ISO 9001:2026 was published on 16 September. See what changed →


When to Update Your Risk Assessment (And What Actually Triggers It)

A risk assessment is only accurate as of the day it was written. That’s true even of a genuinely good one, the kind we described in our guide to writing one properly, specific to your agency rather than copied from a template. The moment your business changes in a material way, that carefully written document starts drifting away from reality, quietly, without anyone necessarily noticing until it’s tested.

Here’s what should actually prompt you to revisit it, separate from just waiting for whatever date happens to be circled on the calendar.

Two kinds of updates, and you need both

A scheduled review, done on a routine basis regardless of whether anything obvious has changed, is worth having as a baseline. It catches the slow, gradual drift that doesn’t announce itself as a single clear event, the kind of change that happens so incrementally nobody quite notices until they step back and compare where the business is now to what the document describes.

But a scheduled review alone isn’t enough, because plenty of the changes that matter most happen suddenly, not gradually, and waiting for the next scheduled date to address them leaves a genuine gap open in the meantime. You need triggered reviews too: specific events that prompt an update regardless of where you are in the routine cycle.

Business changes that should trigger a review

A new service line. If your agency starts handling off the plan sales, commercial property, or property management alongside residential sales, and your current risk assessment only ever addressed residential sales to owner occupiers, it no longer describes your actual business. This needs addressing before the new service line is fully underway, not retrospectively once it’s already been running for months.

A new office or branch. Different locations can carry genuinely different risk profiles, a regional office and an inner city commercial focused branch aren’t the same business wearing the same letterhead. Opening a new location is a natural point to ask whether your existing risk assessment still applies, or whether it needs branch specific detail.

A new customer segment, even an occasional one. If your agency starts seeing a meaningful uptick in overseas buyers, high value transactions, or corporate and trust purchasers, and this wasn’t a feature of your original risk assessment, that document needs to catch up before it becomes a genuine blind spot rather than an oversight.

A change in ownership or structure. New ownership, a merger, or a significant change in how the business is run is worth a fresh look at governance and risk together, since both may have shifted at once.

External triggers worth watching for

AUSTRAC’s own guidance and the AML/CTF rules do get updated periodically, and a risk assessment that was accurate when written can drift out of alignment if nobody’s tracking those changes on your behalf. Emerging typologies, new patterns of misuse that get flagged industry wide, are also worth genuine attention rather than dismissal, even if they haven’t shown up in your own agency yet. A risk factor doesn’t need to have already caused a problem for your agency specifically before it’s worth documenting.

Internal signals that something needs updating

Sometimes the clearest signal comes from inside your own business. If a transaction gets flagged internally, whether or not it ultimately results in a Suspicious Matter Report, and the reason it caught someone’s attention isn’t clearly addressed anywhere in your current risk assessment, that’s a direct sign the document has a gap. The same applies if an independent review identifies a risk category that wasn’t adequately covered, or if staff keep encountering a particular scenario that the current document simply doesn’t speak to.

This last one is worth taking seriously even when it feels minor. If your team is repeatedly handling a situation your risk assessment doesn’t mention, that’s not staff going off script, it’s the document failing to describe the business staff are actually operating in.

What updating actually looks like in practice

Most updates aren’t a full rewrite. They’re targeted additions or adjustments: a new risk factor added, an existing rating adjusted, a new customer or transaction type addressed with the same level of specificity as everything else in the document. The reasoning behind each change should be documented briefly, the same discipline that made the original assessment genuine rather than templated applies to every update as well.

This connects directly to proper document control. Every update should produce a new version, dated and approved by whoever holds that authority in your governance structure, with the previous version archived rather than discarded, exactly as we’ve covered separately. An update that isn’t tracked this way creates the same problem an entirely unversioned program does: nobody can say with confidence what the document said at any given point in time.

A worked example

An agency starts taking on off the plan developer sales for the first time, a genuine expansion of their business, but their risk assessment still only describes standard residential resale transactions. Six months in, an examiner asks how the agency’s risk assessment addresses the specific dynamics of off the plan sales, deposit structures, staged payments, buyers purchasing well ahead of settlement, and the honest answer is that it doesn’t, because nobody updated the document when the business itself changed.

Compare that to an agency that made the same expansion but treated it as a clear trigger: before actively taking on off the plan work, they added a dedicated section addressing the specific risk factors involved, adjusted their CDD approach accordingly, and documented exactly when and why the update was made. When asked the same question, they have a direct, specific answer rather than a gap.

The mistake of waiting for the next scheduled date

If you already know something material has changed, whether that’s a new service line, a new location, or a gap someone’s flagged internally, treating the next annual review as the appropriate time to address it is a choice to leave a known gap open longer than necessary. A scheduled review is a floor, not a reason to defer something you already know needs attention now.

Where Lead Comply fits into this

Keeping your risk assessment current only matters if the rest of your program actually reflects it day to day. The Lead Comply AML Portal’s customer due diligence workflow is built to support exactly this, so when your risk categories change, your team’s actual process can be updated to match, rather than the document and the daily practice slowly drifting apart from each other. Our free account gives you that workflow at no cost, so keeping your operational process aligned with an updated risk assessment doesn’t require new software or a new contract every time your business evolves.

Create your free account → Lead Comply AML Portal



Leave a Reply

Your email address will not be published. Required fields are marked *