Who approved the risk rating: the audit trail AUSTRAC will ask for
The audit trail for a customer risk rating is the name of the person who approved it, the date, and the factors they used. A colour in a spreadsheet, with no owner, does not answer the question.
Quick answer
Store the rating on the program’s scale, the factors, the approver’s name, and the date. If the rating changes, store the new line. Do not overwrite the old one. The compliance officer sees that this happens; they are not the approver of every file unless the program says so; FreeAML does not sign the rating.
People search “AML audit trail prove it” when a two-partner law firm is asked who approved a medium rating and the only record is a coloured cell last edited by a shared login. Checked against AUSTRAC’s page on assigning customer risk ratings on 4 October 2026. This is general information, not legal advice. This page does not reproduce that guidance. How the assessment is built is the ML/TF risk assessment. Keeping it current day to day is ongoing customer due diligence for a small firm. The sector map is /tranche-2.
Four fields that survive a question
A later question is simple. Who approved this rating, when, and from what. A two-partner firm can answer it if those fields exist on the matter.
A shared login called office cannot. The factors matter because a rating without them cannot be reviewed when the customer changes. Overwriting the cell deletes the history the question is about.
- The scale. Use the ratings the program named. A private colour code does not match a scale nobody wrote down.
- The factors. A short note of what drove the rating, enough that another partner can see the reason.
- The name. The approver is a person. Leave cover is a second name, not a blank.
- The date, kept. A change adds a line. It does not erase the line it replaced.
What the file shows six months later
An audit trail a small firm can actually produce. This table does not reproduce AUSTRAC’s risk-rating guidance.
| Field | What to store | What fails the question |
|---|---|---|
| Rating | A value on the program’s scale | Medium, with no scale written anywhere |
| Factors | The points that drove it | A colour with no sentence |
| Approver | A person’s name | A shared login called office |
| Later change | New rating, new name, new date, old line kept | The cell overwritten on a Friday |
Where the audit-trail page stops
This page is who approved the rating and how you show it. It is not how to build the firm-wide assessment, and it is not the whole of ongoing monitoring. Those are the ML/TF risk assessment and ongoing customer due diligence for a small firm.
What the client pays
On FreeAML the firm suite is A$0. The firm emails the client a link. Verification is client-pays. On the public list a personal KYC check is A$20 and a company or trust KYB check is A$40. Use KYB when the customer is a company or a trust. An audit trail is the firm’s record, and the firm suite does not include someone to sign the rating. Confirm the live amounts on FreeAML pricing. FreeAML does not approve a risk rating or sign the audit trail.
📚 Related Resources
Lawyer AML Toolkit →
Complete compliance toolkit for lawyers & conveyancers.
Conveyancer AML Tools →
Specialized tools for settlement agents.
Free KYC Check →
Verify customer identity in 60 seconds. Government ID + AML screening.
Free AML Program →
Board-ready AML/CTF Program template. All 10 AUSTRAC sections included.
Risk Assessment Generator →
AI-powered ML/TF risk assessment. 20-page compliant report in 5 minutes.
Free AML Training →
Online courses for staff. CPD-certified certificates included.
Frequently Asked Questions
The rating is the firm’s decision. The check is the client’s payment.
The firm suite is A$0. The client pays a check the program requires. FreeAML does not approve the rating.
Open the Tranche 2 guideQuestions: team@freeaml.com.au