[Firm name] AML risk assessment
Replace everything in [square brackets].
Assessment details
| Item | Detail |
|---|---|
| Firm | [Firm name] |
| AML compliance officer / MLRO / nominated officer | [Name, role] |
| Supervisor or regulator | [e.g. AUSTRAC, ICAEW, ACCA, HMRC, DIA, FINTRAC, FIC] |
| Services in scope of the AML regime | [List] |
| Approved by (governing body or senior management) | [Name, role, date] |
| Next review | [Date, no more than 12 months away] |
1. Which regime applies
| Country | The regime for accounting practices (as at October 2026) |
|---|---|
| United Kingdom | The Money Laundering Regulations 2017 apply to accountancy service providers. Regulation 18 requires a written firm-wide risk assessment that takes account of your supervisor’s information and covers customers, countries, services, transactions and delivery channels; regulation 19 requires policies, controls and procedures; regulation 28 sets customer due diligence. You are supervised by your professional body (for example ICAEW, ACCA, AAT, ICAS, CIOT or ATT) or by HMRC if you have none. The government has decided to move professional services supervision to the FCA; that needs legislation, and the FCA expects the transition to start in late 2028. |
| Australia | From 1 July 2026, accountants who provide designated services under the AML/CTF Act 2006 (the "tranche 2" reforms) must be enrolled with AUSTRAC, generally within 28 days of first providing one, and have an AML/CTF program: an ML/TF risk assessment, AML/CTF policies, an AML/CTF compliance officer, customer due diligence, reporting and record keeping. The compliance officer reports to the governing body at least every 12 months, and the program needs an independent evaluation at least every three years. AUSTRAC publishes an accounting program starter kit for smaller practices. Check your services against the designated services in section 6 of the Act and AUSTRAC’s accountant guidance. |
| New Zealand | Accounting practices are reporting entities under the AML/CFT Act 2009 for the activities the Act captures, supervised by the Department of Internal Affairs. A written risk assessment and an AML/CFT programme based on it are required, with an annual report to the supervisor. |
| Canada | Accountants and accounting firms are covered by the PCMLTFA when they receive or pay funds, buy or sell securities, real property or business assets, or transfer funds or securities for a client (giving instructions, not just advice). Audit, review and compilation engagements are excluded. A compliance program needs a compliance officer, written policies and procedures, a risk assessment, training and a review every two years (FINTRAC). |
| South Africa | Under the FIC Act, accountants who provide trust and company services (Schedule 1, item 2, since 19 December 2022) are accountable institutions. Section 42 requires a risk management and compliance programme (RMCP) built on an institutional risk assessment (Financial Intelligence Centre). |
| United States | There is no general anti-money laundering program requirement for CPA firms: the Bank Secrecy Act program rules do not cover accounting practices as such. Proposals to extend AML duties to gatekeepers have been introduced in Congress but, to our knowledge, none had become law as at October 2026. Firms that receive large cash payments must still file IRS Form 8300, and many US firms use a risk assessment like this one as good practice for client acceptance. |
2. Part A: firm-wide risk assessment
For each risk factor, describe your exposure, rate the inherent risk before controls, record the controls you apply, and rate what is left. Add rows for anything specific to your practice.
