Obligations

Customer risk assessment under AML/CTF: how to rate a client low, medium or high and what each rating requires

Rating each client's money laundering and terrorism financing risk is the engine of a risk-based program: it decides how much due diligence you do and how often you look again. This page gives you the factors AUSTRAC expects you to weigh, a scoring approach small firms can apply consistently, and the due diligence and review schedule that follows from each rating.

Updated · Checked against AUSTRAC guidance and the legislation

A blank identification card and a navy passport on an open client folder, with a loupe and a fountain pen.
In short

A customer risk assessment rates each client's money laundering and terrorism financing risk as low, medium or high by weighing four factor groups: the customer (type, beneficial ownership, politically exposed status, behaviour), the service, the delivery channel (met in person or not, third parties) and the countries involved. The rating sets the due diligence (standard or enhanced, with source of funds and senior approval for high risk) and the review interval, commonly 24, 12 and 6 months. The assessment and its reasons must be recorded and revisited when circumstances change.

Key points
  • Four factor groups: customer, service, channel, country. Write down which ones drove the rating.
  • Politically exposed persons, cash, unclear source of funds and third-party involvement are the heaviest factors.
  • High risk means enhanced due diligence: source of funds and wealth, senior manager approval, closer monitoring.
  • Review intervals are yours to set; 24/12/6 months for low/medium/high is common practice.
  • A suspicious matter report makes a customer high risk automatically.
Customer risk rating, due diligence and review frequencyThree rows for low, medium and high risk customers, with the level of due diligence and the review interval for each.RATINGDUE DILIGENCEREVIEWLow

Standard identification and verification

Every 24 months
Medium

Standard CDD plus closer attention to purpose and funds

Every 12 months
High

Enhanced CDD: source of funds and wealth, senior manager approval

Every 6 months
The law sets no fixed interval; these are the intervals most small-firm programs adopt and the ones our compliance tool uses by default.

Why rating matters

The regime is risk-based: it does not ask you to treat every client as a suspect, it asks you to do more where the risk is higher and less where it is lower, and to be able to show why. The customer risk rating is that "why". Without it, enhanced due diligence has no trigger and review schedules have no basis.

The four factor groups

  • Customer: individual, company, trust or partnership; who the beneficial owners are and how hard they are to identify; whether the customer or a close associate is a politically exposed person; how the customer behaves (evasive, hurried, inconsistent).
  • Service: which designated service, and how exposed it is. Company formation, nominee roles and moving money through a trust account rate higher than conveyancing a family home.
  • Delivery channel: met in person with documents sighted, or onboarded remotely; introduced by a third party; instructions coming from someone else.
  • Country: residence, incorporation, source and destination of funds. AUSTRAC and FATF publish lists of higher-risk jurisdictions.

A scoring approach that stays consistent

Small firms get into trouble when ratings depend on who did the onboarding. A simple score fixes that: give each factor a weight, add them up, and set thresholds. The estimator on this page uses weights that work for professional firms: a trust structure 2, a company 1, a higher-risk jurisdiction 2 to 4, a matter over AU$750,000 1 and over AU$2 million 2, a politically exposed person 4, cash 3, remote onboarding 1, third-party involvement 2, unclear source of funds 4, no identity document sighted 2. Scores of 6 or more are high, 3 to 5 medium, under 3 low. Your program can use different weights; what matters is that it has them and applies them.

What each rating requires

  • Low: standard identification and verification, purpose of the relationship recorded, review every 24 months or on a trigger.
  • Medium: standard due diligence with closer attention to the purpose and the funds, review every 12 months.
  • High: enhanced due diligence. Establish source of funds and, where relevant, source of wealth; obtain senior manager approval before providing the service; monitor more closely; review every 6 months. Record each step.

Politically exposed persons

A PEP is someone who holds or has held a prominent public position, in Australia or overseas, plus their immediate family and close associates. Foreign PEPs are high risk by default; domestic and international organisation PEPs are high risk when other factors are present. Screening against a PEP list at onboarding, and asking the question directly, are both accepted methods.

Triggers for re-rating

  • A suspicious matter report about the customer: the rating becomes high.
  • A change in the service, the structure or the people behind it.
  • Funds arriving from an unexpected source or country.
  • Information that contradicts what was collected at onboarding.
  • The scheduled review.

Recording it

Keep the rating, the date, the factors and the reasons with the customer's identification records for seven years after the relationship ends. The annual compliance report asks how many customers were rated high risk; your files should produce that number.

Interactive

Client risk rating estimator

Answer six things about a new client and see the rating, what due diligence it calls for and when to review. Same scoring our compliance tool uses.

Estimated ratinglow riskSimplified due diligence. Review every 24 months.

An estimate to start the conversation inside your firm. Your program sets your own factors and weights; nothing you type here is stored or sent anywhere.

Questions people ask

What is a customer risk assessment in AML?
The process of rating each customer's money laundering and terrorism financing risk, usually low, medium or high, from factors about the customer, the service, the delivery channel and the countries involved, and recording why.
How often should customer risk be reviewed?
The law sets no fixed interval; your program does. Common practice is every 24 months for low risk, 12 for medium and 6 for high, plus whenever something changes.
Is every company or trust high risk?
No. Structure is one factor. A long-established Australian trading company with identifiable owners is often low or medium risk. A trust with layers of entities and an unclear controller is high.
What is enhanced due diligence?
The extra steps for high-risk customers: establishing source of funds and wealth, senior manager approval before acting, closer monitoring and more frequent review.
Do I rate existing clients from before 1 July 2026?
Pre-commencement customers do not need initial due diligence until a trigger, but you should rate them as part of ongoing monitoring so that reviews and any enhanced due diligence have a basis.

Read next

Sources

Official pages this page was checked against. The date is when we captured the page; the publisher may have updated it since.

General information about Australian AML/CTF law, not legal advice. The Act, the Rules and AUSTRAC's guidance are the primary sources; check them before you rely on a date or a figure.

Customer risk assessment and risk rating in AML/CTF · AML/CTF Guide