Australian AML/CTF · Explainer

Which sectors face higher money laundering risk?

Use Australian evidence to understand high-risk sectors. Connect the risk to your service instead of assigning every customer the same rating.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: Use national and sector AML risk assessments

A sector label needs a reason

AUSTRAC identifies money laundering exposure through cash-intensive businesses, company and trust structures, trade, and combinations of financial services. These channels can involve different industries.

A high-risk sector label describes exposure in a particular assessment. It is not a finding that every business or customer in that sector commits crime.

Sources: AUSTRAC: Opening paragraphs; Artificial intelligence; Financial channels and criminal activities; Newly regulated entities; AUSTRAC: Your risk assessment obligations; Risk categories you must consider; Kinds of designated services; Delivery channels.

What the 2026 Australian update identifies

AUSTRAC’s Money laundering update 2026 was last updated on 15 May 2026. It should be read with the 2024 national assessment.

The update describes greater connections between existing channels. It highlights services offered together, including remittance, virtual assets, bullion dealing and cash.

It also discusses expected effects of artificial intelligence on cash-intensive businesses, company and trust structures, and trade-based laundering. These are assessed vulnerabilities, not individual findings.

Source: AUSTRAC: Opening paragraphs; Artificial intelligence; Financial channels and criminal activities; Newly regulated entities.

Compare the service and its vulnerability

AUSTRAC’s risk guidance connects real-estate brokering with property used to store criminal value. Complex ownership can conceal who owns that property.

For company-address services, the concern differs. The service can give an appearance of legitimacy or hide connections and ownership.

These comparisons explain possible misuse. They do not rank every provider. Cash use, a company structure or an overseas connection alone does not establish wrongdoing.

Source: AUSTRAC: Your risk assessment obligations; Risk categories you must consider; Kinds of designated services; Delivery channels.

Keep three assessments separate

Whether a service is regulated differs from how it could be misused. Both differ from the risk of a particular customer.

The business assessment connects relevant services, customers, delivery channels and countries. The customer assessment needs that customer’s facts. A sector label cannot supply missing evidence.

Source: AUSTRAC: Your risk assessment obligations; Risk categories you must consider; Kinds of designated services; Delivery channels.

Invented example: two practices in one sector

Two small practices provide the same type of company service. The first receives consistent instructions directly from its customer.

The second receives conflicting instructions through a representative. Its reviewer cannot establish who authorised the requested action.

The second practice examines the representative’s authority and records the evidence. It does not treat the use of a representative as proof of misconduct.

The shared sector does not explain the different information gaps. Clear authority also does not establish where transaction funds came from. Separate questions need separate evidence.

Source: AUSTRAC: Tailor your risk assessment; Delivery channels; Step 2.2 - Assess your inherent risks.

Record the connection to your work

Record the assessment source, date and relevant passage. Identify the service it affects.

Describe the possible misuse and the information needed to assess it. Connect the control to that concern.

Record what remains unresolved and who will act. This suggested method does not replace the business assessment. It does not confirm compliance.

Source: AUSTRAC: Tailor your risk assessment; Delivery channels; Step 2.2 - Assess your inherent risks.

Connect sector evidence to the serviceSector evidence Service exposure Customer facts Control and limit
  1. Sector evidence

    Identify the source, date and relevant risk.

  2. Service exposure

    Explain how the service could be misused.

  3. Customer facts

    Identify the evidence and remaining gaps.

  4. Control and limit

    Explain the response and what it cannot establish.

Connect sector evidence to the service

Invented example of a review method. Sector evidence informs the assessment. It does not decide each customer’s risk.

Follow the process from top to bottom.

Sources and scope

Sources checked on 24 September 2026. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

How we prepare articles

This page does not cover: A complete or ranked industry risk list; A legal scope decision for a business; An individual customer rating or complete business risk assessment.

Common AML/CTF terms