AUSTRAC expects reporting entities to risk-rate clients using a documented, risk-based methodology that considers customer type, services used, delivery channels, and geographic risk. AFS licensees must assign and maintain client risk ratings to determine the level of due diligence and ongoing monitoring required.
Expanded Answer
AUSTRAC’s framework requires reporting entities to assess the money laundering and terrorism financing (ML/TF) risk for each client using defined risk factors. These typically include the client’s structure (e.g., individual, company, trust), the nature of the services provided, how the services are delivered (e.g., face-to-face or remote), and any geographic exposure. The methodology must be documented and consistently applied.
In practice, firms assign risk ratings such as low, medium, or high at onboarding, supported by clear criteria. Higher-risk clients—such as those with complex structures, international connections, or unusual transactions—require enhanced due diligence and more frequent monitoring. Risk ratings must be reviewed and updated when trigger events occur, such as changes in client behaviour or circumstances.
Regulatory scrutiny increases when risk ratings are generic, inconsistently applied, or not linked to actual controls. AUSTRAC expects that risk assessments drive the level of customer due diligence and monitoring applied in practice. Practical approaches are outlined in AML/CTF financial planners Australia and Why AML programs fail adviser audits.
Why it matters
Poor client risk-rating weakens AML/CTF controls and increases exposure to financial crime and regulatory breaches. AUSTRAC enforcement often targets firms that fail to align risk assessments with actual monitoring and due diligence.
Practical guidance
- Define and document clear risk-rating criteria covering customer type, services, delivery channels, and geography
- Assign risk ratings at onboarding and ensure they directly determine due diligence and monitoring levels
- Review and update client risk ratings when trigger events occur, documenting all changes and rationale
Further reading
Five AML questions you must be able to answer