| Risk factor | Our exposure | Inherent risk (L/M/H) | Controls we apply | Residual risk (L/M/H) |
|---|---|---|---|---|
| Customers: entity types (individuals, companies, trusts, partnerships, charities) | [Mix and numbers] | Blank | [e.g. beneficial ownership checks on every entity] | Blank |
| Customers: complex or opaque structures, nominee arrangements, offshore entities | [How many, which services] | Blank | Blank | Blank |
| Customers: politically exposed persons and their associates | [Known or screened] | Blank | Blank | Blank |
| Customers: cash-intensive businesses (hospitality, retail, construction trades) | Blank | Blank | Blank | Blank |
| Customers: clients we have never met in person | Blank | Blank | Blank | Blank |
| Risk factor | Our exposure | Inherent risk (L/M/H) | Controls we apply | Residual risk (L/M/H) |
|---|---|---|---|---|
| Services: company and trust formation, acting as or arranging nominee directors or trustees | Blank | Blank | Blank | Blank |
| Services: handling client money, trust accounts, paying or receiving funds for clients | Blank | Blank | Blank | Blank |
| Services: buying or selling businesses, shares or real property for clients | Blank | Blank | Blank | Blank |
| Services: registered office or business address services | Blank | Blank | Blank | Blank |
| Services: tax, bookkeeping, payroll and advisory work (usually lower, but assess it) | Blank | Blank | Blank | Blank |
| Risk factor | Our exposure | Inherent risk (L/M/H) | Controls we apply | Residual risk (L/M/H) |
|---|---|---|---|---|
| Geography: clients, owners or funds connected to higher-risk or sanctioned countries | Blank | Blank | Blank | Blank |
| Delivery channels: remote onboarding, introductions through third parties | Blank | Blank | Blank | Blank |
| Transactions: unusual size, speed or complexity for the client; payments from third parties | Blank | Blank | Blank | Blank |
| Firm: staff turnover, training gaps, outsourced or offshore teams with access to client data | Blank | Blank | Blank | Blank |
| Overall | Detail |
|---|---|
| Overall firm risk rating | [Low / Medium / High] |
| Main risks and why | [Two or three sentences] |
| Actions arising, owner and date | [List] |
| Supervisor and national risk assessments considered | [Titles and dates] |
3. Part B: client risk assessment
Complete for every new client before work starts, and again at each review date.
| Item | Detail |
|---|---|
| Client and entity type | [Name, type] |
| Beneficial owners and controllers | [Names, how verified] |
| Services we provide | [List; mark any in scope of the AML regime] |
| Source of funds or wealth (where risk requires) | [Explanation and evidence] |
| PEP and sanctions screening | [Result, date, tool used] |
Risk indicators present (tick each that applies):
- Ownership structure is complex, offshore or hard to explain.
- The client, an owner or a close associate is a politically exposed person.
- Funds, owners or trading connected to a higher-risk or sanctioned country.
- Cash-intensive business, or cash amounts out of line with the business.
- The client was reluctant to provide identity or ownership information.
- We have not met the client, and identity was verified remotely.
- The instructions have no clear commercial or tax reason.
- Frequent changes of adviser, or the previous accountant raised a concern.
| Outcome | Detail |
|---|---|
| Client risk rating | [Low / Medium / High] |
| Due diligence level | [Simplified (only where your regime allows) / Standard / Enhanced] |
| Additional measures | [e.g. source of wealth evidence, partner approval, more frequent review] |
| Approved by | [Name, date; partner for High] |
| Next review | [Date: e.g. High yearly, Medium every two years, Low at each engagement renewal] |
4. Red flags that need escalating
- A client asks to pay fees in cash, from a third party, or through an unrelated account.
- Money passes through the firm or a client structure with no obvious reason.
- A transaction is structured to stay under a reporting threshold.
- Documents look altered, or figures cannot be reconciled to source.
- A client’s lifestyle or assets do not match the income they report.
- A client asks how to keep ownership or funds from being seen by a regulator or tax authority.
Anyone who sees a red flag tells [the compliance officer / MLRO] the same day and does not tell the client. The officer decides whether a suspicious matter or suspicious activity report is required (to AUSTRAC, the NCA, the NZ Police FIU, FINTRAC or the FIC). Tipping off is an offence in most of these regimes.
5. Policies and controls that follow from the assessment
- A named compliance officer (MLRO or nominated officer), with the authority and time to do the job.
- Customer due diligence procedure: what we collect, how we verify it, when we do enhanced checks.
- Ongoing monitoring: when client risk ratings are reviewed, and what triggers an early review.
- Internal reporting route for suspicions, and how reports to the authority are made and recorded.
- Record keeping: what we keep, where, and for how long your regime requires.
- Staff screening and AML training at induction and at least yearly, with a record of who completed it.
- Independent review or evaluation of the program at the interval your regime sets.
6. Review and sign-off
| Version | What changed | Approved by | Date |
|---|---|---|---|
| 1.0 | First assessment | Blank | Blank |
| Blank | Blank | Blank | Blank |
Country references checked as at October 2026. Rules and forms change; confirm each one with the regulator or professional body before you rely on it.
This template is not legal advice. Anti-money laundering obligations depend on the services you provide and where you provide them; confirm your obligations with your supervisor or regulator, and use its guidance alongside this template.