AML risk scoring assigns each customer an operational risk tier that dictates due diligence depth and monitoring frequency. The compliance-critical requirement isn’t the number itself. It’s whether every score can be reconstructed later, showing the inputs, the policy version applied, and who approved any departure from it. Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), that reconstructable reasoning is what AUSTRAC actually tests.
TL;DR:
- Risk scores must be fully reconstructible, including inputs, policy versions, and override reasons, to satisfy AUSTRAC’s testing requirements.
- The risk rating process should be based on four factors—customer, service, channel, and jurisdiction—and flexibly applied according to business size and complexity.
- Onboarding, review cadence, and re-scoring must be tied to tiers with automated triggers for changes in information, ensuring proportionate monitoring.
- An immutable, detailed audit trail covering inputs, factor flags, policy version, override documentation, and timestamps is essential for seven-year retention.
- Governance flaws, such as untracked weight changes or overreliance on screening feeds, undermine the defensibility of AML risk scoring programs.
Table of Contents
- What a defensible AML risk-scoring approach must include
- Turning scores into onboarding, monitoring and case decisions
- Building an audit trail that survives seven years
- Common pitfalls that make a scoring program indefensible
- How AML Guard builds this into a working program
- The record beats the number
- Get an audit-ready scoring program without building one from scratch
- Sources
What a defensible AML risk-scoring approach must include
AUSTRAC doesn’t hand reporting entities a formula. It expects a method proportionate to the size and complexity of the business, integrated into your AML/CTF policies rather than bolted on as a separate spreadsheet exercise. The customer risk rating process AUSTRAC describes must draw on information reasonably available at initial customer due diligence, then flex as ongoing due diligence surfaces new facts.
A workable approach captures four factor families and records whether each is present, rather than assigning it a secret point value:
- Customer factors: entity type, ownership structure, and behaviour inconsistent with stated purpose.
- Service or product factors: cash-intensive transactions, high-value settlements, or products known to attract layering.
- Channel factors: face-to-face onboarding versus remote or intermediary-based relationships.
- Jurisdiction factors: links to countries flagged on sanctions or high-risk lists, including DFAT’s consolidated sanctions list.
The rating then determines your customer due diligence posture: standard due diligence for lower-risk relationships, enhanced due diligence where factors stack up. AUSTRAC treats this rating as the operational expression of your risk-based approach, so the link between tier and CDD posture needs to be documented, not assumed by whoever built the spreadsheet.
Policy governance closes the loop. Any change to how factors are weighed needs a version number, an approval record, and a documented reason if an officer overrides the system-generated tier.
Pro Tip: Write your policy so a new compliance officer, reading it cold, could explain to AUSTRAC why any given customer sits in their current tier. If the policy can’t do that, the scoring method isn’t ready.
Turning scores into onboarding, monitoring and case decisions
A risk tier is only useful once it changes what your team actually does. Build the workflow around three moments: onboarding, periodic review, and event-driven re-scoring.
- Branch onboarding by band. Lower-tier customers proceed through standard identity verification. Higher tiers trigger enhanced due diligence, meaning deeper source-of-funds enquiry, senior sign-off before the relationship proceeds, and beneficial ownership tracing where a trust or corporate structure sits between you and the actual client.
- Set a review cadence tied to tier. Higher-risk customers get reviewed more often than lower-risk ones. Build in triggers that shorten the interval, such as a transaction well outside the customer’s stated profile.
- Re-score the moment new information lands. A hit against a sanctions or politically exposed persons screen, adverse media, an unresolved beneficial ownership chain, or unexplained activity should all force an immediate reassessment rather than waiting for the next scheduled review. DFAT’s consolidated list changes are a legitimate trigger and, where possible, should feed the re-scoring engine automatically.
- Route cases with clear ownership. High-risk and escalated files go to a designated analyst queue with a service-level target for first review, and any case involving a proposed lower-risk override needs a second, more senior signature before it’s actioned.
Industry practice increasingly favours dynamic scoring models that update as events occur, freeing analyst time for the relationships that genuinely warrant it while keeping monitoring proportionate for low-risk customers.
