Services

AML Risk Assessment Australia

An AML/CTF risk assessment is the foundation of every compliant program in Australia. Without one, your policies and controls have no basis and your program will not satisfy AUSTRAC requirements. At One AML, we conduct thorough, tailored money laundering and terrorism financing risk assessments for reporting entities across all regulated industries, from financial services to law, accounting, real estate and beyond.

Illustration showing a checklist with blue check marks connected by an arrow to two documents labeled 'AML/CTF Compliance Program' and 'AML/CTF Risk Assessment' on a dark background with a purple circle.

We’re proud to assist small to enterprise-scale businesses across all industry sectors.

What Is an AML Risk Assessment?

An AML risk assessment is a structured analysis of the money laundering and terrorism financing risks your business faces. It examines where your exposure lies, how significant that exposure is and what controls are needed to manage it effectively.

Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, every reporting entity must complete and document a risk assessment as part of their AML/CTF program. It must be specific to your business. A generic or templated risk assessment will not meet AUSTRAC's expectations.

Your risk assessment must consider:

  • Your customer types and the ML/TF risk each presents
  • The products and services you provide and how they could be misused
  • How those products and services are delivered (in person, online, through intermediaries)
  • The countries and jurisdictions you deal with
  • Your business size, structure and ownership
  • Emerging risks relevant to your industry and operating environment

The output is a documented risk rating for your business, along with the controls and procedures you have in place or need to implement to manage those risks.

Why Your AML Risk Assessment Must Be Tailored

AUSTRAC is explicit that risk assessments must reflect your specific business circumstances. A generic template lifted from the internet will not meet your obligations. It may also actively harm your compliance position by giving a false picture of the risks your business actually faces.

A properly tailored AML risk assessment:

  • Identifies the actual ML/TF risks in your specific business
  • Provides a defensible, documented basis for your compliance program
  • Guides your customer due diligence settings and monitoring thresholds
  • Supports your AML/CTF Compliance Officer in managing obligations day to day
  • Demonstrates to AUSTRAC that you have genuinely assessed your risk

When AUSTRAC reviews your program, your risk assessment is one of the first things they look at. It needs to hold up.

Who Needs an AML Risk Assessment in Australia?

Any business classified as a reporting entity under the AML/CTF Act must have a documented ML/TF risk assessment. This includes existing reporting entities, as well as businesses newly captured under the Tranche 2 reforms taking effect from 1 July 2026.

Tranche 2 entities now required to complete an AML risk assessment include:

  • Lawyers and law firms
  • Accountants and bookkeepers
  • Real estate agents and agencies
  • Conveyancers
  • Trust and company service providers
  • High-value dealers in precious metals and stones

If you are a Tranche 2 entity, your AML/CTF program, including your risk assessment, must be operational by 1 July 2026. AUSTRAC enrolment opens 31 March 2026. The time to complete your risk assessment is now.

How One AML Conducts Your AML Risk Assessment

Our risk assessment process is thorough, structured and built around your specific business. We do not use off-the-shelf outputs. Every assessment we deliver is the result of a genuine analysis of your operations, customer base and risk environment.

Step 1: Business Scoping We gather detailed information about your business, the designated services you provide, your customer types, how you deliver your services and the jurisdictions you operate in. This forms the basis for the full assessment.

Step 2: Risk Identification We identify the ML/TF risks relevant to your business across each risk category: customer risk, product and service risk, delivery channel risk and geographic risk. We draw on AUSTRAC guidance, FATF typologies and sector-specific intelligence to ensure nothing material is missed.

Step 3: Risk Rating We assess both the inherent risk and the residual risk for your business, taking into account the controls you already have in place. Each risk category is rated and documented clearly.

Step 4: Controls Assessment We review whether your existing controls are adequate for your risk level and identify any gaps that need to be addressed through your AML/CTF program.

Step 5: Documented Output We deliver a fully documented risk assessment that meets AUSTRAC requirements and forms a solid foundation for your AML/CTF program and compliance activities going forward.

