the update must occur before the change; in other cases, it must occur as soon as practicable after the review is completed.
Governance & Compliance Officer Obligations for Reporting Entities
Board of Directors & Governing Body Oversight
The governing body retains responsibility for oversight of the reporting entity’s AML/CTF program. Under Section 26H(1) of the AML/CTF Act, it must oversee the entity’s identification and assessment of risk for its risk assessment and its compliance with AML/CTF policies, the regulations and the AML/CTF Rules.
The governing body must also take reasonable steps to ensure the entity identifies, assesses, manages and mitigates its money laundering, terrorism financing and proliferation financing risks. A breach of Section 26H(1) of the AML/CTF Act is a civil penalty provision under Section 26H(3).
Appointing an AML/CTF Compliance Officer
A reporting entity that provides a designated service must designate an eligible individual as its AML/CTF compliance officer within 28 days of commencing that service. This obligation arises under Section 26K(1) of the AML/CTF Act, and also applies when an existing officer ceases to be eligible under Section 26K(2).
Under Section 26L of the AML/CTF Act, the compliance officer oversees and coordinates:
- day-to-day compliance;
- the operation of AML/CTF policies; and
- communication with AUSTRAC.
The reporting entity must notify AUSTRAC of the officer’s appointment within 14 days under Section 26M(1) of the AML/CTF Act.
Conclusion
An AML/CTF risk assessment identifies the money laundering, terrorism financing and proliferation financing risks connected with a reporting entity’s services, customers, delivery channels and countries. It should be documented, approved, reviewed when required and kept up to date because Section 26E of the AML/CTF Act prohibits providing designated services without a compliant risk assessment.
For reporting entities reviewing their AML/CTF arrangements, contact Click Legal to request a consultation with our AML/CTF lawyers. For clear, practical guidance on preparing, updating and maintaining a risk assessment that reflects the business and supports its compliance obligations, contact Click Legal’s AML/CTF compliance lawyers for risk assessment guidance.