You're offline, showing the last version we saved.
Free template

AML risk assessment template for accounting practices

Every anti-money laundering regime that covers accountants starts in the same place: a written assessment of where your practice could be used to launder money, and a rating for each client. This template gives you both, plus the policy headings that hang off them. Australian firms new to AML/CTF since 1 July 2026 can use it alongside AUSTRAC's own starter kit.

Updated · Editable Word document (.docx) · Free

How to use it

How to use this template

  1. Check which regime applies, and to which services

    Start with the country table in section 1. In several countries only some services bring a firm into scope; know which of yours do before you assess anything.

  2. Read your supervisor’s risk assessment first

    Your regulator and supervisor publish sector and national risk assessments. The law in several countries requires you to take them into account, and they tell you what your supervisor will look for.

  3. Fill in part A honestly, as a team

    Describe your actual clients, services and channels, not the practice you wish you had. An hour with the partners and one manager is usually enough for a small firm.

  4. Use part B for every new client and at every review

    Rate each client, record the level of due diligence that follows from the rating, and set the next review date. High-risk clients get a partner sign-off.

  5. Review it every year, and when something changes

    A new service, a new kind of client, a supervisor alert or a suspicious matter you reported are all reasons to revisit it before the anniversary.

The template

The template in full

[Firm name] AML risk assessment

Replace everything in [square brackets].

Assessment details

ItemDetail
Firm[Firm name]
AML compliance officer / MLRO / nominated officer[Name, role]
Supervisor or regulator[e.g. AUSTRAC, ICAEW, ACCA, HMRC, DIA, FINTRAC, FIC]
Services in scope of the AML regime[List]
Approved by (governing body or senior management)[Name, role, date]
Next review[Date, no more than 12 months away]

1. Which regime applies

CountryThe regime for accounting practices (as at October 2026)
United KingdomThe Money Laundering Regulations 2017 apply to accountancy service providers. Regulation 18 requires a written firm-wide risk assessment that takes account of your supervisor’s information and covers customers, countries, services, transactions and delivery channels; regulation 19 requires policies, controls and procedures; regulation 28 sets customer due diligence. You are supervised by your professional body (for example ICAEW, ACCA, AAT, ICAS, CIOT or ATT) or by HMRC if you have none. The government has decided to move professional services supervision to the FCA; that needs legislation, and the FCA expects the transition to start in late 2028.
AustraliaFrom 1 July 2026, accountants who provide designated services under the AML/CTF Act 2006 (the "tranche 2" reforms) must be enrolled with AUSTRAC, generally within 28 days of first providing one, and have an AML/CTF program: an ML/TF risk assessment, AML/CTF policies, an AML/CTF compliance officer, customer due diligence, reporting and record keeping. The compliance officer reports to the governing body at least every 12 months, and the program needs an independent evaluation at least every three years. AUSTRAC publishes an accounting program starter kit for smaller practices. Check your services against the designated services in section 6 of the Act and AUSTRAC’s accountant guidance.
New ZealandAccounting practices are reporting entities under the AML/CFT Act 2009 for the activities the Act captures, supervised by the Department of Internal Affairs. A written risk assessment and an AML/CFT programme based on it are required, with an annual report to the supervisor.
CanadaAccountants and accounting firms are covered by the PCMLTFA when they receive or pay funds, buy or sell securities, real property or business assets, or transfer funds or securities for a client (giving instructions, not just advice). Audit, review and compilation engagements are excluded. A compliance program needs a compliance officer, written policies and procedures, a risk assessment, training and a review every two years (FINTRAC).
South AfricaUnder the FIC Act, accountants who provide trust and company services (Schedule 1, item 2, since 19 December 2022) are accountable institutions. Section 42 requires a risk management and compliance programme (RMCP) built on an institutional risk assessment (Financial Intelligence Centre).
United StatesThere is no general anti-money laundering program requirement for CPA firms: the Bank Secrecy Act program rules do not cover accounting practices as such. Proposals to extend AML duties to gatekeepers have been introduced in Congress but, to our knowledge, none had become law as at October 2026. Firms that receive large cash payments must still file IRS Form 8300, and many US firms use a risk assessment like this one as good practice for client acceptance.

2. Part A: firm-wide risk assessment

For each risk factor, describe your exposure, rate the inherent risk before controls, record the controls you apply, and rate what is left. Add rows for anything specific to your practice.

Risk factorOur exposureInherent risk (L/M/H)Controls we applyResidual risk (L/M/H)
Customers: entity types (individuals, companies, trusts, partnerships, charities)[Mix and numbers]Blank[e.g. beneficial ownership checks on every entity]Blank
Customers: complex or opaque structures, nominee arrangements, offshore entities[How many, which services]BlankBlankBlank
Customers: politically exposed persons and their associates[Known or screened]BlankBlankBlank
Customers: cash-intensive businesses (hospitality, retail, construction trades)BlankBlankBlankBlank
Customers: clients we have never met in personBlankBlankBlankBlank
Risk factorOur exposureInherent risk (L/M/H)Controls we applyResidual risk (L/M/H)
Services: company and trust formation, acting as or arranging nominee directors or trusteesBlankBlankBlankBlank
Services: handling client money, trust accounts, paying or receiving funds for clientsBlankBlankBlankBlank
Services: buying or selling businesses, shares or real property for clientsBlankBlankBlankBlank
Services: registered office or business address servicesBlankBlankBlankBlank
Services: tax, bookkeeping, payroll and advisory work (usually lower, but assess it)BlankBlankBlankBlank
Risk factorOur exposureInherent risk (L/M/H)Controls we applyResidual risk (L/M/H)
Geography: clients, owners or funds connected to higher-risk or sanctioned countriesBlankBlankBlankBlank
Delivery channels: remote onboarding, introductions through third partiesBlankBlankBlankBlank
Transactions: unusual size, speed or complexity for the client; payments from third partiesBlankBlankBlankBlank
Firm: staff turnover, training gaps, outsourced or offshore teams with access to client dataBlankBlankBlankBlank
OverallDetail
Overall firm risk rating[Low / Medium / High]
Main risks and why[Two or three sentences]
Actions arising, owner and date[List]
Supervisor and national risk assessments considered[Titles and dates]