AML Risk Assessment and Your AML/CTF Program

Your risk assessment does not sit in isolation. It feeds directly into the rest of your AML/CTF program. The risk ratings it produces determine:

  • How you set your customer due diligence thresholds
  • Which customers require enhanced due diligence
  • What your transaction monitoring should focus on
  • How frequently you review and update your program
  • The level and focus of AML/CTF training your staff need

When we build your risk assessment, we build it as part of your broader compliance framework, not as a standalone document. If you also need a full AML/CTF program, we can deliver both together. See our Consulting and Advisory services for full program packages.

Ongoing Risk Assessment Reviews

Your AML risk assessment is not a set-and-forget document. AUSTRAC requires reporting entities to keep their risk assessment current and to review it whenever there are material changes to their business, customer base, or risk environment.

You should review and update your risk assessment when:

  • You add new products or services
  • You take on new customer types or enter new markets
  • There are changes to your business structure or ownership
  • AUSTRAC or FATF issue new guidance relevant to your sector
  • Your independent audit identifies gaps or changes in your risk profile

One AML provides ongoing advisory support to help you maintain a current and accurate risk assessment. Our AMLCO Support Services are designed for businesses that need expert guidance available on an ongoing basis.

Why Choose One AML for Your AML Risk Assessment?

We have completed risk assessments for over 1,000 reporting entities across Australia and New Zealand, covering every regulated sector. Our team understands the specific ML/TF risks that apply to your industry and knows what AUSTRAC expects to see.

  • Tailored to your business, not a generic template
  • Delivered by specialists with deep regulatory and sector knowledge
  • AUSTRAC-aligned methodology
  • Clear, plain-language documentation your team can work with
  • Part of a full compliance service offering if you need more than just the risk assessment
  • 70+ verified Google reviews

We’re qualified to consult for all Phase 1 and 2 reporting entities across Australia.

Calculator and paperwork Icon

Accounting

The easy access and wide geographic spread of accounting services, coupled with accountants' gatekeeper role and use in every phase of ML/TF.
Piggy Bank Icon

Financial Services

Domestic and international evidence suggests that financial institutions are vulnerable to ML/TF. The Act. and regulations place obligations on Australian financial institutions to detect and deter ML/TF.
Scale Icon

Law

The easy access and wide geographic spread of legal services, coupled with lawyers’ gatekeeper role and use in every phase of ML/TF.
Certificate Icon

Other Captured Sectors

Other industries that are widely spread and easy to access by ML. The nature of these industries lends itself to all stages of ML/TF.
House Icon

Real Estate

The use of real estate in ML/TF is well-known and demonstrable. FIU research indicates real estate is the ML asset of choice.
Wallet Icon

Virtual Assets / Crypto

The easy access and wide geographic spread of VASP services, coupled with their pseudo-anonymous nature and use in every phase of ML/TF.

Frequently Asked Questions

What is the difference between Part A and Part B of an AML/CTF program?
Blue circular icon with a black question mark and upward arrow inside.
Part A covers your business-wide AML/CTF controls, including your risk assessment, policies and governance framework. Part B covers your customer due diligence procedures. Both parts are required under the AML/CTF Act.
How long does it take to build an AML/CTF program?
Blue circular icon with a black question mark and upward arrow inside.
It depends on the size and complexity of your business. For most small to mid-sized businesses, we can deliver a complete program within a few weeks of engagement. We recommend starting as early as possible, particularly if your obligations begin 1 July 2026.
Do I need an independent audit after my program is in place?
Blue circular icon with a black question mark and upward arrow inside.
Yes. The AML/CTF Act requires reporting entities to have their program independently reviewed at least every three years, or when requested by AUSTRAC. One AML also provides independent audit and review services.
Can One AML help if I already have a program but need it updated?
Blue circular icon with a black question mark and upward arrow inside.
Yes. We review and update existing AML/CTF programs to ensure they remain current with regulatory changes and reflect any changes to your business.

Get Your Tailored AML Risk Assessment Today

A compliant AML/CTF program starts with a solid risk assessment. Whether you are an existing reporting entity or a Tranche 2 business preparing for 1 July 2026, One AML can help you get it right.