ML/TF risk assessment — how to actually do one
How to assess your agency's money-laundering, terrorism-financing and proliferation-financing risk in a way that holds up to AUSTRAC review — including who approves it and when it must be reviewed.
In short
Section 26C requires every reporting entity to identify and assess the money-laundering, terrorism-financing and proliferation-financing risks it may reasonably face in providing its designated services. Section 26C(3) makes six matters mandatory: your designated services provided or proposed, your kinds of customers, your delivery channels, the countries you deal with, risk information AUSTRAC communicates to you, and anything the Rules add — with new and emerging technologies expressly inside the services and channels limbs. Assess inherent risk before controls, document the reasoning, and match your policies to what you found. The assessment must be documented (s 26N), approved by a senior manager (s 26P(1)), and reviewed at least once every 3 years and on every significant change (s 26D).
The risk assessment is the foundation of the programme. Every other control — your CDD procedures, your monitoring, your reporting thresholds — should be calibrated to what it finds. It is also the document that builds the system by which you assign risk ratings to individual customers, which is where it stops being paperwork and starts driving daily work.
Three risk legs, not two. The assessment is still colloquially the "ML/TF risk assessment", but s 26C(1) requires you to identify and assess money-laundering, terrorism-financing and proliferation-financing risks. Proliferation financing covers funds connected to the manufacture, acquisition or use of nuclear, chemical or biological weapons in contravention of Australian or international law.
The six mandatory matters
Section 26C(3) makes six matters mandatory — four you will see everywhere, and two that most guidance drops:
- Kinds of designated services provided, or proposed to be provided — including any new or emerging technologies relating to them. Name them exactly: brokering is table 5 item 1 and its customer is both seller and buyer; selling your own stock is table 5 item 2; assisting a person in a transaction, the buyer's-agent case, is table 6 item 1.
- Kinds of customers — categorise the customers you actually deal with (Australian residents, foreign buyers, companies, trusts, PEPs, high-net-worth individuals, first-home buyers) and assess the inherent risk of each.
- Delivery channels — face-to-face engagement is generally lower risk than non-face-to-face. Online auctions, remote signings and agent-introduced buyers each carry their own profile. New or emerging technologies sit expressly inside this limb too.
- The countries you deal with, or will deal with, in providing the service. That is wider than the customer's nationality: it picks up where funds come from, where a corporate buyer was formed, and where a trustee sits.
- Information AUSTRAC communicates to you — directly, or to your sector generally. Financial crime guides, national risk assessments and sector emails are mandatory inputs, and receiving one is also a statutory trigger to review the assessment.
- Anything the Rules specify.
Two points inside that list. The assessment must cover services, customers, channels and countries you propose to take on, not only the ones you have. And s 26C(4) confirms the six do not limit the general duty in s 26C(1).
On country risk: as at the FATF statement of 19 June 2026, Iran and the DPRK are subject to countermeasures and Myanmar to enhanced due diligence proportionate to risk. Countries on that call-for-action list, on the FATF Increased Monitoring list, or under DFAT sanctions materially shift the score. Check the FATF statement each plenary — the list moves. Two of these carry separate statutory weight: Iran and the DPRK are the only countries prescribed under the AML/CTF (Prescribed Foreign Countries) Regulations 2018, and physical presence or formation in a jurisdiction for which the FATF has called for enhanced CDD is an automatic ECDD trigger under s 32(d).
Score inherent risk first
AUSTRAC expects the assessment to identify and assess your inherent risks — the risks you may reasonably face before you apply any policies, procedures, systems or controls. Residual risk, what is left after the controls, is optional and comes second.
Get this backwards and the assessment will show low risk everywhere, your policies will have nothing to attach to, and the link between s 26C and s 26F collapses.
Methodology
AUSTRAC does not prescribe one. It requires a methodology tailored to your nature, size and complexity, run in three stages: identify the risks and when they arise, assess their scale, then optionally evaluate them to prioritise.
Likelihood × impact scored on a matrix is the common way to do the assessment stage and is perfectly defensible — score the likelihood of occurrence (rare through almost certain) and the impact if it does occur (insignificant through catastrophic), combine them, and write down the reasoning. What is not defensible is a matrix with no reasoning behind the cells.
