ML/TF Risk Assessment for Australian Law Firms
Australian law firms must complete an ML/TF risk assessment before 1 July 2026. Here is what to assess, document, and how AMLify helps.
An ML/TF risk assessment is a mandatory document for every Australian law firm providing Tranche 2 designated services. Under the AML/CTF Act 2006, your risk assessment must be completed before you can finalise your AML/CTF programme — and now that Tranche 2 has commenced, it is the most urgent step on your compliance checklist.
What Is an ML/TF Risk Assessment?
An ML/TF risk assessment is a structured analysis of the money laundering and terrorism financing risks that arise from your law firm's designated services, client types, geographic exposures, and delivery channels. It is the foundation document for your AML/CTF programme — without it, you cannot design proportionate controls or demonstrate to AUSTRAC that your programme is fit-for-purpose.
Which Law Firms Must Complete a Risk Assessment?
Under the Tranche 2 reforms, Australian law practices that provide any of the following designated services must register with AUSTRAC and maintain a current ML/TF risk assessment:
- Acting as a conveyancer or settlement agent in real property transactions
- Managing client money, securities, or other assets
- Providing company or trust formation services
- Acting as a nominee director, shareholder, or trustee
- Providing business acquisition advisory services that involve handling client funds
For a complete breakdown of which legal services trigger Tranche 2 obligations, see the AMLify lawyers page.
What Risk Factors Must Your Assessment Cover?
AUSTRAC expects law firms to assess ML/TF risk across four standard dimensions:
- Customer risk — Do you act for politically exposed persons (PEPs), high-net-worth individuals, foreign nationals, or clients with complex ownership structures? Each of these profiles carries elevated inherent risk.
- Service risk — Which designated services present the highest ML/TF exposure? Conveyancing, trust formation, and nominee arrangements are consistently identified as high-risk in AUSTRAC typology reports.
- Geographic risk — Do you facilitate transactions involving funds from FATF-listed high-risk or sanctioned jurisdictions? Do any clients reside or hold assets offshore?
- Delivery channel risk — Do you onboard clients and accept instructions entirely remotely, without in-person identity verification? Non-face-to-face delivery channels attract higher inherent risk ratings.
How to Conduct a Risk Assessment: Step by Step
There is no single prescribed template — AUSTRAC requires your assessment to reflect your firm's specific circumstances. A practical five-step process works for most law practices:
- Map your designated services — List every service your firm provides that falls within Tranche 2 scope. Being specific helps — describing services at the transaction level gives a clearer risk picture than broad category labels.
- Identify applicable risk factors — For each service, document the client types, geographic footprint, and delivery channels involved.
- Rate inherent risk — Assign a rating (low, medium, or high) to each service and risk-factor combination before considering your existing controls.
- Assess your existing controls — Document the controls already in place (identity verification, source-of-funds checks, transaction monitoring) and evaluate how effectively they reduce the inherent risk.
- Determine residual risk — After applying your controls, rate the remaining risk level. Higher residual risk requires more robust CDD procedures, enhanced monitoring, and more frequent staff training.
What Should You Document?
Your risk assessment must be capable of withstanding AUSTRAC scrutiny. At a minimum, it should record:
- The methodology used to rate each risk factor
- The data sources relied upon (AUSTRAC typologies, FATF mutual evaluation reports, internal client data)
- Risk ratings assigned and the rationale for each decision
- Any risk categories excluded from scope, and why
- The date of the assessment and the identity of the person who prepared and approved it
- A scheduled review date
How Often Should the Assessment Be Reviewed?
The AML/CTF Act 2006 requires risk assessments to be kept current. AUSTRAC guidance recommends reviewing your assessment at least annually, or sooner if there is a material change to your practice — for example, adding a new designated service, taking on a significant volume of foreign clients, or when AUSTRAC publishes a new typology report relevant to legal practices.
How AMLify Supports Law Firm Risk Assessments
AMLify includes a guided ML/TF risk assessment module purpose-built for Tranche 2 DNFBPs, including law firms. It walks your AML/CTF Compliance Officer through each risk dimension, prompts documentation of ratings and rationale, and stores the completed assessment in an audit-ready format with full version history. Now that Tranche 2 has commenced, completing your risk assessment inside a structured platform is faster and more defensible than building from scratch. See /pricing for plan details.
Key Takeaways
- An ML/TF risk assessment is mandatory for every law firm providing Tranche 2 designated services — without it, you cannot finalise your AML/CTF programme.
- Cover all four risk dimensions: customer, service, geography, and delivery channel — each must be assessed and documented.
- Document your methodology — AUSTRAC inspectors will assess not just your ratings but the reasoning and evidence behind them.
- Review annually or whenever your firm's services, client base, or geographic exposure changes materially.
- Get compliant now — completing your risk assessment now is the single most important compliance action your firm can take.
Frequently Asked Questions
Q: Is the ML/TF risk assessment the same as the AML/CTF programme?
No. The risk assessment and the AML/CTF programme are distinct documents. The risk assessment identifies and rates your firm's ML/TF risks — it is the analytical input. The AML/CTF programme is the compliance framework built on those findings — it is the operational output. You cannot design a proportionate programme without completing the risk assessment first.
Q: Does every partner need to be involved in the risk assessment process?
Not necessarily. The assessment must be approved at a senior level — typically the principal or managing partner — but the day-to-day preparation is usually led by the firm's AML/CTF Compliance Officer (AMLCO). The AMLCO may consult practice group leaders to understand service scope and client risk profiles. The key requirement is documented senior sign-off, not individual partner involvement in every step.
Q: What happens if our risk assessment is incomplete when AUSTRAC begins compliance reviews?
A missing or inadequate risk assessment is one of the most common compliance failures identified in AUSTRAC reviews of reporting entities. Civil penalties under the AML/CTF Act 2006 can reach millions of dollars for serious or systemic non-compliance. Completing a defensible risk assessment now is far less costly than remediation following an enforcement action.
Q: Can we use a template from a legal industry body as our risk assessment?
A template from a legal industry body is a useful structural guide, but AUSTRAC expects the final document to reflect your firm's specific risks. A generic template that has not been tailored to your services, client types, and geographic exposures is unlikely to satisfy AUSTRAC on its own. Use templates to structure your approach, then populate them with firm-specific analysis.
This is general information only and not a substitute for legal advice.