If your law practice provides a designated service from 1 July 2026, you must prepare a written ML/TF risk assessment before you finalise your AML/CTF program. For lawyers, this matters because certain legal services can be used to move, conceal or legitimise criminal funds, especially where you handle client money, form entities, or assist with property and business transactions. If you do not do this properly, you risk breaching the AML/CTF Act, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional contraventions.
Your AML/CTF obligations
Your risk assessment is the foundation of your AML/CTF compliance. It must be a written document that identifies and rates the money laundering, terrorism financing and proliferation financing risks in your legal practice across four areas: the services you provide, the customers you act for, the delivery channels you use, and the countries you deal with. AUSTRAC’s guidance for lawyers is clear that this comes first: you identify your inherent risk, assess how exposed those weaknesses are to misuse, then evaluate and prioritise which risks need the most attention. High-risk areas should be addressed first, and the outcome of this assessment must directly shape your AML/CTF policies, procedures, systems and controls.
How a lawyer should complete the assessment
Timing matters
You must complete the ML/TF risk assessment before finalising your AML/CTF program. Your AML/CTF program must be finalised by 31 December 2026. If your practice changes materially, the risk assessment must be updated rather than left as a one-off document.
For a law firm, the assessment should be tailored to the matters that actually create exposure. Examples include using a trust account for property settlements, receiving or disbursing funds on behalf of clients, creating companies or trusts, acting in higher-value transactions, and dealing with clients who want anonymity through layered structures. AUSTRAC’s lawyer guidance also points to specific controls that may be needed where risk is higher: enhanced due diligence on high-risk clients, verification of beneficial ownership in complex structures, monitoring trust accounts for unusual payment patterns, stronger scrutiny of third-party deposits and withdrawals, ongoing due diligence for long-term clients, staff training on red flags, and screening customers against the DFAT Consolidated List. You must also assess proliferation financing risk as part of the same exercise.
Common mistakes in legal practices
A practical approach for a small legal practice is to review the last 12 months of matters and sort them by risk. Look closely at conveyancing files, trust account transactions, entity setup work, large one-off matters, and any client who used a representative or wanted funds paid to a third party. Keep evidence of drafts, approvals, version control and meeting notes showing how the assessment was developed and approved by senior management. If your practice is not a sole practitioner model, your governing body should also be kept informed of ML/TF risks and receive compliance reporting at least once every 12 months.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.