Three things carry the weight, and each maps to a stated requirement rather than a rule of thumb:
- Specificity. Does the assessment reflect your actual business — geography, customer mix, average transaction value? Section 26C(2) requires the steps to suit your nature, size and complexity, and AUSTRAC expects the document to be usable by your governing body, your senior managers, your compliance officer and the staff whose work touches the risks.
- Linkage. Do the policies actually address the risks the assessment identified? That is the express requirement in s 26F(1).
- Currency. When was it last reviewed? See below.
Reviewing it — the timing is not open-ended
Section 26D(1) requires a review if there is a significant change to any s 26C(3) matter, if AUSTRAC communicates risk information to you, or in circumstances the Rules specify — and in any event at least once every 3 years.
A significant change is one that could have a significant impact on your ML/TF risks. Not every change qualifies: updating your website in a way that does not change how you deliver services is not a trigger.
The timing rule is the operationally decisive part:
- If the change is within your control — a new service line, a new delivery channel, a new customer type, dealing with a new country — you must review and update before the change occurs.
- If it is outside your control (a country's risk shifts, sanctions land), or AUSTRAC communicates risk information to you, or an independent evaluation returns adverse findings on the assessment, you review as soon as practicable after, and update as soon as practicable after the review.
Then a senior manager approves the update, the governing body is notified in writing, and the update is documented within 14 days.
What to do next. Build it from what you actually did over the last 12 months — the property types, the buyer profiles, the payment routes, the entity structures you actually saw. If you are only weeks into the regime, use the same 12 months of pre-commencement history; the risk profile of your book did not change on 1 July. Then have a senior manager approve it (s 26P(1)), notify your governing body in writing (s 26P(2)), document it (s 26N), and set the next review date now — the statutory backstop is 3 years, and any significant change pulls it forward.
Frequently asked questions
- What are the four mandatory risk factors in an ML/TF risk assessment?
- Section 26C(3) actually lists six. The four everyone quotes are: kinds of designated services provided or proposed (including any new or emerging technologies), kinds of customers, delivery channels (again including new or emerging technologies), and the countries you deal with. The two usually dropped are equally mandatory: information AUSTRAC communicates to you identifying or assessing risks in your provision of designated services, and any matters specified in the Rules. Section 26C(4) confirms the list does not limit the general duty in s 26C(1).
- How often does an ML/TF risk assessment have to be reviewed?
- At least once every 3 years, and sooner on a trigger. Section 26D(1) requires a review if there is a significant change to any s 26C(3) matter, if AUSTRAC communicates risk information to you, or in circumstances specified in the Rules — and in any event at least every 3 years. Timing matters: if the significant change is within your control, you must review and update before the change occurs. If it is outside your control, as soon as practicable after. Failing to review and update is enforceable through s 26E, which contravenes separately for each designated service.
- Who has to approve the ML/TF risk assessment?
- A senior manager, under s 26P(1) — the same for every update. The governing body does not approve it, but it must be notified in writing as soon as practicable after any update (s 26P(2)), and it carries an ongoing oversight duty over your risk identification and assessment under s 26H. Updates must be documented within 14 days.
- Can I copy another agency's risk assessment?
- No. Section 26C(2) requires the steps you take to be appropriate to the nature, size and complexity of your business, and s 26F(1) requires your policies to manage the risks you identified. A copied assessment breaks both links: it will not reflect your customer mix, your channels or the countries you deal with, and the policies hanging off it will address risks you do not have while missing the ones you do.
- Does a real estate agency's risk assessment have to cover proliferation financing?
- Yes. Section 26C(1) names money laundering, terrorism financing and proliferation financing. For most agencies PF risk will be low, and s 26F(11) then lets you skip PF-specific policies if you also reasonably assess that your existing controls manage it — but s 26F(12) puts a legal burden on you to prove that if challenged, so write the reasoning down at the time. The carve-out never applies to the assessment itself.
- What happens if I provide a designated service without an up-to-date risk assessment?
- Section 26E(1) prohibits it outright, s 26E(2) makes it a civil penalty provision, and s 26E(3) makes it a separate contravention for each designated service you provide. For a brokered sale the customer is both the seller and the buyer, so exposure compounds quickly across a book of transactions.