Completing the Firm Risk Assessment
Introduction
After completing the initial Compliance Centre setup, the Firm risk assessment helps you identify and understand your firm’s vulnerabilities to money laundering and terrorism financing (ML/TF). Completing it is a crucial step in identifying and mitigating the ML/TF risks relevant to your business, and in establishing (and maintaining) an effective AML/CTF compliance program within the Compliance Centre.Evaluating and auditing firm risk assessments are core duties for compliance officers. This guide also demonstrates how to review internal risk factors, check customer classifications, and access the compliance audit log.
Summary
This guide provides a comprehensive walkthrough on how to complete and review the Firm risk assessment within the AML/CTF Compliance Centre. It covers the end-to-end process from initiating the assessment to reviewing the generated report/policy, ensuring your firm’s ML/TF risk profile is accurately documented, producing a report that serves as a foundation for your internal policies. By following these steps, compliance managers can successfully document and adjust their firm's overall risk appetite, service delivery methods, and client exposure profiles, ensuring alignment with regulatory standards.
Understanding Where the Risk Assessment Content Comes From
The Firm Risk Assessment module is built using content derived directly from the official AUSTRAC starter kit. This helps ensure the included risk descriptions, vulnerabilities, questions, and suggested actionable steps align with regulatory guidance.
The starter-kit material has been digitalised into an interactive format within the Compliance Centre so firms across different sectors can complete the assessment directly in the platform.
In addition to informational content, the tool incorporates the specific questions and steps that a firm needs to complete. Following these steps is essential to produce a finalised and valid risk assessment document.
When to Use This
Use this guide when you are setting up the Compliance Centre for the first time, conducting your firm’s initial risk assessment, or updating your assessment to reflect changes in your business operations, client base, service delivery methods, or countries.
Only users assigned as the Compliance Officer can access and complete the Firm risk assessment.
What You’ll Complete (Assessment Sections)
As you move through the guided workflow (a multi-part questionnaire), you’ll be prompted to complete each section of the assessment. These sections appear in the left-hand menu/progress tracker:
- Sector information (including confirming designated services)
- Client types (for example, individuals/sole traders or bodies corporate)
- Delivery channels (for example, in person or email)
- Designated service risk factors
- Client risk factors
- Delivery channel risk factors
- Country (geographic risk)
You must complete each section to finish and generate the final report. Save your progress at each stage by clicking Next to proceed to the next section.
Step-by-Step Instructions
1) Start the assessment and confirm your sector/designated services
- Access the Assessment: From the Compliance Centre dashboard, navigate to the Firm risk assessment tab.
- Click Start risk assessment to begin a new assessment, select Upload your own if you’re uploading an existing document, or click the drop-down menu next to the sector selection and choose Update risk assessment. If starting for the first time, review the on-screen wizard which guides you through identifying vulnerabilities and selecting your business sector (for example, Legal Services).
- Sector information / designated services:
- You will be taken to the Sector information screen.
- Use the progress indicator on the left to track completion.
- Review the list of designated services. Depending on your sector (for example, Conveyancing), the relevant service may be pre-selected.
- In the Select designated service section, select all designated services your firm provides (for example, receiving, holding, controlling or managing a person's money, or providing a registered office address), then click Next.
2) Select client types
- Select Client Types: Choose all the client types your firm deals with.
- You will see a list of different client structures (for example, individuals and sole traders, bodies corporate, partnerships, trusts, or associations, or government bodies). Each client type includes a brief description to help you classify them correctly.
- This screen may be labelled Who are your clients?
- Select all client types that your firm has engaged with over the past year (as a rule of thumb, review your client history to ensure accuracy).
3) Select delivery channels
- Select Delivery Channels: Indicate how your firm interacts with clients.
- On the Delivery channels screen, you will be asked: “Which of the following ways do your clients interact with you?”
- Review the available channels (for example: In person, Email, Telephone, Video conferencing programs, and Online platforms).
- Use the on-screen descriptions to confirm what each option covers (for example, Telephone can include calls and text messages).
