Back to Blog
Compliance
October 2, 202610 min read

ML/TF risk assessment: what goes in the program

An ML/TF risk assessment is the business-level half of the program. It is the record of which risks this firm faces, and what it will do about them.

Quick answer

An ML/TF risk assessment is the firm-level part of the AML/CTF program. For a small Tranche 2 firm it records the designated services you actually provide, the customers, the delivery channels, the countries, why you rated them, and the controls you will use. A senior manager approves it. FreeAML keeps the risk worksheet and the evidence in the free suite. A customer check, where the program requires one, stays client-pays.

People search “ml tf risk assessment” and land on a customer score. That is a different document. This one is about the business: the money-laundering, terrorism-financing, and proliferation-financing risks you may reasonably face because of the services you provide. Checked against AUSTRAC’s step 2, identify and assess your risks on 2 October 2026. This is general information, not legal advice, and it does not copy their method. How the assessment sits inside the written program is what goes in the AML/CTF program. Whether the firm is in the regime is /tranche-2.

What the assessment is for

AUSTRAC expects the program to include a documented risk assessment before you provide a designated service, and a senior manager to approve the program. The assessment is the reason the policies look the way they do. A rating with no services, no customers, and no controls is a cover page. A later reviewer should be able to see what you considered and what you refused.

The rating you give one customer during customer due diligence is a file note. It uses this assessment. It does not replace it. When that file note has to go further than a standard check, the extra work is enhanced customer due diligence.

What goes in it

AUSTRAC’s step 2 says you start by listing the designated services you provide, then consider the customers, the way you deliver the service, and the countries you deal with, including Australia. High-value transactions and legal structures that hide who owns the money are called out as factors a wide range of services have to consider. New technology belongs in the same pass. Write the rows that describe this firm. Leave out services you do not provide.

The blocks a small firm’s ML/TF risk assessment has to show. The method stays on AUSTRAC’s step 2.

BlockWhat you writeWhat people leave blank
Designated servicesThe services this practice actually provides, and why each can be misusedA copied industry list that includes work you do not do
CustomersThe kinds you see, and which factors make some of them higher risk“Mostly local individuals”, with no split and no trust or company row
Delivery channelsIn person, remote with a staff member, or through a third partyAssuming a meeting removes the risk, or ignoring the platform you already use
CountriesEvery country you deal with when you provide the service, including AustraliaNo country row because the office is in one city
Controls and appetiteWhat you do about each risk, and the work you will not acceptA colour rating with no control and no refusal line
ReviewThe trigger that makes you open it again, and who approves the updateA file dated the day you downloaded a template
  • Customers. Individuals, companies, trusts, and people who live overseas are different rows when you actually see them. A politically exposed person, a complex structure, or wealth you cannot explain is a factor, not a separate product. The customer check that follows is customer due diligence requirements.
  • Channels. A remote engagement is still a channel when staff help the client. A third-party platform is a channel when the service runs through it. Write the one you use.
  • Countries. Australia is a country in the assessment. Overseas clients are another row, split by the country risk you have actually looked up, not by a hunch.
  • Approval. A senior manager approves the assessment with the rest of the program. In a one-person practice that person may be the owner. The role is can a sole trader be their own compliance officer.

The worksheet is the record of what you considered

Keep the answers, not only the final colour. Which services you ticked, which customer types you see, which countries you listed, and which controls you named are the evidence that the rating came from this firm. If a new service, a new country, or a failed control changes the picture, update the worksheet and approve it again. AUSTRAC’s program guidance is where the review triggers live. Do not invent a shorter cycle than you will keep, and do not leave the document untouched after the first download.

Where FreeAML fits

The FreeAML firm suite is A$0. The risk worksheet lives there: the firm answers the questions, and the suite stores those answers with a draft assessment you can download. That draft is evidence of what you considered. You still edit it so it matches the services you provide, and a senior manager still approves it. FreeAML does not approve the assessment, does not enrol the firm, and does not replace AUSTRAC’s step 2.

A customer check is separate. When the approved program says someone must be verified, the firm sends the request by email and verification is client-pays. Current amounts are on FreeAML pricing. The worksheet does not charge a fee, and it does not decide the customer’s rating.

Frequently Asked Questions

Keep the risk worksheet in the free suite

The firm suite is A$0. You still edit the draft and a senior manager still approves it. Customer checks are client-pays.

Start the risk worksheet

Questions: team@freeaml.com.au