ML/TF/PF Risk Assessment
The foundation of any AML/CTF Program is a thorough assessment of the money laundering, terrorism financing and proliferation financing (ML/TF/PF) risks your business faces. Under the AML/CTF Act and Rules 2025, your risk assessment must be documented, kept current and proportionate to the nature, size and complexity of your business.
A risk assessment is not a one-off exercise. It must be reviewed whenever there is a material change to your business, your customer base, your products or services, your delivery channels, or the jurisdictions in which you operate. It must also be reviewed in response to updated AUSTRAC guidance or changes in the external risk environment.
The risk assessment informs every other element of your Program - from the controls you put in place to the level of due diligence you apply to customers.
Related reading
AML/CTF Policies and Procedures
Your AML/CTF Program must be documented in writing. It must set out the policies, procedures and controls your business has adopted to identify, mitigate and manage its ML/TF/PF risks. The Program must be approved by your Board or senior management and kept up to date.
Under the AML/CTF Rules 2025, your Program must address each of the nine obligation areas: enrolment, risk assessment, AML/CTF policies and procedures, customer due diligence, ongoing due diligence, transaction monitoring, reporting, record-keeping, and independent review. An obligations register is a practical tool for tracking compliance across each of these areas.
Policies must be tailored to your business - generic or template documents that do not reflect your actual operations will not satisfy the requirements of the Act or withstand regulatory scrutiny.
Customer Due Diligence
Customer due diligence (CDD) is the process by which you identify and verify your customers, understand the nature of your business relationship with them, and assess the ML/TF/PF risk they present. The AML/CTF Act and Rules 2025 set out when CDD must be conducted, what it must cover, and when enhanced CDD (ECDD) is required.
Standard CDD applies to all customers. Enhanced CDD applies where the risk is higher - for example, where a customer is a politically exposed person (PEP), where the transaction is unusual, or where your risk assessment identifies elevated risk. Simplified CDD may apply in limited low-risk circumstances.
CDD is not a one-time event. Ongoing due diligence requires you to monitor your customers throughout the relationship, update their information, and escalate concerns where appropriate.
Transaction Monitoring
Transaction monitoring is the process by which you identify transactions that are unusual, suspicious or inconsistent with what you know about your customer. It is a core obligation under the AML/CTF Act and a critical control in any effective AML/CTF Program.
An effective transaction monitoring program is risk-based. It should be calibrated to the specific risks your business faces, drawing on your risk assessment and your knowledge of your customer base. Rules and parameters must be reviewed regularly to ensure they remain fit for purpose.
Where a transaction monitoring alert is generated, it must be investigated promptly. Where a suspicious matter is identified, a Suspicious Matter Report (SMR) must be submitted to AUSTRAC.
Governance and the AMLCO Role
Every reporting entity must appoint an AML/CTF Compliance Officer (AMLCO). The AMLCO must be a member of senior management with the requisite expertise and experience to fulfil the role. The AMLCO is responsible for overseeing the day-to-day operation of the AML/CTF Program and reporting to the Board or senior management on its effectiveness.
Effective governance requires clear accountability, adequate resources, and a reporting structure that gives the AMLCO the authority to escalate concerns and drive remediation. The Board or senior management must receive regular reports on the Program's performance and any material compliance issues.
Employee due diligence is also a governance obligation - ensuring that the people responsible for implementing your Program are themselves appropriately screened and monitored.
AML/CTF Training
All employees whose roles are relevant to your AML/CTF obligations must receive appropriate training. Training must cover your AML/CTF obligations, the ML/TF/PF risks your business faces, the consequences of non-compliance, and the policies and procedures employees are expected to follow.
Training must be tailored to the role. A front-line gaming staff member needs different training from a compliance manager or a Board director. Training must also be ongoing - not a one-off induction exercise - and completion must be tracked and documented.
Under the AML/CTF Rules 2025, your training program is a formal element of your AML/CTF Program and must be documented accordingly.
Controls Testing
Documenting controls is not enough - you must also test whether they are working. Controls testing assesses both the design effectiveness (whether the control is capable of achieving its objective) and the operating effectiveness (whether it is actually working in practice) of the controls in your AML/CTF Program.
Testing should be risk-based and proportionate. Higher-risk controls warrant more frequent and rigorous testing. Results must be documented and any deficiencies remediated promptly.
Controls testing feeds directly into your independent review and your Board reporting. It is the mechanism by which you demonstrate - to yourself, to your Board, and to AUSTRAC - that your Program is not just a document but a functioning compliance system.
Independent Review
The AML/CTF Act requires reporting entities to arrange for an independent review of their AML/CTF Program at regular intervals. The review must be conducted by a person who is independent of the Program - typically an external consultant or an internal audit function that is independent of the compliance function.
The independent review assesses whether your Program is adequate and effective - whether it identifies and manages your ML/TF/PF risks, whether your controls are working, and whether your policies and procedures are being followed in practice.
The results of the independent review must be reported to the Board or senior management, and any deficiencies must be remediated. The review is also a key input into your next risk assessment cycle.
Reporting and Record-Keeping
Reporting entities have ongoing obligations to report certain transactions and matters to AUSTRAC. These include Threshold Transaction Reports (TTRs) for cash transactions of $10,000 or more, Suspicious Matter Reports (SMRs) where you have reasonable grounds to suspect a matter, and International Funds Transfer Instructions (IFTIs) for certain cross-border transfers.
Record-keeping obligations require you to retain records of your CDD, transactions, and Program documentation for at least seven years. Records must be kept in a form that allows them to be retrieved and provided to AUSTRAC on request.
Timely and accurate reporting is a legal obligation. Failures to report - or late reports - can attract significant civil and criminal penalties.