Articles
0
MIN READ

Building a defensible ML/TF risk assessment: a framework for mid-sized Australian law firms

Share

Author

Robbie Goldberg
Robbie Goldberg
,
Country Director, Australia at Legl

Table of Contents

Find out how we can help you onboard clients faster
Book a demo

Three months after Tranche 2 of Australia's anti-money laundering and counter-terrorism financing (AML/CTF) regime commenced on 1 July 2026, most law firms have done the visible part: they have enrolled with AUSTRAC, appointed an AML/CTF compliance officer, and drafted a programme. Fewer have stress-tested the document that everything else is meant to sit on top of, the money laundering, terrorism financing and proliferation financing (ML/TF/PF) risk assessment.

That gap matters more than it looks. Under the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth), which took effect for existing reporting entities from 31 March 2026, reporting entities carry an express obligation to carry out an ML/TF/PF risk assessment with steps "appropriate to the nature, size and complexity" of the business. Earlier iterations of the regime left that requirement largely implicit. For a 40-partner conveyancing and commercial practice, the assessment is also what regulators, insurers and auditors will read first if something goes wrong.

What the amended Act actually requires

The 2024 Amendment Act broadened the scope of the risk assessment in a way many firms have not yet reflected in their documents. Assessments must now address proliferation financing alongside money laundering and terrorism financing, and they must be up to date before the firm provides a designated service to a customer. That is not an annual review as a matter of housekeeping. It means current at the point of engagement. AUSTRAC's own guidance on developing an AML/CTF programme, part of its phased reform materials released through 2025 and 2026, treats the risk assessment as the foundation the rest of the programme is built on, rather than a standalone compliance artefact.

The building blocks of a defensible assessment

A risk assessment that will hold up to scrutiny needs to work through five categories methodically rather than describe the firm's risk profile in general terms. It should cover the types of designated services the firm provides and any use of new or emerging technology in delivering them; the categories of customers it acts for, including politically exposed persons and higher-risk entity structures; the channels used to deliver services, including remote and non-face-to-face engagement; the countries the firm and its clients operate in or send funds to or from; and any specific ML/TF/PF risks AUSTRAC has communicated to reporting entities, whether through sector guidance or its published regulatory priorities.

A document that skips straight to "our risk is low because we act mainly for local clients" without working through each category is unlikely to survive an independent evaluation.

Where mid-sized firms tend to go wrong

Three recurring problems show up in risk assessments built under time pressure.

Genericism. A template drafted for a large corporate practice, lightly edited, that does not actually describe how the firm's own conveyancing, trust account or family law work could be exploited.

A disconnect between assessment and controls. The assessment identifies a risk (say, cash-intensive property settlements) but the programme's customer due diligence procedures do not visibly respond to it.

Governance. The AML/CTF Rules require senior management to approve the risk assessment and each update, and for updates to be notified in writing to the governing body as soon as practicable. A partnership or board that has not seen the document is a gap an AUSTRAC review will find quickly.

Keeping the assessment alive

A risk assessment is not a one-off filing exercise. Firms must review it at least every three years, and sooner if there is a significant change to any of the factors it assesses or AUSTRAC issues new information about relevant risks. Building a light-touch trigger, such as a standing agenda item at partnership or risk committee meetings, is a more realistic way to meet this than waiting for the three-year clock to run down. Firms managing intake, verification and file records on a single platform, such as Legl's, tend to find this easier, because changes in client mix or service lines surface in the data rather than requiring a manual audit.

Key takeaways

  • Cover proliferation financing. Update your risk assessment so it addresses PF, not just money laundering and terrorism financing.
  • Work through five categories. Service types, customer categories, delivery channels, countries and AUSTRAC's own guidance, as distinct sections rather than a single narrative paragraph.
  • Trace risk to control. Draw a direct line from each identified risk to a specific control in your AML/CTF programme.
  • Get it approved and recorded. Senior management approves the assessment and every update, the governing body is notified in writing, and the firm keeps the record of both.
  • Set a review trigger tied to material change, not just a three-year calendar reminder.

Looking ahead

AUSTRAC has said it expects Tranche 2 entities to have a complete AML/CTF framework in place by 30 June 2027, with the first annual compliance reports due between 1 July and 30 September 2027. Independent evaluations, required at least every three years, will be the mechanism that tests whether firms' risk assessments were more than paperwork. Firms that treat the current quiet period as an opportunity to pressure-test their assessment against real client files, rather than waiting for a review to force the issue, will be in a materially stronger position when that evaluation comes.

Sources