AML risk assessment template for Tranche 2 firms

AML risk assessment template for Tranche 2 firms

What section 26C requires your ML/TF risk assessment to cover, how to structure it, and worked property examples. Australian Tranche 2 firms.

AML/CTF Compliance 28 August 2026 11 min read AML Guard

A business-wide ML/TF risk assessment template gives real estate agencies, conveyancers, lawyers and accountants a starting structure to document how money laundering, terrorism financing and proliferation financing risk shows up in their business. It is not a compliance shortcut. Section 26C of the Act sets what you must cover; the structure below is one way to document it. You still need to tailor every section to your designated services, have it approved and revisit it whenever your risk profile shifts.


TL;DR:


Table of Contents

What a proper AML risk assessment template actually contains

A template that will hold up under AUSTRAC scrutiny needs more than a risk matrix with red, amber and green cells. It needs a documented chain of reasoning from “here is our business” through to “here is what we are doing about it.”

Most reporting entities underestimate how much scope-setting work comes before the risk categories even appear. AUSTRAC’s Step 2 reform guidance makes clear that a firm must identify and assess risk across the whole business, not just the parts that feel obviously risky. A conveyancer who also does small-scale probate work needs both activities reflected, even if only one is a designated service.

A workable template usually includes:

Structure the risk categories around what section 26C actually names, not a generic five-box model borrowed from another jurisdiction. There are four: your kinds of designated services, including any new or emerging technologies related to them; your kinds of customers; your delivery channels; and the countries you deal with. You must cover services you plan to provide as well as those you provide today.

Two further requirements sit alongside those four and are the ones most often missed. Your assessment must assess proliferation financing risk, not only money laundering and terrorism financing. And under section 26C(3)(e) you must consider the risk information AUSTRAC communicates, including its national risk assessments and sector indicators; AUSTRAC expects you to keep a register showing what you considered, when, and what changed as a result.

For country risk, list every country you or your customers deal in or with, including Australia, then rate each one. AUSTRAC points to the Basel AML Index as a workable method, and expects a high-risk rating for any country on the FATF grey or black lists or subject to Australian sanctions. For a real estate agency with overseas buyers this is usually the single most consequential section of the document.

The categories are the easy part. What separates a document that passes supervision from one that gets sent back is whether each rating is backed by a reason you can point to, not just a number in a cell.

How do you tailor the template to your firm?

A downloaded template is a skeleton. The muscle comes from mapping it precisely to what your business actually does, who it does it for, and how those services reach the client.

Start by cutting anything that doesn’t apply. If your firm only ever acts as a buyer’s agent and never handles settlement funds, don’t leave settlement-related risk language sitting in the document unedited. Supervisors read an untouched template as a red flag, not a time-saver.

  1. Map your designated services to the scope section first. List each service under Table 5 or Table 6 of the Act that your firm actually provides, and explicitly exclude anything you don’t offer.
  2. Choose the risk drivers relevant to your clients and channels. A suburban residential conveyancer and a firm handling offshore trust settlements face different geographic and customer risk exposure, even under the same Act.
  3. Set measurable indicators and thresholds. A workable indicator might be a measurable proportion of new clients originating from a higher-risk jurisdiction, with a defined threshold that triggers a review of your rating.
  4. Document assumptions and data sources. If a rating rests on an assumption (for example, that walk-in retail clients present lower risk than referred commercial clients), write down why, and where that view comes from.
  5. Link your outputs to your AML/CTF policies. The risk assessment should directly inform how your CDD tiering works in your policy document, so the two pieces read as one coherent program rather than two disconnected files.

Defining concrete indicators is what separates a static report from an operational tool. Practical guidance on AML risk matrices points out that thresholds only earn their keep when they’re specific enough to actually trigger something.

Pro Tip: Write your indicators as numbers you can pull from a report, not impressions. “High proportion of overseas buyers” is not measurable. Use a precisely quantifiable threshold, such as settlements involving a non-resident purchaser exceeding a defined level.

Geometric paperweights symbolising measurable indicators

How do you complete the risk assessment step by step?

Completing the assessment is a sequence, not a single sitting. Rushing the order tends to produce ratings that look arbitrary because the reasoning behind them was never captured.

