AML Compliance Guide

ML/TF risk assessment for Financial adviserss — 2026 AUSTRAC Guide

A money laundering, terrorism financing and proliferation financing risk assessment is the document that identifies where your financial advice business could be misused and rates those risks across your clients, services, delivery channels and geography. It applies because a financial adviser who provides a designated service is a reporting entity under the AML/CTF Act and must understand those risks before finalising an AML/CTF program. If you do not do it properly, you risk breaching federal AML/CTF law, facing AUSTRAC action and civil penalties of up to $33.5 million per contravention, with criminal penalties for intentional contraventions.

For a financial advice practice, this is not a generic compliance form. Your assessment must be tailored to the way you actually operate: whether you only arrange financial products under a limited model, advise on higher-risk structures, deal with trusts and company vehicles, onboard clients remotely, accept instructions from third parties, or have clients with offshore links. AUSTRAC expects you to document the risks your business may reasonably face and show that the assessment was designed for your business, not copied from a template or reduced to 'all clients are low risk'.

What you need to do

  • Map the designated services you provide. Start with the exact services that bring you into the AML/CTF regime, not every service in your practice.
  • Rate your risks across four areas: customer types, services, delivery channels and geography. For advisers, that includes PEPs, trusts, companies with layered ownership, clients using attorneys or nominees, remote onboarding, and clients linked to higher-risk countries.
  • Record why each risk is low, medium or high. If you deal with complex ownership structures, large investments, source-of-funds uncertainty or unusual client behaviour, say so clearly.
  • Get the assessment approved internally and use it to build your AML/CTF policies. The risk assessment must be completed before finalising your AML/CTF program.
  • Review it whenever your business changes materially, such as adding a new product line, moving to fully online onboarding, targeting expatriate clients or accepting more corporate and trust clients.

Deadline and sequence

Newly regulated businesses must enrol with AUSTRAC by 29 July 2026, or within 28 days of first providing a designated service if you start later. Your written risk assessment should be done early because your AML/CTF program cannot be properly finalised without it, and the program must be finalised by 31 December 2026.

The most common mistake for advisers is assuming the practice is automatically low risk because clients are local retirees or because funds move through product issuers rather than your office account. That can be wrong. Risk can arise from how clients are introduced, whether you verify the real beneficial owners of companies and trusts, whether a family member is really controlling the relationship, whether a client is a politically exposed person, and whether the client’s wealth and proposed investment activity make sense together. Another mistake is confusing this assessment with customer due diligence. The risk assessment is a business-wide document; it is not the same as verifying one client’s ID.

Practical tips for a small advice practice

  • Group your client base into real segments you advise: retail individuals, SMSF trustees, family trusts, small company directors, and high-net-worth clients with offshore assets.
  • Write down the trigger events that will force a review, such as onboarding a PEP, accepting non-face-to-face clients only, or expanding into estate planning structures involving multiple entities.
  • Keep evidence of how you reached your ratings, including file reviews, adviser input, complaints trends, and any AUSTRAC guidance you relied on.
  • Nominate who owns the document. In a small practice, that may be the principal adviser or AML/CTF compliance officer, but someone must be responsible for updates.
  • Make sure your advisers, paraplanners and client service staff understand the red flags in the assessment so it feeds into onboarding, sanctions screening and suspicious matter decisions.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need a risk assessment if I only arrange financial products and do not handle client money?
Yes, if you provide a designated service you still need a written ML/TF risk assessment. AUSTRAC’s guidance for financial planners says you must develop an effective AML/CTF program before providing a designated service, and that starts with documenting your business’s ML/TF risks. Not handling cash yourself does not remove the obligation.
Can I use a template bought from a software provider or consultant?
You can use a template as a starting point, but your final document must be tailored to your advice business. AUSTRAC warns that an off-the-shelf risk assessment that is not specific to your services, clients and delivery model will raise questions about whether you really understand your risks. If your practice differs from the template, change it and record why.
What if all my clients are existing clients from before 1 July 2026?
You still need a business-wide risk assessment if you are a reporting entity. The document is about the risks in your practice as a whole, not just new clients. Existing clients may still fall into higher-risk categories, such as trusts, companies with beneficial ownership issues, PEPs or clients with offshore connections.
How much detail does a small suburban advice practice need?
Enough detail to show that you have genuinely assessed your own business and can justify your ratings. A small practice does not need a long corporate report, but it does need clear reasoning about its client segments, services, onboarding methods and geographic exposure. A short but specific document is better than a long generic one.
How often do I have to update the assessment, and what will trigger a review?
You must update it whenever your business changes materially. For advisers, common triggers include adding new designated services, moving to remote-only onboarding, taking on more trust and company clients, entering a new market, or seeing new patterns of unusual client behaviour. Your document should also state the review frequency and who is responsible for doing it.