← Compliance glossary

Risk-assessment review cycle

Reporting & records

The cadence at which a reporting entity's ML/TF (and post-2026 PF) risk assessment must be reviewed and updated. Mandatory triggers include material change to the venue's designated services, customer profile, delivery channels, or AUSTRAC-communicated risk; absent a trigger, the assessment must still be reviewed at least every three years. The reviewed assessment is approved by the senior manager (s.26P) and retained as part of the program's documentation set.

This term sits in the reporting & records section of the working glossary — vocabulary for statutory reporting cadences, evidence retention, and inspection-ready record discipline.

Read more

Operational pillar pages

Related terms

Other terms in Reporting & records