AML Compliance Guide

ML/TF risk assessment for Lawyers — 2026 AUSTRAC Guide

If your law practice provides a designated service from 1 July 2026, you must prepare a written ML/TF risk assessment before you finalise your AML/CTF program. For lawyers, this matters because certain legal services can be used to move, conceal or legitimise criminal funds, especially where you handle client money, form entities, or assist with property and business transactions. If you do not do this properly, you risk breaching the AML/CTF Act, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional contraventions.

Your risk assessment is the foundation of your AML/CTF compliance. It must be a written document that identifies and rates the money laundering, terrorism financing and proliferation financing risks in your legal practice across four areas: the services you provide, the customers you act for, the delivery channels you use, and the countries you deal with. AUSTRAC’s guidance for lawyers is clear that this comes first: you identify your inherent risk, assess how exposed those weaknesses are to misuse, then evaluate and prioritise which risks need the most attention. High-risk areas should be addressed first, and the outcome of this assessment must directly shape your AML/CTF policies, procedures, systems and controls.

How a lawyer should complete the assessment

  • List the designated legal services your practice actually provides. Separate these from work that is generally not designated, such as pure legal advice on its own.
  • Map the customer types you deal with, including individuals, private companies, family trusts, overseas clients, intermediaries and anyone using nominees or complex ownership structures.
  • Review how instructions are received and how money moves. Remote onboarding, third-party payments, trust account activity, urgent settlement requests and withdrawals to unrelated parties are all lawyer-specific risk points.
  • Consider geography, including whether clients, counterparties, funds or assets are linked to overseas jurisdictions, sanctions exposure, or countries of proliferation concern.
  • Rate each risk as low, medium or high, record why, and prioritise the highest-risk workstreams first.
  • Use the final document to build proportionate controls, then review it whenever you add new designated services, customer types, delivery channels or jurisdictions.

Timing matters

You must complete the ML/TF risk assessment before finalising your AML/CTF program. Your AML/CTF program must be finalised by 31 December 2026. If your practice changes materially, the risk assessment must be updated rather than left as a one-off document.

For a law firm, the assessment should be tailored to the matters that actually create exposure. Examples include using a trust account for property settlements, receiving or disbursing funds on behalf of clients, creating companies or trusts, acting in higher-value transactions, and dealing with clients who want anonymity through layered structures. AUSTRAC’s lawyer guidance also points to specific controls that may be needed where risk is higher: enhanced due diligence on high-risk clients, verification of beneficial ownership in complex structures, monitoring trust accounts for unusual payment patterns, stronger scrutiny of third-party deposits and withdrawals, ongoing due diligence for long-term clients, staff training on red flags, and screening customers against the DFAT Consolidated List. You must also assess proliferation financing risk as part of the same exercise.

Common mistakes in legal practices

  • Treating the risk assessment as a generic template instead of linking it to the firm’s actual files, trust account use and client base.
  • Assuming all legal work is covered. The trigger is whether you provide a designated service, not whether you are a lawyer.
  • Ignoring proliferation financing risk because the firm only works in Australia. Low risk may reduce the need for separate PF policies, but the risk still has to be assessed.
  • Failing to revisit the assessment when the firm starts remote client onboarding, adds commercial property work, or begins acting for overseas-connected clients.
  • Describing controls in the risk assessment without testing whether they exist in practice or are strong enough for high-risk matters.

A practical approach for a small legal practice is to review the last 12 months of matters and sort them by risk. Look closely at conveyancing files, trust account transactions, entity setup work, large one-off matters, and any client who used a representative or wanted funds paid to a third party. Keep evidence of drafts, approvals, version control and meeting notes showing how the assessment was developed and approved by senior management. If your practice is not a sole practitioner model, your governing body should also be kept informed of ML/TF risks and receive compliance reporting at least once every 12 months.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need a risk assessment if my firm only gives legal advice and never handles client money?
Only a business that provides a designated service is a reporting entity under the AML/CTF Act. Pure legal advice is generally not a designated service for lawyers, so if that is genuinely all your firm does, the Tranche 2 obligations are generally not triggered. The key issue is the actual service you provide, not your professional title.
Can I use one template risk assessment for every office in my law practice?
You can start with a common framework, but the final assessment must reflect the actual risks in each part of the practice. A suburban conveyancing office, a commercial transactions team and a private client practice using trust structures may have very different customer, service and delivery channel risks. AUSTRAC expects the assessment to be tailored to your business’s size, services and risk profile.
What does this usually cost a small law firm?
The Act does not set a required spend, and AUSTRAC enrolment itself is free. For many small firms, the main cost is staff time spent identifying designated services, reviewing files, documenting risks and approving the assessment. Costs rise if you buy specialist software, external advice or independent compliance support.
Do I have to assess proliferation financing risk even if I only act for local clients in Australia?
Yes. AUSTRAC’s guidance for lawyers states that proliferation financing risk must be assessed as part of your ML/TF risk assessment. If your practice only operates in Australia and does not deal with overseas funds, sensitive goods or higher-risk jurisdictions, your PF risk may be lower, but you still need to document that conclusion.
When do I need to update the assessment after 2026?
Update it whenever your business changes materially. AUSTRAC guidance specifically points to new designated services, customer types, delivery channels and jurisdictions as triggers for a fresh assessment. In a legal practice, that could include starting remote onboarding, adding trust and company setup work, or taking on clients with overseas ownership or sanctions exposure.