How to

Writing your first AML/CTF risk assessment

True Comply · · 5 min read

← Back to Insights
A closed spiral-bound notebook on a dark timber desk.

Everything else is downstream of this

The risk assessment is not the first item on a checklist — it is the thing that makes the rest of the program defensible. Your controls are supposed to be proportionate to your risk, which is impossible to demonstrate if you have never written down what your risk is. Firms that draft a program before assessing risk usually end up with controls they cannot justify.

The four things to assess

  • Customer types. Who do you act for? Individuals, private companies, trusts, offshore entities, politically exposed persons, cash-intensive businesses?
  • Products and services. Which designated services do you provide, and how attractive is each to someone laundering money?
  • Delivery channels. Do you meet clients face to face, act remotely, or take work through intermediaries and referrers? Non-face-to-face and intermediated channels generally carry more risk.
  • Jurisdictions. Where are your clients, their funds and their structures connected? Exposure to higher-risk jurisdictions raises the rating.

You also need to take into account relevant AUSTRAC guidance and national risk assessments — your view of your risk should be informed by the regulator's view of the sector's risk.

Inherent risk, then controls, then residual risk

Assess the inherent risk first: how exposed would you be with no controls at all? Then set out the controls you have. Then state the residual risk that remains. That structure is what turns a description into an assessment, and it is what makes the logic visible to anyone reviewing it.

Two ways firms get this wrong

The first is the generic template — a document that could describe any firm in the sector, with no specifics about your clients, your services or your actual exposure. It reads as compliance theatre because that is what it is.

The second is the epic. Forty pages nobody reads, produced once, never updated. Length is not the measure. A focused document that genuinely reflects your business and gets revisited is worth far more than a comprehensive one that is stale within a quarter.

It has to stay current

The assessment needs review when your business changes — a new service line, a new client segment, a new jurisdiction, a significant change in how you deliver — and periodically in any case. Record the review date and what changed, so the document has a visible history rather than a single creation date receding into the past.

True Comply helps firms produce a risk assessment that is specific, proportionate and maintainable, then builds the program on top of it. Start the conversation.

Related insights

Compliance you can prove.

Tell us where you're at and we'll help you work out what applies to your business.

No jargon, no obligation.