ML/TF Risk Assessments for Precious Metals Dealers

AUSTRAC expects precious metals and stones dealers to document ML/TF risk under Tranche 2. Here is what a defensible assessment must cover.
Dealers in precious metals and stones must maintain a documented money laundering and terrorism financing (ML/TF) risk assessment under the AML/CTF Act 2006 — a written analysis of customer, service, delivery channel, and jurisdiction risk that AUSTRAC can review under your Tranche 2 obligations. Since the deadline passed on 1 July 2026, this is a live obligation, not preparatory paperwork.
Why does AUSTRAC treat this sector as high-risk?
Precious metals and stones are portable, easily converted to cash, and hold value across borders — features that make the sector attractive for layering illicit funds. AUSTRAC's guidance flags cash-intensive transactions, high-value single sales, and international supplier or buyer networks as risk drivers your assessment must address directly.
What must the risk assessment cover?
- Customer risk — cash buyers, repeat sellers, and customers unwilling to explain the source of high-value items
- Service risk — buying, selling, and valuing precious metals or stones, including bullion or scrap trading
- Delivery channel risk — in-person counter sales versus online or remote transactions
- Jurisdiction risk — suppliers or buyers connected to FATF grey- or black-listed countries
How should the assessment be documented?
- Rate each risk category — low, medium, or high — with a written reason for the rating
- Apply your existing controls to work out a residual risk level, not just an inherent one
- Date and sign off the document at senior-management level
- Version-control it so AUSTRAC can see when it was last updated and by whom
When does the assessment need to be reviewed?
The AML/CTF Act 2006 sets no fixed review date, but AUSTRAC expects a fresh look whenever your business changes materially — a new supplier, a shift to online sales, or a suspicious matter report that reveals a gap. Otherwise, an annual review is sound practice. AMLify's compliance module for precious metals dealers keeps risk ratings, CDD files, and review dates in one place.
Key Takeaways
- A written ML/TF risk assessment is mandatory, not optional, for every precious metals and stones dealer under the AML/CTF Act 2006
- Cover four dimensions — customer, service, delivery channel, and jurisdiction — with reasoning behind every rating
- Residual risk matters more than inherent risk — show how your controls actually reduce exposure
- Review triggers include new suppliers, new sales channels, and SMRs — do not wait for an annual date if something material changes
- Sign-off and version control turn a document into evidence AUSTRAC can rely on
Frequently Asked Questions
Q: Do small precious metals dealers need a full risk assessment?
Yes. The AML/CTF Act 2006 sets no size threshold — every reporting entity providing a designated service must have a documented, proportionate risk assessment. A smaller dealer's assessment can be shorter than a large bullion trader's, but it still needs the same four risk dimensions with genuine reasoning.
Q: What is the difference between inherent risk and residual risk?
Inherent risk is how risky a customer, service, or channel would be with no controls at all. Residual risk is what is left after your CDD, monitoring, and reporting controls are applied. A residual rating that never differs from the inherent one suggests your controls are not genuinely reducing risk.
Q: Can we use a template from an industry association?
A template is a reasonable starting point, but it must be adapted to your customer base, products, and supplier relationships, then dated and signed off by someone accountable in your business. An unmodified generic template does not satisfy the obligation on its own.
Q: What happens if our risk assessment is missing or out of date at review?
AUSTRAC treats a missing or stale risk assessment as a sign your AML/CTF programme is not operating as required, which can lead to remediation directions, infringement notices, or civil penalty action for serious failures. Keeping it current is far cheaper than fixing it under scrutiny.
This is general information only and not a substitute for legal advice.