If your bookkeeping practice provides a designated service from 1 July 2026, you must complete a written money laundering, terrorism financing and proliferation financing risk assessment. This applies because bookkeepers can be used to move funds, set up payment arrangements, handle payroll, or help clients operate through business structures that may hide who really controls the money. If you do not do this properly, AUSTRAC can take enforcement action, civil penalties can reach $33.5 million per contravention, and intentional breaches can lead to criminal penalties.
Your AML/CTF obligations
Your risk assessment is the foundation of your AML/CTF setup. It must identify and assess the ML/TF risks your bookkeeping business may reasonably face when you provide designated services, and also when you plan to provide them. For a bookkeeper, that usually means looking closely at the kinds of clients you act for, the services you actually deliver, how you receive instructions, and whether money or payment directions cross borders. You must cover customers, designated services, delivery channels and countries you deal with, and you need to document it in a way your staff and managers can actually use.
Order matters
Do the risk assessment before you finalise your AML/CTF program. Your AML/CTF program must be finalised by 31 December 2026, so your written risk assessment needs to be done first and then updated whenever your business changes materially.
How a bookkeeping practice should do it
For bookkeepers, common weak spots are easy to miss because the work can look routine. A client asking you to process supplier payments to unrelated third parties, frequent changes to bank account details, unexplained cash takings, payroll for workers who cannot be properly identified, or requests to record vague journal entries can all increase risk. Remote-only clients are usually higher risk than established local clients you know well. If you service trades, hospitality, convenience retail, second-hand goods, precious metals, or businesses with large physical cash turnover, your assessment should say so clearly and explain why.
Common mistakes bookkeepers make
Keep the document practical. Use your client list, engagement letters, software permissions, bank authority records and industry mix to support your ratings. If you are a small practice, the risk assessment can be simple, but it still must be tailored to your business and easy for relevant staff to understand. A good approach is to review it whenever you add a new service line, start acting for trusts or foreign-owned clients, change onboarding methods, or receive AUSTRAC risk information relevant to your work.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.