Australian AML/CTF · Explainer

Assign a customer risk rating

Use evidence and the proposed service to explain a customer risk rating.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: When does an AML program become a working process?

Make the rating explain a decision

A customer risk rating is a summary of an assessment. It is not the assessment itself. The useful result is an explanation of the risks presented by this customer, in this service, and the checks needed to manage them. A number without its inputs cannot show that reasoning.

Under section 28, identify customer risk from KYC information reasonably available before the service begins. For an Australian permanent establishment, take account of the business risk assessment, customer type, services, delivery channels and countries. These are connected considerations. Do not select a rating from the customer's name or occupation alone.

Keep the reason behind the ratingFollow the process from top to bottom. Customer and service: Collect the relevant available KYC and service information. Risk assessment: Consider customer, service, channel and country factors. Specific triggers: Check mandatory responses separately from an overall score. Recorded response: Explain the rating, evidence and controls selected.Customer and service Risk assessment Specific triggers Recorded response
  1. Customer and service

    Collect the relevant available KYC and service information.

  2. Risk assessment

    Consider customer, service, channel and country factors.

  3. Specific triggers

    Check mandatory responses separately from an overall score.

  4. Recorded response

    Explain the rating, evidence and controls selected.

Keep the reason behind the rating

A score cannot cancel a mandatory trigger. This is a suggested way to present the reasoning, not a scoring formula.

Follow the process from top to bottom.

Keep mandatory duties separate

A rating can help staff apply the business's policies consistently. The rating should remain connected to the evidence used to assess the customer. The law attaches consequences to risk: high risk requires enhanced CDD, while simplified CDD has several conditions beyond a low rating.

Some enhanced CDD triggers apply independently of a general score. A model must not average those triggers away. Keep the finding that activates a mandatory rule visible beside the rating. The reviewer needs to know whether a response follows the assessed risk, a specific legal trigger, or both.

Worked example: incomplete ownership information

A company gives a clear business purpose but an incomplete ownership chart. A staff member initially expects ordinary risk because the service is routine. The missing information means that expectation needs examination. It does not, by itself, prove the company is involved in crime.

The staff member identifies the missing link, requests suitable information and records the result. If the response explains the structure, the rating can reflect that evidence. If contradictions remain, the reviewer considers their significance and the appropriate controls. Changing the rating without recording what changed would hide the actual decision.

Check consistency with a second case

To check consistency, compare two fictional customers with the same risk factors. Ask whether the system produces the same reasoning and whether any different result has a clear cause. Then add a mandatory trigger to one case. Confirm that it changes the response even if most other facts remain ordinary.

This exercise tests the method, not the customer's honesty. Keep uncertainty visible rather than assigning invented precision. A business can use categories or a score, but the person who approves the case should understand the basis and limits of the result. A rating does not confirm compliance.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

This page does not cover: Business program governance; Ongoing CDD review schedules.

Common AML/CTF terms