3. Part B: client risk assessment

Complete for every new client before work starts, and again at each review date.

ItemDetail
Client and entity type[Name, type]
Beneficial owners and controllers[Names, how verified]
Services we provide[List; mark any in scope of the AML regime]
Source of funds or wealth (where risk requires)[Explanation and evidence]
PEP and sanctions screening[Result, date, tool used]

Risk indicators present (tick each that applies):

  • Ownership structure is complex, offshore or hard to explain.
  • The client, an owner or a close associate is a politically exposed person.
  • Funds, owners or trading connected to a higher-risk or sanctioned country.
  • Cash-intensive business, or cash amounts out of line with the business.
  • The client was reluctant to provide identity or ownership information.
  • We have not met the client, and identity was verified remotely.
  • The instructions have no clear commercial or tax reason.
  • Frequent changes of adviser, or the previous accountant raised a concern.
OutcomeDetail
Client risk rating[Low / Medium / High]
Due diligence level[Simplified (only where your regime allows) / Standard / Enhanced]
Additional measures[e.g. source of wealth evidence, partner approval, more frequent review]
Approved by[Name, date; partner for High]
Next review[Date: e.g. High yearly, Medium every two years, Low at each engagement renewal]

4. Red flags that need escalating

  • A client asks to pay fees in cash, from a third party, or through an unrelated account.
  • Money passes through the firm or a client structure with no obvious reason.
  • A transaction is structured to stay under a reporting threshold.
  • Documents look altered, or figures cannot be reconciled to source.
  • A client’s lifestyle or assets do not match the income they report.
  • A client asks how to keep ownership or funds from being seen by a regulator or tax authority.

Anyone who sees a red flag tells [the compliance officer / MLRO] the same day and does not tell the client. The officer decides whether a suspicious matter or suspicious activity report is required (to AUSTRAC, the NCA, the NZ Police FIU, FINTRAC or the FIC). Tipping off is an offence in most of these regimes.

5. Policies and controls that follow from the assessment

  • A named compliance officer (MLRO or nominated officer), with the authority and time to do the job.
  • Customer due diligence procedure: what we collect, how we verify it, when we do enhanced checks.
  • Ongoing monitoring: when client risk ratings are reviewed, and what triggers an early review.
  • Internal reporting route for suspicions, and how reports to the authority are made and recorded.
  • Record keeping: what we keep, where, and for how long your regime requires.
  • Staff screening and AML training at induction and at least yearly, with a record of who completed it.
  • Independent review or evaluation of the program at the interval your regime sets.

6. Review and sign-off

VersionWhat changedApproved byDate
1.0First assessmentBlankBlank
BlankBlankBlankBlank

Country references checked as at October 2026. Rules and forms change; confirm each one with the regulator or professional body before you rely on it.

This template is not legal advice. Anti-money laundering obligations depend on the services you provide and where you provide them; confirm your obligations with your supervisor or regulator, and use its guidance alongside this template.

Common questions

Frequently asked questions

What is an AML risk assessment for an accounting firm?
A written assessment of how the firm could be used to launder money or finance terrorism, looking at its clients, services, geographic connections, delivery channels and transactions. It sets the controls and the level of customer due diligence the firm applies, and it is the first document a supervisor asks to see.
When did AML obligations start for Australian accountants?
The tranche 2 reforms to the AML/CTF Act took effect for accountants on 1 July 2026, for the designated services the Act lists. Firms providing them must enrol with AUSTRAC, generally within 28 days of first providing one, and have an AML/CTF program. Not every accounting service is in scope; check yours against AUSTRAC’s guidance.
Is an AML policy the same as an AML risk assessment?
No. The risk assessment comes first and says where your risks are; the policy (or program) sets out the controls, procedures and responsibilities that deal with them. UK firms need both under regulations 18 and 19 of the Money Laundering Regulations 2017. Section 5 of this template lists the policy headings that follow from the assessment.
Do US CPA firms need an AML program?
Not as a general rule. As at October 2026 the Bank Secrecy Act does not require CPA firms to run an AML program, though proposals to extend it to gatekeepers have been introduced in Congress. Form 8300 cash reporting still applies to any business, and a client risk assessment is good practice.
How often should an accounting firm review its AML risk assessment?
At least once a year, and whenever something changes: a new service, a new type of client, new guidance or alerts from your supervisor, or a suspicious matter you reported. Client risk ratings are reviewed on a cycle set by the rating, with high-risk clients reviewed most often.
More templates

More templates

The thinking behind these: AI for accountants and bookkeepers: what actually works.

Get your free seat →

AI in Practice Summit returns. What worked, what's next: two days on what AI actually did for firms this year, and where it goes in 2027. 11–12 November 2026, virtual and free.