Back to Blog
Compliance
October 4, 20269 min read

Who approved the risk rating: the audit trail AUSTRAC will ask for

The audit trail for a customer risk rating is the name of the person who approved it, the date, and the factors they used. A colour in a spreadsheet, with no owner, does not answer the question.

Quick answer

Store the rating on the program’s scale, the factors, the approver’s name, and the date. If the rating changes, store the new line. Do not overwrite the old one. The compliance officer sees that this happens; they are not the approver of every file unless the program says so; FreeAML does not sign the rating.

People search “AML audit trail prove it” when a two-partner law firm is asked who approved a medium rating and the only record is a coloured cell last edited by a shared login. Checked against AUSTRAC’s page on assigning customer risk ratings on 4 October 2026. This is general information, not legal advice. This page does not reproduce that guidance. How the assessment is built is the ML/TF risk assessment. Keeping it current day to day is ongoing customer due diligence for a small firm. The sector map is /tranche-2.

Four fields that survive a question

A later question is simple. Who approved this rating, when, and from what. A two-partner firm can answer it if those fields exist on the matter.

A shared login called office cannot. The factors matter because a rating without them cannot be reviewed when the customer changes. Overwriting the cell deletes the history the question is about.

  • The scale. Use the ratings the program named. A private colour code does not match a scale nobody wrote down.
  • The factors. A short note of what drove the rating, enough that another partner can see the reason.
  • The name. The approver is a person. Leave cover is a second name, not a blank.
  • The date, kept. A change adds a line. It does not erase the line it replaced.

What the file shows six months later

An audit trail a small firm can actually produce. This table does not reproduce AUSTRAC’s risk-rating guidance.

FieldWhat to storeWhat fails the question
RatingA value on the program’s scaleMedium, with no scale written anywhere
FactorsThe points that drove itA colour with no sentence
ApproverA person’s nameA shared login called office
Later changeNew rating, new name, new date, old line keptThe cell overwritten on a Friday

Where the audit-trail page stops

This page is who approved the rating and how you show it. It is not how to build the firm-wide assessment, and it is not the whole of ongoing monitoring. Those are the ML/TF risk assessment and ongoing customer due diligence for a small firm.

What the client pays

On FreeAML the firm suite is A$0. The firm emails the client a link. Verification is client-pays. On the public list a personal KYC check is A$20 and a company or trust KYB check is A$40. Use KYB when the customer is a company or a trust. An audit trail is the firm’s record, and the firm suite does not include someone to sign the rating. Confirm the live amounts on FreeAML pricing. FreeAML does not approve a risk rating or sign the audit trail.

Frequently Asked Questions

The rating is the firm’s decision. The check is the client’s payment.

The firm suite is A$0. The client pays a check the program requires. FreeAML does not approve the rating.

Open the Tranche 2 guide

Questions: team@freeaml.com.au