  1. Collect your inputs first. Pull management information, transaction volumes, onboarding rejection or delay rates, and any sanctions or PEP screening results from the past review period.
  2. Rate inherent risk for each category. For designated services, customers, delivery channels and countries, plus proliferation financing, record a rationale alongside the rating. AUSTRAC suggests likelihood multiplied by impact for a medium-complexity business, and impact alone for a smaller, less complex one.
  3. Map your controls to each risk and rate their effectiveness. A control is only as good as the evidence behind it, so cite the specific policy, system check or training record that supports the rating.
  4. Calculate residual risk and build a remediation plan. Where residual risk sits above your risk appetite, the action plan needs a named owner and a real date, not “ongoing.”
  5. Complete versioning and sign-off fields. Record who approved the document, when, and under what version number.

At minimum, keep evidence of:

Regulators tend to look for MI items — onboarding rejection rates, the proportion of non-resident clients, unusual transaction counts — tied directly to rating changes and control testing results, because that’s what stops a rating from looking subjective. Keep that evidence for at least seven years, in line with your broader AML/CTF record-keeping obligations.

Customer risk ratings versus your firm-wide assessment

Your business-wide ML/TF risk assessment and your individual customer risk ratings are related but not identical, and conflating them is one of the more common template mistakes.

The firm-wide assessment describes inherent and residual risk across your whole business. A customer risk rating applies that thinking to one specific relationship, at onboarding and again on an ongoing basis. AUSTRAC’s guidance on assigning customer risk ratings sets out how the firm-wide view should directly inform the initial and ongoing CDD steps you apply to each client.

A simple translation method works for most SMEs: take the risk factors most relevant to that customer (geography, transaction type, delivery channel, source of funds complexity) and map the combined outcome to a low, medium or high tier, consistent with the bands you’ve already defined in your firm-wide assessment.

Practical KYC items typically used at initial and ongoing CDD include:

A firm-wide assessment that never references these individual triggers is incomplete, no matter how thorough its category breakdown looks.

Worked examples for property, conveyancing and accounting

Concrete entries beat generic risk descriptions every time a supervisor reviews your document. Three examples show what a completed row should look like.

Real estate and settlement transactions sit near the top of AUSTRAC’s risk concerns, which is exactly why generic entries in this category attract the most supervisory attention.

Who approves it, and when does it need updating?

Governance is where many otherwise solid assessments fall down. A well-reasoned document with no sign-off trail reads, to a supervisor, as though it was never actually adopted.

Pro Tip: Set a calendar reminder for your annual review well before the anniversary date. Reviews done under deadline pressure tend to skip the evidence-gathering step entirely.

From template to live evidence with AML Guard

A template gets you started. Keeping it accurate, current and linked to real evidence is the part that actually protects your firm.

AML Guard’s guided wizards produce the business-wide ML/TF risk assessment as part of one linked set of AML/CTF program documents, generated from the same underlying answers rather than as separate files that quietly drift out of sync. That matters because a supervisor comparing your risk assessment to your policies and training records is checking for exactly that kind of consistency.

A risk assessment that only exists as a document, disconnected from onboarding and monitoring systems, stops reflecting reality the moment your client base shifts. Evidence has to be live, or it’s already out of date by the time you need it.

Firms handling higher-value or higher-risk matters sometimes commission independent financial due diligence to strengthen source-of-funds evidence before a transaction proceeds, which feeds directly into the kind of management information a risk assessment should reference.

Where most risk assessments actually go wrong

Where most risk assessments actually go wrong — overview diagram

The most common failure isn’t a missing category. It’s a copy-pasted rationale that reads the same for every client and every risk factor. Supervisors notice immediately when a document hasn’t engaged with the firm’s actual book of business.

Keep the assessment live by tying it to real onboarding numbers and transaction data, not a one-off exercise redone reluctantly each year. If you want to see how a platform can generate these documents already linked to that evidence, book a demo and look at what an audit-ready version actually involves.

Turning your template into an audit-ready program with AML Guard

AML Guard replaces the disconnect between a downloaded template and the evidence you actually need at audit time. Because the business-wide risk assessment, AML/CTF policies, compliance action plan and training manual are generated from one linked set of answers, your documents stay consistent with each other automatically, which is precisely what a supervisor checks for and a static template can’t deliver on its own.

AML Guard compliance dashboard showing linked AML/CTF program documents

The platform runs end-to-end customer due diligence, sanctions and PEP screening with ongoing re-screening, and beneficial ownership tracing across companies, trusts and SMSFs, all feeding the same governance dashboard that holds your seven-year audit trail. REX CRM integration surfaces compliance status against a listing without pushing sensitive CDD data anywhere it doesn’t need to go. If your firm is ready to move from a document exercise to a live, evidence-linked compliance program, book a demo and see how your risk assessment stays current as your client base changes.

Where to check the underlying rules

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 28 August 2026.