Skip to content

Your AML risk assessment

This is the section of the program a template cannot write for you, because AUSTRAC does not know your book. Here is what it has to weigh.

The risk assessment is the section of an anti-money laundering and counter-terrorism financing (AML/CTF) program that a template genuinely cannot write for you. Every other part can start from AUSTRAC's wording. This one has to start from your book, because it is the thing that calibrates everything else.

Get it wrong in one direction and you apply heavy checks to every transaction until the process collapses under its own weight. Get it wrong in the other and you have a program that looks fine and catches nothing.

What it has to weigh

Your customers

Who buys and sells through you. Local owner occupiers are a different profile from offshore investors, and both are different from corporate or trust purchasers whose beneficial ownership takes work to establish.

Your services

Which designated services you actually provide. An agency doing residential sales only has a narrower surface than one also handling commercial transactions or development stock. The designated services guide covers what is captured.

How you deliver them

Face to face in a regional office is a different risk from fully remote transactions where nobody ever meets the buyer. Auctions bring their own timing pressure, because the buyer is unknown until the hammer falls.

Where you operate

Your market, and the markets your buyers come from. Jurisdiction risk is real and it is also where assessments most often turn into lazy stereotyping, so it needs to rest on published risk ratings rather than assumption.

Start from the sector assessment

You are not doing this from nothing. AUSTRAC publishes risk insights and indicators of suspicious activity written for real estate specifically, and the sensible approach is to take that as the baseline and then adjust for what is true of your agency.

“Risk insights and indicators of suspicious activity for the real estate sector”
AUSTRAC, Risk insights and indicators of suspicious activity for the real estate sector.

Grading, and what it is for

The output is not a number for its own sake. It is a set of categories that tell your staff what to do differently. Standard due diligence here, enhanced due diligence there, and a defined trigger for escalating to your compliance officer.

If the grading does not change anyone's behaviour, it is decoration. The test of a risk assessment is whether an agent can read the program and know that this particular buyer needs something extra, and what that something is.

Write it honestly

There is a temptation to assess everything as low risk, because low risk means less work. It is a bad trade. A risk assessment is a document you will be asked to justify at the exact moment something has gone wrong, and one that rated an obviously complex transaction type as low will not survive the question.

The opposite failure is rarer but real: rating everything high, applying enhanced due diligence universally, and watching the process get abandoned within a month because it is unworkable. Proportionality is the point.

Turning it into a program

Once the assessment exists, the rest of the program is written against it: the procedures, the escalation triggers, the training and the record keeping. See the AML/CTF program guide and the starter kit.

Common questions

What is an AML risk assessment?

It is the part of your AML/CTF program that works out what money laundering risk your specific business carries, so the rest of the program can be proportionate to it. It considers your customers, the services you provide, how you deliver them and where you operate.

Can we use a risk assessment template?

A template gives you the framework and the prompts, which helps. The conclusions have to be yours, because the whole purpose is to describe your business rather than a generic one. A copied assessment produces a program calibrated to somebody else's risk.

What makes a real estate transaction higher risk?

Common factors include buyers or sellers you cannot easily identify, complex ownership structures such as trusts and layered companies, funds arriving from third parties or offshore, unusual urgency, and transactions where the price or the behaviour does not match the market. None of these is proof of anything on its own.

How often should it be reviewed?

Whenever the business changes in a way that affects risk, such as entering a new market, taking on a new transaction type or seeing a shift in client profile, and periodically regardless. An assessment that never changes stops describing the business.

Does a high risk rating mean we cannot act?

No. A higher rating means more scrutiny, not refusal, and an assessment that led you to decline routine business would be miscalibrated. The point of grading risk is to direct effort where it matters rather than applying identical checks to every transaction, which is both expensive and less effective, because uniform checking finds nothing in particular. A high rating should change what you collect and who signs off, not whether you act.

General information about the obligations, not legal advice about your agency.

Sources

  1. AUSTRAC, Risk insights and indicators of suspicious activity for the real estate sector.
  2. AUSTRAC, Real estate program starter kit: Getting started.
  3. AUSTRAC, Real estate designated services.
  4. AUSTRAC, New reporting regime now in force.