AML Compliance Guide

ML/TF risk assessment for Trust and company service providerss — 2026 AUSTRAC Guide

If your business forms companies, acts as a director or nominee, provides a registered office or business address, or sets up or administers trusts, you must complete a written ML/TF risk assessment. Trust and company service providers are exposed to higher misuse risks because criminals can use corporate structures, trustees, shelf companies and layered ownership to hide who is really behind assets or transactions. If you do not do this properly, you risk breaching the AML/CTF Act, delaying your AML/CTF program, and facing AUSTRAC enforcement, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional contraventions.

This obligation is the foundation for the rest of your AML/CTF compliance. Your risk assessment must be a written document that identifies and rates the money laundering, terrorism financing and proliferation financing risks in your business before you finalise your AML/CTF program. AUSTRAC’s guidance for trust and company service providers says you must consider 4 risk categories: the services you provide, the customers you deal with, the channels you use to deliver services, and the countries you deal with. You must also consider AUSTRAC risk information, including sector guidance, national risk assessments and any direct feedback AUSTRAC gives you.

What a trust and company service provider should do

  • List each designated service you provide, such as company formation, registered office services, acting as trustee, arranging nominee shareholders or directors, or administration of trusts and companies.
  • Identify inherent risk before controls. Ask how each service could be exploited to conceal beneficial ownership, move value through complex structures, obscure source of funds, or create links to overseas high-risk jurisdictions.
  • Assess customer risk. Pay close attention to foreign controllers, politically exposed persons, customers using intermediaries, unusual ownership chains, discretionary trusts, and clients who resist giving trust deeds or corporate documents.
  • Assess delivery channel and geographic risk. Face-to-face onboarding is usually easier to verify than remote onboarding. Cross-border structures, offshore beneficiaries, and dealings connected to high-risk countries increase risk.
  • Evaluate and prioritise the risks. High-risk areas must be addressed first, and the results should directly drive stronger controls in your AML/CTF policies, such as enhanced due diligence and source of funds checks.
  • Document approvals, review triggers and version history so you can show AUSTRAC when the assessment was approved, who approved it, and when it was updated.

Timing rule

Complete the ML/TF risk assessment before finalising your AML/CTF program. Under AUSTRAC guidance, reporting entities must develop an effective AML/CTF program before providing a designated service, and your risk assessment is the first step. Your AML/CTF program must be finalised by 31 December 2026.

For this profession, common mistakes usually come from treating the assessment as a generic template. AUSTRAC expects it to reflect how your practice actually works. A trust and company service provider with only Australian proprietary companies and local directors has a different risk profile from a business setting up structures with overseas beneficiaries, private protectors, nominee arrangements or clients connected to dual-use goods, arms or sanctioned countries. Another mistake is stopping at money laundering and terrorism financing. You must assess proliferation financing risk as well. If your clients, controllers or transactions involve high-risk jurisdictions, export-linked sectors or goods on the Defence and Strategic Goods List, that needs to be considered.

Practical tips for a small TCSP practice

  • Build your risk assessment around your actual file types, not legal categories alone. Separate company formation work from trust administration and nominee services because the risks differ.
  • Create a red-flag section for complex ownership structures, bearer-style control arrangements, unexplained urgency, frequent director changes, and customers who want addresses or office services without a clear commercial reason.
  • Use examples from recent matters to test whether your ratings make sense. If a file would require beneficial ownership tracing across multiple entities, it is unlikely to be low risk.
  • Set clear review triggers now: new services, expansion offshore, a change in customer base, AUSTRAC updates, sanctions developments, or a suspicious matter in your practice.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need a separate risk assessment for each company or trust I set up?
No. The obligation is to prepare a business-level ML/TF risk assessment for your practice. That said, your assessment must be detailed enough to cover the different services you offer, and you still need to assess individual customers and matters under your customer due diligence processes.
What if I only provide registered office or business address services for Australian clients?
You still need a written risk assessment if that service is a designated service. Your overall risk may be lower than a TCSP dealing with offshore structures, but you must still assess misuse risks such as shell company activity, concealment of beneficial ownership, and customers using the address to create a false appearance of legitimacy.
Can I buy a template and use that as my risk assessment?
You can use a template as a starting point, but not as the final product unless it is tailored to your business. AUSTRAC expects the document to reflect your actual services, customer types, delivery channels, countries, and specific proliferation financing exposure. A generic template with no practice-specific analysis will not be enough.
How often do I have to update the risk assessment?
Update it whenever your business changes materially. For a TCSP, that usually means adding new services, taking on overseas clients, dealing with more complex trust structures, changing onboarding channels, or responding to AUSTRAC risk updates. You should also record review frequency and triggers in the document itself.
Does this have to be done by an external consultant, and what records should I keep?
No. A small practice can prepare its own assessment if it is accurate, written, and approved properly. Keep the current version, version history, approval records, notes showing what risks were considered, AUSTRAC communications you relied on, and records of later reviews and updates.