A business-wide ML/TF risk assessment template gives real estate agencies, conveyancers, lawyers and accountants a starting structure to document how money laundering, terrorism financing and proliferation financing risk shows up in their business. It is not a compliance shortcut. Section 26C of the Act sets what you must cover; the structure below is one way to document it. You still need to tailor every section to your designated services, have it approved and revisit it whenever your risk profile shifts.
TL;DR:
- Section 26C requires you to cover four categories: your kinds of designated services, your kinds of customers, your delivery channels, and the countries you deal with. Planned services count too, not only current ones.
- Your assessment must also assess proliferation financing risk, and must consider the risk information AUSTRAC communicates. AUSTRAC expects a register showing you have considered it.
- Completing the process involves gathering comprehensive inputs, rating risks with rationale, mapping controls, calculating residual risk, and updating regularly.
- Governing body approval, version control, and documented review triggers are essential to ensure the assessment remains current and credible.
- Using a linked, automated platform like AML Guard helps maintain ongoing, evidence-backed risk management aligned with regulatory expectations.
Table of Contents
- What a proper AML risk assessment template actually contains
- How do you tailor the template to your firm?
- How do you complete the risk assessment step by step?
- Customer risk ratings versus your firm-wide assessment
- Worked examples for property, conveyancing and accounting
- Who approves it, and when does it need updating?
- From template to live evidence with AML Guard
- Where most risk assessments actually go wrong
- Turning your template into an audit-ready program with AML Guard
- Where to check the underlying rules
- Sources
What a proper AML risk assessment template actually contains
A template that will hold up under AUSTRAC scrutiny needs more than a risk matrix with red, amber and green cells. It needs a documented chain of reasoning from “here is our business” through to “here is what we are doing about it.”
Most reporting entities underestimate how much scope-setting work comes before the risk categories even appear. AUSTRAC’s Step 2 reform guidance makes clear that a firm must identify and assess risk across the whole business, not just the parts that feel obviously risky. A conveyancer who also does small-scale probate work needs both activities reflected, even if only one is a designated service.
A workable template usually includes:
- Scope and context fields that name your designated services, entity structure, client base and any assumptions you’re making about your own exposure.
- Methodology and data sources, including where your management information, transaction data, onboarding statistics and sanctions screening results come from.
- Inherent risk categories with space to record specific indicators and the thresholds that would trigger a re-rating.
- Control mapping and residual risk, followed by an action plan naming an owner and a completion date for each gap.
- File format and evidence expectations — an editable Word or similar document, plus a separate evidence log referencing the MI extracts, minutes and screening reports that support each rating.
Structure the risk categories around what section 26C actually names, not a generic five-box model borrowed from another jurisdiction. There are four: your kinds of designated services, including any new or emerging technologies related to them; your kinds of customers; your delivery channels; and the countries you deal with. You must cover services you plan to provide as well as those you provide today.
Two further requirements sit alongside those four and are the ones most often missed. Your assessment must assess proliferation financing risk, not only money laundering and terrorism financing. And under section 26C(3)(e) you must consider the risk information AUSTRAC communicates, including its national risk assessments and sector indicators; AUSTRAC expects you to keep a register showing what you considered, when, and what changed as a result.
For country risk, list every country you or your customers deal in or with, including Australia, then rate each one. AUSTRAC points to the Basel AML Index as a workable method, and expects a high-risk rating for any country on the FATF grey or black lists or subject to Australian sanctions. For a real estate agency with overseas buyers this is usually the single most consequential section of the document.
The categories are the easy part. What separates a document that passes supervision from one that gets sent back is whether each rating is backed by a reason you can point to, not just a number in a cell.
How do you tailor the template to your firm?
A downloaded template is a skeleton. The muscle comes from mapping it precisely to what your business actually does, who it does it for, and how those services reach the client.
Start by cutting anything that doesn’t apply. If your firm only ever acts as a buyer’s agent and never handles settlement funds, don’t leave settlement-related risk language sitting in the document unedited. Supervisors read an untouched template as a red flag, not a time-saver.
- Map your designated services to the scope section first. List each service under Table 5 or Table 6 of the Act that your firm actually provides, and explicitly exclude anything you don’t offer.
- Choose the risk drivers relevant to your clients and channels. A suburban residential conveyancer and a firm handling offshore trust settlements face different geographic and customer risk exposure, even under the same Act.
