ISO 9001:2026 was published on 16 September. See what changed →


Writing an AML/CTF Risk Assessment That Actually Reflects Your Agency

Every AML/CTF Program Manual we’ve reviewed that fails an examination fails for the same reason, further back than the CDD file or the training record. It fails because the risk assessment underneath it describes the real estate industry in general, not the specific agency it’s supposed to protect. A risk assessment copied from a downloaded template will use correct language and cover the right topics, and it still won’t survive real scrutiny, because it doesn’t describe anything true about your business.

Here’s how to write one that actually does.

What a risk assessment is actually meant to do

A risk assessment isn’t a compliance essay proving you understand what money laundering is. It’s meant to be the honest, specific answer to one question: given exactly how this agency operates, where is our risk actually concentrated. Every other document in your program, your CDD procedure, your screening approach, your training priorities, should be built on what this document actually says, not on a generic industry statement sitting above it disconnected from the rest.

The four lenses most risk assessments work through

Most genuine risk assessments look at risk from four angles. None of these are exotic, and the value isn’t in naming them, it’s in answering each one honestly for your specific agency rather than with an industry generality.

Customer risk. Who do you actually deal with. A suburban family home agency selling mostly to first home buyers and upgraders has a very different customer risk profile to a CBD agency handling high value commercial sales to overseas investors and corporate buyers. Neither is automatically higher or lower risk in the abstract, the point is describing your actual customer base honestly.

Transaction risk. What kinds of transactions do you handle, and at what values. Off the plan sales, auction sales, private treaty, commercial leasing alongside residential sales, each carries a different risk texture, and an agency doing several of these needs to address each one specifically rather than writing about “property transactions” as a single category.

Channel and delivery risk. How do customers actually reach you and how do transactions get completed. An agency that does a meaningful volume of business through referral networks or overseas buyer’s agents has a different risk profile to one built almost entirely on local walk in enquiries and open homes.

Geographic risk. Where are your customers actually from, and where does the money involved in a transaction actually originate. This isn’t just about international buyers, a domestic customer moving funds through an account with no clear connection to their stated occupation is a geographic and source of funds question too.

What makes a risk assessment genuine rather than templated

The difference is almost always specificity, and it shows up in small details. A generic risk assessment says “real estate transactions can be used for money laundering through the purchase of property.” A genuine one says something closer to: “our agency completed 43 residential sales in the past 12 months, predominantly to owner occupier buyers in the $600,000 to $1.2 million range, with four transactions involving overseas based buyers, and no commercial or off the plan sales during this period.” The second version can only have been written by someone who actually looked at their own business. The first could have been written about any agency in the country, including ones that don’t exist yet.

This specificity matters practically too, not just for an examiner reading the document. A vague risk assessment gives your staff nothing to actually act on. A specific one tells them exactly what “normal” looks like for your agency, which makes it far easier to notice when something doesn’t fit that pattern.

A worked comparison

Take two real agencies, both compliant on paper, both using the same four category structure.

Agency one operates in a growing outer suburb, sells primarily established family homes and new builds to owner occupiers, almost entirely through open homes and local advertising, funded through standard bank finance. Their risk assessment reflects this: moderate transaction values, low structural complexity, minimal overseas exposure, and a documented note that off the plan and commercial transactions currently sit outside their service offering, meaning those specific risk factors don’t need deep treatment yet, only a note to revisit if that changes.

Agency two operates in an inner city area with a mix of high value residential and small commercial sales, works regularly with buyers’ agents representing overseas clients, and handles occasional off the plan developer sales. Their risk assessment, using the same four categories, looks substantially different: a dedicated section on enhanced due diligence triggers for overseas buyers, specific attention to beneficial ownership for company and trust purchasers, and heightened attention to source of funds documentation given the transaction values involved.

Same framework, same four lenses, genuinely different documents, because they describe genuinely different businesses. That’s what a real risk assessment looks like.

How the risk assessment should drive everything else in your program

This is the part templates get structurally wrong even when the content reads fine. Your risk assessment isn’t meant to sit as a standalone chapter, it’s meant to be the input that shapes the rest of the program.

If your risk assessment identifies overseas buyers as a genuine, if occasional, part of your business, your CDD procedure needs a clear enhanced due diligence trigger for exactly that scenario, not a vague reference to “higher risk customers” with no specifics. If your risk assessment notes you don’t currently handle commercial transactions, your training doesn’t need to spend equal time on a scenario your staff will never actually encounter, though it’s worth a brief note on what to do if that changes.

A risk assessment that isn’t visibly connected to the rest of your program in this way is a sign, to anyone reviewing it, that the whole document was built in isolated sections rather than as a genuine system.

The mistake that undermines an otherwise solid document

The single most common failure isn’t getting the content wrong, it’s failing to document the reasoning behind it. A risk assessment that states a conclusion without showing the thinking behind it (why this customer segment is rated the way it is, why this transaction type warrants the attention it gets) reads as an assertion rather than an assessment. The word “assessment” implies genuine analysis happened. Show that analysis, even briefly, for each risk factor you address.

Keeping this current is a separate task

Writing the risk assessment properly the first time is only half the job. It needs to be revisited when your business genuinely changes, not left untouched for years. We’ll cover exactly when and how to update it, and what specifically should trigger that review, in a separate article, since that’s a distinct skill from getting the initial document right.

Where to start

Getting your risk assessment genuinely specific to your agency is the foundation everything else in your program builds on, and it’s worth getting right before you move on to policies and procedures. Lead Comply’s free account gives you the customer due diligence workflow that puts your risk assessment into practice day to day, at no cost and with no credit card required, so the categories you’ve identified as higher risk have an actual operational process behind them, not just a paragraph in a document.

Create your free account → Lead Comply AML Portal



Leave a Reply

Your email address will not be published. Required fields are marked *