Compliance6 min read

How to Rate a Client's Risk: The Step Most Firms Skip

Most Tranche 2 firms nail the business risk assessment and skip the other one: rating each client low, medium or high. It is a separate AUSTRAC obligation, and it decides whether you can use simplified CDD or must do enhanced. Here is the method AUSTRAC expects, the four factor categories, the low/medium/high examples, and a worked conveyancer example.

2026-07-26· AML Mate Team
How to Rate a Client's Risk: The Step Most Firms Skip

There are two risk jobs in your AML/CTF program, and firms reliably do the first and skip the second.

The first is the business ML/TF risk assessment: the broad, one-off (then reviewed) look at the risks your whole practice faces. That one gets attention because it is a named deliverable. The second is quieter and per-client: assigning each customer a risk rating, low, medium or high, as you onboard them. AUSTRAC is explicit that these are different jobs. The business assessment "involves identifying broad risks across a business"; the customer rating "involves determining customer risk on a case-by-case basis." (AUSTRAC, assigning customer risk ratings)

The second one is the one that goes missing. A client file with a rating that was never really worked out, or left blank, is the gap an examiner finds fastest, because the rating is supposed to drive everything that follows.

Why the rating decides the rest of CDD

The customer's rating is not a label you file and forget. It determines, in AUSTRAC's words, "the subsequent KYC information you collect and/or verify" and "the monitoring process." Concretely:

  • Low risk lets you apply simplified CDD.
  • High risk means you must apply enhanced CDD: more information, source of funds and wealth, senior sign-off.

So the rating is the switch between a light-touch onboarding and a heavy one. Get it wrong on the low side and you have under-done CDD on a client who needed more. That is exactly the kind of finding that turns a routine examination into a problem.

The four factor categories

AUSTRAC expects the rating to draw on the same four categories as your business risk assessment, applied to this one customer:

  1. The kind of customer (an individual, a company, a trust, an association).
  2. The designated services you are providing them.
  3. The delivery channels you use (in person, remote, through a representative).
  4. The countries involved.

You identify the risk factors in each category, and give each factor a rating. One useful shortcut AUSTRAC offers: in a business risk assessment you weigh both likelihood and impact, but for a single customer "a good method may be using the impact rating... as a starting point," without the likelihood step. Rate by impact, not odds.

The method AUSTRAC wants to see

Your AML/CTF policies need a method your staff can actually follow. AUSTRAC spells out the three moves:

  • Check whether each identified risk factor is present for the customer.
  • Balance the nature and scale of the factors present into an overall rating.
  • Consider any indicators of unusual or criminal activity.

The point of writing it down is consistency: two staff, same client, same rating. A number that comes out of someone's head differently each time is not a method.

What low, medium and high look like

AUSTRAC's own examples are a good calibration:

  • Low: an Australian resident seeking a low-risk service, only low-risk jurisdictions involved, no red flags or enhanced-CDD triggers.
  • Medium: no red flags, but some moderate-impact factors, for example a multi-layered but not unduly complex control structure, a connection to a medium-risk jurisdiction, or a low-profile domestic PEP.
  • High: high-risk indicators with real complexity, for example an unusually complex control structure, a foreign PEP, ties to a high-risk jurisdiction, or a service with no clear economic or lawful purpose.

A common and defensible rule, straight from AUSTRAC's worked example, is that the presence of any high-risk factor makes the customer high risk.

A worked example (AUSTRAC's own)

A conveyancer's business risk assessment finds that large cash transactions are unlikely but very high impact (cash into real estate is a classic laundering path). They build a customer rating method off those impact ratings, with a rule that any high-risk factor means a high rating.

A buyer comes in: an individual, Australian resident, buying with a bank-approved loan, dealing with the firm directly, no medium or high factors and no enhanced-CDD triggers. Rating: low. So the conveyancer applies simplified CDD. Change one fact, say the buyer pays a large deposit in cash, and a high-impact factor is now present, the rating flips to high, and enhanced CDD kicks in. Same firm, same method, a different client, a different rating. That is the system working.

Two things people forget

Timing. The rating has to be done on the information "reasonably available... before you start to provide a designated service." It is part of onboarding, not something you backfill later. And it is not frozen: ongoing CDD can move it as you learn more.

The record. AUSTRAC's record-keeping expects "customer risk identification and assessment, decisions and rationale." A rating with no reasoning behind it is half a record. When someone asks in two years why this client was rated low, the answer is whatever you wrote down at the time.

The honest part

None of this needs software. A written method in your policies, an onboarding form that captures the factors, and a note of the reasoning per client will satisfy the obligation, and for a handful of clients that is entirely workable.

Where it gets heavy is volume and consistency: every new client, every factor checked, every rating reasoned and recorded, and all of it reproducible when an examiner asks. That is the part AML Mate now helps with. Its AI-assisted review reads a privacy-safe client profile, suggests the risk factors that may apply with the AUSTRAC reasoning behind each, and you confirm them; a deterministic rules engine, not the AI, then sets the rating, so the method stays consistent and the reasoning is on the file. The judgement stays yours. The paperwork does not.

If you are working through your first client files, two companion pieces pair well: beneficial ownership and UBO verification and what to do when a screening check returns a match.


Not sure where your setup stands? The free compliance check takes two minutes, no signup, and shows where you are against the new obligations.

This is general information drawn from AUSTRAC's published guidance as at July 2026, not legal advice. Confirm how the rules apply to your practice with a qualified adviser.

customer-risk-ratingcddtranche-2austracrisk-assessmentenhanced-cddsimplified-cddaccountantslawyersreal-estate

Ready to build your AML/CTF program?

AML Mate generates your AML/CTF program in 15 minutes using AUSTRAC's official templates. Start a 14-day free trial, cancel anytime.

This article is based on AUSTRAC's publicly available guidance. It does not constitute legal or compliance advice. Consult a licensed compliance professional for complex situations.

Customer Risk Rating Under Tranche 2 (Australia)