When businesses complete their AML/CTF Risk Assessment, one of the first areas they need to consider is the products and services they provide.
But simply listing your designated services isn’t enough.
The more important question is:
How could the services we provide potentially be misused for money laundering, terrorism financing or proliferation financing?
This is where an AML/CTF Risk Assessment becomes more than a compliance document. It becomes a practical tool for understanding where your business may be vulnerable and what controls you need to put in place.
Start With Your Designated Services
AUSTRAC requires reporting entities to identify and assess the money laundering, terrorism financing and proliferation financing risks they may reasonably face when providing designated services.
Your assessment needs to consider the kinds of designated services you provide, including relevant new and emerging technologies.
Importantly, it should also consider designated services you plan to provide, particularly where the proposed service could increase your ML/TF risk.
The starting point is therefore relatively simple:
What designated services do we provide, and how could someone misuse them?
The Risk Will Be Different for Every Business
There isn’t one standard products and services risk that applies across every industry.
The vulnerabilities associated with a registered club can differ greatly from those associated with real estate, bullion, or professional services.
Registered Clubs
A club might consider risks associated with areas such as:
- gaming-related transactions
- cash handling
- payouts and movement of funds
- high-value transactions
- transactions that appear inconsistent with normal gaming behaviour
- services or processes that could allow someone to disguise the source of funds.
The question isn’t simply whether the club provides gaming services.
The club should consider how those services could potentially be exploited.
Real Estate
Real estate presents a different risk profile.
AUSTRAC identifies real estate as an asset type that can be exploited to integrate illegal funds into the legitimate economy and store the proceeds of crime.
A real estate business may therefore need to consider risks associated with the nature of the transaction, movement of significant amounts of money, ownership structures and circumstances where the true source of funds or wealth may be difficult to establish.
Bullion and Precious Metals
Again, the risk is different.
AUSTRAC identifies the ability to convert illicit cash into stable, high-value assets as a potential vulnerability associated with buying and selling bullion. Those assets can potentially be transported, transferred or resold.
This means a bullion dealer needs to understand the characteristics of their products and transactions that could make them attractive to someone attempting to disguise or move criminal proceeds.
Professional Services
Accountants, lawyers, conveyancers, and other professional service providers may face risks when their services involve establishing or managing structures, handling or controlling assets, assisting with transactions, or other designated services.
Some legal structures and arrangements can potentially be used to obscure ownership or disguise the source of funds or wealth.
The key point is that your risk assessment must reflect what your business does.
Look Beyond the Name of the Service
When assessing a product or service, consider its characteristics.
For example:
Does it involve high-value transactions?
Does it involve significant amounts of cash?
Can value be moved or transferred quickly?
Could ownership or the source of funds be difficult to establish?
Could a customer use a company, trust or other structure to make ownership less transparent?
Could the service allow someone to convert cash into another asset?
Are new technologies changing how the service operates?
AUSTRAC specifically identifies high-value transactions and structures or arrangements that can assist customers to remain anonymous or disguise the source of wealth or funds as important considerations when identifying ML/TF risks.
Risk Should Drive Your Controls
Once you’ve identified how a service could potentially be misused, you can determine what controls are appropriate.
For example, the identified risk might lead your business to introduce or strengthen:
- Customer Due Diligence
- Transaction Monitoring
- Source of Funds/Wealth Enquiries
- Enhanced Customer Due Diligence
- Staff Training
- Management Review
- Suspicious Matter Reporting
Not every service requires the same level of control.
That’s the purpose of the risk-based approach.
AUSTRAC’s current regulatory expectations emphasise understanding the risks facing your business, documenting those risks and putting appropriate controls in place. AUSTRAC does not expect businesses to apply the same controls to every customer regardless of risk.
What Happens When You Introduce Something New?
Your AML/CTF Risk Assessment shouldn’t be something you prepare once and then forget about.
Before introducing a new designated service, ask:
Could this change our ML/TF risk?
AUSTRAC’s guidance states that risk assessments must cover both designated services currently provided and those the business plans to provide. Planned designated services that could increase ML/TF risk must also be assessed.
The same thinking should apply when you materially change how an existing service operates.
For example, you might introduce:
- a new transaction method
- a new technology
- a different payment process
- a new type of customer
- a new way of delivering the service
- operations involving another country or jurisdiction.
These changes may alter your risk profile.
A good internal process is therefore:
- Proposed Change
- Assess AML/CTF Risk
- Identify Required Controls
- Update Risk Assessment/Program
- Train Relevant Workers
- Implement
- Monitor
This is much stronger than introducing the change first and considering AML/CTF risk afterwards.
A Practical Example
Imagine a business has assessed one of its designated services as Medium Risk.
The business then changes how the service operates and customers can undertake larger transactions using a new delivery method.
Rather than assuming the previous Medium Risk rating still applies, the business should ask:
- Has the likelihood of misuse changed?
- Has the potential consequence changed?
- Are our existing controls still appropriate?
- Do we need additional customer due diligence?
- Does transaction monitoring need to change?
- Do staff need additional training?
The outcome might still be Medium Risk.
Or it might increase.
The important thing is that the business has considered the change and documented its decision.
Keep It Practical
For small and medium businesses, your products and services assessment doesn’t need to become unnecessarily complicated.
For each designated service, document:
- Service
- How could it be misused?
- Risk level
- Existing controls
- Additional controls required
- Residual risk
This provides management and the AML/CTF Compliance Officer with a clear picture of why controls exist.
Most importantly, it connects your risk assessment to what happens within the business.
The Key Message
Don’t just ask:
“What designated services do we provide?”
Ask:
“How could someone misuse the services we provide?”
Once you understand that, it becomes much easier to determine the controls your business needs.
When you introduce a new designated service or significantly change an existing one, assess the risk before implementation rather than waiting until the next annual review.
Understand the risk attached to the service before deciding what controls you need.
References
AUSTRAC, Step 2: Identify and assess your risks — guidance on identifying and assessing ML/TF risks, including designated services, customers, delivery channels and countries.
AUSTRAC, Update to regulator statement of expectations – May 2026 — current expectations regarding the risk-based approach and documenting risks and controls.
AUSTRAC, Money laundering update 2026 — current intelligence regarding money-laundering methods and risks affecting designated services.
#CHDPartners #CIRT #RTO #WHS #WorkHealthAndSafety #Training #RiskManagement #SecurityAndSafetyCompliance #SME #SmallBusiness #MichaelHuggett #AUSTRAC #AMLCTFAnnualComplianceReports #AMLCTFCompliance #AMLCTF #AntiMoneyLaundering