- Select all delivery channels your firm uses, then click Next.
4) Review and respond to risk factors
- Review Designated Service Risks:
- For each risk factor (such as high-value transactions, physical currency limits, virtual assets, politically exposed persons, effective anonymity, or clients with significant unexplained wealth), you will see a title, a description, and an inherent risk rating (for example: Medium or High).
- Select Yes if your firm accepts the risk, or No if your firm does not accept the risk.
- If you select No, a text box will appear prompting you to input a detailed explanation detailing how your firm will mitigate that specific risk. For each risk your firm does not accept, select No and enter a detailed mitigation plan.
- Click Next once completed.
- Review Client Risk Factors: Evaluate the listed client risks (such as Politically Exposed Persons or high-risk legal structures) and select Yes or No for each.
- If you select No, you must enter details on how you will mitigate this risk in the provided text box. If you select No, input your avoidance or mitigation strategies where necessary.
- Click Next once completed.
- Review Delivery Channel Risks: Assess risks related to how services are delivered (such as suspected identity risks).
- Select Yes or No and input your avoidance or mitigation strategies where necessary.
- Click Next once completed.
5) Configure countries (country-specific risk)
In the Country section, use the dropdown to search and select all countries your practice deals with when providing designated services. Managing your country risk profile allows you to accurately reflect global operations, highlight high-risk jurisdictions, and document customized mitigation strategies to satisfy audit requirements.
- Configure Countries: Review the countries your practice deals with. Australia is selected by default.
- This is typically the last data-entry step before the final report is generated.
- Click + Add country to include other countries.
- The system assigns a country risk rating (for example Low, Medium, or High) based on international indices.
- To remove a country, click the green X icon next to its risk indicatorrisk rating.
- If you include high-risk countries or do not accept the risk for a specific country, outline your mitigation strategy in the text box provided below the country list, detailing the specific policies, procedures, and controls your firm utilizes to mitigate risks associated with non-local jurisdictions.
6) Finalise and review the generated report/policy
- Finalise: After completing all sections, click Finish to save your assessment and generate the output.
Your assessment is saved in the platform. You can return to the Firm risk assessment tab at any time to review it or run through the workflow again to update it (for example, if your services, client types, delivery methods, or country exposure changes).
- Review the generated report/policy: After you click Finish, the system generates a final report (sometimes referred to as a risk policy) summarising your firm’s risk profile.
This report details your key vulnerabilities and inherent risk factors, including your designated services and the key risk factors identified. You can scroll through the generated assessment and expand sections like Inherent Risk Factors, client types, and delivery channels to review the custom-configured risk ratings and mitigation plans.
Reviewing, Saving, Auditing, and Updating the Final Report
Review your designated services and vulnerabilities (overview)
When you open the Firm risk assessment area, the page will display your firm’s designated services and the vulnerabilities associated with each service (for example, vulnerabilities relevant to conveyancing or emerging technologies).
This overview helps you understand where your main compliance vulnerabilities sit before you update the assessment.
Save a copy
You can use your browser’s print function (often Ctrl+P or Cmd+P) to save the report as a PDF for your records.
View the audit trail
The Firm Risk Assessment module provides an active ledger of a business's vulnerability profile. Accessing the associated audit log guarantees complete transparency by showing who modified risk settings and when those changes occurred.
To see a history of changes made to the assessment:
- Click the three-dot menu at the top right.
- Select Audit trail from the drop-down menu to open the Audit Log - Risk assessment window.
- Review the system-generated log entries to inspect historical modifications and updates made to the assessment document over time.
This generates a PDF log showing dates, times, and the names of users who initiated, updated, or completed the assessment.
Update the assessment later
If your business operations change or you need to conduct a periodic review:
- Click the actions dropdown button (three vertical dots or setting icon) in the upper right of the risk assessment panel (or the drop-down menu next to the sector selection).
- Select from Update risk assessment, Upload new risk assessment or Restart risk assessment.
Update risk assessment = this will display the saved answers from when the assessment was last created. Click Next to be taken to the section that needs updating, make the change, and then click Finish once all the changes have been made.
