Match the response to the risk
A risk-based approach uses the assessed risk to select suitable controls. RBA is a common abbreviation for this approach.
The Financial Action Task Force, or FATF, supports proportionate measures. Higher risks need stronger measures. Lower risks can permit simpler measures within the applicable rules.
Source: FATF: Changes to FATF Standards: proportionate measures and simplified measures.
Start with the Australian requirements
Australian reporting entities must identify and assess the risks they may reasonably face through their designated services. AML/CTF policies must address those risks and legal duties.
A business risk rating cannot cancel a legal requirement. Use the article on mandatory triggers to distinguish a risk factor from a required action.
Source: Federal Register of Legislation: Sections 26C(1) to (2) and 26F(1).
Compare two requests
Consider a fictional practice that receives two company service requests. One has a clear purpose and simple ownership. The other has unexplained third-party instructions.
The practice identifies the unanswered questions in each request. It selects additional enquiries for the second request and records the reasons.
This example shows a decision process. It does not assign a final rating or prove criminal activity.
Source: FATF: Proportionate measures.
Record the link between risk and action
For each material risk, record the facts, control and responsible person. Explain how the control addresses the risk.
A statement such as “we use a risk-based approach” does not explain what staff need to do.
Source: FATF: Proportionate measures.
- Risk information
Identify the relevant facts about the service and customer.
- Response
Select measures that address the assessed risk and mandatory duties.
- Record
Explain the connection between the risk and the action.
Connect risk information to an action
Risk affects the choice of measures. It does not remove a mandatory legal duty.
Follow the process from top to bottom.