AUSTRAC expects AFS licensees to assess customer risk at onboarding using a risk-based approach that incorporates factors such as geography, product, channel, and customer type, supported by fraud signals like IP, device, and network indicators. Effective onboarding risk scoring combines these inputs to assign a defensible risk rating and trigger appropriate controls.
Expanded Answer
AUSTRAC expects reporting entities to conduct ML/TF risk assessments and apply a risk-based approach when onboarding customers. This includes evaluating inherent risk factors such as customer type, products and services used, delivery channels, and geographic exposure. ASIC expects AFS licensees to maintain risk management systems capable of identifying and responding to financial crime and misconduct, including risks evident at onboarding.
In practice, onboarding risk scoring should combine traditional risk factors with fraud signals. Core inputs include geography (for example, high-risk jurisdictions), product or service risk, delivery channel (digital versus face-to-face), and customer profile. These should be supplemented with signals such as high-risk IP geolocation, use of VPN, proxy, or Tor networks, suspicious or anonymised ISPs, and inconsistencies between declared and observed location data. The objective is to produce a consolidated risk rating that reflects both AML/CTF exposure and fraud likelihood.
Risk increases where multiple signals align, such as a high-risk jurisdiction combined with anonymised network access or inconsistent identity data. AFS licensees should calibrate onboarding controls so higher-risk profiles trigger enhanced due diligence, additional verification, or restrictions. This signals-based approach aligns with evolving expectations for data-driven surveillance, as outlined in From samples to signals: a smarter approach to AFSL surveillance and broader AML obligations in AML/CTF financial planners Australia.
Why it matters
Weak onboarding risk assessment increases exposure to financial crime, inadequate customer due diligence, and regulatory breaches. Regulators assess whether AFS licensees can demonstrate a structured, risk-based methodology that integrates multiple signals and supports defensible decisions.
Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
Practical guidance
- Define a risk scoring model that combines geography, product, channel, and customer type with fraud signals
- Incorporate network and device indicators (for example, VPN usage or high-risk IP) into onboarding risk ratings
- Escalate higher-risk customers to enhanced due diligence based on combined risk factors
Further reading