Australian AML/CTF · Explainer

Business risk assessment and customer risk

Separate the risks across your business from the risk of one customer.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: When does an AML program become a working process?

Start with two different questions

A business risk assessment asks how your designated services could be used for money laundering, terrorism financing or proliferation financing. A customer assessment asks how those risks apply to a particular customer and the service you will provide. Both are needed. A business document cannot establish the identity or circumstances of every future customer.

Section 26C requires a business assessment suited to the nature, size and complexity of the business. Section 28 requires you to use reasonably available customer information before starting the designated service. The customer assessment uses the business assessment to examine a particular customer and service.

Connect business risk to customer decisionsFollow the process from top to bottom. Describe services: Identify the designated work and how it can be misused. Assess business risks: Consider the business-wide factors required by section 26C. Assess this customer: Apply relevant facts to the customer and service under section 28. Select the response: Apply suitable controls and any mandatory triggers.Describe services Assess business risks Assess this customer Select the response
  1. Describe services

    Identify the designated work and how it can be misused.

  2. Assess business risks

    Consider the business-wide factors required by section 26C.

  3. Assess this customer

    Apply relevant facts to the customer and service under section 28.

  4. Select the response

    Apply suitable controls and any mandatory triggers.

Connect business risk to customer decisions

The business assessment informs the customer assessment; it does not replace it.

Follow the process from top to bottom.

Connect the assessment to the work

For services provided through an Australian permanent establishment, the business assessment must consider services, customers, delivery channels, countries and relevant risk information communicated by AUSTRAC. Those categories provide a structure for asking questions. Listing these categories does not complete the assessment.

At customer level, section 28 requires consideration of your business assessment and the customer's type, services, channels and countries. Record the specific connection. For example, a business-level concern about opaque company structures leads to questions about the ownership and control of this company. It does not establish that every company is high risk.

Describe the risk before giving it a rating

AUSTRAC distinguishes inherent risk, which exists before controls are applied, from residual risk, which remains after controls. Its guidance expects the assessment to identify and assess inherent risks. Assessing residual risk is an additional option. Keeping these views separate prevents a statement such as we use identity software from hiding the risk that the software is meant to address.

Start with the designated service and the route by which it could be misused. Then consider the relevant customer types, delivery channels and countries. Include planned changes, not only last year’s work. The assessment should explain why a risk matters in this business. AUSTRAC describes approaches that can vary with business complexity; a numerical matrix is not the only possible method.

An intermediary instructs a transfer

In this fictional practice, staff often receive instructions through an adviser rather than directly from the company customer. A useful risk statement is: an unauthorised person could direct the transfer of company assets because staff cannot see who approved the instruction. This identifies the service, possible misuse and weakness. Writing intermediary risk: medium would leave the mechanism unexplained.

The practice proposes checking the representative’s authority and obtaining confirmation through a contact route it has established independently. It records who performs the check and where the result is kept. It also records a limit: confirmation of authority does not establish the origin of the assets. This keeps one control from being used to answer an unrelated question.

At customer level, the reviewer tests the actual instruction and evidence. A documented authority may resolve that question for one customer. Conflicting instructions may require more work for another. Neither outcome changes the need to recognise the underlying business risk.

From a risk statement to a testable controlFollow the process from top to bottom. Possible misuse: An unauthorised intermediary directs company assets in this fictional example. Evidence question: Who authorised this instruction, and what supports that conclusion? Control and limit: Check authority. This does not establish the source of the assets. Customer decision: Record the result and any separate unresolved questions.Possible misuse Evidence question Control and limit Customer decision
  1. Possible misuse

    An unauthorised intermediary directs company assets in this fictional example.

  2. Evidence question

    Who authorised this instruction, and what supports that conclusion?

  3. Control and limit

    Check authority. This does not establish the source of the assets.

  4. Customer decision

    Record the result and any separate unresolved questions.

From a risk statement to a testable control

Illustrative control design. Inherent risk is assessed before controls; this diagram does not assign a risk score.

Follow the process from top to bottom.

Link each risk to a control

Ask whether a staff member can move from each material business risk to a practical customer question or control. If a risk statement says only that money laundering is possible, it does little to guide a decision. Add the service, mechanism and relevant circumstances so the statement can be tested.

Keep the customer's explanation separate from the business's assessment of it. A later reviewer should be able to see what was known, what remained uncertain and why the selected response addressed that uncertainty. This example of documentation is a working method, not a prescribed scoring model or a confirmation of compliance.

Turn the assessment into a usable review record

A suggested working record has six fields: service, possible misuse, relevant circumstances, rating and reasons, response, and responsible person. Add an evidence reference for each material reason. If you use numerical scores, explain what the numbers mean and how you deal with mandatory CDD triggers. An average score must not be used to cancel a separate legal requirement.

Before adopting a new service, walk through one fictional customer from instruction to completion. Ask which risk statement explains each check and what happens when the check fails. Record gaps as actions with an owner. This exercise tests whether the assessment can guide work; it is not an independent evaluation or a prescribed method of proving compliance.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

This page does not cover: Detailed program governance; Ongoing CDD review procedures.

Common AML/CTF terms