AML Compliance Guide

ML/TF risk assessment for Bookkeeperss — 2026 AUSTRAC Guide

If your bookkeeping practice provides a designated service from 1 July 2026, you must complete a written money laundering, terrorism financing and proliferation financing risk assessment. This applies because bookkeepers can be used to move funds, set up payment arrangements, handle payroll, or help clients operate through business structures that may hide who really controls the money. If you do not do this properly, AUSTRAC can take enforcement action, civil penalties can reach $33.5 million per contravention, and intentional breaches can lead to criminal penalties.

Your risk assessment is the foundation of your AML/CTF setup. It must identify and assess the ML/TF risks your bookkeeping business may reasonably face when you provide designated services, and also when you plan to provide them. For a bookkeeper, that usually means looking closely at the kinds of clients you act for, the services you actually deliver, how you receive instructions, and whether money or payment directions cross borders. You must cover customers, designated services, delivery channels and countries you deal with, and you need to document it in a way your staff and managers can actually use.

Order matters

Do the risk assessment before you finalise your AML/CTF program. Your AML/CTF program must be finalised by 31 December 2026, so your written risk assessment needs to be done first and then updated whenever your business changes materially.

How a bookkeeping practice should do it

  • List only the designated services you provide or plan to provide. Do not assume every bookkeeping task is caught. Tax return preparation alone is generally not a designated service for accountants and bookkeeping practices.
  • Map your customer types: sole traders, family companies, trusts, not-for-profits, cash-heavy businesses, overseas-owned entities, and clients using nominees or complex structures.
  • Review your service risks: payroll processing, accounts payable, handling trust or client money, creating or operating entities, arranging payments, and any involvement in international transfers.
  • Assess delivery channels: face-to-face onboarding, email-only clients, cloud accounting access, app-based approvals, and clients you never meet in person.
  • Assess geography: where your clients, beneficial owners, counterparties and payment destinations are located, especially higher-risk or sanctioned jurisdictions.
  • Rate each risk low, medium or high, with a short explanation of likelihood and impact, then identify which risks need stronger controls or senior approval.

For bookkeepers, common weak spots are easy to miss because the work can look routine. A client asking you to process supplier payments to unrelated third parties, frequent changes to bank account details, unexplained cash takings, payroll for workers who cannot be properly identified, or requests to record vague journal entries can all increase risk. Remote-only clients are usually higher risk than established local clients you know well. If you service trades, hospitality, convenience retail, second-hand goods, precious metals, or businesses with large physical cash turnover, your assessment should say so clearly and explain why.

Common mistakes bookkeepers make

  • Using a generic template with no reference to actual bookkeeping workflows, software access, or payment authority arrangements.
  • Assessing the whole practice instead of assessing the specific designated services that trigger the law.
  • Ignoring beneficial ownership risks in private companies and trusts because the engagement came from the day-to-day manager rather than the real controller.
  • Treating all long-term clients as low risk without reconsidering changes in ownership, business activity, cash volume or international dealings.
  • Forgetting to revisit the assessment when the practice adds payroll, debtor collection support, payment processing, or overseas clients.

Keep the document practical. Use your client list, engagement letters, software permissions, bank authority records and industry mix to support your ratings. If you are a small practice, the risk assessment can be simple, but it still must be tailored to your business and easy for relevant staff to understand. A good approach is to review it whenever you add a new service line, start acting for trusts or foreign-owned clients, change onboarding methods, or receive AUSTRAC risk information relevant to your work.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need a risk assessment if I only do BAS and day-to-day bookkeeping?
You need the risk assessment if your practice provides a designated service. Not every bookkeeping task is a designated service, so the first step is to identify exactly which services you provide that are caught by the AML/CTF Act. If you do provide a designated service, the written risk assessment is required.
Can I use one short template for every client type?
You can use a simple format, especially if you are a small practice, but it must be tailored to your business. AUSTRAC expects the methodology to match the nature, size and complexity of your practice. A one-page generic form that does not address your actual clients, services, delivery channels and countries will not be enough.
What if I start offering payroll and supplier payment services after 1 July 2026?
You must update your risk assessment when your business changes materially. Adding payroll, payment processing, or other higher-risk services can change your exposure to misuse, impersonation and movement of funds. Update the assessment before or as you roll out the new service, then reflect it in your AML/CTF policies.
Do I need to include clients I plan to take on, or only current clients?
You must cover both current designated services and designated services you plan to provide. That includes planned customer types, delivery channels and countries that could increase ML/TF risk. If you are targeting e-commerce sellers, foreign-owned entities or remote-only clients, include that now rather than waiting until the first file arrives.
Does the risk assessment need to be done by an external consultant?
No. A small bookkeeping practice can prepare its own risk assessment if it is accurate, written, and tailored to the business. Many owners will still get advice to speed things up or test whether they have missed risks, but the law does not require an external consultant for this step.