AML Compliance Guide

ML/TF risk assessment for Accountants — 2026 AUSTRAC Guide

If your accounting practice provides a designated service from 1 July 2026, you must prepare a written money laundering, terrorism financing and proliferation financing risk assessment. For accountants, this matters most where you help set up companies or trusts, manage client money, or handle higher-risk transaction work rather than routine tax return preparation alone. If you do not do it properly, you cannot build a compliant AML/CTF program, and AUSTRAC can take enforcement action with civil penalties up to $33.5 million per contravention, with criminal penalties for intentional breaches.

Your risk assessment is the foundation document for the rest of your AML/CTF setup. It must be written and it must assess where your accounting practice could be misused for money laundering, terrorism financing or proliferation financing across four categories: your customers, the services you provide, the channels you use to deliver those services, and the countries connected to the work. AUSTRAC’s guidance is clear that you complete the risk assessment before finalising your AML/CTF program, because your policies, systems and controls are supposed to respond to the risks you identify.

What an accounting practice should do

  • List the designated services your practice actually provides. Be precise. Tax return preparation alone is generally not a designated service, but company or trust establishment, acting in higher-risk transaction work, or handling money or assets may be.
  • Map your customer base. Separate individuals, companies, trusts, self-managed structures, overseas-linked clients, cash-intensive businesses, and clients using nominees or complex ownership chains.
  • Assess delivery channels. Remote onboarding, email-only instruction, never meeting the client in person, and using third parties to verify information all raise risk compared with long-standing local clients seen face to face.
  • Assess geography. Note any links to overseas jurisdictions, especially where funds, assets, controllers or beneficiaries are outside Australia.
  • Rate the inherent risk of each area before controls, then decide which risks are low, medium or high and record why.
  • Use those findings to build your AML/CTF policies, and review the risk assessment whenever you introduce a new designated service, customer type, delivery channel or jurisdiction.

Timing rule

Complete the ML/TF risk assessment before finalising your AML/CTF program. The program must be finalised by 31 December 2026, so the risk assessment needs to be done first and kept up to date if your practice changes materially.

For accountants, the biggest mistake is assessing risk at the profession level instead of at the service level. A suburban tax practice doing individual returns is very different from a firm that forms companies, establishes trusts, arranges business acquisitions, receives settlement funds into trust, or helps move assets between entities. Another common error is treating all existing clients as low risk because you already know them. AUSTRAC expects you to look at features that create anonymity or obscure control, such as layered companies, family trusts with broad classes of beneficiaries, unexplained source of funds, unusual physical currency requests, high-value transactions, and clients who insist on remote-only contact.

Practical tips for a small accounting firm

  • Build your assessment around the work you actually do: bookkeeping, payroll and returns may sit outside designated services, while entity setup and transaction support may sit inside.
  • Use real examples from your files when rating risk, such as property structuring, shelf company purchases, or trust changes requested at short notice.
  • Create a simple approval path for high-risk matters so staff know when to escalate to the AML/CTF compliance officer or principal.
  • Keep version control. Save dated copies, reasons for changes, and meeting notes showing senior management approval.
  • Include AUSTRAC risk information in your review process, and brief partners or directors at least annually on ML/TF risks and compliance issues.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need a risk assessment if my practice only does tax returns and BAS work?
If you only prepare tax returns and BAS statements, that work alone is generally not a designated service. If your practice does not provide any designated service, you are not a reporting entity for that work. The position changes if you also provide services such as setting up companies or trusts, handling client money or assets in connection with transactions, or other Schedule 1 services.
Can I use one generic risk assessment template for every office in my firm?
Only if it genuinely reflects how each office operates. A city office dealing with overseas investors, trust structures and remote onboarding will usually have different risks from a local office handling straightforward small-business clients. Your document must be tailored to your actual customers, services, channels and geography.
How often do I have to update the risk assessment?
Update it whenever the business changes materially. AUSTRAC guidance also says you should complete a new assessment before introducing new designated services, customer types, delivery channels or jurisdictions. You should also review it when AUSTRAC issues relevant risk information or when your own file experience shows a new pattern of risk.
Do I need to pay for software or external consultants to do this?
No law says you must buy software or hire a consultant. A small practice can prepare its own written assessment if it is specific, reasoned and based on the services it actually provides. The real requirement is that the document is accurate, current and usable as the basis for your AML/CTF program.
What if I discover during the risk assessment that one client or service line is much riskier than I expected?
Record that risk clearly and adjust your AML/CTF policies to match it. That may mean enhanced due diligence, source of funds checks, senior manager approval before acting, stronger monitoring, or deciding not to provide the service at all. If information gives you reasonable grounds to suspect criminal activity, that becomes a suspicious matter reporting issue, with separate deadlines.