AML/CTF compliance

Your ML/TF Risk Assessment Should Be a Living Document, Not a PDF in a Drawer

26 September 2026 · 4 min read

Compliance officer reviewing a colour-coded AML risk assessment

In brief

An effective ML/TF risk assessment is a living record of business-wide, customer and matter-level risks. It should change when the firm’s services, customers, delivery channels, jurisdictions or transaction patterns change.

Every AML/CTF program starts with a risk assessment. AUSTRAC requires reporting entities to identify and assess their money laundering, terrorism financing and proliferation financing risks, and to keep the program up to date.

Three levels of risk

1. Business-wide: the risks from your client base, your services (conveyancing, entity structuring, trust money), how you deliver them (in person or remotely) and the jurisdictions you deal with. 2. Client: a risk rating for each client that decides the level of due diligence, standard or enhanced. 3. Matter or transaction: the risk of this particular deal. A low-risk long-standing client can still bring you a high-risk transaction.

Red flags common in legal and conveyancing work

Check your list against AUSTRAC's legal-sector guidance and program starter kit.

  • cash, or funds from a source that can't be explained
  • payments from unrelated third parties
  • complex or opaque structures where beneficial ownership is unclear
  • property bought well above or below market value, or resold quickly
  • late changes to settlement instructions or payee accounts
  • instructions that make no commercial sense
  • links to high-risk jurisdictions
  • politically exposed persons (PEPs)
  • digital assets in the funds flow

Why "living" matters

A risk assessment written once for enrolment and never updated won't match your real practice within months. AUSTRAC's concern about low SMR volume ties back to this: weak risk assessment leads to weak detection, which leads to weak reporting.

How Comply.LM helps

- automated client risk scoring with a traffic-light (RAG) display - a document repository for your risk assessments - every rating decision attributed and timestamped

- build your business-wide assessment from your actual client and matter mix - re-score clients and matters when something changes, such as new KYC details, a sanctions update or a change in settlement instructions - explain every score with the evidence behind it

A human confirms every change to a rating.

General information only, not legal advice.

  • Today:
  • Coming next: The Comply.LM Risk Assessment Agent will:

Authoritative sources

This article draws on current AUSTRAC guidance. Always check the source guidance for updates that apply to your circumstances.

Common questions

What are the three levels of ML/TF risk?

Business-wide risk, customer risk, and matter or transaction risk.

How often should the risk assessment change?

Review it regularly and whenever a material trigger changes the firm’s services, customers, delivery channels, jurisdictions or risk exposure.