AML Risk Assessment Australia
An AML/CTF risk assessment is the foundation of every compliant program in Australia. Without one, your policies and controls have no basis and your program will not satisfy AUSTRAC requirements. At One AML, we conduct thorough, tailored money laundering and terrorism financing risk assessments for reporting entities across all regulated industries, from financial services to law, accounting, real estate and beyond.

We’re proud to assist small to enterprise-scale businesses across all industry sectors.









.png)

























.png)





What Is an AML Risk Assessment?
An AML risk assessment is a structured analysis of the money laundering and terrorism financing risks your business faces. It examines where your exposure lies, how significant that exposure is and what controls are needed to manage it effectively.
Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, every reporting entity must complete and document a risk assessment as part of their AML/CTF program. It must be specific to your business. A generic or templated risk assessment will not meet AUSTRAC's expectations.
Your risk assessment must consider:
- Your customer types and the ML/TF risk each presents
- The products and services you provide and how they could be misused
- How those products and services are delivered (in person, online, through intermediaries)
- The countries and jurisdictions you deal with
- Your business size, structure and ownership
- Emerging risks relevant to your industry and operating environment
The output is a documented risk rating for your business, along with the controls and procedures you have in place or need to implement to manage those risks.
Why Your AML Risk Assessment Must Be Tailored
AUSTRAC is explicit that risk assessments must reflect your specific business circumstances. A generic template lifted from the internet will not meet your obligations. It may also actively harm your compliance position by giving a false picture of the risks your business actually faces.
A properly tailored AML risk assessment:
- Identifies the actual ML/TF risks in your specific business
- Provides a defensible, documented basis for your compliance program
- Guides your customer due diligence settings and monitoring thresholds
- Supports your AML/CTF Compliance Officer in managing obligations day to day
- Demonstrates to AUSTRAC that you have genuinely assessed your risk
When AUSTRAC reviews your program, your risk assessment is one of the first things they look at. It needs to hold up.
Who Needs an AML Risk Assessment in Australia?
Any business classified as a reporting entity under the AML/CTF Act must have a documented ML/TF risk assessment. This includes existing reporting entities, as well as businesses newly captured under the Tranche 2 reforms taking effect from 1 July 2026.
Tranche 2 entities now required to complete an AML risk assessment include:
- Lawyers and law firms
- Accountants and bookkeepers
- Real estate agents and agencies
- Conveyancers
- Trust and company service providers
- High-value dealers in precious metals and stones
If you are a Tranche 2 entity, your AML/CTF program, including your risk assessment, must be operational by 1 July 2026. AUSTRAC enrolment opens 31 March 2026. The time to complete your risk assessment is now.
How One AML Conducts Your AML Risk Assessment
Our risk assessment process is thorough, structured and built around your specific business. We do not use off-the-shelf outputs. Every assessment we deliver is the result of a genuine analysis of your operations, customer base and risk environment.
Step 1: Business Scoping We gather detailed information about your business, the designated services you provide, your customer types, how you deliver your services and the jurisdictions you operate in. This forms the basis for the full assessment.
Step 2: Risk Identification We identify the ML/TF risks relevant to your business across each risk category: customer risk, product and service risk, delivery channel risk and geographic risk. We draw on AUSTRAC guidance, FATF typologies and sector-specific intelligence to ensure nothing material is missed.
Step 3: Risk Rating We assess both the inherent risk and the residual risk for your business, taking into account the controls you already have in place. Each risk category is rated and documented clearly.
Step 4: Controls Assessment We review whether your existing controls are adequate for your risk level and identify any gaps that need to be addressed through your AML/CTF program.
Step 5: Documented Output We deliver a fully documented risk assessment that meets AUSTRAC requirements and forms a solid foundation for your AML/CTF program and compliance activities going forward.
AML Risk Assessment and Your AML/CTF Program
Your risk assessment does not sit in isolation. It feeds directly into the rest of your AML/CTF program. The risk ratings it produces determine:
- How you set your customer due diligence thresholds
- Which customers require enhanced due diligence
- What your transaction monitoring should focus on
- How frequently you review and update your program
- The level and focus of AML/CTF training your staff need
When we build your risk assessment, we build it as part of your broader compliance framework, not as a standalone document. If you also need a full AML/CTF program, we can deliver both together. See our Consulting and Advisory services for full program packages.
Ongoing Risk Assessment Reviews
Your AML risk assessment is not a set-and-forget document. AUSTRAC requires reporting entities to keep their risk assessment current and to review it whenever there are material changes to their business, customer base, or risk environment.
You should review and update your risk assessment when:
- You add new products or services
- You take on new customer types or enter new markets
- There are changes to your business structure or ownership
- AUSTRAC or FATF issue new guidance relevant to your sector
- Your independent audit identifies gaps or changes in your risk profile
One AML provides ongoing advisory support to help you maintain a current and accurate risk assessment. Our AMLCO Support Services are designed for businesses that need expert guidance available on an ongoing basis.
Why Choose One AML for Your AML Risk Assessment?
We have completed risk assessments for over 1,000 reporting entities across Australia and New Zealand, covering every regulated sector. Our team understands the specific ML/TF risks that apply to your industry and knows what AUSTRAC expects to see.
- Tailored to your business, not a generic template
- Delivered by specialists with deep regulatory and sector knowledge
- AUSTRAC-aligned methodology
- Clear, plain-language documentation your team can work with
- Part of a full compliance service offering if you need more than just the risk assessment
- 70+ verified Google reviews
We’re qualified to consult for all Phase 1 and 2 reporting entities across Australia.
Accounting
Financial Services
Law
Other Captured Sectors
Real Estate
Virtual Assets / Crypto
Frequently Asked Questions




Get Your Tailored AML Risk Assessment Today
A compliant AML/CTF program starts with a solid risk assessment. Whether you are an existing reporting entity or a Tranche 2 business preparing for 1 July 2026, One AML can help you get it right.