- Set measurable indicators and thresholds. A workable indicator might be a measurable proportion of new clients originating from a higher-risk jurisdiction, with a defined threshold that triggers a review of your rating.
- Document assumptions and data sources. If a rating rests on an assumption (for example, that walk-in retail clients present lower risk than referred commercial clients), write down why, and where that view comes from.
- Link your outputs to your AML/CTF policies. The risk assessment should directly inform how your CDD tiering works in your policy document, so the two pieces read as one coherent program rather than two disconnected files.
Defining concrete indicators is what separates a static report from an operational tool. Practical guidance on AML risk matrices points out that thresholds only earn their keep when they’re specific enough to actually trigger something.
Pro Tip: Write your indicators as numbers you can pull from a report, not impressions. “High proportion of overseas buyers” is not measurable. Use a precisely quantifiable threshold, such as settlements involving a non-resident purchaser exceeding a defined level.

How do you complete the risk assessment step by step?
Completing the assessment is a sequence, not a single sitting. Rushing the order tends to produce ratings that look arbitrary because the reasoning behind them was never captured.
- Collect your inputs first. Pull management information, transaction volumes, onboarding rejection or delay rates, and any sanctions or PEP screening results from the past review period.
- Rate inherent risk for each category. For designated services, customers, delivery channels and countries, plus proliferation financing, record a rationale alongside the rating. AUSTRAC suggests likelihood multiplied by impact for a medium-complexity business, and impact alone for a smaller, less complex one.
- Map your controls to each risk and rate their effectiveness. A control is only as good as the evidence behind it, so cite the specific policy, system check or training record that supports the rating.
- Calculate residual risk and build a remediation plan. Where residual risk sits above your risk appetite, the action plan needs a named owner and a real date, not “ongoing.”
- Complete versioning and sign-off fields. Record who approved the document, when, and under what version number.
At minimum, keep evidence of:
- The raw MI extracts or reports used to justify each inherent risk rating.
- Screening outputs against the DFAT consolidated sanctions list where geographic or counterparty risk was assessed.
- Meeting minutes recording governing body discussion and approval.
- Version history showing what changed between reviews and why.
Regulators tend to look for MI items — onboarding rejection rates, the proportion of non-resident clients, unusual transaction counts — tied directly to rating changes and control testing results, because that’s what stops a rating from looking subjective. Keep that evidence for at least seven years, in line with your broader AML/CTF record-keeping obligations.
Customer risk ratings versus your firm-wide assessment
Your business-wide ML/TF risk assessment and your individual customer risk ratings are related but not identical, and conflating them is one of the more common template mistakes.
The firm-wide assessment describes inherent and residual risk across your whole business. A customer risk rating applies that thinking to one specific relationship, at onboarding and again on an ongoing basis. AUSTRAC’s guidance on assigning customer risk ratings sets out how the firm-wide view should directly inform the initial and ongoing CDD steps you apply to each client.
A simple translation method works for most SMEs: take the risk factors most relevant to that customer (geography, transaction type, delivery channel, source of funds complexity) and map the combined outcome to a low, medium or high tier, consistent with the bands you’ve already defined in your firm-wide assessment.
Practical KYC items typically used at initial and ongoing CDD include:
- Verified identity documents and, where relevant, beneficial ownership records for entities and trusts.
- Source of funds or wealth evidence, scaled to the size and nature of the transaction.
- Sanctions and PEP screening results, refreshed periodically rather than checked once.
- A documented trigger event log, showing when and why a customer moved from standard to enhanced due diligence.
A firm-wide assessment that never references these individual triggers is incomplete, no matter how thorough its category breakdown looks.
Worked examples for property, conveyancing and accounting
Concrete entries beat generic risk descriptions every time a supervisor reviews your document. Three examples show what a completed row should look like.
- Conveyancer, cash purchase with a PEP indicator: record the transaction value, the fact that funds were provided in cash or cash-equivalent form, and the PEP screening hit. The evidence trail should show a request for source-of-funds documentation and an enhanced due diligence outcome, not just a note that “EDD was applied.”
- Real estate agent, third-party payer: where a purchaser’s deposit is paid by someone other than the named buyer, record the relationship between payer and purchaser, the reliance arrangement relied on (if any) under sections 37A or 38, and what verification was obtained on the third party.