Upload new risk assessment = this allows you to upload your own risk assessment and replace any existing uploaded or created assessment.
Restart risk assessment = this restarts the guided process from the beginning so you can make changes and generate an updated report.
Common Questions
Who can complete the Firm Risk Assessment? Only users designated as the Compliance Officer can access and complete the assessment.
What is a designated service? A designated service is a specific activity your business performs that is covered by AML/CTF legislation (for example, acting on behalf of a person in a real estate transaction).
What if my service isn’t listed? The services listed are based on your industry sector. If you believe a service is missing, contact support for clarification.
What does it mean to “accept” a risk? Accepting a risk means you acknowledge it exists within your operations and will manage it as part of your AML/CTF program. It does not mean you are ignoring it.
Is it bad to have high-risk factors? No. The goal of the assessment is awareness. Identifying a high risk allows you to be vigilant and apply the appropriate controls. Many businesses will have high-risk factors as part of their normal operations.
What happens if I select “No” for a risk factor? If you select No, the system requires you to input a detailed explanation detailing how your firm will mitigate that specific risk.
Where do the risk descriptions and questions come from? The content in the Firm Risk Assessment module is derived from the official AUSTRAC starter kit and has been digitalised for completion within the Compliance Centre.
What does “Online platforms” include? This includes your website, payment platforms, or any other third-party applications you use to engage with or provide services to clients.
Are some delivery channels riskier than others? Yes. Non-face-to-face channels (like email, video conferencing, or online platforms) can sometimes present a higher risk of fraud or identity-related issues compared to in-person interactions. The assessment takes this into account.
How are the country risk ratings determined? Country risk ratings are based on established anti-money laundering indices and assessments from regulatory bodies such as the Basel Institute on Governance and AUSTRAC.
What if I only do business in Australia? Leave Australia as the only country listed and proceed by clicking Finish.
Can I change the sector or designated service? The designated service is typically set during the initial Compliance Centre setup. In this assessment, it is displayed for confirmation.
How do I finish the assessment? After completing all sections (including the Country selection), click Finish to save your assessment and generate the report/policy.
How often should I update the risk assessment? Review and update your risk assessment whenever there are significant changes to your business (for example, new services, new client types, new delivery channels, or new countries) and on a regular periodic basis (for example, annually).
Can I reset the Firm risk assessment? To reset the Firm risk assessment, open the completed report, click the three dots (top right), and select Restart risk assessment. This will remove the completed assessment and the Compliance Officer will need to complete it again.
What does the “Last updated” date mean? This date, shown at the top of the report, indicates the last time the assessment was completed and a new report was generated.
Troubleshooting Tips
Cannot access the assessment / can’t see the “Start” button You may not have Compliance Officer permissions. Contact your system administrator to get the correct access level.
“Next” button is disabled or not working Ensure you have made a selection for all required fields on the current screen.
- On the Sector information / designated services screen, you must select at least one designated service.
- For risk factor screens, ensure you have entered text if you selected Yes.
Cannot find a specific country When adding a country, type the name in the search box to filter the list. If it does not appear, check the spelling. If it’s still missing, contact support.
Uncertain about a client’s structure If you are unsure how to classify a client, refer to their formation documents or seek legal advice. The descriptions provided in the assessment can also offer guidance.
My specific software isn’t listed The categories are broad. For example, if you use a specific video call software like Zoom or Microsoft Teams, select Video conferencing programs.
The risk rating seems incorrect for my business The inherent risk ratings are based on general industry and regulatory guidance. The key compliance activity is documenting how your firm manages the risk (including any controls and processes you have in place).
Audit trail is not opening Ensure your browser allows pop-ups and that you have a PDF viewer installed. The audit trail opens as a PDF in a new tab or window.
Unsure about a risk factor Each risk factor includes a description to help you decide. If you’re still unsure, consult internal stakeholders and/or legal or compliance experts. The assessment is about identifying and managing risk, not eliminating it entirely.