Pro Tip: Track your false positive rate by tier over time. If your highest band keeps ballooning without a matching rise in substantiated concerns, your factor weighting probably needs recalibrating, not your headcount.
Building an audit trail that survives seven years
An AUSTRAC officer reviewing a file months after the fact won’t ask what the score was. They’ll ask why it was that score, on what factors, and who signed off if a human overrode it. Answering that requires an immutable, append-only record, never an editable field that gets overwritten each time someone reruns the assessment.
Each score record should preserve:
- The inputs used and the date they were captured.
- Per-factor sub-scores or flags, not just the final composite tier.
- The policy version in force at the time the score was calculated.
- Manual override details: the written reason, the approver’s identity, and the date.
- A timestamp linking the record to the customer file and any related program document.
Retention runs for seven years, and the format matters as much as the content. A changelog approach that stores per-factor detail and version metadata means any historic score can be reconstructed exactly as it stood under the policy active at that time, which is precisely what a regulator wants to see reproduced on demand rather than reconstructed from memory.
Common pitfalls that make a scoring program indefensible
Most weak scoring programs fail for governance reasons, not mathematical ones. Watch for these:
- Letting the score decide alone. A tier is an input to human judgement, not a replacement for it.
- Changing weights or thresholds without a version record. Undocumented tweaks make every prior score unexplainable.
- Leaning on a single screening feed. One data source produces both blind spots and a flood of false positives.
- Ignoring operational load. A banding scheme that pushes half your book into “enhanced” swamps analysts and defeats the purpose of a risk-based approach.
Pro Tip: Backtest your bands against outcomes twice a year. If enhanced due diligence cases rarely reveal anything, your thresholds are miscalibrated, not your analysts.
How AML Guard builds this into a working program
AML Guard’s guided wizards generate the business-wide risk assessment, AML/CTF policies, compliance action plan, and training manual as one linked set, so the scoring method described in your policy is the one your workflows actually apply.
- Identity verification, sanctions and politically exposed persons screening, and beneficial ownership tracing across companies, trusts, and self-managed super funds all feed directly into re-scoring triggers.
- CRM integration pushes only status indicators, never underlying CDD data, so compliance state is visible without exposing sensitive files.
The record beats the number
The industry conversation around AML risk scoring spends too much energy on weighting schemes and not enough on evidence. A supervisor doesn’t care whether your model used five factors or fifteen. They care whether you can show, for any customer, on any date, exactly why that tier applied and who signed off if a human changed it.

That’s a governance discipline, not a maths problem. Versioned policy, append-only history, and named approvers are what separate a program that survives scrutiny from one that collapses under a single pointed question. Automation should support that discipline, not obscure it behind a black box nobody in the compliance team can explain.
Train your staff to read score lineage the same way you’d train them to read a file note: who changed what, when, and why. That’s the skill that matters when AUSTRAC calls.
Get an audit-ready scoring program without building one from scratch
Building the governance described above from spreadsheets and shared drives is possible, but it’s slow, and it’s the first thing that falls apart under scrutiny when the person who built it leaves. AML Guard gives Tranche 2 reporting entities a faster path: guided risk assessment, identity and beneficial ownership checks, sanctions and politically exposed persons screening, and an append-only audit trail, all generated from one linked set of program documents instead of four disconnected templates.

Onboarding starts with a conversation, not a sign-up form. There’s no free trial because every tenant is configured to your specific designated services, risk profile, and existing workflow, including status-only integration with REX CRM that keeps sensitive customer data out of systems that don’t need it. If your current scoring approach couldn’t survive a supervisor’s follow-up question, it’s worth seeing how the pieces fit together. Book a demo and walk through how your business risk assessment, your due diligence workflow, and your evidence trail can finally run as one system rather than three.
Sources
- Assigning customer risk ratings (Reform) | AUSTRAC
- AML/CTF program reform guidance | AUSTRAC
- Consolidated list of sanctions | DFAT
Recommended
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML/CTF Program Documents for Tranche 2
- What Is an AML/CTF Program? A Plain-English Guide for Property Professionals
- When Does AML Compliance Actually Start?
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.