FAQ

How should AFS licensees assess customer risk at onboarding using AML/CTF signals?

AUSTRAC expects AFS licensees to assess customer risk at onboarding using a risk-based approach that incorporates factors such as geography, product, channel, and customer type, supported by fraud signals like IP, device, and network indicators. Effective onboarding risk scoring combines these inputs to assign a defensible risk rating and trigger appropriate controls.

Expanded Answer
AUSTRAC expects reporting entities to conduct ML/TF risk assessments and apply a risk-based approach when onboarding customers. This includes evaluating inherent risk factors such as customer type, products and services used, delivery channels, and geographic exposure. ASIC expects AFS licensees to maintain risk management systems capable of identifying and responding to financial crime and misconduct, including risks evident at onboarding.

In practice, onboarding risk scoring should combine traditional risk factors with fraud signals. Core inputs include geography (for example, high-risk jurisdictions), product or service risk, delivery channel (digital versus face-to-face), and customer profile. These should be supplemented with signals such as high-risk IP geolocation, use of VPN, proxy, or Tor networks, suspicious or anonymised ISPs, and inconsistencies between declared and observed location data. The objective is to produce a consolidated risk rating that reflects both AML/CTF exposure and fraud likelihood.

Risk increases where multiple signals align, such as a high-risk jurisdiction combined with anonymised network access or inconsistent identity data. AFS licensees should calibrate onboarding controls so higher-risk profiles trigger enhanced due diligence, additional verification, or restrictions. This signals-based approach aligns with evolving expectations for data-driven surveillance, as outlined in From samples to signals: a smarter approach to AFSL surveillance and broader AML obligations in AML/CTF financial planners Australia.

Why it matters
Weak onboarding risk assessment increases exposure to financial crime, inadequate customer due diligence, and regulatory breaches. Regulators assess whether AFS licensees can demonstrate a structured, risk-based methodology that integrates multiple signals and supports defensible decisions.

Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.

Practical guidance

  • Define a risk scoring model that combines geography, product, channel, and customer type with fraud signals
  • Incorporate network and device indicators (for example, VPN usage or high-risk IP) into onboarding risk ratings
  • Escalate higher-risk customers to enhanced due diligence based on combined risk factors

Further reading

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?