Articles
0
MIN READ

Client and matter risk assessments and what AUSTRAC needs you to prove on every file

Share

Author

Joshua Krosendijk
Joshua Krosendijk
,
Senior Account Executive

Table of Contents

Find out how we can help you onboard clients faster
Book a demo

Since 1 July, due diligence has become part of delivering designated legal services. Is the client sanctioned or politically exposed? Are they connected to a high-risk country? Who ultimately owns and controls the entity? What is the expected source and movement of funds?

The risk assessment takes what you know about the client, adds what they have asked your firm to do and applies your firm's risk methodology. The result should be more than a rating. It should leave a clear record of the factors considered, the judgement applied and the action that followed.

The AML/CTF Act defines ML/TF risk as the risks a reporting entity may reasonably face when providing designated services to a customer. In practical terms, risk must be understood in the context of both the client and the service.

A client risk assessment considers who you are dealing with. A matter risk assessment considers what you are being asked to do. The two overlap, but they are not interchangeable. The same client may present one level of risk when purchasing a home and another when instructing your firm to establish a trust with an overseas beneficial owner.

We covered the entity-level assessment in Building a defensible ML/TF risk assessment. This article looks at how that framework reaches the individual client and matter.

What the firm-wide assessment feeds

Section 28(4) requires a firm to consider five things when identifying a client's ML/TF risk:

  • its firm-wide ML/TF risk assessment;
  • the type of client;
  • the designated services being provided or proposed;
  • the delivery channels used; and
  • the countries involved.

At file level, two of these are particularly important.

The firm's own assessment should inform the questions fee-earners are asked, the weight given to different factors and the circumstances requiring escalation. A document that never reaches the file-level process cannot perform that role.

The designated service is also critical. Acting on a house purchase, setting up or restructuring a company or trust, and holding or disbursing client money are designated services. Acting in a dispute generally is not.

One client may instruct your firm on several of these matters over time. Knowing the client does not remove the need to assess the work.

AUSTRAC's legal profession starter kit follows the same logic. It provides one risk assessment for conveyancing and another for other professional services, recognising that different service lines expose a firm to different risks.

What you establish before you act

Initial due diligence must happen before the firm starts providing a designated service.

Section 28(2) requires you to establish, on reasonable grounds, who the client is, who they are acting for and who is acting for them. Where the client is not an individual, that includes identifying its beneficial owners. You must also establish whether anyone in the relevant chain is a politically exposed person or designated for targeted financial sanctions.

You also need to understand the nature and purpose of the relationship or transaction: why is this client instructing us, on this matter, now? Recording the answer gives the firm a baseline against which later changes can be identified and assessed.

What the rating decides

You identify the risk using the information reasonably available before providing the service. You then collect and verify information to a depth that matches that risk. Where risk is low and no enhanced trigger applies, simplified due diligence may be available. Where risk is high, enhanced due diligence is mandatory.

The Law Society of New South Wales provides usable arithmetic in its free template: one high-risk factor produces a high rating, two medium factors produce a medium rating and everything else is low.

That methodology is defensible, but it cannot set your firm's risk appetite. Your governing body must decide what is high risk, when approval is required and what work the firm will not accept.

Nor can a template tell you whether the results across your client book are credible. If almost every assessment returns a low or medium rating, the firm should be able to explain why. The team at Holley Nethercote has warned that blanket low or medium ratings are unlikely to satisfy the statutory obligation.

Across the 600+ law firms we work with, the strongest programs reflect the firm's actual work and use language that fee-earners understand. Irrelevant or overly generic questions encourage people to treat an assessment as a tick-box exercise.

One client, two different risk outcomes

Consider a long-standing Australian company your firm has advised on a straightforward commercial matter. Its ownership is transparent, its directors are known and the initial client assessment returns a low rating.

Six months later, the company asks the firm to establish a trust. The proposed structure includes an overseas beneficial owner, funds will arrive from a higher-risk jurisdiction and a third party appears to be directing parts of the transaction.

The client's name has not changed, but several risk inputs have. The firm is providing a different designated service. The ownership and control questions are more complex. New countries and an unexpected third party are involved.

The new matter should trigger a fresh assessment. The file should show what changed, how it affected the rating, whether enhanced due diligence or approval was required and who decided. Reusing the original low-risk result would miss the risk in the new instructions.

A new matter can be a new risk question

Firm-wide assessments operate on a review cycle. Client risk must move with the relationship.

Section 30 requires a firm with an ongoing business relationship to review and update the client's rating when relevant risk inputs change. One of those inputs is the kind of designated service being provided. AUSTRAC similarly identifies a client seeking a new, higher-risk designated service as a trigger for review.

Not every new matter will change the client's rating. It should prompt the firm to consider whether the service, parties, structure, delivery method or countries introduce a new risk.

The firm needs one client record that develops with the relationship, showing how the risk changed, what prompted each review and what was known at each decision point.

What you have to be able to prove

Program-level records demonstrate governance and approval. Separate record-keeping obligations apply to individual clients.

Section 111(3) requires firms to keep the data gathered about a client and records of any analysis, identification or assessment of ML/TF risk or related decision-making.

That means the reasoning matters. Why was this client rated low? Which factor moved another client to high? Was the result overridden? Who approved it, and when? AUSTRAC also includes decisions and rationale among the due diligence records a firm should keep.

State regulators are also paying attention. The Victorian Legal Services Board and Commissioner has said it will take wilful or knowing disregard of risk indicators and red flags very seriously.

What good looks like in practice

AUSTRAC and the law societies provide useful material. The harder part is applying the program consistently across every fee-earner, matter and reassessment.

A defensible file-level process should:

  • apply the firm's methodology consistently;
  • capture risks specific to both the client and the matter;
  • preserve the rating, evidence and rationale together;
  • escalate high-risk results and document approvals or overrides; and
  • prompt reassessment when circumstances change or a review becomes due.

Doing this once is straightforward. Doing it consistently across hundreds or thousands of matters, while keeping the reasoning clear years later, is a systems problem.

How Legl handles client and matter risk assessments

Legl gives firms a consistent workflow for client assessments, matter assessments or a combined client and matter assessment. Matter assessments carry their own reference and can link to multiple contacts, including two people purchasing a property together.

  • Consistent decisions. Firms configure templates around their own policy, language and service lines. Conditional questions and weighted answer options help fee-earners apply the same methodology, while information Legl already holds can populate relevant answers and remains clearly marked as auto-completed.
  • Controlled escalation. A high rating can automatically alert the AMLCO and enter an approval workflow. The person completing the assessment cannot approve their own escalation, and any override requires a recorded rationale.
  • A defensible audit history. Each action is time- and user-stamped. Updates create new versions without losing the earlier rating or reasoning, giving the firm a living client record rather than disconnected forms. Individual versions can be downloaded for an auditor.
  • Timely reassessment. Firms can set review periods by risk level. Legl calculates the next review date, reminds the owner before it is due and flags overdue assessments, helping the AMLCO see where attention is required.

Key takeaways

  • Client and matter assessments answer related but different risk questions.
  • Your firm-wide assessment is an input to individual ratings, not a substitute for them.
  • The rating determines the level of due diligence and escalation that follows.
  • A new designated service may require the client's risk to be reviewed and updated.
  • The file must preserve the analysis and decision-making behind the rating, not only the result.

Ready to see how this works on a real file? Book a demo with our team.

Sources