FAQ

How do you risk-rate clients effectively under an AML/CTF program?

AUSTRAC expects reporting entities to risk-rate clients using a documented, risk-based methodology that considers customer type, services used, delivery channels, and geographic risk. AFS licensees must assign and maintain client risk ratings to determine the level of due diligence and ongoing monitoring required.

Expanded Answer
AUSTRAC’s framework requires reporting entities to assess the money laundering and terrorism financing (ML/TF) risk for each client using defined risk factors. These typically include the client’s structure (e.g., individual, company, trust), the nature of the services provided, how the services are delivered (e.g., face-to-face or remote), and any geographic exposure. The methodology must be documented and consistently applied.

In practice, firms assign risk ratings such as low, medium, or high at onboarding, supported by clear criteria. Higher-risk clients—such as those with complex structures, international connections, or unusual transactions—require enhanced due diligence and more frequent monitoring. Risk ratings must be reviewed and updated when trigger events occur, such as changes in client behaviour or circumstances.

Regulatory scrutiny increases when risk ratings are generic, inconsistently applied, or not linked to actual controls. AUSTRAC expects that risk assessments drive the level of customer due diligence and monitoring applied in practice. Practical approaches are outlined in AML/CTF financial planners Australia and Why AML programs fail adviser audits.

Why it matters
Poor client risk-rating weakens AML/CTF controls and increases exposure to financial crime and regulatory breaches. AUSTRAC enforcement often targets firms that fail to align risk assessments with actual monitoring and due diligence.

Practical guidance

  • Define and document clear risk-rating criteria covering customer type, services, delivery channels, and geography
  • Assign risk ratings at onboarding and ensure they directly determine due diligence and monitoring levels
  • Review and update client risk ratings when trigger events occur, documenting all changes and rationale

Further reading
Five AML questions you must be able to answer

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?