Australian AML/CTF · Explainer

What a risk-based approach to AML means

A risk-based approach uses the assessed risk to select suitable AML controls. Learn how this works within Australian legal requirements.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Match the response to the risk

A risk-based approach uses the assessed risk to select suitable controls. RBA is a common abbreviation for this approach.

The Financial Action Task Force, or FATF, supports proportionate measures. Higher risks need stronger measures. Lower risks can permit simpler measures within the applicable rules.

Source: FATF: Changes to FATF Standards: proportionate measures and simplified measures.

Start with the Australian requirements

Australian reporting entities must identify and assess the risks they may reasonably face through their designated services. AML/CTF policies must address those risks and legal duties.

A business risk rating cannot cancel a legal requirement. Use the article on mandatory triggers to distinguish a risk factor from a required action.

Source: Federal Register of Legislation: Sections 26C(1) to (2) and 26F(1).

Compare two requests

Consider a fictional practice that receives two company service requests. One has a clear purpose and simple ownership. The other has unexplained third-party instructions.

The practice identifies the unanswered questions in each request. It selects additional enquiries for the second request and records the reasons.

This example shows a decision process. It does not assign a final rating or prove criminal activity.

Source: FATF: Proportionate measures.

Record the link between risk and action

For each material risk, record the facts, control and responsible person. Explain how the control addresses the risk.

A statement such as “we use a risk-based approach” does not explain what staff need to do.

Source: FATF: Proportionate measures.

Connect risk information to an action
  1. Risk information

    Identify the relevant facts about the service and customer.

  2. Response

    Select measures that address the assessed risk and mandatory duties.

  3. Record

    Explain the connection between the risk and the action.

Connect risk information to an action

Risk affects the choice of measures. It does not remove a mandatory legal duty.

Follow the process from top to bottom.

Sources and scope

Sources checked on 2026-09-13. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

How we prepare articles

This page does not cover: the full conditions for each mandatory legal trigger.

Common AML/CTF terms