- Accounting practice, complex ownership structure: for a client operating through layered trusts or corporate vehicles, document each step taken to trace beneficial ownership back to the natural persons who ultimately control or benefit from the entity, and note any gaps that couldn’t be resolved.
Real estate and settlement transactions sit near the top of AUSTRAC’s risk concerns, which is exactly why generic entries in this category attract the most supervisory attention.
Who approves it, and when does it need updating?
Governance is where many otherwise solid assessments fall down. A well-reasoned document with no sign-off trail reads, to a supervisor, as though it was never actually adopted.
- Your governing body (board, partners or equivalent) should formally approve the assessment, with the approval date and attendee list recorded in minutes.
- Keep version control so every edit is traceable to a date and an approver, not just a silently updated file.
- Review the assessment on trigger events: a new or planned designated service, a material compliance incident, a shift in your customer mix, new risk information from AUSTRAC, or a change to the Rules. An annual review on top of that is good practice rather than a fixed statutory interval.
- Track progress against your action plan with dated notes, so a supervisor can see remediation actually happening rather than sitting on a to-do list.
Pro Tip: Set a calendar reminder for your annual review well before the anniversary date. Reviews done under deadline pressure tend to skip the evidence-gathering step entirely.
From template to live evidence with AML Guard
A template gets you started. Keeping it accurate, current and linked to real evidence is the part that actually protects your firm.
AML Guard’s guided wizards produce the business-wide ML/TF risk assessment as part of one linked set of AML/CTF program documents, generated from the same underlying answers rather than as separate files that quietly drift out of sync. That matters because a supervisor comparing your risk assessment to your policies and training records is checking for exactly that kind of consistency.
- Risk ratings and indicators stay connected to live CDD workflows, not a static document filed away after sign-off.
- REX CRM integration pushes compliance status against a listing without exposing sensitive CDD data to systems that don’t need it.
- A seven-year tamper-evident audit trail keeps the evidence supervisors ask for ready on demand, rather than reconstructed after the fact.
A risk assessment that only exists as a document, disconnected from onboarding and monitoring systems, stops reflecting reality the moment your client base shifts. Evidence has to be live, or it’s already out of date by the time you need it.
Firms handling higher-value or higher-risk matters sometimes commission independent financial due diligence to strengthen source-of-funds evidence before a transaction proceeds, which feeds directly into the kind of management information a risk assessment should reference.
Where most risk assessments actually go wrong

The most common failure isn’t a missing category. It’s a copy-pasted rationale that reads the same for every client and every risk factor. Supervisors notice immediately when a document hasn’t engaged with the firm’s actual book of business.
Keep the assessment live by tying it to real onboarding numbers and transaction data, not a one-off exercise redone reluctantly each year. If you want to see how a platform can generate these documents already linked to that evidence, book a demo and look at what an audit-ready version actually involves.
Turning your template into an audit-ready program with AML Guard
AML Guard replaces the disconnect between a downloaded template and the evidence you actually need at audit time. Because the business-wide risk assessment, AML/CTF policies, compliance action plan and training manual are generated from one linked set of answers, your documents stay consistent with each other automatically, which is precisely what a supervisor checks for and a static template can’t deliver on its own.

The platform runs end-to-end customer due diligence, sanctions and PEP screening with ongoing re-screening, and beneficial ownership tracing across companies, trusts and SMSFs, all feeding the same governance dashboard that holds your seven-year audit trail. REX CRM integration surfaces compliance status against a listing without pushing sensitive CDD data anywhere it doesn’t need to go. If your firm is ready to move from a document exercise to a live, evidence-linked compliance program, book a demo and see how your risk assessment stays current as your client base changes.
Where to check the underlying rules
- AUSTRAC: Step 2 — identify and assess your risks (Reform)
- AUSTRAC: assigning customer risk ratings (Reform)
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- DFAT consolidated sanctions list
Sources
- Step 2: Identify and assess your risks (Reform) | AUSTRAC
- Assigning customer risk ratings (Reform) | AUSTRAC
- Anti‑Money Laundering and Counter‑Terrorism Financing Act 2006 (Cth) — AustLII
- Consolidated list — Department of Foreign Affairs and Trade
- AML/CTF program reform guidance | AUSTRAC
Recommended
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML/CTF Program Documents for Tranche 2
- AML Guard Features — Identity Verification, UBO Tracing, Risk Assessment, REX Integration
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.