If your business forms companies, acts as a director or nominee, provides a registered office or business address, or sets up or administers trusts, you must complete a written ML/TF risk assessment. Trust and company service providers are exposed to higher misuse risks because criminals can use corporate structures, trustees, shelf companies and layered ownership to hide who is really behind assets or transactions. If you do not do this properly, you risk breaching the AML/CTF Act, delaying your AML/CTF program, and facing AUSTRAC enforcement, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional contraventions.
Your AML/CTF obligations
This obligation is the foundation for the rest of your AML/CTF compliance. Your risk assessment must be a written document that identifies and rates the money laundering, terrorism financing and proliferation financing risks in your business before you finalise your AML/CTF program. AUSTRAC’s guidance for trust and company service providers says you must consider 4 risk categories: the services you provide, the customers you deal with, the channels you use to deliver services, and the countries you deal with. You must also consider AUSTRAC risk information, including sector guidance, national risk assessments and any direct feedback AUSTRAC gives you.
What a trust and company service provider should do
Timing rule
Complete the ML/TF risk assessment before finalising your AML/CTF program. Under AUSTRAC guidance, reporting entities must develop an effective AML/CTF program before providing a designated service, and your risk assessment is the first step. Your AML/CTF program must be finalised by 31 December 2026.
For this profession, common mistakes usually come from treating the assessment as a generic template. AUSTRAC expects it to reflect how your practice actually works. A trust and company service provider with only Australian proprietary companies and local directors has a different risk profile from a business setting up structures with overseas beneficiaries, private protectors, nominee arrangements or clients connected to dual-use goods, arms or sanctioned countries. Another mistake is stopping at money laundering and terrorism financing. You must assess proliferation financing risk as well. If your clients, controllers or transactions involve high-risk jurisdictions, export-linked sectors or goods on the Defence and Strategic Goods List, that needs to be considered.
Practical tips for a small TCSP practice
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.