What the risk-based approach means for accountants and lawyers after 1 July 2026.
1 July 2026 has passed.
For accountants and lawyers, the question is no longer whether the new obligations are coming. The question is whether your firm can make and explain the right risk decisions in everyday client matters.
Australia’s expanded anti-money laundering and counter-terrorism financing laws now apply when professional firms provide certain designated services connected with Australia.
The trigger is the service provided, not the professional title.
Designated services can include actively helping a client with a property or business transaction, handling money or assets for a transaction, arranging financing, or creating or restructuring a company or trust. Newly regulated businesses must enrol by 29 July 2026.
But enrolment is only the entry point.
The real task is making the risk-based approach work.
Risk-based in one sentence
Identify the risk, match the checks to it, decide whether the remaining risk is acceptable, and keep monitoring for change.
Your firm’s risk assessment sets the framework. Each client and matter is then assessed against it.
Higher risk requires stronger, targeted checks. Genuinely lower risk may allow simpler measures where permitted. The regulator does not expect firms to apply the same controls to every client regardless of risk.
The risk-based approach in five simple steps
A risk-based approach does not mean giving every client the same checklist. It means identifying the risks in each client and matter, applying controls that match those risks, and deciding whether the risk that remains is within the firm’s approved risk appetite.
The process can be reduced to five practical questions:
What are we being asked to do? What creates the risk? What checks match that risk? Is the remaining risk acceptable? Has anything changed?
The visual below turns those questions into a simple, repeatable process for accountants and lawyers.
Risk-Based in Practice
A Simple 5-Step Flow for Accountants & Lawyers
Identify the risk, match the checks, decide if the remaining risk is acceptable, and keep monitoring for change.
Is the firm providing a designated service?
Examples: assisting with a property or business transaction, managing money or assets for a transaction, arranging financing, or creating or restructuring a company or trust.
Consider the key risk factors:
- The client and ownership structure
- The service being provided
- How it will be delivered
- Countries involved
- Movement of funds and third parties
- Purpose of the transaction
Apply proportionate controls, such as:
- Verify identity and ownership
- Understand the purpose
- Establish source of funds and wealth (where appropriate)
- Investigate unusual third-party payments
- Screen relevant parties
- Escalate higher-risk matters
- Obtain senior approval
After applying the controls, is the remaining risk within the firm’s approved risk appetite?
Proceed with appropriate approval and monitoring.
Apply further controls if possible. If the risk cannot be within appetite, decline or exit the matter and consider a suspicious matter report.
Reassess the client and matter when:
- The transaction or purpose changes
- Ownership or funding changes
- New information comes to light
- Behaviour is inconsistent or unusual
ONGOING MONITORING
Risk does not stand still. Keep monitoring to ensure your controls remain appropriate.
The takeaway
A risk-based approach is not a longer checklist.
It is a documented judgment about:
the risk, the controls, the remaining risk and whether the firm is prepared to accept it.
Can your team explain why the controls matched the risk and what happens when that risk changes?
How DVT Mcleods can help
We are not advising from the sidelines.
DVT Mcleods has practical experience in anti-money laundering and counter-terrorism financing. We are also a professional services firm subject to the Tranche 2 reforms, so we understand firsthand the challenge of turning new legal obligations into processes that work in a busy practice.
We can help your firm identify which services are regulated, assess business and client risk, define its risk appetite, develop proportionate controls, prepare policies and procedures, and establish clear approval, escalation and record-keeping processes.
Our focus is not a generic compliance pack. It is a practical and defensible framework that your people can understand, apply and maintain.
Need help making the new requirements work in practice? Talk to DVT Mcleods.